Multi - level security authentication method, system, memory and device for power regulation terminal

By adopting convolutional neural network classification and multi-level encryption algorithms in power regulation terminals, combined with multi-level identity authentication, the problems of unsafe data transmission and high energy consumption of power regulation terminals are solved, and the safe and efficient data transmission is achieved.

CN115314889BActive Publication Date: 2025-07-04NARI INFORMATION & COMM TECH +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210789608.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-06
Publication Date
2025-07-04
Estimated Expiration
2042-07-06

AI Technical Summary

Technical Problem

Traditional data encryption algorithms have limited resources in power control terminals and cannot provide sufficient security protection. The existing technology lacks consideration of hardware resource overhead, resulting in unsafe data transmission and high energy consumption.

Method used

Convolutional neural network is used for data classification, power terminal service data is divided into sensitive and non-sensitive data, and SM4 encryption algorithm and lightweight stream encryption algorithm are respectively encrypted, stored in the public cloud through gateway devices, and data security is ensured by multi-level identity authentication.

Benefits of technology

It realizes security and efficiency in power service data transmission, prevents theft and tampering, ensures secure access to users, and reduces the energy consumption of hardware resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115314889B_ABST
    Figure CN115314889B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-level security authentication method, system, memory and device for a power regulation terminal. The method classifies the power terminal service data into sensitive data and non-sensitive data; encrypts the sensitive data using the symmetric encryption algorithm SM4; for the non-sensitive data, adopts a lightweight stream encryption algorithm to ensure the security of the data transmission process; finally stores the data in a public cloud through a gateway device. To avoid attacks by malicious users, multiple identity authentication technologies are used to authorize user access, thereby ensuring the secure and efficient transmission of the power terminal service data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a multi-level security authentication method, system, memory and device for a power regulation terminal, and belongs to the field of network security technology. Background Art

[0002] With the further explosion of service types and quantities in the 5G mobile communication system, the 5G network will support differentiated application services such as enhanced mobile Internet applications, ultra-low latency applications, and massive machine communications. Security technology is indispensable as the basis for the reliable operation of the 5G mobile communication system. Traditional data encryption is all single algorithms or identity authentication technologies, and the data security protection level is insufficient. And the classic encryption algorithms focus on providing high-level encryption performance without considering too much the problem of hardware resource overhead. However, the hardware resources of the power regulation terminal are limited and it is not suitable to adopt high-performance and high-energy-consuming encryption algorithms. Summary of the Invention

[0003] The object of the present invention is to provide a multi-level security authentication method, system, memory and device for a power regulation terminal, classify the data of the power regulation terminal, encrypt and store sensitive data and non-sensitive data in different ways, and formulate three levels of security authentication methods to ensure the integrity and credibility of the data during transmission.

[0004] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0005] On the one hand, the present invention provides a multi-level security authentication method for a power regulation terminal, including:

[0006] Classify the power terminal service data into sensitive data and non-sensitive data;

[0007] Encrypt and store sensitive data and non-sensitive data respectively;

[0008] Perform identity authentication using the corresponding identity authentication method according to the requested level of the stored encrypted data.

[0009] Further, the classifying the power terminal service data into sensitive data and non-sensitive data includes:

[0010] Use a pre-constructed convolutional neural network data classification model to classify the power terminal service data into sensitive data and non-sensitive data.

[0011] Further, the convolutional neural network data classification model is constructed as follows:

[0012] Obtain historical power terminal service data, classify according to data characteristics, and divide the data into sensitive data and non-sensitive data;

[0013] Standardize the two types of data, set the classification label Lable, and use Lable with different values to label sensitive data and non-sensitive data;

[0014] For the two types of data with classification labels set, take 80% of the data set as the training set and input it into the convolutional neural network for training to obtain a convolutional neural network data classification model.

[0015] Furthermore, during the training process of the convolutional neural network data classification model, use the cross-entropy loss function to judge the error between the actual output and the expected output, and optimize and update the parameters of the convolutional neural network.

[0016] Furthermore, the encryption and storage of sensitive data include:

[0017] Use the SM4 symmetric encryption algorithm to encrypt and store sensitive data.

[0018] Furthermore, the encryption and storage of non-sensitive data include:

[0019] Encrypt to obtain the ciphertext stream in the following way:

[0020] For the hash value of the key stream K i and the plaintext stream M i perform an exclusive OR operation for encryption to obtain the ciphertext stream C i , and the encryption calculation is as follows:

[0021]

[0022] where K i is the key stream for the data encryptor to encrypt the data sent for the i-th time, C i is the ciphertext stream for the data encryptor to encrypt the data sent for the i-th time, C i-1 is the ciphertext stream sent by the data encryptor for the (i - 1)-th time, Hash() represents the hash operation, represents the exclusive OR operation, M i is the plaintext stream for the data encryptor to send for the i-th time, M i-1 is the plaintext stream sent by the data encryptor for the (i - 1)-th time, and Key is the device secret value of the data encryptor;

[0023] The generation of the key stream is as follows:

[0024] When i = 1, take C0 = Hash(IV) and M0 = IV to obtain the key stream: where IV is the initial vector;

[0025] When i > 1,

[0026] Further, the initial vector IV is calculated as follows:

[0027]

[0028] where h1 and h2 are obtained through Hash operations on the device ID of the data encryption device and the device secret value Key in different combination ways;

[0029] The device secret value Key is a string of characters uniformly generated by the data decryption party.

[0030] Further, the storage of sensitive data and non-sensitive data is as follows:

[0031] The encrypted data is stored in the public cloud through the gateway device.

[0032] Further, the identity authentication is performed using the corresponding identity authentication method according to the request level of the stored encrypted data, including:

[0033] Judge the user request level:

[0034] If the request is to read a file from the public cloud, it is level one, then the first-level identity authentication method is used for user identity authentication, and after successful authentication, the user is granted the permission to read the file from the public cloud;

[0035] If the request is to download a file from the public cloud, it is level two, then the second-level identity authentication method is used for user identity authentication, and after successful authentication, the user is granted the permission to download the file from the public cloud;

[0036] If the request is to read / download a file from the private cloud, it is level three, then the third-level identity authentication method is used for user identity authentication, and after successful authentication, the user is granted the permission to read / download the file from the private cloud.

[0037] Further, the first-level identity authentication method is: obtain the user pseudo ID, and judge whether the user's pre-registered information matches the obtained pseudo ID. If it matches, the authentication is passed;

[0038] The second-level identity authentication method is: obtain the user's biometric characteristics, and judge whether the user's pre-registered information matches the obtained user biometric characteristics. If it matches, the authentication is passed;

[0039] The third-level identity authentication method is: obtain the user's biometric characteristics and verification code, and judge whether the user's pre-registered information matches the obtained biometric characteristics. If it matches and the verification code is consistent, the authentication is passed.

[0040] The second aspect of the present invention provides a multi-level security authentication system for a power regulation terminal, including:

[0041] A data classification system for classifying power terminal service data into sensitive data and non-sensitive data;

[0042] A sensitive data encryption system for encrypting sensitive data;

[0043] A non-sensitive data encryption system for encrypting non-sensitive data;

[0044] A multi-level identity authentication system for providing multi-level identity authentication methods and performing identity authentication using the corresponding identity authentication method according to the request level for the stored encrypted data.

[0045] Furthermore, the data classification system is specifically used for

[0046] Constructing a convolutional neural network data classification model to classify power terminal service data into sensitive data and non-sensitive data.

[0047] Furthermore, the sensitive data encryption system is specifically used for

[0048] Using the SM4 symmetric encryption algorithm to encrypt sensitive data.

[0049] Furthermore, the non-sensitive data encryption system is specifically used for

[0050] Encrypting to obtain a ciphertext stream in the following manner:

[0051] Performing an exclusive OR operation on the hash value of the key stream K i and the plaintext stream M i to encrypt and obtain the ciphertext stream C i , and the encryption calculation is as follows:

[0052]

[0053] where K i is the key stream for the data encryptor to encrypt the data sent for the i-th time, C i is the ciphertext stream for the data encryptor to encrypt the data sent for the i-th time, C i-1 is the ciphertext stream sent by the data encryptor for the (i - 1)-th time, Hash() represents the hash operation, represents the exclusive OR operation, M i is the plaintext stream sent by the data encryptor for the i-th time, M i-1 is the plaintext stream sent by the data encryptor for the (i - 1)-th time, and Key is the device secret value of the data encryptor;

[0054] The generation of the key stream is as follows:

[0055] When i = 1, take C0 = Hash(IV) and M0 = IV to obtain the key stream Among them, IV is the initial vector;

[0056] When i > 1,

[0057] The initial vector IV is calculated as follows:

[0058]

[0059] Among them, h1 and h2 are obtained by Hash operations on the data encryption party device ID and the device secret value Key through different combination methods;

[0060] The device secret value Key is a string of characters uniformly generated by the data decryption party.

[0061] Furthermore, the multi-level identity authentication system includes:

[0062] A registration module, used to obtain the user's registration information, including the user ID / password and biometric features; and provide a pseudo ID for each user;

[0063] A judgment module, used to judge the user request level: if it is a request to read a file from the public cloud, it is level one; if it is a request to download a file from the public cloud, it is level two; if it is a request to read / download a file from the private cloud, it is level three;

[0064] A level one identity authentication sub-module, used to obtain the user's pseudo ID, judge whether the user's pre-registered information matches the obtained pseudo ID, if it matches, the authentication passes, and the user is granted the permission to read files from the public cloud; otherwise, the user's request is rejected;

[0065] A level two identity authentication sub-module, used to obtain the user's biometric features, judge whether the user's pre-registered information matches the obtained user biometric features, if it matches, the authentication passes, and the user is granted the permission to download files from the public cloud; otherwise, the user's request is rejected;

[0066] A level three identity authentication sub-module, used to obtain the user's biometric features and verification code, judge whether the user's pre-registered information matches the obtained biometric features, if it matches, and the verification code is consistent, the authentication passes, and the user is granted the permission to read / download files from the private cloud; otherwise, the user's request is rejected.

[0067] The third aspect of the present invention provides a memory storing one or more programs, and the one or more programs include instructions, which when executed by a computing device, cause the computing device to execute any one of the methods according to the foregoing methods.

[0068] The fourth aspect of the present invention provides a device, including,

[0069] One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include instructions for performing any of the methods described above.

[0070] The beneficial effects of the present invention are as follows:

[0071] The present invention proposes a multi-level security authentication method for a power regulation terminal, which is used to solve the problems of high energy consumption and insecurity in power service data transmission. By using the method proposed in the present invention, data theft and tampering can be prevented during data transmission, and secure user access can be achieved, thereby ensuring the secure and efficient transmission of power service data. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] Figure 1 It is an architecture of a multi-level security authentication system for a power regulation terminal provided by an embodiment of the present invention;

[0073] Figure 2 It is a flow chart of a multi-level security authentication method for a power regulation terminal provided by an embodiment of the present invention;

[0074] Figure 3 It is an example of the SM4 algorithm in an embodiment of the present invention;

[0075] Figure 4 It is a schematic diagram of a multi-level identity authentication system in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0076] The present invention will be further described below. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and should not be used to limit the protection scope of the present invention.

[0077] Embodiment 1

[0078] This embodiment provides a multi-level security authentication method for a power regulation terminal, including:

[0079] Classify the power terminal service data into sensitive data and non-sensitive data;

[0080] Encrypt and store the sensitive data and the non-sensitive data respectively;

[0081] Perform identity authentication using a corresponding identity authentication method according to the request level of the stored encrypted data.

[0082] In this embodiment, a data classification model is trained by a convolutional neural network to classify the power terminal service data into sensitive data and non-sensitive data.

[0083] In this embodiment, the SM4 algorithm is used to encrypt sensitive data, and the asymmetric RSA encryption algorithm is combined to update the key regularly to prevent tampering and theft during data transmission.

[0084] In this embodiment, the encrypted data is stored in the public cloud through the gateway device.

[0085] Embodiment 2

[0086] This embodiment provides a multi-level security authentication method for power control terminals. Refer to Figure 2 , including:

[0087] (1) Obtain power terminal service data and perform preprocessing;

[0088] (2) Construct a convolutional neural network data classification model, and use this model to automatically classify the obtained power terminal service data into sensitive data and non-sensitive data;

[0089] (3) Use the SM4 symmetric encryption algorithm to encrypt sensitive data;

[0090] (4) For non-sensitive data, create a lightweight stream encryption scheme key for encryption;

[0091] (5) Store the encrypted data in the cloud;

[0092] (6) Obtain the required data by using multi-level identity authentication.

[0093] In step (1) of this embodiment, the preprocessing of the data includes:

[0094] The data is standardized as follows:

[0095]

[0096] Among them, X ij represents the i-th power terminal data feature collected in period j. The power terminal data features include collected data, operating status data, user electricity consumption data, etc. E(X i ) is the mathematical expectation of the i-th power terminal data feature, S i is the standard deviation of the i-th power terminal data feature, and Z ij is the standardized value of X ij .

[0097] Mark the classification data with Lable, 0, 1.

[0098] In step (2) of this embodiment, the convolutional neural network data classification model is constructed as follows:

[0099] Obtain a large amount of power terminal service data, classify the data according to data characteristics, divide the data into sensitive data and non-sensitive data, perform standardized processing on the two types of data, and set a classification label Lable. Use Lable with different values to label sensitive data and non-sensitive data;

[0100] In this embodiment, set Lable to 0 for non-sensitive data and Lable to 1 for sensitive data;

[0101] For the two types of data with classification labels set, take 80% of the data set as the training set, input it into the convolutional neural network to train the classification model, and use 20% of the data set for testing;

[0102] Use the Softmax function for regression processing to output y', where y' corresponds to the output probabilities of labels 0 and 1;

[0103] Adopt the cross-entropy loss function to judge the error between the actual output and the expected output;

[0104] Through continuous training, obtain a trained convolutional neural network data classification model.

[0105] In step (3) of this embodiment, use the SM4 symmetric encryption algorithm to encrypt sensitive data. For the specific implementation process, refer to Figure 3 , specifically as follows:

[0106] Divide the original data and the encrypted data into 128 bits on average, divide them into four parts, adopt 32 rounds of non-linear iteration, and perform an inverse order transformation in the last time to output the ciphertext.

[0107] In the encryption and decryption processes, the key is the same. The data packets and the key length of the plaintext and the ciphertext are both 128 bits. Both the encryption algorithm and the key expansion algorithm adopt a 32-round non-linear iteration structure.

[0108] Let the plaintext input be The ciphertext output is The round key is X i is composed of consecutive bytes of the plaintext input with a length of 4 bytes.

[0109] The encryption transformation is: X i+4 =F(X i , X i+1 , X i+2 , X i+3 , rk i ),

[0110] Output the ciphertext: (Y0, Y1, Y2, Y3) = R(X 32 , X 33 , X 34 , X 35,)=(X 35 ,X 34 ,X 33 ,X 32 ), where R is the negation operation.

[0111] As a preferred embodiment, during the SM4 encryption process, the RSA asymmetric encryption algorithm is used to update the key regularly to improve the data transmission security level.

[0112] In step (4) of this embodiment, for non-sensitive data, a lightweight stream encryption scheme key is created for encryption. The specific implementation process is as follows:

[0113] The key consists of the device ID and the device secret value Key. The device ID is a unique identification code, and the device secret value Key is a string of characters uniformly generated by the data decrypting party. The device refers to the device that collects non-sensitive data.

[0114] The device ID and the device secret value Key obtain h1 and h2 through the Hash operation of different combination methods, and the initial vector IV is obtained by the exclusive OR of h1 and h2;

[0115]

[0116] The encrypting party encrypts the plaintext stream M i by performing an exclusive OR operation on the hash value of the key stream K i to obtain the ciphertext stream C i , and transmits the ciphertext stream C i . The specific encryption algorithm formula is as follows:

[0117]

[0118] Among them, the generation of the key stream is divided into two cases:

[0119] (a) When i = 1, it means that the data encrypting party initially sends a message to the data decrypting party. At this time, take C0 = Hash(IV) and M0 = IV to obtain the key stream

[0120] (b) When i > 1, it means that the device data encrypting party sends a message to the data decrypting party non-initially. At this time, take the ciphertext stream C i-1 and the plaintext stream M i-1 sent last and perform operations to obtain the key stream K i .

[0121] In this embodiment, a multi-level identity authentication method is adopted to obtain the required data. See Figure 4 , including:

[0122] Judge the user request level:

[0123] If the request is to read a file from the public cloud, it is of the first level, and the first-level identity authentication method is used for user identity authentication. After successful authentication, the user is granted the permission to read files from the public cloud.

[0124] If the request is to download a file from the public cloud, it is of the second level, and the second-level identity authentication method is used for user identity authentication. After successful authentication, the user is granted the permission to download files from the public cloud.

[0125] If the request is to read / download a file from the private cloud, it is of the third level, and the third-level identity authentication method is used for user identity authentication. After successful authentication, the user is granted the permission to read / download files from the private cloud.

[0126] The first-level identity authentication method is that the user sends a pseudo ID to the trusted institution, and the trusted institution determines whether the user's pre-registered information matches the provided pseudo ID information. If they match, the authentication is successful.

[0127] The second-level identity authentication method is that the user sends biometric features to the trusted institution, and the trusted institution determines whether the user's pre-registered information matches the provided biometric feature information. If they match, the authentication is successful.

[0128] The third-level identity authentication method is that the user sends a credential including biometric features and a verification code to the trusted institution. The trusted institution determines whether the user's pre-registered information matches the obtained biometric features. If they match and the verification code is consistent, the authentication is successful.

[0129] In this embodiment, the user's biometric feature is a fingerprint.

[0130] Embodiment 3

[0131] This embodiment provides a multi-level security authentication system for power regulation terminals. Refer to Figure 1 , including:

[0132] Data classification system: used to classify power terminal service data into sensitive data and non-sensitive data;

[0133] Sensitive data encryption system: used to encrypt sensitive data;

[0134] Non-sensitive data encryption system: used to encrypt non-sensitive data;

[0135] Multi-level identity authentication system: used to provide multi-level identity authentication methods, and perform identity authentication using the corresponding identity authentication method according to the request level for the stored encrypted data.

[0136] In this embodiment, the data classification system is used to build a convolutional neural network data classification model to classify power terminal service data into sensitive data and non-sensitive data.

[0137] In this embodiment, the data classification system is specifically used for

[0138] obtaining a large amount of power terminal service data, classifying the data according to data characteristics, dividing the data into sensitive data and non-sensitive data, performing standardization processing on the two types of data, setting a classification label Lable, and using Lable with different values to label sensitive data and non-sensitive data;

[0139] In this embodiment, Lable is set to 0 for non-sensitive data and Lable is set to 1 for sensitive data;

[0140] For the two types of data with classification labels set, 80% of the data set is used as the training set, input into a convolutional neural network to train a classification model, and 20% of the data set is used for testing;

[0141] Using the Softmax function to perform regression processing on the output y', where y' corresponds to the output probabilities of labels 0 and 1;

[0142] Adopting a cross-entropy loss function to judge the error between the actual output and the expected output;

[0143] Through continuous training, a trained convolutional neural network data classification model is obtained.

[0144] In this embodiment, the sensitive data encryption system is used to encrypt sensitive data using the SM4 symmetric encryption algorithm.

[0145] In this embodiment, the sensitive data encryption system is also used to periodically update the key using the RSA asymmetric encryption algorithm during the SM4 encryption process to improve the data transmission security level.

[0146] In this embodiment, the non-sensitive data encryption system is used for

[0147] For non-sensitive data, using the HASH encoding to convert the timestamp into a character and marking the data;

[0148] Creating a lightweight encryption scheme to generate a key, where the key consists of the device ID and the device secret value Key. The device ID is a unique identification code, and the device secret value Key is a string of characters uniformly generated by the data decrypting party;

[0149] By performing an exclusive OR operation on the hash value of the key stream K i and the plaintext stream M i to encrypt and obtain the ciphertext stream C i , and transmitting the ciphertext stream C i , and the encryption algorithm formula is as follows:

[0150]

[0151] where the key stream There are two cases for its generation:

[0152] (a) When i = 1, it means that the data encrypting party initially sends a message to the data decrypting party. At this time, take C0 = Hash(IV) and M0 = IV to obtain the key stream

[0153] (b) When i > 1, it means that the device data encrypting party is not initially sending a message to the data decrypting party. At this time, take the ciphertext stream C i-1 and the plaintext stream M i-1 through operations to obtain the key stream K i ;

[0154] Among them,

[0155] the device ID and the device secret value Key are obtained as h1 and h2 through Hash operations with different combination methods, and the initial vector IV is obtained by XORing h1 and h2;

[0156]

[0157] In this embodiment, the multi-level identity authentication system includes:

[0158] A registration module, used to obtain the user's registration information, including the user ID / password and biometric features; and provide a pseudo ID for each user;

[0159] A judgment module, used to judge the user request level: If it is a request to read a file from the public cloud, it is level one; if it is a request to download a file from the public cloud, it is level two; if it is a request to read / download a file from the private cloud, it is level three;

[0160] A level one identity authentication sub-module, used to obtain the user's pseudo ID, judge whether the user's pre-registered information matches the obtained pseudo ID. If it matches, the authentication passes, and the user is granted the permission to read files from the public cloud; otherwise, the user's request is rejected;

[0161] A level two identity authentication sub-module, used to obtain the user's biometric features, judge whether the user's pre-registered information matches the obtained user biometric features. If it matches, the authentication passes, and the user is granted the permission to download files from the public cloud; otherwise, the user's request is rejected;

[0162] A level three identity authentication sub-module, used to obtain the user's biometric features and verification code, judge whether the user's pre-registered information matches the obtained biometric features. If it matches and the verification code is consistent, the authentication passes, and the user is granted the permission to read / download files from the private cloud; otherwise, the user's request is rejected.

[0163] Embodiment 4

[0164] This embodiment provides a memory for storing one or more programs, where the one or more programs include instructions that, when executed by a computing device, cause the computing device to execute any one of the multi-level security authentication methods for power control terminals according to Embodiment 1 or Embodiment 2.

[0165] Embodiment 5

[0166] This embodiment provides a device, including one or more processors, a memory, and one or more programs, where the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include instructions for executing any one of the multi-level security authentication methods for power control terminals according to Embodiment 1 or Embodiment 2.

[0167] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0168] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0169] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0170] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or a plurality of processes and / or blocks Figure 1 one process or a plurality of processes and / or blocks Figure 1 steps for implementing the functions specified in one block or a plurality of blocks.

[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific embodiments of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. A multi-level security authentication method for a power regulation terminal, characterized in that Including: Classify the power terminal service data into sensitive data and non-sensitive data; Encrypt and store the sensitive data and the non-sensitive data respectively; Among them, encrypting and storing the non-sensitive data includes: For the key stream K i and the plaintext stream M i perform an exclusive-or operation to encrypt and obtain the ciphertext stream C i , the encryption calculation is as follows: Among them, K i is the key stream for the data encryptor to encrypt the data sent for the i-th time, and C i is the ciphertext stream obtained by the data encryptor encrypting the data sent for the i-th time. C i-1 is the ciphertext stream sent by the data encryptor for the (i - 1)-th time. Hash() represents the hashing operation, represents the exclusive-or operation, and M i is the plaintext stream sent by the data encryptor for the i-th time. M i-1 is the plaintext stream sent by the data encryptor for the (i - 1)-th time. Key is the device secret value of the data encryptor; Key stream is generated as follows: When i = 1, take C0 = Hash(IV) and M0 = IV to obtain the key stream: where IV is the initial vector; When i > 1, The initial vector IV is calculated as follows: Wherein, h1 and h2 are obtained by Hash operations on the device ID of the data encryption party and the device secret value Key in different combination ways; The device secret value Key is a string of characters uniformly generated by the data decryption party; Perform identity authentication using the corresponding identity authentication method according to the request level of the stored encrypted data.

2. A multi-level security authentication method for a power regulation terminal according to claim 1, characterized in that, The classifying the power terminal service data into sensitive data and non-sensitive data includes: Use a pre-constructed convolutional neural network data classification model to classify the power terminal service data into sensitive data and non-sensitive data.

3. A multi-level security authentication method for a power regulation terminal according to claim 2, characterized in that, The convolutional neural network data classification model is constructed as follows: Obtain historical power terminal service data, classify the data according to data characteristics, and divide the data into sensitive data and non-sensitive data; Perform normalization processing on the two types of data, and set a classification label Lable, and use different values of Lable to label sensitive data and non-sensitive data; For the two types of data with classification labels set, take 80% of the data set as the training set, and input it into the convolutional neural network for training to obtain the convolutional neural network data classification model.

4. A multi-level security authentication method for a power regulation terminal according to claim 3, characterized in that, During the training process of the convolutional neural network data classification model, use the cross-entropy loss function to judge the error between the actual output and the expected output, and optimize and update the parameters of the convolutional neural network.

5. A multi-level security authentication method for a power regulation terminal according to claim 1, characterized in that Encrypt and store the sensitive data, including: Use the SM4 symmetric encryption algorithm to encrypt and store the sensitive data.

6. The multi-level security authentication method for a power regulation terminal according to claim 1, wherein The storage of the sensitive data and the non-sensitive data is: Store the encrypted data in the public cloud through the gateway device.

7. A multi-level security authentication method for a power regulation terminal according to claim 6, characterized in that, The performing identity authentication using the corresponding identity authentication method according to the request level of the stored encrypted data includes: Judge the user request level: If it is a request to read a file from the public cloud, it is the first level, then use the first-level identity authentication method to perform user identity authentication, and grant the user the permission to read the file from the public cloud after successful authentication; If it is a request to download a file from the public cloud, it is the second level, then use the second-level identity authentication method to perform user identity authentication, and grant the user the permission to download the file from the public cloud after successful authentication; If it is a request to read / download a file from the private cloud, it is the third level, then use the third-level identity authentication method to perform user identity authentication, and grant the user the permission to read / download the file from the private cloud after successful authentication.

8. According to the method for multi-level security authentication of a power regulation terminal described in claim 7, characterized in that The first-level identity authentication method is: obtain the user pseudo ID, and judge whether the user's pre-registered information matches the obtained pseudo ID. If it matches, the authentication is passed; The second-level identity authentication method is: obtain the user's biometric characteristics, and judge whether the user's pre-registered information matches the obtained user biometric characteristics. If it matches, the authentication is passed; The third-level identity authentication method is: obtain the user's biometric characteristics and verification code, and judge whether the user's pre-registered information matches the obtained biometric characteristics. If it matches and the verification code is consistent, the authentication is passed.

9. A multi-level security authentication system for a power regulation terminal, characterized in that, For implementing the multi-level security authentication method of the power regulation terminal described in any one of claims 1 to 8, the system includes: A data classification system for classifying power terminal service data into sensitive data and non-sensitive data; A sensitive data encryption system for encrypting sensitive data; A non-sensitive data encryption system for encrypting non-sensitive data, specifically encrypting to obtain a ciphertext stream in the following manner: For the key stream K i and the hash value of the plaintext stream M i perform an exclusive OR operation for encryption to obtain the ciphertext stream C i , and the encryption calculation is as follows: Among them, K i is the key stream for the data encryptor to encrypt the data sent in the i-th time, C i is the ciphertext stream obtained by the data encryptor encrypting the data sent in the i-th time, C i-1 is the ciphertext stream sent by the data encryptor in the (i - 1)-th time, Hash() represents the hashing operation, represents the exclusive OR operation, M i is the plaintext stream sent by the data encryptor in the i-th time, M i-1 is the plaintext stream sent by the data encryptor in the (i - 1)-th time, Key is the device secret value of the data encryptor; Key stream is generated as follows: When i = 1, take C0 = Hash(IV) and M0 = IV to obtain the key stream where IV is the initial vector; When i > 1, The initial vector IV is calculated as follows: Where h1 and h2 are obtained by Hash operations on the device ID and device secret value Key of the data encryption party in different combination ways; The device secret value Key is a string of characters uniformly generated by the data decryption party; A multi-level identity authentication system for providing multi-level identity authentication methods and performing identity authentication using the corresponding identity authentication method according to the request level for the stored encrypted data.

10. A multi-level security authentication system for a power regulation terminal according to claim 9, characterized in that, Specifically, the data classification system is used for Constructing a convolutional neural network data classification model to classify power terminal service data into sensitive data and non-sensitive data.

11. The multi-level security authentication system for a power regulation terminal according to claim 9, characterized in that, Specifically, the sensitive data encryption system is used for Encrypting sensitive data using the SM4 symmetric encryption algorithm.

12. A multi-level security authentication system for a power regulation terminal according to claim 9, characterized in that, The multi-level identity authentication system includes: A registration module for obtaining the user's registration information, including the user ID / password and biometric features; and providing a pseudo ID for each user; A judgment module for judging the user request level: If it is a request to read a file from the public cloud, it is level one; if it is a request to download a file from the public cloud, it is level two; if it is a request to read / download a file from the private cloud, it is level three; A first-level identity authentication sub-module for obtaining the user's pseudo ID and judging whether the user's pre-registered information matches the obtained pseudo ID. If it matches, the authentication passes and the user is granted the permission to read files from the public cloud; otherwise, the user's request is rejected; A second-level identity authentication sub-module for obtaining the user's biometric features and judging whether the user's pre-registered information matches the obtained user biometric features. If it matches, the authentication passes and the user is granted the permission to download files from the public cloud; otherwise, the user's request is rejected; A third-level identity authentication sub-module for obtaining the user's biometric features and verification code, and judging whether the user's pre-registered information matches the obtained biometric features. If it matches and the verification code is consistent, the authentication passes and the user is granted the permission to read / download files from the private cloud; otherwise, the user's request is rejected.

13. A memory for storing one or more programs, characterized in that, The one or more programs include instructions that, when executed by a computing device, cause the computing device to execute any one of the methods described in claims 1 to 8.

14. A device, characterized in that, Including One or more processors, a memory, and one or more programs, where the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include instructions for executing any one of the methods described in claims 1 to 8.

Citation Information

Patent Citations

  • Active power distribution network big data transmission method based on behavior marking and lightweight encryption

    CN111934437A