Intelligent marketing terminal electric power data communication security protection method and system

By combining the electromagnetic sensing module and twin mirror technology of the intelligent marketing terminal with long short-term memory neural network and blockchain evidence storage, the security threat of power data communication of the intelligent marketing terminal is solved, realizing dynamic encryption, accurate detection and full-process trusted evidence storage, thereby improving communication security and data credibility.

CN121000528AActive Publication Date: 2025-11-21JIANGSU ELECTRIC POWER INFORMATION TECH

Patent Information

Application Number
CN202511518194.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-23
Publication Date
2025-11-21
Estimated Expiration
2045-10-23

AI Technical Summary

Technical Problem

In existing technologies, the power data communication of intelligent marketing terminals faces security threats such as electromagnetic interference attacks, command tampering, and privacy leaks, and suffers from problems such as the inability to dynamically adjust encryption parameters, low accuracy of anomaly detection, and lack of full lifecycle integrity protection for data storage.

Method used

Electromagnetic noise spectrum data is collected by the built-in environmental electromagnetic sensing module of the terminal, a correlation model between electromagnetic feature factors and elliptic curve cryptography is constructed, a terminal twin image is built and a long short-term memory neural network is used to predict the communication command sequence, generate encrypted data packets with time-series traceability watermarks and upload them to the blockchain for evidence storage, so as to achieve dynamic encryption adaptation and accurate anomaly detection.

Benefits of technology

It enhances communication security and data credibility, achieves full-process security control, dynamically adapts encryption parameters to resist interference and attacks, accurately identifies abnormal terminal operations, protects user privacy, and ensures that data is traceable and tamper-proof throughout the entire process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000528A_ABST
    Figure CN121000528A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent marketing terminal power data communication security protection method and system, and belongs to the field of power data security, and the method comprises the steps: collecting electromagnetic noise spectrum data through a built-in environment electromagnetic sensing module of a terminal, extracting electromagnetic characteristic factors, and constructing a correlation model of the electromagnetic characteristic factors and the complexity of an elliptic curve cryptosystem; building a terminal twinborn mirror image, predicting a communication instruction sequence and calculating a deviation coefficient in combination with a long-short-term memory neural network; classifying and screening the power data collected by the terminal, desensitizing privacy data, and then fusing the privacy data into the hash fragment of the unique identifier of the terminal equipment to generate a desensitized power data packet containing the terminal identity identifier; a data abstract is generated according to encryption parameters determined by the association model, the access authority is verified, a data acquisition timestamp is converted into a binary coding sequence, the data abstract is embedded, and an encrypted data packet with a time sequence traceability watermark is generated and uploaded to the block chain for evidence storage; according to the invention, full-process security management and control of power data are realized, and the communication security and the data credibility are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of power data security, specifically a method and system for protecting the security of power data communication in intelligent marketing terminals. Background Technology

[0002] With the deepening of smart grid construction, smart marketing terminals, as key nodes connecting users and the power grid, need to collect and transmit large amounts of power data, including sensitive content such as user electricity consumption information and identity information. This data faces security threats during communication, including electromagnetic interference attacks, command tampering, privacy leaks, and data alteration. Existing technologies for power data communication security management mostly employ fixed encryption strategies, static access control, and single-dimensional anomaly detection methods, which have the following shortcomings: encryption parameters cannot be dynamically adjusted according to the environment, resulting in insufficient anti-attack capabilities; the accuracy of anomaly command detection is low, making it difficult to identify new attack methods; after desensitizing privacy data, effective restoration under authorized scenarios is not possible; and data storage lacks full lifecycle integrity guarantees. Therefore, there is an urgent need for a power data communication security protection method for smart marketing terminals that can achieve dynamic encryption adaptation, accurate anomaly detection, secure privacy protection, and trusted storage throughout the entire process. Summary of the Invention

[0003] To address the shortcomings of existing technologies, this invention proposes a method and system for secure protection of power data communication in intelligent marketing terminals. The method involves collecting electromagnetic noise spectrum data through a built-in environmental electromagnetic sensing module in the terminal, extracting electromagnetic feature factors, and constructing a correlation model between these factors and the complexity of elliptic curve cryptography. A terminal twin mirror is then built, and a long short-term memory neural network is used to predict communication command sequences and calculate deviation coefficients. The power data collected by the terminal is categorized and filtered; after desensitizing privacy-related data, a hash fragment containing the terminal's unique identifier is integrated to generate a desensitized power data packet containing the terminal's identity. Based on the encryption parameters determined by the correlation model, a data digest is generated and access permissions are verified. The data collection timestamp is converted into a binary encoded sequence and embedded into the data digest, generating an encrypted data packet with a time-series traceability watermark, which is then uploaded to the blockchain for evidence storage. This invention achieves secure control over the entire power data process, improving communication security and data credibility.

[0004] To achieve the above objectives, the present invention provides the following technical solution:

[0005] The methods for protecting the security of power data communication in intelligent marketing terminals include:

[0006] The terminal collects electromagnetic noise spectrum data through its built-in environmental electromagnetic sensing module, extracts electromagnetic feature factors, and constructs a correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography.

[0007] A terminal twin image is constructed. Based on a long short-term memory neural network, the terminal operation status synchronized with the terminal twin image is used to predict the communication instruction sequence. The deviation coefficient between the actual communication instructions generated by the terminal and the predicted communication instruction sequence is calculated.

[0008] Based on the comparison result between the deviation coefficient and the preset threshold, it is determined whether the terminal behavior is abnormal;

[0009] The power data collected by terminals that are deemed to be normal is classified and filtered. Privacy-related data is extracted and desensitized to obtain desensitized power data. The hash fragment of the unique identifier of the terminal device is then extracted as a reversible parsing factor. A preset embedding algorithm is used to integrate the reversible parsing factor into the desensitized power data to generate a desensitized power data package containing the terminal's identity identifier.

[0010] The encryption parameters are determined based on the association model. The encryption parameters are used to generate a data digest for the de-identified power data packet. Access permission verification is completed based on the terminal identity identifier in the de-identified power data packet.

[0011] Obtain the data collection timestamp corresponding to the desensitized power data packet after access permission verification and convert it into a binary encoding sequence. Embed the binary encoding sequence into the least significant bit of the data digest to generate an encrypted data packet with a time-tracing watermark and upload it to the blockchain for evidence storage.

[0012] Specifically, the original privacy data is restored by a reversible parsing algorithm only if the identifier of the terminal device requesting access matches the hash fragment in the de-identified power data packet.

[0013] Specifically, the terminal collects electromagnetic noise spectrum data through a built-in environmental electromagnetic sensing module and extracts electromagnetic feature factors, including:

[0014] The environmental electromagnetic sensing module monitors and collects the original electromagnetic signals in the preset frequency band in real time when the terminal performs elliptic curve cryptography.

[0015] The original electromagnetic signal is preprocessed to obtain digitized electromagnetic noise spectrum data;

[0016] The digitized electromagnetic noise spectrum data is subjected to a fast Fourier transform to convert it from the time domain to the frequency domain, thus obtaining the noise spectrum.

[0017] The electromagnetic characteristic factors are extracted from the noise spectrum; the electromagnetic characteristic factors include noise amplitude, spectral distribution shape, and dynamic change rate; the noise amplitude is the signal strength value of a preset frequency point or frequency band in the noise spectrum; the spectral distribution shape is determined by quantizing the skewness, kurtosis, and energy entropy of the spectrum; the dynamic change rate is the difference in spectral energy between adjacent sampling cycles.

[0018] Specifically, the construction of the correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography includes:

[0019] Establish a multidimensional feature vector, using the electromagnetic feature factors as vector elements;

[0020] Multiple elliptic curve cryptosystems with different complexities are deployed on the terminal; the complexity is determined by the field size, base order, and dot product algorithm of the selected elliptic curve.

[0021] Under different electromagnetic noise environments, various elliptic curve cryptography operations are performed, and their operation time, power consumption, and error rate are recorded as complexity response indicators.

[0022] Using a machine learning regression algorithm, with the multidimensional feature vector as input and the complexity response index as output, an association model is trained to obtain an association model; the association model predicts the optimal encryption complexity level in the current environment based on the electromagnetic feature factors extracted in real time.

[0023] Specifically, the construction of the terminal twin mirror, based on a long short-term memory neural network, combines the terminal's synchronized operating state with the terminal twin mirror to predict the communication command sequence, and calculates the deviation coefficient between the actual communication commands generated by the terminal and the predicted communication command sequence, including:

[0024] A terminal twin image corresponding one-to-one with the physical terminal is constructed on a local or edge security node; the twin image is synchronized with the running operation status by receiving the terminal's system calls, process list and network connection status information;

[0025] A prediction model is generated by training the terminal's historical communication command sequences under preset business scenarios using a long short-term memory neural network.

[0026] When communication occurs, the prediction model is executed by the terminal twin mirror, and the predicted sequence of communication instructions is output.

[0027] The actual communication commands generated by the terminal are compared with the predicted communication command sequence to obtain the deviation coefficient.

[0028] Specifically, the extraction of the hash fragment uniquely identified by the terminal device is used as a reversible parsing factor, and a preset embedding algorithm is employed to integrate the reversible parsing factor into the desensitized power data, including:

[0029] Obtain the terminal's unique hardware identifier;

[0030] The SM3 hash algorithm is used to calculate the hash digest of the hardware unique identifier.

[0031] Extract the first N bits of the hash digest to generate a hash fragment, and use it as a reversible parsing factor;

[0032] Convert the reversible parsing factor into a binary stream;

[0033] Select the reserved or extended bits of the fields in the desensitized power data packet as the embedding area;

[0034] The binary stream is embedded into the embedding region using the least significant bit substitution algorithm to generate the desensitized power data packet containing the terminal identity identifier.

[0035] Specifically, the step of determining encryption parameters based on the association model and using the encryption parameters to generate a data digest for the de-identified power data packet includes:

[0036] The electromagnetic feature factors extracted in real time are input into the correlation model;

[0037] Obtain the encryption parameters of the elliptic curve cryptosystem output by the correlation model that match the complexity of the current electromagnetic environment; the encryption parameters include elliptic curve type, domain parameters, and key length;

[0038] The de-identified power data packet containing the terminal identity is digitally signed using an elliptic curve digital signature algorithm determined by the encryption parameters, and a digital signature value is generated as the data digest.

[0039] Specifically, the step of obtaining the data acquisition timestamp corresponding to the de-identified power data packet after access permission verification and converting it into a binary encoded sequence, and embedding the binary encoded sequence into the least significant bit of the data digest, includes:

[0040] Extract the data acquisition timestamp from the metadata of the de-identified power data packet;

[0041] Convert the data acquisition timestamps in UTC time format into binary encoded sequences;

[0042] Obtain the binary representation of the data digest;

[0043] The original data in the least significant bit of the binary representation of the data digest is replaced bit by bit by the binary encoded sequence to generate a watermarked data digest.

[0044] Specifically, the process of uploading to the blockchain for evidence storage includes:

[0045] The encrypted data packet with time-series traceability watermark and the deviation coefficient are packaged together into a single transaction;

[0046] Invoke the blockchain smart contract to submit the transaction to the blockchain network;

[0047] After consensus is reached among the blockchain nodes, a new block containing the transaction is added to the chain to complete the notarization.

[0048] The intelligent marketing terminal power data communication security protection system includes: an electromagnetic feature sensing module, a status monitoring module, an identity embedding module, an access control module, and a blockchain evidence storage module;

[0049] The electromagnetic feature sensing module is used to establish an association with the encryption system by sensing the electromagnetic features of the terminal environment.

[0050] The status monitoring module is used to synchronize the terminal's operating status through the terminal twin mirror and predict the communication command sequence to monitor whether the terminal is operating abnormally.

[0051] The identity embedding module is used to perform privacy protection processing on power data and embed terminal identity information at the same time.

[0052] The access control module is used to encrypt the de-identified power data and verify access permissions based on the terminal identity.

[0053] The blockchain evidence storage module is used to add a time-tracking watermark to encrypted data and upload it to the blockchain.

[0054] Compared with the prior art, the beneficial effects of the present invention are:

[0055] 1. This invention proposes a smart marketing terminal power data communication security protection system, and optimizes and improves its architecture, operation steps and processes. The system has the advantages of simple process, low investment and operation costs and low production and working costs.

[0056] 2. This invention proposes a method for protecting the security of power data communication in intelligent marketing terminals. By constructing an encryption system association model through environmental electromagnetic sensing, the encryption parameters can be dynamically adapted to the electromagnetic environment, improving anti-interference and anti-attack capabilities. At the same time, relying on the terminal twin image and neural network to predict the communication command sequence, abnormal terminal operations can be accurately identified, and the risk of communication command tampering can be prevented in advance, thus providing dual protection for the security of terminal data transmission from the communication source and the operation process.

[0057] 3. This invention proposes a method for protecting the security of power data communication in intelligent marketing terminals. By classifying and desensitizing power privacy data and integrating it with terminal identifier hash fragments, it not only protects user privacy but also enables efficient verification of access permissions based on the identifier. Furthermore, by combining association model encryption, timestamp watermarking, and blockchain notarization, it achieves full-process traceability and immutability of power data from collection, processing to storage, thus balancing data security and management efficiency. Attached Figure Description

[0058] Figure 1This is a schematic diagram of the power data communication security protection method for the intelligent marketing terminal of the present invention;

[0059] Figure 2 This is a flowchart illustrating the principle of the intelligent marketing terminal power data communication security protection method of the present invention.

[0060] Figure 3 This is a diagram illustrating the architecture of the intelligent marketing terminal power data communication security protection system of the present invention. Detailed Implementation

[0061] Example 1:

[0062] Please see Figure 1 and Figure 2 The present invention provides an embodiment of a method for security protection of power data communication in intelligent marketing terminals, the method comprising S1 to S5, including the following steps:

[0063] S1: The terminal collects electromagnetic noise spectrum data through the built-in environmental electromagnetic sensing module, extracts electromagnetic feature factors, and constructs a correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography.

[0064] It should be noted that traditional smart marketing terminals often use elliptic curve cryptography with fixed complexity. Regardless of changes in the electromagnetic environment of the terminal, the encryption parameters remain unchanged. When the electromagnetic noise in the environment is strong, fixed low-complexity encryption is easily cracked by electromagnetic side-channel attacks, while fixed high-complexity encryption will cause the error rate to soar due to electromagnetic interference. When the electromagnetic noise in the environment is weak, fixed high-complexity encryption will waste the terminal's computing power and reduce data communication efficiency. This method establishes a dynamic matching mechanism between environmental electromagnetic conditions and encryption complexity. Specifically, it involves: real-time sensing of electromagnetic noise around the terminal, such as radiation from substation equipment and industrial interference signals, extracting electromagnetic feature factors that accurately reflect the severity of the electromagnetic environment; and then binding these electromagnetic feature factors with the complexity of elliptic curve cryptography, such as domain size, base order, and dot product algorithm, through an association model. This allows the terminal to autonomously adjust encryption parameters according to the real-time electromagnetic environment. For example, when electromagnetic noise is strong and the risk of side-channel attacks is high, the association model automatically selects a high-complexity encryption scheme to improve anti-attack capabilities; when electromagnetic noise is weak and communication efficiency requirements are high, the association model automatically selects a suitable medium-to-low complexity encryption scheme to balance security and efficiency. Traditional fixed encryption schemes cannot achieve this kind of environmental adaptive adjustment and cannot simultaneously meet the requirements of anti-interference, anti-attack, and high efficiency.

[0065] S2: Build a terminal twin image, based on a long short-term memory neural network, and combine the terminal operation status synchronized with the terminal twin image to predict the communication instruction sequence, and calculate the deviation coefficient between the actual communication instructions generated by the terminal and the predicted communication instruction sequence.

[0066] Furthermore, the terminal twin mirror continuously receives operation logs, system call sequences, and resource usage status from the physical terminal through a secure communication link to maintain synchronization.

[0067] It should be noted that once a smart marketing terminal is maliciously tampered with, such as by implanting malware or replacing the core chip, attackers may forge electricity data, such as artificially inflating electricity consumption or altering user electricity records, and generate false communication commands. Traditional security solutions can only verify the terminal's legitimacy through identity authentication and cannot identify the true nature of the terminal. Therefore, a real-time comparison mechanism between the physical terminal and its twin mirror image is crucial. This twin mirror image is not simply a copy of the terminal, but a digital substitute that synchronizes the terminal's system calls, process lists, and network connection status. Through learning from the terminal's historical communication commands using a long short-term memory neural network, it can accurately predict the commands the terminal should generate in specific business scenarios, such as when a user purchases electricity or uploads electricity data. When a physical terminal is tampered with, the actual command sequence it generates will deviate from the command sequence predicted by the terminal's twin mirror. By calculating the deviation coefficient, terminal anomalies can be identified immediately. For example, when a normal terminal uploads electricity data, the command sequence should be data reading, format verification, encryption, and sending. However, a tampered terminal may insert commands for data tampering or generating fake data. In this case, the deviation coefficient will exceed a preset threshold, and the system needs to immediately terminate the terminal's data transmission. Therefore, the anomaly detection function based on command prediction in this invention is something that traditional identity authentication schemes cannot achieve. It eliminates the risk of data forgery from the root of the problem and forms a security protection barrier for terminal operation.

[0068] S3: Based on the comparison result between the deviation coefficient and the preset threshold, determine whether the terminal behavior is abnormal;

[0069] Furthermore, if the deviation coefficient is lower than the preset warning threshold, the terminal behavior is determined to be normal, and the subsequent process is executed;

[0070] If the deviation coefficient is higher than the preset warning threshold but lower than the preset circuit breaker threshold, the terminal behavior is determined to be suspicious, and a security alarm log is generated and associated with the de-identified power data packet.

[0071] If the deviation coefficient is higher than the preset circuit breaker threshold, the terminal behavior is determined to be abnormal, the current communication process is terminated and the security isolation mechanism is triggered.

[0072] Furthermore, the warning threshold is used to trigger observation and marking, and the circuit breaker threshold is used to trigger interruption and isolation. The warning threshold and circuit breaker threshold are set based on a comprehensive engineering approach that combines historical behavior baseline analysis, statistical modeling, and business risk tolerance assessment.

[0073] S4: Classify and filter the power data collected by terminals that are determined to be normal, extract the privacy data, and then perform desensitization processing to obtain desensitized power data. Then, extract the hash fragment of the unique identifier of the terminal device as a reversible parsing factor, and use a preset embedding algorithm to integrate the reversible parsing factor into the desensitized power data to generate a desensitized power data packet containing the terminal identity identifier.

[0074] Furthermore, the classification and filtering of power data collected by terminals determined to be normal includes:

[0075] (1) A preset data classification rule base; the data classification rule base defines which data fields belong to user privacy data, equipment operation data and public measurement data;

[0076] (2) Match the raw power data stream collected by the terminal that is determined to be normal with the data classification rule library, and identify and filter out privacy data containing user identity, electricity consumption habits and precise geographical location information.

[0077] Furthermore, the extraction and de-identification of privacy-related data includes:

[0078] (1) De-identify the selected privacy-related data using hash encryption;

[0079] (2) The desensitized data is combined with the original non-privacy equipment operation data and public metering data to obtain desensitized power data.

[0080] It should be noted that the electricity data collected by smart marketing terminals contains a large amount of user privacy information, including but not limited to user names, addresses, and electricity usage habits. Traditional anonymization schemes, while protecting privacy, make it impossible to trace the terminal to which the anonymized data belongs. When data errors occur, it is difficult to determine which terminal collected the data, making accountability challenging. Furthermore, traditional schemes cannot prevent unauthorized terminals from accessing the anonymized data, posing a risk of secondary privacy leaks. This method, however, precisely identifies privacy-related data through classification and filtering, avoiding over-anonymization of non-privacy data, such as public grid voltage data, thus ensuring data usability. Secondly, the embedded reversible parsing factor is not a direct terminal ID, but a fragment processed by SM3 hashing. This avoids leakage of terminal identity information and allows for the reconstruction of the terminal identity through algorithms, solving the data ownership traceability problem. Finally, the anonymized data packet is bound to the terminal identity identifier, providing a basis for subsequent permission verification. Only terminals matching the identifier can access the data, preventing unauthorized terminals from obtaining the anonymized data. The irreplaceable nature of this design lies in the fact that it breaks the contradiction between privacy protection and data traceability. Traditional solutions may give up traceability to protect privacy or retain private information for traceability, while this method achieves a perfect balance between the two through the embedding of reversible parsing factors, and at the same time provides accurate identity basis for access control.

[0081] S5: Determine the encryption parameters based on the association model, use the encryption parameters to generate a data digest for the de-identified power data packet, and complete the access permission verification based on the terminal identity identifier in the de-identified power data packet;

[0082] Furthermore, the step of verifying access permissions based on the terminal identity identifier in the de-identified power data packet includes:

[0083] (1) The terminal’s unique hardware identifier is recovered from the reversible parsing factor embedded in the desensitized power data packet;

[0084] (2) Query the preset permission mapping table; the permission mapping table stores the data access permission levels corresponding to different terminal identifiers;

[0085] (3) Determine whether the permissions of the entity currently requesting access to the data packet match the data access permission level. If they match, the verification is successful. If they fail to match, the process is terminated and a security event is recorded.

[0086] It's important to note that once the encryption parameters of traditional smart marketing terminals are determined, they remain unchanged for a long period. Attackers can exploit vulnerabilities in these fixed encryption parameters to crack the system. Furthermore, traditional access control is often based on role-based authorization, such as granting administrators access to all data, leading to over-allocation of permissions. Even if an administrator doesn't need access to a particular terminal's data, they still have access rights, increasing the risk of data leakage. This method, however, establishes a dynamic encryption-precise authorization mechanism: First, the encryption parameters are not fixed but dynamically determined based on real-time electromagnetic characteristics using the association model built in the first step. For example, when the terminal is near a substation with strong electromagnetic noise, the model selects a 256-bit elliptic curve to generate high-strength encryption parameters; when the terminal is in a residential area with weak electromagnetic noise, a 192-bit elliptic curve is selected to generate suitable encryption parameters. This dynamic encryption prevents attackers from cracking the system using fixed parameters, improving encryption security. Second, access control is not based on roles but on the terminal's identity identifier in the de-identified power data packet. Only when the terminal's identifier matches the identifier in the data packet can the verification pass, achieving precise authorization that the terminal can only access the data it collects, avoiding the over-allocation of permissions inherent in traditional role-based authorization.

[0087] S6: Obtain the data collection timestamp corresponding to the desensitized power data packet after access permission verification and convert it into a binary encoding sequence. Embed the binary encoding sequence into the least significant bit of the data digest to generate an encrypted data packet with a time-tracing watermark and upload it to the blockchain for evidence storage.

[0088] Furthermore, the embedding process ensures that the overall length and encryption strength of the data digest are not altered.

[0089] The original privacy data is restored using a reversible parsing algorithm only if the identifier of the terminal device requesting access matches the hash fragment in the de-identified power data packet.

[0090] Furthermore, an encrypted data packet with a time-tracing watermark is generated, including:

[0091] (1) Re-associate and encapsulate the data digest with embedded timestamp watermark with the original desensitized power data packet;

[0092] (2) Generate the final encrypted data packet with time-tracking watermark that can be uploaded, wherein the data digest serves as an integrity verification and authentication credential, and the least significant bit of the digest contains the data generation time information.

[0093] Furthermore, before uploading to the blockchain, the encrypted data packets undergo integrity verification:

[0094] (1) Extracting the data digest from the encrypted data packet with the time-tracing watermark;

[0095] (2) Extract the binary encoded sequence embedded in the least significant bit of the data digest and restore it to a timestamp;

[0096] (3) Recalculate the data digest for the de-identified power data packet using the same encryption parameters and algorithm;

[0097] (4) Compare the newly calculated data digest with the original data digest that has been separated from the desensitized power data packet and has been embedded with watermark. If they are consistent within the allowable error range, the verification is successful.

[0098] Furthermore, before uploading to the blockchain, the encrypted data packet with the time-tracing watermark is lightly encrypted and encapsulated, and the encapsulation key is dynamically derived from the deviation coefficient and the reversible parsing factor.

[0099] Furthermore, the blockchain is a power data security storage platform based on a consortium blockchain architecture. Only authorized nodes can access the on-chain data, and the integrity and generation time of the data packets can be verified and traced using the data digest and embedded time watermark.

[0100] It should be noted that this method establishes a dual traceability and evidence storage mechanism of time-series watermarking and blockchain: First, time-series watermarking is not simply adding timestamps, but converting timestamps into binary encoded sequences and embedding them into the least significant bits of the data digest. The data digest corresponds one-to-one with the de-identified power data packet. If the data is tampered with, the data digest will change, and the watermark will also be damaged. By verifying the integrity of the watermark, it can be directly determined whether the data has been tampered with. Second, the encrypted data packet with watermark is uploaded to the blockchain. Utilizing the distributed ledger and consensus mechanism of the blockchain, tamper-proof data storage is achieved. Any node attempting to modify the data packet must tamper with the records of all nodes, which is extremely difficult. This achieves full-process protection of traceable data collection time, verifiable data integrity, and tamper-proof data storage, ensuring the security of power data throughout its entire lifecycle from collection to evidence storage.

[0101] The terminal collects electromagnetic noise spectrum data through its built-in environmental electromagnetic sensing module and extracts electromagnetic feature factors, including:

[0102] A1: The environmental electromagnetic sensing module monitors and collects the original electromagnetic signals in the preset frequency band in real time when the terminal performs elliptic curve cryptography.

[0103] It is important to understand that before performing elliptic curve cryptography, the main processor or dedicated security coprocessor inside the terminal device will send a precise synchronization trigger signal to the environmental electromagnetic sensing module. This synchronization trigger signal indicates that a cryptographic operation is about to begin and requires the environmental electromagnetic sensing module to enter the highest readiness state.

[0104] Furthermore, the core of the environmental electromagnetic sensing module is a highly miniaturized and highly sensitive electromagnetic induction probe. This probe is typically composed of a specially designed loop antenna or a magnetic field-effect transistor, and its physical characteristics are precisely calibrated to respond to extremely weak electromagnetic field changes within a specific spatial range.

[0105] Furthermore, the specific steps of A1 include:

[0106] (1) Upon receiving the synchronous trigger signal, the analog front-end circuit inside the environmental electromagnetic sensing module is immediately activated; the analog front-end circuit includes a low-noise amplifier and a programmable gain controller. Its primary task is to initially amplify the original analog electromagnetic signal captured by the probe, while suppressing the inherent thermal noise and shot noise of the circuit itself to ensure the fidelity of the signal.

[0107] (2) The original analog electromagnetic signal after preliminary amplification is sent to the anti-aliasing filter; the anti-aliasing filter is a sharp cutoff low-pass filter, whose cutoff frequency is strictly set according to the requirements of the sampling theorem. The core is to completely filter out all frequency components in the original analog electromagnetic signal that are higher than half of the preset sampling frequency. The working principle of the low-pass filter is the existing technology in this field and is not an inventive solution of this application. It will not be described in detail here.

[0108] Furthermore, in this invention, the amplified original analog electromagnetic signal is fed into an anti-aliasing filter to prevent these high-frequency components from being distorted during subsequent sampling, incorrectly mapped to the low-frequency band, causing confusion and distortion of the signal spectrum, thereby ensuring the authenticity and validity of the acquired data.

[0109] (3) After the analog signal passes through the anti-aliasing filter, it enters the analog-to-digital conversion stage. The analog-to-digital converter operates at a preset fixed sampling frequency to obtain the original digital signal sequence. The fixed sampling frequency is at least twice the highest frequency of the preset monitoring frequency band to satisfy the Nyquist sampling theorem.

[0110] Furthermore, the operation of an analog-to-digital converter is to instantaneously measure a continuous analog voltage signal at each equally spaced time point and convert it into a long series of discrete digital quantized values. Its accuracy is determined by the resolution of the analog-to-digital converter.

[0111] (4) The original digital signal sequence is sent to the digital down-conversion processing unit; the digital down-conversion processing unit consists of a digitally controlled oscillator and a digital filter;

[0112] Furthermore, the working steps of the digital down-conversion processing unit include: First, a digitally controlled oscillator generates a sine wave and a cosine wave digital reference signal with the same center frequency as the preset frequency band; then, the original digital signal sequence is multiplied by these two reference signals respectively. This process is equivalent to shifting the entire spectrum in the frequency domain, moving the center frequency of the preset frequency band to near zero frequency; finally, a high-performance low-pass digital filter is used to retain only the low-frequency component located near zero frequency after the shift. This low-frequency component corresponds to the preset frequency band in the original digital signal, and the output of the filter is called the baseband signal.

[0113] (5) Output multiple frames of preprocessed and frequency band filtered original electromagnetic signal digital samples.

[0114] A2: The original electromagnetic signal is preprocessed to obtain digitized electromagnetic noise spectrum data;

[0115] Furthermore, preprocessing includes signal amplification, filtering, and analog-to-digital conversion.

[0116] A3: Perform a Fast Fourier Transform on the digitized electromagnetic noise spectrum data to convert it from the time domain to the frequency domain to obtain the noise spectrum. The Fast Fourier Transform is a prior art in this field and is not an inventive solution of this application, so it will not be described in detail here.

[0117] A4: Extract the electromagnetic characteristic factors from the noise spectrum; the electromagnetic characteristic factors include noise amplitude, spectral distribution shape, and dynamic change rate; the noise amplitude is the signal strength value of a preset frequency point or band in the noise spectrum; the spectral distribution shape is determined by quantizing the skewness, kurtosis, and energy entropy of the spectrum; the dynamic change rate is the difference in spectral energy between adjacent sampling cycles.

[0118] The construction of the correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography includes:

[0119] B1: Establish a multi-dimensional feature vector, using the electromagnetic feature factors as vector elements;

[0120] B2: Deploy multiple elliptic curve cryptosystems with different complexities on the terminal; the complexity is determined by the field size, base order, and dot product algorithm of the selected elliptic curve.

[0121] Furthermore, before executing B2, the terminal needs to pre-integrate a set of cryptographic parameters that has undergone rigorous testing and verification. This set of cryptographic parameters contains multiple different elliptic curve domain names and all their corresponding parameters, and the parameters must come from international cryptographic standards.

[0122] Furthermore, complexity is a comprehensive evaluation metric determined by three core dimensions: the first dimension is algorithmic complexity, directly determined by the size of the selected elliptic curve domain, with the domain size (number of bits) being the most intuitive metric; the second dimension is computational complexity, reflected in the actual computation time and processor resources consumed to perform a complete cryptographic operation, such as digital signature generation or verification, which needs to be obtained through actual measurement; the third dimension is error rate complexity, referring to the probability of computational errors occurring during algorithm operation under severe electromagnetic noise interference; these three dimensions together constitute a three-dimensional model for evaluating the complexity of a cryptographic system.

[0123] Furthermore, the process of deploying various elliptic curve cryptosystems of different complexities on the terminal includes:

[0124] (1) Construct a pre-defined elliptic curve cryptography parameter library;

[0125] (2) Define and quantify the complexity index of cryptographic systems;

[0126] (3) Establish a test benchmark and performance acquisition environment, specifically including: developing an automated test framework, which sequentially loads each set of curve configurations in the preset elliptic curve cryptography parameter library; for each set of curve configurations, the test framework will simulate real business scenarios, generate test data samples, and drive the cryptographic coprocessor to perform tens of thousands of cryptographic operations, such as repeatedly signing and verifying data; during this process, the test framework uses the terminal's performance counter and high-precision timer to closely monitor and record the precise time consumed by each operation, the CPU occupancy rate, and the frequency of memory access, etc.

[0127] (4) Perform data analysis and associate complexity labels, including: For each set of curve configurations, the system aggregates and analyzes all test run results, calculates the average and variance of all operation run times to measure its computational efficiency and stability, and counts the number of verification errors that occur in all test runs to calculate the error rate. Finally, according to the preset rules, the quantitative results of these three dimensions are weighted and combined to assign a final, single complexity level label to each set of curve configurations. For example, a 256-bit curve with high efficiency and low error rate under low noise may be labeled as standard complexity; while a 5.21 million-bit curve is labeled as high complexity due to its huge computational load and potentially higher error rate.

[0128] (5) Once the elliptic curve cryptography parameter library is complete and the complexity of all configurations has been calibrated, a dynamic selection interface is created. This dynamic selection interface provides a unified function caller. The core input parameter of the function call is the recommended complexity level calculated by the association model, which represents the severity of the current environment. When this interface is called, its internal logic will quickly search and select all curve configuration sets that match this level and have the same label in the parameter library based on the input recommended complexity level. If there are multiple matching configurations, a round-robin method can be used to finally determine a curve and its matching algorithm. Once selected, the interface will load all parameters of the configuration and initialize the corresponding cryptographic algorithm engine, so that it enters the ready state and is ready to perform actual data encryption or signing tasks.

[0129] B3: Perform various elliptic curve cryptography operations under different environmental electromagnetic noise conditions, and record their operation time, power consumption and error rate as complexity response indicators. Elliptic curve cryptography operations, also known as elliptic curve cryptography systems, are existing technologies in this field and are not the inventive solution of this application, so they will not be described in detail here.

[0130] B4: Using a machine learning regression algorithm, with the multidimensional feature vector as input and the complexity response index as output, a correlation model is trained to obtain the correlation model; the correlation model predicts the optimal encryption complexity level in the current environment based on the electromagnetic feature factors extracted in real time. The machine learning regression algorithm is existing technology in this field and is not an inventive solution of this application, so it will not be described in detail here.

[0131] The construction of the terminal twin mirror, based on a long short-term memory neural network, combines the terminal's operating state synchronized with the terminal twin mirror to predict the communication command sequence, and calculates the deviation coefficient between the actual communication commands generated by the terminal and the predicted communication command sequence, including:

[0132] S2.1: Construct a terminal twin image that corresponds one-to-one with the physical terminal at a local or edge security node; the twin image synchronizes with the running operation status by receiving the terminal's system calls, process list, and network connection status information;

[0133] Furthermore, before building a terminal twin image, the physical terminal must first be uniquely identified and registered on the edge security node by generating a unique terminal asset fingerprint.

[0134] Furthermore, a terminal twin image corresponding one-to-one with the physical terminal is constructed on a local or edge security node, including:

[0135] (1) Start the agent program on the physical terminal and collect its multi-dimensional and tamper-proof hardware and software inherent information, including hardware identifier, software identifier and environment configuration. Among them, the hardware identifier includes the central processing unit serial number, motherboard serial number, network card media access control address and hard disk serial number; the software identifier includes the operating system installation identifier, firmware version number and pre-installed security certificate identifier; and the environment configuration includes the list of installed applications and their versions and the hash value of key configuration files.

[0136] (2) The agent program uses the SHA-256 algorithm to standardize and calculate the collected hardware and software inherent information to generate a hash value, i.e., the terminal asset fingerprint;

[0137] (3) The terminal asset fingerprint, along with the terminal's basic model and the organization's metadata, is sent to a designated local or edge security node for registration via a certificate-based two-way authentication channel. The local or edge security node then stores the terminal asset fingerprint in a trusted terminal asset database, thereby completing the initial trust establishment of the terminal's identity.

[0138] (4) After receiving the registration information, the edge security node initializes a corresponding twin image for the physical terminal, including template selection, image instantiation, and injection of identity identifier;

[0139] Template selection: Based on the metadata reported by the physical terminal, select the most matching base template from the pre-set image template library. This base template is a clean, minimal virtual machine or container image that contains the common operating system and basic software environment for this type of terminal.

[0140] Image instantiation: Based on the selected base template, a new virtual machine or container instance is created to obtain an image instance;

[0141] Injecting Identity: The terminal asset fingerprint generated in the first step is used as the unique identifier of the image instance and written into its internal configuration file to generate a newly created twin image instance;

[0142] (5) Deploy the same agent program as on the physical terminal to the newly created twin image instance;

[0143] (6) Configure the agent program, informing it of the network address of the corresponding physical terminal and the credentials required to establish a secure connection, such as using a key derived from the terminal asset fingerprint;

[0144] (7) The agent program on the physical terminal actively establishes a secure communication link with the agent program in the twin mirror instance on the edge security node. It is usually encrypted using the transport layer security protocol and performs two-way authentication based on the certificate registered in the first step.

[0145] (8) After the connection is established, the physical terminal agent sends a complete snapshot of the current system state to the mirror agent. This includes:

[0146] Process list: Information on all currently running processes;

[0147] System service status: The activation and running status of all services;

[0148] Network connection status: All active network connections;

[0149] User session information: The currently logged-in user;

[0150] Critical system configuration: Latest system configuration and policies;

[0151] (9) The mirror agent receives the complete state of the current system and completely resets the internal state of the mirror to keep it consistent with the physical terminal, thus obtaining a synchronized terminal twin mirror.

[0152] S2.2: The terminal's historical communication instruction sequence under a preset business scenario is trained using a long short-term memory neural network to generate a prediction model. The long short-term memory neural network is existing technology in this field and is not an inventive solution of this application, so it will not be described in detail here.

[0153] S2.3: When communication occurs, the prediction model is executed by the terminal twin mirror, and the predicted communication instruction sequence is output;

[0154] Furthermore, based on long short-term memory neural networks, the prediction of communication instruction sequences specifically includes:

[0155] (1) Collect the historical communication instruction sequences obtained by synchronizing the terminal twin mirror to form a training dataset;

[0156] (2) The long short-term memory neural network is trained by supervised learning with the first A instructions in the historical communication instruction sequence as input and the subsequent B instructions as output. The long short-term memory neural network is the prior art in this field and is not an inventive solution of this application. It will not be described in detail here.

[0157] (3) Using a trained long short-term memory neural network, with the current and historical communication instructions of the terminal as input, predict the most likely sequence of communication instructions to be generated in the next cycle.

[0158] S2.4: Compare the actual communication commands generated by the terminal with the predicted communication command sequence to obtain the deviation coefficient.

[0159] Furthermore, acquiring the actual communication commands generated by the terminal involves establishing a transparent data monitoring and analysis pipeline within the terminal. This is equivalent to deploying a data acquisition agent at the terminal's operating system level, or like setting up a high-definition camera at all network exits. Whenever any software on the terminal wants to send data over the network, this acquisition agent instantly intercepts a copy of the raw data, recording which program sent the data, when, and how. Then, according to communication protocols, such as MQTT commonly used in the power industry, the raw data is parsed to decipher its true intent. For example, it identifies whether it is a command to report voltage readings or a command to respond to a device query. After parsing, these parsed commands are arranged in chronological order, forming a complete and ordered sequence of actual commands.

[0160] Furthermore, the specific steps in S2.4 include:

[0161] (1) Align and compare the actual communication instruction sequence generated by the terminal with the predicted communication instruction sequence;

[0162] (2) The cosine similarity algorithm is used to calculate the difference between the two sequences. The cosine similarity algorithm is the prior art in this field and is not an inventive solution of this application. It will not be described in detail here.

[0163] (3) Map the difference to the [0,1] interval to obtain the deviation coefficient. The closer the deviation coefficient is to 1, the greater the deviation and the higher the possibility of abnormal terminal behavior.

[0164] The hash fragment of the extracted terminal device's unique identifier is used as a reversible parsing factor. A preset embedding algorithm is used to integrate the reversible parsing factor into the de-identified power data, including:

[0165] S4.1: Obtain the terminal's unique hardware identifier;

[0166] S4.2: The hardware unique identifier is calculated using the SM3 hash algorithm to obtain a hash digest. The SM3 hash algorithm is prior art in this field and is not an inventive solution of this application, so it will not be described in detail here.

[0167] S4.3: Extract the first N bits of the hash digest to generate a hash fragment, and use it as a reversible parsing factor;

[0168] S4.4: Convert the reversible parse factor into a binary stream;

[0169] S4.5: Select the reserved or extended bits of a specific field in the desensitized power data packet as the embedding area;

[0170] S4.6: The binary stream is embedded into the embedding region using the least significant bit substitution algorithm to generate the desensitized power data packet containing the terminal identity identifier. The least significant bit substitution algorithm is existing technology in this field and is not an inventive solution of this application, so it will not be described in detail here.

[0171] The step of determining encryption parameters based on the association model and using the encryption parameters to generate a data digest for the de-identified power data packet includes:

[0172] S5.1: Input the electromagnetic feature factors extracted in real time into the correlation model;

[0173] S5.2: Obtain the encryption parameters of the elliptic curve cryptosystem output by the correlation model that match the complexity of the current electromagnetic environment; the encryption parameters include elliptic curve type, domain parameters, and key length;

[0174] S5.3: Use the elliptic curve digital signature algorithm determined by the encryption parameters to perform digital signature operation on the de-identified power data packet containing the terminal identity identifier, and generate a digital signature value as the data digest.

[0175] Furthermore, the specific steps in S5.3 include:

[0176] (1) Obtain the encryption parameters and initialize the password environment;

[0177] (2) Retrieve the terminal's static private key. After authentication, the terminal's private key is decrypted from secure non-volatile memory and loaded into the secure memory area of ​​the cryptographic operation module. The private key is a very large secret integer that is randomly generated within a range determined by the order of the base points of the elliptic curve defined by the encryption parameters and paired with a public key.

[0178] (3) Obtain the de-identified power data packet containing the terminal identity identifier, calculate the hash value of the de-identified power data packet using the SM3 hash algorithm, and obtain the message digest;

[0179] (4) Generate a high cryptographically strong random number, and then perform elliptic curve dot product operation, including: multiplying the common base point on the elliptic curve with this random number, the result of the dot product is the coordinate of another point on the elliptic curve, taking the x-coordinate value of the result point and performing a modulo operation on it with the order of the base point of the elliptic curve as the modulus, and finally obtaining a value, namely the commitment value.

[0180] (5) Multiply the terminal private key with the generated commitment value to obtain the first intermediate product. At the same time, multiply the random number with the message digest to obtain the second intermediate product. Then, add the message digest with the first intermediate product to obtain the first sum. Subtract the first sum from the value of the second intermediate product to obtain the final result. Calculate the modular inverse operation modulo the order of the elliptic curve base point on the final result to obtain the proof value.

[0181] (6) The commitment value and the proof value are connected in sequence and combined into a complete digital signature value, i.e., the data digest.

[0182] The process of obtaining the data acquisition timestamp corresponding to the de-identified power data packet after access permission verification and converting it into a binary encoded sequence, and embedding the least significant bit of the binary encoded sequence into the data digest, includes:

[0183] C1: Extract the data acquisition timestamp from the metadata of the de-identified power data packet;

[0184] C2: Convert the data acquisition timestamps in UTC time format into a continuous binary sequence, i.e., a binary encoded sequence;

[0185] C3: Obtain the binary representation of the data digest;

[0186] C4: Replace the original data in the least significant bit of the binary representation of the data digest with the binary encoded sequence bit by bit to generate a watermarked data digest.

[0187] The process of uploading to the blockchain for evidence storage includes:

[0188] D1: Package the encrypted data packet with the time-tracking watermark and the deviation coefficient together into a transaction;

[0189] D2: Invoke the blockchain smart contract to submit the transaction to the blockchain network;

[0190] D3: After consensus is reached among the blockchain nodes, a new block containing the transaction is added to the chain to complete the notarization.

[0191] Furthermore, when the blockchain smart contract is invoked, it executes:

[0192] (1) Read the terminal identity identifier and time-series watermark from the evidence storage data;

[0193] (2) Verify whether the terminal's identity is that of a legitimate member of the consortium blockchain;

[0194] (3) Cross-validate the timestamp with the block time on the blockchain to ensure the authenticity of the data collection time;

[0195] (4) Compare the deviation coefficient with a preset threshold. If the deviation coefficient exceeds the threshold, an abnormal terminal behavior alarm event is automatically generated and recorded on the blockchain.

[0196] Example 2:

[0197] Please see Figure 3 Another embodiment of the present invention provides: a smart marketing terminal power data communication security protection system, comprising:

[0198] Electromagnetic feature sensing module, status monitoring module, identity embedding module, access control module, and blockchain evidence storage module;

[0199] The electromagnetic feature sensing module is used to establish a connection with the encryption system by sensing the electromagnetic features of the terminal environment.

[0200] The status monitoring module is used to synchronize the terminal's operating status through the terminal twin mirror and predict the communication command sequence, monitor whether the terminal is operating abnormally, and ensure the security of the data collection source.

[0201] The identity embedding module is used to perform privacy protection processing on power data, and at the same time embeds terminal identity information to provide a basis for access control.

[0202] The access control module is used to encrypt the de-identified power data and verify access permissions based on the terminal identity to ensure data transmission and access security.

[0203] The blockchain evidence storage module is used to add time-tracing watermarks to encrypted data and upload it to the blockchain, realizing traceability and tamper-proof evidence storage throughout the entire data lifecycle.

[0204] The electromagnetic feature sensing module includes: an electromagnetic noise acquisition unit, a feature extraction unit, and an encrypted correlation modeling unit;

[0205] The electromagnetic noise acquisition unit is used to acquire electromagnetic noise spectrum data in the terminal's operating environment in real time, relying on the terminal's built-in environmental electromagnetic sensing module.

[0206] The feature extraction unit is used to extract electromagnetic feature factors, including noise amplitude, spectral distribution pattern and dynamic change rate, from the collected electromagnetic noise spectrum data.

[0207] The encryption correlation modeling unit is used to construct a correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography, enabling the dynamic determination of encryption parameters based on real-time electromagnetic features.

[0208] The status monitoring module includes: a twin image construction unit, a communication command prediction unit, and an anomaly detection unit;

[0209] The twin image building unit, through the construction of a terminal twin image, synchronizes the terminal's operating status in real time, including hardware load, software processes, and communication behavior.

[0210] The communication instruction prediction unit is used to predict the sequence of communication instructions that the terminal will generate based on a long short-term memory neural network and combined with the terminal state data synchronized by twin mirrors.

[0211] The anomaly determination unit is used to calculate the deviation coefficient between the actual communication command generated by the terminal and the predicted communication command sequence. When the deviation coefficient exceeds a preset threshold, the terminal is determined to be abnormal and an early warning is triggered.

[0212] The identity embedding module includes: a classification and filtering unit, a privacy data desensitization unit, a factor generation unit, and an identity embedding unit;

[0213] The classification and filtering unit is used to classify the raw power data collected by the terminal and filter out user privacy data, including electricity consumption details and personal identity-related data.

[0214] The privacy data desensitization unit is used to desensitize selected privacy-related data, such as anonymization and data transformation, to generate desensitized electricity data and prevent privacy leaks.

[0215] The factor generation unit is used to extract the hash fragment of the unique identifier of the terminal device as a reversible parsing factor. The unique identifier of the terminal device includes the hardware serial number and the device code.

[0216] The identity embedding unit is used to incorporate reversible parsing factors into desensitized power data using a preset embedding algorithm, thereby generating a desensitized power data packet containing the terminal identity identifier.

[0217] The access control module includes: an encryption parameter determination unit, a data digest generation unit, and an access verification unit;

[0218] The encryption parameter determination unit determines the encryption parameters of the elliptic curve cryptosystem by calling the association model generated by the electromagnetic feature sensing and encryption parameter association module and combining it with the current electromagnetic feature factors.

[0219] The data digest generation unit performs encryption operations on the de-identified power data packets using determined encryption parameters to generate a unique corresponding data digest.

[0220] The permission verification unit is used to verify whether the permissions of the access subject match based on the terminal identity identifier embedded in the de-identified power data packet.

[0221] The blockchain evidence storage module includes: a timestamp encoding unit, a traceability watermark embedding unit, and a blockchain evidence storage unit;

[0222] The timestamp encoding unit is used to obtain the data acquisition timestamp corresponding to the de-identified power data packet that has been verified by the authorization, and convert it into a binary encoding sequence.

[0223] The source watermark embedding unit is used to embed the least significant bit of the binary encoded sequence into the data digest to generate an encrypted data packet with a time-series source watermark.

[0224] The blockchain evidence storage unit is used to upload encrypted data packets with time-tracing watermarks to the blockchain, utilizing the distributed ledger and immutability characteristics of the blockchain to achieve secure data storage and full-process traceability.

[0225] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments under the guidance of the present invention without departing from the spirit and scope of the present invention. All of these variations are within the protection scope of the present invention.

[0226] If the technical solution disclosed herein involves personal information, the product using this technical solution has clearly informed the user of the personal information processing rules and obtained the user's voluntary consent before processing the personal information. If the technical solution disclosed herein involves sensitive personal information, the product using this technical solution has obtained the user's separate consent before processing the sensitive personal information, and also meets the requirement of "express consent". For example, at personal information collection devices such as cameras, clear and prominent signs are set up to inform users that they have entered the scope of personal information collection and that personal information will be collected. If an individual voluntarily enters the collection scope, it is deemed that they have agreed to the collection of their personal information; or on the personal information processing device, with clear signs / information informing users of the personal information processing rules, authorization is obtained from the individual through pop-up information or by asking the individual to upload their personal information; wherein, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.

Claims

1. A method for protecting the security of power data communication in intelligent marketing terminals, characterized in that, include: The terminal collects electromagnetic noise spectrum data through its built-in environmental electromagnetic sensing module, extracts electromagnetic feature factors, and constructs a correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography. A terminal twin image is constructed. Based on a long short-term memory neural network, the terminal operation status synchronized with the terminal twin image is used to predict the communication instruction sequence. The deviation coefficient between the actual communication instructions generated by the terminal and the predicted communication instruction sequence is calculated. Based on the comparison result between the deviation coefficient and the preset threshold, it is determined whether the terminal behavior is abnormal; The power data collected by terminals that are deemed to be normal is classified and filtered. Privacy-related data is extracted and desensitized to obtain desensitized power data. The hash fragment of the unique identifier of the terminal device is then extracted as a reversible parsing factor. A preset embedding algorithm is used to integrate the reversible parsing factor into the desensitized power data to generate a desensitized power data package containing the terminal's identity identifier. The encryption parameters are determined based on the association model. The encryption parameters are used to generate a data digest for the de-identified power data packet. Access permission verification is completed based on the terminal identity identifier in the de-identified power data packet. Obtain the data collection timestamp corresponding to the desensitized power data packet after access permission verification and convert it into a binary encoding sequence. Embed the binary encoding sequence into the least significant bit of the data digest to generate an encrypted data packet with a time-tracing watermark and upload it to the blockchain for evidence storage.

2. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 1, characterized in that, The original privacy data is restored using a reversible parsing algorithm only if the identifier of the terminal device requesting access matches a hash fragment in the de-identified power data packet.

3. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 2, characterized in that, The terminal collects electromagnetic noise spectrum data through its built-in environmental electromagnetic sensing module and extracts electromagnetic feature factors, including: The environmental electromagnetic sensing module monitors and collects the original electromagnetic signals in the preset frequency band in real time when the terminal performs elliptic curve cryptography. The original electromagnetic signal is preprocessed to obtain digitized electromagnetic noise spectrum data; The digitized electromagnetic noise spectrum data is subjected to a fast Fourier transform to convert it from the time domain to the frequency domain, thus obtaining the noise spectrum. The electromagnetic characteristic factors are extracted from the noise spectrum; the electromagnetic characteristic factors include noise amplitude, spectral distribution shape, and dynamic change rate; the noise amplitude is the signal strength value of a preset frequency point or frequency band in the noise spectrum; the spectral distribution shape is determined by quantizing the skewness, kurtosis, and energy entropy of the spectrum; the dynamic change rate is the difference in spectral energy between adjacent sampling cycles.

4. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 3, characterized in that, The construction of the correlation model between electromagnetic feature factors and the complexity of elliptic curve cryptography includes: Establish a multidimensional feature vector, using the electromagnetic feature factors as vector elements; Multiple elliptic curve cryptosystems with different complexities are deployed on the terminal; the complexity is determined by the field size, base order, and dot product algorithm of the selected elliptic curve. Under different electromagnetic noise environments, perform various elliptic curve cryptography operations and record their operation time, power consumption, and error rate as complexity response indicators; Using a machine learning regression algorithm, with the multidimensional feature vector as input and the complexity response index as output, an association model is trained to obtain an association model; the association model predicts the optimal encryption complexity level in the current environment based on the electromagnetic feature factors extracted in real time.

5. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 4, characterized in that, The construction of the terminal twin mirror, based on a long short-term memory neural network, combines the terminal's operating state synchronized with the terminal twin mirror to predict the communication command sequence, and calculates the deviation coefficient between the actual communication commands generated by the terminal and the predicted communication command sequence, including: A terminal twin image corresponding one-to-one with the physical terminal is constructed on a local or edge security node; the twin image is synchronized with the running operation status by receiving the terminal's system calls, process list and network connection status information; A prediction model is generated by training the terminal's historical communication command sequences under preset business scenarios using a long short-term memory neural network. When communication occurs, the prediction model is executed by the terminal twin mirror, and the predicted sequence of communication instructions is output. The actual communication commands generated by the terminal are compared with the predicted communication command sequence to obtain the deviation coefficient.

6. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 5, characterized in that, The hash fragment of the extracted terminal device's unique identifier is used as a reversible parsing factor. A preset embedding algorithm is used to integrate the reversible parsing factor into the de-identified power data, including: Obtain the terminal's unique hardware identifier; The SM3 hash algorithm is used to calculate the hash digest of the hardware unique identifier. Extract the first N bits of the hash digest to generate a hash fragment, and use it as a reversible parsing factor; Convert the reversible parsing factor into a binary stream; Select the reserved or extended bits of the fields in the desensitized power data packet as the embedding area; The binary stream is embedded into the embedding region using the least significant bit substitution algorithm to generate the desensitized power data packet containing the terminal identity identifier.

7. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 6, characterized in that, The step of determining encryption parameters based on the association model and using the encryption parameters to generate a data digest for the de-identified power data packet includes: The electromagnetic feature factors extracted in real time are input into the correlation model; Obtain the encryption parameters of the elliptic curve cryptosystem output by the correlation model that match the complexity of the current electromagnetic environment; the encryption parameters include elliptic curve type, domain parameters, and key length; The de-identified power data packet containing the terminal identity is digitally signed using an elliptic curve digital signature algorithm determined by the encryption parameters, and a digital signature value is generated as the data digest.

8. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 7, characterized in that, The process of obtaining the data acquisition timestamp corresponding to the de-identified power data packet after access permission verification and converting it into a binary encoded sequence, and embedding the least significant bit of the binary encoded sequence into the data digest, includes: Extract the data acquisition timestamp from the metadata of the de-identified power data packet; Convert the data acquisition timestamps in UTC time format into binary encoded sequences; Obtain the binary representation of the data digest; The original data in the least significant bit of the binary representation of the data digest is replaced bit by bit by the binary encoded sequence to generate a watermarked data digest.

9. The method for protecting the security of power data communication in intelligent marketing terminals as described in claim 8, characterized in that, The process of uploading to the blockchain for evidence storage includes: The encrypted data packet with time-series traceability watermark and the deviation coefficient are packaged together into a single transaction; Invoke the blockchain smart contract to submit the transaction to the blockchain network; After consensus is reached among the blockchain nodes, a new block containing the transaction is added to the chain to complete the notarization.

10. A smart marketing terminal power data communication security protection system, used to implement the smart marketing terminal power data communication security protection method according to any one of claims 1-9, characterized in that, include: Electromagnetic feature sensing module, status monitoring module, identity embedding module, access control module, and blockchain evidence storage module; The electromagnetic feature sensing module is used to establish an association with the encryption system by sensing the electromagnetic features of the terminal environment. The status monitoring module is used to synchronize the terminal's operating status through the terminal twin mirror and predict the communication command sequence to monitor whether the terminal is operating abnormally. The identity embedding module is used to perform privacy protection processing on power data and embed terminal identity information at the same time. The access control module is used to encrypt the de-identified power data and verify access permissions based on the terminal identity. The blockchain evidence storage module is used to add a time-tracking watermark to encrypted data and upload it to the blockchain.

Citation Information

Patent Citations

  • Medical examination data sharing method and system based on cloud authentication

    CN120281560A

  • Intelligent supervision management and control method and system

    CN120374065A

  • Data security protection method for digital twin system of logistics transfer field

    CN120378096A

  • Construction dynamic twinning method based on Internet of Things and BIM

    CN120509312A

  • Data circulation trusted system and device based on block chain and privacy calculation

    CN120541870A

Cited By

  • Electricity utilization information acquisition terminal with multi-layer security isolation

    CN121309228A

  • Power information protection method and system based on communication security

    CN122001657A