Photovoltaic double-platform data interaction method based on soft and hard encryption cooperation and storage medium

CN122783296APending Publication Date: 2026-09-18DEZHOU POWER SUPPLY COMPANY OF STATE GRID SHANDONG ELECTRIC POWER +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610937190.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-26
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

然而,硬件加密与软件加密两种保护方式各自独立部署,解密后数据分别进入不同解析通道,缺乏对硬件解密结果与软件解密结果之间协同一致性的校验环节

Benefits of technology

[0006]This invention achieves the separation and identification of hardware and software encrypted data by receiving the initial ciphertext data stream encrypted by a hardware encryption component from a first photovoltaic platform and separating a first encrypted segment carrying a hardware encryption identifier and a second encrypted segment carrying a timestamp. The first encrypted segment is parsed using a hardware decryption protocol to obtain a first decrypted plaintext segment. Simultaneously, a pre-built software encryption algorithm library is invoked to parsed the second encrypted segment using a software decryption protocol to obtain a second decrypted plaintext segment. These are then reassembled into a unified set of reconstructed plaintext data based on the hardware encryption identifier and the timestamp. By performing a decryption coordination comparison process on the reconstructed plaintext data set, the first platform signature information parsed from the hardware decryption data unit is compared with hardware signature baseline information to generate a first coordination comparison identifier, and the second platform signature information parsed from the software decryption data unit is compared with software signature baseline information to generate a second coordination comparison identifier. Based on these two identifiers, a coordination identifier representing the consistency of the decryption process is generated, thereby establishing a synchronous verification mechanism for hardware and software decryption results. When the collaboration identifier indicates that the preset collaboration conditions are met, the platform performs data parsing processing on the recombined plaintext data set, extracting photovoltaic module operating status record information and photovoltaic module configuration description information, and performing time-aligned fusion based on timestamp markers to generate a fused data description set. The fused data description set is then pushed to the second photovoltaic platform and converted to generate the target interactive data set. This scheme processes hardware encryption and software encryption/decryption in parallel and collaboratively. By establishing consistency constraints for the dual decryption process through signature comparison after decryption, it maintains high-strength protection of critical data by hardware encryption components while flexibly encrypting and extending configuration data using software encryption channels. This balances data confidentiality strength and processing efficiency. Furthermore, by performing time-aligned fusion and protocol adaptation conversion on the decrypted and recombined data, it shields the impact of differences in the source platform's encryption channels on the target platform's parsing logic, improving the reliability and consistency of cross-platform data interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122783296A_ABST
    Figure CN122783296A_ABST
Patent Text Reader

Abstract

This invention provides a data interaction method and storage medium for photovoltaic dual-platforms based on hardware and software encryption collaboration. The method receives an initial encrypted ciphertext data stream from a first photovoltaic platform and performs streaming parsing to separate a first encrypted segment from a second encrypted segment carrying a timestamp. The first encrypted segment is parsed using a hardware decryption protocol to obtain a first decrypted plaintext segment, and the second encrypted segment is parsed using a software encryption algorithm library to obtain a second decrypted plaintext segment. These segments are then reassembled to generate a reconstructed plaintext data set. A decryption collaboration comparison is performed, comparing the platform signature information in the hardware and software decrypted data units to generate a collaboration identifier. When the collaboration identifier meets preset conditions, the operating status record and configuration description information are parsed and extracted, time-aligned, and fused to generate a fused data description set. This set is then converted to a new format and pushed to the built-in parsing interface of the second photovoltaic platform. This invention improves the security and timing consistency of data interaction between photovoltaic dual platforms.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a photovoltaic dual-platform data interaction method and storage medium based on hardware and software encryption collaboration. Background Technology

[0002] Photovoltaic dual-platform data interaction refers to the process of transmitting component operating status information and configuration description information between photovoltaic management platforms, realizing cross-platform collaborative operation monitoring and synchronous configuration management. Existing technologies typically employ hardware encryption components to encrypt the entire transmitted data, or software encryption algorithms to uniformly encrypt and encapsulate the data stream. The receiving platform then restores the data using the corresponding decryption method and directly parses and uses it. However, hardware and software encryption are deployed independently, and the decrypted data enters different parsing channels, lacking a verification mechanism to ensure consistency between hardware and software decryption results. When a protocol parsing anomaly or signature mismatch occurs in a certain encryption channel, the receiving platform struggles to detect the decryption process deviation before data parsing, easily leading to timing misalignment or content mismatch between component operating status records and configuration description information during subsequent integration. Furthermore, the data carried by different encryption channels each carries independent time reference information; directly pushing it to the target platform for parsing requires additional configuration of timing correction logic and protocol adaptation mechanisms, increasing the deployment complexity and processing overhead of cross-platform interaction. Summary of the Invention

[0003] In view of this, the present invention provides a photovoltaic dual-platform data interaction method and storage medium based on hardware and software encryption collaboration.

[0004] The technical solution of this invention is implemented as follows: On one hand, embodiments of the present invention provide a photovoltaic dual-platform data interaction method based on hardware and software encryption collaboration, the method comprising: The system receives the initial ciphertext data stream after it has been encrypted by the hardware encryption component of the first photovoltaic platform. At the same time, it performs streaming parsing on the initial ciphertext data stream to separate the first encrypted segment carrying the hardware encryption identifier and the second encrypted segment carrying the timestamp mark from the initial ciphertext data stream. The hardware decryption protocol corresponding to the hardware encryption component is executed to parse the first encrypted fragment to obtain the first decrypted plaintext fragment. At the same time, the software decryption protocol is executed to parse the second encrypted fragment to obtain the second decrypted plaintext fragment. Based on the hardware encryption identifier and timestamp, the first decrypted plaintext fragment and the second decrypted plaintext fragment are reassembled to generate a reassembled plaintext data set containing hardware decryption data units and software decryption data units. A decryption collaboration comparison is performed on the recombined plaintext data set. The first platform signature information parsed from the hardware decryption data unit is compared with the preset hardware signature benchmark information to generate a first collaboration comparison identifier. The second platform signature information parsed from the software decryption data unit is compared with the preset software signature benchmark information to generate a second collaboration comparison identifier. A collaboration identifier representing the consistency of the decryption process is generated based on the first collaboration comparison identifier and the second collaboration comparison identifier. When the consistency of the decryption process indicated by the collaborative identifier meets the preset collaborative conditions, the platform data parsing is performed on the recombined plaintext data set. The photovoltaic module operation status record information of the first photovoltaic platform is extracted from the hardware decryption data unit, and the photovoltaic module configuration description information of the first photovoltaic platform is extracted from the software decryption data unit. The photovoltaic module operation status record information and the photovoltaic module configuration description information are time-aligned and merged according to the timestamp mark to generate a fused data description set with a unified time series benchmark. The fused data description set is pushed to the built-in parsing interface of the second photovoltaic platform. During the push process, the fused data description set is formatted according to the data protocol specifications of the second photovoltaic platform to generate a target interactive data set that is compatible with the data receiving structure of the second photovoltaic platform.

[0005] On the other hand, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the methods described above.

[0006] This invention achieves the separation and identification of hardware and software encrypted data by receiving the initial ciphertext data stream encrypted by a hardware encryption component from a first photovoltaic platform and separating a first encrypted segment carrying a hardware encryption identifier and a second encrypted segment carrying a timestamp. The first encrypted segment is parsed using a hardware decryption protocol to obtain a first decrypted plaintext segment. Simultaneously, a pre-built software encryption algorithm library is invoked to parsed the second encrypted segment using a software decryption protocol to obtain a second decrypted plaintext segment. These are then reassembled into a unified set of reconstructed plaintext data based on the hardware encryption identifier and the timestamp. By performing a decryption coordination comparison process on the reconstructed plaintext data set, the first platform signature information parsed from the hardware decryption data unit is compared with hardware signature baseline information to generate a first coordination comparison identifier, and the second platform signature information parsed from the software decryption data unit is compared with software signature baseline information to generate a second coordination comparison identifier. Based on these two identifiers, a coordination identifier representing the consistency of the decryption process is generated, thereby establishing a synchronous verification mechanism for hardware and software decryption results. When the collaboration identifier indicates that the preset collaboration conditions are met, the platform performs data parsing processing on the recombined plaintext data set, extracting photovoltaic module operating status record information and photovoltaic module configuration description information, and performing time-aligned fusion based on timestamp markers to generate a fused data description set. The fused data description set is then pushed to the second photovoltaic platform and converted to generate the target interactive data set. This scheme processes hardware encryption and software encryption / decryption in parallel and collaboratively. By establishing consistency constraints for the dual decryption process through signature comparison after decryption, it maintains high-strength protection of critical data by hardware encryption components while flexibly encrypting and extending configuration data using software encryption channels. This balances data confidentiality strength and processing efficiency. Furthermore, by performing time-aligned fusion and protocol adaptation conversion on the decrypted and recombined data, it shields the impact of differences in the source platform's encryption channels on the target platform's parsing logic, improving the reliability and consistency of cross-platform data interaction. Attached Figure Description

[0007] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present invention and, together with the specification, serve to explain the technical solutions of the present invention.

[0008] Figure 1 This is a schematic diagram illustrating the implementation process of a photovoltaic dual-platform data interaction method based on software and hardware encryption collaboration, provided in an embodiment of the present invention.

[0009] Figure 2 This is a schematic diagram of the hardware entity of a photovoltaic platform provided in an embodiment of the present invention. Detailed Implementation

[0010] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on the present invention. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0011] This invention provides a photovoltaic dual-platform data interaction method based on hardware and software encryption collaboration, which can be executed by a second photovoltaic platform. In this embodiment, the first photovoltaic platform can be an industrial-grade edge computing gateway or intelligent data collector deployed at a photovoltaic power plant site. It integrates a trusted platform module security chip or a dedicated hardware encryption card as the physical carrier of the hardware encryption component. This device is responsible for real-time aggregation of operating status data and configuration description information generated by devices such as photovoltaic inverters, combiner boxes, and environmental monitors via a bus protocol, and then performs hardware and software dual-channel encryption before sending the encrypted data stream outwards. The second photovoltaic platform can be a rack-mounted data server or virtual computing instance deployed at a remote control center or in the cloud. It runs the backend service processes and middleware applications of the photovoltaic monitoring system, responsible for receiving, decrypting, collaborative verification, timing alignment and fusion, and protocol conversion and push. Together, they constitute a secure data interaction system between the photovoltaic power plant side and the central control center side.

[0012] Figure 1 This is a schematic diagram illustrating the implementation process of a photovoltaic dual-platform data interaction method based on hardware and software encryption collaboration, as provided in an embodiment of the present invention. Figure 1 As shown, the method includes: Step S100: Receive the initial ciphertext data stream after it has been encrypted by the hardware encryption component of the first photovoltaic platform, and simultaneously perform streaming parsing on the initial ciphertext data stream to separate the first encrypted segment carrying the hardware encryption identifier and the second encrypted segment carrying the timestamp mark from the initial ciphertext data stream.

[0013] In one implementation, the hardware encryption component can be a dedicated physical security module independent of the general-purpose processor of the first photovoltaic platform. Internally, it includes physically unclonable function circuitry and a hardware cryptographic algorithm coprocessor. After receiving the original plaintext data to be sent by the first photovoltaic platform, this component converts the plaintext data into a ciphertext sequence that cannot be directly recognized, based on its internally embedded encryption logic. The initial ciphertext data stream refers to the continuous binary byte sequence transmitted by the first photovoltaic platform through a wired or wireless communication link after being encrypted by the hardware encryption component. This byte sequence is represented at the transport layer as a string of consecutive bits, and the receiving end cannot distinguish the logical order of its parts before parsing.

[0014] The hardware encryption identifier is a fixed-length binary tag that is pre-placed at the header of a specific encrypted segment when the hardware encryption component performs encryption operations. This tag indicates to the receiving end that the segment originates from the hardware encryption component and requires the corresponding hardware decryption protocol stack for reverse engineering. The first encrypted segment refers to the set of consecutive ciphertext bytes in the initial ciphertext data stream that follows the hardware encryption identifier and whose payload has been processed by the symmetric block cipher algorithm core within the hardware encryption component. This segment carries the core telemetry data on the operating status of the photovoltaic modules collected by the first photovoltaic platform. The timestamp is a precise time description field embedded in the header or at a fixed offset address of a specific encrypted segment. This field is generated by the real-time clock module of the first photovoltaic platform after synchronization based on the GPS timing signal or network time protocol, and is used to mark the original generation time of the data carried by the segment.

[0015] The second encrypted segment refers to the encrypted data block in the initial encrypted data stream whose payload portion has been processed by the pre-built software encryption algorithm library in the kernel of the first photovoltaic platform operating system. The encryption process of this block relies on the computing power of the general-purpose central processing unit and carries configuration description information of photovoltaic modules, non-real-time log records, and statistical summary data. Stream parsing means that after receiving the first byte of the initial encrypted data stream, the receiving end does not need to wait for the entire data stream to arrive, but immediately starts a byte-by-byte scanning mechanism based on a forward finite state machine. By detecting the predefined byte alignment mode and length indicator field, it dynamically identifies and segments the logical boundaries of the data stream.

[0016] In this embodiment, when receiving the initial encrypted data stream from the first photovoltaic platform via hardware encryption, the data receiving physical interface controller deployed on the second photovoltaic platform continuously monitors signal level changes on the communication link. When a start frame delimiter conforming to the physical layer encoding rules is detected, the interface controller converts subsequent arriving analog signals into a digital pulse sequence via an analog-to-digital converter and moves this digital pulse sequence to the receive buffer queue using direct memory access. Simultaneously, regarding the specific implementation of streaming parsing, the streaming parsing engine maintains a byte pointer pointing to the current parsing position, starting from the head address of the receive buffer queue. Each time this pointer advances, it reads one byte and compares it with the pre-stored characteristic byte pattern in the streaming parsing engine's internal status register.

[0017] The streaming parsing engine internally employs two parallel pattern matching channels. The first channel searches for the characteristic byte sequence corresponding to the hardware encryption identifier, while the second channel searches for the frame format indicator bytes corresponding to the timestamp. When the first channel detects that the current byte window perfectly matches the characteristic byte sequence of the hardware encryption identifier, the streaming parsing engine records this match position as the starting boundary of the first encrypted segment and continues scanning until it encounters a preset segment end marker or calculates the ending boundary of the first encrypted segment using the parsing length field. Subsequently, the byte content between the starting and ending boundaries is completely extracted and marked as the first encrypted segment. In parallel, the second pattern matching channel detects the frame format indicator byte of the timestamp mark during the scanning process. This frame format indicator byte is located at a fixed offset in the encapsulation structure of the second encrypted fragment. The streaming parsing engine determines the starting position of the second encrypted fragment by verifying whether the byte at this offset meets the structural constraints of the second encrypted fragment header. After determining the starting position, it further reads the timestamp mark field that follows. This field occupies a fixed length of consecutive bytes and stores the number of seconds since the epoch and the sub-second count value. The streaming parsing engine extracts this field as is and saves it together with the payload of the second encrypted fragment.

[0018] Step S200: Perform hardware decryption protocol parsing corresponding to the hardware encryption component on the first encrypted fragment to obtain the first decrypted plaintext fragment. At the same time, call the preset software encryption algorithm library to perform software decryption protocol parsing on the second encrypted fragment to obtain the second decrypted plaintext fragment. Based on the hardware encryption identifier and timestamp, perform data recombination on the first decrypted plaintext fragment and the second decrypted plaintext fragment to generate a recombined plaintext data set containing hardware decryption data units and software decryption data units.

[0019] Optionally, step S200 may specifically include the following steps S210 to S260: Step S210: Extract the hardware key index information carried by the hardware encryption identifier in the first encrypted segment, and obtain the corresponding hardware decryption key copy from the preset hardware key management container based on the hardware key index information.

[0020] In addition to serving as a tag for the fragment source, the hardware encryption identifier has a specific sub-segment in its bit structure dedicated to storing hardware key index information. The hardware key index information is an integer value corresponding to the key slot number established by the hardware encryption component on the first photovoltaic platform during key negotiation with the second photovoltaic platform during the initialization phase. The pre-defined hardware key management container is a storage area protected by a hardware security module. This container is internally divided into multiple uniquely numbered storage slots, each independently storing a copy of the hardware decryption key, with a one-to-one mapping between the slot and the key index information.

[0021] In this embodiment, when extracting the hardware key index information, the pre-processing logic of the hardware decryption protocol parsing reads several consecutive bytes starting from the starting offset address of the first encrypted segment. Based on the predefined format description file of the hardware encryption identifier, it determines the bit offset and bit width of the hardware key index information within the hardware encryption identifier. Then, it uses bitmasking and shift operations to extract the original integer value of the hardware key index information from the binary representation of the hardware encryption identifier. After obtaining the hardware key index information, this value is passed as an address index parameter to the access interface of the hardware key management container.

[0022] Upon receiving the index parameter, the internal access arbitration circuit of the hardware key management container first checks whether the source permission level of the current access request meets the security policy requirements for reading the corresponding slot. If the verification is successful, the arbitration circuit drives the word lines and bit lines of the storage array to select the specific storage slot pointed to by the index parameter. It then converts the charge state of the storage cell in that slot into a digital logic level via a sensitive amplifier, thereby reading out a complete copy of the hardware decryption key. This copy of the hardware decryption key is then directly transmitted to the key input latch of the hardware decryption operation subunit via a shielded dedicated key bus. The entire transmission process does not pass through the system main memory to prevent the key data from being eavesdropped on by the bus.

[0023] Step S220: Input the first encrypted fragment and the hardware decryption key copy into the hardware decryption operation subunit. The hardware decryption operation subunit decrypts and restores the first encrypted fragment based on the hardware decryption key copy to obtain the first decrypted plaintext fragment. Then, output the first decrypted plaintext fragment to the reassembly buffer area.

[0024] Optionally, step S220 may specifically include the following steps S221 to S227: Step S221: Divide the first encrypted segment into groups. Divide the ciphertext data stream of the first encrypted segment into multiple ciphertext data groups with sequential dependencies according to the preset hardware encryption block size.

[0025] The preset hardware encryption block size is the bit width for a single encryption / decryption process specified by the core cryptographic algorithm within the hardware encryption component on the first photovoltaic platform side. This parameter is determined by the chip model of the hardware encryption component during system initialization and is pre-synchronized between the communicating parties. Sequential dependency refers to the fact that, when decrypting a sequence of ciphertext data blocks, the correct reconstruction of subsequent ciphertext data blocks depends on specific intermediate state information generated during the decryption of preceding ciphertext data blocks. This dependency is introduced by the cryptographic block chaining mode adopted by the hardware encryption component.

[0026] In this embodiment of the invention, the grouping process is executed by the flow control state machine at the front end of the hardware decryption operation subunit. The flow control state machine internally maintains a byte counter and a group sequence number counter. When the ciphertext data stream of the first encrypted segment enters the group buffer from the input first-in-first-out queue, the byte counter begins to accumulate the count of the incoming bytes. Whenever the byte counter reaches a preset hardware encryption block size, the flow control state machine generates a group truncation signal, packages the accumulated bytes in the current group buffer into an independent ciphertext data group, assigns the value of the current group sequence number counter to this group as its sequence identifier, then clears the group buffer, resets the byte counter to zero, and increments the group sequence number counter by one, preparing to receive the next group.

[0027] For any remaining bytes at the end of the ciphertext data stream that are smaller than the hardware encryption block size, the flow control state machine pads the remaining bytes according to the padding standard specified by the hardware encryption component, ensuring that the last block also reaches the complete hardware encryption block size, thus guaranteeing the normal operation of subsequent decryption. All the divided ciphertext data blocks form an ordered sequence according to their assigned sequence identifiers. This sequence contains strict sequential dependencies, and the decryption output of the preceding block directly affects the decryption input of the following block.

[0028] Step S222: Input the first ciphertext data block and the hardware decryption key copy into the initialization vector generation part of the hardware decryption operation subunit. The initialization vector generation part iteratively transforms the first ciphertext data block and the hardware decryption key copy to generate an initialization vector for decrypting the first ciphertext data block.

[0029] The initialization vector generation section is a dedicated hardware module within the hardware decryption subunit, specifically designed to generate the initial state vector for block cipher decryption operations. Its circuitry includes a multi-stage linear feedback shift register chain, a nonlinear compression function circuit, and a round-control counter. In this embodiment, the first ciphertext data block is directly fed from the block buffer into the first input latch of the initialization vector generation section, and the hardware decryption key copy is fed from the key register into the second input latch. Upon receiving the start signal, the control logic of the initialization vector generation section first loads a portion of the bits from the hardware decryption key copy as an initial seed value into each stage of the multi-stage linear feedback shift register chain, and simultaneously adds a portion of the bits from the first ciphertext data block as a perturbation input to the feedback loop. In each subsequent clock cycle, the linear feedback shift register chain performs a shift operation according to a predetermined feedback polynomial, with the output of each register being fed to the input of the nonlinear compression function circuit during the shift. The nonlinear compression function circuit consists of a multi-layer XOR gate tree and a substitution box array. This circuit performs multiple rounds of nonlinear mixing on the input multi-bit signals to generate a compressed feedback bitstream. This feedback bitstream is re-injected into the least significant bit input of the linear feedback shift register chain and is also temporarily stored in an intermediate state register. The above shifting, mixing, and feedback process is repeatedly executed under the control of a round control counter. The number of repetitions is equal to the number of iterations for generating the initialization vector specified by the cryptographic algorithm inside the hardware encryption component.

[0030] When the round control counter reaches the preset number of iterations, the initialization vector generation part stops iterating and reads out the final state values ​​stored in each register of the multi-level linear feedback shift register chain in parallel, combining them into a binary vector with a width equal to the size of the hardware encryption block. This vector is the initialization vector used to decrypt the first ciphertext data block. This initialization vector is latched into the initialization vector temporary storage area of ​​the decryption core logic part, waiting to participate in the next decryption operation.

[0031] Step S223: Input the initialization vector and the first ciphertext data block together into the decryption core logic part of the hardware decryption operation subunit. The decryption core logic part performs logical obfuscation and permutation operations on the initialization vector and the first ciphertext data block to generate the first plaintext data block.

[0032] Optionally, step S223 may specifically include the following steps S2231 to S2237: Step S2231: Store the initialization vector and the first ciphertext data block into the initialization vector temporary storage area and the ciphertext data block temporary storage area of ​​the decryption core logic part, respectively.

[0033] The initialization vector buffer is a parallel register array composed of edge-triggered data flip-flops, with a bit width equal to the hardware encryption block size. It is dedicated to maintaining the stability of the initialization vector before decryption begins. The ciphertext data block buffer is another parallel register array with the same bit width, used to latch the current ciphertext data block to be decrypted. In this embodiment, the initialization vector generation part generates a data validity flag signal while outputting the initialization vector. After the control state machine of the decryption core logic part detects the validity of this flag signal, it issues a register load enable pulse. On the rising edge of this enable pulse, each bit of the initialization vector is synchronously written into the corresponding flip-flop in the initialization vector buffer. Simultaneously, each bit of the first ciphertext data block is read from the block buffer and synchronously written into the corresponding flip-flop in the ciphertext data block buffer, completing the data loading operation.

[0034] Step S2232: Perform bitwise logical obfuscation on the initialization vector in the initialization vector temporary storage area and the first ciphertext data block in the ciphertext data block temporary storage area by decrypting the first logical obfuscation array in the core logic part to generate the initial obfuscated byte sequence.

[0035] The first logic obfuscation array is a combinational logic network in the core decryption logic section that achieves the initial mixing of plaintext, ciphertext, and key-related materials. This array consists of multiple sets of parallel logic gates, each responsible for processing two bits at the same bit position in the initialization vector and ciphertext data blocks. Each obfuscation unit in the first logic obfuscation array contains a two-input XOR gate and a two-input AND gate. One input of the XOR gate is connected to the corresponding bit output in the initialization vector temporary storage area, and the other input is connected to the corresponding bit output in the ciphertext data block temporary storage area. One input of the AND gate is connected to the corresponding bit output in the initialization vector temporary storage area, and the other input is connected to the corresponding bit output in the key-related extended material. The outputs of the XOR gate and the AND gate are further fed into a two-input NOR gate for secondary combination. The output of the NOR gate is the result of the bit after processing by the first logic obfuscation array. The obfuscation results of all bits are generated in parallel, forming the initial obfuscated byte sequence. This sequence is transmitted on the internal data bus of the hardware decryption operation subunit to the next processing stage, namely the input of the preset nonlinear substitution table.

[0036] Step S2233: Input the initial obfuscated byte sequence into the preset nonlinear replacement table in the decryption core logic part, and perform nonlinear replacement on the initial obfuscated byte sequence through the preset nonlinear replacement table to generate a nonlinear transformed byte sequence.

[0037] The pre-defined nonlinear substitution table is a key component within the core decryption logic. Physically, it is implemented using a mask-programmed read-only memory (ROM) or a one-time programmable ROM array. The address line width and data line width of this array are equal to the hardware encryption block size. Each memory cell in the array stores a cryptographically designed substitution value. All bits of the initial obfuscated byte sequence are applied in parallel to the address lines of the pre-defined nonlinear substitution table as the address input for a memory read operation. The internal address decoder of the pre-defined nonlinear substitution table decodes the input address signal, selecting the row of memory cells uniquely corresponding to that address. The pre-set substitution value in that row is read out onto the data lines via a column gating circuit and a sensitive amplifier, forming the output byte sequence. Because the mapping relationship stored internally in the pre-defined nonlinear substitution table is a rigorously designed nonlinear function, even a small change in the input address will cause drastic and irregular changes in multiple bits of the output data, thus achieving the cryptographic effect of nonlinear substitution. The read byte sequence is the nonlinearly transformed byte sequence, which is latched into the intermediate result register of the core decryption logic.

[0038] Step S2234: Input the nonlinear transformation byte sequence into the cyclic shift processing part in the decryption core logic part, and perform a cyclic shift operation of a preset number of bits on the nonlinear transformation byte sequence through the cyclic shift processing part to generate a shifted transformation byte sequence.

[0039] The cyclic shift processing section is a combinational logic circuit in the core decryption logic responsible for bit-level rearrangement of the data byte sequence. It is primarily implemented by a barrel shifter composed of cascaded multiplexers. In this embodiment, the nonlinearly transformed byte sequence is read in parallel from the intermediate result register and sent to the data input of the barrel shifter. Simultaneously, the control unit of the core decryption logic, based on the current decryption round number, looks up a shift bit control signal from the round parameter table and applies it to the shift bit selection terminal of the barrel shifter. The multiplexer network inside the barrel shifter, based on the signal state of the shift bit selection terminal, reconnects each bit at the input terminal to its corresponding position at the output terminal according to the cyclic left shift rule. Specifically, the cyclic left shift operation shifts the highest bit in the input sequence out and reinserts it into the lowest bit position, while the remaining bits are shifted one position higher in the order of shift bits. When the shift bit is greater than one, the above operation is repeated a corresponding number of times. However, the hardware structure of the barrel shifter allows for the cyclic shift of any number of bits to be completed within a single clock cycle. The output of the barrel shifter presents a new byte sequence after cyclic shifting by a preset number of bits. This sequence is the shift transformation byte sequence and is sent to the next processing stage.

[0040] Step S2235: Input the shift-transformed byte sequence into the second logic obfuscation array in the core logic part of the decryption, and perform bitwise logic obfuscation operation on the shift-transformed byte sequence and the preset round constant byte sequence to generate the first round of decryption intermediate state byte sequence.

[0041] The second logic obfuscation array is another combinational logic network in the core decryption logic section used to mix the diffused data with the round-related constants. Its circuit structure is more complex than the first logic obfuscation array, containing a mixed arrangement of XOR gate arrays and half-adder arrays. The preset round constant byte sequence is generated in real-time by the round constant generation circuit inside the core decryption logic section according to the current round number. The round constant generation circuit is a small lookup table or linear feedback shift register driven by a counter, and its output is a fixed-pattern byte sequence with a width equal to the hardware encryption block size. This sequence has a different bit combination pattern in each round. In this embodiment, the shift transformation byte sequence and the preset round constant byte sequence are respectively fed into the two sets of input terminals of the second logic obfuscation array. Each bit processing unit of the second logic obfuscation array contains a three-input XOR gate and a carry-bypass half-adder. The three inputs of the three-input XOR gate are connected to the corresponding bits of the shift-transform byte sequence, the corresponding bits of the round constant byte sequence, and the state feedback bits stored in the previous round of processing, respectively. The half-adder receives the corresponding bits of the shift-transform byte sequence and the corresponding bits of the round constant byte sequence, and generates a sum and carry output. This carry output is fed to the XOR gate input of the adjacent high-order processing unit to achieve lateral diffusion between bits. After the above combinational logic processing, the results output by each bit unit are combined to form the first round of decryption intermediate state byte sequence. This sequence is written back to the intermediate result register, overwriting the previously stored nonlinear transformation byte sequence, preparing for the next round of processing.

[0042] Step S2236: Take the intermediate state byte sequence of the first round of decryption as the new input byte sequence, and repeat the non-linear replacement processing, cyclic shift operation and round constant byte sequence logical obfuscation operation until the preset number of rounds is reached to generate the final plaintext data group.

[0043] The control state machine within the core decryption logic maintains a round counter to track the number of decryption rounds completed. In this embodiment, after the first round of intermediate state byte sequence is generated, the round counter is incremented. The control state machine then determines whether the current count has reached the preset number of rounds specified by the hardware encryption component. If not, the control state machine issues a new round processing start signal, using the first round of intermediate state byte sequence stored in the intermediate result register as the input byte sequence for the new round. This sequence sequentially flows through a preset nonlinear replacement table for nonlinear replacement, through a cyclic shift processing section for cyclic shifting, and through a second logic obfuscation array to perform logic obfuscation with the new round's round constant byte sequence, generating the second round of intermediate state byte sequence. This process is repeated in a pipelined or iterative manner. Each completed round increments the round counter until its value equals the preset number of rounds. When the preset number of rounds is reached, the control state machine recognizes the intermediate state byte sequence generated in the last round as the final plaintext data block and generates a decryption completion flag signal.

[0044] Step S2237: Push the final plaintext data packet from the output temporary storage area of ​​the decryption core logic part to the plaintext data packet cache queue as the first plaintext data packet generated.

[0045] The output buffer of the decryption core logic is a set of parallel output registers with the same width as the hardware encryption block, used to temporarily store the final plaintext data packet upon decryption completion. The plaintext data packet buffer queue is a first-in-first-out (FIFO) storage queue within the hardware decryption subunit, used to sequentially collect the plaintext data packets generated after decryption of each ciphertext data packet. When the decryption completion flag is valid, the final plaintext data packet is synchronously loaded from the combinational logic output into the output buffer. Simultaneously, the queue management logic within the hardware decryption subunit detects that the output buffer is not empty, generating a queue write request. This request moves all bits in the output buffer to the tail storage location of the plaintext data packet buffer queue via the internal data bus and updates the queue tail pointer. The plaintext data packet written to the queue is then marked as the first plaintext data packet, awaiting participation in the final plaintext concatenation operation along with subsequently generated plaintext data packets.

[0046] Step S224: Extract the contents of the intermediate state register generated during the decryption of the first ciphertext data block, and use the contents of the intermediate state register as the link input information for the next ciphertext data block.

[0047] The intermediate state registers are a set of edge-triggered registers within the core decryption logic section used to store the intermediate results of each round of decryption operations and the circuit state at the end of the final round. Because the hardware encryption component uses a ciphertext block chaining mode during encryption, the encryption process of each ciphertext data block depends on the ciphertext output generated after the encryption of the previous ciphertext data block as feedback. Therefore, at the decryption end, the decryption process of each ciphertext data block must use the specific state information generated and stored during the decryption process of the previous ciphertext data block as the chaining input.

[0048] When the final round of decryption of the first ciphertext data packet ends, the control state machine of the decryption core logic generates a state latch pulse. The rising edge of this pulse samples and stores the signal levels of all signals on the current second logic obfuscation array output bus, as well as the level states of some key internal nodes, into an intermediate state register. The stored content constitutes a complete snapshot of the circuit state at the end of the decryption process of the first ciphertext data packet. This snapshot is extracted and transmitted to the link input information buffer at the input end of the decryption core logic through a dedicated state feedback path. When the hardware decryption operation subunit begins processing the next ciphertext data packet, the content in the link input information buffer will replace the role of the initialization vector and be sent to the decryption core logic along with the next ciphertext data packet to participate in the first round of logic obfuscation, thereby ensuring the correct linking between packets during the decryption process.

[0049] Step S225: Input the next ciphertext data block and the link input information into the decryption core logic part, perform the same logical obfuscation and permutation operation as the first ciphertext data block, and generate the next plaintext data block.

[0050] After decrypting the first ciphertext data packet and extracting the link input information, the hardware decryption operation subunit's packet scheduling logic retrieves the second ciphertext data packet, whose sequence identifier immediately follows, from the input first-in-first-out queue. The next ciphertext data packet is loaded into the ciphertext data packet temporary storage area of ​​the decryption core logic part, while the link input information extracted and saved during the decryption of the first ciphertext data packet is loaded from the link input information temporary storage area to the initialization vector temporary storage area originally occupied by the initialization vector. Subsequently, the decryption core logic part uses the link input information and the next ciphertext data packet as the initial input for a new round of decryption operations, completely repeating the entire logic obfuscation and permutation operation process described in steps S2232 to S2237. Since the link input information contains state remnants from the decryption process of the first ciphertext data packet, these state remnants, when mixed with the next ciphertext data packet, will correctly cancel the inter-packet coupling effect introduced during encryption, thereby restoring the next ciphertext data packet to the correct next plaintext data packet. The generated next plaintext data packet is also pushed to the tail of the plaintext data packet buffer queue.

[0051] Step S226: Iteratively execute the extraction operation of the contents stored in the intermediate state register and the decryption operation of the next ciphertext data block until all ciphertext data blocks with sequential dependencies have been processed.

[0052] The group processing loop control logic within the hardware decryption subunit continuously monitors the empty / full status of the input FIFO queue and the current group number. Each time a ciphertext data group is decrypted and a corresponding plaintext data group is generated, the loop control logic extracts the next round of link input information from the intermediate status register, while simultaneously checking if there are still unprocessed subsequent ciphertext data groups in the input FIFO queue. If so, the next ciphertext data group is read, and the loading, decryption, and status extraction process is repeated. In this embodiment, this iterative process operates efficiently in a pipeline manner: while the core decryption logic is processing the current ciphertext data group, the group prefetch logic has already read the next ciphertext data group from the input FIFO queue and temporarily stored it in the prefetch buffer; when the link input information is extracted and the prefetch buffer is not empty, the next group can seamlessly enter the core decryption logic, achieving uninterrupted continuous execution of the decryption operation. The iteration process continues until the input first-in-first-out queue is empty and the grouping control logic confirms that all ciphertext data groups of the first encrypted segment have been divided and sent into the queue. At this point, the last ciphertext data group is processed and the iteration terminates.

[0053] Step S227: Concatenate all the generated plaintext data groups according to the processing order of the ciphertext data groups to obtain a continuous plaintext byte sequence, and output the plaintext byte sequence as the first decrypted plaintext fragment to the reassembly buffer area.

[0054] The plaintext concatenation buffer logic within the hardware decryption subunit is responsible for reassembling multiple plaintext data packets scattered in the plaintext data packet buffer queue into a continuous byte stream in its original order. In this embodiment, the plaintext concatenation buffer logic incorporates an output byte counter and a reassembly buffer pointer. When the plaintext data packet buffer queue is not empty, the queue management logic retrieves a plaintext data packet from the head of the queue in a first-in-first-out order, and the order identifier of this packet is strictly consistent with the processing order of the original ciphertext data packets.

[0055] The plaintext concatenation buffer logic writes all bytes contained in the packet, starting from the first byte of the packet, byte by byte, to the memory address pointed to by the reassembly buffer pointer. Each time a byte is written, the reassembly buffer pointer is incremented by one, and the output byte counter is incremented by one. After writing one packet, the queue management logic continues to retrieve the next plaintext data packet, appending its byte content immediately after the end of the previous packet, and continues writing to memory. This cycle continues until the plaintext data packet buffer queue is cleared. When all plaintext data packets have been concatenated, a contiguous memory region defined by the starting address of the reassembly buffer pointer and the final value of the output byte counter stores the complete plaintext byte sequence, which constitutes the first decrypted plaintext fragment. Subsequently, the output direct memory access engine of the hardware decryption operation subunit, based on the starting address and length parameters, transmits the entire contents of this memory region via the system bus to the storage segment pre-allocated and locked for the hardware decryption result in the reassembly buffer region, completing the final output of the first decrypted plaintext fragment.

[0056] Step S230: Extract the software encryption algorithm identifier from the second encrypted segment, and select the corresponding target software decryption logic from the preset software encryption algorithm library based on the software encryption algorithm identifier.

[0057] The software encryption algorithm identifier is an enumerated type field in the header structure of the second encryption segment. Its values ​​have been mapped one-to-one with the various encryption algorithms supported by the software encryption algorithm library on the first photovoltaic platform during the system design phase. The pre-built software encryption algorithm library is represented in the storage space of the second photovoltaic platform as a dynamically linked function set or a statically linked function table. Each member function in this library encapsulates the decryption implementation of a symmetric cryptographic algorithm, and the entry address of the function is registered in the symbol table of the operating system when the library is loaded.

[0058] The central processing unit (CPU) of the second photovoltaic platform executes the second encrypted fragment parsing routine. This routine reads two consecutive bytes at a fixed offset address in the header of the second encrypted fragment and interprets them as an unsigned short integer, which is the software encryption algorithm identifier. The CPU uses this software encryption algorithm identifier as an index parameter and passes it to the algorithm selector and dispatcher of the pre-built software encryption algorithm library. The algorithm selector and dispatcher internally maintains a jump table, where each entry corresponds to a software encryption algorithm identifier and stores the memory entry address of the corresponding target software decryption logic. The dispatcher uses the software encryption algorithm identifier as the offset index to access the jump table, reads the entry address in the corresponding entry, and then redirects the program execution flow to the target software decryption logic code body at that address through an unconditional jump instruction or function pointer call, thereby completing the selection and preparation for calling the target software decryption logic.

[0059] Step S240: Call the target software decryption logic to perform reverse parsing on the second encrypted fragment, strip the software encryption layer from the second encrypted fragment, and output the plaintext data unit obtained after stripping the software encryption layer as the second decrypted plaintext fragment to the reconstructing buffer area.

[0060] After the target software decryption logic is invoked, its code body unfolds sequentially in the instruction execution pipeline of the central processing unit, performing a reverse parsing operation on the ciphertext payload of the second encrypted segment. In this embodiment, the target software decryption logic first parses the total length and number of blocks of the ciphertext payload from the payload description field of the second encrypted segment, and then divides the ciphertext payload into multiple equal-length ciphertext data blocks according to the block length specified by the corresponding symmetric cryptographic algorithm. The target software decryption logic then obtains the symmetric decryption key associated with the current second encrypted segment from the software key store through a secure system call. This key is securely exchanged with the first photovoltaic platform side through a key negotiation protocol during the system initialization phase and encrypted and stored locally in a protected key file.

[0061] For each ciphertext data block, the target software decryption logic initiates a decreasing-round cyclic processing flow. In each round, the central processing unit sequentially executes a sequence of inverse byte substitution instructions, a sequence of reverse shift instructions, a sequence of inverse column mixing instructions, and a sequence of XOR operations with the round key. Inverse byte substitution is achieved by looking up a pre-stored array of inverse substitution boxes in memory. Each inverse substitution box is an array containing 256 constant bytes; the value of the input byte serves as the array index, and the retrieved array member is the substitution result. Reverse shift is achieved through a series of register cyclic shift instructions or byte rearrangement instructions, adjusting the byte order within the block according to the block size and algorithm specifications. Inverse column mixing is achieved through table lookup and XOR combination, dividing the block into several columns and performing a combination of multiplication and addition on the Galois field for the bytes in each column. The multiplication result required for this operation is also obtained by looking up a pre-computed multiplication result table. The round key addition operation involves bitwise XORing the current block state with the round key obtained from the key expansion scheduler. After all predetermined rounds of reverse processing, the ciphertext data packets are restored to plaintext data packets. Once all ciphertext data packets have been decrypted, the target software's decryption logic sequentially concatenates the plaintext data packets to form a continuous plaintext data unit. This plaintext data unit is then moved from the temporary working buffer to a storage segment reserved for the software's decryption result in the reassembly buffer area via a memory copy operation. This plaintext data unit is the second decrypted plaintext fragment.

[0062] Step S250: Extract the first decrypted plaintext fragment and the second decrypted plaintext fragment from the reconstructed buffer area, and extract the hardware encryption identifier associated with the first decrypted plaintext fragment and the software encryption algorithm identifier associated with the second decrypted plaintext fragment.

[0063] The reassembly buffer is a structured memory pool partitioned from the main memory of the second photovoltaic platform for temporarily storing intermediate decryption results. After both the first and second decrypted plaintext fragments are output to the reassembly buffer, the hardware decryption operation subunit and the central processing unit send output completion interrupt signals to the management logic of the reassembly buffer. After confirming that both decryption results are ready, the management logic initiates the data extraction process. In this embodiment, the management logic first reads the descriptor table of the reassembly buffer. This descriptor table records the starting physical address, length, and associated attribute metadata of the hardware decryption result storage segment and the software decryption result storage segment. Based on the address information in the descriptor table, the management logic reads all bytes of the first decrypted plaintext fragment from the hardware decryption result storage segment to the reassembly working area via direct memory access operations, and reads all bytes of the second decrypted plaintext fragment from the software decryption result storage segment to another area of ​​the reassembly working area. Simultaneously, the management logic reads the previously saved hardware encryption identifier associated with the first decrypted plaintext fragment from the extended attribute field of the descriptor table, and the software encryption algorithm identifier associated with the second decrypted plaintext fragment from the header appendix information area of ​​the software decryption result storage segment. The extracted hardware encryption identifier and software encryption algorithm identifier are stored respectively in two metadata variables in the reconstructing work area for use in subsequent reconstructing steps.

[0064] Step S260: Based on the timestamp, the first decrypted plaintext fragment and the second decrypted plaintext fragment are concatenated to generate a reconstructed plaintext data set, and the hardware encryption identifier and the software encryption algorithm identifier are used as additional descriptive information for the reconstructed plaintext data set.

[0065] The timestamp is present in the same format and offset position in the internal data structures of both the first and second decrypted plaintext segments, used to identify the original generation time of each data record within the segment. The management logic performs internal record scanning on both the first and second decrypted plaintext segments respectively. The scanning process is based on a predefined data record format description file within the segment, which specifies the header length of each record, the offset of the timestamp field within the record header, the byte length of the timestamp field, and the storage location of the total record length. Starting from the beginning address of the first decrypted plaintext segment, the management logic parses out the timestamp and record content of each hardware operating status record, and constructs a temporary hardware record mapping table using the timestamp as the key and the record content as the value.

[0066] Similarly, the management logic performs the same scanning and parsing operation on the second decrypted plaintext fragment, parsing out the timestamp and record content of each software configuration description record one by one, and constructing a temporary software record mapping table. After completing the mapping table construction, the management logic extracts the union of all timestamps in the two mapping tables and sorts the timestamps in ascending order. For each sorted timestamp, it searches for records in both the hardware and software temporary mapping tables that exactly match the timestamp or are within a preset tolerance range. If a match is found in the hardware temporary mapping table, the corresponding hardware operating status record is extracted and encapsulated into a hardware decryption data unit; if a match is found in the software temporary mapping table, the corresponding software configuration description record is extracted and encapsulated into a software decryption data unit. The hardware decryption data units and software decryption data units generated for the same timestamp are combined to form a composite data entry. All composite data entries corresponding to all timestamps are arranged sequentially according to the order of their timestamps, together constituting the main data part of the reconstructed plaintext data set. Finally, a description information block is constructed at the header of the reconstructed plaintext data set. The hardware encryption identifier and software encryption algorithm identifier extracted above are written into the corresponding predefined fields in the description information block, so that the two are permanently saved as additional description information of the reconstructed plaintext data set.

[0067] Step S300: Perform a decryption coordination comparison on the recombined plaintext data set. Compare the first platform signature information parsed from the hardware decryption data unit with the preset hardware signature benchmark information to generate a first coordination comparison identifier. Compare the second platform signature information parsed from the software decryption data unit with the preset software signature benchmark information to generate a second coordination comparison identifier. Based on the first coordination comparison identifier and the second coordination comparison identifier, generate a coordination identifier that represents the consistency of the decryption process.

[0068] Optionally, step S300 may specifically include the following steps S310 to S360: Step S310: Parse the first platform signature information field at a fixed offset address from the hardware decryption data unit of the reconstructed plaintext data set, and perform signature feature extraction on the first platform signature information field. Compare the extracted first signature feature with the benchmark signature feature in the preset hardware signature benchmark information to generate a first collaborative comparison identifier.

[0069] The fixed offset address is the starting position of a field that is explicitly defined during the data structure design phase and is known to both communicating parties. This offset address is calculated from the starting byte of the hardware decryption data unit. The first platform signature information field is a structured data field that sequentially contains a signature algorithm identifier subfield, a signature length subfield, and a signature value subfield. Signature feature extraction refers to the process of parsing specific cryptographic feature data that can be used for comparison from the signature value subfield according to the algorithm type indicated by the signature algorithm identifier subfield. In this embodiment, the base address of the currently processed hardware decryption data unit in memory is first obtained, and then the base address is added to the predefined fixed offset address to obtain the starting access address of the first platform signature information field. The first byte is read from this starting address. This byte is the signature algorithm identifier subfield, and its value indicates the signature algorithm type used by the first photovoltaic platform hardware encryption component, such as using an elliptic curve digital signature algorithm or a hash-based message authentication code algorithm. Subsequently, according to the indication of the signature algorithm identifier subfield, the number of bytes in the signature length subfield is determined and the signature length value is read. Then, the complete signature value subfield is read from the subsequent address according to the signature length value. The specific operations for signature feature extraction vary depending on the signature algorithm type: if the signature algorithm identifier indicates an asymmetric digital signature, the corresponding digital signature algorithm's decoding function is called to parse the signature value subfield into its internal cryptographic commitment component, and this commitment component is used as the first signature feature; if the signature algorithm identifier indicates a symmetric message authentication code, the original byte sequence of the signature value subfield is directly used as the first signature feature.

[0070] While extracting the first signature feature, the corresponding baseline signature feature is read from the preset hardware signature baseline information storage area based on the same signature algorithm identifier. For asymmetric digital signatures, the baseline signature feature is the public key parameter set extracted from the first photovoltaic platform public key certificate; for symmetric message authentication codes, the baseline signature feature is the pre-shared symmetric authentication key. The first signature feature and the baseline signature feature are compared. For asymmetric digital signatures, a digital signature verification operation is performed. This operation uses the public key in the baseline signature feature to perform modular exponentiation or elliptic curve multiplication on the first signature feature, and the result is compared with the hash value of the data to be signed in the hardware decryption data unit; for symmetric message authentication codes, the hash message authentication code is recalculated using the symmetric key in the baseline signature feature, and the result is compared byte-by-byte with the first signature feature. If the comparison or verification operation results in a match, a logical truth value is output as the first collaborative comparison identifier; if the results are inconsistent, a logical false value is output.

[0071] Step S320: Parse the second platform signature information field at the fixed offset address from the software decryption data unit of the reconstructed plaintext data set, and perform signature feature extraction on the second platform signature information field. Compare the extracted second signature feature with the benchmark signature feature in the preset software signature benchmark information to generate a second collaborative comparison identifier.

[0072] The second platform signature information field in the software decryption data unit has a structured definition similar to that of the first platform signature information field, including a signature algorithm identifier subfield, a signature length subfield, and a signature value subfield. This embodiment of the invention employs a process similar to that used for processing the hardware decryption data unit, obtaining the base address of the software decryption data unit, adding a fixed offset address, and then accessing the second platform signature information field. Since the software encryption algorithm library on the first photovoltaic platform side typically uses a hash message authentication code based on a symmetric key to protect the software configuration data, the signature algorithm identifier subfield in the second platform signature information field usually indicates a certain hash message authentication code algorithm, such as a message authentication code based on a secure hash algorithm. After reading the signature length, the signature value subfield is extracted, and the original byte sequence of this signature value subfield is used as the second signature feature. Simultaneously, the symmetric authentication key corresponding to the current first photovoltaic platform is read from the preset software signature baseline information storage area; this key is the baseline signature feature. The system receives the second signature feature and the baseline signature feature. Using the symmetric key in the baseline signature feature, it re-executes the exact same hash message authentication code calculation process on the data portion to be signed in the software decryption data unit. This calculation process first generates internal and external key pads using the symmetric key and padding constants. Then, it divides the data to be signed into hash blocks and sequentially feeds them into a hash compression function for iterative compression, ultimately generating a fixed-length message authentication code. The calculated message authentication code is then compared byte-by-byte with the second signature feature. If every byte is identical, a logical true value is output as the second collaborative comparison identifier; if any byte difference exists, a logical false value is output.

[0073] Step S330: Input the first co-alignment identifier and the second co-alignment identifier into the dual-path alignment result combination logic part, and the dual-path alignment result combination logic part performs logical AND combination processing on the first co-alignment identifier and the second co-alignment identifier.

[0074] Optionally, step S330 may specifically include the following steps S331 to S336: Step S331: Store the first collaborative comparison identifier in the first state temporary storage area of ​​the dual-path comparison result combinational logic part, and store the second collaborative comparison identifier in the second state temporary storage area of ​​the dual-path comparison result combinational logic part.

[0075] The first and second state buffers are two independent one-bit data registers within the combinational logic section of the dual-path comparison results, each composed of edge-triggered data flip-flops. When the first co-matching identifier is generated, it appears as a logic level on the output pin. The input control logic of the dual-path comparison results combinational logic section detects the valid signal of the first co-matching identifier and generates a write enable pulse for the first state buffer. Under the action of this pulse, the logic level of the first co-matching identifier is latched into the flip-flops in the first state buffer, ensuring that the output of the first state buffer stably reflects this logic state. Similarly, when the second co-matching identifier is generated, the input control logic generates a write enable pulse for the second state buffer, latching the logic level of the second co-matching identifier into the flip-flops in the second state buffer. The output signals of the two state buffers will serve as the input stimulus for subsequent combinational logic.

[0076] Step S332: Perform a logical AND combination operation on the output states of the first state temporary storage area and the output states of the second state temporary storage area using the first logical AND combination element in the combinational logic part of the dual-path comparison result to generate the initial and combined output states.

[0077] Optionally, step S332 may specifically include the following steps S3321 to S3326: Step S3321: Lead out the first state signal path from the data output port of the first state temporary storage area, connect the first state signal path to the first input port of the first logic AND combination element, and set the first potential stabilizing element at the connection point to stabilize the potential level of the first state signal path.

[0078] The data output port of the first state buffer area is the positive output of the flip-flop unit. The first state signal path refers to a section of metal interconnect wire connecting this output to the first input port of the first logic AND combination element. The first potential stabilizing element is an electrostatic discharge protection and level clamping circuit composed of a reverse-biased diode structure with its source connected to the power supply and its drain grounded, or a weak pull-up or pull-down resistor. Its function is to absorb ringing and overshoot on the interconnect line when the output signal of the first state buffer area undergoes level switching, ensuring that the potential waveform reaching the input port of the first logic AND combination element has clear edges and a stable high or low level plateau, thereby preventing logic misjudgment caused by signal integrity issues.

[0079] Step S3322: Lead out the second state signal path from the data output port of the second state temporary storage area, connect the second state signal path to the second input port of the first logic AND combination element, and set a second potential stabilizing element at the connection point to stabilize the potential level of the second state signal path.

[0080] The second potential stabilizing element has the same circuit structure and working principle as the first potential stabilizing element. In this embodiment, the second potential stabilizing element is symmetrically disposed at the connection point between the output terminal of the second state temporary storage area and the second input port of the first logic AND combination element. Its function is to filter out noise coupling and ground bounce reflection on the second state signal path, ensuring that the logic level received by the second input port truly reflects the logic value stored in the second state temporary storage area.

[0081] Step S3323: In the semiconductor structure of the first logic and combination element, the potential state of the first state signal path is received through the first input stage switching element, and the potential state of the second state signal path is received through the second input stage switching element.

[0082] The first and second input-level switching elements form an input buffer stage within the first logic AND combinational element, composed of metal-oxide-semiconductor field-effect transistors. The first input port is internally connected to the gate of the first input-level switching element, whose source and drain are connected to the internal pull-up and pull-down networks of the AND gate circuit, respectively. When a high-level state is received from the first state signal path, the first input-level switching element is turned on, changing the internal node charge distribution; when a low-level state is received, the first input-level switching element is turned off. The second input-level switching element responds to the potential state of the second state signal path in exactly the same way. The on / off states of the two input-level switching elements together determine the connection relationship of the series and parallel paths within the first logic AND combinational element.

[0083] Step S3324: Based on the series conduction characteristics of the first input stage switching element and the second input stage switching element, when the first state signal path and the second state signal path are both in a high potential state, the intermediate node potential state of the first logic AND combination element is driven to flip.

[0084] The pull-down network within the first logic and combinational element consists of a first input stage switching element and a second input stage switching element connected in series, while the pull-up network consists of corresponding parallel switching elements. When both the first and second state signal paths are at a high potential, the first and second input stage switching elements are simultaneously turned on, creating a low-impedance path from the intermediate node to ground in the pull-down network. Simultaneously, the parallel switching elements in the pull-up network are turned off, cutting off the path from the power supply to the intermediate node. Because the pull-down path is on and the pull-up path is off, the charge stored at the intermediate node is rapidly discharged to ground through the pull-down path. The intermediate node potential flips from a high level close to the power supply potential to a low level close to ground potential, and after inversion by the output stage, it manifests as a logic high output.

[0085] Step S3325: Input the intermediate node potential flip signal of the first logic AND combination element to the output buffer stage of the first logic AND combination element, and enhance the driving capability of the intermediate node potential flip signal through the output buffer stage.

[0086] The intermediate node is a circuit node located at the connection point of the pull-up and pull-down networks within the first logic and combinational element. Its direct drive capability for capacitive loads is relatively weak. The output buffer stage is a drive enhancement circuit composed of one or two cascaded inverters. The potential flip signal of the intermediate node is connected to the input of the first-stage inverter in the output buffer stage. The output of the first-stage inverter drives the input of the second-stage inverter, and the output of the second-stage inverter is the final output of the first logic and combinational element. By progressively increasing the transistor channel width at each stage, the output buffer stage enables each stage to drive a larger capacitive load than the previous stage. This provides sufficient current drive capability at the final output to drive subsequent circuits or longer interconnects, ensuring steep signal edges and a complete voltage swing in the initial and combined output states.

[0087] Step S3326: Obtain the enhanced potential signal from the output port of the output buffer stage of the first logic and combination element, and output the enhanced potential signal as the initial and combined output state to the external connection port of the first logic and combination element.

[0088] The external connection port of the first logic and combinational element is its physical pad or lead-out on the integrated circuit layout that connects to the upper metal interconnect. The final output of the output buffer stage is directly connected to this external connection port via internal interconnect. The enhanced potential signal appears on the external connection port in the form of a stable logic level; this signal represents the initial and combined output state. The subsequent circuitry of the dual-path comparison result combinational logic section reads the logic level from this external connection port to determine the logic and combination result of the first and second co-matching identifiers.

[0089] Step S333: Input the initial and combined output states into the state holding part of the combinational logic part of the dual-channel comparison result, and use the state holding part to synchronize the initial and combined output states in time to generate synchronized and combined output states.

[0090] The state holding section is a sequential circuit in the combinational logic section of the dual-path comparison result used to eliminate glitches in the combinational logic output and synchronize with the system clock domain. It typically consists of an edge-triggered data flip-flop controlled by a clock signal. The initial and combinational output states arrive at the data input of the state holding section from the external connection port of the first logic and combinational element via the combinational logic transmission path. The clock input of the state holding section receives a stable periodic clock signal from the second photovoltaic platform system clock tree. At each valid edge of the system clock signal, the state holding section samples the logic level at the data input and latches the sampled level state into its internal storage node. Since the initial and combinational output states will inevitably reach stability before the next valid clock edge after a certain propagation delay, the state holding section latches a stable, glitch-free logic value at the clock edge. The output of the state holding section will maintain this latched value unchanged within the current clock cycle, thereby generating a synchronized and combinational output state strictly synchronized with the system clock, which is then provided for subsequent processing.

[0091] Step S334: Input the synchronization and combinational output states to the waveform shaping section of the combinational logic part of the dual-channel comparison result. The waveform shaping section performs waveform regularization on the synchronization and combinational output states to eliminate state jitter interference in the synchronization and combinational output states.

[0092] The waveform shaping section is a set of buffering and shaping circuits used to filter out residual high-frequency noise on the signal and eliminate the risk of metastability propagation. It can be composed of two stages of Schmitt triggers connected in series. After the synchronous and combined output state is output from the state holding section, it first enters the first stage of the waveform shaping section's Schmitt trigger before being transmitted to the subsequent output driving section. The Schmitt trigger has an input voltage hysteresis characteristic, and its positive switching threshold voltage is higher than its negative switching threshold voltage. When the input signal transitions from low to high, the higher positive switching threshold voltage must be exceeded for the output to switch; when the input signal transitions from high to low, the lower negative switching threshold voltage must be exceeded for the output to switch back. This characteristic prevents small-amplitude state jitter interference superimposed on the signal edge from causing incorrect logic switching at the output, thus effectively eliminating false transitions caused by power supply noise or ground bounce reflection. After being shaped by the first-stage Schmitt trigger, the signal enters the second-stage Schmitt trigger for further shaping, which sharpens the signal edges and enhances the driving capability, ultimately outputting a well-ordered logic signal with steep edges and a pure level.

[0093] Step S335: Input the synchronous and combined output states after waveform normalization to the output driver section of the combinational logic section of the dual-channel comparison result, and the output driver section converts the synchronous and combined output states into standard logic state signals.

[0094] The output driver section is the interface circuit within the dual-channel comparison result combinational logic section, responsible for converting internal logic signals into output signals conforming to the system bus electrical standards. The logic signals, regulated by the waveform shaping section, are connected to the input of the output driver section. The output driver section internally includes a push-pull output stage with significant current driving capability. This stage consists of a pair of complementary metal-oxide-semiconductor field-effect transistors (MOSFETs). The pull-up transistor is connected to the power supply, and the pull-down transistor is connected to ground. When the input signal is high, the pull-up transistor is on, and the pull-down transistor is off, strongly pulling the output to the power supply voltage, presenting a standard high level. When the input signal is low, the pull-up transistor is off, and the pull-down transistor is on, strongly pulling the output to ground potential, presenting a standard low level. The output driver section ensures that the voltage swing, rise and fall times, and load-carrying capacity of the output signal conform to the interface timing specifications of the subsequent coordination status register or system bus, generating standard logic status signals.

[0095] Step S336: Use the standard logic state signal as the final output of the logic AND combinational processing, and write the final output into the output temporary storage area of ​​the combinational logic part of the dual-channel comparison result.

[0096] The output result buffer is a read-only register or memory-mapped input / output register within the dual-channel comparison result combinational logic section, addressable and readable by the system bus. Standard logic status signals, after being sent from the output driver section, are connected to the data input pins of the output result buffer. After confirming that the logic and combinational processing flow has been fully executed, the control state machine of the dual-channel comparison result combinational logic section generates a write enable pulse signal, latching the current level of the standard logic status signal into the register unit of the output result buffer. Subsequently, the central processing unit of the second photovoltaic platform can obtain the final output result of the logic and combinational processing at any time by reading the address of this output result buffer. This result accurately reflects the logic and truth values ​​of the first and second cooperative comparison identifiers.

[0097] Step S340: When the result of the logical AND combination processing indicates a logical true state, generate a collaborative identifier that represents the consistency of the decryption process meeting the preset collaborative conditions, and set the status indicator of the collaborative identifier to a valid state.

[0098] The result of the logical AND combinational processing indicates a logical true state, meaning that both the hardware decryption data unit and the software decryption data unit of the current composite data entry have successfully passed their respective signature verifications, indicating that the key materials used by the two decryption channels are correct and the data has not been tampered with in any way during the decryption process. The preset coordination condition is defined as both the first and second coordination comparison identifiers being logically true. When the value stored in the output result buffer of the dual-path comparison result combinational logic part is logically true, the coordination identifier generation logic is triggered. The coordination identifier generation logic creates a coordination identifier data structure, which includes a status indicator bit field and a reserved field. The coordination identifier generation logic sets the bit value of the status indicator bit field to a pre-agreed value representing a valid state. This coordination identifier, along with its valid status indicator bit, is temporarily stored in the coordination identifier output buffer, awaiting association with the reconstructed plaintext data set.

[0099] Step S350: When the result of the logical AND combination processing indicates a logical false state, generate a collaborative identifier that represents the consistency of the decryption process does not meet the preset collaborative conditions, and set the status indicator of the collaborative identifier to an invalid state.

[0100] When either the first or second collaborative matching identifier is logically false, or both are logically false, the result of the logical AND combination process indicates a logically false state. This indicates that at least one decryption channel's signature verification has failed. Possible reasons include incorrect decryption key usage, bit errors occurring during data transmission or decryption, or malicious tampering of the ciphertext payload. In this embodiment, when the value in the output result buffer is logically false, the collaborative identifier generation logic also creates a collaborative identifier data structure, but sets the bit value of its status indicator field to a pre-agreed value indicating an invalid state. The collaborative identifier with an invalid status indicator is also temporarily stored in the collaborative identifier output buffer.

[0101] Step S360: Extract the status indication information of the collaboration identifier, and associate the status indication information of the collaboration identifier with the timestamp in the reconstructed plaintext data set for storage, thereby generating a collaboration process record with time stamp.

[0102] To persistently record the decryption collaboration results of each data interaction and support subsequent audit tracing, the status of the collaboration identifier needs to be bound to the timestamp of the corresponding data entry and stored in a non-volatile storage area. In this embodiment, the collaboration identifier is read from the collaboration identifier output buffer, and the status indicator bit information is obtained separately through bit extraction. Simultaneously, the record management logic reads the associated timestamp from the header of the currently processed composite data entry. The record management logic then requests a new log entry storage space in the system security audit log area, and sequentially writes the timestamp field, the collaboration identifier status indicator bit field, and necessary context identifier information into this storage space. After writing is complete, a collaboration process record with a time sequence mark is generated. This record is stored in the security audit log in the order of the timestamp marks, and the decryption collaboration comparison results at any historical moment can be retrieved through the query interface, providing a complete time-series evidence chain for the security audit of photovoltaic dual-platform data interaction.

[0103] Step S400: When the consistency of the decryption process indicated by the collaborative identifier meets the preset collaborative conditions, the platform data parsing is performed on the recombined plaintext data set. The photovoltaic module operation status record information of the first photovoltaic platform is extracted from the hardware decryption data unit, and the photovoltaic module configuration description information of the first photovoltaic platform is extracted from the software decryption data unit. The photovoltaic module operation status record information and the photovoltaic module configuration description information are time-aligned and merged according to the timestamp mark to generate a fused data description set with a unified time series benchmark.

[0104] Optionally, step S400 may specifically include the following steps S410 to S460: Step S410: When the status indicator bit of the collaborative identifier is detected to be in a valid state, the platform data parsing and processing flow for reconstructing plaintext data set is initiated.

[0105] The data fusion scheduler of the second photovoltaic platform contains a cooperative identifier monitoring logic, which continuously monitors the output cooperative identifier through polling or interruption. The cooperative identifier is mapped to a specific memory-mapped input / output address space accessible by the data fusion scheduler. The cooperative identifier monitoring logic periodically reads the cooperative identifier status word in this address space and extracts the value of the bit containing the status indicator. When the extracted bit value matches a preset valid status representative value, the cooperative identifier monitoring logic confirms that the consistency of the current decryption process has been verified. At this point, the monitoring logic sends a platform data parsing start event signal to the main control state machine of the data fusion scheduler. Upon receiving this event signal, the main control state machine transitions from the idle state to the parsing preparation state, initializes the memory buffer, temporary table data structure, and various parsing pointers required for parsing, thereby formally starting the platform data parsing processing flow for reconstructing the plaintext data set.

[0106] Step S420: Parse the header area of ​​the data structure of the hardware decryption data unit to obtain the storage start offset address and storage length of the photovoltaic module operation status record information, and extract the corresponding byte fragments from the hardware decryption data unit according to the storage start offset address and storage length, and use the extracted byte fragments as the photovoltaic module operation status record information.

[0107] The header area of ​​the data structure of the hardware decryption data unit is a fixed-length or variable-length descriptive byte sequence at the very beginning, which is organized using type-length value encoding or key-value pair encoding.

[0108] The hardware data parsing logic of the data fusion scheduler begins reading the header region from the base address of the hardware decrypted data unit. The first field in the header region is the total header length field; after reading this field, the hardware data parsing logic determines the total number of bytes in the header region. Subsequently, the hardware data parsing logic enters a tag parsing loop, scanning the header region byte by byte, and identifying the type of field being parsed based on predefined tag values. When the parsing logic identifies a tag corresponding to the starting offset address of the photovoltaic module operating status record information storage, it immediately reads the following length value field and numeric field, interpreting the numeric field as an unsigned integer representing the storage starting offset address.

[0109] When a tag corresponding to the storage length is identified, its numerical field is read and interpreted as the storage length. After successfully resolving the storage start offset address and storage length, the hardware data parsing logic calculates the sum of the hardware decryption data unit base address and the storage start offset address to obtain the precise starting position of the operating status record information. Then, starting from this starting position, a continuous byte sequence with a length equal to the storage length is read and copied verbatim into the newly allocated operating status record buffer. The byte fragments in this buffer are the original binary representation of the photovoltaic module operating status record information. The hardware data parsing logic records the pointer and length of this buffer in a new entry in the operating status temporary table and associates it with the timestamp of the current hardware decryption data unit.

[0110] Step S430: Parse the header area of ​​the data structure of the software decryption data unit, obtain the storage start offset address and storage length of the photovoltaic module configuration description information, and extract the corresponding byte fragments from the software decryption data unit according to the storage start offset address and storage length, and use the extracted byte fragments as the photovoltaic module configuration description information.

[0111] The header area of ​​the software-decrypted data unit uses the same encoding convention as the hardware-decrypted data unit to ensure consistency in the parsing logic. The software data parsing logic of the data fusion scheduler parses the software-decrypted data unit in the same way. The software data parsing logic reads the total length field of the header, enters the tag parsing loop, sequentially identifies the tags representing the starting offset address and storage length of the photovoltaic module configuration description information, and extracts the corresponding numerical fields. After obtaining the starting offset address and storage length, the software data parsing logic locates the starting byte of the configuration description information, extracts a byte sequence of a specified length, and copies this byte sequence as the photovoltaic module configuration description information into the configuration description buffer. Subsequently, the software data parsing logic records the pointer, length, and timestamp of the current software-decrypted data unit in a new entry of the configuration description temporary table.

[0112] Step S440: Extract the associated timestamp sequence from the reconstructed plaintext data set and use the timestamp sequence as a unified time series reference.

[0113] Each composite data entry in the reconstructed plaintext data set is uniquely associated with a timestamp, which has been bound to the hardware decryption data unit and the software decryption data unit during the splicing process in step S260. The timing benchmark construction logic of the data fusion scheduler traverses all composite data entries in the reconstructed plaintext data set, extracting the timestamp field from the header of each entry. The timing benchmark construction logic stores all extracted timestamps into a temporary sorted array. To avoid duplicate timestamps and ensure the monotonicity of the timing benchmark, the timing benchmark construction logic performs a deduplication operation on the array: sorting the timestamps in the array, then scanning the sorted array, merging adjacent duplicate timestamps into one item. The deduplicated timestamp array is copied to a read-only timing benchmark array, which serves as the unified timing benchmark for this platform data parsing. Each timestamp in the unified timing benchmark represents a timing index point in the subsequent fused data set.

[0114] Step S450: Assign a corresponding time-series index tag to each operating status record in the photovoltaic module operating status record information based on the unified time-series benchmark, and assign a corresponding time-series index tag to each configuration description record in the photovoltaic module configuration description information based on the unified time-series benchmark.

[0115] Optionally, step S450 may include the following steps S451 to S457: Step S451: Traverse all operating status records in the photovoltaic module operating status record information and obtain the generation timestamp contained in each operating status record.

[0116] The photovoltaic module's operating status record information consists of multiple independent operating status records arranged sequentially. Each operating status record has a fixed record header structure, and the generated timestamp is located at a fixed offset position in the record header. In this embodiment, the timing alignment logic first obtains the number of records in the temporary operating status table and the storage address of each record. The timing alignment logic initializes a record traversal counter and enters a loop for processing. In each loop iteration, the timing alignment logic reads the binary value of the generated timestamp field based on the storage address of the current record, adds the fixed offset of the generated timestamp in the record header, and converts it into a comparable time description, which can be the number of seconds or milliseconds since the epoch. The read generated timestamp is temporarily stored in a local variable and passed to subsequent timing matching steps along with other information of the operating status record.

[0117] Step S452: For each time stamp in the unified time series benchmark and the time stamp of the generation timestamp of each running status record, select the time stamp that is closest to the generation timestamp in time series as the target time series index mark corresponding to the running status record.

[0118] Optionally, step S452 may specifically include the following steps S4521 to S4527: Step S4521: Extract the first time descriptor of the generation timestamp of the current running status record, and extract the second time descriptor of any time stamp in the unified time series reference.

[0119] Both the first-time descriptor and the second-time descriptor use the same data type and precision, such as a 64-bit unsigned integer representing the number of milliseconds elapsed since a preset epoch. In this embodiment, the timing alignment logic directly reads this 64-bit integer from the generation timestamp field of the current running state record and assigns it to the first-time descriptor variable. Subsequently, the timing alignment logic accesses the unified timing reference array through array indexing, reads the value of the zeroth element in the array, which is also a 64-bit unsigned integer, and assigns it to the second-time descriptor variable as input data for subsequent timing offset calculations.

[0120] Step S4522: Input the first time-descriptor and the second time-descriptor into the timing proximity analysis section, and obtain the timing offset between the first time-descriptor and the second time-descriptor through the timing comparison element in the timing proximity analysis section.

[0121] The timing proximity analysis section is a dedicated computational logic segment within the timing alignment logic, with the timing comparison element being the core computational unit within this section. In this embodiment, the timing comparison element first compares the magnitudes of the first and second timing descriptors. If the first timing descriptor is greater than or equal to the second timing descriptor, the timing comparison element subtracts the second timing descriptor from the first timing descriptor, and the difference is used as the timing offset; if the first timing descriptor is less than the second timing descriptor, the timing comparison element subtracts the first timing descriptor from the second timing descriptor, and the difference is used as the timing offset. This subtraction operation is performed by the arithmetic logic unit of the central processing unit, and the difference result is a non-negative integer, representing the absolute distance between the two timing descriptors on the time axis.

[0122] Step S4523: Associate and store the acquired time offset with the current running status record and any time marker to generate a temporary time proximity record.

[0123] To ensure that the time stamp corresponding to the timing offset can be traced back during subsequent selection of the minimum offset, the timing offset needs to be bound and stored with its source time stamp. In this embodiment, the timing alignment logic defines a temporary structure in memory. This structure contains three members: a pointer to the current running state record, a 64-bit integer variable storing the time stamp, and a 64-bit integer variable storing the timing offset. The timing alignment logic fills the pointer member with the address of the current running state record, the time stamp member with the currently traversed time stamp, and the timing offset member with the calculated timing offset. This structure instance is a temporary timing proximity record, which is appended to the end of a temporary dynamic array.

[0124] Step S4524: Repeat the process of extracting the first time descriptor, extracting the second time descriptor, and obtaining the time offset for all time markers in the unified time series reference to generate a temporary time series proximity record set corresponding to all time markers.

[0125] The timing alignment logic maintains a loop, with the loop variable incrementing from zero to the length of the unified timing reference array minus one. In each loop iteration, the timing alignment logic extracts the next time marker from the unified timing reference array as the new second time-time descriptor, and repeats the processes of calculating the timing offset in step S4522 and generating temporary timing proximity records in step S4523. When the loop ends, the temporary dynamic array contains a number of temporary timing proximity records equal to the length of the unified timing reference array; this dynamic array constitutes the set of temporary timing proximity records.

[0126] Step S4525: Input the temporary time series proximity record set into the minimum time series offset filtering part. The minimum time series offset filtering part performs pairwise comparison of the time series offsets in the temporary time series proximity record set and gradually eliminates temporary time series proximity records with larger time series offsets.

[0127] The minimum timing offset filtering section is the logical unit in the timing alignment logic responsible for finding the minimum value and its associated data from a set of candidates. In this embodiment, the minimum timing offset filtering section first takes the first record in the temporary timing proximity record set as the current candidate minimum record. Then, starting from the second record in the set, the minimum timing offset filtering section reads each record sequentially, comparing the timing offset of the read record with the timing offset of the current candidate minimum record. If the timing offset of the read record is less than the timing offset of the candidate minimum record, the minimum timing offset filtering section eliminates the current candidate minimum record and promotes the read record to the new candidate minimum record; if the timing offset of the read record is greater than or equal to the timing offset of the candidate minimum record, the candidate minimum record remains unchanged. This process continues until all records in the set have been traversed and compared with the candidate minimum record at least once.

[0128] Step S4526: After multi-level comparison operations, retain the temporary time proximity record with the smallest time offset, and extract the associated time stamp in the temporary time proximity record.

[0129] After the minimum timing offset filtering section completes a full traversal of the temporary timing proximity record set, the last candidate record retained is the temporary timing proximity record with the smallest timing offset value in the entire set. The minimum timing offset filtering section returns the address of this record to the timing alignment logic. The timing alignment logic accesses the timestamp member of the structure through this address and reads the 64-bit integer value of this member. This value is the timestamp that is most timing-close to the generation timestamp of the current running state record.

[0130] Step S4527: Use the extracted time stamp as the target time series index stamp corresponding to the running status record, and bind and store the target time series index stamp with the running status record.

[0131] The timing alignment logic assigns the timestamp value extracted in step S4526 to a variable named the target timing index tag. Subsequently, the timing alignment logic creates a new key-value pair entry in the runtime record timing index mapping table, where the key field is filled with the target timing index tag, and the value field is filled with the index number or memory address of the current runtime record in the runtime temporary table. Through this write operation, the binding relationship between the target timing index tag and the runtime record is persistently stored in the mapping table data structure.

[0132] Step S453: Establish the first association between the running status record and the target time-series index mark, and store the first association in the running status record time-series index mapping table.

[0133] The first association refers to the association structure in the runtime record time-series index mapping table that allows for quick retrieval of one or more corresponding runtime records using the target time-series index marker as the index. In this embodiment, the runtime record time-series index mapping table is implemented in memory as a hash table or a balanced binary search tree structure. When step S4527 is executed, the time-series alignment logic calls the insertion interface of the mapping table, using the target time-series index marker as the key and the storage pointer of the runtime record as the value, to perform an insertion operation. If an entry with the same key already exists in the mapping table, the insertion interface, according to a predefined multi-record conflict resolution strategy, such as expanding the value field into a linked list or dynamic array, appends the new runtime record pointer to the value container corresponding to the key, thereby completely preserving multiple runtime records that may exist under the same time marker.

[0134] Step S454: Traverse all configuration description records in the photovoltaic module configuration description information and obtain the update effective timestamp contained in each configuration description record.

[0135] The photovoltaic module configuration description information consists of multiple configuration description records. Each configuration description record also has a record header with a fixed format. The update effective timestamp is located at a fixed offset position in the record header, indicating the precise time when the configuration parameter begins to take effect. In this embodiment, the timing alignment logic adopts the same mechanism as traversing the running status records, obtaining the number and storage address of records in the configuration description temporary table, and reading the update effective timestamp field in the header of each configuration description record one by one, converting it into a time description format. Each obtained update effective timestamp is temporarily stored for subsequent matching operations with a unified timing benchmark.

[0136] Step S455: For each configuration description record, select the time stamp that is closest in time sequence to the update effective timestamp and each time stamp in the unified time series benchmark.

[0137] For each configuration description record, the timing alignment logic extracts the timing description value of its update effective timestamp. Then, it iterates through each timestamp in the unified timing benchmark array, calculates the timing offset, constructs a temporary timing proximity record set, and uses the minimum timing offset filtering part to find the temporary timing proximity record with the smallest timing offset. The timestamp in this record is then extracted as the target timing index mark. The entire process ensures that the runtime status record and the configuration description record use the same timing alignment criteria.

[0138] Step S456: Establish a second association between the configuration description record and the target time-series index tag, and store the second association in the configuration description record time-series index mapping table.

[0139] The second association pointer relationship maintains symmetry with the first association pointer relationship in terms of data structure and storage mechanism. In this embodiment, the timing alignment logic creates or reuses another hash table or balanced binary search tree as the timing index mapping table for configuration description records. For each configuration description record that has completed timing matching, the timing alignment logic uses the selected target timing index tag as the key and the storage pointer of the configuration description record in the configuration description temporary table as the value, and calls the mapping table insertion interface to complete the storage. If a key conflict occurs, multiple records under the same key are aggregated using a linked list or dynamic array.

[0140] Step S457: Output the time-series index mapping table of the running status record and the time-series index mapping table of the configuration description record together as the result of time-series index allocation, and complete the time-series index allocation operation for the running status record and the configuration description record.

[0141] After traversing and processing all runtime status records and configuration description records, the runtime status record time-series index mapping table and the configuration description record time-series index mapping table are fully constructed. The timing alignment logic encapsulates the memory base address of these two mapping tables and the element counts within the tables into a timing index allocation result description block. The timing alignment logic passes a pointer to this description block to the main control state machine of the data fusion scheduler and returns an operation completion status code. At this point, the timing index tag allocation operation based on the unified timing benchmark is complete.

[0142] Step S460: Merge the running status records and configuration description records with the same time-series index mark into data units, generate a fused data unit corresponding to each time-series index mark, and combine all the fused data units corresponding to the time-series index marks into a fused data description set.

[0143] Data unit merging refers to extracting the associated runtime status record and configuration description record content for each time stamp appearing in the unified time series benchmark and merging them to form a new data unit with complete information. The merging logic of the data fusion scheduler first obtains the unified time series benchmark array and the two mapping tables output in step S457. The merging logic traverses each time stamp in the unified time series benchmark array. For the currently traversed time stamp, the merging logic searches for the runtime status record time series index mapping table and the configuration description record time series index mapping table using the time stamp as the key. If the corresponding entry is found in the runtime status record time series index mapping table, the merging logic reads the complete content of the runtime status record according to the storage pointer in the entry; if not found, the runtime status part is set to empty or filled with a default value. Similarly, the merging logic searches for and reads the corresponding configuration description record content in the configuration description record time series index mapping table. The merging logic then creates a new fused data unit structure, which contains three main blocks: a time series index block, a runtime status data block, and a configuration description data block. The merge logic fills the time series index block with the current timestamp, the runtime data block with the content read from the runtime status record, and the configuration description data block with the content read from the configuration description record. This completed fused data unit is appended to the end of a dynamic result array. Once the unified time series reference array has been traversed, the dynamic result array contains all generated fused data units arranged in ascending order of timestamp. The merge logic encapsulates this dynamic result array and its length information into a data set descriptor; the entire set of data pointed to by this descriptor constitutes the fused data description set.

[0144] Step S500: Push the fused data description set to the built-in parsing interface of the second photovoltaic platform, and convert the format of the fused data description set according to the data protocol specification of the second photovoltaic platform during the push process to generate a target interactive data set that is compatible with the data receiving structure of the second photovoltaic platform.

[0145] Optionally, step S500 may specifically include the following steps S510 to S570: Step S510: Obtain the interface address descriptor of the pre-registered built-in parsing interface of the second photovoltaic platform, and establish a data transmission path between the second photovoltaic platform and the second photovoltaic platform based on the interface address descriptor.

[0146] The interface address descriptor is a structured data object containing all the addressing information needed to locate the built-in parsing interface of the second photovoltaic platform. During system initialization, the second photovoltaic platform calls the service registration function to write the communication endpoint information of the built-in parsing interface into the system's global service discovery table. When data needs to be pushed, the service discovery client queries this global service discovery table to retrieve the service name corresponding to the built-in parsing interface and obtains a copy of its registered interface address descriptor. The address family type field in the interface address descriptor indicates the communication domain type, such as a network domain or a local inter-process communication domain. If it is a network domain, the interface address descriptor also contains the Internet Protocol address and transport layer port number; if it is a local inter-process communication domain, it contains a queue identifier or shared memory path. Based on the value of the address family type field, the corresponding communication protocol stack is selected, and the endpoint creation and connection functions of that protocol stack are called, passing the target address in the interface address descriptor as a connection parameter. The communication protocol stack executes the connection establishment handshake process specified by the protocol. After a successful handshake, it returns a handle or file descriptor representing an established data transmission path. This handle is saved, and subsequent data transmission operations are performed through this handle.

[0147] Step S520: Read the data protocol specification description file of the second photovoltaic platform, and extract the frame header construction definition information, data payload encoding method definition information, and frame trailer additional information definition information of the data frame from the data protocol specification description file.

[0148] The data protocol specification description file is a structured text document or binary configuration file stored on the non-volatile storage medium of the second photovoltaic platform. In this embodiment, the description file adopts a custom format combining key-value pairs and nested blocks. At startup or before the first data push, the entire contents of the description file are opened and read into a memory buffer via the file system interface. The protocol loader internally includes a lexical analyzer and a syntax analyzer. The lexical analyzer segments the file content into a stream of tags, values, and delimiters, while the syntax analyzer parses the token stream according to predefined grammar rules. When the syntax analyzer identifies a frame header construction definition block, it extracts the byte sequence literal value of the start-of-frame identifier and the bit-width enumeration value and byte order enumeration value of the data frame length indicator, storing these values ​​as frame header construction definition information. When it identifies a data payload encoding mode definition block, it extracts the encoding mode type identifier, which points to a specific serialization encoding rule. When it identifies a frame tail append information definition block, it extracts the append information generation mode type identifier and the append information field length value, storing these values ​​as frame tail append information definition information. The three extracted definition information items are encapsulated in a protocol specification runtime object for use in subsequent format conversion steps.

[0149] Step S530: Based on the frame header construction definition information, encapsulate the fused data description set with a data frame header, and add a data frame start identifier and a data frame length indicator that conform to the parsing rules of the second photovoltaic platform to the fused data description set.

[0150] The data frame header encapsulation operation inserts a control information segment before each data segment of the merged data description set. First, the start-of-frame identifier, a fixed-length byte array, is read from the protocol specification runtime object. The frame encapsulator writes all bytes of this byte array verbatim to the beginning of the target transmit buffer. Next, the frame encapsulator calculates and fills the data frame length indicator. The data frame length indicator represents the total number of bytes in the entire data payload from the frame header to the frame tail. The frame encapsulator obtains the byte length of the current data segment to be transmitted and reads the bit width information of the length indicator from the protocol specification runtime object. If the bit width is two bytes, the frame encapsulator converts the length value into a 16-bit unsigned integer; if the bit width is four bytes, it converts it into a 32-bit unsigned integer. Subsequently, the frame encapsulator adjusts the memory representation of this integer according to the byte order information: if the byte order is big-endian, the most significant byte of the integer is stored at the low address of the length indicator field; if the byte order is little-endian, the least significant byte is stored at the low address. The frame wrapper writes the length indicator binary sequence, adjusted for byte order, immediately after the start-of-data-frame identifier into the send buffer.

[0151] Step S540: Based on the encoding method definition information of the data payload, the encoding form of the data payload part in the fused data description set is converted into the target data representation form that can be recognized by the second photovoltaic platform.

[0152] The fused data description set may exist in memory as a native data structure of the host platform, while the built-in parsing interface of the second photovoltaic platform may require the data payload to use a specific platform-independent encoding format. In this embodiment, the encoding converter reads the encoding method type identifier from the protocol specification runtime object. This identifier indicates that the target encoding format is a distinguishing encoding rule of Abstract Syntax Notation 1. The encoding converter loads the corresponding encoding engine. The encoding engine traverses each fused data unit in the current data segment of the fused data description set and encodes each data field according to the predefined abstract syntax markers. For integer fields, the encoding engine converts them into variable-length integer representations. Specifically, the integer value is divided into multiple bytes in groups of seven bits from low to high, with the highest bit of each byte serving as a continuation flag. If there are subsequent bytes, this flag is set, and the flag of the last byte is cleared. For string or byte sequence fields, the encoding engine appends a length prefix before the content, and the length prefix itself also uses variable-length integer encoding. For nested structures, the encoding engine recursively encodes each of its member fields. After the above encoding operations, the internal data representation, which might have contained memory alignment padding and pointer references, is converted into a compact, platform-independent linear byte sequence, which is the target data representation recognizable by the second photovoltaic platform. The encoder-converter writes this linear byte sequence into the payload area following the data frame length indicator in the transmit buffer.

[0153] Step S550: Based on the frame tail append information definition information, perform overall append information generation on the data payload part after encoding form conversion, as well as the data frame start identifier and data frame length indicator, to generate a data frame tail append information field for integrity verification by the data receiving side.

[0154] Optionally, step S550 may include the following steps S551 to S556: Step S551: Extract the additional information generation method type identifier from the frame tail additional information definition information, and select the corresponding additional information generation logic entry from the preset additional information generation method set according to the additional information generation method type identifier.

[0155] The preset set of additional information generation methods is an internal function pointer table or policy object registry. This table stores the entry address of the corresponding additional information generation logic, indexed by the additional information generation method type identifier. The additional information generator reads the value of the additional information generation method type identifier. For example, the value might be one, indicating cyclic redundancy check; two, indicating modulo-sum check; and three, indicating a cryptographic hash function. Using this value as an index, the additional information generator searches for the corresponding entry in the preset additional information generation method set array. If the index value is within the valid range of the array, the additional information generator reads the function pointer stored in that entry, which points to the entry point of the additional information generation logic. The additional information generator saves this function pointer for subsequent calls.

[0156] Step S552: Store the byte sequence corresponding to the start identifier of the data frame, the byte sequence corresponding to the length indicator of the data frame, and the byte sequence corresponding to the data payload part after encoding conversion into the data buffer to be processed in the order of generation.

[0157] The data buffer to be processed is a contiguous array of bytes allocated in memory. The append information generator first determines the starting address and length of the start-of-frame identifier byte sequence in the transmit buffer, and then calls a memory copy function to copy this segment of bytes to the beginning of the data buffer to be processed. Next, the append information generator determines the starting address and length of the data frame length indicator byte sequence and copies it to the address in the data buffer immediately following the start-of-frame identifier. Finally, the append information generator determines the starting address and length of the data payload byte sequence after encoding conversion and copies it to the address in the data buffer immediately following the data frame length indicator. After copying, the data buffer to be processed contains a complete and contiguous byte sequence whose order perfectly matches the order in which the data frame appears on the physical link.

[0158] Step S553: ​​Call the additional information generation logic pointed to by the additional information generation logic entry point, and pass the starting address of the data buffer to be processed and the total length of the data as the input content of the additional information generation logic to the additional information generation logic.

[0159] The additional information generator initiates a function call using the function pointer saved in step S551. Before the call, the additional information generator loads the starting address of the data buffer to be processed into the first parameter register or stack location of the calling convention, and loads the total length of the data buffer to be processed into the second parameter register or stack location. Subsequently, the additional information generator executes the call instruction, and the program execution flow jumps to the first address of the code segment pointed to by the additional information generation logic entry point. The additional information generation logic thus gains complete access to the input data.

[0160] Step S554: Inside the additional information generation logic, starting from the starting address of the data buffer to be processed, read the data content in the data buffer to be processed byte by byte, and perform iterative mixing and transformation processing on each byte of data read and the additional information state variable.

[0161] The supplementary information state variable is an unsigned integer register variable maintained internally by the supplementary information generation logic. Its width is the same as the length of the supplementary information field specified in the frame tail supplementary information definition. When the supplementary information generation logic is a cyclic redundancy check (CRC) check, the initial value of the supplementary information state variable is preset to all ones or all zeros. The supplementary information generation logic uses a loop structure, with a loop counter incrementing from zero to the total data length minus one. In each loop iteration, the supplementary information generation logic reads one byte of data from the data buffer to be processed, using the starting address plus the current loop counter value as the read address. The read byte of data is then iteratively mixed and transformed with the supplementary information state variable: First, the byte of data is XORed with the high byte of the supplementary information state variable to obtain an intermediate index value; then, using this intermediate index value as an offset, the corresponding transformation value is searched in a pre-calculated lookup table array; next, the supplementary information state variable is shifted left by one byte, and the vacated low byte is cleared; finally, the found transformation value is XORed with the shifted supplementary information state variable, and the XOR result is used to update the supplementary information state variable. This process non-linearly mixes the information from each input byte into the state variables.

[0162] Step S555: After traversing all bytes of data in the data buffer to be processed, perform final morphological adjustment on the additional information status variable to compress the bit width of the additional information status variable to be consistent with the length of the additional information field specified by the frame tail additional information definition information.

[0163] Optionally, step S555 may include the following steps S5551 to S5556: Step S5551: When it is detected that the data read pointer of the data buffer to be processed has pointed to the end address of the buffer, read all the bit-width data content in the temporary storage area of ​​the current additional information status variable.

[0164] The data read pointer is an address index variable that increments continuously during the loop iteration. In this embodiment, the additional information generation logic compares the data read pointer with the end address of the data buffer to be processed at the end of each loop iteration. When they are equal, the additional information generation logic triggers a traversal completion signal. In response to this signal, the additional information generation logic accesses the temporary storage area for additional information status variables. This temporary storage area is a general-purpose register or memory variable inside the central processing unit, and its bit width is typically 32 bits or 64 bits. The additional information generation logic reads all the bit-width data content in the temporary storage area into a temporary wide-bit variable.

[0165] Step S5552: Input all bit-width data content to the first input port of the bit-width adjustment logic section, and simultaneously input the bit-width mask data content corresponding to the length of the additional information field specified in the frame tail additional information definition information to the second input port of the bit-width adjustment logic section.

[0166] The bit-width adjustment logic is a submodule within the additional information generation logic responsible for bit truncation and compression of the data. The first and second input ports are the two data input interfaces of this submodule. In this embodiment, the additional information generation logic transmits all the read bit-width data to the first input port. Simultaneously, the additional information generation logic constructs the bit-width mask data content according to the length of the additional information field specified in the frame tail additional information definition. If the additional information field length is one byte, the bit-width mask data content is an integer value with the lower eight bits all one and the remaining bits all zero; if it is two bytes, it is an integer value with the lower sixteen bits all one. This bit-width mask data content is then transmitted to the second input port.

[0167] Step S5553: Perform a bitwise AND operation on all bit-width data content and bit-width masking data content using the bit-width adjustment logic section's bit-width AND gate combination array, masking the high-order bits of all bit-width data content that exceed the length of the additional information field, and retaining the low-order bits that are the same length as the additional information field, to generate the first adjusted data content.

[0168] The bitwise AND gate combinational array is a combinational logic unit that implements the bit-masking function in the bit-width adjustment logic section. In this embodiment, the array performs a logical AND operation on each bit of the first input port and the corresponding bit of the second input port. Since bits within the length of the additional information field of the bit-width masked data content are logic 1s and bits outside the range are logic 0s, the result of the logical AND operation is that the bits corresponding to the masked logic 1 positions in the entire bit-width data content remain unchanged, while the bits corresponding to the masked logic 0 positions are forcibly cleared to zero. Thus, the high-order excess parts are masked, and only the low-order valid bit segments equal in length to the additional information field are retained. The result of this operation is the first adjusted data content.

[0169] Step S5554: Input all bit-width data content into the loop remainder compression part of the bit-width adjustment logic part, and perform polynomial division transformation on all bit-width data content through the loop remainder compression part to generate the second adjusted data content with the same length as the additional information field.

[0170] The cyclic remainder compression section is a hardware or software computation unit within the bit-width adjustment logic that provides an alternative bit-width compression strategy. When data needs to be compressed to produce a shorter summary with good distribution characteristics, polynomial division can be used. The cyclic remainder compression section internally implements a linear feedback shift register logic. It treats the entire bit-width data content as the coefficients of a high-order polynomial with the most significant bit first, and performs a modulo-2 division operation on this polynomial with a preset generator polynomial. For example, the entire bit-width data content is shifted into the linear feedback shift register bit by bit from most significant bit to least significant bit. Whenever a shifted-in bit differs from the most significant bit of the linear feedback shift register, the register performs a feedback operation, XORing its current state with the binary vector corresponding to the generator polynomial. After all data bits have been shifted in and processed, the remainder remaining in the linear feedback shift register is the result of the polynomial division transformation. The bit width of this remainder is determined by the order of the generator polynomial, which is chosen to match the length of the additional information field; therefore, the generated remainder naturally has the required length. The remainder is the second adjusted data content.

[0171] Step S5555: Input the first adjusted data content and the second adjusted data content into the data selection section. The data selection section selects one of the first adjusted data content or the second adjusted data content as the final adjusted output data content according to the pre-configured adjustment strategy selection instruction.

[0172] The data selection section is a 2-to-1 multiplexer. The pre-configured adjustment strategy selection indicator is implicitly determined by the appended information generation method type identifier in the frame tail appended information definition information. When the generation method is cyclic redundancy check, the adjustment strategy selection indicator specifies the selection of the first adjusted data content; when the generation method is a specific hash compression, it specifies the selection of the second adjusted data content. The data selection section reads this adjustment strategy selection indicator. If the indicator selects the first adjusted data content, it connects the signal at the first input terminal to the output terminal; if the indicator selects the second adjusted data content, it connects the signal at the second input terminal to the output terminal. The signal at the output terminal is the final adjusted output data content.

[0173] Step S5556: Write the final adjusted output data content into the additional information field output buffer, and output the data content in the additional information field output buffer as the data frame tail additional information field.

[0174] The supplementary information field output buffer is a local variable or register used by the supplementary information generation logic to temporarily store the checksum data to be written to the end of the frame. In this embodiment, the output of the data selection portion is assigned to this buffer. The supplementary information generation logic then writes the value in the buffer, according to the byte order and bit width required by the frame supplementary information definition, into the end of the encoded data payload in the transmit buffer in binary form. The written byte sequence is the formal data frame supplementary information field, completing the entire process of supplementary information generation and output.

[0175] Step S556: Use the additional information state variable after final form adjustment as the data frame tail additional information field, and append the data frame tail additional information field to the data payload part after the encoding form conversion process.

[0176] After step S555 is completed, the additional information state variable has undergone final morphological adjustment, and its value has been converted into a binary representation that meets the length and byte order requirements. The additional information generator treats this binary representation as a whole field and directly appends it to the last byte of the encoded data payload in the transmit buffer via a memory copy operation. At this point, the transmit buffer sequentially stores the data frame start identifier, data frame length indicator, encoded data payload, and data frame tail additional information field, constituting the complete content of a data frame.

[0177] Step S560: Sequentially concatenate the data frame start identifier, data frame length indicator, data payload portion after encoding conversion, and data frame tail additional information field to generate the target interactive data frame unit.

[0178] In this embodiment, sequential splicing does not refer to physically copying and moving data again, but rather to logically confirming that the four parts are stored consecutively in the transmission buffer in the correct order. The frame assembler checks the consistency of the pointers and lengths of each part in the transmission buffer: the data frame start identifier pointer points to the beginning of the transmission buffer, the data frame length indicator pointer equals the start pointer plus the length of the frame start identifier, the data payload pointer equals the length indicator pointer plus the width of the length indicator field, and the data frame tail append information field pointer equals the data payload pointer plus the data payload length. When these pointer relationships are verified to be correct, the frame assembler treats this contiguous memory region as a whole and describes it as a target interactive data frame unit. The description information of this frame unit includes the buffer start address and the total frame length, which equals the sum of the data frame start identifier length, the data frame length indicator width, the data payload length, and the length of the data frame tail append information field.

[0179] Step S570: Push the target interactive data frame unit to the built-in parsing interface of the second photovoltaic platform through the data transmission path to complete the generation and push operation of the target interactive data set.

[0180] Obtain the buffer start address and total frame length of the target interactive data frame unit generated in step S560, and pass these two parameters as arguments to the data transmission function. If the data transmission path is a network socket, call the network transmission interface function, which copies the data of the specified length from the buffer to the socket transmission queue, where the transport layer protocol is responsible for packet segmentation and physical transmission. If the data transmission path is a local inter-process communication queue, call the queue transmission interface function to push the data frame as a complete message into the message queue. After the transmission operation is completed, the built-in parsing interface of the second photovoltaic platform is awakened or triggered, reads the data frame from its corresponding receiving endpoint, performs frame synchronization header matching, length verification, frame tail append information verification, and payload decoding according to the same data protocol specifications, and finally delivers the restored fused data content to the business processing logic of the second photovoltaic platform. At this point, a complete data push and receive process of the photovoltaic dual-platform data interaction method based on hardware and software encryption collaboration is completed, and the generation and push operation of the target interactive data set is successfully completed.

[0181] Figure 2 This is a schematic diagram of the hardware entity of a photovoltaic platform provided in an embodiment of the present invention, such as... Figure 2 As shown, the hardware entity of the photovoltaic platform 1000 includes a processor 1001 and a memory 1002, wherein the memory 1002 stores a computer program that can run on the processor 1001, and the processor 1001 executes the program to implement the steps in the method of any of the above embodiments.

[0182] The memory 1002 stores computer programs that can run on the processor. The memory 1002 is configured to store instructions and applications that can be executed by the processor 1001. It can also cache data to be processed or already processed (e.g., image data, audio data, voice communication data, and video communication data) of the processor 1001 and various modules in the photovoltaic platform 1000. It can be implemented by flash memory or random access memory (RAM).

[0183] When the processor 1001 executes the program, it implements any of the steps of the above-mentioned method for data interaction between photovoltaic dual platforms based on hardware and software encryption. The processor 1001 typically controls the overall operation of the photovoltaic platform 1000.

[0184] This invention provides a computer storage medium storing one or more programs that can be executed by one or more processors to implement the steps of the photovoltaic dual-platform data interaction method based on software and hardware encryption collaboration as described in any of the above embodiments.

[0185] It should be noted that the descriptions of the above storage medium and device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of the present invention, please refer to the descriptions of the method embodiments of the present invention for understanding. The processor described above can be at least one of an Application Specific Integrated Circuit (ASIC), a Digital Signal Processor (DSP), a Digital Signal Processing Device (DSPD), a Programmable Logic Device (PLD), a Field Programmable Gate Array (FPGA), a Central Processing Unit (CPU), a controller, a microcontroller, and a microprocessor. It is understood that the electronic device implementing the above processor function can also be other types, and the embodiments of the present invention do not specifically limit it.

Claims

1. A photovoltaic dual-platform data interaction method based on hardware and software encryption collaboration, characterized in that, The method includes: The system receives the initial ciphertext data stream after it has been encrypted by the hardware encryption component of the first photovoltaic platform, and simultaneously performs streaming parsing on the initial ciphertext data stream to separate the first encrypted segment carrying the hardware encryption identifier and the second encrypted segment carrying the timestamp mark from the initial ciphertext data stream. The first encrypted fragment is parsed using a hardware decryption protocol corresponding to the hardware encryption component to obtain a first decrypted plaintext fragment. At the same time, a preset software encryption algorithm library is called to perform software decryption protocol parsing on the second encrypted fragment to obtain a second decrypted plaintext fragment. Based on the hardware encryption identifier and the timestamp, the first decrypted plaintext fragment and the second decrypted plaintext fragment are reassembled to generate a reassembled plaintext data set containing hardware decryption data units and software decryption data units. A decryption coordination comparison is performed on the recombined plaintext data set. The first platform signature information parsed from the hardware decryption data unit is compared with the preset hardware signature benchmark information to generate a first coordination comparison identifier. The second platform signature information parsed from the software decryption data unit is compared with the preset software signature benchmark information to generate a second coordination comparison identifier. A coordination identifier representing the consistency of the decryption process is generated based on the first coordination comparison identifier and the second coordination comparison identifier. When the coordination identifier indicates that the consistency of the decryption process meets the preset coordination conditions, the platform data parsing is performed on the recombined plaintext data set. The photovoltaic module operation status record information of the first photovoltaic platform is extracted from the hardware decryption data unit, the photovoltaic module configuration description information of the first photovoltaic platform is extracted from the software decryption data unit, and the photovoltaic module operation status record information and the photovoltaic module configuration description information are time-aligned and fused according to the timestamp mark to generate a fused data description set with a unified time series benchmark. The fused data description set is pushed to the built-in parsing interface of the second photovoltaic platform. During the push process, the fused data description set is formatted according to the data protocol specification of the second photovoltaic platform to generate a target interactive data set that is compatible with the data receiving structure of the second photovoltaic platform.

2. The method as described in claim 1, characterized in that, The first encrypted segment is parsed using a hardware decryption protocol corresponding to the hardware encryption component to obtain a first decrypted plaintext segment. Simultaneously, a pre-set software encryption algorithm library is invoked to perform software decryption protocol parsing on the second encrypted segment to obtain a second decrypted plaintext segment. Based on the hardware encryption identifier and the timestamp, the first and second decrypted plaintext segments are reassembled to generate a reassembled plaintext data set containing hardware decryption data units and software decryption data units, including: Extract the hardware key index information carried by the hardware encryption identifier in the first encrypted segment, and obtain the corresponding hardware decryption key copy from the preset hardware key management container based on the hardware key index information. The first encrypted fragment and the copy of the hardware decryption key are input together into the hardware decryption operation subunit. The hardware decryption operation subunit decrypts and restores the first encrypted fragment based on the copy of the hardware decryption key to obtain the first decrypted plaintext fragment. The first decrypted plaintext fragment is then output to the reconstruction buffer area. Extract the software encryption algorithm identifier from the second encrypted segment, and select the corresponding target software decryption logic from the preset software encryption algorithm library based on the software encryption algorithm identifier; The target software decryption logic is invoked to perform reverse parsing on the second encrypted fragment, stripping the software encryption layer from the second encrypted fragment, and outputting the plaintext data unit obtained after stripping the software encryption layer as the second decrypted plaintext fragment to the reconstructing buffer area; Extract the first decrypted plaintext fragment and the second decrypted plaintext fragment from the reconstructed buffer area, and extract the hardware encryption identifier associated with the first decrypted plaintext fragment and the software encryption algorithm identifier associated with the second decrypted plaintext fragment. The first decrypted plaintext fragment and the second decrypted plaintext fragment are concatenated according to the timestamp mark to generate the reconstructed plaintext data set, and the hardware encryption identifier and the software encryption algorithm identifier are used as additional descriptive information for the reconstructed plaintext data set.

3. The method as described in claim 2, characterized in that, The step of inputting the first encrypted fragment and the hardware decryption key copy into the hardware decryption operation subunit, decrypting and restoring the first encrypted fragment based on the hardware decryption key copy to obtain the first decrypted plaintext fragment, and outputting the first decrypted plaintext fragment to the reassembly buffer area includes: The first encrypted segment is divided into groups, and the ciphertext data stream of the first encrypted segment is divided into multiple ciphertext data groups with sequential dependencies according to the preset hardware encryption block size. The first ciphertext data block and the hardware decryption key copy are input together into the initialization vector generation part of the hardware decryption operation subunit. The initialization vector generation part iteratively transforms the first ciphertext data block and the hardware decryption key copy to generate an initialization vector for decrypting the first ciphertext data block. The initialization vector and the first ciphertext data block are input together into the decryption core logic part of the hardware decryption operation subunit. The decryption core logic part performs logical obfuscation and permutation operations on the initialization vector and the first ciphertext data block to generate the first plaintext data block. Extract the contents of the intermediate state register generated during the decryption of the first ciphertext data packet, and use the contents of the intermediate state register as the link input information for the next ciphertext data packet; The next ciphertext data group and the link input information are input together into the decryption core logic part, and the same logical obfuscation and permutation operation as the first ciphertext data group is performed to generate the next plaintext data group; Iteratively execute the extraction operation of the contents stored in the intermediate state register and the decryption operation of the next ciphertext data block until all ciphertext data blocks with sequential dependencies have been processed; All generated plaintext data groups are concatenated according to the processing order of ciphertext data groups to obtain a continuous plaintext byte sequence. The plaintext byte sequence is then output as the first decrypted plaintext fragment to the reassembly buffer area.

4. The method as described in claim 3, characterized in that, The process of inputting the initialization vector and the first ciphertext data block into the decryption core logic part of the hardware decryption operation subunit, and performing logical obfuscation and permutation operations on the initialization vector and the first ciphertext data block through the decryption core logic part to generate the first plaintext data block includes: The initialization vector and the first ciphertext data block are respectively stored in the initialization vector temporary storage area and the ciphertext data block temporary storage area of ​​the decryption core logic part; The first logical obfuscation array in the decryption core logic part performs a bitwise logical obfuscation operation on the initialization vector in the initialization vector temporary storage area and the first ciphertext data block in the ciphertext data block temporary storage area to generate an initial obfuscated byte sequence. The initial obfuscated byte sequence is input into a preset non-linear replacement table in the decryption core logic part, and the initial obfuscated byte sequence is non-linearly replaced by the preset non-linear replacement table to generate a non-linear transformed byte sequence. The nonlinear transformed byte sequence is input into the cyclic shift processing part in the decryption core logic part. The cyclic shift processing part performs a cyclic shift operation of a preset number of bits on the nonlinear transformed byte sequence to generate a shifted transformed byte sequence. The shift transformation byte sequence is input into the second logic obfuscation array in the decryption core logic part, and the shift transformation byte sequence is subjected to bitwise logic obfuscation operation with the preset round constant byte sequence to generate the first round decryption intermediate state byte sequence; The first round of decryption intermediate state byte sequence is used as the new input byte sequence. The nonlinear replacement process, the cyclic shift operation, and the round constant byte sequence logical obfuscation operation are repeatedly executed until the preset number of rounds is reached to generate the final plaintext data group. The final plaintext data packet is pushed from the output temporary storage area of ​​the decryption core logic part to the plaintext data packet cache queue as the first plaintext data packet generated.

5. The method as described in claim 1, characterized in that, The step of performing a decryption coordination comparison on the reconstructed plaintext data set includes comparing the first platform signature information parsed from the hardware decryption data unit with preset hardware signature benchmark information to generate a first coordination comparison identifier, comparing the second platform signature information parsed from the software decryption data unit with preset software signature benchmark information to generate a second coordination comparison identifier, and generating a coordination identifier representing the consistency of the decryption process based on the first coordination comparison identifier and the second coordination comparison identifier, including: The first platform signature information field at a fixed offset address is parsed from the hardware decryption data unit of the reconstructed plaintext data set, and signature feature extraction is performed on the first platform signature information field. The extracted first signature feature is compared with the benchmark signature feature in the preset hardware signature benchmark information to generate a first collaborative comparison identifier. The second platform signature information field at a fixed offset address is parsed from the software decryption data unit of the reconstructed plaintext data set, and signature feature extraction is performed on the second platform signature information field. The extracted second signature feature is compared with the benchmark signature feature in the preset software signature benchmark information to generate a second collaborative comparison identifier. The first collaborative alignment identifier and the second collaborative alignment identifier are input to the dual-path alignment result combination logic part, and the dual-path alignment result combination logic part performs logical AND combination processing on the first collaborative alignment identifier and the second collaborative alignment identifier; When the result of the logical AND combination process indicates a logical true state, a collaborative identifier is generated to represent that the consistency of the decryption process meets the preset collaborative conditions, and the state indicator of the collaborative identifier is set to a valid state. When the result of the logical AND combination process indicates a logical false state, a collaborative identifier is generated to represent that the consistency of the decryption process does not meet the preset collaborative conditions, and the state indicator of the collaborative identifier is set to an invalid state. Extract the status indication information of the collaboration identifier, and associate the status indication information of the collaboration identifier with the timestamp in the recombined plaintext data set to generate a collaboration process record with time sequence marking.

6. The method as described in claim 5, characterized in that, The step of inputting the first collaborative alignment identifier and the second collaborative alignment identifier to the dual-path alignment result combination logic part, and having the dual-path alignment result combination logic part perform a logical AND combination on the first collaborative alignment identifier and the second collaborative alignment identifier, includes: The first collaborative comparison identifier is stored in the first state temporary storage area of ​​the dual-path comparison result combination logic part, and the second collaborative comparison identifier is stored in the second state temporary storage area of ​​the dual-path comparison result combination logic part. The first logic and combination element in the dual-path comparison result combination logic part performs a logic and combination operation on the output state of the first state temporary storage area and the output state of the second state temporary storage area to generate an initial and combined output state. The initial and combined output states are input to the state holding part of the dual-path comparison result combinational logic part. The initial and combined output states are synchronized in time through the state holding part to generate synchronized and combined output states. The synchronization and combination output state is input to the waveform shaping part of the combinational logic part of the dual-path comparison result. The waveform shaping part performs waveform regularization on the synchronization and combination output state to eliminate state jitter interference in the synchronization and combination output state. The synchronous and combined output states after waveform normalization are input to the output driving part of the combinational logic part of the dual-channel comparison result, and the output driving part converts the synchronous and combined output states into standard logic state signals. The standard logic state signal is used as the final output of the logic AND combination process, and the final output is written into the output result temporary storage area of ​​the combinational logic part of the dual-path comparison result.

7. The method as described in claim 6, characterized in that, The step of performing a logical AND combination operation on the output states of the first state temporary storage area and the second state temporary storage area through the first logical AND combination element in the combinational logic part of the dual-path comparison result to generate an initial AND combination output state includes: A first state signal path is led out from the data output port of the first state temporary storage area, the first state signal path is connected to the first input port of the first logic AND combination element, and a first potential stabilizing element is set at the connection point to stabilize the potential level of the first state signal path. A second state signal path is led out from the data output port of the second state temporary storage area, and the second state signal path is connected to the second input port of the first logic AND combination element. A second potential stabilizing element is set at the connection point to stabilize the potential level of the second state signal path. In the semiconductor structure of the first logic AND combination element, the potential state of the first state signal path is received through a first input stage switching element, and the potential state of the second state signal path is received through a second input stage switching element. Based on the series conduction characteristics of the first input stage switching element and the second input stage switching element, when the first state signal path and the second state signal path are both in a high potential state, the potential state of the intermediate node of the first logic AND combination element is driven to flip. The intermediate node potential reversal signal of the first logic AND combination element is input to the output buffer stage of the first logic AND combination element, and the driving capability of the intermediate node potential reversal signal is enhanced through the output buffer stage. The enhanced potential signal is obtained from the output port of the output buffer stage of the first logic and combination element, and the enhanced potential signal is output as the initial and combined output state to the external connection port of the first logic and combination element.

8. The method according to any one of claims 1 to 7, characterized in that, When the consistency of the decryption process indicated by the collaborative identifier meets the preset collaborative conditions, platform data parsing is performed on the recombined plaintext data set. The photovoltaic module operating status record information of the first photovoltaic platform is extracted from the hardware decryption data unit, and the photovoltaic module configuration description information of the first photovoltaic platform is extracted from the software decryption data unit. Based on the timestamp, the photovoltaic module operating status record information and the photovoltaic module configuration description information are time-aligned and fused to generate a fused data description set with a unified time series benchmark, including: When the status indicator bit of the collaboration identifier is detected to be in a valid state, the platform data parsing and processing flow for the reconstructed plaintext data set is initiated. The header area of ​​the data structure of the hardware decryption data unit is parsed to obtain the storage start offset address and storage length of the photovoltaic module operation status record information. The corresponding byte fragments are extracted from the hardware decryption data unit according to the storage start offset address and storage length, and the extracted byte fragments are used as the photovoltaic module operation status record information. The header area of ​​the data structure of the software decryption data unit is parsed to obtain the storage start offset address and storage length of the photovoltaic module configuration description information. The corresponding byte fragments are extracted from the software decryption data unit according to the storage start offset address and storage length, and the extracted byte fragments are used as the photovoltaic module configuration description information. Extract the timestamp sequence associated with the reconstructed plaintext data set, and use the timestamp sequence as a unified time series reference. Based on the unified timing benchmark, a corresponding timing index tag is assigned to each operating status record in the photovoltaic module operating status record information, and a corresponding timing index tag is assigned to each configuration description record in the photovoltaic module configuration description information based on the unified timing benchmark. The running status records and configuration description records with the same time-series index mark are merged into data units to generate a fused data unit corresponding to each time-series index mark, and all fused data units corresponding to time-series index marks are combined into a fused data description set.

9. The method as described in claim 8, characterized in that, The process of assigning a corresponding time-series index tag to each operating status record in the photovoltaic module operating status record information based on the unified time-series benchmark, and assigning a corresponding time-series index tag to each configuration description record in the photovoltaic module configuration description information based on the unified time-series benchmark, includes: Traverse all operating status records in the photovoltaic module operating status record information and obtain the generation timestamp contained in each operating status record; For each running status record, the time stamp that is generated and each time mark in the unified time series reference are selected as the target time series index mark corresponding to the running status record. Establish a first association between the running status record and the target time-series index marker, and store the first association between the running status record and the time-series index mapping table; Iterate through all configuration description records in the photovoltaic module configuration description information and obtain the update effective timestamp contained in each configuration description record; For each configuration description record, the time stamp that is closest in time to the update effective time stamp is selected as the target time index mark corresponding to the configuration description record. Establish a second association between the configuration description record and the target time-series index tag, and store the second association between the configuration description record and the time-series index mapping table; The time-series index mapping table of the running status record and the time-series index mapping table of the configuration description record are used together as the result of time-series index allocation to complete the time-series index allocation operation for the running status record and the configuration description record.

10. The method as described in claim 9, characterized in that, The process of generating a timestamp for each running status record and selecting the timestamp that is most sequentially close to the generated timestamp as the target time series index mark for that running status record includes: Extract the first time-description value of the generation timestamp of the current running status record, and extract the second time-description value of any time stamp in the unified time series reference; The first time-descriptor and the second time-descriptor are input to the timing proximity analysis section, and the timing offset between the first time-descriptor and the second time-descriptor is obtained through the timing comparison element in the timing proximity analysis section. The acquired time offset is associated with the current running status record and any of the timestamps and stored to generate a temporary time proximity record. Repeat the process of extracting the first time descriptor, extracting the second time descriptor, and obtaining the time offset for all time markers in the unified time series reference to generate a temporary time series proximity record set corresponding to all time markers; The temporary time series proximity record set is input into the minimum time series offset filtering part, which performs pairwise comparison of the time series offsets in the temporary time series proximity record set and gradually eliminates temporary time series proximity records with larger time series offsets. After multiple comparison operations, the temporary time proximity record with the smallest time offset is retained, and the associated time stamps in the temporary time proximity record are extracted. The extracted timestamp is used as the target time series index marker corresponding to the running status record, and the target time series index marker is bound and stored with the running status record.

11. The method according to any one of claims 1 to 8, characterized in that, The step of pushing the fused data description set to the built-in parsing interface of the second photovoltaic platform, and converting the format of the fused data description set according to the data protocol specification of the second photovoltaic platform during the pushing process to generate a target interactive data set adapted to the data receiving structure of the second photovoltaic platform, includes: Obtain the interface address descriptor of the pre-registered built-in parsing interface of the second photovoltaic platform, and establish a data transmission path between the second photovoltaic platform and the second photovoltaic platform based on the interface address descriptor; Read the data protocol specification description file of the second photovoltaic platform, and extract the frame header construction definition information, data payload encoding method definition information, and frame tail append information definition information of the data frame from the data protocol specification description file; Based on the frame header construction definition information, the fused data description set is encapsulated with a data frame header, and a data frame start identifier and a data frame length indicator that conform to the second photovoltaic platform parsing rules are added to the fused data description set. Based on the encoding method definition information of the data payload, the encoding form of the data payload part in the fused data description set is converted, and the internal data representation of the fused data description set is converted into the target data representation that can be recognized by the second photovoltaic platform; Based on the frame tail append information definition information, the data payload part after the encoding conversion process, as well as the data frame start identifier and data frame length indicator, are processed to generate overall append information, and a data frame tail append information field is generated for integrity verification by the data receiving side. The data frame start identifier, the data frame length indicator, the data payload portion after encoding conversion, and the data frame tail additional information field are sequentially concatenated to generate the target interactive data frame unit. The target interactive data frame unit is pushed to the built-in parsing interface of the second photovoltaic platform through the data transmission path to complete the generation and push operation of the target interactive data set.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program performs the steps of the method according to any one of claims 1 to 11.