Malicious-behavior-resistant multi-party cooperative charging load safety prediction method and system

By constructing a secure neural network model using encrypted secret sharing and function secret sharing techniques, the problems of privacy leakage and malicious behavior in load forecasting are solved, enabling efficient and secure multi-party collaborative load forecasting, improving forecast accuracy and reducing computational and communication overhead.

CN120879540APending Publication Date: 2025-10-31国网重庆市电力公司信息通信分公司 +4

Patent Information

Application Number
CN202510969803.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

Existing technologies for load forecasting pose a risk of privacy breaches due to reliance on historical user load data, and are unable to effectively combat malicious server behavior, impacting forecast accuracy and efficiency.

Method used

By employing encrypted secret sharing and function secret sharing technologies, a secure neural network model is constructed. Message authentication codes are generated using a global authentication key and multiplication triples to achieve multi-party collaborative computation, verify the correctness of data transmission, and resist malicious actors.

Benefits of technology

While improving prediction accuracy, it reduces computation and communication overhead, protects privacy data, resists malicious server behavior, and supports multi-party collaborative load prediction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120879540A_ABST
    Figure CN120879540A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-party cooperative charging load safety prediction method and system capable of resisting malicious behaviors, and the method comprises the steps: enabling a trusted third party to generate a global authentication key, a function key and a related random value, which are needed in a load prediction process, at an offline stage in a system initialization stage; the data owner splits the original power data into a plurality of parts and sends the parts to the server; the charging operator decomposes the load prediction model into a plurality of secret shares, and the secret shares are deployed on different server nodes respectively; the plurality of server nodes cooperatively execute a safety function protocol, complete a neural network reasoning process and send a load prediction result share to a power grid dispatching center; and the power grid dispatching center reconstructs the received load prediction result share to obtain a load prediction result. The method can support a plurality of participants, greatly reduces the calculation and communication overhead under the condition of guaranteeing high prediction precision, and can resist malicious behaviors of server nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of power data security protection technology, and relates to the privacy protection technology of charging data, specifically a multi-party collaborative charging load security prediction method and system to resist malicious behavior. Background Technology

[0002] Currently, as new power systems shift towards a "source-load interaction" model and continue to develop towards greener, smarter, and more diversified directions, it is necessary to improve the accuracy of forecasts on the load side as much as possible to ensure power system security, thereby enhancing load-side resource utilization and promoting high-quality development of the power industry.

[0003] The key to electricity load forecasting lies in how to utilize existing historical data to build predictive models and forecast load values ​​for future moments or time periods. Machine learning and deep learning have become mainstream methods for load forecasting due to their advantages in pattern recognition and nonlinear modeling. While existing methods have improved prediction accuracy, they largely rely on users' historical load data. This load data includes sensitive information such as user electricity consumption, power parameters, and behavioral records. During the uploading and storage of user data, this sensitive information is at risk of being maliciously stolen or even altered. Through unconventional technical means, attackers can infer users' lifestyle habits and identity information from load data, posing a serious threat to personal privacy. Furthermore, malicious parties can arbitrarily disrupt the training / prediction process, such as by sending incorrect messages to other participants.

[0004] Currently, the main approaches to solving the above problems fall into two categories: non-cryptographic and cryptographic techniques. Non-cryptographic techniques primarily include federated learning and differential privacy. The former faces the risk of model parameter leakage, while the latter reduces prediction accuracy due to the introduction of noise. Cryptographic techniques mainly include homomorphic encryption, zero-knowledge proofs, and secure multi-party computation. Although these provide a high level of privacy protection, they are usually accompanied by high communication and computational complexity, severely impacting the efficiency of load forecasting services. Therefore, there is an urgent need to design a secure multi-party collaborative charging load forecasting method and system resistant to malicious behavior, improving prediction accuracy while reducing computational and communication overhead, and resisting malicious actors.

[0005] Prior art document 1 (CN 117291258 A) discloses a neural network training and inference method and system based on function secret sharing. Prior art document 2 (CN 117592527 A) discloses a privacy-preserving neural network training method and apparatus based on function secret sharing.

[0006] However, the shortcomings of existing technology document 1 are that it only supports three-party computation scenarios and implements linear multiplication operations for three-party secret replication, which cannot resist malicious behavior from the server, i.e., sending incorrect messages. The shortcomings of existing technology document 2 are that it only guarantees data privacy, i.e., semi-honest security. This technology implements linear multiplication operations for multiplication triples, which cannot resist malicious behavior from the server, i.e., sending incorrect messages. Summary of the Invention

[0007] To address the shortcomings of existing technologies, this invention provides a multi-party collaborative charging load security prediction method and system resistant to malicious behavior. Based on the prediction task and data characteristics, it completes the security function protocol of the linear and nonlinear layers in the neural network through encrypted secret sharing and function secret sharing, constructs a secure neural network model, and realizes privacy-preserving load prediction calculation. While improving prediction accuracy, it reduces the computational and communication overhead of prediction, and resists malicious participants, thereby effectively supporting the development of multiple businesses such as power grid dispatching, maintenance planning, stability analysis, and new energy consumption analysis.

[0008] The present invention adopts the following technical solution.

[0009] A first aspect of the present invention provides a multi-party collaborative charging load security prediction method to resist malicious behavior, comprising:

[0010] A trusted third party generates a global authentication key, multiple function key shares, and multiple multiplication triple shares required for load forecasting during the offline phase. It obtains secret shares of multiple message authentication codes (MACs) through the global authentication key and multiple multiplication triple shares. The secret shares of the message authentication codes (MACs) and function key shares are then sent to the corresponding server nodes, and the global authentication key is sent to the data owner.

[0011] The data owner obtains the raw power data, preprocesses it, splits the preprocessed power data into multiple secret data shares, and sends the secret data shares to the corresponding server nodes. When load forecasting is required, the charging operator selects the corresponding neural network model according to the load forecasting task and data type published by the power grid dispatch center, decomposes the neural network model into multiple secret model shares, and deploys the multiple secret model shares on multiple server nodes in a secret sharing manner.

[0012] Each server node collaboratively executes a preset security function protocol based on the secret share of the corresponding message authentication code MAC and the function key share, completes the calculation of each layer of the neural network model, and uses a hash value to verify whether the secret data share transmitted by the data owner is correct when executing the preset security function protocol. If it is incorrect, the execution of the protocol is stopped; otherwise, the execution of the protocol continues. Finally, the load forecast result share is output and sent to the power grid dispatch center.

[0013] The power grid dispatch center reconstructs the received load forecast results by reconstructing the proportions of the load forecast results to obtain the load forecast results.

[0014] Optionally, a trusted third party generates the global authentication key, function key share, and multiplication triple share required for load forecasting during the offline phase. The secret share of the message authentication code (MAC) is obtained through the global authentication key and the multiplication triple share, including:

[0015] A trusted third party uses a pseudo-random generator and a distributed comparison function to generate multiple function key shares;

[0016] Select α←Z q As a global authentication password, Z q Let represent a group of order q, where q is a prime number of length λ bits and λ is a system security parameter;

[0017] Obtain a multiplication triplet, wherein the multiplication triplet satisfies w = u·v mod q, where w is the first element of the multiplication triplet, u is the second element of the multiplication triplet, and v is the third element of the multiplication triplet; split the multiplication triplet into n random shares, and combine them with the global authentication password to generate secret shares of multiple message authentication codes (MACs), where n represents the number of server nodes.

[0018] Optionally, the multiplication triple is split into n random shares, and combined with the global authentication cipher to generate multiple secret shares of the Message Authentication Code (MAC), including:

[0019] Each multiplication triplet is split into n first random shares by addition;

[0020] Multiply the global authentication password by the multiplication triples respectively, and then add the results of the multiplications to split them into n second random shares.

[0021] The first and second random shares are combined to obtain the secret shares of the Message Authentication Code (MAC): {[u],[v],[w],[αu],[αv],[αw]} L , where [u] represents the addition of u, and L represents the total number of multiplication triples.

[0022] Optionally, a trusted third party may use a pseudo-random generator and a distributed comparison function to generate multiple function key shares, including:

[0023] Let ρ = (γ, δ), where γ ∈ [s] and δ ∈ [t] represent the first s bits and the last t bits of binary ρ, and ρ is the path of the distributed comparison function. When the input of the distributed comparison function is less than ρ, the output is 1; otherwise, the output is 0.

[0024] Select s n×2 n-1 A set of matrices of dimension A1, A2, ... A s Make it satisfy A γ ∈O n,q A γ′ ∈E n,q And γ′≠γ, where O n,q This represents an n×2 n-fold summation of each column of elements, modulo q, where the summation is equal to 1. n-1 A set of matrices of dimension E n,q This represents an n×2 column of elements whose summation modulo q is 0. n-1 A set of matrices of dimension A γ Let A represent the γ-th matrix set. γ′ Represents the γ′-th matrix set;

[0025] Randomly select s·2 n-1 a random string

[0026] Option 2 n-1 A randomized corrected word vector CW1, CW2, ..., Make it satisfy In the formula, CW i Let C represent the i-th randomly corrected word vector, PRG represent the pseudo-random generator, and C... δ This indicates that the dimension is 2, where δ is 1 at position δ and 0 at other positions. |δ| ;

[0027] Choose n random vectors T1, T2, ... Make it satisfy Among them, T j Let C represent the j-th random vector. γ This indicates that position γ is 1 and all other positions are 0, with a dimension of 2. |γ| ;

[0028] When A γ′ When [j,i]≠0, let σ j,γ′,i =(φ γ′j A γ′ [j,i]), otherwise σ j,γ′,i = (0,0), where 1≤γ′≤s, 1≤i≤2 n-1 ;

[0029] From σ j,γ′ =(σ j,γ′,1 ||σ j,γ′,2 ), (1≤γ′≤s) and σ j =σ j1 ||…σ js σ is calculated j , where σ j As the seed for the pseudo-random generator, obtain the j-th function key share. (1≤j≤n).

[0030] Optionally, the preset security function protocol includes a secure scalar multiplication protocol SMul([x],[y]), used to perform secure multiplication operations on the secret data shares of scalars [x] and [y]. Each server node collaboratively executes the preset security function protocol based on the secret share of the corresponding message authentication code (MAC) and the function key share. During the execution of the preset security function protocol, a hash value is used to verify whether the secret data shares transmitted by other server nodes are correct. If incorrect, the protocol execution stops; otherwise, the protocol execution continues. This includes:

[0031] Each server node subtracts the second and third elements of the multiplication triple from the secret data share to obtain the corresponding first and second differences, and sends the first and second differences to other server nodes.

[0032] Each server node calculates the third and fourth values ​​based on the secret share of the corresponding message authentication code MAC, the first difference of the function key share, and the second difference, and calculates the first hash value of the third and fourth values, and sends the third, fourth, and first hash values ​​to other server nodes;

[0033] Each server node calculates the second hash value based on the obtained third and fourth values, and compares the first hash value with the second hash value. If they are not equal, the protocol is terminated. If they are equal, the first difference and the second difference are verified to be correct. If they are not correct, the protocol is terminated. Otherwise, the protocol is executed to obtain the multiplication output share of the secure scalar multiplication protocol.

[0034] Optionally, the third and fourth values ​​are calculated for each server node based on the secret share of the corresponding message authentication code MAC, the function key share, and the first and second differences, according to the following formula, and the first hash value of the third and fourth values ​​is calculated:

[0035] [g] j =[α] j ·e-([αx] j -[αu] j )

[0036] [h] j=[α] j ·f-([αy] j -[αv] j )

[0037] hash j =hash([g]) j [h] j )

[0038] In the formula, [g] j Represents the third value of the j-th server node, [h] j Let [α] represent the fourth value of the j-th server node. j Let represent the global authentication key share of the j-th server node, e represent the first difference, f represent the second difference, and [αx] represent the third difference. j Let [αu] represent the MAC value of the scalar x-share of secret data for the j-th server node. j Let [αy] represent the secret share of the Message Authentication Code (MAC) corresponding to the second element of the multiplication triple of the j-th server node. j Let [αv] represent the MAC value of the secret data share of the scalar y of the j-th server node. j This represents the secret share of the Message Authentication Code (MAC) corresponding to the third element of the multiplication triple of the j-th server node.

[0039] Optionally, verify whether the first difference and the second difference are correct, including:

[0040] Server node calculates g = ∑ n [g] j =αe-(αx-αu) and h=∑ n [h] j =αf-(αy-αv);

[0041] If both g and h are 0, then the verification results of the first and second differences are correct; otherwise, they are incorrect.

[0042] Among them, [g] j Represents the third value of the j-th server node, [h] j Let represent the fourth value of the j-th server node, α represent the global authentication key, e represent the first difference, f represent the second difference, x represent one scalar input to the secure scalar multiplication protocol, y represent another scalar input to the secure scalar multiplication protocol, u represent the second element of the multiplication triple, and v represent the third element of the multiplication triple.

[0043] Optionally, the multiplication output share of the secure scalar multiplication protocol is calculated using the following formula:

[0044] [z] n =[w] n+e·[v] n +f·[u] n +e·f

[0045] In the formula, [z] n This represents the output of multiplication across n server nodes, [w] n Let [v] represent the first element of a triplet of n multiplications. n [u] represents the second element of a triplet of n multiplications. n Let represent the third element of n multiplicative triples, e represent the first difference, and f represent the second difference.

[0046] A second aspect of the present invention provides a multi-party collaborative charging load security prediction system to resist malicious behavior, including a data owner, a computing server, a charging operator, a power grid dispatch center, and a trusted third party, the system further including:

[0047] The key generation and deployment module is used by a trusted third party to generate a global authentication key, multiple function key shares, and multiple multiplication triplet shares required for load prediction during the offline phase. It obtains secret shares of multiple message authentication codes (MACs) through the global authentication key and multiple multiplication triplet shares, and sends the secret shares of the message authentication codes (MACs) and function key shares to the corresponding server nodes, and sends the global authentication key to the data owner.

[0048] The data and neural network model deployment module is used by data owners to obtain raw power data, preprocess it, split the preprocessed power data into multiple secret data shares, and send the secret data shares to the corresponding server nodes. When load forecasting is required, the charging operator selects the corresponding neural network model according to the load forecasting task and data type published by the power grid dispatch center, decomposes the neural network model into multiple secret model shares, and deploys the multiple secret model shares on multiple server nodes in a secret sharing manner.

[0049] The load forecasting module is used by each server node to collaboratively execute a preset security function protocol based on the secret share of the corresponding message authentication code MAC and the function key share. This completes the calculation of each layer of the neural network model. When executing the preset security function protocol, the module uses a hash value to verify whether the secret data share transmitted by other server nodes is correct. If it is incorrect, the module stops executing the protocol; otherwise, it continues executing the protocol. Finally, the module outputs the load forecasting result share and sends it to the power grid dispatch center.

[0050] The reconstructing module is used by the power grid dispatch center to reconstruct the received load forecast results to obtain the load forecast results.

[0051] A third aspect of the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when loaded onto the processor, implements the aforementioned multi-party collaborative charging load safety prediction method against malicious behavior.

[0052] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for predicting the safe charging load against malicious behavior through multi-party collaborative charging.

[0053] Compared with the prior art, the beneficial effects of the present invention include at least the following:

[0054] (1) The present invention rationally divides the original data and model parameter matrix into multiple shares, so that no server node can obtain useful information, thereby protecting sensitive information while supporting multiple participants to perform inference calculation scenarios.

[0055] (2) The present invention employs lightweight secure multi-party computation and designs a security protocol applicable to different layers of neural networks, which greatly reduces computation and communication overhead while ensuring high prediction accuracy.

[0056] (3) In the load forecasting process, the present invention uses malicious and secure multiplication triples to construct secure scalar multiplication, secure matrix multiplication and other calculations, and performs hash value verification of the correctness of the data. On this basis, it is extended to multi-party computation scenarios and can resist malicious behavior of the server, such as sending incorrect secret shares. Attached Figure Description

[0057] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0058] Figure 1 This is a schematic diagram of a multi-party collaborative charging load safety prediction method for resisting malicious behavior provided by an embodiment of the present invention;

[0059] Figure 2 This is a schematic diagram of a multi-party collaborative charging load safety prediction system framework for resisting malicious behavior, provided by an embodiment of the present invention. Detailed Implementation

[0060] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The embodiments described in this application are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of this invention.

[0061] like Figure 1 As shown, Embodiment 1 of the present invention provides a multi-party collaborative charging load safety prediction method to resist malicious behavior.

[0062] Combination Figure 2 As shown, the multi-party collaborative charging load security prediction method to resist malicious behavior involves multiple roles, including: data owner, charging operator, computing server, power grid dispatch center, and trusted third party. Specifically, the data owner prepares the raw power data, preprocesses it, and splits it into multiple parts before sending them to the computing server; the charging operator decomposes its own load prediction model into multiple secret shares and deploys them on different server nodes; multiple server nodes collaboratively execute a security function protocol to complete the neural network inference process and send the load prediction result shares to the power grid dispatch center; the power grid dispatch center reconstructs the received load prediction result shares to obtain the final load prediction result.

[0063] Specifically, data owners include, but are not limited to, various entities such as users and government departments, holding massive amounts of electricity data, including historical load, meteorological factors, and social factors. This data is collected through physical devices such as smart meters and sensors and may contain sensitive user information. Charging operators select appropriate neural network models based on the prediction task and deploy them on computing servers in a secret, shared manner. The computing servers consist of multiple independent and non-colluding server nodes. When receiving data shares from different data owners, secure inference services are provided. The power grid dispatch center publishes the required prediction tasks and uses the load prediction results to adjust power dispatch and optimize the power system. A trusted third party generates the function keys and related random values ​​required in the load prediction process during the offline phase for subsequent secure computation.

[0064] The multi-party collaborative charging load safety prediction method for resisting malicious behavior specifically includes the following steps:

[0065] Step 1: During the offline phase, the trusted third party generates a global authentication key, multiple function key shares, and multiple multiplication triple shares required for load forecasting. It obtains secret shares of multiple message authentication codes (MACs) through the global authentication key and multiple multiplication triple shares. The secret shares of the message authentication codes (MACs) and function key shares are then sent to the corresponding server nodes, and the global authentication key is sent to the data owner.

[0066] A trusted third party generates the function key and related random values ​​required for load forecasting, including the function secret shared key k. j j represents the index of the server node, the global message authentication key α, the multiplication triple and its secret share of the message authentication key {[u],[v],[w],[αu],[αv],[αw]}. L , satisfying w = u·v mod q.

[0067] Then, k j The relevant random value share is sent to the corresponding server node P. j The key α is sent to the data owner.

[0068] Preferably, but not limitingly, step 1 specifically includes:

[0069] Step 1.1: A trusted third party uses a pseudo-random generator and a distributed comparison function to generate multiple function key shares.

[0070] The function's secret shared key is j∈{1,2,…,n} represents the index of the server node, and n represents the total number of server nodes; the relevant random values ​​include two random mask values ​​r. in and r out , used as a mask for input and output values. The input value is the input to the distributed comparison function (which is an instantiation of the function secret shared) evaluation algorithm Eval(*), and the output value is the comparison result of element x and 0.

[0071] Where Gen(*) represents the key generation algorithm of the distributed comparison function, using the pseudo-random generator PRG:{0,1} n →{0,1} 2n+4 Output n keys k j ,here (1≤j≤n), σ j For PRG seeds, T j Let CW be a vector, and CW be a correction word used in binary trees to correct paths that are inconsistent with special values.

[0072] More specifically, in step 1.1, a trusted third party uses a pseudo-random generator and a distributed comparison function to generate multiple function key shares, including:

[0073] Let ρ = (γ, δ), where γ ∈ [s] and δ ∈ [t] represent the first s bits and the last t bits of binary ρ, and ρ is the path of the distributed comparison function. When the input of the distributed comparison function is less than ρ, the output is 1; otherwise, the output is 0.

[0074] Select s n×2 n-1 A set of matrices of dimension A1, A2, ... A s Make it satisfy A γ ∈O n,q A γ′ ∈E n,q And γ′≠γ, where O n,q This represents an n×2 n-fold summation of each column of elements, modulo q, where the summation is equal to 1. n-1 A set of matrices of dimension E n,q This represents an n×2 column of elements whose summation modulo q is 0. n-1 A set of matrices of dimension A γ Let A represent the γ-th matrix set. γ′ Represents the γ′-th matrix set

[0075] Randomly select s·2 n-1 a random string

[0076] Option 2 n-1 A randomized corrected word vector CW1, CW2, ..., Make it satisfy In the formula, CW i Let C represent the i-th randomly corrected word vector, PRG represent the pseudo-random generator, and C... δ This indicates that the dimension is 2, where δ is 1 at position δ and 0 at other positions. |δ| ;

[0077] Choose n random vectors T1, T2, ... Make it satisfy Among them, T j Let C represent the j-th random vector. γ This indicates that position γ is 1 and all other positions are 0, with a dimension of 2. |γ| ;

[0078] When A γ′ When [j,i]≠0, let σ j,γ′,i =(φ γ′j A γ′ [j,i]), otherwise σ j,γ′,i = (0,0), where 1≤γ′≤s, 1≤i≤2 n-1 ;

[0079] From σ j,γ′ =(σ j,γ′,1 ||σj,γ′,2 ), (1≤γ′≤s) and σ j =σ j1 ||…σ js σ is calculated j , where σ j As the seed for the pseudo-random generator, obtain the j-th function key share. (1≤j≤n).

[0080] Step 1.2: Select α←Z q Z serves as the message authentication key, used to verify whether the server node's behavior is correct. q Let n denote a group of order q, where q is a prime number of length λ bits, λ is a system security parameter, and n represents the input length.

[0081] Step 1.3: Obtain the multiplication triple, which satisfies w = u·v mod q, where w is the first element of the multiplication triple, u is the second element of the multiplication triple, and v is the third element of the multiplication triple; split the multiplication triple into n random shares, and combine them with the global authentication password to generate multiple secret shares of message authentication codes (MACs), where n represents the number of server nodes.

[0082] Step 1.3 includes:

[0083] Each multiplication triplet is split into n first random shares by addition;

[0084] Multiply the global authentication password by the multiplication triples respectively, and then add the results of the multiplications to split them into n second random shares.

[0085] The first and second random shares are combined to obtain the secret shares of the Message Authentication Code (MAC): {[u],[v],[w],[αu],[αv],[αw]} L , where [u] represents the addition of u, and L represents the total number of multiplication triples.

[0086] In this embodiment of the disclosure, the secret share {[u],[v],[w],[αu],[αv],[αw]} of the multiplication triple and its message authentication code (MAC) is calculated. L The condition w = u·v mod q is satisfied, where [u] represents the addition of u into n random shares [u], such that L represents the total number of multiplication triples.

[0087] Step 1.4: A trusted third party will {[u] j [v] j [w] j ,[αu] j [αv]j [αw] j} L and k j Send to the corresponding server node P j The authentication key α is sent to the data owner, and the parameter n is sent to both the charging operator and the data owner.

[0088] Step 2: The data owner obtains the raw power data, preprocesses it, splits the preprocessed power data into multiple secret data shares, and sends the secret data shares to the corresponding server nodes; when load forecasting is required, the charging operator selects the corresponding neural network model according to the load forecasting task and data type published by the power grid dispatch center, decomposes the neural network model into multiple secret model shares, and deploys the multiple secret model shares on multiple server nodes in a secret sharing manner.

[0089] Preferably, but not limitingly, step 2 specifically includes:

[0090] Step 2.1: The data owner preprocesses the raw power data according to the prediction task, calculates the MAC value MAC(X) of the processed data X, and splits the data X, key α, and MAC(X) into corresponding secret shares, which are then sent to the corresponding server node through a secure channel. The specific calculation process is as follows:

[0091] Step 2.1.1: Raw data preprocessing: The input data for load forecasting comes from power system measurements, meteorological factors, social factors, etc. Therefore, the type, granularity and quality of the raw data cannot be guaranteed. It is necessary to preprocess the raw data to reduce the impact of initial factors such as poor quality of historical data and differences in data units.

[0092] Step 2.1.2: Splitting of data X, key α, and MAC(X): Based on parameter n, split the data matrix X into n input matrix shares X. j and, satisfy For the authentication key α, α is randomly selected. j ←Z q ,satisfy Multiplying the data by the global authentication key yields the MAC value of the data, MAC(X) = α·X, which can also be broken down into n fractional MAC(X) values. j ),satisfy

[0093] Step 2.2: The power grid dispatch center needs to publish the load forecasting task and data type. For example, the forecasting task model should be a convolutional neural network, the data type should be the historical load of the previous 24 hours, and the power load of the next hour should be predicted.

[0094] Step 2.3: The charging operator decomposes its own load forecasting model parameter matrix W into n parameter matrix shares W. j ,satisfy They are deployed on different server nodes.

[0095] Step 3: Each server node collaboratively executes the preset security function protocol based on the secret share of the corresponding message authentication code MAC and the function key share, completes the calculation of each layer of the neural network model, and uses the hash value to verify whether the secret data share transmitted by other server nodes is correct when executing the preset security function protocol. If it is incorrect, the execution of the protocol is stopped; otherwise, the execution of the protocol continues. Finally, the load prediction result share is output and sent to the power grid dispatch center.

[0096] Multiple server nodes collaboratively execute the security function protocol to complete the neural network inference process and send the load forecast results to the power grid dispatch center. Preferably, but not limitingly, step 3 specifically includes:

[0097] Step 3.1: Server node P j They jointly execute a safe function protocol, including safe scalar multiplication, safe matrix multiplication, safe Hadamard product, and safe ReLU function.

[0098] Specifically, for the linear and nonlinear layers of the neural network, secure two-party computation protocols are designed using addition secret sharing and function secret sharing techniques, respectively, to compute core operations such as secure scalar multiplication protocol SMul([x],[y]), secure matrix multiplication protocol MatMul([X],[Y]), secure Hadamard product protocol MatHad([X],[Y]), secure fully connected layer protocol, secure convolution protocol SConv([X],[Y]), secure integer comparison protocol SComp(x,y), and secure ReLU function protocol SReLU(x).

[0099] Step 3.1 specifically includes:

[0100] Step 3.1.1: Design a secure scalar multiplication protocol using addition secret sharing and function secret sharing techniques. Each server node collaboratively executes the preset secure scalar multiplication protocol based on the secret share of the corresponding message authentication code MAC and the function key share. When executing the secure scalar multiplication function protocol, a hash value is used to verify whether the secret data share transmitted by other server nodes is correct. If it is incorrect, the protocol execution stops; otherwise, the protocol execution continues.

[0101] Specifically, the secure scalar multiplication protocol SMul([x],[y]) is used to perform secure multiplication operations on secret shares of scalars [x] and [y]. Where [x]... j and [y] j It is Pj The input share, [u] j [v] j [w] j ,[αu] j [αv] j [αw] j Is it a trusted third party for P during the offline phase? j Provide the share of the multiplication triples and their MAC values, where j∈{1,2,…,n} is the participant index, [αx] j and [αy] j The data owner is P j The MAC value share of the provided data is calculated as follows:

[0102] Step 3.1.1.1: Each server node subtracts the second and third elements of the multiplication triple from the secret data share to obtain the corresponding first and second differences, and sends the first and second differences to other server nodes.

[0103] P j Local computation [e] j =[xu] j =[x] j -[u] j [f] j =[yv] j =[y] j -[v] j And [e] j and [f] j Send it to the other party.

[0104] Step 3.1.1.2: Each server node calculates the third and fourth values ​​based on the secret share of the corresponding message authentication code MAC, the first difference of the function key share, and the second difference, and calculates the first hash value of the third and fourth values, and sends the third, fourth, and first hash values ​​to other server nodes.

[0105] Furthermore, the third and fourth values ​​are calculated for each server node based on the secret share of the corresponding message authentication code MAC, the function key share, and the first and second differences, according to the following formula. The first hash value of the third and fourth values ​​is then calculated:

[0106] [g] j =[α] j ·e-([αx] j -[αu] j )

[0107] [h] j =[α] j·f-([αy] j -[αv] j )

[0108] hash j =hash([g]) j [h] j )

[0109] In the formula, [g] j Represents the third value of the j-th server node, [h] j Let [α] represent the fourth value of the j-th server node. j Let represent the global authentication key share of the j-th server node, e represent the first difference, f represent the second difference, and [αx] represent the third difference. j Let [αu] represent the MAC value of the scalar x-share of secret data for the j-th server node. j Let [αy] represent the secret share of the Message Authentication Code (MAC) corresponding to the second element of the multiplication triple of the j-th server node. j Let [αv] represent the MAC value of the secret data share of the scalar y of the j-th server node. j This represents the secret share of the Message Authentication Code (MAC) corresponding to the third element of the multiplication triple of the j-th server node.

[0110] In this embodiment of the disclosure, P j Reconstruct e = ∑ n [e] j =xu and f=∑ n [f] j =yv. In calculating the secret share [z] of xy. j =[xy] j Previously, the correctness of e and f needed to be verified. Next, P... j Local computation [g] j =[α] j ·e-([αx] j -[αu] j ) and [h] j =[α] j ·f-([αy] j -[αv] j ) and its commitment value, i.e., hash value j =hash([g]) j [h] j Finally, P j hash j Send it to the recipient. If verification fails, the server will indicate that it is a fake message, suggesting malicious activity.

[0111] For j∈{1,2,…,n}, P j[g] j [h] j Sending it to the other party will activate the commitment.

[0112] Step 3.1.1.3: Each server node calculates the second hash value based on the obtained third and fourth values, and compares the first hash value with the second hash value. If they are not equal, the protocol is terminated. If they are equal, the first difference and the second difference are verified to be correct. If they are not correct, the protocol is terminated. Otherwise, the protocol is executed to obtain the multiplication output share of the secure scalar multiplication protocol.

[0113] Further, verify whether the first difference and the second difference are correct, including:

[0114] Server node calculates g = ∑ n [g] j =αe-(αx-αu) and h=∑ n [h] j =αf-(αy-αv);

[0115] If both g and h are 0, then the verification results of the first and second differences are correct; otherwise, they are incorrect.

[0116] Among them, [g] j Represents the third value of the j-th server node, [h] j Let represent the fourth value of the j-th server node, α represent the global authentication key, e represent the first difference, f represent the second difference, x represent one scalar input to the secure scalar multiplication protocol, y represent another scalar input to the secure scalar multiplication protocol, u represent the second element of the multiplication triple, and v represent the third element of the multiplication triple.

[0117] In this embodiment of the disclosure, P j Verify hash j =hash([g]) j [h] j If the equation does not hold, the agreement is terminated; otherwise, P j Calculate g = ∑ n [g] j =αe-(αx-αu) and h=∑ n [h] j =αf-(αy-αv). If g=0 and h=0, it means that e and f are correct, and continue to the next step; otherwise, the agreement is terminated.

[0118] Furthermore, the multiplication output share of the secure scalar multiplication protocol is calculated using the following formula:

[0119] [z] n =[w] n +e·[v]n +f·[u] n +e·f

[0120] In the formula, [z] n This represents the output of multiplication across n server nodes, [w] n Let [v] represent the first element of a triplet of n multiplications. n [u] represents the second element of a triplet of n multiplications. n Let represent the third element of n multiplicative triples, e represent the first difference, and f represent the second difference.

[0121] In this embodiment of the disclosure, {P i} i=1,2,...,n-1 Calculate the output share [z] i =[w] i +e·[v] i +f·[u] i P n Calculate the output share [z] n =[w] n +e·[v] n +f·[u] n +e·f. Its protocol correctness is as follows:

[0122] [z] n +∑ n-1 [z] i =e·f+w+e·v+f·u

[0123] =(xu)(yv)+uv+(xu)v+(yv)

[0124] =xy

[0125] In this embodiment, the MAC value of the result of multiplying two random numbers is calculated. Then, the random numbers, the multiplication result, and their MAC values ​​are split and sent to different server nodes. The data owner then uses a global authentication key to calculate the MAC value of the data, and then splits the data and MAC value, deploying them on different server nodes, thus completing the secure scalar multiplication. This embodiment not only supports multiple participants in the computation but also ensures the multiplication protocol resists malicious behavior and guarantees the correctness of data transmission through two-layer verification, resulting in higher security.

[0126] Step 3.1.2: The secure matrix multiplication protocol MatMul([X],[Y]) is used to multiply matrix shares [X] and [Y] to obtain [Z], satisfying Z = X × Y. During initialization, scalar multiplication triples are replaced with matrix triples [U], [V], and [W], satisfying W = U × V, where U has the same dimension as X, V has the same dimension as Y, and all elements in U and V are Z.q The values ​​in the array. By extending the SMul() protocol, matrix multiplication triplets can be implemented using vectorization techniques. For example, {[u i ] j ,[v i ] j ,[w i ] j} i=1, … ,k For P j The set of multiplication triplets held, where X and Y have the same dimension of 3, has the following matrix triplets: and The corresponding MAC value matrix share is calculated using a similar method.

[0127] This disclosure utilizes vectorization technology to construct the authentication multiplication triplet share and MAC value share in the form of a diagonal matrix, transforming the corresponding scalar multiplication into matrix multiplication. Only through the redesigned scalar multiplication and matrix multiplication schemes can secure core operations, such as convolution operations and activation functions, be achieved.

[0128] Step 3.1.3: The secure Hadamard product protocol MatHad([X],[Y]) is used to perform element-wise multiplication of matrix shares [X] and [Y] to obtain [Z], satisfying Z = X ⊙ Y, where ⊙ represents the Hadamard operation. Similarly, using the method in step (3-2), element-wise matrix triples [U], [V], and [W] are generated during the initialization phase, satisfying W = U ⊙ V. Then, secure computation is performed on each element during the online phase.

[0129] Step 3.1.4: Secure fully connected layer protocol for matrix multiplication. Therefore, a secure fully connected layer can be directly implemented using MatMul(), thus ensuring the security of the fully connected layer.

[0130] Step 3.1.5: Secure convolution protocol SConv([X],[Y]), used to calculate the weighted sum of the input matrix and the convolution kernel at corresponding positions. For a height of H... X Width is W X The input matrix X and the height H Y Width is W Y The convolution kernel Y is used, and the convolution result is Z = X * Y, where * represents the convolution operation. The secure convolution protocol SConv([X],[Y]) is implemented using MatMul(). During the initialization phase, P... j Generate matrix multiplication triples [U] by extending the SMul() protocol. j [V] j and [W] j During the calculation phase, P j Holding high is HX Width is W X The share of the input matrix [X] j And high is H Y Width is W Y kernel share [Y] j , and initialize the output matrix [Z]. j Its height is H X -H Y +1, width is W X -W Y +1. For each element [Z(i,j)] in the output matrix, its corresponding local input matrix is ​​[X(i:i+H... Y -1,j:j+W Y The specific calculation process is similar to step 3.1.1, except that scalar multiplication is replaced by matrix multiplication, and the share of the first n-1 elements in the matrix is ​​output [Z(i,j)]. b=1,2, … ,n-1 =E*F+[W] j +E*[V] j +F*[U] j And the share of the nth element [Z(i,j)] n =E*F+[W] j +E*[V] j +F*[U] j .

[0131] Step 3.1.6: Secure integer comparison protocol SComp(x,y), used to compare the size of integer values ​​x and y.

[0132] In this embodiment of the disclosure, a distributed comparison function is used to construct integers, which is defined as follows: That is, the output is 1 when x < ρ, and 0 otherwise. This process is divided into two stages: key generation and function evaluation.

[0133] Step 3.1.6.1: In the key generation phase, construct a binary tree with n bits as input, where ρ is a path. The goal is to output 1 through path ρ and 0 through other paths. Each node in the binary tree contains two pieces of information: a random seed and control bits. Only nodes on path ρ have valid information; nodes on other paths are all 0.

[0134] Therefore, additional correction words need to be added to each layer so that in one of the left and right child nodes, the information of that node is 0, and the random seed of the other node is a random string and 1. Thus, the key distributed to both parties is a fragment of the initial random seed and the common correction words for each layer. During the function evaluation phase, each party uses the random seed fragment to continuously generate subtrees through the PRG. During this process, the addition of correction words depends on the control bits held by each party (initially, one party has 0, the other has 1, and both parties hold fragments of 1 because the root node must be on the ρ path). Thus, starting from the root node, the information of one subtree node held by one party is changed to 0, while the other subtree node updates its random seed and control bits. This continues; if the path is deviated, the corresponding subtree node information is 0; if on the ρ path, both parties will hold fragments of 1. The specific calculation process is as follows:

[0135] Key generation algorithm The algorithm was developed by a trusted third party. The specific process is as follows:

[0136] Let ρ = (γ, δ), where γ ∈ [s] and δ ∈ [t], representing the first s bits and the last t bits of the binary ρ, respectively. Then, select s n×2 n-1 A set of matrices of dimension A1, A2, ... A s Satisfying A γ ∈O n,q and A γ′ ∈E n,q , γ′≠γ, where, O n,q This represents an n×2 n-fold summation of each column of elements, modulo q, where the summation is equal to 1. n-1 A set of matrices of dimension E n,q This represents an n×2 column of elements whose summation modulo q is 0. n-1 A set of matrices of dimension A γ Let A represent the γ-th matrix set. γ′ Let γ' represent the set of matrices.

[0137] Randomly select s·2 n-1 A random string:

[0138] Next, select 2. n-1 Let CW1, CW2, ... be random vectors. satisfy Among them, CW i Let C represent the i-th randomly corrected word vector, PRG represent the pseudo-random generator, and C... δ This indicates that the dimension is 2, where δ is 1 at position δ and 0 at other positions. |δ| ;

[0139] Choose n random vectors T1, T2, ... satisfy Among them, T j Let C represent the j-th random vector. γ This indicates that position γ is 1 and all other positions are 0, with a dimension of 2. |γ| The vector.

[0140] When A γ′ When [j,i]≠0, then σ j,γ′,i =(φ γ′j A γ′ [j,i]), otherwise σ j,γ′,i = (0,0), where 1≤γ′≤s, 1≤i≤2 n-1 .

[0141] Let σ j,γ′ =(σ j,γ′,1 ||σ j,γ′,2 ), (1≤γ′≤s) and σ j =σ j1 ||…σ js and (1≤j≤n). Finally, the key k j Send to server P j .

[0142] Step 3.1.6.2: Function evaluation algorithm Eval(j,k) j ,x)→z j The algorithm is performed by each server node individually.

[0143] Let x = (γ′, δ′), γ′ ∈ [s], δ′ ∈ [t], analytic k j for in, Then, calculate. Obtain the output share z j =(T j [γ′]+d j [δ′])modq.

[0144] Step 3.1.7: The safe ReLU function protocol SReLU(x) is one of the most commonly used activation functions in neural networks.

[0145] For input x, it is defined as ReLU(x) = max(0,x), that is, when x > 0, ReLU(x) = x, otherwise it is 0. Its derivative is defined as DReLU(x) = 1{x > 0}, that is, ReLU(x) = x·DReLU(x). Therefore, SReLU() is implemented by combining the SCMop() protocol and the SMul() protocol.

[0146] First, use SComp(x,0) to calculate the output share of DReLU(x), and then call SMul([DReLU],[x]) to calculate the output share of the ReLU function [ReLU(x)].

[0147] Step 3.2: Server node P j The component Y of its own load forecast result matrix j Send to the power grid dispatch center.

[0148] CNNs primarily consist of convolutional layers and the ReLU function. The SConv() protocol performs convolution operations on the input data to extract key features. The output of the convolutional layers is then processed by the SReLU() protocol, introducing non-linear characteristics and enhancing the model's expressive power. Finally, the server node P... j The component Y of its own load forecast result matrix j Send to the power grid dispatch center.

[0149] Step 4: The power grid dispatch center reconstructs the received load forecast results to obtain the final load forecast. Preferably, but not limitingly, step 4 specifically includes:

[0150] Step 4.1: The power grid dispatch center assigns a share Y to the received load forecast results. j To add together, that is, to calculate The load forecast result matrix Y is obtained, which is an H out ×W out The matrix.

[0151] Step 4.2: Extract feature information based on the load forecast result matrix and output the predicted load value.

[0152] It is understandable that feature information is extracted to reconstruct the preprocessed data and restore it to the original power data. The reverse operations of preprocessing techniques, such as denormalization and destandardization, will not be elaborated upon here.

[0153] Embodiment 2 of the present invention provides a multi-party collaborative charging load security prediction system resistant to malicious behavior, which runs the multi-party collaborative charging load security prediction method resistant to malicious behavior as described in Embodiment 1. The system includes a data owner, a computing server, a charging operator, a power grid dispatch center, and a trusted third party. The system also includes:

[0154] The key generation and deployment module is used by a trusted third party to generate a global authentication key, multiple function key shares, and multiple multiplication triplet shares required for load prediction during the offline phase. It obtains secret shares of multiple message authentication codes (MACs) through the global authentication key and multiple multiplication triplet shares, and sends the secret shares of the message authentication codes (MACs) and function key shares to the corresponding server nodes, and sends the global authentication key to the data owner.

[0155] The data and neural network model deployment module is used by data owners to obtain raw power data, preprocess it, split the preprocessed power data into multiple secret data shares, and send the secret data shares to the corresponding server nodes. When load forecasting is required, the charging operator selects the corresponding neural network model according to the load forecasting task and data type published by the power grid dispatch center, decomposes the neural network model into multiple secret model shares, and deploys the multiple secret model shares on multiple server nodes in a secret sharing manner.

[0156] The load forecasting module is used by each server node to collaboratively execute a preset security function protocol based on the secret share of the corresponding message authentication code MAC and the function key share. This completes the calculation of each layer of the neural network model. When executing the preset security function protocol, the module uses a hash value to verify whether the secret data share transmitted by other server nodes is correct. If it is incorrect, the module stops executing the protocol; otherwise, it continues executing the protocol. Finally, the module outputs the load forecasting result share and sends it to the power grid dispatch center.

[0157] The reconstructing module is used by the power grid dispatch center to reconstruct the received load forecast results to obtain the load forecast results.

[0158] Regarding the system in the above embodiments, the specific manner in which each unit performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

[0159] Embodiment 3 of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements the multi-party collaborative charging load safety prediction method for resisting malicious behavior described in Embodiment 1.

[0160] Embodiment 4 of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the multi-party collaborative charging load safety prediction method against malicious behavior as described in Embodiment 1.

[0161] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0162] This disclosure can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of this disclosure.

[0163] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0164] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.

[0165] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, etc., and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.

[0166] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A multi-party collaborative charging load safety prediction method to resist malicious behavior, characterized in that, include: A trusted third party generates a global authentication key, multiple function key shares, and multiple multiplication triple shares required for load forecasting during the offline phase. It obtains secret shares of multiple message authentication codes (MACs) through the global authentication key and multiple multiplication triple shares. The secret shares of the message authentication codes (MACs) and function key shares are then sent to the corresponding server nodes, and the global authentication key is sent to the data owner. The data owner obtains the raw power data, preprocesses it, splits the preprocessed power data into multiple secret data shares, and sends the secret data shares to the corresponding server nodes. When load forecasting is required, the charging operator selects the corresponding neural network model according to the load forecasting task and data type published by the power grid dispatch center, decomposes the neural network model into multiple secret model shares, and deploys the multiple secret model shares on multiple server nodes in a secret sharing manner. Each server node collaboratively executes a preset security function protocol based on the secret share of the corresponding message authentication code (MAC) and the function key share, completes the calculation of each layer of the neural network model, and uses a hash value to verify whether the secret data share transmitted by other server nodes is correct when executing the preset security function protocol. If it is incorrect, the execution of the protocol is stopped; otherwise, the execution of the protocol continues. Finally, the load forecast result share is output and sent to the power grid dispatch center. The power grid dispatch center reconstructs the received load forecast results by reconstructing the proportions of the load forecast results to obtain the load forecast results.

2. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 1, characterized in that: A trusted third party generates the global authentication key, function key share, and multiplication triple share required for load forecasting during the offline phase. The secret share of the Message Authentication Code (MAC) is obtained through the global authentication key and multiplication triple share, including: A trusted third party uses a pseudo-random generator and a distributed comparison function to generate multiple function key shares; Select α←Z q As a global authentication password, Z q Let represent a group of order q, where q is a prime number of length λ bits and λ is a system security parameter; Obtain a multiplication triplet, wherein the multiplication triplet satisfies w = u·v mod q, where w is the first element of the multiplication triplet, u is the second element of the multiplication triplet, and v is the third element of the multiplication triplet; split the multiplication triplet into n random shares, and combine them with the global authentication password to generate secret shares of multiple message authentication codes (MACs), where n represents the number of server nodes.

3. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 2, characterized in that: The multiplication triple is split into n random shares, and combined with the global authentication cipher to generate multiple secret shares of the Message Authentication Code (MAC), including: Each multiplication triplet is split into n first random shares by addition; Multiply the global authentication password by the multiplication triples respectively, and then add the results of the multiplications to split them into n second random shares. The first and second random shares are combined to obtain the secret shares of the Message Authentication Code (MAC): {[u],[v],[w],[αu],[αv],[αw]} L , where [u] represents the addition of u, and L represents the total number of multiplication triples.

4. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 2, characterized in that: A trusted third party uses a pseudo-random generator and a distributed comparison function to generate multiple function key shares, including: Let ρ = (γ, δ), where γ ∈ [s] and δ ∈ [t] represent the first s bits and the last t bits of binary ρ, and ρ is the path of the distributed comparison function. When the input of the distributed comparison function is less than ρ, the output is 1; otherwise, the output is 0. Select s n×2 n-1 A set of n-dimensional matrices A1, A2, ... A s , such that A satisfies γ ∈O n,q A γ′ ∈E n,q and γ′≠γ, where O n,q This represents an n×2 n-fold summation of each column of elements, modulo q, where the summation is equal to 1. n-1 A set of matrices of dimension E n,q This represents an n×2 column of elements whose summation modulo q is 0. n-1 A set of matrices of dimension A γ Let A represent the γ-th matrix set. γ′ Represents the γ′-th matrix set; Randomly select s·2 n-1 a random string Option 2 n-1 Each random correction word vector Make it satisfy In the formula, CW i Let C represent the i-th randomly corrected word vector, PRG represent the pseudo-random generator, and C... δ This indicates that the dimension is 2, where δ is 1 at position δ and 0 at other positions. |δ| ; Select n random vectors Make it satisfy Among them, T j Let C represent the j-th random vector. γ This indicates that position γ is 1 and all other positions are 0, with a dimension of 2. |γ| ; When A γ′ When [j,i]≠0, let σ j,γ′,i =(φ γ′j A γ′ [j,i]) times, otherwise σ j,γ′,i = (0,0) items, where 1≤γ′≤s, 1≤i≤2 n-1 ; From σ j,γ′ =(σ j,γ′,1 ||σ j,γ′,2 ), (1≤γ′≤s) and σ j =σ j1 ||…σ js The calculation yields σ j , of which σ j As the seed for the pseudo-random generator, obtain the j-th function key share.

5. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 2, characterized in that: The pre-defined security function protocol includes the secure scalar multiplication protocol SMul([x],[y]), used to perform secure multiplication operations on secret data shares of scalars [x] and [y]. Each server node collaboratively executes the pre-defined security function protocol based on its corresponding message authentication code (MAC) secret share and function key share. During the execution of the pre-defined security function protocol, a hash value is used to verify the correctness of the secret data shares transmitted by other server nodes. If incorrect, the protocol execution stops; otherwise, execution continues. This includes: Each server node subtracts the second and third elements of the multiplication triple from the secret data share to obtain the corresponding first and second differences, and sends the first and second differences to other server nodes. Each server node calculates the third and fourth values ​​based on the secret share of the corresponding message authentication code MAC, the first difference of the function key share, and the second difference, and calculates the first hash value of the third and fourth values, and sends the third, fourth, and first hash values ​​to other server nodes; Each server node calculates the second hash value based on the obtained third and fourth values, and compares the first hash value with the second hash value. If they are not equal, the protocol is terminated. If they are equal, the first difference and the second difference are verified to be correct. If they are not correct, the protocol is terminated. Otherwise, the protocol is executed to obtain the multiplication output share of the secure scalar multiplication protocol.

6. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 5, characterized in that: The third and fourth values ​​for each server node are calculated using the following formula, based on the secret share of the corresponding MAC message authentication code, the function key share, the first difference, and the second difference. The first hash value of the third and fourth values ​​is then calculated: [g] j =[a] j ·e-([αx] j -[au] j ) [h] j =[a] j ·f-([αy] j -[av] j ) hash j =hash([g] j ,[h] j ) In the formula, [g] j Represents the third value of the j-th server node, [h] j Let [α] represent the fourth value of the j-th server node. j Let represent the global authentication key of the j-th server node, e represent the first difference, f represent the second difference, and [αx] represent the third difference. j Let [αu] represent the MAC value of the scalar x-share of secret data for the j-th server node. j Let [αy] represent the secret share of the Message Authentication Code (MAC) corresponding to the second element of the multiplication triple of the j-th server node. j Let [αv] represent the MAC value of the secret data share of the scalar y of the j-th server node. j This represents the secret share of the Message Authentication Code (MAC) corresponding to the third element of the multiplication triple of the j-th server node.

7. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 5, characterized in that: Verify that the first and second differences are correct, including: Server node calculates g = ∑ n [g] j =αe-(αx-αu) and sum h=∑ n [h] j = αf - (αy - αv) items; If both g and h are 0, then the verification results of the first and second differences are correct; otherwise, they are incorrect. Among them, [g] j Represents the third value of the j-th server node, [h] j Let represent the fourth value of the j-th server node, α represent the global authentication key, e represent the first difference, f represent the second difference, x represent one scalar input to the secure scalar multiplication protocol, y represent another scalar input to the secure scalar multiplication protocol, u represent the second element of the multiplication triple, and v represent the third element of the multiplication triple.

8. The multi-party collaborative charging load safety prediction method for resisting malicious behavior according to claim 5, characterized in that: The multiplication output share of the secure scalar multiplication protocol is calculated using the following formula: [z] n =[w] n +e·[v] n +f·[u] n +e·f In the formula, [z] n This represents the output of multiplication across n server nodes, [w] n Let [v] represent the first element of a triplet of n multiplications. n [u] represents the second element of a triplet of n multiplications. n Let represent the third element of n multiplicative triples, e represent the first difference, and f represent the second difference.

9. A multi-party collaborative charging load security prediction system to resist malicious behavior, comprising a data owner, a computing server, a charging operator, a power grid dispatch center, and a trusted third party, characterized in that, The system also includes: The key generation and deployment module is used by a trusted third party to generate a global authentication key, multiple function key shares, and multiple multiplication triplet shares required for load prediction during the offline phase. It obtains secret shares of multiple message authentication codes (MACs) through the global authentication key and multiple multiplication triplet shares, and sends the secret shares of the message authentication codes (MACs) and function key shares to the corresponding server nodes, and sends the global authentication key to the data owner. The data and neural network model deployment module is used by data owners to obtain raw power data, preprocess it, split the preprocessed power data into multiple secret data shares, and send the secret data shares to the corresponding server nodes. When load forecasting is required, the charging operator selects the corresponding neural network model according to the load forecasting task and data type published by the power grid dispatch center, decomposes the neural network model into multiple secret model shares, and deploys the multiple secret model shares on multiple server nodes in a secret sharing manner. The load forecasting module is used by each server node to collaboratively execute a preset security function protocol based on the secret share of the corresponding message authentication code MAC and the function key share. This completes the calculation of each layer of the neural network model. When executing the preset security function protocol, the module uses a hash value to verify whether the secret data share transmitted by other server nodes is correct. If it is incorrect, the module stops executing the protocol; otherwise, it continues executing the protocol. Finally, the module outputs the load forecasting result share and sends it to the power grid dispatch center. The reconstructing module is used by the power grid dispatch center to reconstruct the received load forecast results to obtain the load forecast results.

10. An electronic device, comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is configured to operate according to the instructions to perform the steps of the multi-party collaborative charging load security prediction method for combating malicious behavior according to any one of claims 1-8.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the steps of the method for multi-party collaborative charging load security prediction against malicious behavior as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Neural network training reasoning method and system based on function secret sharing

    CN117291258A

  • Privacy protection neural network training method and device based on function secret sharing

    CN117592527A

Cited By

  • A charging pile group cooperative scheduling and privacy management method and device based on secure multi-party computation, an electronic device, a computer readable storage medium, a charging pile and a system

    CN122372328A