Inverter and energy storage system

The inverter's internal decryption mechanism allows secure upgrades without relying on user gateways, addressing the challenge of insecure user gateways by decrypting data internally for secure firmware updates.

CN223110035UActive Publication Date: 2025-07-15BEIJING HEKANG NEW ENERGY FREQUENCY CONVERSION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202422320714.2
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-07-15
Estimated Expiration
2034-09-23

AI Technical Summary

Technical Problem

Traditional inverter security upgrade methods rely on user gateway encryption, resulting in the inverter security upgrade cannot be achieved when the user gateway does not have security.

Method used

By setting the key injection port and communication port in the inverter, the decryption key is directly injected by the upper computer, and the main control chip decrypts it, achieving a security upgrade within the inverter and avoiding the security design of the user gateway.

Benefits of technology

Under the security design that does not rely on user gateways, the security upgrade of the inverter is achieved, ensuring the security and integrity of data transmission, and preventing data tampering and piracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223110035U_ABST
    Figure CN223110035U_ABST
Patent Text Reader

Abstract

The utility model discloses an inverter and an energy storage system, relates to the technical field of equipment safety, and discloses the inverter comprising a main control chip; the key injection port is connected with the main control chip, and the main control chip is set to store a decryption key injected by an external upper computer through the key injection port; the first communication port is connected with the main control chip, and the first communication port is set to receive encrypted upgrading data which is sent by the upper computer and is transmitted by an external user gateway; and the main control chip is set to decrypt the encrypted upgrading data based on the decryption key to obtain data to be upgraded, so as to carry out security upgrading based on the data to be upgraded. According to the invention, on the premise of not depending on the security design of the user gateway, the security upgrade of the inverter is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security technologies, and in particular, to an inverter and an energy storage system. Background Art

[0002] With the increasingly widespread application of inverters in different fields, users have also put forward higher requirements for the inverter security upgrade method.

[0003] The traditional inverter security upgrade method is to directly transmit the data packet to be upgraded to the inverter after being encrypted by the user gateway, so as to complete the upgrade in the inverter. This inverter security upgrade method has the phenomenon that the data packet to be upgraded needs to be encrypted by the user gateway. Therefore, there is an urgent need for a new inverter to achieve inverter security upgrade without relying on the security design of the user gateway.

[0004] The above content is only used to assist in understanding the technical solution of this application, and does not represent an admission that the above content is prior art. Utility Model Content

[0005] The main purpose of this application is to provide an inverter and an energy storage system, aiming to solve the technical problem of how to achieve inverter security upgrade when the user gateway does not have security.

[0006] To achieve the above object, this application provides an inverter, and the inverter includes:

[0007] A main control chip;

[0008] A key injection port, the key injection port is connected to the main control chip, and the main control chip is configured to store the decryption key injected by an external host computer through the key injection port;

[0009] A first communication port, the first communication port is connected to the main control chip, the first communication port is configured to receive the encrypted upgrade data sent by the host computer and transmitted through an external user gateway, and the main control chip is configured to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded, so as to perform a security upgrade based on the data to be upgraded.

[0010] In an embodiment, the inverter further includes:

[0011] An internal control chip, an input end of the internal control chip is connected to a first output end of the main control chip. When the data to be upgraded is the upgrade firmware of the internal control chip, the internal control chip is configured to perform a security upgrade based on the data to be upgraded;

[0012] An external control chip, the input end of the external control chip is connected to the second output end of the main control chip. When the data to be upgraded is the upgrade firmware of the external control chip, the external control chip is configured to perform a secure upgrade based on the data to be upgraded.

[0013] In one embodiment, the main control chip includes:

[0014] A random number generation module, the random number generation module is used to generate random numbers;

[0015] An encryption / decryption operation module, the encryption / decryption operation module is connected to the random number generation module and the key injection port. The encryption / decryption operation module is used to perform encapsulation based on the random number and the decryption key to obtain the encrypted decryption key.

[0016] A secure storage module, the secure storage module is connected to the encryption / decryption operation module. The secure storage module is used to store the encrypted decryption key. Wherein, the encryption / decryption operation module is further used to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded.

[0017] In one embodiment, the secure storage module is the EEPROM, FUSE or FLASH of the main control chip.

[0018] In one embodiment, the encryption / decryption operation module includes an HMAC module.

[0019] In one embodiment, the inverter further includes:

[0020] A transmission module, the transmission module is respectively connected to the user gateway and the main control chip through the first communication port. Wherein, the transmission module includes a physical connection of a wire, or a communication connection of a serial port Bluetooth or an RFID wireless transmission device.

[0021] In one embodiment, the key injection port includes a serial communication interface, and the first communication port includes a 485 port.

[0022] In one embodiment, the main control chip includes a secure encryption engine component.

[0023] In addition, to achieve the above object, an energy storage system is further provided. The energy storage system includes the above inverter;

[0024] The key injection port of the inverter is connected to the output interface of an external host computer, and the second communication port of the inverter is connected to an external user gateway.

[0025] In one embodiment, the energy storage system further includes:

[0026] A level controller, which is connected to the level control port of the inverter. The level controller is configured to control the inverter to be in different operating states based on different levels, where the operating states include a power-on state, a key injection state, and a normal state.

[0027] In one embodiment, the level controller includes:

[0028] A high-level power supply;

[0029] A conducting switch, the first end of the conducting switch is connected to the level control port and the high-level power supply, the second end of the conducting switch is grounded. The conducting switch is used to ground the level control port when pressed, and connect the level control port to the high-level power supply when not pressed.

[0030] An embodiment of the present application provides an inverter, including a main control chip; a key injection port, which is connected to the main control chip. The main control chip is configured to store the decryption key injected by an external host computer through the key injection port; a first communication port, which is connected to the main control chip. The first communication port is configured to receive the encrypted upgrade data sent by the host computer and transmitted through an external user gateway. The main control chip is configured to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded, so as to perform a secure upgrade based on the data to be upgraded. The decryption key is injected into the inverter through the key injection port of the inverter by the host computer, so that when the inverter receives the encrypted upgrade data sent by the host computer and transmitted through an external user gateway, the encrypted upgrade data can be decrypted based on the decryption key to obtain the data to be upgraded, so as to achieve a secure upgrade based on the data to be upgraded, thus avoiding the phenomenon that a secure upgrade needs to rely on the user gateway connected to the inverter. By using the inverter as the location for setting the key for secure upgrade verification, a secure upgrade of the inverter can be achieved without relying on the security design of the user gateway. Description of the Drawings

[0031] Figure 1 It is a framework schematic diagram of the first embodiment of the inverter of the present application;

[0032] Figure 2 It is a framework schematic diagram of the second embodiment of the inverter of the present application;

[0033] Figure 3 It is a framework schematic diagram of the third embodiment of the inverter of the present application;

[0034] Figure 4 It is a connection schematic diagram of the inverter of the present application;

[0035] Figure 5It is a schematic diagram of a scenario of the inverter of the present application;

[0036] Figure 6 It is another schematic diagram of a scenario of the inverter of the present application;

[0037] Figure 7 It is a connection schematic diagram of the energy storage system of the present application;

[0038] Figure 8 It is a connection schematic diagram of the port conduction selector in the inverter of the energy storage system of the present application.

[0039] The realization, functional features and advantages of the purpose of the present application will be further described in conjunction with the embodiments with reference to the accompanying drawings.

[0040] Explanation of the reference numerals in the drawings:

[0041] 100, host computer; 101, output interface; 102, second communication port; 200, inverter; 201, key injection port; 202, first communication port; 300, user gateway; 400, server; 210, main control chip; 220, internal control chip; 230, external control chip; 203, first control port; 204, second control port; 510, first signal output circuit; 511, first power supply; 512, first selection key switch; 520, second signal output circuit; 521, second power supply; 522, second selection key switch; 600, selector; A, selector input terminal; C1-Cn, selector control terminal; B1-1-B1-4, selector output terminal; 211, random number generation module; 212, encryption and decryption operation module; 213, secure storage module. Detailed implementation manners

[0042] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0043] For a better understanding of the technical solution of the present application, the following will be described in detail in conjunction with the drawings in the specification and specific implementation manners.

[0044] The inverter can perform application upgrades by wireless / wired data transmission. When the application is transmitted in plain text, it is easily captured by hackers or the data is tampered with due to signal interference. To prevent data from being tampered with or copied for piracy during transmission, the program file needs to use a key for data encryption and digital signature authentication to ensure that the data cannot be directly used and the integrity of the data packet. In the inverter system, usually a key is set on the user gateway connected to the inverter (the key is first injected into the user gateway by the host computer), so as to perform encrypted transmission of the application on the user gateway. In the case where the user gateway is the customer's user gateway, the user needs to configure the key on the customer side, and the following problems will exist: If the key cannot be set on the user gateway due to confidentiality requirements or design requirements, the inverter cannot be safely used on the customer side. Therefore, when the user gateway connected to the inverter does not have security (such as being restricted by internal confidentiality reasons and design, and the user is restricted from setting the key on the user gateway), there will be a phenomenon that the safe upgrade of the inverter cannot be guaranteed.

[0045] Therefore, based on the deficiencies of the above inverter security upgrade methods, the inverter of the present application is proposed. In the embodiment of the present application, the decryption key is injected into the inverter through the key injection port of the inverter by the host computer, so that when the inverter receives the encrypted upgrade data sent by the host computer and transmitted through the external user gateway, the encrypted upgrade data can be decrypted based on the decryption key to obtain the data to be upgraded, so as to achieve a safe upgrade based on the data to be upgraded, thus avoiding the phenomenon that the safe upgrade needs to rely on the user gateway connected to the inverter. By using the inverter as the location for setting the key for security upgrade verification, the safe upgrade of the inverter can be realized without relying on the security design of the user gateway.

[0046] Based on this, the embodiment of the present application provides an inverter, referring to Figure 1 , Figure 1 which is a frame schematic diagram of the first embodiment of the inverter of the present application.

[0047] Referring to Figure 1 , the present application provides an inverter 200, and the inverter 200 includes:

[0048] A main control chip 210;

[0049] A key injection port 201, the key injection port 201 is connected to the main control chip 210, and the main control chip 210 is configured to store the decryption key injected by the external host computer 100 through the key injection port 201;

[0050] The first communication port 202 is connected to the main control chip 210. The first communication port 202 is configured to receive the encrypted upgrade data sent by the host computer 100 and transmitted through the external user gateway 300. The main control chip 210 is configured to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded, so as to perform a security upgrade based on the data to be upgraded.

[0051] In one embodiment, the key injection port 201 includes a serial communication interface, and the first communication port 202 includes a 485 port.

[0052] In one embodiment, the main control chip 210 includes a secure encryption engine component.

[0053] In this embodiment, different from the conventional solution where the user gateway is connected to the host computer to transmit the key, and then the data transmitted is encrypted based on the key on the user gateway and then a security upgrade is performed, in this application, the decryption key injected by the external host computer 100 through the key injection port 201 is stored, and then verified and decrypted in the inverter 200, so that it is not necessary to set the key on the user gateway. That is, on the premise of not relying on the security design of the user gateway, the security upgrade of the inverter can be realized. It should be noted that except for the first time (production stage) when the decryption key is burned into the key injection port 201 of the inverter 200 directly by the host computer 100, subsequently, the host computer 100 transmits to the inverter 200 through the user gateway 300. For example, the user manually or downloads to the server through the port, and the server transmits to the user gateway 300 based on the wireless communication method, that is, at this time, the encrypted upgrade data sent by the host computer 100 and transmitted through the external user gateway 300 is received. Since the decryption key already exists in the inverter 200 at this time, the inverter 200 can encrypt and sign and verify the transmitted data based on the decryption key to ensure the security of the data. Among them, the decryption key refers to the key used to decrypt the data or a new key, which can be the same as the common decryption method and is not limited here. The encrypted upgrade data refers to the upgraded data after encryption, which can be the key or firmware to be upgraded. Because the decryption key is stored in the main control chip 210 of the inverter 200, and it is not necessary to use the user gateway 300 to realize the security upgrade of the inverter 200, the security upgrade of the inverter can be realized by setting the decryption key inside the inverter, and on the premise of not relying on the security design of the user gateway.

[0054] In one embodiment, after injecting the decryption key during the production stage, the decryption key is used to securely upgrade the encrypted upgrade data, which can be the encrypted key or firmware, and is not limited herein. When it is necessary to transmit the encrypted upgrade data (if the user issues an upgrade requirement), the host computer 100 transmits the encrypted upgrade data to the inverter 200 through the user gateway 300. The inverter 200 decrypts the encrypted upgrade data based on the stored decryption key to obtain the data to be upgraded, so as to upgrade the program or key inside the inverter 200 based on the data to be upgraded. Among them, the encrypted upgrade data refers to the program or key encrypted by the host computer 100, and the data to be upgraded refers to the program or key after the inverter 200 decrypts and verifies the signature of the encrypted upgrade data. During the entire execution process, encryption, decryption, signature verification, and signature can all be performed in the same manner as in the prior art, which is not limited herein. A decryption chip can also be directly set inside the main control chip 210 (which can be a certain control chip in the main control chip 210) to transmit the decryption key and the encrypted upgrade data to this chip for processing. It should be noted that the key injection port 201 includes a serial communication interface on the inverter 200, and the second communication port 202 connected to the user gateway 300 includes a 485 port, and the first communication port 102 includes a wireless network port. Of course, it can also be other communication ports, which is not limited herein. In another embodiment, to ensure the security of the data inside the inverter, the main control chip 210 includes a secure encryption engine component at this time. Among them, the secure encryption engine is a key component in the inverter. It integrates a variety of security protection mechanisms and is designed to ensure that the inverter can maintain a safe, stable, and reliable operating state under various operating conditions. These security protection functions include, but are not limited to, short-circuit protection, overload protection, overvoltage protection, undervoltage protection, and overtemperature protection, etc. It can quickly cut off the power supply or adjust the working state in case of an abnormal situation, prevent equipment damage or cause safety accidents, so as to ensure the security of the storage and use of the internal decryption key. That is, the entire process can use an inverter with a secure encryption engine to achieve the secure upgrade of the inverter without relying on the security design of the user gateway. Therefore, a new inverter can be used to achieve the secure upgrade of the inverter without relying on the security design of the user gateway.

[0055] In this embodiment, an inverter is provided, which includes a main control chip; a key injection port connected to the main control chip, and the main control chip is configured to store a decryption key injected by an external host computer through the key injection port; a first communication port connected to the main control chip, and the first communication port is configured to receive encrypted upgrade data sent by the host computer and transmitted through an external user gateway. The main control chip is configured to decrypt the encrypted upgrade data based on the decryption key to obtain data to be upgraded, so as to perform a secure upgrade based on the data to be upgraded. The decryption key is injected into the inverter through the key injection port of the inverter by the host computer, so that when the inverter receives the encrypted upgrade data sent by the host computer and transmitted through the external user gateway, the encrypted upgrade data can be decrypted based on the decryption key to obtain the data to be upgraded, and a secure upgrade can be realized based on the data to be upgraded. Thus, the phenomenon that a secure upgrade depends on the user gateway connected to the inverter is avoided. By using the inverter as the location for setting the key for secure upgrade verification, a secure upgrade of the inverter can be realized without relying on the security design of the user gateway.

[0056] Further, based on the first embodiment of the present application above, a second embodiment of the inverter of the present application is proposed. Refer to Figure 2 , Figure 2 which is a schematic framework diagram of the second embodiment of the inverter of the present application. The inverter 200 further includes:

[0057] An internal control chip 220, the input end of the internal control chip 220 is connected to the first output end of the main control chip 210. When the data to be upgraded is the upgrade firmware of the internal control chip 220, the internal control chip 220 is configured to perform a secure upgrade based on the data to be upgraded;

[0058] An external control chip 230, the input end of the external control chip 230 is connected to the second output end of the main control chip 210. When the data to be upgraded is the upgrade firmware of the external control chip 230, the external control chip 230 is configured to perform a secure upgrade based on the data to be upgraded.

[0059] In this embodiment, the interior of the inverter 200 at least includes a main control chip 210, an internal control chip 220, and an external control chip 230. Among them, since the main control chip 210 includes a security encryption engine component, that is, the main control chip 210 is mainly used to store decryption keys, and use the decryption keys to decrypt and verify the signature of the data transmitted by the second communication port 202. Among them, the input end of the main control chip 210 can be the same port, that is, this port can receive the decryption key burned by the host computer 100, and can also receive the data from the user gateway 300 for decryption. The input end of the main control chip 210 can be different ports, that is, receive the decryption key burned by the host computer 100 through one port alone, and receive the data from the user gateway 300 through another port alone for decryption. It should be noted that the decryption key burned by the host computer 100 or the decryption key in the data from the user gateway 300 needs to be directly stored inside the main control chip 210. The data to be upgraded in the data from the user gateway 300 can be safely upgraded to the inside of the main control chip 210, the internal control chip 220, or the external control chip 230 according to requirements. That is, the main control chip 210 is responsible for operations such as key storage, decryption, and signature verification. Since the internal control chip 220 and the external control chip 230 need to be firmware-upgraded, the main control chip 210 is also connected to the internal control chip 220 and the external control chip 230 inside the inverter 200, so as to transmit the data to be upgraded in the data from the user gateway 300 to the corresponding chip through different ports of the main control chip 210, so as to realize the program upgrade of the corresponding chip. Among them, the internal control chip 220 includes a digital signal processing chip and a programmable logic control chip. That is, the main control chip 210 can transmit the upgrade programs of the digital signal processing chip and / or the programmable logic control chip to the corresponding chip through a dedicated interface, such as the processing program upgrade of the digital signal processing chip and the storage program upgrade of the programmable logic control chip; the external control chip 230 includes a battery management chip. That is, the main control chip 210 can transmit the upgrade program of the battery management chip to the corresponding chip through a dedicated interface, such as the battery power supply control program of the battery management chip. The above are only examples of some chips, and there may also be other different types of chips, which are not limited here.

[0060] In one embodiment, reference may be made to Figure 2, the inverter 200 needs to be connected to the host computer through the server 400 and the user gateway 300. The server 400 is communicatively connected to the first communication port 102 and the user gateway 300, that is, it communicates with the user gateway 300 and the first communication port 102 in the host computer 100 through the server or an APP (Application). Among them, the first communication port 102 mainly refers to the output port of the key management tool in the host computer 100. The key management tool can be a software program in the host computer 100, such as a program developer, etc. It should be noted that the host computer 100 can also be directly connected to the main control chip 210 (the key injection port 201 of the inverter 200 is connected to the output interface 101 of the dedicated key management tool in the host computer 100), that is, the decryption key is directly injected (burned) during the production stage. However, after the production stage ends, the data transmission between the key injection port 201 and the output interface 101 will be restricted to ensure the data security inside the inverter. Further, referring to Figure 4 , Figure 4 is a connection schematic diagram of the inverter of the present application. The connection relationship between the inverter 200, the host computer 100, and the user gateway 300 is introduced in the figure. Taking the serial communication between the host computer 100 and the inverter 200 as an example, during the production stage (generally referring to the state of the inverter 200), the key will be directly injected into the inverter 200 through serial communication. After the key injection is completed or the production stage is completed, the data transmission between the host computer 100 and the inverter 200 will be cut off (such as restricting the port or the user disconnecting the connection line). At this time, the data will be transmitted from the host computer 100 to the user gateway 300 to upgrade the key or the firmware. The firmware refers to the upgrade program of the inverter 200. At this time, the firmware and the key are collectively referred to as upgrade data. The upgrade data can be transmitted in the communication mode of 485. At this time, the direct communication between the host computer 100 and the inverter 200 can be restricted to ensure that the data inside the inverter will not be tampered with or read, thereby ensuring the security of the inverter upgrade.

[0061] Further, based on the first embodiment and / or the second embodiment of the present application above, the third embodiment of the inverter of the present application is proposed. Referring to Figure 3 , Figure 3 is a framework schematic diagram of the third embodiment of the inverter of the present application. The main control chip 210 includes:

[0062] A random number generation module 211, which is used to generate random numbers;

[0063] An encryption / decryption operation module 212, which is connected to the random number generation module 211 and the key injection port 201. The encryption / decryption operation module 212 is configured to encapsulate based on the random number and the decryption key to obtain the decryption key after encryption;

[0064] A secure storage module 213, which is connected to the encryption / decryption operation module 212. The secure storage module 213 is configured to store the decryption key after encryption. Wherein, the encryption / decryption operation module 212 is further configured to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded.

[0065] In one embodiment, the secure storage module 213 is the EEPROM, FUSE or FLASH of the main control chip 210.

[0066] In one embodiment, the encryption / decryption operation module 212 includes an HMAC module.

[0067] In one embodiment, the inverter 200 further includes:

[0068] A transmission module, which is respectively connected to the user gateway 300 and the main control chip 210 through the first communication port 202. Wherein, the transmission module includes a physical connection of a wire, or a communication connection of a serial port Bluetooth or an RFID wireless transmission device.

[0069] In this embodiment, the main control chip 210 includes a random number generation module 211, an encryption / decryption operation module 212 and a secure storage module 213. Among them, the random number generation module 211 is configured to generate a random number, and in the decryption operation module 212, the decryption key is encapsulated based on the random number and the decryption key, that is, the decryption key is encrypted based on the random number and then stored in the secure storage module 213. It should be noted that the entire storage process can be obtaining the encryption key - encrypting with a random number - storing in the secure storage module 213. Among them, the secure storage module 213 is the EEPROM, FUSE or FLASH of the main control chip 210, the encryption / decryption operation module 212 includes an HMAC module, and the method of encrypting with a random number is the same as the existing method, and the encryption method is not limited herein. When the decryption key is used, the decryption key is obtained by decrypting with a random number - and used in the encryption / decryption operation module 212 for decryption. It should be noted that the inverter 200 further includes: a transmission module, which is configured to transmit data between the user gateway 300 and the inverter 200, including a physical connection of a wire, or a communication connection of a serial port Bluetooth or an RFID wireless transmission device, etc.

[0070] This application also provides an energy storage system, refer toFigure 7 , Figure 7 is a connection schematic diagram of an energy storage system, and the energy storage system includes the above-mentioned inverter 200;

[0071] The key injection port 201 of the inverter 200 is connected to the output interface 101 of the external host computer 100, and the second communication port 202 of the inverter 200 is connected to the external user gateway 300.

[0072] Among them, the energy storage system may further include an encapsulation body composed of a device shell. The inverter may be disposed in the encapsulation body, and the encapsulation body is provided with corresponding ports connected to the output interface 101 of the host computer 100 and the external user gateway 300. The second communication port 201 includes a wireless network port. It should be noted that the user gateway, the host computer, and the server may all be directly disposed on the inverter, and the entire control system of the inverter is composed of the inverter.

[0073] The device provided by the present application can solve the technical problem of realizing the security upgrade of the inverter without relying on the security design of the user gateway. Compared with the prior art, the beneficial effects of the device provided by the present application are the same as those of the device circuit provided in the above embodiment, and will not be elaborated here.

[0074] In one embodiment, referring to Figure 8 , Figure 8 is a connection schematic diagram of a port conduction selector in the inverter of the energy storage system of the present application. The energy storage system further includes:

[0075] A level controller, the level controller is connected to the level control port of the inverter, and the level controller is configured to control the inverter to be in different operating states based on different levels. Among them, the operating states include a power-on state, a key injection state, and a normal state.

[0076] In one embodiment, the level controller includes:

[0077] A high-level power supply;

[0078] A conduction switch, the first end of the conduction switch is connected to the level control port and the high-level power supply, the second end of the conduction switch is grounded, and the conduction switch is configured to ground the level control port when pressed, and connect the level control port to the high-level power supply when not pressed.

[0079] In this embodiment, the energy storage system further includes a level controller, and the level controller is connected to the level control port of the inverter, as Figure 7As shown, the inverter 200 further includes a first control port 203 and a second control port 204. Therefore, the inverter further includes a level controller for controlling the two ports. It should be noted that the inverter 200 may also have only one port, and a level controller is used for control. The advantage of using one port for control is that the number of port designs can be saved. However, at this time, only two control logics can be implemented, namely high-level control and low-level control. While two-port control can implement four control logics, namely the control logics of 01, 10, 11, and 00, where 1 represents high level and 0 represents low level. In this embodiment, the two-control-port method is used for illustration. Therefore, the control circuits of the respective ports can be circuits for controlling the output of high and low levels. In an embodiment, the two control circuits (i.e., the first signal output circuit 510 and the second signal output circuit 520) can both be composed of a power supply (high-level power supply) and a selection push-button switch (conductive switch) (or other circuits or devices for outputting high and low levels, which are not limited herein, such as directly manually connecting to high level or low level). Taking the first signal output circuit 510 as an example, the first signal output circuit 510 can achieve that when the selection push-button switch is pressed, the first power supply 511 is directly connected to the first control port 203. At this time, the first control port 203 inputs a high level. When the selection push-button switch is not pressed, the ground is connected to the first control port 203. At this time, the first control port 203 inputs a low level, that is, different level inputs of the first control port 203 are realized, thereby controlling the operation of the inverter 200. It should be noted that the control logic of the second signal output circuit 520 is the same as that of the first signal output circuit 510 and will not be described one by one here. The first power supply 511 and the second power supply 521 can also be directly shared without affecting the actual output signals of the first signal output circuit 510 and the second signal output circuit 520. The first control port and the second control port can also control the inverter to implement the power-on function. By controlling the power-on conduction selector through the first control port and the second control port, the internal power supply interface is connected to the chip that needs to be powered. At this time, the internal power supply interface also needs to be connected to the voltage processing circuit, and then different amplitudes of voltage are output based on the voltage processing circuit to supply power to the chip. Among them, the voltage processing circuit can be composed of respective voltage regulator chips. For example, 78 and 79 series chips output +5V, +9V, and +12V voltages to the required chip interfaces. At this time, the voltage processing circuit can be a common power supply circuit for processing the input voltage and outputting the amplitudes of voltage required by each chip, or can also be directly individual DC-to-DC chips, which are not limited here. Through the port control of the inverter 200, the safety upgrade of the inverter is realized.

[0080] In an embodiment, such as Figure 4As shown, the PCS (inverter) device with a security encryption engine is connected to the host computer 100 through the SCI (Serial Communication Interface). During the production stage, the first control port and the second control port are pulled to the low state through the first signal output circuit 510 and the second signal output circuit 520 to power on the inverter 200. Then, the host computer 100 is connected to the PCS device via the SCI port. Next, the input signal of the second control port is pulled high to perform the key injection operation. After the operation is successful, the first control port and the second control port return to the normal state (pulled high), and no other control is performed on the inverter at this time. After the non-production stage, the first control port and the second control port are powered on again. The PCS device with a security encryption engine establishes communication with the gateway through the 485 port, and upgrades the application program to the PCS device via the gateway by means of OTA to complete the data transmission in the non-production stage. The entire process can also be other control logics, such as injecting keys when both the first control port and the second control port are at a high level, and powering on when both are at a low level. The control logic of the inverter is not limited here. Then, the key is stored in the inverter so that it can be used when the user gateway does not have security. It should be noted that in order to ensure that the data in the inverter 200 will not be modified by external factors, a port conduction selector can be set inside the inverter 200 at this time. The port conduction selector can be controlled by the input signals of the first control port and the second control port. Of course, it can also be other controls, such as directly prohibiting the connection between the host computer 100 and the inverter 200 when the internal program logic of the inverter is not in the production stage, or directly setting a switch on the connection line between the host computer 100 and the inverter 200 to connect the host computer 100 and the inverter 200 through this switch during the production stage; after the production stage (generally referring to the production process when the inverter is not in use), the direct connection line between the host computer 100 and the inverter 200 will be disconnected through this switch.

[0081] In one embodiment, refer to Figure 5 , Figure 5 This is a schematic diagram of a scenario of the inverter of the present application. At this time, it is in the production stage, and the host computer 100 is directly connected to the inverter 200. The decryption key generated by the host computer 100 can be directly injected into the inverter 200. Then, the inverter 200 can perform a security upgrade (firmware and key upgrade) based on the decryption key. At this time, the user gateway 300 can also be used to inject the key, but the cost of connecting the user gateway 300 during the production stage is relatively high. For example, if the user gateway 300 is at the customer side, it needs to be processed at the customer side. Further, refer to Figure 6 , Figure 6This is another schematic diagram of the inverter in this application. When in the non-production stage, the control host computer 100 is disconnected from the inverter 200. At this time, data cannot be directly transmitted to the inverter 200 or read the data in the inverter 200, thereby ensuring the security of the data in the inverter 200. At this time, after the key update and firmware upgrade are transmitted from the host computer 100 to the user gateway 300, they are transmitted from the user gateway 300 to the inverter 200, so as to prevent the internal data of the inverter 200 from being read or tampered with, and to ensure the security of the internal data of the inverter.

[0082] The above are only some embodiments of this application, and do not limit the patent scope of this application. Any equivalent structural transformation made under the technical concept of this application by using the content of the specification and drawings of this application, or directly / indirectly applied in other related technical fields, is included in the patent protection scope of this application.

Claims

1. An inverter, characterized in that, The inverter includes: A main control chip; A key injection port, which is connected to the main control chip. The main control chip is configured to store the decryption key injected by an external host computer through the key injection port; A first communication port, which is connected to the main control chip. The first communication port is configured to receive encrypted upgrade data sent by the host computer and transmitted through an external user gateway. The main control chip is configured to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded, so as to perform a secure upgrade based on the data to be upgraded.

2. The inverter according to claim 1, characterized in that, The inverter further includes: An internal control chip, the input end of which is connected to the first output end of the main control chip. When the data to be upgraded is the upgrade firmware of the internal control chip, the internal control chip is configured to perform a secure upgrade based on the data to be upgraded; An external control chip, the input end of which is connected to the second output end of the main control chip. When the data to be upgraded is the upgrade firmware of the external control chip, the external control chip is configured to perform a secure upgrade based on the data to be upgraded.

3. The inverter according to claim 1, characterized in that The main control chip includes: A random number generation module, which is used to generate random numbers; An encryption / decryption operation module, which is connected to the random number generation module and the key injection port. The encryption / decryption operation module is used to encapsulate based on the random number and the decryption key to obtain the encrypted decryption key; A secure storage module, which is connected to the encryption / decryption operation module. The secure storage module is used to store the encrypted decryption key. Among them, the encryption / decryption operation module is also used to decrypt the encrypted upgrade data based on the decryption key to obtain the data to be upgraded.

4. The inverter according to claim 3, characterized in that, The secure storage module is the EEPROM, FUSE or FLASH of the main control chip.

5. The inverter according to claim 3, characterized in that, The encryption / decryption operation module includes an HMAC module.

6. The inverter according to any one of claims 1 to 5, characterized in that, The inverter further includes: A transmission module, which is respectively connected to the user gateway and the main control chip through the first communication port. Among them, the transmission module includes a physical connection of wires, or a communication connection of a serial port Bluetooth or an RFID wireless transmission device.

7. The inverter according to any one of claims 1 to 5, characterized in that, The key injection port includes a serial communication interface, and the first communication port includes a 485 port.

8. The inverter according to any one of claims 1 to 5, characterized in that, The main control chip includes a secure encryption engine component.

9. A energy storage system, characterized in that, The energy storage system includes the inverter according to any one of claims 1 to 8; The key injection port of the inverter is connected to the output interface of an external host computer, and the second communication port of the inverter is connected to an external user gateway.

10. The energy storage system according to claim 9, characterized in that, The energy storage system further includes: A level controller, which is connected to the level control port of the inverter. The level controller is configured to control the inverter to be in different operating states based on different levels. Among them, the operating states include a power-on state, a key injection state and a normal state.

11. The energy storage system according to claim 10, wherein The level controller includes: A high-level power supply; A conducting switch, the first end of the conducting switch is connected to the level control port and the high-level power supply, the second end of the conducting switch is grounded, and the conducting switch is used to ground the level control port when pressed and connect the level control port to the high-level power supply when not pressed.