Security communication method and device based on 5g virtual private network slice and storage medium

By employing a lightweight secondary authentication method in 5G virtual private network slices, which combines physical non-cloning functions, hash calculations, and XOR calculations with high-performance symmetric and asymmetric encryption algorithms using shuffling coding, the problems of high computational overhead and data isolation in power control services are solved, achieving low-latency and highly reliable secure communication.

CN115567219BActive Publication Date: 2026-03-27GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +3
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-22
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing 5G virtual private network slicing has problems such as high computational overhead for secondary authentication and inability to achieve data isolation during data transmission in power dispatching services, which cannot meet the requirements of low latency and high reliability for power dispatching services.

Method used

A lightweight secondary authentication method based on physical non-cloning functions, hash calculation, and XOR calculation is adopted, and data encryption is performed through a hybrid form of high-performance symmetric algorithm, asymmetric algorithm, and hash algorithm using shuffling encoding, thereby achieving data isolation and encryption/decryption.

Benefits of technology

It achieves low-complexity secondary authentication, ensuring the real-time performance and security of power dispatching services, reducing network rental costs, improving the effectiveness and security of data encryption and decryption, and meeting the low-latency and high-reliability requirements of power dispatching services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567219B_ABST
    Figure CN115567219B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on 5G virtual private network slice security communication method, device and storage medium, comprising: based on physical unclonable function, hash calculation and XOR calculation with power business server between lightweight secondary authentication;When secondary authentication passes, communication data transmission between with power business server, data is the encrypted ciphertext obtained by high-performance symmetric algorithm on plaintext message based on shuffle coding, the secret key ciphertext obtained by public key of asymmetric algorithm on secret key of high-performance symmetric algorithm, and the plaintext digest obtained by hash algorithm on plaintext message.It is reduced that the secondary authentication duration is reduced by using the lightweight secondary authentication method without PKI and bilinear mapping calculation by implementing the application.The effectiveness of symmetric cryptographic algorithm and the security of asymmetric cryptography are used to securely and efficiently transmit data.The network rental cost is reduced, and the real-time and security requirements of power regulation business are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and specifically to a secure communication method, device, and storage medium based on 5G virtual private network slicing. Background Technology

[0002] With the continuous development of my country's power system, power services are exhibiting new characteristics. Power control services, typically represented by distributed energy regulation, precise load control, distribution network area protection, and distribution network automation, require more stringent millisecond-level low-latency transmission and ultra-high reliability exceeding 99.99%. Traditional 4G networks are no longer sufficient to support the continued development of power control services. 5G Virtual Private Networks (VPNs), by virtualizing a dedicated network for the power industry within the 5G networks of telecom operators based on technologies such as network slicing, have become a new way to support power control services due to their powerful customizability.

[0003] However, carrying power control services via 5G virtual private network (VPN) slicing still presents many significant challenges. In terms of communication performance, ensuring the communication requirements of control services relies on slice isolation technology. However, because the slice granularity currently supported by power VPNs is relatively large (above 1G), while the service data granularity of power control services is relatively small, multiple soft slices need to be divided within a single hard slice for economic reasons. The soft slice solution is based on existing network mechanisms, using a mapping between Virtual Local Area Network (VLAN) tags and network slice identifiers. Although the soft slice isolation method distinguishes different slice data by VLAN, all slice data tagged with VLANs are still mixed and scheduled for forwarding, failing to achieve hardware and time slot-level isolation. In logically isolated bearer network slices, an attack on one slice may consume resources from other slices, leading to resource shortages and causing other virtual slices in the same physical pipeline to malfunction. Therefore, more secure safeguards are needed to ensure the security of soft slices.

[0004] Regarding data security at the main business station, power terminals connect to the control business data main station via a 5G virtual private network. To prevent unauthorized terminals from accessing the main station data, secondary authentication is required after the power terminal completes primary authentication on the 5G network to confirm its access rights to the data main station. Most existing secondary authentication methods are based on user passwords or public-key cryptography. User passwords are easily leaked or cracked, causing security issues. While public-key cryptography can ensure access security, it also incurs significant computational overhead and cannot meet the ultra-low latency requirements of control services.

[0005] Based on the above analysis, there are two key issues that urgently need to be addressed when using 5G virtual private networks to carry power dispatching services. First, a lightweight secondary authentication method needs to be proposed while maintaining security. Second, a data isolation method needs to be proposed to ensure data isolation between different soft slices within the same hard slice, in order to meet the low latency and high reliability requirements of power dispatching services. Summary of the Invention

[0006] In view of this, embodiments of the present invention provide a secure communication method, apparatus and storage medium based on 5G virtual private network slicing, to solve the technical problems of high computational overhead of secondary authentication and inability to achieve data isolation during data transmission in the prior art.

[0007] The technical solution proposed in this invention is as follows:

[0008] The first aspect of this invention provides a secure communication method based on 5G virtual private network slicing, applied to a power terminal. The secure communication method includes: performing lightweight secondary authentication between the power service server and a physical non-cloning function, hash calculation, and XOR calculation; after successful secondary authentication, transmitting communication data with the power service server, wherein the transmitted communication data consists of encrypted ciphertext obtained by encrypting plaintext messages using a high-performance symmetric algorithm based on shuffling coding, key ciphertext obtained by encrypting the key of the high-performance symmetric algorithm using the public key of an asymmetric algorithm, and a plaintext digest obtained by calculating the plaintext message using a hash algorithm.

[0009] Optionally, a lightweight secondary authentication is performed between the power business server and the system based on a physically unclonable function, hash calculation, and XOR calculation. This includes: identity authentication between the power business server and the system based on a hash calculation of the system's own identity information based on a physically unclonable function; and time authentication between the power business server and the system based on hash calculation and XOR calculation after successful identity authentication.

[0010] Optionally, identity authentication between the user and the power service server is performed based on a hash calculation of the physical unclonable function and the user's own identity information, including: sending a first hash value and a random number of the user's own identity information to the power service server; receiving a second hash value, a second random number, and a first input of the physical unclonable function corresponding to the first hash value sent by the power service server after successful identity authentication based on the hash value, wherein the second hash value is obtained by hash calculation based on the first output, the first random number, and the second random number of the physical unclonable function corresponding to the first hash value; calculating a third hash value of the second output, the first random number, and the second random number of the physical unclonable function corresponding to the first input; and when the third hash value is equal to the second hash value, the identity authentication is successful.

[0011] Optionally, time authentication between the power service server and the power service server is performed based on hash calculation and XOR calculation, including: sending the calculated third random number and the first XOR value of the second output, the calculated self-identity information and the fourth hash value of the second output, and the first time to the power service server; receiving the second XOR value of the fourth random number and the fifth random number and the fifth hash value of the third random number and the fourth random number sent by the power service server, wherein the fifth random number is the hash value of the first output, the third random number, and the second output calculated by the power service server when it determines that the received fourth hash value and the calculated identity information of the power terminal and the fifth hash value of the first output are equal; the second XOR value and the fifth hash value are the difference between the first time determined by the power service server and the second time of receiving the first time is less than a threshold, and the fifth random number, the first output, and the first time are equal. The output is generated when the hash values ​​of the time, the second random number, the third random number, the second output, the first time, and the second random number are equal; the hash values ​​of the fourth, fifth, and sixth random numbers are calculated to see if they are equal to the hash values ​​of the fourth and third random numbers, where the sixth random number is the XOR value calculated based on the third, fourth, and fifth random numbers; when they are equal, the third input and the third output are determined based on the hash values ​​of the third and sixth random numbers and the physical non-cloning function, and the hash value of the third output is sent to the power service server; an authentication success message is received from the power service server; the authentication success message is generated when the power service server inputs the hash values ​​of the fifth and fourth random numbers into the physical non-cloning function to obtain the fourth output, and the hash value of the fourth output is equal to the hash value of the third output.

[0012] Optionally, after the secondary authentication is successful, communication data is transmitted between the server and the power business server. The transmitted communication data consists of encrypted ciphertext obtained by encrypting the plaintext message using a high-performance symmetric algorithm based on shuffling coding, key ciphertext obtained by encrypting the key of the high-performance symmetric algorithm using the public key of the asymmetric algorithm, and plaintext digest obtained by calculating the plaintext message using a hash algorithm. The process includes: after successful secondary authentication, encrypting the plaintext message of the business data using a high-performance symmetric algorithm based on shuffling coding to obtain a first encrypted ciphertext; encrypting the key of the high-performance symmetric algorithm using the public key of an asymmetric algorithm to obtain a first key ciphertext; and calculating a first plaintext digest using a hash algorithm. The first encrypted ciphertext, the first key ciphertext, and the first plaintext digest are then sent to the power business server. Alternatively, after successful secondary authentication, receiving a second encrypted ciphertext, a second key ciphertext, and a second plaintext digest from the power business server; decrypting the second key ciphertext using the private key of an asymmetric algorithm to obtain a high-performance key; decrypting the second encrypted ciphertext using the high-performance key to obtain a plaintext message; decrypting the plaintext message obtained by the hash algorithm to obtain a third plaintext digest; comparing the second plaintext digest and the third plaintext digest; and outputting the decrypted plaintext message if they are the same.

[0013] Optionally, a high-performance symmetric algorithm based on shuffling encoding is used to encrypt the plaintext message of the business data to obtain the first encrypted ciphertext, including: generating a seventh random number, an eighth random number, a ninth random number, and a tenth random number; generating an encoding table by performing factorial operations on the eighth and ninth random numbers; performing plaintext shuffling encoding on the plaintext message of the business data based on the column corresponding to the tenth random number in the encoding table; and replacing the plaintext shuffling encoded data based on the seventh random number and the encoding table to obtain the encrypted ciphertext, wherein the seventh, eighth, ninth, and tenth random numbers constitute the high-performance key.

[0014] Optionally, generating an encoding table based on the coefficients of the factorial sequence corresponding to the eighth random number and the ratio of the eighth random number to the ninth random number includes: performing factorial operations on the eighth random number and a preset arrangement to obtain a first arrangement of the preset arrangement; performing factorial operations on the first arrangement using the rounded value of the ratio of the eighth random number and the ninth random number and the first arrangement to obtain a second arrangement of the first arrangement; performing factorial operations on the second arrangement using the rounded value of the ratio and the second arrangement to obtain a third arrangement of the second arrangement; performing factorial operations on the third arrangement using the rounded value of the ratio and the third arrangement to obtain a fourth arrangement of the third arrangement; repeating the factorial operation process to obtain a fifth, sixth, seventh, eighth, and ninth arrangement; and generating an encoding table based on the first to ninth arrangements.

[0015] Optionally, performing factorial operations based on the eighth random number and the preset arrangement to obtain the first arrangement of the preset arrangement includes: factoring the eighth random number to obtain the factorial coefficient data; and selecting the corresponding character in the preset arrangement based on the coefficient data to form the first arrangement of the preset arrangement.

[0016] Optionally, the high-performance key is used to decrypt the second encrypted ciphertext to obtain a plaintext message, including: receiving the high-performance key; generating an encoding table based on the high-performance key and the high-performance symmetric algorithm; and performing reverse substitution and reverse plaintext shuffling based on the encoding table and the second encrypted ciphertext to obtain the plaintext message.

[0017] A second aspect of this invention provides a secure communication device based on 5G virtual private network slicing, applied to a power terminal. The secure communication device includes: an authentication module for performing lightweight secondary authentication with a power service server based on a physical non-cloning function, hash calculation, and XOR calculation; and a data transmission module for transmitting communication data with the power service server after successful secondary authentication. The transmitted communication data consists of encrypted ciphertext obtained by encrypting plaintext messages using a high-performance symmetric algorithm based on shuffling coding, key ciphertext obtained by encrypting the key of the high-performance symmetric algorithm using the public key of an asymmetric algorithm, and a plaintext digest obtained by calculating the plaintext message using a hash algorithm.

[0018] Optionally, the authentication module includes: a first authentication module for identity authentication with the power business server based on a hash calculation of the physical non-clonable function and its own identity information; and a second authentication module for time authentication with the power business server based on hash calculation and XOR calculation after successful identity authentication.

[0019] Optionally, the first authentication module is specifically configured to: send a first hash value and a random number of its own identity information to the power business server; receive a second hash value, a second random number, and a first input of the physical unclonable function corresponding to the first hash value sent by the power business server after successful identity authentication based on the hash value, wherein the second hash value is obtained by hash calculation based on the first output, the first random number, and the second random number of the physical unclonable function corresponding to the first hash value; calculate a third hash value of the second output, the first random number, and the second random number of the physical unclonable function corresponding to the first input; and when the third hash value is equal to the second hash value, the identity authentication is successful.

[0020] Optionally, the second authentication module is specifically configured to: send the calculated third random number and the first XOR value of the second output, the calculated self-identity information and the fourth hash value of the second output, and the first time to the power service server; receive the second XOR value of the fourth random number and the fifth random number and the fifth hash value of the third random number and the fourth random number sent by the power service server, wherein the fifth random number is the hash value of the first output, the third random number, and the second output calculated by the power service server when it determines that the received fourth hash value, the calculated identity information of the power terminal, and the fifth hash value of the first output are equal; the second XOR value and the fifth hash value are the difference between the first time determined by the power service server and the second time of receiving the first time being less than a threshold, and the fifth random number, the first output, the first time, and the second random number are also considered to be equal. The output is generated when the hash value of the first random number is equal to the hash values ​​of the third random number, the second output, the first time, and the second random number; the hash values ​​of the fourth random number, the fifth random number, and the sixth random number are calculated to see if they are equal to the hash values ​​of the fourth random number and the third random number, wherein the sixth random number is the XOR value calculated based on the third random number, the fourth random number, and the fifth random number; when they are equal, the third input and the third output are determined based on the hash values ​​of the third random number, the sixth random number, and the physical unclonable function, and the hash value of the third output is sent to the power service server; the authentication success message is received from the power service server; the authentication success message is generated when the power service server inputs the hash values ​​of the fifth random number and the fourth random number into the physical unclonable function to obtain the fourth output, and the hash value of the fourth output is equal to the hash value of the third output.

[0021] Optionally, the data transmission module includes: an encryption module, configured to, after successful secondary authentication, encrypt the plaintext message of the business data using a high-performance symmetric algorithm based on shuffling coding to obtain a first encrypted ciphertext, encrypt the key of the high-performance symmetric algorithm using the public key of an asymmetric algorithm to obtain a first key ciphertext, and calculate a first plaintext digest using a hash algorithm; a first transmission module, configured to send the first encrypted ciphertext, the first key ciphertext, and the first plaintext digest to the power business server; or, it includes: a second transmission module, configured to, after successful secondary authentication, receive the second encrypted ciphertext, the second key ciphertext, and the second plaintext digest sent by the power business server; a decryption module, configured to decrypt the second key ciphertext using the private key of an asymmetric algorithm to obtain a high-performance key, decrypt the second encrypted ciphertext using the high-performance key to obtain a plaintext message, and decrypt the plaintext message obtained by using a hash algorithm to obtain a third plaintext digest; and a comparison module, configured to compare the second plaintext digest and the third plaintext digest, and output the decrypted plaintext message when they are the same.

[0022] Optionally, the encryption module is specifically used to: generate a seventh random number, an eighth random number, a ninth random number, and a tenth random number; generate an encoding table by performing factorial operations on the eighth and ninth random numbers; perform plaintext shuffling encoding on the plaintext message of the business data based on the column corresponding to the tenth random number in the encoding table; and replace the plaintext shuffling encoded data based on the seventh random number and the encoding table to obtain encrypted ciphertext, wherein the seventh, eighth, ninth, and tenth random numbers constitute the high-performance key.

[0023] Optionally, generating an encoding table based on the coefficients of the factorial sequence corresponding to the eighth random number and the ratio of the eighth random number to the ninth random number includes: performing factorial operations on the eighth random number and a preset arrangement to obtain a first arrangement of the preset arrangement; performing factorial operations on the first arrangement using the rounded value of the ratio of the eighth random number and the ninth random number and the first arrangement to obtain a second arrangement of the first arrangement; performing factorial operations on the second arrangement using the rounded value of the ratio and the second arrangement to obtain a third arrangement of the second arrangement; performing factorial operations on the third arrangement using the rounded value of the ratio and the third arrangement to obtain a fourth arrangement of the third arrangement; repeating the factorial operation process to obtain a fifth, sixth, seventh, eighth, and ninth arrangement; and generating an encoding table based on the first to ninth arrangements.

[0024] Optionally, performing factorial operations based on the eighth random number and the preset arrangement to obtain the first arrangement of the preset arrangement includes: factoring the eighth random number to obtain the factorial coefficient data; and selecting the corresponding character in the preset arrangement based on the coefficient data to form the first arrangement of the preset arrangement.

[0025] Optionally, the decryption module is specifically used for: receiving a high-performance key; generating an encoding table based on the high-performance key and the high-performance symmetric algorithm; and performing reverse substitution and reverse plaintext shuffling based on the encoding table and the second encrypted ciphertext to obtain a plaintext message.

[0026] A third aspect of the present invention provides a computer-readable storage medium storing computer instructions for causing the computer to perform a secure communication method based on 5G virtual private network slicing as described in the first aspect and any one of the first aspects of the present invention.

[0027] A fourth aspect of the present invention provides an electronic device, including: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the secure communication method based on 5G virtual private network slicing as described in the first aspect and any one of the first aspects of the present invention.

[0028] The technical solution provided by this invention has the following effects:

[0029] The secure communication method, apparatus, and storage medium based on 5G virtual private network (VPN) slicing provided in this invention, in terms of secondary authentication, verifies the identities of both parties through a physically unclonable function, hides important data based on XOR calculation, and ensures data integrity based on hash calculation, avoiding the use of PKI and other infrastructure and complex encryption / decryption algorithms, thus ensuring security while achieving low-complexity, lightweight secondary authentication, guaranteeing the real-time and security requirements of power control services. Regarding data isolation in the soft slice, a hybrid cryptographic algorithm based on high-performance symmetric, asymmetric, and hash algorithms is used, significantly improving the effectiveness of data encryption and decryption while ensuring the security of business data and the symmetric key, saving encryption and decryption time. Simultaneously, a high-performance symmetric cryptographic algorithm based on shuffling encoding is used for the encryption and decryption of control service data, achieving higher security and effectiveness than traditional symmetric cryptographic algorithms. The key of the improved cryptographic algorithm is asymmetric encrypted before being transmitted to the receiver, ensuring the security of the symmetric key. Furthermore, a hash algorithm is used to calculate the plaintext digest, ensuring the integrity of the business data.

[0030] The secure communication method, apparatus, and storage medium based on 5G virtual private network (VPN) slicing provided in this invention, through soft slicing technology and a secure and efficient hybrid cryptographic method, can effectively reduce network leasing costs compared to leasing 5G hard slice channels, while ensuring the real-time and security requirements of power regulation services. In the hybrid cryptographic algorithm, a symmetric cryptographic algorithm based on shuffling coding is used, which can effectively hide the connection between plaintext and ciphertext. The highly randomized coding scheme ensures its security against specific plaintext attacks and brute-force attacks. Furthermore, the encryption and decryption process can be completed without complex bilinear mapping calculations, so its effectiveness is far greater than that of classic symmetric cryptographic algorithms. Attached Figure Description

[0031] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0032] Figure 1 This is a flowchart of a secure communication method based on 5G virtual private network slicing according to an embodiment of the present invention;

[0033] Figure 2 This is a flowchart of encryption and decryption according to an embodiment of the present invention;

[0034] Figure 3 This is a flowchart of secondary authentication according to an embodiment of the present invention;

[0035] Figure 4 This is a schematic diagram of the encoding table generated according to an embodiment of the present invention;

[0036] Figure 5 This is a structural block diagram of a secure communication device based on 5G virtual private network slicing according to an embodiment of the present invention;

[0037] Figure 6 This is a schematic diagram of the structure of a computer-readable storage medium provided according to an embodiment of the present invention;

[0038] Figure 7 This is a schematic diagram of the structure of an electronic device provided according to an embodiment of the present invention. Detailed Implementation

[0039] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0040] The terms "first," "second," "third," "fourth," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0041] As described in the background section, traditional lightweight two-factor authentication methods rely on user passwords or public-key cryptography as credentials. Password credentials are vulnerable to dictionary attacks, and public-key cryptography-based authentication processes involve complex bilinear mapping calculations and PKI infrastructure, leading to unnecessary latency. Therefore, a lightweight two-factor authentication scheme that does not use PKI or similar infrastructure and requires minimal computation is needed. Furthermore, while maintaining low computational cost, it should effectively prevent illegal attacks such as replay attacks, dictionary attacks, simulated server attacks, and man-in-the-middle attacks.

[0042] In terms of data isolation between soft slices, various data encryption methods are currently widely used to achieve both the economy of soft isolation and the encryption security of communication. To avoid potential vulnerabilities in a single cryptographic algorithm, the industry often adopts a hybrid encryption approach to encrypt transmitted data. An effective hybrid approach is to use a low-complexity symmetric cryptographic algorithm to encrypt relatively large volumes of control and regulation business data, while simultaneously using a relatively complex asymmetric cryptographic algorithm to encrypt the key of a small symmetric algorithm, thus preventing potential leakage of the symmetric algorithm key during transmission. The main computational load and complexity of this encryption method come from the symmetric cryptographic algorithm. However, given the practical requirements of low latency and high reliability in power control and regulation services, the computational complexity of currently popular algorithms such as AES, DES, and SM4 is relatively high. Therefore, it is necessary to propose more secure and efficient symmetric cryptographic algorithms to achieve higher security and greater effectiveness than classic symmetric algorithms.

[0043] In view of this, embodiments of the present invention provide a secure communication method based on 5G virtual private network slicing. This method employs lightweight secondary authentication with a power service server based on a physically unclonable function, hash calculation, and XOR calculation. After successful secondary authentication, communication data is transmitted with the power service server. The transmitted data consists of encrypted ciphertext obtained by encrypting plaintext messages using a high-performance symmetric algorithm based on shuffling coding, key ciphertext obtained by encrypting the key of the high-performance symmetric algorithm using the public key of an asymmetric algorithm, and a plaintext digest calculated using a hash algorithm. This combination of soft-slice isolation technology, lightweight secondary authentication method, and secure and efficient hybrid encryption method effectively reduces network rental costs while fully ensuring the real-time performance and security requirements of power control services.

[0044] According to an embodiment of the present invention, a secure communication method based on 5G virtual private network slicing is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0045] This embodiment provides a secure communication method based on 5G virtual private network slicing, applied to power terminals. Figure 1 This is a flowchart of a secure communication method based on 5G virtual private network slicing according to an embodiment of the present invention, as shown below. Figure 1 As shown, the method includes the following steps:

[0046] Step S101: Lightweight secondary authentication is performed between the power terminal and the power service server based on a physically unclonable function, hash calculation, and XOR calculation. It should be noted that before secondary authentication, the power terminal first accesses the 5G virtual private network for identity and slice authentication. This authentication process is implemented using existing industry standards and will not be elaborated further. The physically unclonable function uses its inherent physical structure to uniquely identify itself; any input stimulus will output a unique and unpredictable response. Therefore, the physically unclonable function can also be called a mathematical equation. During the secondary authentication process, the same mathematical equation, or physically unclonable function, is deployed in both the power terminal and the power service server. Simultaneously, the power service server stores the hash value of the power terminal's identity. Furthermore, there are currently multiple calculation standards for physically unclonable functions and hash functions; this embodiment of the invention can select any calculation standard, and its specific calculation process will not be elaborated further.

[0047] Step S102: After successful secondary authentication, communication data is transmitted between the terminal and the power service server. The transmitted communication data consists of ciphertext obtained by encrypting the plaintext message using a high-performance symmetric algorithm based on shuffling coding, key ciphertext obtained by encrypting the high-performance symmetric algorithm's key using the public key of an asymmetric algorithm, and a plaintext digest calculated using a hash algorithm. During data transmission, the power terminal can act as both a sender (encrypting the data using the above encryption methods) and a receiver (decrypting the data encrypted using the above methods). Data transmission between the sender and receiver utilizes 5G virtual private network slicing.

[0048] Specifically, such as Figure 2 As shown, when the power terminal acts as the sender, a high-performance symmetric algorithm based on shuffling coding is used to encrypt the plaintext message of the business data to obtain a first encrypted ciphertext. The public key of an asymmetric algorithm is used to encrypt the key of the high-performance symmetric algorithm to obtain a first key ciphertext. A hash algorithm is used to calculate a first plaintext digest of the plaintext message. The first encrypted ciphertext, the first key ciphertext, and the first plaintext digest are then sent to the power business server. The asymmetric algorithm can be the Chinese national cryptographic algorithm SM2, and the hash algorithm can be the Chinese national cryptographic algorithm SM3.

[0049] like Figure 2As shown, when the power terminal acts as the receiving end, it receives the second encrypted ciphertext, the second key ciphertext, and the second plaintext digest sent by the power service server. The second key ciphertext is decrypted using a private key with an asymmetric algorithm to obtain a high-performance key. The second encrypted ciphertext is then decrypted using the high-performance key to obtain a plaintext message. This plaintext message is then decrypted using a hash algorithm to obtain a third plaintext digest. The second plaintext digest and the third plaintext digest are compared. If they match, the decrypted plaintext message is output. This plaintext digest comparison ensures the integrity of the business data.

[0050] The secure communication method based on 5G virtual private network (VPN) slicing provided in this invention, in terms of secondary authentication, verifies the identities of both parties through a physically unclonable function, hides important data based on XOR calculation, and ensures data integrity based on hash calculation. It avoids the use of PKI and other infrastructure, as well as complex encryption and decryption algorithms, achieving low-complexity, lightweight secondary authentication while ensuring security. This guarantees the real-time and security requirements of power control services. Regarding data isolation in the soft slice, a hybrid cryptographic algorithm based on high-performance symmetric, asymmetric, and hash algorithms is used. This significantly improves the effectiveness of data encryption and decryption while ensuring the security of business data and the symmetric key, saving encryption and decryption time. Simultaneously, a high-performance symmetric cryptographic algorithm based on shuffling encoding is used for the encryption and decryption of control service data, achieving higher security and effectiveness than traditional symmetric cryptographic algorithms. The key of the improved cryptographic algorithm is asymmetric encrypted before being transmitted to the receiver, ensuring the security of the symmetric key. Furthermore, a hash algorithm is used to calculate the plaintext digest, ensuring the integrity of the business data.

[0051] The secure communication method based on 5G virtual private network slicing provided in this invention reduces the secondary authentication time of power terminals by using a lightweight secondary authentication method without PKI or bilinear mapping computation. It leverages the effectiveness of symmetric cryptography and the security of asymmetric cryptography to achieve secure and efficient encryption and decryption of transmitted data using a hybrid cryptographic method. By combining soft slicing isolation technology, lightweight secondary authentication, and a secure and efficient hybrid encryption method, it effectively reduces network leasing costs while fully ensuring the real-time and security requirements of power control services.

[0052] In one embodiment, lightweight secondary authentication is performed between the power service server and the server based on physically unclonable functions, hash calculations, and XOR calculations, including the following steps:

[0053] Step S201: Authentication is performed between the user and the power service server based on a hash calculation using a physically unclonable function and the user's own identity information. Specifically, this authentication process is implemented as follows:

[0054] Send the first hash value of your identity information and a random number to the power business server.

[0055] The system receives a second hash value, a second random number, and a first input to a physical unclonable function corresponding to the first hash value, sent by the power service server after successful identity authentication based on the hash value. The second hash value is obtained by hash calculation based on the first output of the physical unclonable function corresponding to the first hash value, the first random number, and the second random number.

[0056] Calculate the second output of the physical non-cloning function corresponding to the first input, the first random number, and the third hash value of the second random number.

[0057] When the third hash value is equal to the second hash value, the authentication is successful.

[0058] Step S201: After identity authentication is successful, time authentication is performed between the power business server based on hash calculation and XOR calculation.

[0059] The calculated third random number and the first XOR value of the second output, the calculated self-identity information and the fourth hash value of the second output are sent to the power business server in the first time.

[0060] The system receives the second XOR value of the fourth and fifth random numbers and the fifth hash value of the third and fourth random numbers sent by the power service server. The fifth random number is the hash value of the first output, the third random number, and the second output calculated by the power service server when it determines that the received fourth hash value, the calculated identity information of the power terminal, and the fifth hash value of the first output are equal. The second XOR value and the fifth hash value are output by the power service server when it determines that the difference between the first time and the second time of receiving the first time is less than a threshold, and the hash values ​​of the fifth random number, the first output, the first time, and the second random number are equal to the hash values ​​of the third random number, the second output, the first time, and the second random number.

[0061] Calculate whether the hash values ​​of the fourth, fifth, and sixth random numbers are equal to the hash values ​​of the fourth and third random numbers, wherein the sixth random number is the XOR value calculated based on the third, fourth, and fifth random numbers.

[0062] When they are equal, the third input and the third output are determined based on the hash values ​​of the third random number, the sixth random number, and the physical non-cloning function, and the hash value of the third output is sent to the power service server.

[0063] Receive an authentication success message sent by the power service server; the authentication success message is the fourth output obtained by the power service server by inputting the hash values ​​of the fifth and fourth random numbers into the physical non-cloning function, and outputting the hash value of the fourth output when it is equal to the hash value of the third output.

[0064] Specifically, based on the above identity authentication and time authentication processes, such as Figure 3 As shown, lightweight two-factor authentication between the power terminal and the power service server can be implemented in the following way:

[0065] Step A1: The power terminal uses a hash function to calculate its identity information. First hash value Generate the first random number and the first hash value and the first random number Send to the power business server.

[0066] Step A2: If the power service server does not contain... If the authentication fails, the identity verification will fail. Otherwise, the power service server will process the authentication based on the first... Select the input-output set of the stored mathematical equations (i.e., physically unclonable functions). And generate a second random number. Then, the first input and the second random number and the second hash value Send to the power terminal.

[0067] Step A3: The power terminal receives the first input. As input to the mathematical equation, a second output is obtained. Then calculate the third hash value. And compare the value with the received second hash value. Are they equal? ​​If they are equal, the identity verification passes and the time verification continues; otherwise, the verification fails.

[0068] Step A4: The power terminal generates a third random number. And will contain the fourth hash value, the first XOR value, and the first time message. Send to the authentication server. (Among them) Represents the current time, i.e., the immediate moment, used to verify the timeliness of authentication messages. (Operator) This indicates an XOR operation.

[0069] Step A5: The power service server calculates the fifth hash value. And determine whether the hash value matches the received fourth hash value. If they are equal, authentication fails; otherwise, calculate the fifth random number. Then the power service server calculates the current time. (i.e., the second time) and the first time received The difference is used to determine whether the authentication is valid if it is less than a threshold, where the threshold is an expected delay that can be determined based on the actual situation. If it is not less than the threshold, the authentication fails; otherwise, the hash values ​​of the fifth random number, the first output, the first time, and the second random number are further compared with the hash values ​​of the third random number, the second output, the first time, and the second random number, i.e., the equation is: Is the equation true? If the equation is false, authentication fails; if the equation is true, proceed to the next step.

[0070] Step A6: The power service server generates a fourth random number. And the second XOR value containing the fourth and fifth random numbers, and the fifth hash value containing the third and fourth random numbers, are... Send to the power terminal.

[0071] Step A7: The power terminal calculates a random number based on the received value. To distinguish the value, the calculated value is recorded as the sixth random number. Among them, the sixth random number Then verify whether the hash values ​​of the fourth, fifth, and sixth random numbers are equal to the hash values ​​of the fourth and third random numbers, i.e., the equation... Check if the values ​​are true. If they are not equal, the verification fails. If they are equal, proceed to the next step.

[0072] Step A8: After completing the above verification, the power terminal inputs the following into its mathematical equation: Obtain a new set of mathematical equation inputs and outputs. Used for secondary authentication of the next power terminal. The third input... Third output Then the power terminal deletes all temporary variables, such as... and and the hash value of the third output Send to the power business server.

[0073] Step A9: The power service server calculates the hash values ​​of the fifth and fourth random numbers. And input it into the mathematical equation to obtain the fourth output. Then calculate the hash value of the fourth output. Verify whether the hash value of the fourth output is equal to the hash value of the third output, i.e., the equality. Is the authentication successful? If not, authentication fails. If successful, proceed with setting... This forms the new mathematical equation input-output set, used for the next secondary authentication of the power equipment. At this point, the secondary authentication process is complete, and the terminal can communicate with the power service server.

[0074] In one embodiment, a high-performance symmetric algorithm based on shuffling coding is used to encrypt the plaintext message of business data to obtain the first encrypted ciphertext, including the following steps:

[0075] Step S301: Generate the seventh, eighth, ninth, and tenth random numbers; wherein, the seventh random number... The seventh random number is an eight-digit random number. Each digit in the seventh random number can be between 1 and 8, and each number can only be selected once. For example, the seventh random number could be 36457128 or 45126873; the eighth random number... A random number between 1 and 128!; the ninth random number. A random number ranging from 1 to 1000; the tenth random number. The value ranges from 2 to 9.

[0076] Step S302: Generate an encoding table by performing factorial operations on the eighth and ninth random numbers. Specifically, the process of generating the encoding table is as follows:

[0077] Step S31: Perform a factorial operation based on the eighth random number and the preset arrangement to obtain the first arrangement of the preset arrangement. In this embodiment, the preset arrangement is assumed to be A, which is an arrangement consisting of 128 characters; the eighth random number... Decompose the eighth random number into The coefficient data are obtained in the form of [formula / format]. Then, based on this coefficient data, select the corresponding characters from A to form the first permutation of the eighth random number. For example, select... The The nth character (that is, starting from the 0th character in A, find the nth character). (number of characters) as The 0th character. For The remaining 127 characters, select its first... characters as The first character; and so on, from 128 new character permutations are obtained , That is, a pre-set arrangement The The first permutation, or the pre-defined permutation, is denoted as [a_n]. .

[0078] To illustrate the factorial operation more clearly, let's take a simple example of a 4-character permutation: Suppose the default permutation of the four symbols is [4,2,1,3], which has 4! = 24 unique permutations (from position 0 to position 23). To obtain its... If the substitution is to be found, then we need to find The factorial representation, i.e. The coefficient is [2 21 0]. From the set [4 2 1 3], we select an element at the 2nd position (the first element of the coefficient is 2), which is "1" (the position is counted from 0). Therefore, it is the first element of the first permutation, and the set will be [4 2 3]. Next, we select the element at the 2nd position in the set, which is "3", and the remaining set will be [4,2]. Next, we select an element at the 1st position, which is "2". Finally, we select "4", so the output [1,3,2,4] is the first element of the preset permutation with the input [1,3,2,4]. A permutation.

[0079] Step S32: Perform a factorial operation on the ratio of the eighth and ninth random numbers and the first arrangement to obtain the second arrangement of the first arrangement; specifically, divide the eighth random number by the ninth random number, and round the quotient to obtain a new rounded ratio value. Then arrange them in the first order. For the preset arrangement, the ratio is rounded to the nearest integer. As a new random number, a factorial operation is performed using the method in step S31 to obtain the first permutation. The There are 1 permutation, denoted as . The second permutation is denoted as .

[0080] Step S33: Perform a factorial operation based on the rounded value of the ratio and the second permutation to obtain the third permutation of the second permutation. Specifically, using the second permutation... For the preset arrangement, the ratio is rounded to the nearest integer. As a new random number, a factorial operation is performed using the method in step S31 to obtain the second permutation. The The third permutation is denoted as . .

[0081] Step S34: Perform a factorial operation based on the rounded value of the ratio and the third permutation to obtain the fourth permutation of the third permutation. Specifically, using the third permutation... For the preset arrangement, the ratio is rounded to the nearest integer. As a new random number, a factorial operation is performed using the method in step S31 to obtain the third permutation. The There are 1 permutations, the fourth permutation is denoted as . .

[0082] Step S35: Repeat the factorial operation to obtain the fifth, sixth, seventh, eighth, and ninth permutations. The fifth, sixth, seventh, eighth, and ninth permutations are denoted as follows: The specific calculation process is detailed in the steps outlined above and will not be repeated here.

[0083] Step S36: Generate an encoding table based on the first to ninth permutations. Specifically, the generated encoding table has 128 rows and 9 columns, with the first column value being... , No. The column values ​​are

[0084] Step S303: Perform plaintext shuffling encoding on the plaintext message of the business data based on the column corresponding to the tenth random number in the encoding table; specifically, when shuffling the plaintext message, 128 characters are processed at a time. Therefore, the first 128 characters of the input data are taken, and the encoding table generated in the above steps is used to encode the plaintext message. The column encodes the plaintext. Assume... The plaintext message is "abcd", and the generated encoding table is as follows: Figure 4 As shown; the value of row 97-100 in column 7 of the encoding table is... If "a" is encoded as the 56th symbol of ASCII, which is "8", and "b" is encoded as the 125th symbol of ASCII, "}", and so on, the plaintext message after plaintext shuffling will result in "8}CQ". After the current 128 characters are shuffled, another 128 characters are selected and the same operation is performed until all data is shuffled. If the number of characters selected in the last step is less than 128, some useless data is added to form 128 characters, and the number of useless characters is added to the beginning of the input data for the receiver to understand.

[0085] Step S304: Replace the plaintext shuffled and encoded data based on the seventh random number and the encoding table to obtain encrypted ciphertext. The seventh, eighth, ninth, and tenth random numbers constitute the high-performance key. Specifically, if the encoding table is as follows... Figure 4 As shown, the seventh random number The given value is 46357128. The shuffled encoded data is "Zacd…". Then, the first character of the shuffled encoded data, "Z" (90 ASCII), is taken and replaced with the 4+1=5th code in the 90th row of the encoding table (because 4 is the lowest ASCII value). The first digit in the data (Z) will be encoded as the character "S" (ASCII 83). Now, the second character, "a" (ASCII 97), is extracted from the data and replaced with the corresponding code (6+1=7) in line 97 of the encoding table. Therefore, "a" will be encoded as "8" (ASCII 56). The same applies to the remaining characters. After replacing the first 8 characters in the shuffled encoded data, the next 8 characters in the data are encoded according to... The encoded values ​​in the encoding table are alternately moved up and down (for example, if S is 57248613, columns 5, 2, 8, and 1 will move up one row, while columns 7, 4, 6, and 3 will move down one row). After this shuffling step, the encoded value of each piece of data will change, and the replacement process for characters 9-16 will continue using the new shuffling table, as described above, until the encoding of all shuffled encoded data is complete. This simple replacement technique achieves encryption of business data.

[0086] In one embodiment, the second encrypted ciphertext is decrypted using the high-performance key to obtain the plaintext message, including the following steps:

[0087] Step S401: Receive the high-performance key; specifically, after the high-performance symmetric algorithm encryption is completed at the data sending end, a high-performance key composed of the seventh, eighth, ninth, and tenth random numbers is generated, and this high-performance key is shared with the receiving end. The key received by the receiving end is then represented as follows: .

[0088] Step S402: Generate an encoding table based on the high-performance key and the high-performance symmetric algorithm; specifically, the encoding table can be formed using the data in the high-performance key. The specific process of forming the encoding table is described in step S302 above and will not be repeated here.

[0089] Step S403: Perform reverse substitution and reverse plaintext shuffling according to the encoding table and the second encrypted ciphertext to obtain the plaintext message. Specifically, for example, the encoding table is as follows: Figure 4 As shown, the first random number in the received key The ciphertext is 46357128, and the receiver will extract the first element from the ciphertext, the character "S", and search for the decimal value of "S" in the 5th column of the table. This value is 83 (because 4 is a random number). The first element in the table). When the receiver finds 83 in column 5, its corresponding value in column 1 is 90 (the ASCII value of the character "Z"). Therefore, the "S" (decimal 83) is replaced by the corresponding ASCII code in column 1 of the table in the same row, which is 90 (ASCII "Z"). This process continues, and the 8 characters of business data can be decoded. Then, based on the key... of The plaintext shuffling operation is then performed to obtain the standard ASCII value corresponding to the encoded value obtained from the plaintext shuffling, thus obtaining the plaintext data. It should be noted that the plaintext obtained through this step is 8 characters. The subsequent character decoding process only requires repeating the reverse substitution and plaintext shuffling. The only difference is that a different encoding table is used for each decoding. The encoding table transformation form is as described in step S304, and will not be repeated here.

[0090] The secure communication method based on 5G virtual private network (VPN) slicing provided in this invention, through soft slicing technology and a secure and efficient hybrid cryptographic method, effectively reduces network leasing costs compared to leasing 5G hard slice channels, while ensuring the real-time and security requirements of power regulation services. In the hybrid cryptographic algorithm, a symmetric cryptographic algorithm based on shuffling coding is used, which effectively hides the connection between plaintext and ciphertext. The highly randomized coding scheme ensures its resistance to specific plaintext attacks and brute-force attacks. Furthermore, the encryption and decryption process can be completed without complex bilinear mapping calculations, making its effectiveness far greater than that of classic symmetric cryptographic algorithms.

[0091] A second aspect of this invention provides a secure communication device based on 5G virtual private network slicing, applied to power terminals, such as... Figure 5 As shown, the secure communication device includes:

[0092] The authentication module is used to perform lightweight secondary authentication with the power business server based on physical non-clonable functions, hash calculations, and XOR calculations; for details, please refer to the corresponding sections of the above method embodiments, which will not be repeated here.

[0093] The data transmission module is used to transmit communication data with the power business server after successful secondary authentication. The transmitted communication data consists of ciphertext obtained by encrypting the plaintext message using a high-performance symmetric algorithm based on shuffling coding, key ciphertext obtained by encrypting the key of the high-performance symmetric algorithm using the public key of the asymmetric algorithm, and a plaintext digest calculated by a hash algorithm. For details, please refer to the corresponding sections of the above method embodiments, which will not be repeated here.

[0094] The secure communication device based on 5G virtual private network (VPN) slicing provided in this invention, in terms of secondary authentication, verifies the identities of both parties through a physically unclonable function, hides important data based on XOR calculation, and ensures data integrity based on hash calculation. It avoids the use of PKI and other infrastructure, as well as complex encryption and decryption algorithms, achieving low-complexity, lightweight secondary authentication while ensuring security. This guarantees the real-time and security requirements of power control services. Regarding data isolation in the soft slice, a hybrid cryptographic algorithm based on high-performance symmetric, asymmetric, and hash algorithms is used. This significantly improves the effectiveness of data encryption and decryption while ensuring the security of business data and the symmetric key, saving encryption and decryption time. Simultaneously, a high-performance symmetric cryptographic algorithm based on shuffling encoding is used for the encryption and decryption of control service data, achieving higher security and effectiveness than traditional symmetric cryptographic algorithms. The key of the improved cryptographic algorithm is asymmetric encrypted before being transmitted to the receiver, ensuring the security of the symmetric key. Furthermore, a hash algorithm is used to calculate the plaintext digest, ensuring the integrity of the business data.

[0095] Optionally, the authentication module includes: a first authentication module for identity authentication with the power business server based on a hash calculation of the physical non-clonable function and its own identity information; and a second authentication module for time authentication with the power business server based on hash calculation and XOR calculation after successful identity authentication.

[0096] Optionally, the first authentication module is specifically configured to: send a first hash value and a random number of its own identity information to the power business server; receive a second hash value, a second random number, and a first input of the physical unclonable function corresponding to the first hash value sent by the power business server after successful identity authentication based on the hash value, wherein the second hash value is obtained by hash calculation based on the first output, the first random number, and the second random number of the physical unclonable function corresponding to the first hash value; calculate a third hash value of the second output, the first random number, and the second random number of the physical unclonable function corresponding to the first input; and when the third hash value is equal to the second hash value, the identity authentication is successful.

[0097] Optionally, the second authentication module is specifically configured to: send the calculated third random number and the first XOR value of the second output, the calculated self-identity information and the fourth hash value of the second output, and the first time to the power service server; receive the second XOR value of the fourth random number and the fifth random number and the fifth hash value of the third random number and the fourth random number sent by the power service server, wherein the fifth random number is the hash value of the first output, the third random number, and the second output calculated by the power service server when it determines that the received fourth hash value, the calculated identity information of the power terminal, and the fifth hash value of the first output are equal; the second XOR value and the fifth hash value are the difference between the first time determined by the power service server and the second time of receiving the first time being less than a threshold, and the fifth random number, the first output, the first time, and the second random number are also considered to be equal. The output is generated when the hash value of the first random number is equal to the hash values ​​of the third random number, the second output, the first time, and the second random number; the hash values ​​of the fourth random number, the fifth random number, and the sixth random number are calculated to see if they are equal to the hash values ​​of the fourth random number and the third random number, wherein the sixth random number is the XOR value calculated based on the third random number, the fourth random number, and the fifth random number; when they are equal, the third input and the third output are determined based on the hash values ​​of the third random number, the sixth random number, and the physical unclonable function, and the hash value of the third output is sent to the power service server; the authentication success message is received from the power service server; the authentication success message is generated when the power service server inputs the hash values ​​of the fifth random number and the fourth random number into the physical unclonable function to obtain the fourth output, and the hash value of the fourth output is equal to the hash value of the third output.

[0098] Optionally, the data transmission module includes: an encryption module, configured to, after successful secondary authentication, encrypt the plaintext message of the business data using a high-performance symmetric algorithm based on shuffling coding to obtain a first encrypted ciphertext, encrypt the key of the high-performance symmetric algorithm using the public key of an asymmetric algorithm to obtain a first key ciphertext, and calculate a first plaintext digest using a hash algorithm; a first transmission module, configured to send the first encrypted ciphertext, the first key ciphertext, and the first plaintext digest to the power business server; or, it includes: a second transmission module, configured to, after successful secondary authentication, receive the second encrypted ciphertext, the second key ciphertext, and the second plaintext digest sent by the power business server; a decryption module, configured to decrypt the second key ciphertext using the private key of an asymmetric algorithm to obtain a high-performance key, decrypt the second encrypted ciphertext using the high-performance key to obtain a plaintext message, and decrypt the plaintext message obtained by using a hash algorithm to obtain a third plaintext digest; and a comparison module, configured to compare the second plaintext digest and the third plaintext digest, and output the decrypted plaintext message when they are the same.

[0099] Optionally, the encryption module is specifically used to: generate a seventh random number, an eighth random number, a ninth random number, and a tenth random number; generate an encoding table by performing factorial operations on the eighth and ninth random numbers; perform plaintext shuffling encoding on the plaintext message of the business data based on the column corresponding to the tenth random number in the encoding table; and replace the plaintext shuffling encoded data based on the seventh random number and the encoding table to obtain encrypted ciphertext, wherein the seventh, eighth, ninth, and tenth random numbers constitute the high-performance key.

[0100] Optionally, generating an encoding table based on the coefficients of the factorial sequence corresponding to the eighth random number and the ratio of the eighth random number to the ninth random number includes: performing factorial operations on the eighth random number and a preset arrangement to obtain a first arrangement of the preset arrangement; performing factorial operations on the first arrangement using the rounded value of the ratio of the eighth random number and the ninth random number and the first arrangement to obtain a second arrangement of the first arrangement; performing factorial operations on the second arrangement using the rounded value of the ratio and the second arrangement to obtain a third arrangement of the second arrangement; performing factorial operations on the third arrangement using the rounded value of the ratio and the third arrangement to obtain a fourth arrangement of the third arrangement; repeating the factorial operation process to obtain a fifth, sixth, seventh, eighth, and ninth arrangement; and generating an encoding table based on the first to ninth arrangements.

[0101] Optionally, performing factorial operations based on the eighth random number and the preset arrangement to obtain the first arrangement of the preset arrangement includes: factoring the eighth random number to obtain the factorial coefficient data; and selecting the corresponding character in the preset arrangement based on the coefficient data to form the first arrangement of the preset arrangement.

[0102] Optionally, the decryption module is specifically used for: receiving a high-performance key; generating an encoding table based on the high-performance key and the high-performance symmetric algorithm; and performing reverse substitution and reverse plaintext shuffling based on the encoding table and the second encrypted ciphertext to obtain a plaintext message.

[0103] For a detailed description of the functions of the secure communication device based on 5G virtual private network slicing provided in this embodiment of the invention, please refer to the description of the secure communication method based on 5G virtual private network slicing in the above embodiments.

[0104] This invention also provides a storage medium, such as... Figure 6As shown, a computer program 601 is stored on it. When executed by a processor, this program implements the steps of the secure communication method based on 5G virtual private network slicing in the above embodiments. The storage medium also stores audio and video stream data, feature frame data, interactive request signaling, encrypted data, and preset data size, etc. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), etc.; the storage medium may also include combinations of the above types of memory.

[0105] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), etc.; the storage medium can also include combinations of the above types of memory.

[0106] This invention also provides an electronic device, such as... Figure 7 As shown, the electronic device may include a processor 51 and a memory 52, wherein the processor 51 and the memory 52 may be connected via a bus or other means. Figure 7 Taking the example of a connection between China and Israel via a bus.

[0107] Processor 51 can be a central processing unit (CPU). Processor 51 can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or combinations of the above types of chips.

[0108] The memory 52, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the corresponding program instructions / modules in the embodiments of the present invention. The processor 51 executes various functional applications and data processing by running the non-transitory software programs, instructions, and modules stored in the memory 52, thereby realizing the secure communication method based on 5G virtual private network slicing in the above method embodiments.

[0109] The memory 52 may include a program storage area and a data storage area. The program storage area may store applications required for operating the device and at least one function; the data storage area may store data created by the processor 51, etc. Furthermore, the memory 52 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory 52 may optionally include memory remotely located relative to the processor 51, and these remote memories may be connected to the processor 51 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0110] The one or more modules are stored in the memory 52, and when executed by the processor 51, they perform the following: Figure 1-2 The embodiment shown illustrates a secure communication method based on 5G virtual private network slicing.

[0111] For specific details regarding the aforementioned electronic devices, please refer to the relevant documentation. Figures 1 to 2 The relevant descriptions and effects in the illustrated embodiments are for understanding purposes only and will not be repeated here.

[0112] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A method for secure communication based on 5G virtual private network (VPN) slice, characterized in that, The safe communication method is applied to a power terminal and comprises the following steps: Lightweight secondary authentication is performed between the power service server and the power terminal based on a physically unclonable function, hash calculation and XOR calculation; When the secondary authentication is passed, the transmission of communication data between the power service server and the power terminal is performed, and the transmitted communication data is encrypted ciphertext obtained by encrypting plaintext messages based on a symmetric algorithm of shuffle coding, secret key ciphertext obtained by encrypting a secret key of the symmetric algorithm based on a public key of an asymmetric algorithm, and plaintext digest obtained by calculating the plaintext messages based on a hash algorithm; The symmetric algorithm of shuffle coding is used to encrypt plaintext messages of service data to obtain encrypted ciphertext, which comprises the following steps: A seventh random number, an eighth random number, a ninth random number and a tenth random number are generated; A code table is generated by performing factorial operation based on the eighth random number and the ninth random number; The plaintext messages of service data are subjected to plaintext shuffle coding based on the column corresponding to the tenth random number of the code table; The data subjected to the plaintext shuffle coding are replaced based on the seventh random number and the code table to obtain encrypted ciphertext, and the seventh random number, the eighth random number, the ninth random number and the tenth random number form a secret key. 2.The 5G virtual private network slice based secure communication method of claim 1, wherein, Lightweight secondary authentication is performed between the power service server and the power terminal based on a physically unclonable function, hash calculation and XOR calculation, which comprises the following steps: Identity authentication is performed between the power service server and the power terminal based on a physically unclonable function and hash calculation of own identity information; After the identity authentication is passed, time authentication is performed between the power service server and the power terminal based on hash calculation and XOR calculation. 3.The 5G virtual private network slice based secure communication method of claim 2, wherein, Identity authentication is performed between the power service server and the power terminal based on a physically unclonable function and hash calculation of own identity information, which comprises the following steps: A first hash value of own identity information and a first random number are sent to the power service server; After the identity authentication is passed by the power service server based on the hash value, a second hash value, a second random number and a first input of a physically unclonable function corresponding to the first hash value are sent, and the second hash value is obtained by hash calculation based on a first output of the physically unclonable function corresponding to the first hash value, the first random number and the second random number; A second output of the physically unclonable function corresponding to the first input, a third hash value of the first random number and the second random number are calculated; When the third hash value is equal to the second hash value, the identity authentication is passed. 4.The 5G virtual private network slice based secure communication method of claim 3, wherein, Time authentication is performed between the power service server and the power terminal based on hash calculation and XOR calculation, which comprises the following steps: A first XOR value of the calculated third random number and the second output, a fourth hash value of the calculated own identity information and the second output and a first time are sent to the power service server; receive a second exclusive or value of a fourth random number and a fifth random number and a fifth hash value of a third random number and a fourth random number sent by the power service server, the fifth random number being a first output, the third random number, and a hash value of a second output calculated by the power service server when the fourth hash value received and the fifth hash value calculated are equal; the second exclusive or value and the fifth hash value being output by the power service server when a difference between the first time and a second time of receiving the first time is less than a threshold value, and a hash value of the fifth random number, the first output, the first time, and a second random number is equal to a hash value of the third random number, the second output, the first time, and the second random number; calculate whether a hash value of a fourth random number, a fifth random number, and a sixth random number is equal to a hash value of the fourth random number and the third random number, the sixth random number being an exclusive or value calculated according to the third random number, the fourth random number, and the fifth random number; when they are equal, determine a third input and a third output according to a hash value of the third random number and the sixth random number, and a physical unclonable function, and send a hash value of the third output to the power service server; receive an authentication success message sent by the power service server, the authentication success message being a fourth output obtained by inputting the hash value of the fifth random number and the fourth random number into the physical unclonable function, and output when the hash value of the fourth output is equal to the hash value of the third output. 5.The 5G virtual private network slice based secure communication method according to claim 1, wherein, when the secondary authentication passes, perform transmission of communication data between the power service server, the communication data being encrypted ciphertext obtained by encrypting a plaintext message based on a symmetric algorithm of a shuffle code, key ciphertext obtained by encrypting a key of the symmetric algorithm based on a public key of an asymmetric algorithm, and plaintext digest obtained by calculating the plaintext message based on a hash algorithm, including: when the secondary authentication passes, encrypt a plaintext message of service data based on a symmetric algorithm of a shuffle code to obtain first encrypted ciphertext, encrypt a key of the symmetric algorithm based on a public key of an asymmetric algorithm to obtain first key ciphertext, and calculate a first plaintext digest based on a hash algorithm; send the first encrypted ciphertext, the first key ciphertext, and the first plaintext digest to the power service server; or when the secondary authentication passes, receive second encrypted ciphertext, second key ciphertext, and second plaintext digest sent by the power service server; decrypt the second key ciphertext based on a private key of the asymmetric algorithm to obtain a key, decrypt the second encrypted ciphertext based on the key to obtain a plaintext message, and decrypt the plaintext message obtained based on the hash algorithm to obtain a third plaintext digest; compare the second plaintext digest and the third plaintext digest, and output the decrypted plaintext message when they are equal. 6.The 5G virtual private network slice based secure communication method according to claim 1, wherein, generate an encoding table based on factorial operation of the eighth random number and the ninth random number, including: perform factorial operation based on the eighth random number and a preset permutation to obtain a first permutation of the preset permutation; According to the value of the ratio of the eighth random number and the ninth random number and the first permutation, a factorial operation is performed to obtain a second permutation of the first permutation; According to the value of the ratio and the second permutation, a factorial operation is performed to obtain a third permutation of the second permutation; According to the value of the ratio and the third permutation, a factorial operation is performed to obtain a fourth permutation of the third permutation; The process of the factorial operation is repeated to obtain a fifth permutation, a sixth permutation, a seventh permutation, an eighth permutation and a ninth permutation; An encoding table is generated according to the first permutation to the ninth permutation.

7. The secure communication method based on a 5G virtual private network slice according to claim 6, characterized in that, According to the eighth random number and a preset permutation, a factorial operation is performed to obtain a first permutation of the preset permutation, including: The eighth random number is subjected to factorial decomposition to obtain coefficient data after decomposition; According to the coefficient data, a corresponding character in the preset permutation is selected to form the first permutation of the preset permutation. 8.The 5G virtual private network slice based secure communication method of claim 5, wherein, The second encrypted ciphertext is decrypted by using the secret key to obtain a plaintext message, including: Receiving a secret key; Generating an encoding table according to the secret key and the symmetric algorithm; According to the encoding table and the second encrypted ciphertext, reverse replacement and reverse plaintext shuffling are performed to obtain a plaintext message. 9.A secure communication device based on a 5G virtual private network slice, characterized in that, The security communication device is applied to a power terminal, and includes: An authentication module, configured to perform lightweight secondary authentication with a power service server based on a physically unclonable function, hash calculation and exclusive or calculation; A data transmission module, configured to perform transmission of communication data between the power service server after the secondary authentication passes, the communication data being encrypted ciphertext of plaintext messages of service data obtained by using a symmetric algorithm based on shuffling encoding, secret key ciphertext of a secret key of the symmetric algorithm obtained by using a public key of an asymmetric algorithm, and plaintext digest of the plaintext messages obtained by using a hash algorithm; The symmetric algorithm based on shuffling encoding is used to encrypt the plaintext messages of the service data to obtain the encrypted ciphertext, including: Seventh random number, eighth random number, ninth random number and tenth random number are generated; The eighth random number and the ninth random number are subjected to a factorial operation to generate an encoding table; The tenth random number corresponding to a column of the encoding table is used to perform plaintext shuffling encoding on the plaintext messages of the service data; The seventh random number and the encoding table are used to replace the data after the plaintext shuffling encoding to obtain the encrypted ciphertext, the seventh random number, the eighth random number, the ninth random number and the tenth random number forming the secret key.

10. The secure communication device based on 5G virtual private network slice according to claim 9, characterized in that, The authentication module includes: A first authentication module, configured to perform identity authentication with the power service server based on a physically unclonable function and hash calculation of own identity information; A second authentication module, configured to perform time authentication with the power service server based on hash calculation and exclusive or calculation after the identity authentication passes.

11. The secure communication device based on 5G virtual private network slice according to claim 9, characterized in that, The data transmission module includes: An encryption module, configured to, after the secondary authentication passes, use the symmetric algorithm based on shuffling encoding to encrypt the plaintext messages of the service data to obtain first encrypted ciphertext, use the public key of the asymmetric algorithm to encrypt the secret key of the symmetric algorithm to obtain first secret key ciphertext, and use the hash algorithm to calculate first plaintext digest of the plaintext messages; The first transmission module is configured to send the first encrypted ciphertext, the first secret key ciphertext, and the first plaintext digest to the power service server; or The second transmission module is configured to receive the second encrypted ciphertext, the second secret key ciphertext, and the second plaintext digest sent by the power service server after the secondary authentication is passed. The decryption module is configured to decrypt the second secret key ciphertext by using a private key of an asymmetric algorithm to obtain a secret key, decrypt the second encrypted ciphertext by using the secret key to obtain a plaintext message, and decrypt the plaintext message obtained by using a hash algorithm to obtain a third plaintext digest. The comparison module is configured to compare the second plaintext digest and the third plaintext digest, and output the decrypted plaintext message when the two are the same.

12. The secure communication device based on 5G virtual private network slice according to claim 11, characterized in that, The decryption module is specifically configured to receive a secret key, generate an encoding table according to the secret key and the symmetric algorithm, and perform reverse replacement and reverse plaintext shuffling according to the encoding table and the second encrypted ciphertext to obtain a plaintext message.

13. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the security communication method based on the 5G virtual private network slice.

14. An electronic device, comprising: The memory and the processor are mutually connected in communication, the memory stores computer instructions, and the processor executes the computer instructions to execute the security communication method based on the 5G virtual private network slice. The memory and the processor are mutually connected in communication, the memory stores computer instructions, and the processor executes the computer instructions to execute the security communication method based on the 5G virtual private network slice.

Citation Information

Patent Citations

  • Data link trusted transmission method and system

    CN114826656A