An Efficient Privacy-Preserving Aggregation and Access Control Method for Power Grid Data

Through the smart terminal generating a key sequence and encrypting the grid data, combining cloud server storage and fine-grained access control, the existing grid privacy protection aggregation solution solves the delay problem of the existing grid privacy protection aggregation solution when dealing with high throughput read and write, realizes low-time latency query and high throughput read and write, and ensures secure sharing and privacy protection of data.

CN112668039BActive Publication Date: 2025-05-30STATE GRID INFO TELECOM GREAT POWER SCI & TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011456313.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-11
Publication Date
2025-05-30
Estimated Expiration
2040-12-11

AI Technical Summary

Technical Problem

The existing power grid privacy protection aggregation solution has a large processing delay when handling high-throughput read and write, and it is difficult to meet the needs of low-latency transmission. At the same time, in terms of data user identity security, privacy protection is weak and causes calculation and communication losses.

Method used

The intelligent terminal uses a pseudo-random number generator and master key to generate a key sequence, divides the data into independent data blocks and encrypts it, stores it on a cloud server, and realizes the authentication and permission management of data users through fine-grained access control, supporting low-time latency query and high-throughput read and write.

Benefits of technology

It realizes low-delay query and high-throughput reading and writing of power grid data, reduces dependence on cloud servers, and realizes secure sharing and privacy protection of power grid data through fine-grained data access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112668039B_ABST
    Figure CN112668039B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for efficient aggregation and access control of power grid data privacy protection. By generating all n key sequences required within a fixed time period, dividing the data generated within this time period into n independent data blocks according to time segments, calculating the data aggregation summary of each database, encrypting all data blocks within the time period with keys to generate encrypted files, and then sending the encrypted files to the cloud server for storage. Subsequently, according to the request of data users, obtain the ciphertext according to the access permission, and perform an aggregation decryption operation on the ciphertext with the key set issued by the intelligent terminal to obtain the plaintext aggregation result of the power grid data. The present invention can support low-latency queries for power grid data with huge volume, fast generation speed, and low value density. It makes full use of the computing power of edge intelligent terminals, reduces the dependence on cloud servers, and realizes the secure sharing of power grid data through fine-grained data access control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for accessing power grid data, in particular to a method for efficient aggregation and access control of privacy protection of power grid data. Background Art

[0002] With the development of modern science and technology and the acceleration of the process of urbanization construction, the smart grid has emerged and is about to replace the traditional power grid. The smart grid aims to combine the traditional power grid, the Internet of Things and information technology to encourage power grid users to actively manage their daily power usage and provide the necessary reference information for the power grid planning and regulation of the power department. At present, due to the continuous development of the smart grid and the Internet of Things system, the number of power users is showing a continuous high-speed growth, and the types and amounts of various power grid data are also increasing. The explosive growth of power grid data has made the efficient aggregation and access of power grid data a research hotspot in the academic and industrial fields. There are many information systems in the smart grid, and a large amount of data is collected every day. These data are large in volume and wide in source. Although the value density is low, through big data technology analysis, various data can be obtained for power supply business planning, operation, maintenance, etc. At the same time, due to the requirement of real-time performance, it is hoped that a quick response can be made, so as to be used to improve various decisions. In addition, smart electricity meters, smart terminals, etc. will regularly send the collected data to the control center, and these data contain a large amount of user sensitive information and privacy data. Once used by malicious attackers, very serious consequences will be caused.

[0003] The privacy protection data of the smart grid needs to ensure that the user's power consumption data is transmitted to the data control center quickly and effectively and is available for data analysis by other relevant third-party institutions. This process needs to prevent lawbreakers from stealing the user's power consumption data, protect the user's privacy data and ensure the normal operation of the power grid supply. In order to resist the threat of user privacy leakage, the privacy protection research of the smart grid usually focuses on solving two security hazards: the security hazard of power grid data and the identity security hazard of data users. Data security needs to ensure the confidentiality and integrity of data and avoid situations such as data loss or leakage. Even if a malicious attacker obtains the data ciphertext of the data control center, it is impossible to decrypt and obtain the actual power consumption data of the user. Identity security needs to consider the access control problem of data users in the smart grid.

[0004] To ensure the security of power grid data, cryptography technology, as the main tool for privacy-preserving data aggregation solutions, has received extensive attention. However, most current power grid privacy-preserving aggregation solutions adopt asymmetric homomorphic encryption algorithms, such as Paillier homomorphic encryption, resulting in relatively large processing delays and being difficult to meet the requirements of high-throughput reading and writing. In terms of the identity security of data users, some privacy-preserving methods have also emerged, such as signature authentication schemes based on hash message authentication codes and identity authentication protocols based on zero-knowledge proofs. However, these schemes have relatively weak privacy protection effects and cause a certain degree of computational and communication losses. Traditional smart grid models usually use gateways to collect and aggregate data, but it is difficult to meet the storage and computational requirements of large-scale data. Therefore, the cloud computing model is considered an effective way to solve this problem. However, most cloud computing models adopt centralized data processing methods, making the computing resources of edge devices not effectively utilized. And with the continuous growth of the data scale, the bandwidth resources of cloud computing will be difficult to meet the requirements of low-latency transmission. For this reason, the edge computing model extends the computing from the network center to the network edge, fully exploiting the computing capabilities of edge devices and providing sufficient support for the efficient collection, transmission, and processing of big data. Edge-aggregated data is sufficient to provide differentiated data services for users. Summary of the Invention

[0005] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a method for privacy-preserving and efficient aggregation and access control of power grid data that can further reduce the query latency of data aggregation, increase the throughput of data aggregation, and simultaneously achieve access control at different granularities for data users.

[0006] A method for privacy-preserving and efficient aggregation and access control of power grid data, step 1: The intelligent terminal uses a pseudo-random number generator and a master key to generate all n + 1 key sequences k required within a fixed time period 1 ,…,k n+1 ;

[0007] Step 2: The intelligent terminal divides the data generated within this time period into n independent data blocks according to time segments and calculates the data aggregation digest m of each database 1 ,…,m n , where the plaintext space is [0, M - 1];

[0008] Step 3: The intelligent terminal uses the key sequences k 1 ,…,m n to encrypt the data blocks m generated within this time period 1 ,…,k n+1 to generate ciphertexts c 1 ,…,c n ;

[0009] Step 4: The intelligent terminal sends all the ciphertext data blocks c within this time period 1 ,…,c n to the cloud server for storage;

[0010] Step 5: The data user requests data access permission from the intelligent terminal. The data terminal generates a corresponding key set K according to the identity of the data user and the data request, and sends it to the data user;

[0011] Step 6: The data user obtains the ciphertext through the cloud server, and performs an aggregation decryption operation on the ciphertext using the key set K issued by the intelligent terminal to obtain the plaintext aggregation result of the power grid data.

[0012] Calculate the data aggregation summary of each database, either by summing or by averaging.

[0013] The specific steps of Step 1 are as follows:

[0014] Step 1.1: The intelligent terminal randomly selects a master key mk and secretly stores mk;

[0015] Step 1.2: The intelligent terminal constructs a hierarchical key generation tree. The number of levels h of this structure is rounded up to log(n + 1), where G 0 (x) = H(x||00) and G 1 (x) = H(x||11) are two one-way functions;

[0016] Step 1.3: The intelligent terminal inputs the master key mk into the key generation tree and outputs the key stream k1,…,k n+1 .

[0017] The symmetric homomorphic encryption algorithm in Step 3 is:

[0018] where ki' = ki - ki + 1,

[0019] Therefore, for the aggregation ciphertext decryption operation within this time range, only two boundary keys are required.

[0020] The specific steps of Step 5 are as follows:

[0021] Step 5.1: The data user sends a data access request to the intelligent terminal, including the identity of the data user and the requested data time period.

[0022] Step 5.2: The intelligent terminal receives the request and verifies whether the identity of the data user is legal and whether it has the access permission to the data within this time period.

[0023] Step 5.3: If the data user's identity is legal and has access rights, the smart terminal will send the boundary key K=(k 1 ,k n+1 ) within this time period to the data user.

[0024] The symmetric homomorphic decryption algorithm described in Step 6 is as follows:

[0025]

[0026] In summary, the advantages of the present invention compared with the prior art are as follows:

[0027] For the power grid data with huge volume, fast generation speed, and low value density, the present invention can support low-latency queries. By making full use of the computing power of edge intelligent terminals, it reduces the dependence on cloud servers and realizes the secure sharing of power grid data through fine-grained data access control. Brief Description of the Drawings

[0028] Figure 1 It is the architecture diagram of the efficient aggregation and access control method for power grid data privacy protection.

[0029] Figure 2 It is the structure diagram of key stream generation.

[0030] Figure 3 It is the comparison diagram of the throughput of the present invention with other schemes.

[0031] Figure 4 It is the comparison diagram of the response time of the present invention with other schemes. Detailed Embodiments

[0032] The present invention will be described in more detail below in conjunction with embodiments.

[0033] Embodiment 1

[0034] The present invention improves the existing cloud-based privacy protection data aggregation scheme, proposes a power grid data privacy protection aggregation method based on edge computing to protect power grid data, and realizes the secure sharing of power grid data through a fine-grained access control method. When a data user requests access to data, the present invention can support low-latency data processing and improve the throughput of system data processing.

[0035] The present invention includes the following steps:

[0036] Step 1: The smart terminal uses a pseudo-random number generator and a master key to generate all n+1 key sequences k required within a fixed time period (for example, one hour) 1 ,…,k n+1 .

[0037] Step 2: The intelligent terminal divides the data generated during this time period into n independent data blocks according to time segments, and calculates the data aggregation summary (such as summation, average value) m of each data block 1 ,…,m n , and the plaintext space is [0, M - 1] (for example, the data within every 10s is taken as a data block).

[0038] Step 3: The intelligent terminal uses the key sequence k 1 ,…,k n to encrypt all the data blocks m 1 ,…,m n+1 during this time period to generate ciphertext c 1 ,…,c n .

[0039] Step 4: The intelligent terminal sends all the ciphertext data blocks c 1 ,…,c n during this time period to the cloud server for storage.

[0040] Step 5: The data user requests data access permission from the intelligent terminal, and the data terminal generates a corresponding key set K according to the identity of the data user and the data request, and sends it to the data user.

[0041] Step 6: The data user obtains the ciphertext through the cloud server, and performs an aggregation decryption operation on the ciphertext using the key set K issued by the intelligent terminal to obtain the plaintext aggregation result of the grid data.

[0042] Figure 1 The specific implementation process of the present invention is shown above.

[0043] The generation of the key sequence specifically includes the following steps:

[0044] 1) The intelligent terminal randomly selects a master key mk and secretly stores mk.

[0045] 2) The intelligent terminal constructs a hierarchical key generation tree (as Figure 2 shown). The number of levels h of this

[0046] structure is the ceiling of log(n + 1), where G 0 (x) = H(x||00)

[0047] and G 1 (x) = H(x||11) are two one-way functions.

[0048] 3) The intelligent terminal inputs the master key mk into the key generation tree and outputs the key stream

[0049] k 1 ,…,kn+1 。

[0050] As an edge device, the intelligent terminal needs to encrypt the smart grid data in time slices. The present invention proposes to calculate an aggregation of the data every once in a while starting from 0s and perform encryption. The specific encryption algorithm is as follows:

[0051] where ki' = ki - ki+1,

[0052] Therefore, for the decryption operation of the aggregated ciphertext within this time range, only two boundary keys are required. The corresponding decryption algorithm is as follows:

[0053]

[0054] In addition to the privacy protection aggregation of grid data, the present invention also realizes fine-grained access control for data users, as follows:

[0055] 1) The data user sends a data access request to the intelligent terminal, including the identity of the data user and the requested data time period.

[0056] 2) The intelligent terminal receives the request and verifies whether the identity of the data user is legal and whether it has the access right to the data within this time period.

[0057] 3) If the identity of the data user is legal and has the access right, the intelligent terminal will send the boundary key K = (k 1 , k n+1 ) within this time period to the data user.

[0058] In order to verify whether the privacy protection data aggregation method proposed by the present invention can achieve the effects of low-latency query and high-throughput read and write, a prototype system was built for simulation. The cloud server used is Amazon AWS, with a 2.5GHz CPU and Ubuntu 16.04 LTS, and the intelligent terminal used is a smart meter with a 10Gbps bandwidth. The encryption performance of the intelligent terminal and the data user (simulated using a MacBook Pro with a 2.8GHz Intel Core i7 and 16GB RAM) were tested.

[0059] 1) Ciphertext expansion. Compare the size of the encrypted ciphertext with the size of the plaintext.

[0060] 2) Query time. Test the privacy protection aggregation time of the grid data.

[0061] 3) Throughput. Test the read and write throughput of the privacy protection aggregation of the grid data.

[0062] By Figure 3It can be seen that the throughput of the present invention is only reduced by about 2% compared with the plaintext aggregation, and it has very obvious advantages compared with the existing asymmetric homomorphic encryption-based schemes. Figure 4 It can be seen that the latency of the present invention is very close to the performance in the case of plaintext sharing (without any protection).

[0063] The experimental results show that the present invention can ensure low query latency and high throughput for reading and writing in the privacy protection aggregation of smart grid data.

[0064] As mentioned above, the above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

[0065] The parts not described in this embodiment are the same as the prior art.

Claims

1. An efficient privacy protection aggregation and access control method for power grid data, Characterized in that: The specific steps are as follows: Step 1: The intelligent terminal uses a pseudo-random number generator and a master key to generate all n + 1 key sequences k required within a fixed time period 1 ,…,k n+1 ; Step 2: The smart terminal divides the data generated during this time period into n independent data blocks according to time segments, and calculates the data aggregation summary m of each database 1 ,…,m n , and the plaintext space is [0, M-1]; Step 3: The smart terminal uses all data blocks m during this time period 1 ,…,m n and the key sequence k 1 ,…,k n+1 to encrypt and generate ciphertext c 1 ,…,c n ; Step 4: The smart terminal sends all the ciphertext data blocks c 1 ,…,c n during this time period to the cloud server for storage; Step 5: The data user requests data access permission from the intelligent terminal, and the data terminal generates a corresponding key set K according to the identity of the data user and the data request, and sends it to the data user; Step 6: The data user obtains the ciphertext through the cloud server, and performs an aggregation decryption operation on the ciphertext with the key set K issued by the intelligent terminal to obtain the plaintext aggregation result of the power grid data; The specific content of the said Step 1 includes, Step 1.1: The intelligent terminal randomly selects a master key mk and secretly stores mk; Step 1.2: The intelligent terminal constructs a hierarchical key generation tree, where the number of levels h of this structure is the ceiling of log(n + 1), where G 0 (x) = H(x||00) and G 1 (x) = H(x||11) are two one-way functions; Step 1.3: The smart terminal inputs the master key mk into the key generation tree and outputs the key streams k1, …, k n+1 ; The method for encrypting and generating the ciphertext in the said Step 3 adopts a symmetric homomorphic encryption algorithm, specifically: where k i ' = k i - k i+1 , Therefore, for the aggregation ciphertext decryption operation during this time period, only two boundary keys are required. The said Step 5 specifically includes the following steps: Step 5.1: The data user sends a data access request to the intelligent terminal, including the identity of the data user and the requested data time period; Step 5.2: The intelligent terminal receives the request, verifies whether the identity of the data user is legal and whether it has the access permission to the data during this time period; Step 5.3: If the data user's identity is legal and has access rights, the smart terminal will send the boundary key K = (k 1 , k n+1 ) within this time period to the data user; The said aggregation decryption operation in Step 6 adopts a symmetric homomorphic decryption algorithm, specifically as follows:

Citation Information

Patent Citations

  • V erifiable, leak-resistant encryption and decryption

    CN102725737A