Electric power communication data transmission method, system, equipment and medium

By generating parameter sets based on trusted policies and master keys between cloud devices and edge gateways, identity authentication and platform integrity authentication are performed, and shared key pairs are generated to encrypt data transmission, thus solving the problem of low security of power communication data transmission and achieving the credibility and security of data transmission.

CN120785527APending Publication Date: 2025-10-14CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510881467.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

Existing power communication data transmission methods have low security issues and cannot meet today's security and trust requirements, especially at the edge gateway of the power system, where the data transmission risks are relatively high.

Method used

By adopting a trusted strategy and a preset master key generation parameter set between cloud devices and edge gateways, identity authentication and platform integrity authentication are performed, and a shared key pair is generated to encrypt data transmission, ensuring the security of data transmission.

Benefits of technology

It improves the security of power communication data transmission, ensures the legitimacy of the edge gateway and the authentication of cloud devices, and realizes the credibility and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785527A_ABST
    Figure CN120785527A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power communication data transmission method, system, device and medium, which are applied to cloud equipment, and the method comprises the following steps: obtaining a first parameter set according to a preset credible strategy and a preset master key, and sending the first parameter set to an edge gateway; receiving a third parameter set sent by the edge gateway, and determining the legality of the edge gateway according to the third parameter set; if the edge gateway is illegal, determining that the edge gateway is illegal, and stopping data transmission; if yes, obtaining a first shared key pair according to the first parameter set and the third parameter set; and sending data to the edge gateway through the first shared key pair. According to the invention, the security of power communication data transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of power communication, in particular to a power communication data transmission method, system, device and medium. BACKGROUND

[0002] With the rapid development of power communication network, the scale of power communication network is getting larger and larger, and the data collection and transmission of each link of the power system is particularly important. Especially at the edge gateway of the power system, a large amount of data needs to be collected through the gateway and transmitted to the cloud device to ensure the stable operation of the power system. However, the network security problems such as computer viruses and malicious codes are increasing, resulting in frequent security incidents such as information leakage and privacy theft, and the transmission risk of sensitive data is further increased. The existing data transmission method has the problem of low security, which cannot meet the current requirements of security and credibility. SUMMARY

[0003] The present application aims to at least solve one of the technical problems existing in the prior art. To this end, the present application provides a power communication data transmission method, which can improve the security of power communication data transmission.

[0004] The present application also provides a system, device and medium with the above power communication data transmission method.

[0005] According to the power communication data transmission method of the first aspect of the present application, applied to a cloud device, comprising:

[0006] According to the preset trusted strategy and the preset master key, a first parameter set is obtained, and the first parameter set is sent to the edge gateway;

[0007] The third parameter set sent by the edge gateway is received, and the legality of the edge gateway is determined according to the third parameter set; if not legal, it is determined that the edge gateway is not legal, and the data transmission is terminated;

[0008] If legal, a first shared key pair is obtained according to the first parameter set and the third parameter set; data is sent to the edge gateway through the first shared key pair.

[0009] According to the power communication data transmission method, the cloud device sends a first parameter set to an edge gateway of required transmission data, so that the edge gateway knows that the cloud device needs to transmit data and preliminarily verifies the identity of the cloud device through the first parameter set; whether the edge gateway is legal is determined through a third parameter set sent by the edge gateway, and if the edge gateway is legal, it is considered that the edge gateway is trusted and can safely transmit data; finally, the edge gateway transmits data through a first shared key pair obtained according to the first parameter set and the third parameter set, that is, the key for transmitting data is generated through the double-end data of the first parameter set generated by the cloud device and the third parameter set generated by the edge gateway, so as to improve the security of data transmission and the security of power communication data transmission between the cloud device and the edge gateway.

[0010] According to some embodiments of the present application, the first shared key pair obtained according to the first parameter set and the third parameter set comprises:

[0011] A fourth parameter set is obtained according to the first parameter set and the third parameter set, and the fourth parameter set is sent to the edge gateway;

[0012] A fifth parameter set sent by the edge gateway is received, a sixth parameter set is obtained according to the first parameter set, the third parameter set and the fifth parameter set, and a first shared key pair is obtained according to the fifth parameter set and the sixth parameter set.

[0013] According to some embodiments of the present application, the first parameter set comprises a first random value, a first identity certificate and a first serial number; the first random value is a generated random number;

[0014] The first parameter set is obtained according to a preset trusted strategy and a preset master key, and the first parameter set comprises:

[0015] A first complete measurement value is obtained according to a preset trusted strategy, and the first serial number is obtained according to the first complete measurement value;

[0016] The first identity certificate is obtained according to a preset master key.

[0017] According to some embodiments of the present application, the third parameter set comprises a second identity certificate, a second serial number, a second reference value, a second signature value and a second random value;

[0018] The legality of the edge gateway is determined according to the third parameter set, and the legality of the edge gateway comprises:

[0019] Whether the edge gateway passes identity authentication is determined according to the second identity certificate; if not, it is determined that the edge gateway is not legal, and the data transmission is terminated;

[0020] If yes, the second signature value is determined to be legal according to the second identity certificate; if not, the edge gateway is determined to be illegal, and the data transmission is terminated;

[0021] If yes, the edge gateway is determined to be legal according to the first reference value.

[0022] If yes, the edge gateway is determined to be legal according to the first reference value.

[0023] According to some embodiments of the present application, the fourth parameter set comprises: a first reference value, a first signature value, and a first encryption flag; the third parameter set comprises a second random value; and the first parameter set comprises: a first serial number and a first identity certificate.

[0024] The fourth parameter set is obtained according to the first parameter set and the third parameter set, and comprises:

[0025] The first reference value is obtained according to the first parameter set and the third parameter set.

[0026] The first signature value is obtained according to the first reference value and the first parameter set.

[0027] The first encryption flag is obtained according to the security level of the transmission information.

[0028] According to some embodiments of the present application, the sixth parameter set comprises: a first key pair and a first certificate.

[0029] The sixth parameter set is obtained according to the first parameter set, the third parameter set, and the fifth parameter set, and comprises:

[0030] The second certificate is determined to be legal according to the third parameter set; if not, the edge gateway is determined to be illegal, and the data transmission is terminated.

[0031] If yes, the second certificate is determined to be complete according to the first parameter set and the fifth parameter set; if not, the data transmission is terminated.

[0032] If yes, a first key pair is generated; and a first certificate is obtained according to the first parameter set and the third parameter set.

[0033] According to some embodiments of the present application, the fifth parameter set comprises: a public key of a second key pair; and the first shared key pair is obtained according to the fifth parameter set and the sixth parameter set, and comprises:

[0034] The first shared key pair is obtained according to a private key of the first key pair and the public key of the second key pair.

[0035] The power communication data transmission system according to the second aspect of the present application is used for implementing the power communication data transmission method according to any one of the first aspect, and comprises a cloud device and an edge gateway;

[0036] The cloud device is connected with the edge gateway, and is configured to obtain a first parameter set according to a preset trusted policy and a preset master key, and send the first parameter set to the edge gateway required for data transmission.

[0037] The edge gateway is connected with the cloud device, and is configured to receive the first parameter set sent by the cloud device, obtain a third parameter set according to a second identity certificate and a second integrity measurement value, and send the third parameter set to the cloud device, wherein the second identity certificate is an identity certificate of the edge gateway, and the second integrity measurement value is a platform integrity measurement value of the edge gateway.

[0038] If the edge gateway is legal, a first shared key pair is obtained according to the first parameter set and the third parameter set, and data is sent to the edge gateway through the first shared key pair.

[0039] The edge gateway is connected with the cloud device, and is configured to receive the first parameter set sent by the cloud device, obtain a third parameter set according to a second identity certificate and a second integrity measurement value, and send the third parameter set to the cloud device, wherein the second identity certificate is an identity certificate of the edge gateway, and the second integrity measurement value is a platform integrity measurement value of the edge gateway.

[0040] The edge gateway is connected with the cloud device, and is configured to receive the first parameter set sent by the cloud device, obtain a third parameter set according to a second identity certificate and a second integrity measurement value, and send the third parameter set to the cloud device, wherein the second identity certificate is an identity certificate of the edge gateway, and the second integrity measurement value is a platform integrity measurement value of the edge gateway.

[0041] The electronic device according to the third aspect of the present application comprises:

[0042] The memory is configured to store a program.

[0043] The processor is configured to execute the program stored in the memory, and when the processor executes the program stored in the memory, the processor is configured to execute the method according to any one of the first aspect.

[0044] The storage medium according to the fourth aspect of the present application stores computer executable instructions, and the computer executable instructions are used for executing the method according to any one of the first aspect.

[0045] Other features and advantages of the present application will be described in the following description, and some will become apparent from the description, or will be understood through implementation of the present application. The purpose and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF DRAWINGS

[0046] The accompanying drawings are used to provide a further understanding of the technical solutions of the present application, constitute a part of the specification, and are used to explain the technical solutions of the present application together with the embodiments of the present application, and do not constitute a limitation on the technical solutions of the present application.

[0047] Figure 1 is a flowchart of a power communication data transmission method provided by an embodiment of the present application;

[0048] Figure 2 is a flowchart of a power communication data transmission method provided by another embodiment of the present application;

[0049] Figure 3 is a flowchart of a power communication data transmission method provided by another embodiment of the present application;

[0050] Figure 4 is a schematic diagram of a power communication data transmission method provided by another embodiment of the present application. DETAILED DESCRIPTION

[0051] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and do not limit the present application.

[0052] It should be understood that, in the description of the embodiments of the present application, the meaning of multiple (or multiple items) is two or more, greater than, less than, more than, and the like are understood as not including the number, and above, below, and the like are understood as including the number. If there is a description of "first", "second", and the like, it is only used for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features or implicitly indicating the sequence of indicated technical features.

[0053] As shown in Figure 1 , the present application provides a power communication data transmission method, applied to a cloud device, comprising:

[0054] Step S100, obtaining a first parameter set according to a preset trusted strategy and a preset master key, and sending the first parameter set to an edge gateway;

[0055] Step S200, receiving a third parameter set sent by the edge gateway, determining the legality of the edge gateway according to the third parameter set; if not legal, performing step S300;

[0056] Step S300, determining that the edge gateway is not legal, and aborting data transmission;

[0057] if legal, performing step S400;

[0058] Step S400, obtaining a first shared key pair according to the first parameter set and the third parameter set;

[0059] Step S500, sending data to the edge gateway through the first shared key pair.

[0060] The cloud device sends the first parameter set to the edge gateway required to transmit data, so that the edge gateway knows that the cloud device needs to transmit data and preliminarily verifies the identity of the cloud device through the first parameter set; then determines whether the edge gateway is legal through the third parameter set sent by the edge gateway, determines that the edge gateway is trusted and can safely transmit data, and finally transmits data to the edge gateway through the first shared key pair obtained according to the first parameter set and the third parameter set. In fact, the key pair for transmitting data is generated through the double-end data of the first parameter set generated by the cloud device and the third parameter set generated by the edge gateway, so as to improve the security of data transmission and the security of power communication data transmission between the cloud device and the edge gateway.

[0061] As shown in FIG. 4, in an embodiment, in step S400, obtaining a first shared key pair according to the first parameter set and the third parameter set includes: Figure 2

[0062] Step S410, obtaining a fourth parameter set according to the first parameter set and the third parameter set, and sending the fourth parameter set to the edge gateway;

[0063] Step S420, receiving the fifth parameter set sent by the edge gateway, and obtaining a sixth parameter set according to the first parameter set, the third parameter set and the fifth parameter set;

[0064] Step S430, obtaining a first shared key pair according to the fifth parameter set and the sixth parameter set.

[0065] In an embodiment, the first parameter set includes a first random value, a first identity certificate and a first serial number; in step S100, obtaining the first parameter set according to the preset trusted strategy and the preset master key includes:

[0066] obtaining a first integrity measurement value according to the preset trusted strategy; obtaining the first serial number according to the first integrity measurement value;

[0067] obtaining the first identity certificate according to the preset master key;

[0068] The first random value is a generated random number.

[0069] ​It should be noted that the cloud device stores a trusted policy and a platform master key (i.e., a master key), the embodiment illustrates the generation process of each parameter in the first parameter set, but does not limit the order of generation; the first random value is used in the subsequent verification and encryption steps, the first identity certificate is used to indicate the identity of the cloud device, and the first serial number is used to indicate the platform component integrity of the cloud device;

[0070] After the cloud device completes the trusted start, the platform component integrity of the cloud device is measured and verified according to the trusted policy, that is, the component integrity of the computing platform of the cloud device is measured and verified, the first integrity measurement value obtained is saved in the platform configuration register of the computing platform trusted password module of the cloud device, and the related log is generated and saved at the same time;

[0071] The first serial number corresponding to the first integrity measurement value is generated, and the corresponding first integrity measurement value can be indexed through the first serial number;

[0072] The first random value is generated by a random number generator built in the trusted password module of the platform of the cloud device; in this embodiment, the identity certificate of the cloud device platform itself, the computing platform integrity measurement information of the cloud device, and the random value of the cloud device are obtained, and they are used as the first parameter to indicate the identity and platform integrity of the cloud device, which lays a foundation for the edge gateway to perform identity authentication and platform integrity authentication on the cloud device.

[0073] In an embodiment, obtaining the first identity certificate according to the preset master key comprises:

[0074] According to the preset master key, a first identity key pair is obtained;

[0075] The first identity information and the public key of the first identity key pair are sent to a trusted third party to obtain the first identity certificate sent by the trusted third party.

[0076] According to the preset master key, a first identity key pair is obtained, that is, the identity key of the cloud device platform is generated according to the master key of the computing platform of the cloud device platform itself.

[0077] It should be noted that the key pair includes a public key and a private key, and the cloud device internally stores first identity information, which is the identity information of the cloud device; in this embodiment, the first identity certificate is obtained through a trusted third party to improve the trustworthiness of the cloud device identity, and to lay a foundation for the edge gateway to perform identity authentication and platform integrity authentication on the cloud device.

[0078] In an embodiment, the third parameter set includes a second identity certificate, a second serial number, a second reference value, a second signature value, and a second random value;

[0079] In step S200, determining the legitimacy of the edge gateway according to the third parameter set comprises:

[0080] In step S210, determining whether the edge gateway passes the identity authentication according to the second identity certificate; if not, executing step S220;

[0081] In step S220, determining that the edge gateway is illegitimate, and aborting the data transmission;

[0082] If yes, executing step S230;

[0083] In step S230, determining the legitimacy of the second signature value according to the second identity certificate; if not legitimate, executing step S220;

[0084] If legitimate, executing step S240;

[0085] In step S240, determining whether the edge gateway passes the platform integrity authentication according to the second reference value; if not, executing step S220;

[0086] If yes, determining that the edge gateway is legitimate.

[0087] It should be noted that the second identity certificate is the identity certificate of the edge gateway, the second serial number corresponds to the second integrity measurement value, the second integrity measurement value is the platform integrity measurement value of the edge gateway, the second reference value is the second integrity measurement value corresponding to the second serial number obtained by the edge gateway, and the second signature value is obtained by the edge gateway by signing the second reference value.

[0088] In step S230, the second identity certificate includes a second identity key pair, and the second signature value is obtained by signing the second reference value by the edge gateway using the private key of the second identity key pair, so the legitimacy of the second signature value can be verified by using the public key of the second identity key pair;

[0089] It is easy to understand that the identity certificate includes: identity information of the certificate owner, signature of the certificate issuing authority, identity key pair; the second reference value is a data set including the second integrity measurement value and the first random value sent by the cloud device, or data collected in a certain format from the second integrity measurement value and the first random value.

[0090] In step S240, since the second reference value is obtained according to the second integrity measurement value and the first random value sent by the cloud device, the platform integrity of the edge gateway can be authenticated by verifying whether the second reference value includes the first random value and the second integrity measurement value at the cloud device, and if the authentication is successful, it is determined that the platform integrity authentication of the edge gateway is passed.

[0091] It should be noted that when the cloud device verifies whether the second reference value includes the second integrity measurement value, not only whether the second reference value includes the integrity measurement data of the edge gateway, but also whether the integrity measurement data is consistent with the expected integrity measurement value (the expected integrity measurement value obtained by the cloud device evaluating the edge gateway) needs to be verified, to prevent the second integrity measurement value from being lost or tampered with during transmission. Only when the second reference value includes the first random value, and includes the integrity measurement data of the edge gateway and the integrity measurement data is consistent with the expected integrity measurement value, can it be determined that the second integrity measurement value is the correct second integrity measurement value, and the integrity authentication of the edge gateway platform is passed.

[0092] The embodiment verifies whether the identity certificate of the edge gateway is legal. If it is legal, the identity authentication of the edge gateway is passed, and the integrity authentication of the edge gateway computing platform is passed by verifying the second signature value and the second reference value of the edge gateway.

[0093] In an embodiment, the fourth parameter set includes: the first reference value, the first signature value, and the first encryption flag; the third parameter set includes the second random value; and the first parameter set includes: the first serial number and the first identity certificate.

[0094] In step S410, the fourth parameter set is obtained according to the first parameter set and the third parameter set, and includes:

[0095] The first reference value is obtained according to the first integrity measurement value and the second random value; wherein the first integrity measurement value is obtained according to the first serial number.

[0096] The first signature value is obtained according to the first reference value and the first identity certificate.

[0097] The first encryption flag is obtained according to the security level of the transmission information.

[0098] The first reference value and the first signature value are generated by a trusted cryptographic module in the cloud device computing platform.

[0099] In an embodiment, the first identity certificate includes a first identity key pair, and the first signature value is obtained according to the first reference value and the first identity certificate, specifically: the first signature value is obtained according to the first reference value and the private key of the first identity key pair.

[0100] If the information transmission security level is high, and the data needs to be encrypted for transmission, the value of the first encryption flag is configured as 1, otherwise it is configured as 0.

[0101] In addition, after the cloud device authenticates the identity and platform integrity of the edge gateway, a platform integrity report of the cloud device itself can be generated, and the fourth parameter set is recorded in the report, and the fourth parameter set is sent to the edge gateway by sending the report.

[0102] The embodiment realizes encryption of the integrity measurement value of the cloud device computing platform by generating the first reference value, the first signature value and the value of the first encryption flag, and ensures the security of the subsequent transmission process.

[0103] In an embodiment, the fifth parameter set includes a second certificate and a public key of a second key pair; and the sixth parameter set includes a public key of the first key pair and the first certificate.

[0104] In step S420, the sixth parameter set is obtained according to the first parameter set, the third parameter set and the fifth parameter set, and includes:

[0105] In step S421, it is determined whether the second certificate is legal according to the third parameter set; if not, step S422 is performed.

[0106] In step S422, it is determined that the transmission is insecure, and the data transmission is aborted.

[0107] If yes, step S423 is performed.

[0108] In step S423, it is determined whether the second certificate is complete according to the first parameter set and the public key of the second key pair; if not, step S422 is performed.

[0109] If yes, step S424 is performed.

[0110] In step S424, the first key pair is generated.

[0111] In step S425, the first certificate is obtained according to the first parameter set and the third parameter set.

[0112] It is easy to understand that the generated first key pair includes a public key and a private key, and since the sixth data set is transmitted to the external edge gateway, only the public key of the first key is transmitted, and the private key of the first key is stored in the cloud device.

[0113] In an embodiment, in step S421, it is determined whether the second certificate is legal according to the third parameter set, and includes:

[0114] It is determined whether the signature information of the second certificate is legal according to the public key of the second identity key pair.

[0115] It should be noted that the second identity key is generated according to the platform master key of the edge gateway; and the second certificate is generated after being signed by the private key of the second identity key pair by the edge gateway, and therefore, the signature information in the second certificate can be verified for legality by using the public key of the second identity key pair.

[0116] In an embodiment, in step S423, it is determined whether the second certificate is complete according to the first parameter set and the public key of the second key pair, and includes:

[0117] determining whether the second certificate includes the first random value and the public key of the second key pair; if yes, the second certificate is complete; if no, the second certificate is incomplete;

[0118] Since the second certificate is generated after the edge gateway signs the first random value and the public key of the second key pair, the second certificate can be authenticated by verifying whether the second certificate contains the first random value and the public key of the second key pair at the cloud device, and if the authentication is successful, it is determined that the second certificate is authenticated.

[0119] In an embodiment, in step S424, generating the first key pair includes: generating the first key pair by SM2.

[0120] The first key pair of SM2 is generated by a trusted cryptographic module of a cloud device computing platform, and the first key pair is loaded to the trusted cryptographic module.

[0121] In an embodiment, in step S425, obtaining the first certificate according to the first parameter set and the third parameter set includes: signing the second random value and the public key of the first key pair by the private key of the first identity key to obtain the first certificate.

[0122] The first certificate can be generated by signing the second random value and the public key of the first key pair by the private key of the first identity key through a trusted cryptographic module of a cloud device computing platform.

[0123] In an embodiment, obtaining the first shared key pair according to the fifth parameter set and the sixth parameter set includes:

[0124] The first shared key pair is obtained according to the private key of the first key pair and the public key of the second key pair.

[0125] The first shared key can be generated by the trusted cryptographic module of the cloud device computing platform according to the private key of the first key pair and the public key of the second key pair.

[0126] The sixth parameter set is generated in this embodiment, so as to subsequently perform key negotiation with the edge gateway, and the first shared key is generated, so as to realize data transmission with the edge gateway by using the first shared key, and improve data transmission security.

[0127] In an embodiment, the method further includes: after obtaining the sixth parameter set, sending the sixth parameter set to the edge gateway, so that the edge gateway generates a second shared key to perform data transmission with the cloud device.

[0128] As shown in Figure 3 The embodiment of the present application also provides a power communication data transmission method applied to an edge gateway, including:

[0129] Step S600, obtaining the second parameter set and receiving the first parameter set sent by the cloud device;

[0130] Step S700, determining whether the cloud device passes the identity authentication according to the first parameter set, and if not, aborting the data transmission;

[0131] If the identity authentication of the cloud device passes, step S800 is performed;

[0132] Step S800, generating a third parameter set according to the first parameter set and the second parameter set, and sending the third parameter set to the cloud device;

[0133] Step S900, receiving the fourth parameter set sent by the cloud device, and determining whether the cloud device passes the authentication according to the first parameter set, the third parameter set and the fourth parameter set; if not, aborting the data transmission;

[0134] If yes, step S1000 is performed;

[0135] Step S1000, obtaining a fifth parameter set according to the fourth parameter set, and sending the fifth parameter set to the cloud device;

[0136] Step S1100, receiving the sixth parameter set sent by the cloud device, obtaining a second shared key according to the first parameter set, the third parameter set and the sixth parameter set, and performing the data transmission with the cloud device through the second shared key.

[0137] The third parameter is sent to the cloud device to initiate a verification request to the cloud device.

[0138] The power communication data transmission method provided by the embodiment transmits various parameters between the cloud device and the edge gateway through trusted computing, so that the edge gateway can use these parameters to realize identity authentication and platform integrity authentication of the cloud device, and generate a second shared key after the authentication is completed, and use the second shared key to realize data transmission with the cloud device. Since the edge gateway completes the identity authentication and platform integrity authentication of the cloud device, the identity information of the cloud device is guaranteed to be legal and the computing platform of the cloud device is guaranteed to be complete, that is, it is confirmed that the cloud device is trusted, and then the second shared key is used to perform data transmission with the cloud device, thereby guaranteeing the data transmission process, especially the security of sensitive data transmission.

[0139] In an embodiment, in step S600, obtaining the second parameter set includes: determining the component integrity of the edge gateway according to the trusted policy to obtain a second integrity measurement value;

[0140] Obtaining a second identity key according to the master key of the edge gateway, sending the public key of the second identity information and the second identity key pair to a trusted third party to obtain a second identity certificate;

[0141] adding the second identity certificate and the second integrity measurement value to the second parameter set.

[0142] The second identity certificate comprises a signature of the trusted third party, second identity information and a second identity key pair.

[0143] After the edge gateway completes the trusted boot, the component integrity of the edge gateway is measured and verified according to the trusted policy, that is, the component integrity of the computing platform of the edge gateway itself is measured and verified, and the obtained second integrity measurement value can be saved in the platform configuration register of the computing platform trusted cryptographic module of the edge gateway, and relevant logs are generated and saved.

[0144] The second identity key is generated according to the edge gateway master key, that is, the identity key of the edge gateway is generated according to the master key of the computing platform of the edge gateway itself.

[0145] The embodiment obtains the identity certificate of the edge gateway itself and the edge gateway computing platform integrity measurement information, indicates the identity and platform integrity of the edge gateway itself, and lays a foundation for the cloud device to perform identity authentication and platform integrity authentication on the edge gateway.

[0146] In an embodiment, the first parameter set comprises a first identity certificate, a first serial number and a first random value.

[0147] In step S700, whether the cloud device passes the identity authentication is determined according to the first parameter set, comprising:

[0148] Whether the cloud device passes the identity authentication is determined according to the first identity certificate; if not, the data transmission is aborted.

[0149] If the identity authentication of the cloud device passes, the identity authentication passes.

[0150] In an embodiment, the first parameter set comprises a first identity certificate, a first serial number and a first random value; the third parameter set comprises a second identity certificate, a second serial number, a second reference value, a second signature value and a second random value; and the second parameter set comprises the second identity certificate and a second integrity measurement value.

[0151] In step S800, the third parameter set is generated according to the first parameter set and the second parameter set, and the third parameter set is sent to the cloud device, comprising:

[0152] The second serial number is obtained and the second random value is generated according to the second integrity measurement.

[0153] The second reference value is obtained according to the second integrity measurement value and the first random value.

[0154] The second reference value is signed by using the private key of the second identity key pair to obtain the second signature value.

[0155] The second serial number, the second random value, the second identity certificate, the second reference value and the second signature value are taken as the third parameter.

[0156] The second serial number corresponding to the second integrity measurement value is generated, and the second integrity measurement value can be indexed by the second serial number. The random number generator can be built in a trusted cryptographic module of the computing platform of the edge gateway.

[0157] The second reference value and the second signature value can be generated by the trusted cryptographic module in the edge gateway computing platform.

[0158] In addition, after the edge gateway authenticates the identity of the cloud device, a platform integrity report of the edge gateway itself can be generated, and the third parameter is recorded in the report. The third parameter is sent to the cloud device by sending the report.

[0159] The embodiment verifies whether the identity certificate of the cloud device is legal. If it is legal, the identity authentication of the cloud device is passed, and the encryption of the integrity measurement value of the edge gateway computing platform is realized by generating the second serial number, the second random value, the second reference value and the second signature value, so as to ensure the security of the subsequent transmission process.

[0160] In an embodiment, the first parameter set includes a first identity certificate, a first serial number and a first random value. The fourth parameter set includes a first reference value, a first signature value and a first encryption flag.

[0161] In step S900, the fourth parameter set sent by the cloud device is received, and whether the cloud device passes the authentication is determined according to the first parameter set, the third parameter set and the fourth parameter set, including:

[0162] It is determined whether the first signature value is legal according to the first identity key pair. For example, it is determined whether the first signature value is legal according to the public key of the first identity key pair. If not, the data transmission is aborted.

[0163] If the first signature value is legal, it is determined whether the cloud device passes the platform integrity authentication by determining whether the first reference value includes the second random value and the first integrity measurement value. If yes, the cloud device passes the authentication. If not, the data transmission is aborted.

[0164] It should be noted that the first integrity measurement value is retrieved from the first serial number in the first parameter set.

[0165] The first signature value is obtained by signing the first reference value by the cloud device using the private key of the first identity key. Therefore, the legality of the first signature value can be verified by using the public key of the first identity key.

[0166] Since the first reference value is a first integrity metric value corresponding to the first serial number obtained by the cloud device and is generated together with the second random value, the platform integrity of the cloud device can be authenticated by verifying whether the first reference value contains the second random value and the first integrity metric value at the edge gateway, and if the verification is successful, it is determined that the platform integrity of the cloud device is authenticated.

[0167] It should be noted that when the edge gateway verifies whether the first reference value contains the first integrity metric value, not only whether the first reference value contains the integrity metric data of the cloud device, but also whether the integrity metric data is consistent with the expected integrity metric value needs to be verified, so as to prevent the first integrity metric value from being lost or tampered with during transmission. Only when the first reference value contains the second random value and the integrity metric data of the cloud device and the integrity metric data is consistent with the expected integrity metric value, the first integrity metric value is determined to be the correct first integrity metric value, and the platform integrity of the cloud device is authenticated.

[0168] In an embodiment, the fourth parameter set includes: the first reference value, the first signature value, and the first encryption flag bit; and the fifth parameter set includes: the second certificate and the public key of the second key pair.

[0169] In step S1000, the fifth parameter set is obtained according to the fourth parameter set, and the fifth parameter set is sent to the cloud device, including:

[0170] The value of the first encryption flag bit is determined to be 0 or 1.

[0171] If the value of the first encryption flag bit is 0, the cloud device and the edge gateway perform clear text information transmission.

[0172] If the value of the first encryption flag bit is 1, the second key pair is generated.

[0173] The first random value and the public key of the second key pair are signed by the private key of the second identity key to generate the second certificate.

[0174] The public key of the second key pair and the second certificate are determined as the fifth parameters.

[0175] It should be noted that the first encryption flag bit indicates the information security level, and the value is 0 or 1. 1 indicates that encryption is needed, and 0 indicates that encryption is not needed.

[0176] The second key pair is generated by a trusted password module in the edge gateway computing platform; and the first random value and the public key of the second key pair are signed by the trusted password module of the edge gateway computing platform using the private key of the second identity key to generate the second certificate.

[0177] The embodiment can complete integrity authentication of the cloud device computing platform by verifying the first signature value and the first reference value of the cloud device, and generate the public key of the second key pair and the second certificate, so as to perform key negotiation with the cloud device subsequently.

[0178] In an embodiment, the sixth parameter set includes: the first certificate, the public key of the first key pair;

[0179] In step S1100, the sixth parameter set sent by the cloud device is received, and the second shared key is obtained according to the first parameter set, the third parameter set and the sixth parameter set, including:

[0180] The signature information in the first certificate is determined to be legal or not by using the public key of the first identity key pair; if not, the data transmission is aborted;

[0181] If the signature information in the first certificate is legal, it is determined whether the first certificate includes the second random value and the public key of the first key pair; if not, the data transmission is aborted;

[0182] If the first certificate includes the second random value and the public key of the first key pair, the second shared key is obtained according to the private key of the second key pair and the public key of the first key pair.

[0183] It should be noted that the sixth parameter set includes the public key of the first key pair and the first certificate, the first key pair is generated by the cloud device according to the second certificate, and the first certificate is obtained by the cloud device signing the second random value and the public key of the first key pair;

[0184] The first certificate is generated by the cloud device signing the second random value and the public key of the first key pair using the private key of the first identity key, so the signature information in the first certificate can be verified by using the public key of the first identity key.

[0185] Since the first certificate is obtained by the cloud device signing the second random value and the public key of the first key pair, the first certificate can be authenticated by verifying whether the first certificate contains the second random value and the public key of the first key pair at the edge gateway.

[0186] The second shared key can be generated by the trusted cryptographic module of the edge gateway computing platform according to the private key of the second key pair and the public key of the first key pair.

[0187] The embodiment can realize data transmission with the cloud device by generating the second shared key, and improve the security of data transmission.

[0188] As shown in Figure 4 The embodiment of the application also provides a power communication data transmission method, applied to a cloud device and an edge gateway, including:

[0189] The cloud device obtains a first parameter set according to a preset trusted strategy and a preset master key, and sends the first parameter set to the edge gateway; wherein the first parameter set comprises a first identity certificate, a first serial number, and a first random value;

[0190] The edge gateway receives the first parameter set sent by the cloud device, obtains a third parameter set according to a second identity certificate and a second integrity measurement value, and sends the third parameter set to the cloud device; wherein the second identity certificate is an identity certificate of the edge gateway, the second integrity measurement value is a platform integrity measurement value of the edge gateway, and the third parameter set comprises the second identity certificate, a second serial number, a second reference value, a second signature value, and a second random value;

[0191] The cloud device receives the third parameter set sent by the edge gateway, and determines the legality of the edge gateway according to the third parameter set; if not legal, it is determined that the edge gateway is not legal, and the data transmission is terminated;

[0192] If the edge gateway is legal, a fourth parameter set is obtained according to the first parameter set and the third parameter set, and the fourth parameter set is sent to the edge gateway; wherein the fourth parameter set comprises a first reference value, a first signature value, and a first encryption flag bit;

[0193] The edge gateway receives the fourth parameter set sent by the cloud device, obtains a fifth parameter set according to the first parameter set, the third parameter set, and the fourth parameter set, and sends the fifth parameter set to the cloud device; wherein the fifth parameter set comprises a second certificate and a public key of a second key pair;

[0194] The cloud device receives the fifth parameter set sent by the edge gateway, obtains a sixth parameter set according to the first parameter set, the third parameter set, and the fifth parameter set, sends the sixth parameter set to the edge gateway, and obtains a first shared key pair according to the fifth parameter set and the sixth parameter set; the cloud device sends data to the edge gateway through the first shared key pair; the sixth parameter comprises a public key of a first key pair and a first certificate;

[0195] The edge gateway generates a second shared key according to a private key of the second key pair and a public key of the first key pair; the edge gateway sends data to the cloud device through the second shared key.

[0196] In an embodiment, the third parameter set comprises the second identity certificate, the second serial number, the second reference value, the second signature value, and the second random value; the edge gateway obtains the third parameter set according to the second identity certificate and the second integrity measurement value, which comprises obtaining the second serial number according to the second integrity measurement value;

[0197] The second reference value is obtained according to the second integrity measurement value and the first random value;

[0198] The second signature value is obtained according to the second reference value.

[0199] The third parameter is sent to the cloud device to initiate a verification request to the cloud device.

[0200] In an embodiment, the fifth parameter set includes: the second certificate, the public key of the second key pair; obtaining the fifth parameter set according to the first parameter set and the fourth parameter set includes: obtaining the second key pair according to the first encryption flag; obtaining the second certificate according to the first random value, the public key of the second key pair and the second identity key.

[0201] The embodiment of the application also provides an electric power communication data transmission system, comprising: a cloud device and an edge gateway.

[0202] The cloud device is connected with the edge gateway, and is configured to obtain a first parameter set according to a preset trusted strategy and a preset master key, and send the first parameter set to the edge gateway required for data transmission.

[0203] The edge gateway is connected with the cloud device, and is configured to receive the third parameter set sent by the cloud device, and determine the legality of the edge gateway according to the third parameter set; if the edge gateway is not legal, the data transmission is terminated.

[0204] If the edge gateway is legal, a first shared key pair is obtained according to the first parameter set and the third parameter set; and data is sent to the edge gateway through the first shared key pair.

[0205] The edge gateway is connected with the cloud device, and is configured to receive the first parameter set sent by the cloud device, obtain a third parameter set according to a second identity certificate and a second integrity measurement value, and send the third parameter set to the cloud device; wherein the second identity certificate is an identity certificate of the edge gateway, and the second integrity measurement value is a platform integrity measurement value of the edge gateway.

[0206] The edge gateway is connected with the cloud device, and is configured to receive the first parameter set sent by the cloud device, obtain a third parameter set according to a second identity certificate and a second integrity measurement value, and send the third parameter set to the cloud device; wherein the second identity certificate is an identity certificate of the edge gateway, and the second integrity measurement value is a platform integrity measurement value of the edge gateway.

[0207] The embodiment of the application also provides an electronic device, which includes but is not limited to:

[0208] The memory is configured to store a program.

[0209] The processor is configured to execute the program stored in the memory, and when the processor executes the program stored in the memory, the processor is configured to execute the electric power communication data transmission method.

[0210] The processor and the memory can be connected through a bus or other means.

[0211] The memory, as a non-transitory computer readable storage medium, can be used to store non-transitory software programs and non-transitory computer executable instructions, such as the method described in the embodiments of the present application. The processor can implement the above method by running the non-transitory software programs and instructions stored in the memory.

[0212] The memory can include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required by a function; and the data storage area can store the above method. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely arranged relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0213] The non-transitory software programs and instructions required to implement the above terminal selection method are stored in the memory, and when executed by one or more processors, the above method is executed.

[0214] The embodiments of the present application also provide a storage medium storing computer executable instructions for executing the above method.

[0215] In an embodiment, the storage medium stores computer executable instructions, and the computer executable instructions are executed by one or more control processors.

[0216] The above described embodiments are only illustrative, and units described as separate components can or can not be physically separated, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment.

[0217] As will be appreciated by one of ordinary skill in the art, all or some steps, systems of the above-disclosed methods can be implemented as software, firmware, hardware, or any suitable combination thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application- specific integrated circuit. Such software can be distributed on computer readable media, which can comprise computer storage media (or non-transitory media), and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes both volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media include, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer. Further, as is well known to those of ordinary skill in the art, communication media typically embodies computer readable instructions, data structures, program modules, or other data in a modulated data signal, such as carrier waves or other transport mechanisms, and includes any information delivery media.

[0218] Embodiments of the present application are described herein with reference to the drawings, including embodiments presently preferred by the inventors for the practice of the present application. Variations on described embodiments can become apparent to those of ordinary skill in the art upon reading the foregoing description. The inventors expect skilled artisans to employ such variations as appropriate, and the inventors intend for the scope of the application to include all such modifications and equivalents resorting to the claims appended hereto as presently stated and as subsequently amended. The scope of the application covers any combination of the above-described elements in all possible variations thereof unless otherwise explicitly indicated herein or otherwise clearly contradicted by context.

Claims

1. A power communication data transmission method, applied to cloud devices, characterized in that: include: Obtaining a first parameter set according to a preset trust policy and a preset master key, and sending the first parameter set to an edge gateway; receiving a third parameter set sent by the edge gateway, and determining the legitimacy of the edge gateway according to the third parameter set; If it is illegal, the edge gateway is determined to be illegal and the data transmission is terminated; If it is legal, a first shared key pair is obtained according to the first parameter set and the third parameter set; and data is sent to the edge gateway through the first shared key pair.

2. The method for transmitting power communication data according to claim 1, wherein: Obtaining a first shared key pair according to the first parameter set and the third parameter set includes: Obtain a fourth parameter set according to the first parameter set and the third parameter set, and send the fourth parameter set to the edge gateway; Receive a fifth parameter set sent by the edge gateway, obtain a sixth parameter set according to the first parameter set, the third parameter set, and the fifth parameter set, and obtain a first shared key pair according to the fifth parameter set and the sixth parameter set.

3. The method for transmitting power communication data according to claim 1, wherein: The first parameter set includes: a first random value, a first identity certificate, and a first serial number; the first random value is a generated random number; The obtaining of the first parameter set according to the preset trust policy and the preset master key includes: Obtaining a first complete measurement value according to a preset trust policy; Obtaining the first sequence number according to the first integrity metric value; The first identity certificate is obtained according to the preset master key.

4. The method for transmitting power communication data according to claim 1, wherein: The third parameter set includes a second identity certificate, a second serial number, a second reference value, a second signature value, and a second random value; Determining the legitimacy of the edge gateway according to the third parameter set includes: determining whether the edge gateway passes identity authentication based on the second identity certificate; if not, determining that the edge gateway is illegal and terminating data transmission; If so, determining the legitimacy of the second signature value based on the second identity certificate; if not, determining that the edge gateway is illegal and terminating data transmission; If it is legal, determining whether the edge gateway has passed the platform integrity authentication according to the second reference value; if not, determining that the edge gateway is illegal and terminating data transmission; If so, it is determined that the edge gateway is legal.

5. The method for transmitting power communication data according to claim 2, wherein: The fourth parameter set includes: a first reference value, a first signature value, and a first encryption flag; the third parameter set includes a second random value; the first parameter set includes: a first serial number and a first identity certificate; The obtaining of the fourth parameter set according to the first parameter set and the third parameter set includes: Obtaining a first reference value according to the first parameter set and the third parameter set; Obtaining a first signature value according to the first reference value and the first parameter set; A first encryption flag is obtained according to the security level of the transmitted information.

6. The method for transmitting power communication data according to claim 2, wherein: The sixth parameter set includes: a first key pair and a first certificate; The obtaining of the sixth parameter set according to the first parameter set, the third parameter set, and the fifth parameter set includes: determining whether the second certificate is legal based on the third parameter set; if not, determining that the edge gateway is illegal and terminating data transmission; If yes, determining whether the second certificate is complete based on the first parameter set and the fifth parameter set; if not, terminating data transmission; If so, generate a first key pair; and obtain a first certificate based on the first parameter set and the third parameter set.

7. The method for transmitting power communication data according to claim 6, wherein: The fifth parameter set includes: the public key of the second key pair; and obtaining the first shared key pair according to the fifth parameter set and the sixth parameter set includes: A first shared key pair is obtained according to the private key of the first key pair and the public key of the second key pair.

8. A power communication data transmission system, characterized in that: For executing the method according to any one of claims 1 to 7, comprising: a cloud device, an edge gateway; The cloud device is connected to the edge gateway and is used to obtain a first parameter set according to a preset trust policy and a preset master key, and send the first parameter set to the edge gateway to which data needs to be transmitted; receiving a third parameter set sent by the edge gateway, and determining the legitimacy of the edge gateway according to the third parameter set; if not, determining that the edge gateway is not legal and terminating data transmission; If legal, obtaining a first shared key pair according to the first parameter set and the third parameter set; sending data to the edge gateway through the first shared key pair; The edge gateway is connected to the cloud device and is configured to receive the first parameter set sent by the cloud device, obtain the third parameter set based on the second identity certificate and the second integrity metric, and send the third parameter set to the cloud device; wherein the second identity certificate is the identity certificate of the edge gateway, and the second integrity metric is the platform integrity metric of the edge gateway; Receive the fourth parameter set sent by the cloud device, and obtain a second shared key according to the first parameter set, the third parameter set, and the fourth parameter set; the edge gateway sends data to the cloud device using the second shared key.

9. An electronic device, characterized in that: include: Memory, used to store programs; A processor, configured to execute the program stored in the memory. When the processor executes the program stored in the memory, the processor is configured to execute the method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: Computer-executable instructions are stored, and the computer-executable instructions are used to execute the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Power communication data transmission guarantee method and system based on deterministic network

    CN121967345A