Image encryption system and method in smart power grid environment
By adopting dynamic key generation and layered encryption technology in a smart grid environment, combined with the collaborative work of terminals, edges and central devices, the adaptability and robustness of the smart grid image data encryption solution is solved, and image data transmission with high security and high reliability is achieved.
Patent Information
- Application Number
- CN202511039194.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-28
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-07-28
AI Technical Summary
In the prior art, the image data encryption scheme in the smart grid environment has problems such as the at-rest encryption strategy that cannot adapt to heterogeneous devices, fragile key management, inability to adapt to the dynamic network topology, and lack of robustness under complex channels.
The dynamic key generation unit is used to generate dynamic session keys through the hyperchaotic system using the physical non-clone characteristics of the terminal device and the real-time load data of the power grid node. Combined with the hierarchical encryption and co-encryption units, the content-sensitive encryption processing is realized, and the encryption resource allocation and transmission priority is dynamically adjusted through the collaborative work of edge devices and central devices, and low-density parity check codes are used to improve transmission robustness.
It realizes intelligent image encryption and secure transmission that is adaptable to the full-link based on image content, device computing power, network topology and channel quality, and improves image data security and transmission reliability in smart grid environments.
Smart Images

Figure CN120547282A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an image encryption system and method in a smart grid environment. Background Art
[0002] With the rapid development and digital transformation of smart grids, massive numbers of visual sensing devices (such as surveillance cameras, drones, and inspection robots) are being widely deployed across power transmission, substations, and distribution, for equipment status monitoring, fault diagnosis, and environmental awareness. The image data generated by these devices not only captures the operational status of the grid but also potentially reveals the topology and potential security vulnerabilities of critical infrastructure, making it highly sensitive and valuable. Therefore, ensuring the confidentiality, integrity, and availability of this image data during collection, transmission, and storage has become a key challenge in smart grid security systems.
[0003] In existing technologies, the encryption and secure transmission solutions for image data have the following main deficiencies: Static and universal encryption strategies: Most solutions use standard, static encryption algorithms (such as AES and DES) with fixed keys. This model is unsuitable for the highly heterogeneous device environment of smart grids. For example, using the same complex encryption algorithm as the central server for front-end cameras with limited computing power would significantly consume their computing resources and increase processing latency. Conversely, using a unified lightweight algorithm would fail to guarantee the security of core fault images during transmission. This lack of content-sensitivity and device-awareness leads to a serious imbalance between security and efficiency.
[0004] Key management vulnerabilities: Traditional key management solutions typically rely on pre-set keys or centralized key distribution centers. With this approach, if the key is compromised during storage or transmission, the security of the entire system is compromised. Furthermore, the key generation process is completely disconnected from the physical device it protects and the operational environment (such as grid load fluctuations). This makes the key itself lack dynamic and contextual relevance, making it more susceptible to prediction and attack.
[0005] Insufficient adaptability to dynamic network topologies: Smart grids are dynamically evolving networks, and their topology frequently changes due to factors such as equipment maintenance, the on-grid and off-grid integration of distributed energy resources (such as photovoltaic and wind power), and line failures. Existing encrypted transmission solutions are typically based on static, pre-set routes and lack real-time awareness of network topology changes. When critical communication links become congested or interrupted, the system cannot intelligently and dynamically adjust the allocation of encryption resources and data transmission priorities, potentially resulting in delays or even failures in the transmission of important fault images.
[0006] Lack of robustness in complex channels: Smart grid communication environments are complex, especially in outdoor and high-voltage environments. Wireless channels are often subject to strong electromagnetic interference and signal fading, leading to bit errors or packet loss during data transmission. Traditional encryption algorithms lack error correction capabilities. If even a single bit of ciphertext is incorrect during transmission, decryption of the entire data block will typically fail, resulting in complete loss of image information and significantly reducing system availability.
[0007] Therefore, how to provide an intelligent image encryption and secure transmission solution that can perform full-link, adaptive adjustments based on image content, device computing power, network topology, and channel quality is a technical problem that needs to be urgently solved in this field. Summary of the Invention
[0008] In view of this, the present invention aims to solve at least one of the problems existing in the prior art, such as static encryption strategy, fragile key management, inability to adapt to dynamic network topology, and lack of robustness under complex channels, to a certain extent.
[0009] The present invention provides an image encryption system in a smart grid environment, characterized by comprising: At least one terminal device, the terminal device comprising: an image acquisition unit for acquiring real-time images of power grid equipment; a dynamic key generation unit for generating dynamic session keys through a hyperchaotic system using the physical unclonable characteristics of the terminal device and the real-time load data of the power grid node associated with the terminal device; and a layered encryption unit for analyzing the real-time images and performing layered encryption on them using the dynamic session keys; at least one edge device, the edge device comprising: a data receiving and preprocessing unit for receiving encrypted data from the terminal device and performing format conversion and integrity verification on the data; and a collaborative encryption unit for performing enhanced encryption on high-complexity areas in the received encrypted data; and a central device, the central device comprising: a global key management unit for generating and distributing master keys to the terminal devices and edge devices; and a decryption and restoration unit for decrypting and restoring the encrypted data received from the edge device.
[0010] Optionally, the dynamic key generation unit is further configured to: hash the physical unclonable feature to serve as the initial state value of the hyperchaotic system; and quantify the real-time operating status data into a load fluctuation factor to dynamically modulate the system parameters of the hyperchaotic system.
[0011] Optionally, the central device is further configured to perform the following actions: analyzing the data output by the decryption and restoration unit to identify potential operating risks of the power grid; and generating and issuing dispatch instructions or safety warnings based on the potential operating risks.
[0012] Optionally, the system further includes a blockchain evidence storage module, which is configured to: capture key operations in the layered encryption, enhanced encryption, and decryption and restoration processes; and record the key operations in a distributed ledger.
[0013] Optionally, the layered encryption unit is further configured to perform the following actions: calculate the gradient entropy value of each image block in the real-time image; determine the image block whose gradient entropy value is greater than a preset threshold as a high-complexity area; and adopt a first encryption strategy to encrypt the high-complexity area, and adopt a second encryption strategy different from the first encryption strategy to encrypt the non-high-complexity area.
[0014] Optionally, the system also includes a topology-aware transmission module, which is configured to: construct and dynamically update a topology map representing the current smart grid; input the topology map into a graph neural network model to calculate the priority of each data transmission link; and schedule data transmission between the terminal device and the edge device according to the priority.
[0015] Optionally, the collaborative encryption unit is further configured to perform the enhanced encryption on the high-complexity area using a hybrid encryption algorithm, the hybrid encryption algorithm comprising: using a hyperchaotic system to perform pixel scrambling on the high-complexity area; and further using an AES algorithm to encrypt the scrambled pixel data.
[0016] Optionally, the edge device also includes a low-density parity-check code encoding unit for encoding the data before sending it; the decryption and restoration unit in the central device also includes a low-density parity-check code decoding unit, which is further configured to: monitor the channel quality parameters of the data transmission channel; and adaptively adjust its decoding and error correction strategy based on the channel quality parameters.
[0017] Optionally, the low-density parity-check code decoding unit adaptively adjusts its decoding strategy including: when the channel quality parameter indicates that the channel quality has degraded and exceeds a preset threshold, increasing the number of iterations of the hyperchaotic system used for decryption, and / or increasing the number of iterations of low-density parity-check code decoding.
[0018] Optionally, the central device further includes a federated learning center module, which is configured to: aggregate encrypted model parameter updates from multiple edge devices; train a global optimization model locally; and send the optimized model parameters to each edge device.
[0019] Another aspect of the present invention provides an image encryption method in a smart grid environment, which includes encryption, transmission and decryption steps corresponding to the functions of each unit or module performed by any of the aforementioned system solutions.
[0020] Specifically, this invention provides a collaborative, fully adaptive, end-to-end image encryption security system that deeply couples encryption strategies with device physical characteristics, real-time service status, dynamic network topology, and channel transmission quality. Compared to existing technologies, this invention balances the computational efficiency of heterogeneous devices and transmission robustness over complex channels while ensuring high-level security. This significantly enhances the intelligence and overall performance of critical image data security protection in smart grid environments.
[0021] In order to more intuitively demonstrate the workflow of the present invention, a simplified algorithm flow example is provided below.
[0022] In a specific scenario, when a terminal device with the ID T-001 captures an image containing a device fault: 1. Dynamic key generation: The device extracts its unique PUF signature "A1B2C3D4" and detects a current load fluctuation factor of 2.3. Based on these two real-time parameters, the PUF signature and the current load fluctuation factor, its internal hyperchaotic system is dynamically configured and iterated 1000 times to generate a 256-bit dynamic session key. 2. Layered encryption and collaborative enhanced encryption: The device divides the image into blocks and calculates the image block containing the fault point. The gradient entropy of this image block is greater than a preset threshold of 4.0, thus determining it as a high-complexity region. The terminal device then performs strong encryption on this region, specifically using the Chaos-SPECK algorithm (an encryption scheme that cascades chaotic scrambling with the SPECK algorithm). After data is transmitted to the edge device, the already strongly encrypted, high-complexity region undergoes an additional round of enhanced encryption (Enhanced Encryption). This is a secondary encryption layer applied on top of the existing encryption layer. Specifically, the HyperChaos-AES algorithm (a hybrid encryption scheme that cascades four-dimensional hyperchaos scrambling with the AES algorithm) is used. 3. Topology-Aware Transmission: Simultaneously, the GNN model on the central device determines that the core link carrying the fault image data has a transmission priority of 0.95 and, accordingly, allocates higher network bandwidth resources and a more frequent key update policy. 4. Interference Resilience and Adaptive Decryption: Data is subject to interference during transmission, causing the channel bit error rate (BER) to rise to 8%. 5. Adaptive Decoding and Restoration: Upon detecting this, the central device's decryption and restoration unit triggers an adaptive decryption mechanism, automatically increasing the number of iterations of the hyperchaos system used for decryption from the standard 1000 to 1200, and performing 50 low-density parity-check code decoding iterations, ultimately successfully restoring image clarity to over 98%.
[0023] This embodiment clearly demonstrates how, in practical applications, the present invention can achieve end-to-end, highly secure, and highly reliable encryption and transmission of critical image data through intelligent collaboration of multiple devices and multiple stages.
[0024] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0026] In order to more clearly illustrate the technical content of the present invention, embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0027] Figure 1 The following schematically illustrates a top-level functional module structure diagram of an image encryption system in a smart grid environment provided by an embodiment of the present application; Figure 2 The core flow chart of the smart grid image encryption method provided in an embodiment of the present application is schematically shown. DETAILED DESCRIPTION
[0028] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.
[0029] The following describes the embodiments of the present disclosure through specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present disclosure.
[0030] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will appreciate that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement an apparatus and / or practice a method. Additionally, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this apparatus and / or practice this method.
[0031] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The illustrations only show components related to the present disclosure and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.
[0032] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples. However, one skilled in the art will appreciate that the aspects described can be practiced without these specific details.
[0033] This embodiment provides an image encryption system for a smart grid environment. This system utilizes an innovative architecture comprised of three levels of collaborative work: terminal devices, edge devices, and central devices. This system implements adaptive security protection for grid image data across the entire chain, from acquisition and encryption to transmission and decryption.
[0034] See also Figure 1 , which schematically illustrates the physical and logical layered architecture of the encryption system provided in this embodiment. In a preferred embodiment, the system mainly includes at least one terminal device 10, at least one edge device 20 and a central device 30.
[0035] See also Figure 1 , which schematically shows a system structure block diagram of an image encryption system in a smart grid environment provided by an embodiment of the present application. In a preferred embodiment, the system mainly includes a terminal device 10, an edge device 20 and a central device 30.
[0036] Terminal device 10, the sensing and encryption source for the entire system, is typically an intelligent sensor deployed at the monitoring site, such as a high-definition surveillance camera or inspection drone. Its core function is to complete the original image acquisition and the first stage of lightweight intelligent encryption processing.
[0037] In a specific embodiment, the terminal device 10 includes the following core units: Image acquisition unit 101: Responsible for acquiring real-time images of power grid equipment. For example, it uses a high-resolution CMOS sensor to capture operating status images of key equipment such as transformers and insulators at a rate of 30 frames per second.
[0038] Dynamic key generation unit 102: This is the key to achieving "one device, one secret, one time, one secret." It is configured to utilize the terminal device's physical unclonable feature (PUF) and real-time load data from the grid node associated with the terminal device to generate a dynamic session key through a hyperchaotic system. Specifically, the hyperchaotic system is a four-dimensional hyperchaotic system. Specifically, the unit utilizes a "dual factor" mechanism as follows: First, a unique, unclonable PUF fingerprint sequence is extracted by reading the power-on state of the device's on-chip SRAM array or the frequency of the ring oscillator. This PUF fingerprint sequence is processed using a standard hash algorithm such as SHA-256, and the resulting PUF value is used as the initial state value of the hyperchaotic system. Simultaneously, the unit obtains real-time active power or current data from local grid nodes (such as PMUs) as load data and quantizes it into a load fluctuation factor α(t) using mathematical methods such as fractional differentiation. This factor is used to dynamically modulate one or more key system parameters of the hyperchaotic system, for example, a'=a+k0*α(t). Where a' represents the dynamically modulated, immediately effective parameter of the hyperchaotic system, which directly influences the subsequent evolution of the chaotic sequence. a represents a baseline or default value for the parameter. This is a preset benchmark constant that ensures the hyperchaotic system remains in a chaotic state. k0 is a modulation coefficient or scaling factor. This coefficient controls the impact of load fluctuations on system parameters, and its value can be preset based on the safety level requirements of the actual application scenario. α(t) is the real-time load fluctuation factor calculated at time t. As a time-varying variable, it introduces the actual operational state of the power grid into the hyperchaotic system.
[0039] In this way, the dynamic session key ultimately generated by the iterative hyperchaotic system is not only unique to the device, but its evolution trajectory is also constantly affected by the actual business status of the power grid, making it extremely random, anti-predictable and context-relevant.
[0040] Layered encryption unit 103: This unit is responsible for performing content-sensitive differential encryption. It analyzes the real-time image and performs layered encryption on it using the dynamic session key. It should be noted that the process for this unit to perform layered encryption is as follows: the captured image is first divided into blocks of a preset size (e.g., 16×16 pixels), and then the gradient entropy is calculated for each image block. Gradient entropy can effectively measure the complexity of image texture and the density of information. Then, image blocks with gradient entropy greater than a preset threshold are determined to be high-complexity areas containing critical information, while the rest are non-high-complexity areas. Finally, different encryption algorithms are called (e.g., a first encryption strategy, such as Chaos-SPECK, is used for high-complexity areas, and a second encryption strategy, such as SPECK, is used for non-high-complexity areas) and encryption is performed using the newly generated dynamic session key.
[0041] Edge devices 20 act as a bridge between end devices and central equipment. Typically deployed in substations or regional aggregation centers, they possess greater computing and storage capabilities than end devices. They are responsible for preprocessing and performing secondary encryption on encrypted data.
[0042] In a specific embodiment, the edge device 20 includes the following core units: Data receiving and preprocessing unit 201: Responsible for receiving encrypted data from the terminal device, converting its format, and performing integrity verification. For example, it encapsulates the raw data stream uploaded by the terminal into a standard TCP / IP data packet with metadata such as timestamp, device ID, encryption policy identifier, and calculates its MD5 hash value for subsequent integrity verification.
[0043] Collaborative encryption unit 202: This unit is responsible for performing enhanced encryption on high-complexity regions within the received encrypted data. It should be noted that this enhanced encryption is a hybrid encryption strategy. For example, the unit can first use a hyperchaotic key associated with the edge device, issued by the central device, to perform a second pixel-level scrambling of the encrypted key image block data to further disrupt its statistical characteristics. It then invokes the hardware-accelerated AES-128 algorithm to perform a high-speed, high-intensity block encryption on the scrambled data. This "scrambling + block encryption" combination can significantly improve defenses against brute force and statistical analysis attacks.
[0044] The central device 30 is the core of the entire system and is usually deployed in a cloud server or a regional control center. It has the most powerful computing, storage and management capabilities.
[0045] In a specific embodiment, the central device 30 includes the following core units: Global Key Management Unit 301: Responsible for generating and distributing master keys to terminal devices and edge devices. To achieve the highest level of security, this unit preferably utilizes quantum key distribution (QKD) technology when generating and distributing master keys. Leveraging the principle that quantum states cannot be cloned, QKD ensures absolute security during the master key distribution process. Even eavesdropping would be immediately detected, thus fundamentally eliminating the risk of master key leakage.
[0046] Decryption and Restoration Unit 302: This unit is responsible for decrypting and restoring the encrypted data received from the edge device. It should be noted that the decryption process in this unit is a sophisticated, multi-stage inverse operation. It first performs low-density parity-check code decoding and error correction to correct errors that may occur in complex channels. Then, based on the metadata in the data packet, it invokes the corresponding decryption algorithm (such as inverse AES) for decryption. Finally, if the data has been scrambled, it performs hyperchaotic inverse scrambling based on the permutation index stored during the encryption phase to restore the pixels to their original positions and produce a clear image.
[0047] Through the precise coordination of the above-mentioned "end-edge-cloud" three-level devices and their internal units, this system has built a hierarchical and progressive security protection system.
[0048] In a preferred embodiment, the dynamic key generation unit 102 is further configured to: process the physical unclonable feature through a hash algorithm such as SHA-256 as the initial state value of the hyperchaotic system; and quantify the real-time operating status data (such as power grid load) into a load fluctuation factor to dynamically modulate one or more system parameters of the hyperchaotic system.
[0049] In a preferred embodiment, the central device 30 is further configured to perform data analysis and decision-making actions, which include: first, analyzing the image data output by the decryption and restoration unit 302, for example, by comparing it with a normal state image library or using an image recognition algorithm to identify potential operating risks of the power grid (such as equipment overheating, insulator damage); then, based on the level and type of the potential operating risk, automatically generating and issuing corresponding dispatch instructions (such as adjusting regional loads) or safety warnings (such as pushing alarm information to the mobile terminals of operation and maintenance personnel).
[0050] In a preferred embodiment, the system also includes a blockchain evidence storage module. This module is configured to capture key operational information, such as the timestamp of the operation, the device ID performing the operation, and the hash value of the key used, at key points in the encryption process (e.g., key generation, layered encryption, enhanced encryption, and decryption and restoration). This information is then packaged into immutable transactions and recorded on a distributed ledger. This approach provides immutable security auditing and post-event traceability for all encryption operations.
[0051] In a preferred embodiment, when the layered encryption unit 103 performs layered encryption, its specific decision-making and execution actions include: first, calculating the gradient entropy value of each image block in the real-time image; then, determining the image block whose gradient entropy value is greater than a preset threshold as a high-complexity area; finally, using a cascade of a hyperchaotic encryption and a block cipher algorithm as a first encryption strategy to encrypt the high-complexity area; and using a lightweight block cipher algorithm (such as SPECK) as a second encryption strategy to encrypt the non-high-complexity area.
[0052] In a preferred embodiment, the system also includes a topology-aware transmission module. This module is configured to perform the following actions: first, by reading network management data, it constructs and dynamically updates a topology map that represents the current state of smart grid communication links; second, it inputs the topology map into a pre-trained graph neural network (GNN) model, which calculates the priority of each data transmission link; and finally, based on the priority, the system schedules encrypted data packets for transmission via higher-priority links.
[0053] In a preferred embodiment, the enhanced encryption employed by the collaborative encryption unit 202 is a hybrid encryption algorithm. The specific steps of this algorithm include: first, using a hyperchaotic system to perform pixel-level scrambling on the high-complexity region to disrupt its spatial correlation; then, further encrypting the scrambled pixel data using the Advanced Encryption Standard (AES) algorithm to provide high-strength cryptographic protection.
[0054] In a preferred embodiment, to enhance the robustness of the system under complex channels, the edge device 20 further includes a low-density parity-check code encoding unit for encoding data before transmission. Accordingly, the decryption and restoration unit 302 in the central device 30 further includes a low-density parity-check code decoding unit, which is further configured to: first, monitor the channel quality parameters of the data transmission channel, such as the bit error rate (BER); then, when the channel quality parameters indicate that the channel quality has degraded and exceeds a preset threshold (e.g., BER>5%), the unit adaptively increases the number of iterations of the hyperchaotic system used for decryption and / or increases the number of iterations of the low-density parity-check code decoding, thereby sacrificing some decryption speed in exchange for the highest success rate in recovering data under poor channels.
[0055] It should be noted that the low-density parity-check (LDPC) code described above is a high-performance linear block code. Its core concept is to strategically add redundant parity check bits to the original information bit sequence based on a pre-set, sparse parity check matrix. This encoding scheme generates a final codeword whose internal bits are subject to specific algebraic constraints. When errors occur during transmission of this redundant codeword over a channel, the receiving decoder can leverage these constraints to detect and correct the errors with high probability through iterative algorithms such as belief propagation, thereby recovering the original information. Due to the low density of the parity check matrix (i.e., the number of "1" elements in the matrix is far less than the number of "0"), LDPC codes achieve an excellent balance between decoding complexity and error correction performance, making them particularly suitable for communication systems with extremely high reliability requirements.
[0056] In a preferred embodiment, the central device 30 also includes a federated learning center module. This module is designed to continuously optimize the performance of the system's encryption algorithms (particularly hyperchaotic systems) through distributed collaborative training, without having to upload original sensitive data from each device. Its workflow includes: first, aggregating locally generated encryption model parameter updates (e.g., gradient information) from multiple edge devices; then, using this aggregated information locally (i.e., on the central device) to update and train a global optimization model to generate optimized global model parameters; finally, distributing these optimized global model parameters to each edge device, guiding them to update their local models, thereby achieving collaborative evolution and continuous optimization of the encryption model for the entire system.
[0057] In specific implementation, the workflow of this system can be broken down into the following collaborative stages: 1. Data collection and key pre-generation stage: On the terminal device 10, the image acquisition unit 101 first acquires a real-time image. At the same time, the dynamic key generation unit 102 starts working: A1) Extracting PUF features: A random sequence is generated by reading device hardware noise (such as SRAM voltage fluctuations). Dimensionality reduction can be performed using methods such as principal component analysis (PCA). Ultimately, a unique 64-bit integer is extracted and converted as the device's PUF feature.
[0058] A2) Obtaining real-time grid load data: Synchronously collect active power data within a preset time window (e.g., 600 seconds) to form a load time series.
[0059] B1) Generate a dynamic key: The PUF signature obtained in step A1 is hashed and used as the initial state value of the hyperchaotic system. The load sequence obtained in step A2 is used to calculate a real-time load fluctuation factor through methods such as fractional integration. This load fluctuation factor is used to dynamically modulate the parameters of the hyperchaotic system (e.g., a, b, c, d, q). Finally, by iterating this "doubly" modulated hyperchaotic system, a dynamic session key is generated that is deeply bound to both the device and grid states.
[0060] 2. Layered encryption processing stage, which is also performed on the terminal device 10 by the layered encryption unit 103: C1) Image Analysis and Decision-Making: The captured image is divided into 16×16 pixel blocks, and the gradient entropy is calculated for each block. A gradient entropy threshold (e.g., 4.0) is set. If the gradient entropy of a block exceeds the threshold, it is considered a high-complexity region (i.e., a key block) containing rich textures (e.g., equipment nameplates, fault points). Otherwise, it is considered a non-high-complexity region.
[0061] D1) Encryption strategy selection and execution: For high-complexity areas, a Chaos-SPECK strong encryption strategy is adopted.
[0062] E1) This strategy first uses a hyperchaotic sequence to generate pixel permutation indexes and scrambles the pixel positions of the RGB channels of the image block. E2) Then, the SPECK block cipher algorithm is used to encrypt the scrambled data. For non-high-complexity areas, the SPECK lightweight encryption strategy is directly used to save computing resources.
[0063] E3) After encryption, all data blocks are further processed by a low-density parity-check (LDPC) encoding unit. This process adds redundant parity bits to the original data, generating a coded codeword. A preferred implementation uses a LDPC code with a code rate of 0.8. This adds 25% redundant data to the original information, enabling effective error correction in channels with a bit error rate of, for example, less than 5%, significantly enhancing the data transmission's robustness against interference.
[0064] 3. Topology-aware transmission phase, which is led by the topology-aware transmission module of the central device 30: F1) GNN Topology Perception and Priority Calculation: This module abstracts the power grid topology into graph data, with devices as nodes and communication links as edges. This graph data is then fed into a pre-trained GCN (graph convolutional network) model. The model comprehensively considers node connectivity and real-time status (such as load) to output the transmission priority of each communication link.
[0065] F2) Dynamic Scheduling: Encrypted packets are scheduled based on calculated priorities. For example, packets carrying highly complex regional data originating from critical substations will be prioritized for transmission over higher-priority links. It's important to note that if the GNN detects a topology change (such as the addition of new equipment), it recalculates priorities and may trigger dynamic adjustments to encryption parameters for the relevant links (such as increasing the rekeying frequency or the number of hyperchaos iterations) to ensure that encryption strength matches link importance in real time.
[0066] 4. Anti-interference reception and decryption stage, which is mainly performed in the decryption and restoration unit of the central device 30: G1) Adaptive Decryption: The receiver first monitors the bit error rate (BER) of the transmission channel. If the BER exceeds a preset threshold (e.g., 5%), the decryption process automatically increases the number of iterations of the hyperchaotic system used for decryption, thereby improving the decryption success rate in poor channel conditions.
[0067] G2) LDPC code decoding: The received data is iteratively decoded (e.g., 50 times) using the Belief Propagation (BP) algorithm to correct bit errors generated during transmission.
[0068] G3) Hyperchaotic inverse scrambling and restoration: After decryption and decoding are completed, the inverse operation is performed according to the permutation index saved in the encryption stage to restore the pixels to their original order, and finally restore a clear image.
[0069] It should be noted that in the scenario with the highest security level, the decryption process can also introduce quantum key distribution (QKD) technology, that is, using a one-time quantum key to perform secondary decryption on the key of the hyperchaotic system to achieve the level of information-theoretic security.
[0070] 5. During the quality assessment phase, the system can also include a quality assessment module to verify the encryption effectiveness. Evaluation metrics include: information entropy of the encrypted image (should be close to the ideal value of 8.0 to prove sufficient obfuscation) and the peak signal-to-noise ratio (PSNR) of the decrypted image compared to the original image (should be greater than 30dB to ensure visual lossless restoration).
[0071] Another aspect of the present invention provides an image encryption method in a smart grid environment, which aims to achieve intelligent, adaptive and secure processing of image data through a series of logically interconnected steps.
[0072] See also Figure 2 , which schematically illustrates the core process of the image encryption method provided by this embodiment. In a preferred embodiment, the method mainly includes the following steps: Step S100: Dynamically generate encryption keys. This is the starting point and security foundation of the entire encryption process. This step abandons static, pre-set keys and instead adopts a dynamic generation mechanism that is linked to physical entities and real-time status.
[0073] Specifically, this step involves first obtaining a physical unclonable feature (PUF) of a terminal device on which encryption will be performed; simultaneously, obtaining real-time load data (e.g., operating status) of the power grid node associated with the terminal device. These two heterogeneous factors are then coordinated and used as input parameters to drive an iterative hyperchaotic system, ultimately generating the dynamic encryption key required for this encryption session. As described in Example 1, the PUF feature can be used as the initial value of the hyperchaotic system, and the operating status data can be used as a perturbation factor for the system parameters.
[0074] Step S200: Perform content-sensitive layered encryption. After obtaining the dynamic key, this step performs differential encryption processing on the collected original image data.
[0075] Specifically, this step involves first analyzing the content complexity of the image to be encrypted. This can be achieved by calculating the gradient entropy of each image block. Then, based on the analysis results, the image is divided into high-complexity regions (such as those containing device details) and low-complexity regions (such as the background). Finally, different encryption strategies are applied to these two regions. For example, a strong encryption strategy consisting of a hyperchaotic scrambling and a block cipher cascade is used for the high-complexity regions, while a lightweight block cipher algorithm is used for the low-complexity regions.
[0076] Step S300: Execute topology-aware intelligent transmission. After data encryption is completed, this step is responsible for planning its transmission path and resources in an intelligent manner.
[0077] Specifically, this step involves first analyzing the current smart grid topology using a graph neural network (GNN) model. This model outputs the transmission priority of each available communication link. The system then dynamically adapts encryption resources to different encrypted data packets based on these calculated priorities. For example, more important packets containing high-complexity areas are scheduled for transmission on higher-priority links.
[0078] Step S400: Execute anti-interference encoding and transmission. In order to deal with data transmission errors in complex channels, this step will perform an enhancement process on the encrypted data before the data is officially sent.
[0079] Specifically, this step involves performing forward error correction encoding on the encrypted data packet. A preferred encoding method is low-density parity-check coding, which enhances data corruption resistance by adding redundant check bits. After encoding, the data is sent to the receiving end.
[0080] Step S500: Execute adaptive decoding and restoration, which is the reverse process performed at the data receiving end.
[0081] Specifically, this step includes: first, receiving data and monitoring the channel quality parameters (such as the bit error rate (BER)) of its transmission channel. Then, performing low-density parity-check (LDPC) code decoding and error correction to correct any existing errors. It should be noted that the decoding process here is adaptive. If the monitored channel quality is poor (for example, the BER is higher than a preset threshold), the decoding program automatically increases the number of iterations of the hyperchaotic system used for decryption and / or the number of iterations of the LDPC code decoding to improve the success rate of data recovery under adverse conditions. Finally, after decryption and possible descrambling operations, the data is restored to the original image.
[0082] By organically combining the above steps, this method constructs a full-process intelligent, adaptive encryption and secure transmission solution from key generation to final restoration.
[0083] In order to further illustrate the implementation details of the core algorithm involved in the present invention, the following will provide a detailed mathematical principle and logic description of several key algorithm modules. It should be understood that the following description is a preferred, but not exclusive, implementation of the present invention.
[0084] 1. PUF feature and payload data processing: First, collect the PUF feature of the device and generate a unique identifier , and obtain real-time load data L(t) at the same time, and calculate the load fluctuation factor by fractional order differential : ; Where: α(t) is the load fluctuation factor calculated at time point t. Represents the load function Perform a 0.5-order differentiation operation. is the load observation value at the historical time point τ. is the gamma function, an extension of the factorial function to real and complex numbers. When the order is 0.5, Γ(0.5) = sqrt(π). It should be noted that the physical meaning of this formula is that it does not simply calculate the instantaneous rate of change of the current load, but rather calculates it by performing a weighted integration of all historical load observations L(τ). The closer the historical data is to the current time point t, the greater its weight (given by The larger the decision).
[0085] Initialization of parameters of hyperchaotic system: After hashing, it is converted into the initial state value of the hyperchaotic system ( ), and dynamically adjust the parameters of the hyperchaotic system according to α(t): ; Among them: SHA256( ) represents the identifier The result of the hash operation. [0:8], [8:16], [16:24], and [24:32] all represent slice operations, representing specific byte segments of the hash value. int(..., 16) converts a hexadecimal string to an integer. 2³² - 1 is a normalization constant representing the maximum value of a 32-bit unsigned integer.
[0086] Furthermore, the evolution of the hyperchaotic system is determined by a set of system parameters (a, b, c, d, q). To ensure that the key reflects the real-time state of the power grid, these parameters are dynamically modulated by the previously calculated load fluctuation factor α(t). A preferred linear modulation scheme is as follows: ; Among them, mod represents mathematical modulus operation; Key generation iteration: Based on the initialized parameters, the hyperchaotic system is iterated: ; in, 、 、 、 Represent the time derivatives of the system state variables x, y, z, and v. After multiple iterations, the system state variables x, y, z, and v are mapped to a fixed-length byte array as the final encryption key.
[0087] Underlying logic, device uniqueness binding: The uniqueness of the PUF signature ensures that the key generated by each device is unique at the hardware level. For example, different smart meters generate different PUF signatures due to differences in chip manufacturing processes, resulting in different initial values and, consequently, different keys. This prevents attackers from cloning devices and obtaining the same key.
[0088] Dynamic Correlation with Grid Status: Grid load data reflects the grid's operating status in real time. Load fluctuation factors are incorporated into the hyperchaotic system's parameters, closely linking the encryption key to the grid's status. During peak hours, load fluctuation factors increase, hyperchaotic system parameters change, and the generated key changes accordingly, ensuring that the encryption strategy adapts to the grid's dynamic operation.
[0089] Advantages of hyperchaotic systems: Compared to traditional chaotic systems, hyperchaotic systems possess multiple positive Lyapunov exponents and are extremely sensitive to small changes in initial values and parameters. Even if the PUF signatures or grid load data of two devices differ only slightly, the keys generated after iterations of the hyperchaotic system will be completely different, significantly improving the randomness and anti-attack capabilities of the keys.
[0090] 2. Edge-Center Collaborative Layered Encryption Algorithm The algorithm's role is to address the vast differences in computing power across smart grid devices, from terminal sensors to edge servers to central control servers. Furthermore, different regions within image data possess varying importance. This algorithm implements differentiated encryption based on device type and the gradient entropy characteristics of image blocks, ensuring data security while improving encryption efficiency and resource utilization.
[0091] Algorithm flow, image block feature analysis: After dividing the image into blocks of preset size, calculate the gradient entropy of each image block , to measure its complexity: ; in: is the calculated gradient entropy. M and N are the width and height of the image patch (in pixels), respectively. p(i0, j0) is the probability of the gradient (or gradient level) at pixel (i0, j0) occurring in the gradient map. Σ represents the summation operation.
[0092] At the same time, a deep learning model is used to determine whether the image block is a key area, such as whether it contains equipment instruments, fault characteristics, etc.
[0093] In the encryption system of this invention, the selection of encryption strategy is not static, but a dynamic decision-making process that comprehensively considers the device type, power grid status, and image block characteristics. The following details the encryption strategy selection logic for different devices in different scenarios: (1) For terminal devices (T category): This type of device usually has limited computing power, and its encryption strategy is mainly based on the content complexity of the image block itself. When the image block is judged to be a non-high-complexity area (for example, a background area with low gradient entropy), in order to achieve the highest efficiency, the system will choose to execute the SPECK lightweight encryption algorithm. When the image block is judged to be a high-complexity area (for example, containing key device details), the system will choose to execute the more secure Chaos-SPECK encryption algorithm, which adds a hyper-chaotic scrambling operation on the basis of SPECK encryption.
[0094] (2) For edge devices (Class E): This type of device has stronger computing power, and its encryption strategy not only considers the image block features, but also combines the real-time status of the power grid. When the power grid status is "normal", the edge device uniformly performs HyperChaos-AES enhanced encryption on all received image blocks, that is, first performs a four-dimensional hyperchaos scrambling, and then performs AES encryption. When the power grid status is judged to be "fault" or "warning", its processing logic is the same as in the normal state, but the encryption model features (such as chaos parameters) used in processing the key image blocks will be fed back to the central device through the federated learning mechanism to participate in the optimization of the global model.
[0095] (3) For central devices (Class C): This type of device has the strongest security and computing capabilities, and its encryption strategy selection is mainly targeted at core data and scenarios with the highest security level. When the received image data is determined to be core data (for example, directly related to major fault diagnosis) and the power grid status is "faulty", the system will start the highest security level Quantum-HyperChaos hybrid encryption. This strategy uses a one-time key generated by quantum key distribution (QKD) technology to provide secondary protection for the hyperchaos encryption process to achieve information-theoretic security level. When the power grid status is "normal", the central device usually executes a HyperChaos-AES encryption strategy similar to that of the edge device for the received data, or archives the data according to its importance. Through the above-mentioned hierarchical and context-aware encryption strategy selection logic, the present invention ensures that security resources can be allocated in the most reasonable way that matches the risk level in the entire "end-edge-cloud" architecture.
[0096] Encryption operation execution: After the encryption algorithm is selected, the image block is encrypted accordingly. For example, when using the four-dimensional hyperchaotic image scrambling algorithm, the chaotic values generated by the hyperchaotic system are used to permute the positions of the image pixels.
[0097] Underlying logic and device computing power adaptation: Terminal device resources are limited, and a lightweight SPECK algorithm is used for non-critical and low-complexity image blocks, which can complete encryption in a short time and meet the real-time monitoring image transmission needs of the power grid; edge devices and central devices have strong computing power, and high-intensity algorithms such as hyperchaos-AES hybrid encryption and quantum-hyperchaos encryption are used for key image blocks to ensure the security of core data.
[0098] Differentiated image block processing: By assessing the complexity and critical areas of image blocks, different encryption strengths are applied to areas of varying importance. For power grid equipment monitoring images, the instrument area, crucial for determining equipment operating status, is encrypted with high strength, while the background environment area is encrypted with lower strength, balancing security and efficiency.
[0099] Collaborative Optimization Mechanism: During the encryption process, edge devices feed back the encrypted features of image blocks to the central device through federated learning. The central device then optimizes the parameters of the hyperchaotic system, enabling global collaborative optimization of encryption strategies across the entire smart grid system, improving overall encryption effectiveness.
[0100] 3. Topology-aware dynamic encryption link algorithm The algorithm works because smart grid network topology frequently changes due to factors like distributed power generation and equipment failures. Traditional static encrypted links cannot guarantee data security. This algorithm uses a graph neural network (GNN) to analyze grid topology and device status, dynamically adjusting encrypted links to ensure that important data transmission is prioritized and protected.
[0101] Algorithm process, data preparation: The power grid topology is converted into an adjacency matrix, and equipment status information (such as online rate, load, etc.) is collected as node features to construct GNN model input data.
[0102] Priority calculation: The encryption priority between devices is calculated through the forward propagation of the GNN model: ; ; in: Is the device node i in the The hidden feature representation of the layer (or node embedding). σ is a nonlinear activation function, such as the ReLU function. It is the set of neighbor nodes of device node i (including device node i itself). is the neighbor node of device node i, is the previous layer feature of neighbor node j . and They are The learnable weight matrix and bias vector of the layer network. After propagation and aggregation through L layers (L is the total number of layers in the network), the last formula uses the softmax function to convert the final node features Convert to encrypted priority probability .
[0103] Output encryption priority probability between devices , filtering out high-priority links.
[0104] Link adjustment: Real-time monitoring of grid topology changes. When devices are added, deleted, or their status changes, the encrypted link is adjusted based on the link priority update formula: ; in: Indicates the new link priority from device node f to device node g in the current evaluation cycle. This value will serve as the direct basis for subsequent encryption resource allocation and transmission scheduling. Indicates the old link priority from device node f to device node g, calculated in the previous evaluation cycle." "Device status unchanged" is a judgment condition, indicating that the system has not detected any significant changes in the network topology or key node status that exceed the preset threshold during the current evaluation cycle. Under this condition, the system will directly use the old priority value to maintain stability. "Device addition / deletion / status change" is a mutually exclusive judgment condition with the previous condition, indicating that the system has detected at least one event that affects the overall network status, such as the connection of a new device to the grid, a device going offline due to a fault, or a significant load fluctuation at a key node. The update value represents the new link priority value obtained after the system triggers the aforementioned graph neural network (GNN) model when the "Device addition / deletion / status change" condition is met and performs a complete forward propagation calculation based on the latest network topology and node feature data.
[0105] Underlying logic and topology modeling: The grid topology is abstracted as graph data, with the adjacency matrix describing device connectivity and node features reflecting device status. The GNN model effectively captures the connectivity and feature information between nodes in the graph data, accurately assessing the importance of each link in data transmission. For example, when analyzing the connectivity between multiple substations and distributed generation (DGs) in a power grid, GNN can identify key transmission links.
[0106] Dynamic Priority Assessment: Device status, such as online rate and load, directly impacts data transmission reliability and urgency. Incorporating these factors into priority calculations allows encryption strategies to dynamically adjust based on grid operating conditions. When a distributed power source is connected to the grid, the device status of the associated link changes, and GNN recalculates priorities to ensure appropriate encryption strength for the data transmission link of the newly connected device.
[0107] Rapid Response Mechanism: When the grid topology changes, the algorithm promptly detects and adjusts encrypted links based on a priority update formula. For example, if a device fails and goes offline, encryption resources associated with that device are immediately removed and reallocated to other important links, preventing security vulnerabilities caused by topology changes and ensuring data security.
[0108] 4. Robust encryption algorithm that is resistant to interference The smart grid communication environment is complex, subject to electromagnetic interference, data packet loss and other issues. Traditional encryption algorithms cannot guarantee correct data decryption and recovery. This algorithm combines low-density parity-check code encoding with adaptive decryption to improve data anti-interference capabilities in complex environments and ensure reliable image data transmission.
[0109] Algorithm flow, data preprocessing and encoding encryption cascade: After the image data is divided into blocks, low-density parity check code encoding is first performed to add redundant check bits: , where H is the low-density parity-check code matrix, c is the encoded codeword vector, and T represents the matrix or vector transpose. After encoding, the data block is encrypted using a hyperchaotic encryption algorithm.
[0110] Adaptive decryption and error correction: The receiver adjusts the decryption strategy based on the current channel bit error rate (BER). When the BER is high, the number of iterations of the hyperchaotic system is increased; error correction is performed using the belief propagation decoding iterative formula: ; in: It is in In the iteration, the check node p sends a message to the variable node r (usually the log-likelihood ratio LLR); represents the set of all other variable nodes connected to the check node p but excluding the variable node r; is a sign function; Indicates taking the minimum value among the absolute values of all incoming messages; It is in In the iteration, the message sent by check node z to check node p; is the detection value received from the channel and related to the check node p. The messages between the check node and the variable node are iteratively updated to gradually approach the correct decoding result, and the data integrity is verified through block marking.
[0111] Underlying logic and error correction coding principles: Low-density parity-check (LDPC) codes add redundant check bits to the original data by applying a check matrix to the codeword vector. This redundant information enables the receiver to detect and correct errors based on the checksum equations when data transmission errors occur. For example, if electromagnetic interference causes partial data errors, the receiver can use the redundant bits to recover the original data, improving data transmission reliability.
[0112] Encryption and encoding work together: Low-density parity-check (LDPC) encoding is performed before encryption, ensuring the security of redundant checksum information during transmission. The high randomness and obfuscation properties of hyperchaotic encryption further protect the encoded data, preventing attackers from deciphering it by analyzing redundant information.
[0113] Adaptive Adjustment: Decryption parameters are dynamically adjusted based on the channel bit error rate. When the bit error rate is high, the hyperchaotic system iterations are increased to enhance anti-interference capabilities. When the bit error rate is low, the standard decryption process is used to reduce computational overhead. Belief propagation decoding iteratively updates messages, gradually correcting errors. Block marking is combined with data integrity verification to ensure accurate and usable decrypted data.
[0114] In order to more clearly demonstrate the workflow of the system of the present invention in different practical application scenarios, this embodiment provides a comprehensive application scenario description.
[0115] In a typical application scenario, such as equipment monitoring at a regional substation, a surveillance camera deployed at the site serves as a terminal device 10. When it captures a real-time image containing the transformer instrument panel, its internal dynamic key generation unit 102 extracts the camera's PUF signature and, combined with real-time load data obtained from the substation, generates a dynamic session key tied to both the device and the current operating conditions. Subsequently, the layered encryption unit 103 identifies the instrument panel as a high-complexity area and applies the Chaos-SPECK strong encryption strategy to it; for non-critical areas such as background walls, SPECK lightweight encryption is used.
[0116] The encrypted data is sent to an edge device 20 deployed within the substation, such as an edge server. The server's collaborative encryption unit 202 performs an enhanced encryption method called "hyperchaotic scrambling + AES-128" on the critical data block representing the dashboard. Before being transmitted to a central device 30 (such as a regional control center), the data is further processed using a low-density parity-check (LDPC) encoding unit to enhance interference resistance. During this process, the topology-aware transmission module utilizes a GNN model to determine that the link from the substation to the control center is high-priority and allocates optimal transmission resources to it.
[0117] It should be noted that the application scenarios of the present invention are not limited to this. For example, in the scenario of power distribution network fault repair, the smart handheld terminal of the on-site staff can serve as the terminal device 10, which can quickly perform layered encryption on the fault point and then transmit the data to a nearby edge computing node via a low-latency, high-reliability communication protocol such as 5G-URLLC. At the same time, to ensure the traceability of operations, the central device 30 can also introduce a blockchain evidence storage module to store key logs of the entire encryption and transmission process on the chain.
[0118] For example, in the case of distributed renewable energy power plants, this system can effectively adapt to the drastic changes in network topology caused by the frequent grid connection and disconnection of photovoltaic and wind power equipment. The GNN model monitors these changes in real time and dynamically adjusts the priority and encryption parameters of encrypted links to ensure stable and secure data transmission.
[0119] Furthermore, alternative implementations exist for each technical module described in this invention. For example, low-density parity-check codes can be replaced with higher-performance Turbo codes; GNN models can employ graph attention networks (GATs) to improve feature extraction accuracy; and hyperchaotic systems can be replaced with improved Lorenz hyperchaotic systems. These alternatives fall within the scope of this invention.
[0120] The present invention provides an image encryption system and method for a smart grid environment. This system utilizes a collaborative, fully adaptive "end-edge-cloud" security system to achieve intelligent and robust protection of critical image data from acquisition to restoration. First, by implementing a "two-factor" dynamic key generation mechanism based on physical unclonable features (PUFs) and real-time grid load on front-end devices, the system fundamentally eliminates the vulnerability of static keys and ensures the device uniqueness, unpredictability, and contextual relevance of encryption keys. Second, the system innovatively employs a content-sensitive layered encryption strategy, intelligently identifying the complexity of image content using metrics such as gradient entropy and matching encryption algorithms of varying strengths to different regions. This approach seamlessly resolves the conflict between security and computational efficiency in heterogeneous device environments. More importantly, the system innovatively applies graph neural networks (GNNs) to encrypted transmission. By leveraging real-time awareness of the dynamic grid topology, it enables intelligent, prioritized scheduling of encryption links and resources, addressing the fundamental inability of traditional solutions to adapt to network changes. Furthermore, by deeply integrating low-density parity-check error correction coding with an adaptive decryption strategy, the system demonstrates exceptional robustness in the face of complex electromagnetic interference and channel errors, ensuring reliable data recovery. Through the synergistic effect of these key technical links, this invention overcomes the limitations of traditional encryption schemes and establishes a new security paradigm that is adaptive to device, content, network, and channel environments. This significantly enhances the security protection level of visual data throughout its lifecycle in critical infrastructure such as smart grids.
[0121] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0122] References herein to "one embodiment," "an embodiment," or "one or more embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Furthermore, please note that instances of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.
[0123] In the description provided herein, a large number of specific details are described. However, it is understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.
[0124] In the claims, any reference signs placed between brackets shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application may be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.
[0125] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An image encryption system in a smart grid environment, characterized in that: include: At least one terminal device, the terminal device comprising: an image acquisition unit for acquiring real-time images of power grid equipment; a dynamic key generation unit for generating a dynamic session key through a hyperchaotic system using a physical unclonable feature of the terminal device and real-time load data of a power grid node associated with the terminal device; and a hierarchical encryption unit for analyzing the real-time image and performing hierarchical encryption on the image using the dynamic session key. At least one edge device, the edge device comprising: a data receiving and preprocessing unit, configured to receive encrypted data from the terminal device and perform format conversion and integrity verification on the encrypted data; a collaborative encryption unit, configured to perform enhanced encryption on high-complexity regions in the received encrypted data; And, a central device, the central device includes: a global key management unit, used to generate and distribute a master key to the terminal device and the edge device; a decryption and restoration unit, used to decrypt and restore the encrypted data received from the edge device.
2. The system according to claim 1, wherein: The dynamic key generation module is further configured to: The physical unclonable feature is hashed and used as the initial state value of the hyperchaotic system; The real-time operating status data is quantified into a load fluctuation factor to dynamically modulate the system parameters of the hyperchaotic system.
3. The system according to claim 1, wherein: The central device is further configured to perform the following actions: Analyzing the data output by the decryption and restoration unit to identify potential operational risks of the power grid; Based on the potential operational risks, dispatch instructions or safety warnings are generated and issued.
4. The system according to claim 1, wherein: The system also includes a blockchain evidence storage module, which is configured to: Capturing key operations in the layered encryption, enhanced encryption, and decryption and restoration processes, including timestamps, operation subjects, and key hashes; The key operations are recorded as transactions on the distributed ledger to provide tamper-proof security auditing and traceability.
5. The system according to claim 1, wherein: The layered encryption unit is further configured to perform the following actions: Calculating the gradient entropy value of each image block in the real-time image; Determining the image block whose gradient entropy value is greater than a preset threshold as a high complexity area; Encrypting the high-complexity region using a first encryption strategy, and encrypting the non-high-complexity region using a second encryption strategy different from the first encryption strategy; The first encryption strategy is a cascade of hyperchaotic encryption and block cipher algorithms, and the second encryption strategy is a lightweight block cipher algorithm.
6. The system according to claim 1, wherein: The system further includes a topology-aware transmission module configured to perform the following actions: Build and dynamically update a topological map representing the current smart grid; Inputting the topology graph into a graph neural network model to calculate the priority of each data transmission link; The data transmission between the terminal device and the edge device is scheduled according to the priority.
7. The system according to claim 1, wherein: The collaborative encryption unit is further configured to perform the enhanced encryption on the high-complexity region using a hybrid encryption algorithm, the hybrid encryption algorithm comprising: Utilizing a hyperchaotic system to perform pixel scrambling on the high-complexity region; The scrambled pixel data is further encrypted using the AES algorithm.
8. The system according to claim 1, wherein: The edge device further includes a low-density parity check code encoding unit for encoding the data before sending it; the decryption and restoration unit in the central device further includes a low-density parity check code decoding unit, which is further configured to: When the channel quality parameter indicates that the channel quality has degraded and exceeds a preset threshold, the number of iterations of the hyperchaotic system for decryption is adaptively increased, and / or the number of iterations of low-density parity-check code decoding is increased.
9. The system according to any one of claims 1 to 8, characterized in that The central device further includes a federated learning center module, which is configured to: aggregating encrypted model parameter updates from a plurality of said edge devices to form an aggregated gradient; locally updating and training a global optimization model using the aggregated gradient to generate optimized global model parameters; The optimized global model parameters are sent to each edge device to achieve collaborative evolution of the encryption model.
10. An image encryption method in a smart grid environment, characterized in that: The method includes encryption, transmission and decryption steps performed by the system according to any one of claims 1 to 9, corresponding to the functions of each unit or module.
Citation Information
Patent Citations
Power transmission line image data encryption and decryption method
CN113763493A
Smart power grid data aggregation method and system based on security mask
CN117155692A
Power distribution network distributed energy storage cooperative operation control method and system based on multi-agent reinforcement learning
CN118040731A
Data security management system and method in smart power grid
CN119598484A
Multi-layer distributed micro-grid control system and method based on edge cloud collaborative lightweight reinforcement learning
CN120073869A
Cited By
Power grid network data security management system
CN121261918A
A power grid network data security management system
CN121261918B
Security encryption method and system for mainboard hardware
CN121351161A
Picture encryption internet transmission method and system
CN121397158A
Quantum random encryption method and device for video image information
CN121665037A