A secure aggregation method based on random exchange and key homomorphic pseudorandom function

By adopting a secure aggregation method of random exchange and key homomorphic pseudo-random functions in the smart grid, the problem of complex protocols and trusted third parties in the existing technology is solved, and efficient and robust secure data aggregation is achieved, supporting user management and result accuracy, and strong applicability.

CN116388967BActive Publication Date: 2025-08-22CHINA UNIV OF GEOSCIENCES (WUHAN)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211736737.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-08-22
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

The existing secure data aggregation method for privacy protection in smart grids has complex protocols and complex encryption algorithms, resulting in large computing volume and poor performance, and requires trusted third parties to participate and is inflexible, making it difficult to ensure the availability and security of protocols in the case of user addition, exit and network delay.

Method used

A secure aggregation method based on random exchange and key homomorphic pseudo-random functions is adopted, including initialization, transmission, decryption and management stages. Through random number exchange and ciphertext calculations between users, secure aggregation without the need for trusted third parties is achieved, and a variety of solutions are adapted to facilitate user management and result accuracy.

Benefits of technology

It realizes efficient and robust security aggregation, adapts to multiple solutions, light-weight user management, supports user addition and deletion, and the results are safe and accurate, highly applicable, and there is no need for trusted third parties to participate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116388967B_ABST
    Figure CN116388967B_ABST
Patent Text Reader

Abstract

The present invention provides a secure aggregation method based on random exchange and key homomorphic pseudorandom functions, specifically comprising: in an initial stage, a user randomly selects n other users and exchanges the generated random numbers with them respectively; after the exchange, the total amount of the users' random numbers is calculated and sent to a control center; in a sending stage, a ciphertext is formed by a modular addition homomorphic operation based on the current time period, the user's electricity consumption, and the key obtained in the initial stage, and the ciphertext is summed up at the gateway and sent to the control center; in a decryption stage, the obtained ciphertext sum and the total amount of random numbers corresponding to the ciphertext sum are decrypted to obtain the total electricity consumption; in a management stage, new users are added, old customers are withdrawn, or the user's smart meter malfunctions are managed. The beneficial effects of the present invention are: no trusted third party is required, multiple solutions are adaptable, implementation is convenient, user management is lightweight, and while ensuring the security and accuracy of the results, additions and deletions can be freely made, resulting in strong applicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of smart grids, and in particular to a security aggregation method based on random exchange and key homomorphic pseudorandom functions. Background Art

[0002] Common methods for achieving privacy-preserving secure data aggregation in smart grids include homomorphic encryption and noise addition. However, implementations of these solutions often suffer from complex protocols or encryption algorithms, resulting in high computational complexity, poor performance, or security risks. Among feasible solutions, some require the involvement of a trusted third party, which is challenging to implement in practice. Others lack flexibility, making it difficult to guarantee protocol availability and security under the conditions of user additions and deletions, as well as network latency, required in real-world deployments. Summary of the Invention

[0003] To address the above issues, the present invention provides a secure aggregation method based on random exchange and key homomorphic pseudorandom functions, which is efficient, robust, and does not require a trusted third party. The method mainly includes: initialization phase, sending phase, decryption phase, and management phase;

[0004] In the initial stage, the user randomly selects n other users and exchanges the generated random numbers with each of them. That is, the user sends the random number he or she obtains to the user to be exchanged, and the user to be exchanged also sends his or her random number to the user. The n other users need to exchange n times. After the exchange is completed, the total amount of random numbers of the users is calculated and sent to the control center.

[0005] In the sending phase, a ciphertext is generated through modular addition homomorphic operations based on the current time period, the user's power consumption, and the key obtained in the initial phase. This is then sent to the gateway, where the ciphertext is summed and sent to the control center.

[0006] In the decryption phase, the total ciphertext obtained by the control center and the total random number corresponding to the ciphertext are decrypted to obtain the total power consumption;

[0007] During the management stage, management is carried out for situations where new users join, old customers withdraw, or users’ smart meters malfunction.

[0008] Furthermore, the exchange method in the initial stage adopts traditional key exchange or quantum-resistant key exchange.

[0009] Furthermore, the total amount of random numbers is calculated using the following formula:

[0010]

[0011] Among them, m+k is the total number of random numbers, m is the number of random number exchanges, k is the number of additional random numbers generated, R i,j SM for users i The jth random number.

[0012] Furthermore, the ciphertext c i The calculation formula is:

[0013]

[0014] Among them, m i is the power consumption, F is the key homomorphic pseudo-random function, is the modulus, R' i is the sum of m+k random numbers after replacement.

[0015] Furthermore, the calculation formula for the sum of ciphertexts is: C = ∑c i .

[0016] Furthermore, when a new user joins, a list of SMs that can be exchanged is obtained from the gateway, and then the total power consumption is finally obtained after the operations of the initial stage, the sending stage, and the decryption stage.

[0017] Furthermore, when an old user quits, during the sending phase, the gateway learns that the old user has not sent ciphertexts on a periodic basis, and the old user is informed of his / her quitting within the BAN. All users who exchanged random numbers with the old user restore the random numbers before the exchange, and recalculate the total random numbers and ciphertexts exchanged with the old user. The sum of the ciphertexts is then calculated, and the decoding phase is performed to obtain the total power consumption.

[0018] Furthermore, when a user's smart meter fails, it is processed as an old user exiting before modification, and as a new user joining after modification.

[0019] The beneficial effects of the technical solution provided by the present invention are: the present invention does not require a trusted third party, is adaptable to multiple solutions, is easy to implement, and has lightweight user management. While ensuring the security and accuracy of the results, it can also be freely added and deleted, and has strong applicability. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The present invention will be further described below with reference to the accompanying drawings and embodiments, in which:

[0021] Figure 1 2 is a working scenario diagram of the smart grid in an embodiment of the present invention.

[0022] Figure 2 It is an abstract diagram of the smart grid application scenario in the embodiment of the present invention.

[0023] Figure 3This is a flowchart of a secure aggregation method based on random exchange and key homomorphic pseudorandom function in an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to have a clearer understanding of the technical features, purposes and effects of the present invention, specific embodiments of the present invention are now described in detail with reference to the accompanying drawings.

[0025] The embodiment of the present invention provides a security aggregation method based on random exchange and key homomorphic pseudo-random function, which can be applied to multiple fields. The application scenario of this embodiment is one of the fields, such as Figure 1 As shown, Figure 1 The working scenario of smart grid is shown. The power consumption of multiple electrical appliances will be sent to the control center through the network. The control center will use the power consumption to carry out power distribution, electricity price setting and other services. Figure 2 As shown, within a certain range, multiple electricity consumption points are assigned their own smart meters (SM). The SM will count the electricity consumption within a unit time, such as every 15 minutes, and then periodically report it to the gateway (GW). The GW will count and integrate the reported information and report the organized electricity consumption information corresponding to its management range to the control center (CC). The CC receives messages from multiple different GWs and obtains the actual electricity consumption information to carry out various tasks.

[0026] In the above application scenario, a secure aggregation method based on random exchange and key homomorphic pseudorandom function is proposed. Figure 3 As shown in the figure, it specifically includes four phases: initialization phase, sending phase, decryption phase and management phase. The initialization phase is only performed once in the initial deployment, after which the sending phase and decryption phase can be performed periodically. An SM can be regarded as a user participating in the aggregation. When the user (i.e., SM) changes, the management phase will be introduced in real time to make adjustments. Figure 3 SM refers to each smart meter participating in the aggregation. The specific contents of each stage are as follows:

[0027] 1. Initialization phase:

[0028] Each SM randomly selects n other users to perform random exchanges between smart meters, that is, each SM exchanges a random number generated by itself with n other users once. The exchange is carried out in a secure way, which can use traditional key exchange, such as Diffie-Hellman key exchange, or quantum-resistant key exchange, such as Kyber exchange. i For example, SM iRandomly select a user SM in the user group who has not exchanged with him before j , and generate a random number R for this purpose i,x With user SM j Exchange and obtain user SM j Also randomly selected random number R j,y , denoted as R' i,x . Among them, x, y are the serial numbers of the random numbers of each user. Because there are n other users, n exchanges are required. Whether you actively select other users to exchange or are selected as the exchange target, it will be counted in this number. After n times, SM i Will no longer actively select other users to exchange, but will try to respond to SM selection after this i The user who exchanges, that is, the SM i Respond as the chosen one.

[0029] When the exchange is complete, set SM i If a total of m (m>n) exchanges are performed, m random numbers will be generated for the exchanges, that is, m is SM i The total number of random number exchanges between the active and passive agents, SM i An additional k random numbers will be generated (k>n), so SM i The total number of random numbers generated R i Including R i,1 , R i,2 ,……,R i,m+k , Afterwards, SM i The calculated R i It is also sent to the CC in a secure manner (such as Diffie-Hellman key exchange).

[0030] The value ranges of n, k, and the random number R are all public parameters and will be given at the beginning.

[0031] At the same time, after the exchange is completed, SM i You will get the R i,x The number of random numbers corresponding to m other users. SM i The original R will be replaced one by one in order. i,x And record the replaced m+k random numbers as R' i,1 , R' i,2 ,……,R' i,m+k , and calculate SM i It will also record which users it has exchanged with and which random numbers it has exchanged with. This will be used in subsequent user management.

[0032] 2. Sending phase:

[0033] SM i Periodically count your own electricity consumption m i And use the deployed key homomorphic pseudo-random number generation function F and the current time period T to generate the ciphertext c i , The value range of the key homomorphic pseudorandom function F is greater than the sum of all possible m. The subsequent addition and subtraction operations will be performed on the modulus Therefore, the subsequent calculations are omitted. Ciphertext c i The generation formula is as follows:

[0034]

[0035] Key homomorphic pseudorandom function F and modulus It was given at the beginning.

[0036] The generated ciphertext c i Send it to GW, which counts the number of SM users and calculates the sum of ciphertexts C = ∑c i , and then send C to CC; the sending phase calculates the sum of ciphertext C, the decryption phase calculates the total power consumption M and the proof process, and its equations must be in Established below.

[0037] 3. Decryption phase:

[0038] CC obtains the total ciphertext C sent by GW and the SM that is not reported regularly. First, calculate the total number of random numbers corresponding to the SM that participated in reporting this ciphertext R = ∑R i , then calculate the total power consumption of all SMs M = ∑m i =CF R (T), the proof process is:

[0039] C=∑c i =∑m i +∑F R'i (T)=M+F ∑R'i (T)

[0040] Because, ∑R i =∑R ij =∑R' ij =∑R' i , so, ∑R i =∑R' i .

[0041] 4. User management stage:

[0042] New user added:

[0043] When a new user SM u To join, you must first ask the GW for a list of SMs that can be exchanged. The GW will inform the SM of the list of SMs that can be exchanged based on the number of SMs in the BAN (building area networks) and the number of SMs that have been reported and cannot be exchanged. u , SM u Generate n+k random numbers R as in the initialization phase u,1 ,R u,2 ,……,R u,n+k , randomly select n SMs from the list to exchange, and Send to CC. After that, SM u Calculate R' u , the n SMs exchanged with it also need to recalculate their respective R' i , and then the periodic sending phase can proceed normally. If this causes a SM i Swap out all m+k-1 random numbers. Then SM i This situation will be sent to the GW, so that the SM to be exchanged later will no longer i As the exchange object. The k random numbers in the initialization phase are prepared for the newly added smart meters. The newly added smart meters may choose SM i As an exchange object, in order to continuously add new smart meters to the entire aggregation system, the number of exchanges n required for each smart meter added must not be greater than the number of exchanges that can be provided after the smart meter is added, that is, the number of random numbers k.

[0044] Exit of old users:

[0045] When an old user SM u When exiting, it often cannot give a message. In the sending phase, when GW statistics find SM u If the ciphertext is not sent periodically, the GW will broadcast it within the BAN to inform the SM u Exit, all with SM u SMs that have undergone exchange (including initialization phase and new user addition) i Will exchange himself for R' i,x Restore to unswapped R i,x , recalculate R' and c i , the new c i Send it to GW. If the number of exchanges made by GW is less than m+k-1 and it can continue to be the target of exchange, GW will be informed as well. After calculating C, GW will compare C with the exiting SM. u Send it to CC, CC will then send R u Removed from the decryption phase.

[0046] User smart meter failure: When a user's smart meter fails, it cannot send messages as scheduled and is considered an old user. Therefore, when the user's smart meter failure is repaired, it will rejoin and perform random number exchange as a new user.

[0047] This invention protects user privacy through a cleverly designed randomized key exchange protocol, enabling secure data aggregation and user management, and exhibiting excellent scalability. While providing a robust secure aggregation design framework, it also does not restrict specific key exchange or key-homomorphic pseudorandom number generation functions. This allows for multiple implementation options, adapting to standard models, random oracle models, and even enabling quantum-resistant implementations.

[0048] The beneficial effects of the present invention are: the present invention does not require a trusted third party, is adaptable to multiple solutions, is easy to implement, and has lightweight user management. While ensuring the safety and accuracy of the results, it can also be freely added and deleted, and has strong applicability.

[0049] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A secure aggregation method based on random exchange and key homomorphic pseudorandom function, characterized by: include: Initialization phase, sending phase, decryption phase and management phase; In the initial stage, the user randomly selects n other users and The random numbers generated are exchanged once, that is, the user sends the random number he obtained to the user to be exchanged, and the user to be exchanged also sends his random number to the user. N other users need to exchange n times; after the exchange is completed, the total amount of random numbers of the users is calculated and sent to the control center; The total amount of random numbers is calculated using the following formula: Among them, m+k is the total number of random numbers, m is the number of random number exchanges, k is the number of additional random numbers generated, R i,j SM for users i The jth random number of ; In the sending phase, according to the current time period, the user's power consumption and the key obtained in the initial phase, a ciphertext is formed through modular addition homomorphic operation and sent to the gateway. The ciphertext is summed up at the gateway and sent to the control center. The ciphertext c i The calculation formula is: Among them, m i is the power consumption, F is the key homomorphic pseudo-random function, is the modulus, R' i is the sum of m+k random numbers after replacement, and T represents the current time period; In the decryption phase, the total ciphertext obtained by the control center and the total random number corresponding to the ciphertext are decrypted to obtain the total power consumption; During the management stage, management is carried out for situations where new users join, old customers withdraw, or users’ smart meters malfunction.

2. The secure aggregation method based on random exchange and key homomorphic pseudorandom function according to claim 1, characterized in that: The exchange method in the initial stage uses traditional key exchange or quantum-resistant key exchange.

3. The secure aggregation method based on random exchange and key homomorphic pseudorandom function according to claim 1, characterized in that: The formula for calculating the sum of ciphertexts is: C=∑c i 。 4. The secure aggregation method based on random exchange and key homomorphic pseudorandom function according to claim 1, characterized in that: When a new user joins, it obtains a list of SMs that can be exchanged from the gateway, and then goes through the initialization phase, sending phase, and decryption phase to finally obtain the total power consumption.

5. The secure aggregation method based on random exchange and key homomorphic pseudorandom function according to claim 4, characterized in that: When an old user quits, during the sending phase, the gateway learns that the old user has not sent ciphertext on a regular basis, and the old user is notified of his / her quitting within the BAN. All users who exchanged random numbers with the old user restore the random numbers before the exchange, and recalculate the total random numbers and ciphertexts exchanged with the old user. The sum of the ciphertexts is then calculated, and the decoding phase is carried out to obtain the total power consumption.

6. The secure aggregation method based on random exchange and key homomorphic pseudorandom function according to claim 5, characterized in that: When a user's smart meter fails, it will be treated as an old user exiting before the modification is completed, and as a new user joining after the modification is completed.