Summary of the invention
An object of the present invention is for above-mentioned deficiency, a kind of IC-card intelligent electric energy meter being embedded with information security management module is provided, with problems such as the information security management of expecting to solve IC-card intelligent electric energy meter of the prior art and management system thereof can not be guaranteed, eliminate the risk of information security management in Utilities Electric Co.'s operation.
For solving above-mentioned technical problem, the present invention by the following technical solutions:
A kind of IC-card intelligent electric energy meter being embedded with information security management module provided by the present invention, comprise counting module, relay, IC-card intelligent electric energy meter terminal master controller and memory, described counting module accesses power input on electric energy meter and IC-card intelligent electric energy meter terminal master controller respectively, for measuring power consumption, and variable is exported to IC-card intelligent electric energy meter terminal master controller, described relay accesses power input on electric energy meter and power output end respectively, described IC-card intelligent electric energy meter terminal master controller is by control relay circuit cut-in relay, for closing and disconnecting by IC-card intelligent electric energy meter terminal main controller controls relay, described memory also accesses IC-card intelligent electric energy meter terminal master controller, information security management module is also comprised in described IC-card intelligent electric energy meter, described information security management module comprises processor, first data-interface, second data-interface and FLASH memory, described processor accesses the first data-interface respectively, second data-interface and FLASH memory, wherein:
Described first data-interface access IC card information Switching Module, communicates with the unique data of IC card information Switching Module for performing IC-card intelligent electric energy meter, and transmits it to processor when receiving the external data coming from IC card information Switching Module;
Described FLASH memory is for storing control in information security management module and documentor;
Described second data-interface access IC-card intelligent electric energy meter terminal master controller, for performing the data communication between processor and IC-card intelligent electric energy meter terminal master controller, described IC-card intelligent electric energy meter terminal master controller is used for performing the operation of corresponding table end according to the instruction of processor;
Described processor is used for when receiving the external data coming from the first data-interface, authentication is carried out to the management system for selling power of write external data, judge whether to obtain the encrypted packets in this external data, and send corresponding operational order by the second data-interface to IC-card intelligent electric energy meter terminal master controller according to the affairs comprised in data.
As preferably, further technical scheme is: described processor is used for when receiving the external data coming from the first data-interface, authentication is carried out according to the management system for selling power of external data to write external data, when authentication result is judged as legal, then encrypted packets is decrypted and completeness check, on the contrary the original state that then resets;
After data integrity verifying passes through, the validity of data is verified, on the contrary the original state that then resets;
After Validation of Data is passed through, pretreatment is carried out to the affairs comprised in data, and from IC-card intelligent electric energy meter terminal master controller, obtain corresponding return information by the second data-interface, IC card information Switching Module is returned to by the first data-interface by after described return information encryption, then pre-processed results approved after effectively being confirmed and stored relevant operation information, and to IC-card intelligent electric energy meter terminal master controller transmit operation instruction; Otherwise then abandon pre-processed results or make caching process.
Further technical scheme is: preset agreement restrictive condition and multiple different cipher key procedures in described FLASH memory, for when the subsystem of information security management module classification different from management system for selling power respectively carries out exchanges data, processor according to the encryption key of external data compared with multiple cipher key procedures preset in FLASH memory, thus the identity of certification management system for selling power, and after encrypted packets deciphering and completeness check are passed through, according to the validity of agreement restrictive condition verification msg under current identity, judge whether to carry out pretreatment to the affairs in data.
Further technical scheme is: also comprise eeprom memory in described information security management module, described eeprom memory also accesses processor, for the associative operation information of storage of processor to IC-card intelligent electric energy meter terminal master controller, and processor is to the pre-processed results of affairs in external data.
Further technical scheme is: described processor is central processing unit or the single-chip microcomputer that can perform AES.
Further technical scheme is: the first described data-interface is IC-card interface.
Further technical scheme is: the second described data-interface be at least in the middle of USART serial line interface, SPI serial line interface or I2C serial line interface any one.
Further technical scheme is: described information security management module also comprises encrypting module, described encrypting module access processor, for the multistage encryption and decryption to information security management module and management system for selling power, IC-card intelligent electric energy meter terminal master controller exchanges data, and the data encryption key that auxiliary processor obtains management system for selling power carries out authentication.
Further technical scheme is: described encrypting module is by the Advanced Encryption Standard in AES(cryptography, the abbreviation of English Advanced Encryption Standard) or the triple DEA of 3DES(, English Triple Data Encryption Algorithm) mode carry out data encrypting and deciphering.
Further technical scheme is: described memory is for storing the presell electric quantity data information coming from information security management module forwards, described IC-card intelligent electric energy meter terminal master controller is also connected with LCDs by liquid crystal display circuit, for being deducted the presell electric quantity data information initial value stored in memory according to the variable in counting module by IC-card intelligent electric energy meter terminal master controller, and presented on LCDs by liquid crystal display circuit; Also comprise buzzer in described intelligent electric energy meter, described IC-card intelligent electric energy meter terminal master controller is by surplus judging circuit access buzzer.
Compared with prior art, one of beneficial effect of the present invention is: by embedding information security management module in IC-card intelligent electric energy meter, authentication is carried out when making it carry out exchanges data by IC card information Switching Module and management system for selling power, ensure that the legitimacy of both communication, IC-card intelligent electric energy meter terminal master controller could must be communicated with outside by information security management module; Utilize different keys can realize the priority assignation of Utilities Electric Co.'s differentiated control, and adopt 3DES/AES multi-level encryption mode, make the security of key higher, and by upgrade key during download program cause for gossip in information security management module, avoid the risk that key exposure brings; By built-in data verifying program, ensure that the data of transmission are true, accurate, complete.Simultaneously a kind of IC-card intelligent electric energy meter structure being embedded with information security management module provided by the present invention is simple, can seamless access power supply management system by the information security management module of inside, realize the dispersion manufacture of IC-card intelligent electric energy meter, unified management, range of application is wide, and ensure that the independence of Utilities Electric Co. on terminal electric energy meter controls, not by extraneous restriction.
Detailed description of the invention
Below in conjunction with accompanying drawing, the present invention is further elaborated.
With reference to figure 1, shown in Fig. 2, one embodiment of the present of invention are a kind of IC-card intelligent electric energy meters being embedded with information security management module, comprise counting module, relay, IC-card intelligent electric energy meter terminal master controller and memory, described counting module accesses power input on electric energy meter and IC-card intelligent electric energy meter terminal master controller respectively, for measuring power consumption, and variable is exported to IC-card intelligent electric energy meter terminal master controller, described relay accesses power input on electric energy meter and power output end respectively, described IC-card intelligent electric energy meter terminal master controller is by control relay circuit cut-in relay, for closing and disconnecting by IC-card intelligent electric energy meter terminal main controller controls relay, described memory also accesses IC-card intelligent electric energy meter terminal master controller, unlike the prior art, information security management module is also comprised in described IC-card intelligent electric energy meter, described information security management module comprises processor, the first data-interface, the second data-interface and FLASH memory, described processor accesses the first data-interface, the second data-interface and FLASH memory respectively, wherein:
Above-mentioned first data-interface access IC card information Switching Module, its effect performs IC-card intelligent electric energy meter to communicate with the unique data of IC card information Switching Module, and transmit it to processor when receiving the external data coming from IC card information Switching Module;
The effect of above-mentioned FLASH memory stores control in information security management module and documentor;
Above-mentioned second data-interface access IC-card intelligent electric energy meter terminal master controller, its effect performs the data communication between processor and IC-card intelligent electric energy meter terminal master controller, and the effect of IC-card intelligent electric energy meter terminal master controller performs the operation of respective table end according to the instruction of processor;
The effect of above-mentioned processor is when receiving the external data coming from the first data-interface, authentication is carried out to the management system for selling power of write external data, judge whether to obtain the encrypted packets in this external data, and send corresponding operational order by the second data-interface to IC-card intelligent electric energy meter terminal master controller according to the affairs comprised in data.
According to above-mentioned technical scheme, the technical problem that the present embodiment solves is the information security management module by above-mentioned composition structure, data retransmission is carried out between IC-card intelligent electric energy meter terminal master controller and management system for selling power, and give certification and encryption and decryption when forwarding, thus coordinate the IC-card intelligent electric energy meter of Utilities Electric Co. to terminal to manage, to eliminate the risk of information security management in Utilities Electric Co.'s operation.
And the Oscillator module shown in Fig. 1 and pin XIN, XOUT provide clock signal to information security management module; RAM memory is used for the operating ephemeral data of memory module; VCC and VSS two pins provides working power for information security management module, and this power supply should be continued power and can not be provided by IC-card intelligent electric energy meter terminal master controller pin.And go out as shown in Figure 1, in the present embodiment, the memory of above-mentioned access IC-card intelligent electric energy meter terminal master controller preferably adopts eeprom memory.
Shown in Fig. 1, in the embodiment that the present invention is more preferably for technical solution problem, the concrete mode that a kind of above-mentioned processor performs management system for selling power authentication and affairs is provided, namely when processor receives the external data coming from the first data-interface, according to external data, authentication is carried out to management system for selling power, when authentication result is judged as legal, then encrypted packets is decrypted and completeness check, on the contrary the original state that then resets;
After data integrity verifying passes through, the validity of data is verified, on the contrary the original state that then resets;
After Validation of Data is passed through, pretreatment is carried out to the affairs comprised in data, and from IC-card intelligent electric energy meter terminal master controller, obtain corresponding return information by the second data-interface, IC card information Switching Module is returned to by the first data-interface by after described return information encryption, then pre-processed results approved after effectively being confirmed and stored relevant operation information, and to IC-card intelligent electric energy meter terminal master controller transmit operation instruction; Such as, otherwise then abandon pre-processed results or make caching process, namely do not receive the confirmation result of IC card information Switching Module within the time preset, do not receive the confirmation of IC card information Switching Module in three minutes, then reset original state; Aforesaid caching process refers to keeps in pre-processed results instruction, when processor is again waken up and receives the confirmation of IC card information Switching Module, then in the same way to IC-card intelligent electric energy meter terminal master controller transmit operation instruction.
The whole flow process of the present embodiment peripheral data from management system for selling power authentication to affairs wherein performed by processor is contained in above-mentioned technical scheme, by the programming of above-mentioned flow process, further enhance in information security management module the security receiving information and executing.And the above-mentioned processor reset original state repeatedly mentioned, be resetting processor and perform the state before any one operation above-mentioned, it is resting state that such as processor carried out the state of authentication before receiving external data, be waken up by resting state when receiving external data, but when being judged as illegal to the authentication of management system for selling power, processor then recovers resting state, do not carry out any operation, in other step, the situation of processor reset also substantially as hereinbefore, when failing the authentication, operation note can be stored by processor.Above-mentioned mentioned management system for selling power can be the terminal electric energy meter management system that Utilities Electric Co. is set up in actual applications simultaneously.
And it is same, in another embodiment of the invention, for realizing being managed the information security management module in terminal IC-card intelligent electric energy meter by different rights, need in above-mentioned FLASH memory preset agreement restrictive condition and multiple different cipher key procedures, it act as when the subsystem of information security management module classification different from management system for selling power respectively carries out exchanges data, processor according to the encryption key of external data compared with multiple cipher key procedures preset in FLASH memory, thus the identity of certification management system for selling power, and after encrypted packets deciphering and completeness check are passed through, according to the validity of agreement restrictive condition verification msg under current identity, judge whether to carry out pretreatment to the affairs in data.
According to another embodiment of the present invention, as mentioned here above, for ease of the buffer memory of processor pre-processed results, in information security management module, also relatively independent eeprom memory can be set, and eeprom memory is also accessed processor, for the associative operation information of storage of processor to IC-card intelligent electric energy meter terminal master controller, processor is to the pre-processed results of affairs in external data, and the failure record of processor checking, and in FLASH memory, be also provided with other program that can be utilized by processor, namely processor to the associative operation information of IC-card intelligent electric energy meter terminal master controller once be stored to after in eeprom memory, by unsuppressible-suppression and amendment, to make the running status of information security management module leave complete record.
Shown in Fig. 1, be embedded with in the IC-card intelligent electric energy meter practical application of information security management module in above-described embodiment, be as good as with existing IC-card intelligent electric energy meter, IC-card intelligent electric energy meter master controller read data information from electric energy meter counting module, and the initial value of EPPROM memory storage is deducted according to data message, IC-card intelligent electric energy meter master controller connects buzzer by surplus judging circuit, when charge value is about to use up, send alarm sound prompting user to need to supplement with money, IC-card intelligent electric energy meter master controller is also by the action of control relay circuit control relay, play the effect of control power supply break-make,
When after the power input on power supply input electric energy meter, enter the VI pulse amplifier in counting module, for improving load capacity and reducing load to the impact of signal source in intelligent electric energy meter, and with the jamproof ability of increase; Then two mutual incoherent signal multiplications are realized by analog multiplier, namely output signal is directly proportional to input signal phase product, be transferred to pulse counter by V/F converter again, after pulse counter counting, send data to IC-card intelligent electric energy meter terminal master controller and process; Also voltage detecting circuit is provided with, for detecting the voltage strength of power input to input VI pulse amplifier between power input on described VI pulse amplifier and electric energy meter.
Above-mentioned memory is for storing the presell electric quantity data information coming from information security management module forwards, described IC-card intelligent electric energy meter terminal master controller is also connected with LCDs by liquid crystal display circuit, for being deducted the presell electric quantity data information initial value stored in memory according to the variable in counting module by IC-card intelligent electric energy meter terminal master controller, and presented on LCDs by liquid crystal display circuit; All exchange data of management system for selling power and IC-card intelligent electric energy meter all have to pass through information security management module and arrive IC-card intelligent electric energy meter terminal master controller, IC-card intelligent electric energy meter terminal master controller is according to the instruction received, complete corresponding operation, such as when the balance depletion of supplementing with money in subscriber's meter, IC-card intelligent electric energy meter terminal master controller completes the shutoff action of relay by control relay circuit, and then stops power supply.
The core of the information security management module that above-described embodiment is mentioned is processor, for performing corresponding program and data encryption, in another embodiment of the present invention, above-mentioned processor is directly adopt in prior art can perform AES or such as, with the central processing unit of ready-made AES or single-chip microcomputer, EFM32 etc.
Based on data communication mode required in above-described embodiment, inventor, with reference to prior art, is IC-card interface for what carry out that the first data-interface of unique communication adopts with IC card information Switching Module in above-described embodiment.
And it is corresponding, the second data-interface that in above-described embodiment, processor and IC-card intelligent electric energy meter terminal master controller carry out communicating preferably matches with conventional master controller, the serial line interfaces such as such as USART interface, SPI interface or I2C interface, to increase the compatibility on information security management module integration and IC-card intelligent electric energy meter.
Shown in Fig. 1, for ensureing the security of data encryption and solution in the information security management module in intelligent electric energy meter further, preferably independently encrypting module is set therein, and by this independently encrypting module access processor, for to information security management module and management system for selling power, the multistage encryption and decryption of information security management module and IC-card intelligent electric energy meter terminal master controller exchanges data, and the data encryption key that auxiliary processor obtains management system for selling power carries out authentication, and the cipher mode that in reference prior art, security is higher, Advanced Encryption Standard in preferred employing AES(cryptography, the abbreviation of English AdvancedEncryption Standard) or the triple DEA of 3DES(, English Triple DataEncryption Algorithm) encryption and decryption is carried out to the data of coming and going in information security management module.
Shown in Fig. 3, after IC-card intelligent electric energy meter embeds above-mentioned information security management module, the outside all communication datas of intelligent electric energy meter are all by forwarding after information security management module encryption and decryption, and the internal processes of information security management module is unique, therefore information security management module can be considered as terminal by management system for selling power, in order to manage IC-card intelligent electric energy meter, namely with the compatible various brand of a management system for selling power, the IC-card intelligent electric energy meter of type is managed concentratedly, effective reduction Utilities Electric Co. is to different brands in region, the difficulty of type electric energy meter integration management.
Than that described above, also it should be noted that spoken of in this manual " embodiment ", " another embodiment ", " embodiment " etc., refer to the specific features, structure or the feature that describe in conjunction with this embodiment and be included at least one embodiment of the application's generality description.Multiple place occurs that statement of the same race is not necessarily refer to same embodiment in the description.Furthermore, when describing specific features, structure or a feature in conjunction with any embodiment, what advocate is also fall within the scope of the invention to realize this feature, structure or feature in conjunction with other embodiments.
Although with reference to multiple explanatory embodiment of the present invention, invention has been described here, but, should be appreciated that, those skilled in the art can design a lot of other amendment and embodiment, these amendments and embodiment will drop within spirit disclosed in the present application and spirit.More particularly, in the scope of, accompanying drawing open in the application and claim, multiple modification and improvement can be carried out to the building block of subject combination layout and/or layout.Except the modification of carrying out building block and/or layout is with except improvement, to those skilled in the art, other purposes also will be obvious.