An Authentication Method for Low-Voltage Distributed Power Intelligent Terminal Equipment Based on CPU Clock Offset
Through the "challenge-response" mechanism based on CPU clock offset, the clock offset fingerprint information of the low-voltage distributed power supply smart terminal is collected and verified, which solves the lightweight identity authentication problem of the low-voltage distributed power supply smart terminal, and realizes the security authentication and protection of the terminal.
Patent Information
- Application Number
- CN202211229400.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-08
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-10-08
AI Technical Summary
The prior art is difficult to implement lightweight identity authentication in low-voltage distributed power smart terminals, and has high requirements for terminal hardware or high computing complexity, so it cannot effectively resist counterfeiting and replay attacks.
By establishing a "challenge-response" mechanism based on CPU clock offset, the terminal's CPU clock offset fingerprint information is collected, and the associated data pair is established in combination with identifier information, and the authentication system is registered, and the matching degree verification is used to verify the clock offset vector, and the identity authentication is realized.
It realizes lightweight identity authentication, can resist counterfeiting and replay attacks without changing the terminal hardware structure, and is suitable for factory-departed and unfabricated terminals, with significant security protection effects.
Smart Images

Figure CN115589064B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of smart grid security and relates to an authentication method for intelligent terminal devices of low-voltage distributed power sources based on CPU clock offset. Background Art
[0002] With the continuous development of intelligent technologies such as sensing and measurement technologies and advanced control technologies, the power system has shown an intelligent trend. Currently, the installed capacity and proportion of distributed energy are increasing year by year. Especially in low-voltage distributed systems, a large number of intelligent terminals of distributed power sources replace the original terminals to access the power grid. While this brings more flexible control and efficient management, there are also many security risks. As an important part of the safe and stable operation of the power grid, intelligent terminals of low-voltage distributed power sources are very vulnerable to being exploited by attackers and used as a "springboard" to cause heavy losses to the power system. Moreover, intelligent terminals of distributed power sources have characteristics such as complex types and diverse functions, and are very vulnerable to attacks such as spoofing attacks (i.e., using illegal devices to impersonate legitimate intelligent terminals of distributed power sources for attacks). Therefore, it is necessary to control them from the access authentication link to ensure the authenticity and reliability of the accessed intelligent terminals.
[0003] For the access authentication of intelligent terminals of distributed power sources, some security mechanisms have been used to strengthen identity authentication, mainly including principles based on cryptography, where encryption is performed through theoretically unbreakable keys for authentication, and corresponding keys are implanted during device manufacturing through physical unclonable functions (PUFs), etc. In recent years, blockchain technology, artificial intelligence technology, etc. have also provided new authentication methods for authentication technologies. However, the above authentication technologies either require the hardware of intelligent terminals of distributed power sources to be modified or require a large amount of complexity in operation to ensure the encryption strength. Since the production and manufacturing of intelligent terminals of low-voltage distributed power sources have strict standards and requirements, and the low-voltage distributed scenario determines that the operating overhead of intelligent terminals of distributed power sources themselves has relatively large limitations, in actual application scenarios, a lightweight authentication mechanism is needed to authenticate intelligent terminals of low-voltage distributed power sources. Summary of the Invention
[0004] The present invention discloses an authentication method for intelligent terminal devices of low-voltage distributed power sources based on CPU clock offset. By establishing a "challenge-response" mechanism for the access process of intelligent terminals of distributed power sources, the CPU clock offset fingerprint information of intelligent terminals of distributed power sources is obtained, and this information is used to verify whether it is a legitimate intelligent terminal of a distributed power source, and authentication is performed comprehensively considering freshness. This method can obtain the differences in the hardware characteristics of intelligent terminals of distributed power sources, thereby realizing the identity authentication of intelligent terminals of low-voltage distributed power sources in a lightweight form.
[0005] The technical solution adopted by the present invention is as follows:
[0006] An authentication method for a low-voltage distributed power intelligent terminal device based on CPU clock offset, comprising the following steps:
[0007] Step 1: Run multiple specific programs on the distributed power intelligent terminal in the low-voltage distributed system multiple times, time the running time, and collect the CPU clock offset fingerprint information of the distributed power intelligent terminal;
[0008] Step 2: Combine the identifier information S of the distributed power intelligent terminal k , associate it with the CPU clock offset fingerprint information obtained in Step 1, and establish a unique mapping association data pair with the unique identifier information S k , the specific program for generating fingerprints, and the clock offset fingerprint matrix M k The three are uniquely mapped, and record this association data pair into the database to obtain the distributed power intelligent terminal fingerprint database D, and complete the registration of the low-voltage distributed power intelligent terminal in the authentication system;
[0009] Step 3: When the low-voltage distributed power intelligent terminal needs to access the system, send a request authentication signal to the system, and the request authentication signal includes the identifier information S of the distributed power intelligent terminal k ;
[0010] Step 4: The authentication system establishes a "challenge-response" authentication mechanism for the low-voltage distributed power intelligent terminal that responds to the request according to the existing distributed power intelligent terminal devices and the distributed power intelligent terminal fingerprint database D, and obtains the clock offset vector V;
[0011] Step 5: The authentication system verifies the distributed power intelligent terminal by calculating the matching degree according to the association data pair in the distributed power intelligent terminal database D and the clock offset vector V returned in Step 4, and rejects the access of the distributed power intelligent terminal that fails the clock offset fingerprint verification;
[0012] Step 6: Perform freshness verification on the distributed power intelligent terminal that passes the verification in Step 5 according to timestamp matching, reject the access of the distributed power intelligent terminal that fails the verification, and allow the access of the low-voltage distributed power intelligent terminal that passes the verification.
[0013] The beneficial effects of the present invention are as follows: The present invention proposes an authentication method for intelligent terminal devices of low-voltage distributed power supplies based on CPU clock offset, obtaining the CPU clock offset differences of distributed power supply intelligent terminals in a simple and low-overhead manner, using this as the fingerprint of the intelligent terminal, establishing a "challenge-response" mechanism, and combining freshness verification to achieve an authentication method that can resist impersonation attacks and replay attacks, providing a means of security protection for intelligent terminal devices of low-voltage distributed power supplies.
[0014] At the same time, the technical solution proposed by the present invention can obtain the hardware differences in clock offset during the operation of the CPU without changing the hardware structure of the distributed power supply intelligent terminal, so it can be applied to distributed power supply intelligent terminals that have been manufactured and those that have not been manufactured, and has very low requirements for the performance and overhead of the distributed power supply intelligent terminal, having a wide range of application scenarios in low-voltage distributed energy, and having significant social and economic benefits. Brief Description of the Drawings
[0015] Figure 1 It is a flowchart of an authentication method for intelligent terminal devices of low-voltage distributed power supplies based on CPU clock offset shown in an embodiment of the present invention. Detailed Embodiments
[0016] The present invention will be further described below with reference to the drawings.
[0017] The present invention provides an authentication method for intelligent terminal devices of low-voltage distributed power supplies, using the CPU clock offset differences of distributed power supply intelligent terminals as the fingerprints of the intelligent terminals to conduct authentication of power terminal devices. Among them, the CPU clock offset refers to the manufacturing process differences between the CPU of the distributed power supply intelligent terminal and the crystal oscillator used to provide the clock signal, and the time deviation caused by different CPU performances when running the same program. The flowchart of the authentication method is as Figure 1 shown, mainly divided into clock offset fingerprint acquisition, distributed power supply intelligent terminal fingerprint database generation, request authentication, "challenge-response" authentication mode, distributed power supply intelligent terminal clock offset fingerprint verification, distributed power supply intelligent terminal access freshness verification, and distributed power supply intelligent terminal access management.
[0018] The method is as follows:
[0019] Step 1: Use the low-voltage distributed power supply intelligent terminal to run multiple segments of specific programs multiple times, time the running time, and collect the CPU clock offset fingerprint information of the distributed power supply intelligent terminal. The specific steps are as follows:
[0020] Step 1.1: Randomly select m different specific programs f1, f2,..., f for generating fingerprintsm , these programs can be operation processes containing simple functions, and the overhead of a single program is very small;
[0021] Step 1.2: Due to voltage fluctuations and differences in system instruction scheduling, the time for a single measurement run of the program will cause instability in the clock offset fingerprint. Therefore, each program in Step 1.1 is run n times (n ≥ 20) on each distributed power intelligent terminal. Among them, timing starts at the beginning of the program, and the running time of the program is obtained after the program ends. Denote the nth running time of the mth program as t mn ;
[0022] Step 1.3: For each distributed power intelligent terminal, establish a clock offset fingerprint matrix M based on the running times of the n*m programs obtained in Step 1.2 k :
[0023]
[0024] Among them, M k represents the clock offset fingerprint matrix corresponding to the kth distributed power intelligent terminal, and this is used as the CPU clock offset fingerprint information of the distributed power intelligent terminal.
[0025] Step 2: Combine the unique identifier information S such as the MAC address of the distributed power intelligent terminal k , and associate it with the CPU clock offset fingerprint information obtained in Step 1 to establish an association data pair with a unique mapping of the unique identifier information S k , the specific program for generating fingerprints, and the clock offset fingerprint matrix M k The three are uniquely mapped, and record this association data pair into the database to obtain the distributed power intelligent terminal fingerprint database D, completing the registration of the low-voltage distributed power intelligent terminal in the authentication system.
[0026] Step 3: When the distributed power intelligent terminal needs to access the system, send a request authentication signal to the system, and at the same time, this signal should contain the unique identifier information S such as the MAC address of the distributed power intelligent terminal k .
[0027] Step 4: The authentication system establishes a "challenge - response" authentication mechanism for the distributed power intelligent terminal that requests a response based on the existing distributed power intelligent terminal devices and the distributed power intelligent terminal fingerprint database D. The specific steps are as follows:
[0028] Step 4.1: The system searches in the database for the distributed power intelligent terminal association data pair corresponding to the unique identifier information S k , and records the current timestamp information T1;
[0029] Step 4.2: Return the specific programs for generating fingerprints in the associated data pairs of the distributed power intelligent terminal in Step 4.1 to the distributed power intelligent terminal to be authenticated in a random order, and require all specific programs to be run in sequence to establish a "challenge" process;
[0030] Step 4.3: The distributed power intelligent terminal records the running time t required for each specific program run in sequence. The running times t of all specific programs constitute the clock offset vector V for this authentication, and returns the vector V and the current timestamp information T2 to the authentication system to complete the "response" process.
[0031] Step 5: The authentication system verifies the distributed power intelligent terminal by calculating the matching degree based on the associated data pairs in the distributed power intelligent terminal database D and the clock offset vector V returned in Step 4. The distributed power intelligent terminals that fail the clock offset fingerprint verification are refused access. The specific steps are as follows:
[0032] Step 5.1: The authentication system reorders the clock offset vector V returned to the authentication system according to the random order described in Step 4.2 to obtain V′, so that its order is consistent with the row order of the clock offset fingerprint matrix M k ;
[0033] Step 5.2: Initially define the matching value Match = 0;
[0034] Step 5.3: For the i-th value in V′ described in Step 5.1, respectively search for the values in each column of the i-th row in the clock offset fingerprint matrix M k . If it is found that there are consistent running times in each column corresponding to the i-th row, then it is considered that the two match on the i-th specific program, and the Match value is increased by 1;
[0035] Traverse each value in V′ to obtain the final matching value Match of the distributed power intelligent terminal;
[0036] Step 5.4: Divide the final matching value Match of the distributed power intelligent terminal described in Step 5.3 by the number of specific programs m, and define it as the matching degree of the distributed power intelligent terminal;
[0037] Step 5.5: Judge the relationship between the matching degree of the distributed power intelligent terminal and the threshold. If the matching degree described in Step 5.4 is lower than the threshold, the authentication system considers that the verification fails and refuses the distributed power intelligent terminal to access; otherwise, the authentication system considers that the clock offset fingerprint verification of the distributed power intelligent terminal passes.
[0038] Step 6: To counter the threat of replay attacks, the distributed power intelligent terminals that passed the verification in step 5 are subjected to freshness verification based on timestamp matching. Distributed power intelligent terminals that failed the verification are denied access, while low-voltage distributed power intelligent terminals that passed the verification are allowed access. The specific steps are as follows:
[0039] Step 6.1: Calculate the freshness index Fr of this authentication = T2 - T1;
[0040] Step 6.2: When the freshness index Fr is lower than or equal to the set time T, the authentication is considered valid and the distributed power intelligent terminal is allowed access; when the freshness index Fr is higher than the set time T, the authentication is considered invalid and the distributed power intelligent terminal is denied access.
[0041] Step 7: Record the current status of the connected distributed power intelligent terminal in the authentication system, and record the time of passing the authentication (the time of access), and manage the connected low-voltage distributed power intelligent terminal.
[0042] The present invention establishes a low-voltage distributed power supply intelligent terminal device authentication method based on CPU clock offset through processes such as clock offset fingerprint collection, distributed power supply intelligent terminal fingerprint library generation, request authentication, "challenge-response" authentication mode, distributed power supply intelligent terminal clock offset fingerprint verification, distributed power supply intelligent terminal access freshness verification, and distributed power supply intelligent terminal access management. The CPU clock offset fingerprint information is obtained by the distributed power supply intelligent terminal running a random simple program multiple times, and is verified using a clock offset vector. Finally, the distributed power supply intelligent terminal that passes the clock offset fingerprint verification is subjected to a freshness verification. This authentication method can resist counterfeit attacks and replay attacks, providing a means of security protection for low-voltage distributed power supply intelligent terminals, and has significant technical effects.
[0043] The above examples are merely specific embodiments of the present invention. Obviously, the present invention is not limited to the above examples, and many variations are possible. All variations that can be directly derived or imagined by a person skilled in the art from the disclosure of the present invention should be considered to be within the scope of protection of the present invention.
Claims
1. An authentication method for an intelligent terminal device of a low-voltage distributed power supply based on CPU clock offset, characterized in that, The steps include: Step 1: Run multiple specific programs on the distributed power intelligent terminal in the low-voltage distributed system multiple times, count the running time, and collect the CPU clock offset fingerprint information of the distributed power intelligent terminal; Step 2: Combine the identifier information S of the distributed power intelligent terminal k , associate it with the CPU clock offset fingerprint information obtained in step 1, and establish a unique identifier information S k , a specific procedure for generating fingerprints, clock offset fingerprint matrix M k The three uniquely mapped associated data pairs are recorded in the database to obtain the distributed power intelligent terminal fingerprint database D, completing the registration of the low-voltage distributed power intelligent terminal in the authentication system; Step 3: When the intelligent terminal of the low-voltage distributed power source needs to access the system, it sends a request authentication signal to the system, and the said request authentication signal contains the identifier information S of the intelligent terminal of the distributed power source k ; Step 4: The authentication system establishes a "challenge-response" authentication mechanism for the distributed power intelligent terminal requesting a response based on the existing distributed power intelligent terminal devices and the distributed power intelligent terminal fingerprint database D, and obtains the clock offset vector V; Step 5: The authentication system verifies the distributed power intelligent terminal by calculating the matching degree based on the associated data pairs in the distributed power intelligent terminal database D and the clock offset vector V returned in step 4. The distributed power intelligent terminal that fails the clock offset fingerprint verification is denied access. Step 6: Perform freshness verification on the distributed power intelligent terminals that passed the verification in step 5 based on timestamp matching, deny access to the distributed power intelligent terminals that failed the verification, and allow access to the distributed power intelligent terminals that passed the verification.
2. The authentication method for the intelligent terminal device of the low-voltage distributed power supply based on the CPU clock offset according to claim 1, wherein The step 1 is specifically as follows: Step 1.1: Randomly select m different specific programs f1, f2, …, f for generating fingerprints m ; Step 1.2: Due to voltage fluctuations and differences in system instruction scheduling, the time taken for a single measurement run of the program can cause instability in the clock offset fingerprint. Therefore, each program in Step 1.1 is run n times on each distributed power intelligent terminal, and timing is started at the beginning of the program. The running time of the program is obtained after the program ends. The nth running time of the mth program is denoted as t mn ; Step 1.3: For each distributed power intelligent terminal, establish the clock offset fingerprint matrix M based on the running time of the n*m programs obtained in step 1.2 k : Among them, M k Represents the clock offset fingerprint matrix corresponding to the kth distributed power intelligent terminal, which is used as the CPU clock offset fingerprint information of the distributed power intelligent terminal.
3. The authentication method for the intelligent terminal device of the low-voltage distributed power supply based on the CPU clock offset according to claim 1, wherein The step 4 is specifically as follows: Step 4.1: The low-voltage distributed system searches for the identifier information S in the database k for the associated data pair of the distributed power intelligent terminal, and records the current timestamp information T1; Step 4.2: Return the specific programs used to generate fingerprints in the distributed power intelligent terminal association data in step 4.1 to the distributed power intelligent terminal to be authenticated in a random order, requiring all specific programs to be run in sequence to establish a "challenge" process; Step 4.3: The distributed power intelligent terminal records the running time t required for each specific program to run in sequence. The running time t of all specific programs constitutes the clock offset vector V of this authentication, and returns the vector V and the current timestamp information T2 to the authentication system to complete the "response" process.
4. The authentication method for the intelligent terminal device of a low-voltage distributed power supply based on CPU clock offset according to claim 1, characterized in that, The step 5 is specifically as follows: Step 5.1: The authentication system re - adjusts the order according to the returned clock offset vector V to obtain V′, such that its order is consistent with the row order of the clock offset fingerprint matrix M k ; Step 5.2: Initially define the match value Match = 0; Step 5.3: For the i-th value in V' described in Step 5.1, search for the values in each column of the i-th row in the clock offset fingerprint matrix M k respectively. If consistent running times are found in each column corresponding to the i-th row, it is considered that they match on the i-th specific program, and the Match value is incremented by 1; Traverse each value in V′ to obtain the final matching value Match of the distributed power intelligent terminal; Step 5.4: Divide the final matching value Match of the distributed power intelligent terminal described in step 5.3 by the number of specific programs m, and define it as the matching degree of the distributed power intelligent terminal; Step 5.5: Determine the relationship between the matching degree of the distributed power intelligent terminal and the threshold value. If the matching degree described in step 5.4 is lower than the threshold value, the authentication system considers that the verification fails and denies the access of the distributed power intelligent terminal. Otherwise, the authentication system considers that the clock offset fingerprint verification of the distributed power intelligent terminal passes.
5. The authentication method for a low-voltage distributed power intelligent terminal device based on CPU clock offset according to claim 3, characterized in that The step 6 is specifically as follows: Step 6.1: Calculate the freshness index Fr = T2-T1 of the distributed power intelligent terminal authentication; Step 6.2: When the freshness index Fr is lower than or equal to the set time T, the authentication is considered valid and the distributed power intelligent terminal is allowed access; when the freshness index Fr is higher than the set time T, the authentication is considered invalid and the distributed power intelligent terminal is denied access.
6. The authentication method for a low-voltage distributed power intelligent terminal device based on CPU clock offset according to claim 1, wherein The identifier information adopts the MAC address of the distributed power supply intelligent terminal and has unique identification.
7. An authentication method for a low-voltage distributed power intelligent terminal device based on CPU clock offset according to claim 1, characterized in that, Also includes: Step 7: Record the current status of the connected low-voltage distributed power intelligent terminal in the authentication system, record the time of successful authentication, and manage the connected distributed power intelligent terminals.
Citation Information
Patent Citations
Nginx dynamic passive traffic limiting method and system based on device fingerprints
CN108234341A
AU2824989A