IBE-based power grid PMU identity authentication method, device, computer equipment and medium

By adopting the IBE-based grid PMU identity authentication method in the smart grid, the problem of insufficient security of device access and authentication in the smart grid is solved, and trusted identity authentication of PMU and SCADA is realized, improving the security and reliability of the power grid.

CN114238886BActive Publication Date: 2025-05-09GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111372266.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-18
Publication Date
2025-05-09
Estimated Expiration
2041-11-18

AI Technical Summary

Technical Problem

The prior art prevents insufficient access and authentication of equipment in smart power grids, resulting in information security risks, affecting the normal operation of the power grid and the life and production of users.

Method used

The IBE-based Identity-Based Encryption method is used to obtain initialization parameters, including the real identity identification, and complete the first identity registration process of the PMU on a trusted central server, and complete the second identity registration process on SCADA, and finally perform identity authentication on SCADA.

Benefits of technology

Through this method, trusted identity authentication of PMU and SCADA in the power grid is realized, data loss and tampering are curbed, data integrity and security are ensured, and the reliability of identity authentication of power grid nodes is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114238886B_ABST
    Figure CN114238886B_ABST
Patent Text Reader

Abstract

The present application relates to a method, device, computer equipment, storage medium and computer program product for power grid PMU identity authentication based on IBE. The present application can provide trusted identity authentication based on a trusted central server for PMU and SCADA in the power grid, effectively improving the reliability of power grid node identity authentication. The method includes: obtaining initialization parameters; wherein the initialization parameters include a real identity identifier; sending the real identity identifier to the trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to generate edge registration parameters based on the real identity identifier, and send the edge registration parameters to SCADA, so that the PMU completes the second identity registration process on SCADA; after the first identity registration process is completed and the second identity registration process is completed, a service request is sent to SCADA, so that SCADA completes the identity authentication process with the PMU based on the service request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of digital encryption technology, and in particular to an IBE-based power grid PMU identity authentication method, device, computer equipment, storage medium and computer program product. Background Art

[0002] As the foundation and important component of the development of industrialized and information-based society, smart grid has brought great changes to people's lives and produced huge social and economic benefits, but at the same time, it has inevitably introduced information security risks. In recent years, there have been frequent cybersecurity incidents in smart power systems internationally. For example, hackers gain control of the power grid in a certain area by invading the control center of the smart grid. In serious cases, it can lead to the inability to distribute electricity in the area, affecting residents' lives and industrial production, and causing huge losses.

[0003] Existing technologies are not sufficient to prevent the access and authentication of various devices in smart grids, so how to improve the security of devices in the power grid has become an urgent problem to be solved. Summary of the invention

[0004] Based on this, it is necessary to provide a power grid PMU identity authentication method, device, computer equipment, computer readable storage medium and computer program product based on IBE to address the above technical problems.

[0005] In a first aspect, the present application provides a power grid PMU identity authentication method based on IBE, which is applied to PMU, and the method includes:

[0006] Acquire initialization parameters; wherein the initialization parameters include a real identity identifier;

[0007] The real identity identifier is sent to the trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to generate edge registration parameters based on the real identity identifier, and send the edge registration parameters to SCADA, so that the PMU completes the second identity registration process on the SCADA;

[0008] After the first identity registration process is completed and the second identity registration process is completed, a service request is sent to the SCADA, so that the SCADA completes the identity authentication process with the PMU based on the service request.

[0009] In one embodiment, sending the real identity identifier to the trusted central server to complete the first identity registration process of the PMU on the trusted central server includes:

[0010] Sending the real identity to a trusted central server so that the trusted central server generates a virtual identity from the real identity using an IBE encryption algorithm, and generates a terminal key pair for the PMU; the trusted central server is also used to return the virtual identity and the terminal key pair to the PMU;

[0011] Generate a first terminal random number, and use a trusted public key to encrypt the first terminal random number and the virtual identity to generate a first registration parameter;

[0012] The first registration parameter is sent to the trusted central server so that the trusted central server uses the trusted private key to decrypt the first registration parameter to obtain the first terminal random number and the virtual identity, generates a terminal shared key between the local and PMU based on the virtual identity, and saves the terminal shared key.

[0013] In one of the embodiments, the trusted central server is further used to randomly generate a terminal shared key for the PMU after the first identity registration process is completed;

[0014] The trusted central server is also used to query the SCADA to which the PMU belongs, obtain the edge identity of the SCADA, generate the edge registration parameters based on the edge identity and the terminal shared key, and send the edge registration parameters to the SCADA so that the SCADA saves the edge registration parameters and completes the second identity registration process.

[0015] In one embodiment, the service request includes a virtual identity; and sending the service request to the SCADA so that the SCADA completes an identity authentication process with the PMU based on the service request, includes:

[0016] The service request is sent to the SCADA, so that the SCADA searches the edge registration parameters for the virtual identity identifier to see whether the virtual identity identifier is included in the edge registration parameters, and if included, verifies that the message sender is a non-malicious identity.

[0017] In one of the embodiments, the SCADA is further used to record the time when the service request is received as an initial timestamp, generate encryption parameters based on the edge identity of the SCADA after verifying that the message sender has a non-malicious identity, and return the encryption parameters to the PMU;

[0018] The PMU is used to record the timestamp of receiving the encryption parameter as a first timestamp, verify the sender identity of the encryption parameter according to the time difference between the first timestamp and the initial timestamp, and verify the message integrity of the encryption parameter according to the time difference.

[0019] In one of the embodiments, the service request further includes a first temporary random number; the encryption parameter further includes a second random number generated by the SCADA, and the SCADA is further configured to set the second random number based on the first random number to verify the identity of the PMU.

[0020] In a second aspect, the present application further provides an IBE-based power grid PMU identity authentication device, which is applied to a PMU, and the device includes:

[0021] A parameter initialization module, used to obtain initialization parameters; wherein the initialization parameters include a real identity identifier;

[0022] An identity registration module, used for sending the real identity identifier to a trusted central server to complete a first identity registration process of the PMU on the trusted central server; the trusted central server is further used for generating edge registration parameters based on the real identity identifier, and sending the edge registration parameters to SCADA, so that the PMU completes a second identity registration process on the SCADA;

[0023] The identity authentication module is used to send a service request to the SCADA after the first identity registration process is completed and the second identity registration process is completed, so that the SCADA completes the identity authentication process with the PMU based on the service request.

[0024] In a third aspect, the present application further provides a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor implements each step in the above-mentioned IBE-based power grid PMU identity authentication method embodiment when executing the computer program.

[0025] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in the above-mentioned embodiment of the IBE-based power grid PMU identity authentication method are implemented.

[0026] In a fifth aspect, the present application further provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the computer program implements the steps in the above-mentioned IBE-based power grid PMU identity authentication method embodiment.

[0027] The above-mentioned IBE-based power grid PMU identity authentication method, device, computer equipment, storage medium and computer program product, by obtaining initialization parameters; wherein the initialization parameters include a real identity identifier; the real identity identifier is sent to a trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to generate edge registration parameters based on the real identity identifier, and send the edge registration parameters to SCADA, so that the PMU completes the second identity registration process on SCADA; after the first identity registration process is completed and the second identity registration process is completed, a service request is sent to SCADA, so that SCADA completes the identity authentication process with the PMU based on the service request. This application can provide a trusted identity authentication based on a trusted central server for PMU and SCADA in the power grid, curb the risks of data loss and tampering from the PMU node, ensure the integrity and security of data transmission from the data transmission, provide protection for the construction of the power grid system security system, and effectively improve the reliability of power grid node identity authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 FIG. 1 is an application environment diagram of an IBE-based power grid PMU identity authentication method in one embodiment;

[0029] Figure 2 1 is a flow chart of a method for authenticating a power grid PMU based on IBE in one embodiment;

[0030] Figure 3 is a timing diagram of an identity registration process in an embodiment;

[0031] Figure 4 is a timing diagram of an identity authentication process in another embodiment;

[0032] Figure 5 is a structural block diagram of a power grid PMU identity authentication device based on IBE in one embodiment;

[0033] Figure 6 is an internal structure diagram of a computer device in one embodiment;

[0034] Figure 7 FIG. 4 is a diagram showing the internal structure of a computer device in another embodiment. DETAILED DESCRIPTION

[0035] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0036] The IBE-based power grid PMU identity authentication method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown in the figure, the terminal is PMU (phasor measurement unit); PMU communicates with SCADA (Supervisory Control And Data Acquisition) server through the network. For the convenience of management, PMU is grouped, each group includes a SCADA and multiple PMUs, and each SCADA is connected to TCS (Trusted computing system) through the network. In this application, PMU can be referred to as terminal, SCADA can be considered as edge service area, and TCD can be considered as trusted central server.

[0037] In one embodiment, Figure 2 As shown in FIG. 1 , a power grid PMU identity authentication method based on IBE is provided, and the method is applied to Figure 1 The terminal PMU in the example is used to illustrate, including the following steps:

[0038] Step S201, obtaining initialization parameters; wherein the initialization parameters include a real identity identifier;

[0039] The real identity identifier is the identity identifier of the PMU, for example, it may be the chip physical address of the PMU, which can be used to uniquely identify a PMU.

[0040] Specifically, the parameters of the PMU are first initialized. For example, the configuration parameters can be manually input into the PMU. The PMU can also read the physical address of its own chip as the real identity identifier, which can be recorded as ID PMU .

[0041] Step S202, sending the real identity to the trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to generate edge registration parameters based on the real identity, and send the edge registration parameters to SCADA, so that the PMU completes the second identity registration process on SCADA;

[0042] The first identity registration process refers to the registration process that the PMU completes for the first time on the TCS, and the second identity registration process refers to the registration process that the PMU completes for the first time on the SCADA to which it belongs. The edge registration parameters refer to the parameters that the PMU needs to use to complete the registration on the edge server (ie, SCADA).

[0043] Specifically, PMU will use its real identity IDPMU Sent to the trusted central server TCS, which stores the real identity ID PMU At the same time, for the security consideration of PMU terminal, TCS uses IBE (Identity Based Encryption) algorithm to use the real identity ID of PMU PMU Generate a virtual identity V for each PMU terminal ID , and the virtual identity V ID Return to PMU; the virtual identity is mainly used to provide anonymous identity authentication between PMU terminal and SCADA. TCS also uses the above virtual identity V ID Generate a terminal key pair (pk PMU ,sk PMU ) Among them, pk PMU is the public key of PMU, sk PMU is the private key of PMU; the above virtual identity V ID , terminal key pair pk PMU ,sk PMU The generation method is as follows:

[0044] V ID =H1(ID PMU ), pk PMU =H1(V ID ), sk PMU =s.pk PMU

[0045] Among them, V ID is the virtual identity of PMU, ID PMU is the real identity of PMU, H1(ID PMU ) represents the hash value generated by the hash function for the real identity of the PMU; H1(V ID ) represents the virtual identity V of PMU using hash function ID The generated hash value; sk PMU s.pk is the private key of PMU; PMU The point product of the PMU's public key and the RA's master key is the PMU's private key (s.pk PMU The s in it represents the master key of RA, and . represents the point multiplication);

[0046] Furthermore, TCS has its own key pair (pk TCS ,sk TCS ), called a trusted key pair, where pk TCS is the public key of TCS (referred to as the trusted public key in this article), sk TCsIt is the private key of TCS (referred to as the trusted private key in this article); the trusted public key is known to the public (including PMU and SCADA), while the trusted private key is only known to TCS itself.

[0047] Furthermore, if Figure 3 As shown, the terminal PMU generates a first terminal random number nonce (denoted as n1) and uses Epk TCS Function pair <ID PMU ,V ID ,pk PMU , n1> After encryption, the first registration parameter is generated and sent to TCS (trusted central server) for registration. After receiving it, TCS uses TCS's private key sk TCS Decrypt it and get <ID PMU ,V ID ,pk PMU > and store the relevant parameters of these PMUs <ID PMU ,V ID ,pk PMU >, at this point, PMU has completed the identity registration on TCS, that is, the first identity registration process is completed.

[0048] Furthermore, TCS also needs to register the SCADA in the system. The registration process includes: using the IBE encryption algorithm to generate an edge key pair (pk SCADA ,sk SCADA ) and the shared key k SCADA , the shared key k SCADA It is the shared key between TCS and SCADA. TCS will store the public key pk of each SCADA SCADA The edge key pair and shared key are sent to SCADA through a secure channel. The specific generation method is as follows:

[0049] pk SCADA =H1(ID SCADA ,ID SCADAC )

[0050] sk SCADA =s.pk SCADA

[0051] Among them, pk SCADA Indicates the public key of SCADA, that is, the edge public key, ID SCADA Indicates the real identity of SCADA, ID SCADAC Indicates the real identity of SCADAC (SCADAC stands for data acquisition and monitoring control system cluster); H1 (ID SCADA ,ID SCADAC) represents the hash value of the real identity of SCADA and the real identity of SCADAC; sk SCADA Indicates the private key of SCADA, that is, the edge private key; s.pk SCADA Represents the dot product of SCADA's public key and RA's master key;

[0052] Furthermore, the PMU needs to register on the SCADA to which it belongs, that is, complete the second identity registration process. Specifically, the TCS randomly selects a terminal shared key k for the PMU PMU , using the terminal private key sk PMu Share the key k for the above terminals PMU After encryption, it is returned to the PMU terminal, which decrypts it and obtains the terminal shared key k PMU ;

[0053] The trusted central server TCS is also used to query the SCADA to which the above-mentioned PMU belongs, and obtain the edge identity of the SCADA. For the SCADA to which the PMU belongs, TCS calculates SP (that is, edge registration parameters), where SP = {V ID ,ID SCADAC ,ID SCADA ,k PMU ,pk PMU}, k PMU It is the terminal shared key between TCS and PMU; it is randomly generated by TCS. Use the SCADA public key pk SCADA Encrypt SP and use TCS's private key sk TCS After signing, it is sent to SCADA. TCS sends the encrypted and signed edge registration parameter SP to SCADA. After SCADA receives the edge registration parameter SP, it uses its own private key sk SCADA After decryption, the edge registration parameter SP is obtained and saved, which includes the shared key of the PMU and the public key of the PMU. At this point, the PMU has completed the registration on the SCADA to which it belongs, that is, the second identity registration process is completed.

[0054] Step S203, after the first identity registration process is completed and the second identity registration process is completed, a service request is sent to the SCADA, so that the SCADA completes the identity authentication process with the PMU based on the service request.

[0055] Specifically, Figure 4 As shown, Figure 4 The authentication process between PMU and SCADA is shown. Since the terminal PMU does not know the real identity of SCADA, it is ID SCADA, so virtual identity authentication begins. PMU uses the virtual identity V ID , generate a service request, and send the service request to SCADA to start mutual identity authentication.

[0056] In the above embodiment, by obtaining initialization parameters, wherein the initialization parameters include a real identity identifier, the real identity identifier is sent to a trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to generate edge registration parameters based on the real identity identifier, and send the edge registration parameters to SCADA, so that the PMU completes the second identity registration process on SCADA; after the first identity registration process is completed and the second identity registration process is completed, a service request is sent to SCADA, so that SCADA completes the identity authentication process with the PMU based on the service request. This embodiment can provide a trusted identity authentication based on a trusted central server for the PMU and SCADA in the power grid, curb the risks of data loss and tampering from the PMU node, ensure the integrity and security of data transmission from the data transmission, provide protection for the construction of the power grid system security system, and effectively improve the reliability of the power grid node identity authentication.

[0057] In one embodiment, the service request includes a virtual identity, and the step S203 includes: sending the service request to the SCADA, so that the SCADA searches the edge registration parameters for the virtual identity according to the virtual identity, and if it is included, verifies the non-malicious identity of the message sender. The SCADA is further used to record the time when the service request is received as the initial timestamp, and after verifying the non-malicious identity of the message sender, generates encryption parameters based on the edge identity of the SCADA, and returns the encryption parameters to the PMU; the PMU is used to record the timestamp of receiving the encryption parameters as the first timestamp, verify the identity of the sender of the encryption parameters according to the time difference between the first timestamp and the initial timestamp, and verify the message integrity of the encryption parameters according to the time difference. The service request also includes a first temporary random number; the encryption parameter also includes a second random number generated by the SCADA, and the SCADA is also used to set the second random number based on the first random number to verify the identity of the PMU.

[0058] Specifically, the PMU terminal first requests a service and generates a temporary random number nonce, recorded as n1. Then, after a SCADA in the SCADAC (field real-time data acquisition system cluster) receives the service request, SCADA generates a temporary random number nonce, recorded as n2, and the timestamp T0 is the time when the message from the PMU terminal is received. Then SCADA verifies the SP list sent by TCS to check the V sent by the PMU terminal.ID Whether it is malicious.

[0059] If the verification is successful, the public key pk of the PMU terminal obtained from the SP is used PMU Tuple <V ID ,ID SCADAC ,ID SCADA ,n1,n2>encrypt and return to PMU; otherwise, the authentication process is terminated immediately. The PMU terminal generates a timestamp T1 when receiving the message returned by SCADA. In order to ensure that the message received this time is not a malicious message, the PMU terminal will verify the timestamp, that is, the PMU terminal checks whether the time interval between T1 and T0 is less than or equal to ΔT. If not, it is considered that the message comes from a malicious attacker, then the PMU terminal rejects the message and interrupts the authentication. If the time interval is less than or equal to ΔT, the integrity of the message is further checked to prevent the message from being tampered by the middleman.

[0060] Then, the PMU terminal uses its own private key sk PMU Decrypt the received message and get the ID SCADA ,ID SCADAC Then calculate the public key pk of the edge server SCADA . Then connect n1 and n2 in series to calculate μ = H1 (n1 || n2). Then use the calculated pk SCADA Encrypt <μ,n1,n2> and send it to SCADA.

[0061] Then, SCADA receives the message from the PMU terminal and generates a timestamp T2. SCADA will verify the timestamp, that is, SCADA checks whether the time interval between T2 and T1 is less than or equal to ΔT. If the time interval is less than or equal to ΔT, SCADA will further check the message integrity. Otherwise, SCADA will reject the message and terminate the authentication. SCADA uses its own private key sk SCADA Decrypt the received message, then use the stored n1 and the received n2 in series to calculate μ1=H1(n1||n2), compare the calculated μ1 with the sent μ (μ is just a variable representing the value of the hash function calculated by the series of n1 and n2), and if the comparison is successful, use the k stored in the SP list sent by TCS PMU Calculate C = μ1.k PMU , otherwise the authentication is terminated.

[0062] Then SCADA will use the public key pk of the PMU terminal PMUThe encrypted C is sent to the PMU terminal. The PMU terminal receives the message returned by SCADA and generates a timestamp T3. The PMU terminal verifies the timestamp, that is, the PMU terminal checks whether the time interval between T3 and T2 is less than or equal to ΔT. If the time interval is less than or equal to ΔT, the message integrity is further checked. Otherwise, the PMU terminal rejects the message and terminates the authentication. After receiving the message, the PMU terminal uses the private key sk PMU Decrypt it, and then use the k stored by yourself PMU Calculated C1 = μ.k PMU Finally, the calculated result C1 is compared with C sent by the PMU terminal. If the two are equal, the authentication is successful.

[0063] In the above embodiment, the identity authentication in the IBE-based power grid PMU environment is first initialized; then the PMU terminal registers the identity on the SCADA and the SCADA registers the identity on the TCS; finally, the PMU terminal and the SCADA perform identity authentication. The present invention proposes an identity authentication method in the IBE-based power grid PMU environment to curb the risks of data loss and tampering from the PMU node, ensure the integrity and security of data transmission from the data transmission, provide protection for the construction of the power grid system security system, and effectively improve the reliability of identity authentication.

[0064] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0065] Based on the same inventive concept, the embodiment of the present application also provides an IBE-based power grid PMU identity authentication device for implementing the IBE-based power grid PMU identity authentication method involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more IBE-based power grid PMU identity authentication device embodiments provided below can refer to the limitations of the IBE-based power grid PMU identity authentication method above, and will not be repeated here.

[0066] In one embodiment, Figure 5As shown, a power grid PMU identity authentication device 500 based on IBE is provided, comprising: a parameter initialization module 501, an identity registration module 502 and an identity authentication module 503, wherein:

[0067] The parameter initialization module 501 is used to obtain initialization parameters; wherein the initialization parameters include a real identity identifier;

[0068] The identity registration module 502 is used to send the real identity identifier to the trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to generate edge registration parameters based on the real identity identifier, and send the edge registration parameters to the SCADA, so that the PMU completes the second identity registration process on the SCADA;

[0069] The identity authentication module 503 is used to send a service request to the SCADA after the first identity registration process is completed and the second identity registration process is completed, so that the SCADA completes the identity authentication process with the PMU based on the service request.

[0070] In one embodiment, the above-mentioned identity registration module 502 is further used to: send the real identity identifier to a trusted central server, so that the trusted central server uses the IBE encryption algorithm to generate a virtual identity identifier from the real identity identifier, and generates a terminal key pair for the PMU; the trusted central server is also used to return the virtual identity identifier and the terminal key pair to the PMU; generate a first terminal random number, and use a trusted public key to encrypt the first terminal random number and the virtual identity identifier to generate a first registration parameter; send the first registration parameter to the trusted central server, so that the trusted central server uses a trusted private key to decrypt the first registration parameter to obtain the first terminal random number and the virtual identity identifier, generate a terminal shared key between the local and PMU based on the virtual identity identifier, and save the terminal shared key.

[0071] In one embodiment, the trusted central server is further used to randomly generate a terminal shared key for the PMU after the first identity registration process is completed; the trusted central server is also used to query the SCADA to which the PMU belongs, obtain the edge identity of the SCADA, generate the edge registration parameters based on the edge identity and the terminal shared key, and send the edge registration parameters to the SCADA so that the SCADA saves the edge registration parameters and completes the second identity registration process.

[0072] In one embodiment, the service request includes the virtual identity identifier; the above-mentioned identity authentication module 503 is further used to: send the service request to the SCADA, so that the SCADA searches the edge registration parameters for the virtual identity identifier based on the virtual identity identifier, and if so, verifies that the message sender is a non-malicious identity.

[0073] In one embodiment, the SCADA is further used to record the time when the service request is received as an initial timestamp, generate encryption parameters based on the edge identity of the SCADA after verifying that the message sender has a non-malicious identity, and return the encryption parameters to the PMU;

[0074] The PMU is used to record the timestamp of receiving the encryption parameter as a first timestamp, verify the sender identity of the encryption parameter according to the time difference between the first timestamp and the initial timestamp, and verify the message integrity of the encryption parameter according to the time difference.

[0075] In one embodiment, the service request further includes a first temporary random number; the encryption parameter further includes a second random number generated by the SCADA, and the SCADA is further configured to set the second random number based on the first random number to verify the identity of the PMU.

[0076] Each module in the above-mentioned IBE-based power grid PMU identity authentication device can be implemented in whole or in part by software, hardware, and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0077] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store power grid parameters and key pairs or identity identification data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a power grid PMU identity authentication method based on IBE is implemented.

[0078] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a power grid PMU identity authentication method based on IBE is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse.

[0079] Those skilled in the art will understand that Figures 6 to 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0080] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When the processor executes the computer program, each step in the above-mentioned IBE-based power grid PMU identity authentication method embodiment is implemented.

[0081] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, each step in the above-mentioned IBE-based power grid PMU identity authentication method embodiment is implemented.

[0082] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above-mentioned IBE-based power grid PMU identity authentication method embodiment are implemented.

[0083] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0084] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.

[0085] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0086] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A power grid PMU identity authentication method based on IBE, characterized in that: Applied to a PMU, the method comprises: Acquire initialization parameters; wherein the initialization parameters include a real identity identifier; The real identity is sent to the trusted central server, so that the trusted central server determines the virtual identity of the PMU according to the real identity and generates a terminal key pair; the PMU encrypts the virtual identity of the PMU generated by the trusted central server, the terminal key pair and the real identity according to the trusted public key of the trusted key pair of the trusted central server, and then sends them to the trusted central server to complete the first identity registration process of the PMU on the trusted central server; The trusted central server is further used to determine the terminal shared key and the edge identity of the SCADA based on the virtual identity, and generate edge registration parameters according to the edge identity, the terminal key pair and the terminal shared key, and send the edge registration parameters to the SCADA, so that the PMU completes the second identity registration process on the SCADA; the terminal shared key is used as a random factor to generate encryption parameters in the identity authentication process between the PMU and the SCADA; After the first identity registration process is completed and the second identity registration process is completed, a service request is sent to the SCADA, so that the SCADA completes the identity authentication process with the PMU based on the service request, the terminal key and the encryption parameter; the terminal key is used to encrypt and decrypt the encryption parameter during the identity authentication process.

2. The method according to claim 1, characterized in that The first identity registration process of the PMU on the trusted central server also includes: Generate a first terminal random number, and use a trusted public key to encrypt the first terminal random number and the virtual identity to generate a first registration parameter; The first registration parameter is sent to the trusted central server so that the trusted central server uses the trusted private key to decrypt the first registration parameter to obtain the first terminal random number and the virtual identity, generates a terminal shared key between the local and PMU based on the virtual identity, and saves the terminal shared key.

3. The method according to claim 1, characterized in that The service request includes a virtual identity; the sending of the service request to the SCADA, the SCADA completing the identity authentication process with the PMU based on the service request, the terminal key and the encryption parameter, including: The service request is sent to the SCADA, so that the SCADA searches the edge registration parameters for the virtual identity identifier to see whether the virtual identity identifier is included in the edge registration parameters, and if included, verifies that the message sender is a non-malicious identity.

4. The method according to claim 3, characterized in that: The SCADA is further used to record the time when the service request is received as an initial timestamp, generate encryption parameters based on the edge identity of the SCADA after verifying that the message sender has a non-malicious identity, and return the encryption parameters to the PMU; The PMU is used to record the timestamp of receiving the encryption parameter as a first timestamp, verify the sender identity of the encryption parameter according to the time difference between the first timestamp and the initial timestamp, and verify the message integrity of the encryption parameter according to the time difference.

5. The method according to claim 4, characterized in that The service request also includes a first temporary random number; the encryption parameter also includes a second random number generated by the SCADA, and the SCADA is further used to set the second random number based on the first temporary random number to verify the identity of the PMU.

6. A power grid PMU identity authentication device based on IBE, characterized in that: Applied to PMU, the device comprises: A parameter initialization module, used to obtain initialization parameters; wherein the initialization parameters include a real identity identifier; An identity registration module is used to send the real identity to a trusted central server so that the trusted central server determines the virtual identity of the PMU according to the real identity and generates a terminal key pair; the PMU encrypts the virtual identity of the PMU generated by the trusted central server, the terminal key pair and the real identity according to the trusted key pair of the trusted central server and sends them to the trusted central server to complete the first identity registration process of the PMU on the trusted central server; the trusted central server is further used to determine the terminal shared key and the edge identity of the SCADA based on the virtual identity, and generate edge registration parameters according to the edge identity, the terminal key pair and the terminal shared key, and send the edge registration parameters to the SCADA, so that the PMU completes the second identity registration process on the SCADA; the terminal shared key is used to generate encryption parameters in the identity authentication process between the PMU and the SCADA; The identity authentication module is used to send a service request, the terminal key and the encryption parameter to the SCADA after the first identity registration process is completed and the second identity registration process is completed, so that the SCADA completes the identity authentication process with the PMU based on the service request; the terminal key is used to encrypt and decrypt the encryption parameter during the identity authentication process.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Computer-implemented method and system for secure identification of disconnected objects and their locations

    US20230179592A1