An operation permission verification method for a data verification system of a power communication optical cable

By implementing multiple authentication methods of identity authentication and data encryption in the power communication optical cable data verification system, the system's lack of screening of illegal user identification and legal user overright operations is solved, and the system's high security and reliability are achieved.

CN113987527BActive Publication Date: 2025-06-17HUZHOU ELECTRIC POWER SUPPLY CO OF STATE GRID ZHEJIANG ELECTRIC POWER CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111157789.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-29
Publication Date
2025-06-17
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

The existing power communication optical cable data verification system lacks the identification of illegal users and the screening of legal users' overriding operations, making it difficult to ensure the security of the system.

Method used

By implementing multiple authentication methods in the power communication optical cable data verification system, and encrypting the operation object data in different forms, the key is divided and stored in the identity-time database and the identity-IP address database, and the key is combined for permission verification during decryption.

Benefits of technology

Effectively deny illegal users access to the system and legal users' overriding operations, avoid system damage, prevent system data theft and tampering, and improve system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987527B_ABST
    Figure CN113987527B_ABST
Patent Text Reader

Abstract

The present invention discloses an operation authority verification method for a power communication optical cable data verification system. In order to overcome the problem in the prior art that the identification of illegal users and the screening of unauthorized operations by legitimate users are lacking, making it difficult to ensure the security of the system; the present invention encrypts different operation data, and determines whether the operator has the corresponding operation authority based on whether the decryption is successful, which can not only ensure the security of the data, but also reject illegal users from entering the system and unauthorized operations by legitimate users, avoid damage to the system, and prevent theft and tampering of system data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of permission verification, and particularly to an operation permission verification method for a data verification system of a power communication optical cable. Background Art

[0002] After years of construction, a backbone power communication network covering the main grid of the municipal power grid has basically been built. This network has a wide coverage area, a large number of optical cables and fibers, and a long distance. However, at the same time, with the increase in the number of optical cables and the aging of the early laid optical cables, the problems of optical cable maintenance and fault handling have become increasingly prominent. Especially for the verification and preservation of optical cable resource data, the existing maintenance methods still remain at the low level of manual checking and centralized rectification, lacking information-based auxiliary support means, which brings great troubles to the fault analysis and troubleshooting of optical cables, and also brings great pressure to the operation work of the communication specialty.

[0003] Currently, there are explorations and researches on information-based maintenance means for backbone network optical cable resource data, and based on this, a resource verification and maintenance system based on the resource data of the TMS system and combined with the dynamic data of the backbone transmission network management is studied. By studying the verification rules and algorithms of network management dynamic data and optical cable resource data, information-based means are used to promote the timely update of dumb data (optical cables), break the lagging situation of the original optical cable resource data maintenance, promote the real-time update of optical cable resource data, and form a long-term management system, laying a solid foundation for improving the work efficiency of maintenance and fault handling, thereby effectively improving the safety level of the power grid.

[0004] For example, a "Method for Intelligent Identification and Diagnosis of a Power Digital Link" disclosed in a Chinese patent document, with the publication number CN113300765A, includes the following steps: generating an optical cable intelligent label and establishing a safety measure model; parsing the optical cable intelligent label, including label scanning and label information display; performing safety measure verification according to the safety measure model; and performing fast fault location and traffic anomaly diagnosis according to the label parsing information and the verification result. However, the above solution lacks the identification of illegal users and the screening of unauthorized operations by legitimate users, and it is difficult to ensure the security of the system. Summary of the Invention

[0005] The present invention mainly solves the problem that the existing data verification system of power communication optical cables lacks the identification of illegal users and the screening of unauthorized operations by legitimate users, and it is difficult to ensure the security of the system; and provides an operation permission verification method for a data verification system of a power communication optical cable, which rejects illegal users from entering the system and unauthorized operations by legitimate users, avoids damage to the system, and prevents theft and tampering of system data.

[0006] The above technical problems of the present invention are mainly solved by the following technical solutions:

[0007] An operation permission verification method for a power communication optical cable data verification system, comprising the following steps:

[0008] S1: An operator logs in to a user account on the interactive interface of the power communication optical cable data verification system and performs identity authentication through multiple verification methods;

[0009] S2: The data processing layer obtains and parses the operation requests sent by the operator, and parses the operation object, request time, and request occurrence IP address of the operation request;

[0010] S3: The database performs encryption processing on all operation object data in different forms, and after the secret keys are split, they are respectively stored in the identity-time database and the identity-IP address database corresponding to the operation permissions;

[0011] S4: According to the operation object parsed by the data processing layer, transmit the encrypted operation object data to the data processing layer;

[0012] According to the request time and request occurrence IP address parsed by the data processing layer, obtain the secret keys from the identity-time database and the identity-IP address database corresponding to the operator respectively for combination, and decrypt the encrypted operation object data;

[0013] S5: Perform integrity verification on the decrypted data. If the verification is complete, the operator has the corresponding operation permission; otherwise, the operator does not have the corresponding operation permission.

[0014] This solution encrypts different operation data, and judges whether the operator has the corresponding operation permission based on whether the decryption is successful. It can not only ensure the security of the data, but also reject illegal users from entering the system and prevent legitimate users from performing unauthorized operations, avoiding damage to the system and preventing system data from being stolen and tampered with.

[0015] Preferably, the multiple verification methods include user password method, signature method, and biometric method, and the biometric features include fingerprint, iris, and face recognition;

[0016] When using the biometric method for identity authentication, at least one verification method is used for identity authentication;

[0017] When using the user password method or signature method for identity authentication; in addition to the user password method or signature method, at least one other verification method is also included to complete the identity authentication.

[0018] Through multiple verification methods, ensure that the operation is performed by the person himself, and avoid the phenomenon of inconsistent person and household.

[0019] Preferably, the step S3 specifically includes the following steps:

[0020] S301: Select an operation object data and perform binary conversion;

[0021] S302: Randomly remove several "1"s from the binary operation object data to generate the secret key A corresponding to the operation permission;

[0022] A = [a1, a2, a3......a n

[0023] where a n is the position marker of the nth "1" removed;

[0024] S303: Randomly divide the secret key A into the first secret key A1 and the second secret key A2; store the first secret key A1 in the identity-time database corresponding to the operation permission of the operation object data; store the second secret key A2 in the identity-IP address database corresponding to the operation permission of the operation object data;

[0025] S304: Select the next operation object data and execute step S301 until all operation object data is encrypted.

[0026] Use the encryption method of this solution to encrypt the operation object data. Different operation object data is encrypted in different forms, which is convenient for distinguishing different operation permissions.

[0027] Preferably, the identity-time database stores the divided secret keys corresponding to the operation permissions of each operator in different time periods; the identity-IP address database stores the divided secret keys corresponding to the operation permissions of each operator at different IP addresses.

[0028] The operation permissions of different operators are different in different time periods and different places. The secret keys corresponding to the operation permissions are divided according to time and IP address, combined during decryption, and used for operation permission authentication to ensure the rigor and security of the judgment.

[0029] Preferably, the step S4 includes the following steps:

[0030] S401: According to the operation object parsed by the data processing layer, transmit the encrypted binary operation object data to the data processing layer;

[0031] S402: According to the request time parsed by the data processing layer and the identity of the operator after identity authentication, obtain the divided first secret key A1 corresponding to different operation permissions from the identity-time database of the operator;

[0032] ​S403: Based on the IP address of the request parsed by the data processing layer and the identity of the operator after identity authentication, obtain the segmented second secret key A2 corresponding to different operation authorities from the operator's identity-IP address database;

[0033] S404: The data processing layer respectively splices and combines the first secret key A1 and the second secret key A2, and decrypts the encrypted binary operation object data respectively.

[0034] During the decryption process, the operation authority of the operator is judged by the combination of the authority corresponding to the operator's time and the authority of the IP address, and the judgment process is more rigorous and diverse.

[0035] Preferably, the data processing layer judges the integrity of the operation object data decrypted by each secret key combination; the integrity verification includes content judgment and format judgment;

[0036] The format judgment includes the format judgment of binary data. The converted binary data sequentially includes a start code, a data type code, a data content code, and an end code;

[0037] The content judgment includes inverse conversion of the decrypted binary operation object to the original data type, and judges whether the conversion is successful. If so, the next judgment is carried out. If not, the integrity verification fails;

[0038] Judge whether there is garbled code in the operation object data converted to the original data type. If so, the integrity verification fails. If not, the integrity verification is successful;

[0039] Judge whether the integrity verification of the decrypted operation object data is successful. If so, the operator has the corresponding operation authority. Otherwise, the operator does not have the corresponding operation authority.

[0040] This solution encrypts different operation data and judges whether the operator has the corresponding operation authority by whether the decryption is successful, which can not only ensure the security of the data, but also reject illegal users from entering the system and prevent legitimate users from performing unauthorized operations, avoiding damage to the system and preventing system data from being stolen and tampered with.

[0041] The beneficial effects of the present invention are:

[0042] 1. By judging whether the decryption is successful to determine whether the operator has the corresponding operation authority, it can not only ensure the security of the data, but also reject illegal users from entering the system and prevent legitimate users from performing unauthorized operations, avoiding damage to the system and preventing system data from being stolen and tampered with.

[0043] 2. During the decryption process, the operation authority of the operator is judged by the combination of the authority corresponding to the operator's time and the authority of the IP address, and the judgment process is more rigorous and diverse.

[0044] 3. Different operation object data are encrypted in different forms to facilitate the distinction of different operation permissions. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is a flowchart of the operation permission verification method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0046] The technical solution of the present invention will be further specifically described below through embodiments in conjunction with the drawings.

[0047] Embodiment:

[0048] An operation permission verification method for a power communication optical cable data verification system according to this embodiment is as Figure 1 shown, and includes the following steps:

[0049] S1: The operator logs in to the user account on the interaction interface of the power communication optical cable data verification system and performs identity authentication through multiple verification methods.

[0050] The multiple verification methods include user password method, signature method and biometric method, and the biometrics include fingerprint, iris and face recognition.

[0051] When performing identity authentication by biometric method, at least one verification method is used for identity authentication.

[0052] Using the biometric method for identity authentication can effectively confirm the identity of the user and ensure the consistency of the person and the account.

[0053] When performing identity authentication by user password method or signature method; in addition to the user password method or signature method, at least one other verification method is also included to complete the identity authentication.

[0054] The user password method or signature method cannot fully determine the identity of the user. At least two identity authentication methods are used to corroborate each other to ensure the accuracy of identity authentication.

[0055] S2: The data processing layer obtains and parses the operation request sent by the operator, and parses the operation object, request time and request occurrence IP address of the operation request.

[0056] S3: The database performs different forms of encryption processing on all operation object data, and the secret keys are split and stored in the identity-time database and identity-IP address database corresponding to the operation permissions respectively.

[0057] S301: Select an operation object data and perform binary conversion;

[0058] S302: Randomly remove several "1"s from the binary operation object data to generate the secret key A corresponding to the operation permission;

[0059] A = [a1, a2, a3......a n

[0060] where a n is the position mark of the nth "1" removed.

[0061] S303: Randomly split the secret key A into the first secret key A1 and the second secret key A2; store the first secret key A1 in the identity-time database corresponding to the operation permission of the operation object data; store the second secret key A2 in the identity-IP address database corresponding to the operation permission of the operation object data.

[0062] The identity-time database stores the split secret keys corresponding to the operation permissions of each operator in different time periods.

[0063] The identity-IP address database stores the split secret keys corresponding to the operation permissions of each operator at different IP addresses.

[0064] S304: Select the next operation object data and execute step S301 until all operation object data is encrypted.

[0065] For example, the data after binary conversion of the operation object data is: 1101100111100011111000101010

[0067] The binary data after random encryption is: 101100111000111100001010

[0069] In this time, the "1" at the 2nd position, the "1" at the 6th position after the previous removal position, the "1" at the 7th position after the previous removal position, and the "1" at the 8th position after the previous removal position are removed.

[0070] Therefore, the secret key of this data is [2, 6, 7, 8].

[0071] Randomly divide this secret key into two parts, [2, 6] and [7, 8]; store the divided secret keys in the identity-time database and the identity-IP address database of the user with the corresponding operation permission of this operation object data respectively.

[0072] Different operation object data are encrypted in different forms to facilitate the distinction of different operation permissions.

[0073] ​S4: Transmit the encrypted operation object data to the data processing layer according to the operation object parsed by the data processing layer; obtain the secret keys from the identity-time database and the identity-IP address database corresponding to the operator respectively according to the request time and the request occurrence IP address parsed by the data processing layer, and combine them to decrypt the encrypted operation object data.

[0074] S401: Transmit the encrypted binary operation object data to the data processing layer according to the operation object parsed by the data processing layer.

[0075] S402: Obtain the segmented first secret key A1 corresponding to different operation authorities from the identity-time database of the operator according to the request time parsed by the data processing layer and the identity of the operator after identity authentication.

[0076] S403: Obtain the segmented second secret key A2 corresponding to different operation authorities from the identity-IP address database of the operator according to the request occurrence IP address parsed by the data processing layer and the identity of the operator after identity authentication.

[0077] S404: The data processing layer splices and combines the first secret key A1 and the second secret key A2 respectively, and decrypts the encrypted binary operation object data respectively.

[0078] During the decryption process, the operation authority of the operator is judged by the combination of the authority corresponding to the time of the operator and the authority of the IP address, and the judgment process is more rigorous and diverse.

[0079] S5: Perform integrity verification on the decrypted data. If the verification is complete, the operator has the corresponding operation authority; otherwise, the operator does not have the corresponding operation authority.

[0080] The data processing layer judges the integrity of the operation object data decrypted by each secret key combination; the integrity verification includes content judgment and format judgment;

[0081] The format judgment includes the format judgment of binary data. The converted binary data sequentially includes a start code, a data type code, a data content code, and an end code;

[0082] The content judgment includes inverse conversion of the decrypted binary operation object to the original data type, and judges whether the conversion is successful. If so, proceed to the next judgment. If not, the integrity verification fails;

[0083] Judge whether there is garbled code in the operation object data converted to the original data type. If so, the integrity verification fails. If not, the integrity verification is successful;

[0084] Determine whether the integrity verification of the decrypted operation object data is successful. If so, the operator has the corresponding operation permission; otherwise, the operator does not have the corresponding operation permission.

[0085] The solution of this embodiment determines whether the operator has the corresponding operation permission by whether the decryption is successful, which can not only ensure the security of data, but also reject illegal users from entering the system and prevent legitimate users from performing unauthorized operations, avoiding damage to the system and preventing theft and tampering of system data.

[0086] It should be understood that the embodiments are only used to illustrate the present invention and not to limit the scope of the present invention. In addition, it should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms also fall within the scope defined by the appended claims of this application.

Claims

1. A method for verifying the operation authority of a power communication optical cable data verification system, characterized in that, It includes the following steps: S1: The operator logs in to the user account on the interactive interface of the power communication optical cable data verification system and conducts identity authentication through multiple verification methods; S2: The data processing layer obtains and parses the operation requests issued by the operator, and parses the operation object, request time, and IP address where the request occurs of the operation request; S3: The database performs encryption processing on all operation object data in different forms, and after the secret keys are split, they are respectively stored in the identity-time database and the identity-IP address database corresponding to the operation permissions; S4: According to the operation object parsed by the data processing layer, transmit the encrypted operation object data to the data processing layer; According to the request time and the IP address where the request occurs parsed by the data processing layer and the identity of the operator after identity authentication, obtain the split first secret key corresponding to different operation permissions from the identity-time database corresponding to the operator and the split second secret key corresponding to different operation permissions from the identity-IP address database, combine the obtained secret keys, decrypt the encrypted operation object data, the data processing layer splices and combines the first secret key and the second secret key respectively, and decrypts the encrypted binary operation object data respectively; S5: Perform integrity verification on the decrypted data. If the verification is complete, the operator has the corresponding operation permission, otherwise the operator does not have the corresponding operation permission.

2. The method for verifying the operation authority of a power communication optical cable data verification system according to claim 1, characterized in that, The multiple verification methods include user password method, signature method, and biometric method. Biometrics include fingerprint, iris, and face recognition; When using the biometric method for identity authentication, at least one verification method is used for identity authentication; When using the user password method or the signature method for identity authentication; in addition to the user password method or the signature method, at least one other verification method is also included to complete identity authentication.

3. The method for verifying the operation authority of a power communication optical cable data verification system according to claim 1, characterized in that, The step S3 specifically includes the following steps: S301: Select an operation object data and perform binary conversion; S302: Randomly remove several "1"s from the binary operation object data to generate the secret key A corresponding to the operation permission; A = [a1, a2, a3......a n ​ where a n is the position marker of the nth "1" to be removed; S303: Randomly split the secret key A into the first secret key A1 and the second secret key A2; store the first secret key A1 in the identity-time database corresponding to the operation permission of the operation object data; store the second secret key A2 in the identity-IP address database corresponding to the operation permission of the operation object data; S304: Select the next operation object data and execute step S301 until all operation object data is encrypted.

4. The method for verifying the operation authority of a power communication optical cable data verification system according to claim 1 or 3, characterized in that, The identity-time database stores the split secret keys corresponding to the operation permissions of each operator at different time periods; the identity-IP address database stores the split secret keys corresponding to the operation permissions of each operator at different IP addresses.

5. The method for verifying the operation authority of a power communication optical cable data verification system according to claim 3, characterized in that, The step S4 includes the following steps: S401: According to the operation object parsed by the data processing layer, transmit the encrypted binary operation object data to the data processing layer; S402: Obtain the segmented first secret key A1 corresponding to different operation authorities from the identity-time database of the operator according to the request time parsed by the data processing layer and the identity of the operator after identity authentication; S403: Obtain the segmented second secret key A2 corresponding to different operation authorities from the identity-IP address database of the operator according to the request occurrence IP address parsed by the data processing layer and the identity of the operator after identity authentication; S404: The data processing layer respectively splices and combines the first secret key A1 and the second secret key A2, and decrypts the encrypted binary operation object data respectively.

6. The method for verifying the operation authority of a power communication optical cable data verification system according to claim 1 or 5, characterized in that, The data processing layer performs integrity judgment on the operation object data decrypted by each secret key combination; the integrity verification includes content judgment and format judgment; The format judgment includes the format judgment of binary data, and the converted binary data sequentially includes a start code, a data type code, a data content code, and an end code; The content judgment includes inverse conversion of the decrypted binary operation object to the original data type, and judges whether the conversion is successful. If so, proceed to the next judgment. If not, the integrity verification fails; Judge whether there is garbled code in the operation object data converted to the original data type. If so, the integrity verification fails. If not, the integrity verification is successful; Judge whether there is successful integrity verification of the decrypted operation object data. If so, the operator has the corresponding operation authority, otherwise, the operator does not have the corresponding operation authority.

Citation Information

Patent Citations

  • Communication method, client and server

    CN110708156A

  • Intelligent identification and diagnosis method for power digital link

    CN113300765A