A power grid security authentication method

By installing the database client and server in the power grid, using the client-server interactive distribution calculation of the zero-knowledge proof Fzkp-i algorithm, the data transmission vulnerability and technical team separation problems in the power grid security authentication are solved, and efficient and transparent data protection is achieved.

CN115766083BActive Publication Date: 2025-07-29GUANGDONG POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211248898.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-12
Publication Date
2025-07-29
Estimated Expiration
2042-10-12

AI Technical Summary

Technical Problem

The existing power grid security authentication method has loopholes in the data transmission process, requiring additional security measures, long and inconvenient processes, and ordinary ZKP methods require setting up new technical teams in the data storage and application places, which are inconvenient and costly.

Method used

Install the database server in the verified domain and the database client in the verified domain. Through the client-server interactive distribution calculation, the predefined zero-knowledge proof Fzkp-i algorithm is executed to realize data security authentication.

Benefits of technology

Simplifies the technology stack, improves security and efficiency, reduces costs, achieves transparent data protection for applications, and is easy to promote.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766083B_ABST
    Figure CN115766083B_ABST
Patent Text Reader

Abstract

The present invention provides a power grid security authentication method, belonging to the technical field of power grid security authentication. For this power grid security authentication method, a database client is installed in the verifier domain where data protection security authentication of the party to be verified is required for power grid applications, and a database server is installed in the domain of the party to be verified. It is characterized in that, through the client-server interactive distributed computing method, within the scope of database functions, the execution process of the corresponding predefined zero-knowledge proof Fzkp-i algorithm is realized. The method proposed by the present invention can, at the original location of the data (mostly the database), organically integrate the zero-knowledge proof method with common SQL statements, so as to achieve the effect of being imperceptible and almost invulnerable to brute-force attacks, so as to well solve the application requirements and the above problems, be well applied in the field of power grid-related security authentication, and can be fully popularized to other application fields.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power grid security authentication, and in particular, to a power grid security authentication method. Background Art

[0002] There are many security authentication requirements in the power grid IT application field, including identity authentication, data scope legality authentication, etc. In many cases in the power grid field, this kind of authentication is required to protect the actual data of the party to be verified, that is, on the premise that the party to be verified does not provide actual original data, the security characteristics (identity, scope, etc.) of the data it holds are authenticated, and attackers cannot crack it through brute-force calculation; traditional methods generally need to first store the data to be authenticated in a dedicated security area, and then design encryption or related methods to achieve it. However, this will bring some related problems: one is that there are loopholes in the process of data from the original location to the security area, or additional security measures are added to avoid this transmission loophole; the second is that in addition to the measures already existing in the original location of the data, it is also necessary to add design protection measures to the dedicated security area; the third is that it is also necessary to set up two different technical teams and application systems respectively, and the process is long and the efficiency is low when used at the same time. Such a method has a long process, many insecure links, requires an additional third-party environment, and at the same time, the authority and security of the third party need to be ensured. For a long time, this method has been much criticized and its promotion and use are extremely limited; while the ordinary two-party ZKP method also needs to specifically design different data storage and calculation domains outside the two parties of the data original storage location (i.e., the database) and the application location, and at the same time, the verifier and the party to be verified need to set up new technical links and teams respectively, which is extremely inconvenient to use. These problems have greatly affected the security, convenience, cost and efficiency of related applications.

[0003] How to invent a power grid security authentication method to improve these problems has become an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0004] To make up for the above deficiencies, the present invention provides a power grid security authentication method, aiming to improve the problems of extremely inconvenient use, low efficiency and high cost of the existing method.

[0005] The present invention is implemented as follows: A power grid security authentication method installs a database client in the verifier domain where data protection security authentication of the party to be verified is required in the power grid application, and installs a database server in the party to be verified domain. Through the client-server interactive distributed calculation method, within the scope of the database function, the execution process of the corresponding predefined zero-knowledge proof Fzkp-i algorithm is realized. The method includes the following steps:

[0006] Step 1: Pre-registration: This is performed once when the application is initialized: the database server pre-registers the identity value to be verified according to the verification conditions required by the database client, and registers the value of the predefined function Fzkp-i according to the verification conditions;

[0007] Step 2: Verify execution. The database client parses the SQL, obtains the predefined function Fzkp-i, finds that its ZKP verification method is y = gx, and sends the SQL to the server.

[0008] Step 3: The database server parses the SQL and obtains the predefined function Fzkp-i. It also learns that its ZKP verification method is y = gx. Based on the SQL condition, the server retrieves the data PROVEE to be verified from the corresponding database table T.

[0009] Step 4: The database server generates a random number sr, calculates t = gsr, and sends t to the client;

[0010] Step 5: The client first stores the t value, then generates a random number cr, and sends cr to the database server;

[0011] Step 6: The database server calculates p = sr + x * cr and sends the p value to the client. x is the HASH of the value PROVEE obtained in the database based on the SQL condition.

[0012] Step 7: The client finds the corresponding y value pre-registered in step 1 and calculates whether gp = ycr * t holds. If so, verification succeeds; otherwise, verification fails.

[0013] In a preferred technical solution of the present invention, in the application domain of the authenticator, a predefined function for performing predefined security authentication on specified data in a field of the authenticated party is called in SQL statement mode through a database client.

[0014] In a preferred technical solution of the present invention, the predefined function is SELECT FZKP-i(PROVEE) FROM T WHERE ID = constant, where PROVEE represents the field to be verified; ID = constant is the data condition in the field to be verified, T is the database table, Fzkp-i refers to the predefined authentication condition, and -i indicates that multiple predefined authentication conditions can be implemented independently;

[0015] In a preferred technical solution of the present invention, the authentication conditions represented by -i are identity and data range.

[0016] In a preferred technical solution of the present invention, the database client has an SQL parsing function. The client can parse out the predefined function type of Fzkp-i and interact with the server for execution according to the corresponding design.

[0017] In a preferred technical solution of the present invention, the specific logic description of the distributed calculation method through client-server interaction is as follows: When the application is initialized, the server first registers the value to be verified with the client; when the application runs, the server sends the commitment value commitment of the random value sr to the client; the client stores the commitment value commitment and sends the challenge random value cr to the server; the server executes the predefined encryption calculation to generate the response value scr = ServerResponse(sr, cr, PROVEE) and sends it to the client; the client executes the predefined encryption verification calculation ClientVerify(scr, commitment, cr) to implement the verification of the required data conditions. If all verifications pass, then Fzkp-i(PROVEE) returns true; the following steps will take the predefined function Fzkp-i as y = gx as an example to illustrate the detailed implementation process, that is, it means that the verifier believes that the verified party really knows the corresponding x such that y = gx holds.

[0018] In a preferred technical solution of the present invention, in step 1, during registration, the database server hashes the identity value PROVEE to be verified, and then calculates y = gx and sends it to the database client as the verification root for registration and storage.

[0019] In a preferred technical solution of the present invention, in step 3, the data PROVEE to be verified is the specific value of x.

[0020] The beneficial effects of the present invention are:

[0021] 1. The application party and the database do not need to do any additional work and do not need to make any architectural changes. Only by adopting the same method as the common "application-database" development mode, the data protection and anti-cracking security authentication of the verified party can be achieved, that is, it is completely transparent to the application and has high security;

[0022] 2. The SQL method is simple and easy to learn, completely shielding the difficulty of complex algorithms, and greatly improving the easy promotion and popularity of the method;

[0023] 3. The structure is simple, the process is short, the efficiency is high, and the technical cost of the application party is low.

[0024] The method proposed in the present invention can organically integrate the zero-knowledge proof method with commonly used SQL statements at the original location of the data (in most cases, the database), thereby achieving the effect of imperceptible and almost brute-force attack cracking, so as to well solve the application needs and the above problems. It is well applied in the field of power grid-related security authentication and can be fully promoted and popularized to other application fields. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0026] Figure 1 This is a block diagram of power grid security authentication provided by an embodiment of the present invention;

[0027] Figure 2 This is an example diagram of the ZKP verification process performed by the server and client in an embodiment of the present invention. DETAILED DESCRIPTION

[0028] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention. Example

[0029] See also Figure 1 and Figure 2 The present invention provides a technical solution: a power grid security authentication method, which installs a database client in the domain of the verifying party where the power grid application requires data protection security authentication of the verified party, and installs a database server in the domain of the verified party.

[0030] In the verification party's application domain, through the database client, in SQL statement mode, a predefined function for performing predefined security authentication on specified data in a certain field of the verified party is called, such as SELECT FZKP-i(PROVEE) FROM T WHERE ID = constant; where PROVEE represents the field to be verified; ID = constant is the data condition for which the requirement is to be verified in this field, and ID is only an example, and it can also be other non-ID conditions; T is the database table; Fzkp-i refers to the predefined authentication condition (i.e., a certain data meets a certain condition), and -i means that multiple predefined authentication conditions can be implemented by oneself, such as identity, data range, etc.; The present invention needs to add SQL parsing function in the database client, so that the client can parse out the Fzkp-i predefined function type and interact with the server for execution according to the corresponding design.

[0031] Through the interactive distributed computing method of the client (verification party) --- server (verified party), within the scope of the database function, the execution process of the corresponding predefined zero-knowledge proof Fzkp-i algorithm is realized. The specific logic description is as follows: When the application is initialized, the server first registers the value to be verified with the client; when the application runs, the server sends the commitment value commitment of the random value sr to the client; the client stores the commitment value commitment and sends the challenge random value cr to the server; the server executes the predefined encryption calculation to generate the response value scr = ServerResponse(sr, cr, PROVEE) and sends it to the client; the client executes the predefined encryption verification calculation ClientVerify(scr, commitment, cr) to implement the verification of the required data conditions. If all verifications pass, then Fzkp-i(PROVEE) returns true;

[0032] The following steps take the predefined function Fzkp-i as y = gx as an example to illustrate the detailed implementation process, that is, it means that the verification party believes that the verified party really knows the corresponding x such that y = gx holds;

[0033] The innovation of the present invention lies in implementing ZKP in the database SQL way of client --- server distributed computing. For other ZKP implementation methods different from the following examples, they can also be implemented by themselves according to the design architecture and process of this patent.

[0034] This method includes the following steps:

[0035] Step 1: Pre-registration: When the application is initialized, execute once: The database server pre-registers the identity values to be verified according to the verification conditions required by the database client, and registers the values of the predefined function Fzkp-i according to the verification conditions. Taking y = gx as an example, the database server (the party to be verified) hashes the identity value to be verified, PROVEE (such as MD5), and then calculates y = gx and sends it to the database client (the verifying party) as the verification root for registration and storage.

[0036] Step 2: Verification execution. The database client (i.e., the verifying party, the power grid application side) parses the SQL, obtains the predefined function Fzkp-i, and learns that its ZKP verification method is y = gx, and sends the SQL to the server.

[0037] Step 3: The database server (the party to be verified) parses the SQL, obtains the predefined function Fzkp-i, also learns that its ZKP verification method is y = gx, and retrieves the data to be verified, PROVEE (i.e., the specific value of x) from the corresponding database table T according to the SQL conditions.

[0038] Step 4: The database server (the party to be verified) generates a random number sr, calculates t = gsr, and sends t to the client (the verifying party).

[0039] Step 5: The client (the verifying party) first stores the value of t, then generates a random number cr, and sends cr to the database server (the party to be verified).

[0040] Step 6: The database server (the party to be verified) calculates p = sr + x * cr, and sends the value of p to the client (the verifying party); x is the hash of the value PROVEE obtained according to the SQL conditions in the database, that is, MD5(PROVEE).

[0041] Step 7: The client finds the corresponding y value pre-registered in Step 1, calculates and determines whether gp = ycr * t holds. If it holds, the verification is successful; if not, the verification fails.

[0042] The method proposed in the present invention aims to achieve brute-force-unbreakable data security authentication on the premise of protecting the privacy of the verified party in the way of the inherent characteristics of the database, which is a common scenario requirement in power grid applications. Thus, the security authentication of data protection becomes a database call process that is transparent to the application. Compared with the traditional method, it simplifies the technology stack, effectively improves the security, convenience and efficiency of the implementation process, and reduces the cost. First, the present invention transforms the implementation method of SQL from the general client sending requests and receiving results - server-side computing mode into a client-server interactive distributed computing mode. Secondly, the implementation of data security authentication in power grid applications is transformed into a common SQL call process for database applications by database application developers. General database application developers can achieve it simultaneously with application development without any additional storage area and protection process. Then, the zero-knowledge proof (ZKP) method for privacy data protection is implemented as relevant data security authentication functions (identity, scope, etc.) in the database. The implementation method of ZKP-related functions in SQL syntax is completed through the above-mentioned database client-server interactive distributed computing, so that the data of the verified party can achieve the effect of reliable security authentication without leaving the original domain where the data is located (i.e., in the database) through database SQL operations. The present invention provides a new and application-transparent database implementation method for the data security authentication required by power grid-related applications, without the users of the method having to master any new technology stack and without establishing any security area independent of the database. Thus, to a considerable extent, it effectively improves the quality and efficiency of data security authentication in power grids and similar scenarios, and provides an innovative idea worthy of reference for designing and producing more and wider methods along this direction.

[0043] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A power grid security authentication method, which installs a database client in the verifier domain that requires data protection security authentication for the party to be verified in the power grid application, and installs a database server in the domain of the party to be verified, characterized in that, Through the client-server interaction distributed computing method, within the scope of database functions, the execution process of the corresponding predefined zero-knowledge proof Fzkp-i algorithm is implemented. The method includes the following steps: Step 1: Pre-registration: At the initialization of the application, execute once: The database server pre-registers the identity values to be verified according to the verification conditions required by the database client, and registers the values of the predefined function Fzkp-i according to the verification conditions; Step 2: Verification execution, the database client parses the SQL, obtains the predefined function Fzkp-i, learns that its ZKP verification method is y = gx, and sends the SQL to the server; Step 3: The database server parses the SQL, obtains the predefined function Fzkp-i, also learns that its ZKP verification method is y = gx, and retrieves the data to be verified PROVEE from the corresponding database table T according to the SQL conditions; Step 4: The database server generates a random number sr, calculates t = gsr, and sends t to the client; Step 5: The client first stores the t value, then generates a random number cr, and sends cr to the database server; Step 6: The database server calculates p = sr + x * cr, and sends the p value to the client, where x is the HASH of the value PROVEE obtained according to the SQL conditions in the database; Step 7: The client finds the corresponding y value pre-registered in Step 1, calculates and judges whether gp = ycr * t holds. If it holds, the verification is successful; if not, the verification fails.

2. The power grid security authentication method according to claim 1, characterized in that, In the verification party application domain, through the database client, in the SQL statement mode, a predefined function for performing predefined security authentication on the specified data of a certain field of the party to be verified is called.

3. The power grid security authentication method according to claim 2, wherein The predefined function is SELECT FZKP-i(PROVEE) FROM T WHERE ID = constant, where PROVEE represents the field to be verified; ID = constant is the data condition for which verification is required in this field, T is the database table, and Fzkp-i refers to the predefined authentication condition, and -i means that multiple predefined authentication conditions can be implemented by oneself.

4. The power grid security authentication method according to claim 3, wherein The authentication conditions represented by -i are identity and data range.

5. The power grid security authentication method according to claim 2, wherein This database client has an SQL parsing function. The client can parse out the type of the Fzkp-i predefined function and interact with the server for execution according to the corresponding design.

6. The power grid security authentication method according to claim 1, wherein The specific logic of the distributed computing method through client-server interaction is described as follows: When the application is initialized, the server first registers the values to be verified with the client; when the application is running, the server sends the commitment value of the random value sr to the client; the client stores the commitment value commitment and sends the challenge random value cr to the server; the server executes the predefined encryption calculation to generate the response value scr = ServerResponse(sr, cr, PROVEE) and sends it to the client; the client executes the predefined encryption verification calculation ClientVerify(scr, commitment, cr) to implement the verification of the required data conditions. If all verifications pass, Fzkp-i(PROVEE) returns true; the following steps take the predefined function Fzkp-i with y = gx as an example to illustrate the detailed implementation process, that is, the verifier believes that the verified party really knows the corresponding x such that y = gx holds.

7. The power grid security authentication method according to claim 1, wherein In step 1, during registration, the database server hashes the identity value PROVEE to be verified, and then calculates y = gx and sends it to the database client as the verification root for registration and storage.

8. The power grid security authentication method according to claim 1, characterized in that, In step 3, the data PROVEE to be verified is the specific value of x.

Citation Information

Patent Citations

  • Data security management method of power business terminal

    CN107743125A

  • Smart contract authentication data privacy protection method based on zero knowledge proof

    CN109614820A