Summary of the invention
One of purpose of the present invention is at above-mentioned deficiency, a kind of remote-control intelligent electric energy meter information security management module is provided, information security management with various types of remote-control intelligent electric energy meters and management system thereof in the expectation solution prior art can not get problems such as assurance, thereby eliminates the risk of information security management in Utilities Electric Co.'s operation.
For solving above-mentioned technical matters, the present invention by the following technical solutions:
A kind of remote-control intelligent electric energy meter information security management module provided by the present invention, described information security management module comprises processor, first data-interface, second data-interface and FLASH storer, described processor inserts first data-interface, second data-interface and FLASH storer respectively, wherein:
Described first data-interface is used to carry out the remote-control intelligent electric energy meter communicates by letter with the unique data of data transmission module, and transmits it to processor when receiving the external data that comes from data transmission module; Described data transmission module directly receives the external data that comes from long-range management system for selling power;
Described FLASH storer is used for the control and the documentor of canned data safety management module;
Described second data-interface is used to carry out the data communication between processor and the remote-control intelligent electric energy meter terminal master controller, and described remote-control intelligent electric energy meter terminal master controller is used for carrying out the operation of corresponding table end according to the instruction of processor;
Described processor is used for when receiving the external data that comes from first data-interface, the management system for selling power that sends external data is carried out authentication, judge whether to obtain the encrypted packets in this external data, and send corresponding operational order by second data-interface to remote-control intelligent electric energy meter terminal master controller according to the affairs that comprise in the data.
As preferably, further technical scheme is: described processor is used for when receiving the external data that comes from first data-interface, according to external data management system for selling power is carried out authentication, when authentication result is judged as when legal, then encrypted packets is decrypted and completeness check, on the contrary the original state that then resets;
After data integrity verifying passes through, the validity of data is verified, on the contrary the original state that then resets;
After Validation of Data is passed through, the affairs that comprise in the data are carried out pre-service, and from remote-control intelligent electric energy meter terminal master controller, obtain corresponding return message by second data-interface, described return message is encrypted the back return to data transmission module by first data-interface, after effectively being confirmed, then the pre-service result is approved and stored relevant operation information, and instructed to the transmit operation of remote-control intelligent electric energy meter terminal master controller; Otherwise then abandon the pre-service result or make caching process.
Further technical scheme is: preset protocols limit condition and a plurality of different cipher key procedures in the described FLASH storer, be used for when the information security management module is carried out exchanges data with the subsystem of the different classifications of management system for selling power respectively, processor is compared according to a plurality of cipher key procedures that preset in the encryption key of external data and the FLASH storer, thereby the identity of authentication management system for selling power, and after encrypted packets deciphering and completeness check pass through, according to the validity of protocols limit condition verification msg under current identity, judge whether the affairs in the data are carried out pre-service;
Described first data-interface also inserts the IC information exchange module, be used for transmitting it to when receiving the external data that comes from the IC information exchange module processor, processor is carried out the verification identical with the external data that comes from data transmission module to described external data.
Further technical scheme is: also comprise eeprom memory in the described information security management module, described eeprom memory also inserts processor, be used for the associative operation information of storage of processor, and processor is to the pre-service result of affairs in the external data to remote-control intelligent electric energy meter terminal master controller.
Further technical scheme is: described processor is for carrying out the central processing unit or the single-chip microcomputer of cryptographic algorithm; Described data transmission module is network communication module or bus communication module.
Further technical scheme is: described first data-interface is network communication interface or bus interface.
Further technical scheme is: described network communication interface is at least any one in the middle of RF module interface, Zigbee module interface, WiFi module interface, bluetooth module interface, infrared module interface or Optical Fiber Transmission interface, data line transmission interface, the power line transmission interface; Described bus interface is at least any one in the middle of the Mbus bus interface, RS485 bus interface, CAN bus interface.
Further technical scheme is: described second data-interface is at least any one in the middle of USART serial line interface, SPI serial line interface or the I2C serial line interface.
Further technical scheme is: described information security management module also comprises encrypting module, described encrypting module inserts processor, be used for multistage encryption and decryption, and the data encryption key that auxiliary processor obtains management system for selling power carries out authentication to information security management module and management system for selling power, remote-control intelligent electric energy meter terminal master controller exchanges data.
Further technical scheme is: described encrypting module is by the Advanced Encryption Standard in the AES(cryptography, the abbreviation of English Advanced Encryption Standard) or the triple data encryption algorithm of 3DES(, mode English Triple Data Encryption Algorithm) is carried out data encrypting and deciphering.
Compared with prior art, one of beneficial effect of the present invention is: the information security management module is carried out authentication when carrying out exchanges data by data transmission module and management system for selling power, guaranteed the legitimacy of both communication, remote-control intelligent electric energy meter terminal master controller must could communicate with the outside by the information security management module; Utilize different keys can realize the authority setting of Utilities Electric Co.'s differentiated control, and adopt 3DES/AES multi-level encryption mode, make that the security of key is higher, and upgrading key can download cause for gossip by the program on the information security management module time, avoid key to leak the risk of being brought; By built-in data verifying program, guarantee that the data of transmission are true, accurate, complete.A kind of remote-control intelligent electric energy meter information security management modular structure provided by the present invention is simple simultaneously, can embed in various types of remote-control intelligent electric energy meters, by multiple communication transmission technology and the compatible remote-control intelligent electric energy meter of bus interface terminal master controller, there is no and sew up into the power supply management system, realize that the remote-control intelligent electric energy meter disperses to make, unified management, range of application is wide, and guarantee the independence of Utilities Electric Co. in electric energy meter control, and be not subjected to extraneous restriction.
Embodiment
The present invention is further elaborated below in conjunction with accompanying drawing.
With reference to shown in Figure 1, one embodiment of the present of invention are a kind of remote-control intelligent electric energy meter information security management modules, described information security management module comprises processor, first data-interface, second data-interface and FLASH storer, described processor inserts first data-interface, second data-interface and FLASH storer respectively, wherein:
The effect of above-mentioned first data-interface is to carry out the remote-control intelligent electric energy meter to communicate by letter with the unique data of data transmission module, and transmits it to processor when receiving the external data that comes from data transmission module; Described data transmission module directly receives the external data that comes from long-range management system for selling power;
The effect of above-mentioned FLASH storer is control and the documentor in the canned data safety management module;
With reference to shown in Figure 1, the effect of above-mentioned second data-interface is the data communication of carrying out between processor and the remote-control intelligent electric energy meter terminal master controller, and the effect of remote-control intelligent electric energy meter terminal master controller is to carry out the operation of respective table end according to the instruction of processor;
The effect of above-mentioned processor is when receiving the external data that comes from first data-interface, the management system for selling power that sends external data is carried out authentication, judge whether to obtain encrypted packets in this external data, and send corresponding operational order by second data-interface to remote-control intelligent electric energy meter terminal master controller according to the affairs that comprise in the data.
According to above-mentioned technical scheme as can be known, the technical matters that present embodiment solved is the information security management module by above-mentioned composition structure, between remote-control intelligent electric energy meter terminal master controller and management system for selling power, carry out data forwarding, and when transmitting, authenticated and encryption and decryption, thereby cooperate Utilities Electric Co. that the intelligent electric energy meter of terminal is managed, to eliminate the risk of information security management in Utilities Electric Co.'s operation.
And the Oscillator module shown in Fig. 1 and pin XIN, XOUT provide clock signal to the information security management module; The RAM storer is used for the operating ephemeral data of memory module; VCC and VSS two pins provide working power for the information security management module, and this power supply should be a continued power and can not being provided by the pin of remote-control intelligent electric energy meter terminal master controller.
Again with reference to shown in Figure 1, be used for the embodiment that the technical solution problem is more preferably in the present invention, the concrete mode of a kind of above-mentioned processor to management system for selling power authentication and affairs execution is provided, promptly when processor receives the external data that comes from first data-interface, according to external data management system for selling power is carried out authentication, when authentication result is judged as when legal, then encrypted packets is decrypted and completeness check, on the contrary the original state that then resets;
After data integrity verifying passes through, the validity of data is verified, on the contrary the original state that then resets;
After Validation of Data is passed through, the affairs that comprise in the data are carried out pre-service, and from remote-control intelligent electric energy meter terminal master controller, obtain corresponding return message by second data-interface, described return message is encrypted the back return to data transmission module by first data-interface, after effectively being confirmed, then the pre-service result is approved and stored relevant operation information, and instructed to the transmit operation of remote-control intelligent electric energy meter terminal master controller; Otherwise then abandon the pre-service result or make caching process, promptly do not receive the affirmation result of data transmission module in the predefined time, for example do not receive the affirmation information of data transmission module in three minutes, original state then resets; Aforesaid caching process is meant keeps in the pre-service object command, when processor is waken up and receives the affirmation information of data transmission module once more, then instructs to the transmit operation of remote-control intelligent electric energy meter terminal master controller in the same way.
The affairs from the management system for selling power authentication to external data of external data in the present embodiment have also been comprised in the above-mentioned technical scheme by the performed whole flow process of processor, by the program setting of above-mentioned flow process, further strengthened in the information security management module receiving the security of information and executing.And the above-mentioned processor reset original state of repeatedly mentioning, be the state of resetting processor before carrying out above-mentioned any one operation, for example to carry out the state of authentication before receiving external data be dormant state to processor, when receiving that external data is waken up by dormant state, but the authentication of management system for selling power is judged as when illegal, processor then recovers dormant state, do not carry out any operation, the situation of processor reset also substantially as hereinbefore in other step, when authentication failed, processor can be stored operation note.
And it is same, in another embodiment of the present invention, for realizing the information security management module being managed by different rights, need in above-mentioned FLASH storer, to preset protocols limit condition and a plurality of different cipher key procedures, its act as the information security management module respectively with management system for selling power in the subsystem of different classifications when carrying out exchanges data, processor is compared according to a plurality of cipher key procedures that preset in the encryption key of external data and the FLASH storer, thereby the identity of authentication management system for selling power, and after encrypted packets deciphering and completeness check pass through, according to the validity of protocols limit condition verification msg under current identity, judge whether the affairs in the data are carried out pre-service;
With reference to shown in Figure 2, for satisfying the present greatly how far inner structure of control electric energy meter, above-mentioned first data-interface also inserts the IC information exchange module, be used for transmitting it to when receiving the external data that comes from the IC information exchange module processor, processor is carried out the verification identical with the external data that comes from data transmission module to described external data.
According to another embodiment of the present invention, mention as above-mentioned, buffer memory for ease of processor pre-service result, in the information security management module, also relatively independent eeprom memory can be set, and eeprom memory also inserted processor, be used for the associative operation information of storage of processor to remote-control intelligent electric energy meter terminal master controller, processor is to the pre-service result of affairs in the external data, and the failure record of processor checking, and in the FLASH storer, also be provided with other program that to be utilized by processor, after in a single day be processor be stored in the eeprom memory to the associative operation information of remote-control intelligent electric energy meter terminal master controller, with unsuppressible-suppression and modification, so that make the running status of information security management module stay complete record.
With reference to shown in Figure 2, remote-control intelligent electric energy meter information security management module in the foregoing description in actual applications, insert between remote-control intelligent electric energy meter terminal master controller and the data transmission module, and the inner structure of electric energy meter and existing remote-control intelligent electric energy meter are as good as, itself contain multiple functional module, as pulse counter module, memory module, display module, relay control module, surplus reminding module etc., these modules are by being connected with remote-control intelligent electric meter terminal master controller, finish the correlation function of remote-control intelligent electric meter, measure as finish power consumption with pulse counter module, display module shows power consumption and dump energy, relay control module is as the power on/off switch, the surplus reminding module should be purchased electricity operation or the like as early as possible by hummer prompting prompting user before purchasing electric weight is about to use up.
And according to above-mentioned principle, this remote-control intelligent electric meter information security management module can directly integratedly be applied in the conventional remote-control intelligent electric meter, carries out exchanges data by data transmission module with wireless or wired mode and long-range management system for selling power; And in addition, the improvement of going back adaptability is applied to other carries out telemanagement by electronic information measuring apparatus.
The processor that the foregoing description is mentioned is the core of information security management module, be used to carry out corresponding program and data encryption, in another embodiment of the present invention, above-mentioned processor is for directly adopting central processing unit or the single-chip microcomputer that can carry out cryptographic algorithm in the prior art, for example EFM32 etc.
Based on data communication mode required in the foregoing description, the inventor is with reference to prior art, selected for use the transmission technology of part in the prior art to realize communicating by letter between processor and the interface, wherein data transmission module can adopt network communication module or bus communication module, and corresponding with aforesaid data transmission module, be used for carrying out unique first data-interface of communicating by letter in the foregoing description and can adopt network communication interface or bus interface with data transmission module.
Further, above-mentioned network communication interface can adopt wireless or wired form, radio network interface can adopt one or more in the middle of RF module interface, Zigbee module interface, WiFi module interface, infrared module interface and the bluetooth module interface, and wired network interface can adopt one or more in the middle of Optical Fiber Transmission interface, data line transmission interface and the power line transmission interface; In the middle of the above-mentioned bus interface Mbus bus interface, RS485 bus interface, CAN bus interface one or more.
And it is corresponding, second data-interface that processor and remote-control intelligent electric energy meter terminal master controller communicate in the foregoing description preferably is complementary with conventional master controller, serial line interfaces such as USART interface, SPI interface or I2C interface for example, with increase the information security management module integrated with intelligent electric energy meter on compatibility.
Again with reference to shown in Figure 1, security for data encryption and deciphering in the administration module that further ensures information security, be preferably in its inside independently encrypting module is set, and with this independently encrypting module insert processor, be used for information security management module and management system for selling power, the multistage encryption and decryption of remote-control intelligent electric energy meter terminal master controller exchanges data, and the data encryption key that auxiliary processor obtains management system for selling power carries out authentication, and with reference to the higher cipher mode of security in the prior art, the preferred Advanced Encryption Standard that adopts in the AES(cryptography, the abbreviation of English Advanced Encryption Standard) or the triple data encryption algorithm of 3DES(, English Triple Data Encryption Algorithm) data of coming and going in the information security management module are carried out encryption and decryption.
Again with reference to shown in Figure 3, after the integrated above-mentioned information security management module of remote-control intelligent electric energy meter that a plurality of different vendors produce, outside all communication datas of electric energy meter are all by transmitting after the information security management module encryption and decryption, and the internal processes of information security management module is unique, therefore management system for selling power can be considered as terminal with the information security management module, in order to the management intelligent electric energy meter, promptly with the compatible various brands of a management system for selling power, the intelligent electric energy meter of type is managed concentratedly, effectively reduces Utilities Electric Co. to different brands in the zone, the difficulty of the intelligent electric energy meter integration management of type.As shown in Figure 3, the communication path of remote-control intelligent electric energy meter and management system for selling power is: the table end passes through the upper strata multistage communication device, as collector, and repeater, concentrators etc. directly arrive management system for selling power.By above-mentioned path, the direct and management system for selling power realization data transmission of table end.
Except that above-mentioned, " embodiment ", " another embodiment " that also need to prove in this manual to be spoken of, " embodiment " etc. refer to concrete feature, structure or the characteristics described in conjunction with this embodiment and are included among at least one embodiment that the application's generality describes.A plurality of local appearance statement of the same race is not necessarily to refer to same embodiment in instructions.Furthermore, when describing a concrete feature, structure or characteristics in conjunction with arbitrary embodiment, what advocate is to realize that in conjunction with other embodiment this feature, structure or characteristics also fall within the scope of the invention.
Although invention has been described with reference to a plurality of explanatory embodiment of the present invention here, but, should be appreciated that those skilled in the art can design a lot of other modification and embodiments, these are revised and embodiment will drop within the disclosed principle scope and spirit of the application.More particularly, in the scope of, accompanying drawing open and claim, can carry out multiple modification and improvement to the building block and/or the layout of subject combination layout in the application.Except modification that building block and/or layout are carried out with improving, to those skilled in the art, other purposes also will be tangible.