Smart grid authentication and key negotiation method and system considering dynamic identity matching table
By generating a dynamic identity matching table through a hash function, the problems of secure communication and privacy protection in resource-constrained environments of smart meters are solved, lightweight authentication and key negotiation are realized, and the security and efficiency of smart grid communications are improved.
Patent Information
- Application Number
- CN202510963180.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-10-10
AI Technical Summary
Existing technologies make it difficult to achieve efficient secure communication and privacy protection in resource-constrained smart meters. Traditional public key technology has high computational complexity and cannot adapt to the resource-constrained smart meter environment in smart grids. In addition, the dynamic identity matching mechanism is insufficient, resulting in low security in the transmission process.
A dynamic identity matching table is generated using a hash function. Dynamic identity matching and authentication information comparison are achieved through a random number generation and encryption process between the smart meter and the service provider. Public key technology is omitted, and only the hash function is used to generate the session key.
It reduces computational complexity, improves system operation efficiency, protects user privacy, ensures information security, is suitable for resource-constrained smart grid equipment environments, and realizes lightweight authentication and key negotiation.
Smart Images

Figure CN120768613A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of smart grid communication security technology. More specifically, it relates to a smart grid authentication and key agreement method and system taking into account a dynamic identity matching table. The invention aims to provide a lightweight method with privacy protection, high efficiency, security and applicability to resource-constrained environments. Background Art
[0002] Smart grids collect and analyze data from the grid through key components such as smart meters to regulate and distribute electricity. However, smart meters typically have limited computing resources, making it difficult to directly deploy traditional security measures. Existing technologies use public key technology for privacy protection, resulting in low system efficiency in resource-limited smart meters. This makes it particularly important to develop specialized lightweight authentication protocols to ensure secure communication and user privacy.
[0003] Prior art document 1 (CN120185809A) discloses a smart grid authentication and key agreement method based on NTRU lattice. Since it uses NTRU public key technology, the selected modulus is as high as 2048 and the dimension is as high as 1499, which involves modular multiplication / modular addition operations on high-dimensional polynomial rings. Polynomial multiplication requires O(N 2 ) Time complexity, key generation and encryption / decryption are time-consuming, increasing latency and power consumption; using physical unclonable functions, physical stimulation is required to generate responses, the response time is in milliseconds, and multiple sampling and averaging are required to resist noise, which is highly dependent on the physical characteristics of the device hardware and is not suitable for resource-constrained smart meters; the fuzzy extractor then corrects the physical unclonable function, and the operation consumes KB-level data computing power; the hash function is used to assist key generation and verification in the prior art document 1, but does not play a core security function. The four types of technologies are superimposed to realize power grid authentication and key negotiation, resulting in large data transmission overhead, long delay and device limitations, resulting in low efficiency of the method, and the introduction of pseudonym PID SM However, pseudonym generation relies on the long-term key A2. If an attacker cracks a single session, the pseudonym association relationship can be inferred. The inability to dynamically refresh the identifier leads to the exposure of historical messages, the inability to protect user privacy, and the low security of the transmission process.
[0004] Prior art document 2 (CN119561699A) discloses a lightweight smart meter authentication method based on modular grouping. Since its identity authentication uses elliptic curve point multiplication and modular inverse calculation, the computational complexity is high. When forwarding data, a session key is generated and the ciphertext needs to be signed with ECDSA. The signature verification requires multiple elliptic curve operations, which further increases the computational load and leads to low efficiency of the method. Prior art document 2 describes that the smart meter authentication stage needs to carry fixed parameters (Y, n i ,H(n i ,b i), attackers can track multiple messages from the same device by associating these fixed values, and message b i After a leak, the device needs to be revoked through broadcast, further exposing its identity. The lack of a dynamic identity matching mechanism makes messages linkable, making secure communication impossible and the transmission process less secure.
[0005] Prior art document 3 (CN117749447A) discloses a smart meter identity authentication method that resists collusion attacks. Since its identity authentication uses public key decryption to perform modular exponentiation operations, and the Chinese remainder theorem constructs congruence equations to perform modular operations and solves them, the operation is highly complex, time-consuming, and inefficient. Resource-constrained smart meters cannot afford the decryption overhead, and only the authentication of smart meters is realized. Each authentication of the smart meter requires sending (X, n i ,H(n i ,a i ), parameters X and n i Long-term fixation: After an attacker intercepts multiple session data, they can directly link the communication of the same device through statistical analysis links. Because the identity identifier IDi remains unchanged and the long-term identity identifier is not hidden, the transmission process is less secure. Summary of the Invention
[0006] To address the deficiencies in the prior art, the present invention provides a smart grid authentication and key negotiation method and system taking into account a dynamic identity matching table, aiming to solve the security authentication and key negotiation problems between smart meters and service providers, and is particularly suitable for resource-constrained smart meter environments.
[0007] The present invention adopts the following technical solutions.
[0008] A first aspect of the present invention provides a smart grid authentication and key agreement method taking into account a dynamic identity matching table, characterized in that:
[0009] A random number of length L0 is randomly generated by the smart meter and set as the first identity of the smart meter;
[0010] The service provider randomly generates a first random number and a second random number of length L0 and stores them in the dynamic identity matching table of the service provider;
[0011] Encrypting the first identity identifier through a hash function to obtain a first encrypted identity identifier;
[0012] A third random number of length L0 is randomly generated by the smart meter and encrypted by a hash function, and the first authentication information is solved according to the encrypted third random number;
[0013] Match the first random number and the corresponding second random number in the dynamic identity matching table, combine the first encrypted identity identifier to solve the first verification information and compare and verify it with the first authentication information, and after the verification is passed, solve the first verification code, the second verification code and the second authentication information according to the hash function, and update the dynamic identity random table;
[0014] The first verification code and the second verification code are decrypted by the smart meter and the decrypted authentication information is compared with the second authentication information. If the two are equal, the identity of the smart meter is updated and the authentication process is determined to be complete, which is used for smart grid authentication and key negotiation taking into account the dynamic identity matching table.
[0015] Preferably, the randomly generating a first random number and a second random number with a length of L0 and storing them in the dynamic identity matching table includes:
[0016] Randomly generate a first random number and a second random number with a length of L0, set the first random number and the second random number to the latest first random number and the latest second random number respectively, set the null value to the old first random number and the old second random number, and store the old first random number, the old second random number, the new first random number and the latest second random number in the dynamic identity matching table.
[0017] Preferably, encrypting the first identity includes:
[0018] Concatenate the second random number with the long-term key of the service provider, and input the concatenation result into the hash value of the hash function;
[0019] Determine whether the length of the hash value meets the set length constraint. If the length of the hash value is greater than or equal to the set data length, the hash value is determined to meet the length constraint, and the first L0 bytes of the hash value are intercepted and set as the hash output;
[0020] The first identity identifier of the smart meter is encrypted by performing an XOR operation on the hash output and the first identity identifier of the smart meter to obtain a first encrypted identity identifier.
[0021] Preferably, solving the first authentication information based on the encrypted third random number includes:
[0022] A third random number of length L0 is randomly generated by the smart meter, the first random number is concatenated with the first identity identifier of the smart meter, the result is input into a hash function, and the third random number is encrypted by performing an XOR operation on the hash function output and the third random number;
[0023] The first identity identifier of the smart meter is connected with the encrypted third random number, input into a hash function, and solved to obtain first authentication information.
[0024] Preferably, matching the first random number and the corresponding second random number in the dynamic identity matching table and solving the first verification information in combination with the first encrypted identity identifier includes:
[0025] Searching the dynamic identity matching table for the first random number in the received message and the corresponding second random number. If no match is found, the service provider denies the service.
[0026] If a match is found, the second random number is concatenated with the service provider's long-term key, inputted into a hash function, and the output of the hash function is XORed with the first encrypted identity to obtain a second identity.
[0027] The second identity identifier is concatenated with the encrypted third random number and input into a hash function to obtain first verification information.
[0028] Preferably, solving the first verification code and the second verification code includes:
[0029] The service provider performs a concatenation operation using the second identity identifier and the first random number, inputs the hash function, and performs an XOR operation on the output of the hash function and the second random number to obtain a first verification code;
[0030] The service provider uses the second identity to perform a concatenation operation with the first random number and the second random number, inputs the hash function, and performs an XOR operation on the output result of the hash function and the second encrypted identity to obtain a second verification code.
[0031] Preferably, solving the second authentication information includes:
[0032] The first random number is concatenated with the second identity identifier and input into a hash function, and an XOR operation is performed on the hash function output and the encrypted third random number to obtain a decrypted third random number;
[0033] The service provider concatenates the second identity, the second random number, and the decrypted third random number and inputs the concatenated number into a hash function to calculate a session key.
[0034] The session key is concatenated with the second encryption identity and input into a hash function to calculate and obtain the second authentication information.
[0035] Preferably, the updating of the dynamic identity random table includes:
[0036] The service provider updates the first random number in the dynamic identity matching table as the first random number, updates the old second random number as the second random number, updates the new first random number as the second random number, and updates the new second random number as the decrypted third random number, if the connection between the smart meter and the service provider is abnormally disconnected, the next time the service request is executed, the first random number sent by the smart meter is matched to the first random number in the old first random number in the dynamic identity matching table, and the service request is continuously executed.
[0037] Preferably, the first verification code and the second verification code are decrypted, and the decrypted authentication information is compared with the second authentication information, if the two are equal, the identity of the smart meter is updated, including:
[0038] The first identity and the first random number are connected and input into a hash function, and the output result of the hash function is XORed with the first verification code to obtain the decrypted second random number; the first identity, the first random number and the decrypted second random number are connected and input into a hash function, and the result of the hash function is XORed with the second verification code to obtain the decrypted second encrypted identity;
[0039] The first identity, the decrypted second random number and the third random number are connected and input into a hash function to obtain the decrypted session key; the decrypted session key and the decrypted second encrypted identity are connected and input into a hash function to solve the decrypted authentication information;
[0040] The decrypted authentication information is compared with the second authentication information, if the two are equal, it is determined that the decrypted session key and the decrypted second encrypted identity are correct and accurate, and it is determined that the authentication process is completed.
[0041] The second aspect of the application provides a smart grid authentication and key agreement system considering a dynamic identity matching table, according to the smart grid authentication and key agreement method considering a dynamic identity matching table, including:
[0042] The identity solving module is used for randomly generating a random number with a length of L0 by the smart meter, and setting it as the first identity of the smart meter;
[0043] The dynamic identity matching table storage module is used for randomly generating a first random number and a second random number with a length of L0 by the service provider and storing them into the dynamic identity matching table of the service provider;
[0044] The identity encryption module is used for encrypting the first identity by a hash function to obtain a first encrypted identity;
[0045] An authentication information solving module, configured to randomly generate a third random number of length L0 through the smart meter, encrypt the third random number through a hash function, and solve the first authentication information based on the encrypted third random number;
[0046] A verification information solving module is used to match the first random number and the corresponding second random number in the dynamic identity matching table, solve the first verification information in combination with the first encrypted identity identifier, and compare and verify it with the first authentication information. After the verification is successful, the first verification code, the second verification code, and the second authentication information are solved according to the hash function, and the dynamic identity random table is updated;
[0047] The authentication module is used to decrypt the first verification code and the second verification code through the smart meter and compare the decrypted authentication information with the second authentication information. If the two are equal, the identity of the smart meter is updated and the authentication process is determined to be complete. It is used for smart grid authentication and key negotiation taking into account the dynamic identity matching table.
[0048] Compared with the prior art, the beneficial effects of the present invention include at least:
[0049] Attackers cannot link messages from the same device, nor do they know the identity of the sender of the message. Only the receiver SP knows the sender's identity. The present invention uses the service provider as the receiver, maintains a dynamic identity matching table, and sends the random number in the dynamic identity matching table to the sender as an identifier. Each time the sender sends a message, the message contains a random number as an identifier. The SP matches this random number in the dynamic identity matching table. If the match is successful, the sender's identity is determined, otherwise the service is denied. At the same time, each random number is only used once, which ensures that all messages are random from the attacker's perspective, ensures the unlinkability of user messages, fully protects user privacy, ensures information security during smart grid communication, and improves the security of quality inspection communications between the smart grid and the service provider.
[0050] During the implementation process of the present invention, only the most basic hash function is used. The session key is generated by the hash function and then the authentication information is generated. The use of public key technology is omitted. Under the premise of ensuring information security and user privacy, the demand for computing resources is greatly reduced, the computing complexity is significantly reduced, the computing resource consumption is reduced, the system operation efficiency is improved, and the authentication and key negotiation processes are lightweight. It is suitable for smart grid environments, making it more suitable for resource-constrained smart grid equipment environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a schematic diagram of a process provided according to an embodiment of the present invention;
[0052] Figure 2 According to the embodiment of the present invention, a smart meter SM is provided iTo the service provider SP j Schematic diagram of the registration process diagram;
[0053] Figure 3 The smart meter SM provided in accordance with the embodiment of the present invention i With service provider SP j Schematic diagram of the authentication and key negotiation process. DETAILED DESCRIPTION
[0054] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. The described embodiments are only part of the embodiments of the present invention, not all of them. Based on the spirit of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present invention.
[0055] like Figure 1 As shown, embodiment 1 of the present invention provides a smart grid authentication and key agreement method and system taking into account a dynamic identity matching table, comprising the following steps:
[0056] Step 1: Through smart meter SM i Randomly generate a random number of length L0 and set it as the smart meter SM i First identity ID i , and the ID i Sent to the service provider SP j .
[0057] Step 2, such as Figure 2 As shown, a first random number r1 and a second random number r2 with a length of L0 are randomly generated by a service provider and stored in the dynamic identity matching table.
[0058] In a preferred but non-limiting embodiment of the present invention, step 2 comprises:
[0059] Randomly generate a first random number r1 and a second random number r2 of length L0, and set the first random number r1 and the second random number r2 as the latest first random number and the latest second random number Set the null value to the old first random number and the old second random number The old first random number, the old second random number, the new first random number and the latest second random number are stored in the dynamic identity matching table, where nil represents a null value, and the service provider SP j The dynamic identity matching table stores two sets of data for each smart meter, one set is the most recently used data The other group is unused data
[0060] Step 3: Combine the second random number with SP j The long-term key s is used to hash SP j Received SM i First identity ID i Encryption, and sending the encrypted smart meter identity message and the first random number to the smart meter.
[0061] In a preferred but non-limiting embodiment of the present invention, step 3 comprises:
[0062] Step 3.1, the second random number r2 and SP j The long-term key s is used for concatenation, and the concatenation result is input into the hash function set in step 1 to solve the hash value;
[0063] Step 3.2, determine whether the length of the hash value meets the set length constraint. If the length of the hash value is greater than or equal to the set data length, determine that the hash value meets the length constraint, intercept the data length L0 bytes before the hash value, and set it as the hash output.
[0064] Step 3.3, pass the hash output of step 3.2 and SM i First identity ID i Perform an XOR operation to encrypt the first identity of the smart meter to obtain a first encrypted identity M, which is expressed as the following formula:
[0065]
[0066] Where,
[0067] M represents the first encryption identity,
[0068] h(·) represents the hash function,
[0069] represents the exclusive OR operation,
[0070] || represents a concatenation operation.
[0071] Step 3.4, SP j Send the calculated {M, r1} to SM i .
[0072] Step 4, such as Figure 3 As shown, SM i Receive and store data from SP j {M,r1}, through the smart meter SM i Randomly generate a third random number r3 of length L0, SM iFirst identity ID i The first random number r1 obtained in step 3 is encrypted using a hash function, and the first authentication information is solved based on the encryption result. The first random number, the encrypted smart meter identity, the third random number and the first authentication information are combined into a message {r1, M, X, Auth i}Sent to the service provider, only the corresponding SP j You can know SM through these messages i identity.
[0073] In a preferred but non-limiting embodiment of the present invention, step 4 comprises:
[0074] Step 4.1, through the smart meter SM i Randomly generate a third random number r3 of length L0, the first random number r1 and SM i First identity ID i Perform a concatenation operation, input the hash function, and encrypt the third random number by performing an XOR operation on the hash function output and the third random number r3 to obtain the encrypted third random number X, which is expressed as the following formula:
[0075]
[0076] Where,
[0077] X represents the encrypted third random number.
[0078] Step 4.2, SM i First identity ID i Connect it with X obtained in step 4.1, input the hash function, and solve to get the first authentication information Auth i , expressed as follows:
[0079] Auth i =h(ID i ||X) (3)
[0080] Auth i =h(ID i ||X) followed by SM i The message {r1,M,X,Auth i}Sent to the service provider SP j .
[0081] Step 5: Match the first random number r1 and the corresponding second random number r2 in the received message of step 4 in the dynamic identity matching table of step 3 to obtain the verification information Auth′ i Auth′ i The Auth message in step 4i Compare and verify, and solve M based on the verification results new And encrypt to get V1 and V2, according to M new Solve authentication information Auth j , the authentication information Auth j Combined with V1 and V2 to form the message {Auth j ,V1,V2} sent to SM i , update the dynamic identity matching table.
[0082] Step 5.1, Service Provider SP j Receive SM i After receiving the message, the first random number r1 in the received message and the corresponding second random number r2 are searched in the dynamic identity matching table obtained in step 2. If no match is found, the service provider refuses the service. If a match is found, the second identity ID′ is solved. i and the first verification information Auth′ i .
[0083] Further preferably, step 5.1 includes:
[0084] Step 5.1.1, Service Provider SP j Receive SM i After receiving the message, the first random number r1 in the received message and the corresponding second random number r2 are searched in the dynamic identity matching table obtained in step 3. If no match is found, the service is denied. If a match is found, the service is denied through the second random number r2 and the SP j The result of the concatenation operation of the long-term key s stored by itself is input into the hash function, and the output value of the hash function is XORed with the first encrypted identity M to obtain the second identity ID′ i , expressed as follows:
[0085]
[0086] Where,
[0087] ID′ i Indicates the second identity, which is the service provider SP j Calculated SM i Identity identification.
[0088] Service Provider SP j By the new first random number in the dynamic identity matching table and the old first random number Match the first random number r1 to find the corresponding second random number r2.
[0089] Step 5.1.2, the ID′ obtained in step 5.1.1i Perform a connection operation with X, input the hash function, and obtain the first verification information Auth′ i , expressed as follows:
[0090] Auth′ i =h(ID′ i ||X) (5)
[0091] Step 5.2: Auth′ calculated in step 5.1 i With the receipt of SM i Auth in the message i Perform comparison verification, if Auth′ i ≠Auth i , determine that the comparison fails and deny service, if Auth′ i =Auth i , determine that the comparison is successful, the verification is passed, and solve the second encrypted identity M new .
[0092] Further preferably, step 5.2 includes:
[0093] Auth′ calculated in step 5.1 i With the receipt of SM i Auth in the message i Perform comparison verification, if Auth′ i ≠Auth i , the comparison fails, the service provider refuses the service, if Auth′ i =Auth i , the comparison is successful, the verification is passed, the third random number r3 and ID' i Perform the connection operation and input the hash function, perform the XOR operation on the output of the hash function and X to obtain the second encrypted identity M new , expressed as follows:
[0094]
[0095] Where,
[0096] M new Represents the second encrypted identity, ID′ encrypted with r3 and s i information.
[0097] Step 5.3, SP j Use the second identity ID' calculated in step 5.1 i and r1 respectively for r2 and M solved in step 5.2 new Encrypt to form V1 and V2.
[0098] Further preferably, step 5.3 includes:
[0099] Step 5.3.1, SP j Use ID′ i The result of the hash function is XORed with r2 to obtain the first verification code V1, which is expressed as follows:
[0100]
[0101] Step 5.3.2, SP j Use ID′ i , r1 and r2 are connected and input into the hash function, and the output of the hash function is the same as M new Perform an XOR operation to obtain the second verification code V2, which is expressed as the following formula:
[0102]
[0103] Step 5.4, according to the ID′ calculated in step 5.1 i Calculate the session key SK with r′3 calculated in step 5.2, and add SK to M calculated in step 5.2. new Solve the second authentication information Auth j , combine the second authentication information with V1 and V2 calculated in step 5.3 to form the message {Auth j ,V1,V2} sent to SM i , update the dynamic identity matching table.
[0104] Further preferably, step 5.4 includes:
[0105] Step 5.4.1, through r1 and ID′ i Perform a concatenation operation and input the hash function. Perform an XOR operation on the hash function output and the encrypted third random number X to obtain the decrypted third random number r′3, which is expressed as the following formula:
[0106]
[0107] Step 5.4.2, SP j ID′ i , r2 and r′3 are concatenated and input into the hash function to calculate the session key SK, which is expressed as the following formula:
[0108] SK=h(ID′ i ||r2||r′3) (10)
[0109] Step 5.4.3: Compare the session key SK obtained in step 5.4.1 with the M calculated in step 5.2.new Perform the connection operation and input the hash function to calculate the second authentication information Auth j , expressed as follows:
[0110] Auth j =h(SK||M new ) (11)
[0111] Step 5.4.3, combine the authentication information with V1 and V2 calculated in step 5.3 to form the message {Auth j ,V1,V2} sent to SM i At the same time, SP j Update the corresponding SM in the dynamic identity matching table i information, will Updated to r1, Updated to r2, Updated to r2, Update to r′3, that is, and Back up the most recently used r1 and r2. If the protocol is abnormally disconnected and SM does not update the new first random number, the next time a service request is executed, SM i The first random number r1 sent will be matched in the dynamic identity matching table r1 in, continue to execute the service request.
[0112] This update mechanism ensures that even if the protocol is abnormally disconnected at this time, both parties can still stay synchronized.
[0113] Step 6, SM i Receive SP j Message sent {Auth j ,V1,V2}, according to SM i ID i and r1, decrypt the first verification code V1 and the second verification code V2 through the smart meter, and then solve SK' according to r'2, according to SK' and M' new Solving Auth′ j , compare the authentication information Auth′ j Auth in the message j ,If the two are equal, the identity of the smart meter is updated, and the ,authentication process is determined to be completed, thus realizing ,lightweight authentication key negotiation for smart grid communication.
[0114] In a preferred but non-limiting embodiment of the present invention, step 6 comprises:
[0115] Step 6.1, SM i Receive SP j Message sent {Auth j,V1,V2}, then the ID i Concatenate it with r1 and input the hash function. XOR the hash function output with V1 in the message to get r′2, which is expressed as follows:
[0116]
[0117] Where r′2 represents the second random number after decryption, which is SM i Calculated r2.
[0118] Step 6.2, ID i , r1 and r′2 obtained in step 6.1 are concatenated and input into the hash function. The result of the hash function is XORed with V2 to obtain M′ new , expressed as follows:
[0119]
[0120] Where M′ new Indicates the second encrypted identity after decryption, SM i The calculated M new .
[0121] Step 6.3, ID i , r′2 and r3 obtained in step 6.1 are concatenated and input into the hash function to obtain the decrypted session key SK′, which is expressed as the following formula:
[0122] SK′=h(ID i ||r′2||r3) (13)
[0123] Step 6.4, SK′ and M′ new Perform the connection operation and input the hash function to solve the decrypted authentication information Auth′ j , expressed as follows:
[0124] Auth′ j =h(SK′||M′ new ) (14)
[0125] Step 6.5: Compare the decrypted authentication information Auth′ obtained in step 6.4 j With Aurh in the message j If the two are equal, the authentication process is determined to be complete, and lightweight authentication key negotiation for smart grid communication is realized. i Compare the Auth in the received message j and the new authentication information Auth′ obtained in step 6.4 j , if the two are equal, then SM iDetermine SK and M' new If all are correct, the authentication process is completed and r1=r′2 and M=M′ are updated. new , SM i The first random number r1 in is replaced by the decrypted second random number r′2, and the first encrypted identity M is replaced by the decrypted second encrypted identity. When the protocol is executed next time, no repeated r1 will be used, which ensures the unlinkability of user messages.
[0126] It is worth noting that, in view of the existing technology, since the identity identifier IDi of the smart meter remains unchanged, the attacker can directly link the communication of the same device through statistical analysis after intercepting multiple session data. The long-term identity identifier is not hidden, resulting in low security in the transmission process. The present invention adopts a dynamic identity matching table. and the old second random number Back up the most recently used first random number r1 and second random number r2 in the new first random number and the new second random number, back up the second random number r2 and the decrypted third random number r′3, replace the first random number r1 of the smart meter with the decrypted second random number r′2, and replace the first encrypted identity M with the decrypted second encrypted identity M′ new In the next authentication and key negotiation process, the decrypted second random number r′2 after the smart meter is replaced will be searched in the dynamic identity matching table, and the second random number r2 in the new first random number in the dynamic identity matching table will be matched. The second encrypted identity M′ after decryption of the corresponding new second random number r′3 and the updated identity of the smart meter will be combined. new The verification information is solved and compared and verified. By dynamically updating the dynamic identity matching table and the identity of the smart meter, the user identity is inconsistent during each communication process. Therefore, after an attacker intercepts multiple session data, it is impossible to directly link the communication of the same device through statistical analysis links, which ensures the unlinkability of user messages. It also ensures that even if the protocol is abnormally disconnected at this time, the two parties can still maintain synchronization by searching the current "first random number" of the smart meter in the old first random number and the new first random number in the dynamic identity matching table.
[0127] Embodiment 2 of the present invention provides a smart grid authentication and key agreement system taking into account a dynamic identity matching table, which runs the smart grid authentication and key agreement method taking into account a dynamic identity matching table described in embodiment 1, including:
[0128] An identity identification solution module is used to randomly generate a random number of length L0 through the smart meter and set it as the first identity identification of the smart meter;
[0129] A dynamic identity matching table storage module, configured to randomly generate a first random number and a second random number of length L0 through a service provider and store the generated numbers in a dynamic identity matching table of the service provider;
[0130] An identity encryption module, configured to encrypt the first identity using a hash function to obtain a first encrypted identity;
[0131] An authentication information solving module, configured to randomly generate a third random number of length L0 through the smart meter, encrypt the third random number through a hash function, and solve the first authentication information based on the encrypted third random number;
[0132] A verification information solving module is used to match the first random number and the corresponding second random number in the dynamic identity matching table, solve the first verification information in combination with the first encrypted identity identifier, and compare and verify it with the first authentication information. After the verification is successful, the first verification code, the second verification code, and the second authentication information are solved according to the hash function, and the dynamic identity random table is updated;
[0133] The authentication module is used to decrypt the first verification code and the second verification code through the smart meter and compare the decrypted authentication information with the second authentication information. If the two are equal, the identity of the smart meter is updated and the authentication process is determined to be complete. It is used for smart grid authentication and key negotiation taking into account the dynamic identity matching table.
[0134] In Example 3 of the present invention, all data length is 8 bytes and the hash function is SM3 as an example:
[0135] Initial stage:
[0136] Step 1: Smart MeterSM i Generate a random number as ID i , assuming ID i =0xD5744897. Then send ID i To the service provider SP j .
[0137] Step 2: Service Provider SP j Generate two random numbers, assuming r1 = 0xE47FB6D7, r2 = 0x8B726E9F. Then calculate Assume SP j If the output of SM3 is greater than 8 bytes, the first 8 bytes are selected as the output. Then, SP j Send M,r1 to SM i , and save to the dynamic identity matching table, where nil represents an empty value.
[0138] Step 3: SM i Receive and store data from SP j {M,r1}.
[0139] Authentication and key negotiation phase:
[0140] Step 1: Smart MeterSM i Generate a random number r3, assuming r3 = 0xE0013A0D, and then calculate and Auth i =h(ID i ||X), the calculation process is the same as M, and we get X=0xC9E17589,Auth i =0xC296C738. Then SM i The message {r1,M,X,Auth i}Sent to the service provider SP j .
[0141] Step 2: SP j After receiving the message, it first searches for the received r1 and the corresponding data r2 in its dynamic identity matching table, assuming a match is found. Then SP j calculate and Auth′ i =h(ID′ i ||X) respectively calculate ID′ i =0xD5744897 and verification information Auth′ i =0xC296C738, and calculate the Auth′ i With the received Auth i Perform comparison verification. i =Auth′ i , verified, SP j calculate and Calculate r′3=0xE0013A0D and M new =0xCF2BF12F. Then, SP j Use ID′ i and r1 respectively for r2 and M new Encrypt to form and The calculation results are V1 = 0xA292211B, V2 = 9A8EECE2. Then, SP j According to the formula SK=h(ID′ i||r2||r′3) calculates the session key SK=0x5D26D770, and uses the formula Auth j =h(SK||M new )Generate authentication information Auth j =0x33ADEB16, and finally the message {Auth j ,V1,V2} sent to SM i At the same time, SP j The corresponding SM in the dynamic identity matching table will also be updated i Information, updates
[0142] Step 3: SM i Receive SP j After the message is sent, according to its own ID i and r1, respectively. and Get r′2=0x8B726E9F,M′ new =0xCF2BF12F. Then, according to the formula SK=h(ID i ||r′2||r3) calculates the session key SK=0x5D26D770, and uses the formula Auth′ j =h(SK||M′ new ) Generate authentication information Auth′ j =0x33ADEB16. Finally, SM i Compare the received Auth j and Auth′ calculated by itself j Auth j =Auth′ j =0x33ADEB16, then SM i Determine SK and M′ new All are correct, thus completing the authentication process, and updating r1=r′2=0x8B726E9F and M=M′ new =0xCF2BF12F.
[0143] It is worth noting that the present invention uses the first identity identifier of the smart meter provided by the service provider in combination with the service provider's own long-term key to encrypt the information through a hash function, and sends the information together with the first random number generated by the service provider to the smart meter to establish a connection between the service provider and the smart meter and confirm their identities.
[0144] The smart meter generates first authentication information by performing XOR, hashing, and concatenation operations, combined with the first random number transmitted by the service provider, and then sends the first authentication information to the service provider;
[0145] The service provider encrypts the first identity of the smart meter through an exclusive OR, concatenation operation, and a hash function to obtain a first encrypted identity, and combines the encryption result with the concatenation operation and the hash function to generate first verification information. The first verification information is compared and verified with the first authentication information sent by the smart meter. Based on the verification result, the service provider performs an exclusive OR, concatenation, and hash function operation on the first encrypted identity, the service provider's own long-term key, and the first random number to obtain a first verification code, a second verification code, and a second authentication information, and sends them to the smart meter.
[0146] The smart meter decrypts the first verification code and the second verification code through exclusive-or, concatenation, and hash function operations, and generates decrypted authentication information in combination with the first identity identifier through a hash function. The decrypted authentication information is compared with the second authentication information. If the results are consistent, the authentication and key negotiation are determined to be complete.
[0147] The distinguishing technical features of the present invention that are closely related, interdependent, have synergistic effects, jointly solve the same technical problem, and produce related technical effects should be considered as a whole and should not be simply evaluated separately.
[0148] Example 4 of the present invention provides a comparative experiment on the advantages of the present invention and the prior art.
[0149] In Example 4, the computational costs of the computing elements used in the present invention and the prior art, Comparative Documents 1, 2, and 3, were compared and tested. Specifically, on the same hardware platform, each computing element was implemented in software, and the time required for a single execution was measured, with the length of time used as a measure of the computational cost. The test platform was a Raspberry Pi 5 running Linux, equipped with an Arm Cortex-A76 processor. All tests used a fixed input data length of 160 bits. The test results are shown in the following table:
[0150] Table 1 Efficiency comparison between the present invention and the prior art
[0151] Calculation method used Computation time for authentication and key agreement in smart grids Hash function 0.702 microseconds Physical unclonable function 378.945 microseconds Fuzzy Extractor 110.041 microseconds Scalar multiplication in public key cryptography 608.988 microseconds
[0152] The test results show that the hash function executes significantly faster than other computing elements, at least a hundred times faster. The present invention uses only the hash function as its core computing element, while Comparative Document 1 uses a hash function, PUF, a fuzzy extractor, and public-key encryption technology, and Comparative Documents 2 and 3 use both hash functions and public-key encryption technology. Therefore, the present invention has a clear advantage in computational efficiency.
[0153] Compared with the prior art, the beneficial effects of the present invention include at least:
[0154] Attackers cannot link messages from the same device, nor do they know the identity of the sender of the message. Only the receiver SP knows the sender's identity. The present invention uses the service provider as the receiver, maintains a dynamic identity matching table, and sends the random number in the dynamic identity matching table to the sender as an identifier. Each time the sender sends a message, the message contains a random number as an identifier. The SP matches this random number in the dynamic identity matching table. If the match is successful, the sender's identity is determined, otherwise the service is denied. At the same time, each random number is only used once, which ensures that all messages are random from the attacker's perspective, ensures the unlinkability of user messages, fully protects user privacy, ensures information security during smart grid communication, and improves the security of quality inspection communications between the smart grid and the service provider.
[0155] During the implementation process of the present invention, only the most basic hash function is used. The session key is generated by the hash function and then the authentication information is generated. The use of public key technology is omitted. Under the premise of ensuring information security and user privacy, the demand for computing resources is greatly reduced, the computing complexity is significantly reduced, the computing resource consumption is reduced, the system operation efficiency is improved, and the authentication and key negotiation processes are lightweight. It is suitable for smart grid environments, making it more suitable for resource-constrained smart grid equipment environments.
[0156] The present disclosure may be a system, method and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.
[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.
Claims
1. A smart grid authentication and key agreement method taking into account a dynamic identity matching table, characterized in that: The following steps are involved: A random number of length L0 is randomly generated by the smart meter and set as the first identity of the smart meter; The service provider randomly generates a first random number and a second random number of length L0 and stores them in the dynamic identity matching table of the service provider; Encrypting the first identity using a hash function to obtain a first encrypted identity; A third random number of length L0 is randomly generated by the smart meter and encrypted by a hash function, and the first authentication information is solved according to the encrypted third random number; Match the first random number and the corresponding second random number in the dynamic identity matching table, combine the first encrypted identity identifier to solve the first verification information and compare and verify it with the first authentication information, and after the verification is passed, solve the first verification code, the second verification code and the second authentication information according to the hash function, and update the dynamic identity random table; The first verification code and the second verification code are decrypted by the smart meter and the decrypted authentication information is compared with the second authentication information. If the two are equal, the identity of the smart meter is updated and the authentication process is determined to be completed.
2. The smart grid authentication and key agreement method according to claim 1, wherein: The randomly generating a first random number and a second random number of length L0 and storing them in the dynamic identity matching table includes: Randomly generate a first random number and a second random number with a length of L0, set the first random number and the second random number to the latest first random number and the latest second random number respectively, set the null value to the old first random number and the old second random number, and store the old first random number, the old second random number, the new first random number and the latest second random number in the dynamic identity matching table.
3. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: Encrypting the first identity identifier includes: Concatenate the second random number with the long-term key of the service provider, and input the concatenation result into the hash value of the hash function; Determine whether the length of the hash value meets the set length constraint. If the length of the hash value is greater than or equal to the set data length, the hash value is determined to meet the length constraint, and the first L0 bytes of the hash value are intercepted and set as the hash output; The first identity of the smart meter is encrypted by performing an XOR operation on the hash output and the first identity of the smart meter to obtain a first encrypted identity.
4. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: Solving the first authentication information based on the encrypted third random number includes: A third random number of length L0 is randomly generated by the smart meter, the first random number is concatenated with the first identity identifier of the smart meter, the result is input into a hash function, and the third random number is encrypted by performing an XOR operation on the hash function output and the third random number; The first identity identifier of the smart meter is connected with the encrypted third random number, input into a hash function, and solved to obtain first authentication information.
5. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: Matching the first random number and the corresponding second random number in the dynamic identity matching table and solving the first verification information in combination with the first encrypted identity identifier includes: Searching the dynamic identity matching table for the first random number in the received message and the corresponding second random number. If no match is found, the service provider denies the service. If a match is found, the second random number is concatenated with the service provider's long-term key, inputted into a hash function, and the output of the hash function is XORed with the first encrypted identity to obtain a second identity. The second identity identifier is concatenated with the encrypted third random number and input into a hash function to obtain first verification information.
6. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: Solving the first verification code and the second verification code includes: The service provider performs a concatenation operation using the second identity identifier and the first random number, inputs the hash function, and performs an XOR operation on the output of the hash function and the second random number to obtain a first verification code; The service provider uses the second identity to perform a concatenation operation with the first random number and the second random number, inputs the hash function, and performs an XOR operation on the output result of the hash function and the second encrypted identity to obtain a second verification code.
7. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: The solving of the second authentication information includes: The first random number is concatenated with the second identity identifier and input into a hash function, and an XOR operation is performed on the hash function output and the encrypted third random number to obtain a decrypted third random number; The service provider concatenates the second identity, the second random number, and the decrypted third random number and inputs the concatenated number into a hash function to calculate a session key. The session key is concatenated with the second encryption identity and input into a hash function to calculate and obtain the second authentication information.
8. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: The updating of the dynamic identity random table includes: The service provider updates the first random number in the dynamic identity matching table to the first random number, updates the old second random number to the second random number, updates the new first random number to the second random number, and updates the new second random number to the decrypted third random number. If the connection between the smart meter and the service provider is abnormally disconnected, the next time the service request is executed, the first random number sent by the smart meter matches the first random number in the old first random number in the dynamic identity matching table, and the service request continues to be executed.
9. The smart grid authentication and key agreement method taking into account a dynamic identity matching table according to claim 1, characterized in that: The decrypting the first verification code and the second verification code and comparing the decrypted authentication information with the second authentication information, and if the two are equal, updating the identity of the smart meter includes: Concatenate the first identity identifier and the first random number and input them into a hash function, perform an XOR operation on the output of the hash function and the first verification code to obtain a decrypted second random number; Concatenate the first identity, the first random number, and the decrypted second random number and input them into a hash function, perform an XOR operation on the result of the hash function and the second verification code to obtain a decrypted second encrypted identity; Concatenate the first identity, the decrypted second random number, and the third random number and input them into a hash function to obtain a decrypted session key; Concatenate the decrypted session key with the decrypted second encrypted identity and input them into a hash function to obtain the decrypted authentication information; Compare the decrypted authentication information with the second authentication information. If the two are equal, it is determined that the decrypted session key and the decrypted second encrypted identity are correct. Replace the first random number in the smart meter with the decrypted second random number, and replace the first encrypted identity with the decrypted second encrypted identity. It is determined that the authentication process is complete.
10. A smart grid authentication and key agreement system taking into account a dynamic identity matching table, according to a smart grid authentication and key agreement method taking into account a dynamic identity matching table according to any one of claims 1-9, characterized in that: An identity identification solution module is used to randomly generate a random number of length L0 through the smart meter and set it as the first identity identification of the smart meter; A dynamic identity matching table storage module, configured to randomly generate a first random number and a second random number of length L0 through a service provider and store the generated numbers in a dynamic identity matching table of the service provider; An identity encryption module, configured to encrypt the first identity using a hash function to obtain a first encrypted identity; An authentication information solving module, configured to randomly generate a third random number of length L0 through the smart meter, encrypt the third random number through a hash function, and solve the first authentication information based on the encrypted third random number; A verification information solving module is used to match the first random number and the corresponding second random number in the dynamic identity matching table, solve the first verification information in combination with the first encrypted identity identifier, and compare and verify it with the first authentication information. After the verification is successful, the first verification code, the second verification code, and the second authentication information are solved according to the hash function, and the dynamic identity random table is updated; The authentication module is used to decrypt the first verification code and the second verification code through the smart meter and compare the decrypted authentication information with the second authentication information. If the two are equal, the identity of the smart meter is updated and the authentication process is determined to be complete. It is used for smart grid authentication and key negotiation taking into account the dynamic identity matching table.
Citation Information
Patent Citations
Intelligent electric meter identity authentication method capable of resisting collusion attack
CN117749447A
Lightweight intelligent electric meter authentication method and system based on analog-to-digital grouping
CN119561699A
Smart power grid authentication and key agreement method based on NTRU grid
CN120185809A