Completely peer-to-peer trusted power Internet of Things and its construction method

By adopting offline servers to generate key pairs and multiple trust challenges in the power Internet of Things, peer-to-peer trusted communication is established, and the security threats of terminal devices and bottlenecks in online authentication servers are solved, and efficient identity authentication and secure communication are achieved.

CN115801422BActive Publication Date: 2025-08-12STATE GRID LIAONING SHENYANG ELECTRIC POWER SUPPLY COMPANY +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211503196.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-08-12
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

The main security threats faced by IoT terminal devices in the existing power Internet of Things are illegal use, counterfeiting and malicious attacks, and online authentication servers have become performance bottlenecks and targets of network communication.

Method used

Using a fully peer-to-peer trustworthy power Internet of Things construction method, the terminal device generates key pairs and device numbers through offline servers. When joining the network, the terminal device needs to establish peer-to-peer trustworthy communication through the trust challenges of multiple random challengers and cancel the participation of the online authentication server.

Benefits of technology

It improves the identity authentication efficiency of terminal devices, reduces the probability of counterfeit devices passing through trust challenges, forms a peer-to-peer trusted network, and avoids performance bottlenecks and security risks of online authentication servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801422B_ABST
    Figure CN115801422B_ABST
Patent Text Reader

Abstract

The present invention discloses a fully peer-to-peer trusted electric power Internet of Things and a method for establishing the same. According to the establishment method, for a terminal device newly added to the electric power Internet of Things, only after successfully passing the trust challenge of multiple existing trusted terminal devices in the electric power Internet of Things can it successfully join the electric power Internet of Things and become a new trusted terminal device in the electric power Internet of Things. In the subsequent communication process, the terminal device can directly conduct trusted communication with other trusted terminal devices in the electric power Internet of Things without the participation of an online authentication server. The trusted electric power Internet of Things established by the above method can effectively prevent other counterfeit and untrusted terminal devices from accessing the electric power Internet of Things and thereby damaging the communication and control of the electric power Internet of Things. There is no online authentication server in the trusted electric power Internet of Things established by the above method, and all terminal devices are peer-to-peer trusted, completely eliminating the central security risks and performance bottlenecks of the online authentication server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of electric power Internet of Things, peer-to-peer networks, and trusted networks, and in particular to a fully peer-to-peer trusted electric power Internet of Things and a method for establishing the same. Background Art

[0002] The Internet of Things is based on the Internet and uses radio frequency identification, QR codes, infrared sensors, GPS and other devices to connect devices to each other through wireless data communication and other means, and access the Internet in a certain way, ultimately constructing an intelligent network covering everything.

[0003] The Power Internet of Things (PoI) is the specific manifestation and application of the Internet of Things in the power industry. By connecting power users and their equipment, grid companies and their equipment, power generation companies and their equipment, and suppliers and their equipment, it generates shared data and thus serves users, grids, power plants, suppliers, and the government. Therefore, with the grid as its hub, the PoI can play a platform and sharing role, creating greater opportunities for the development of the entire industry and more market players, and providing more valuable services.

[0004] IoT terminal devices within the power Internet of Things (PoT) are typically deployed across multiple power grid segments, including transmission, distribution, and utilization. These intelligent terminals or devices often operate in unattended or uncontrollable environments, making it easy for attackers to gain direct access to the devices and carry out physical damage, forge devices through cloning, or conduct attacks such as information theft, software tampering, and remote control through various means, both near and far. Currently, the primary security threats facing IoT terminal devices, particularly within the widespread power Internet of Things (PoT), are illegal use, counterfeiting, and malicious attacks.

[0005] Traditional security protection methods use online authentication servers to implement identity authentication between devices in the network, thereby achieving encrypted communication. However, online authentication servers are not only prone to becoming performance bottlenecks for network communications, but also often become the focus of network attacks. Once the online authentication server is compromised, the entire network will fall or collapse.

[0006] Therefore, how to develop and establish a trusted power Internet of Things so that Internet of Things terminal devices can improve the security protection level of the power Internet of Things through security technologies such as identity authentication and encrypted communication has become an urgent problem to be solved. Summary of the Invention

[0007] In view of this, the present invention provides a fully peer-to-peer trusted electric power Internet of Things and a method for establishing the same to solve the problems existing in the prior art.

[0008] On one hand, the present invention provides a method for establishing a fully peer-to-peer trusted electric power Internet of Things, comprising the following steps:

[0009] S1: Initialization of the Trusted Power Internet of Things: Establishing a minimum-scale peer-to-peer trusted power Internet of Things, which includes multiple trusted terminal devices;

[0010] S2: Trusted Network Access: A new terminal device is added to the established peer-to-peer trusted power Internet of Things. The terminal device requesting access can only successfully join the power Internet of Things and become a new trusted terminal device in the power Internet of Things after successfully passing the trust challenge of multiple existing trusted terminal devices in the power Internet of Things.

[0011] S3: Trusted Communication: Trusted data communication between any two terminal devices in the Trusted Power Internet of Things;

[0012] S4: Trusted network exit: Remove the terminal device connected to the trusted power Internet of Things from the trusted power Internet of Things without affecting the trusted communication of other terminal devices in the trusted power Internet of Things.

[0013] Preferably, the trusted power Internet of Things initialization includes the following steps:

[0014] S101: Generate a key pair for each trusted terminal device included in the initialization of the trusted power Internet of Things according to a unified public key system algorithm, wherein the key pair includes a public key and a private key, which are randomly generated by the terminal device itself, and the generated key pair is correspondingly stored in a key tag in the memory of the trusted terminal device itself;

[0015] S102: The offline server assigns a device number and a device random number to each initial trusted terminal device and stores them in a device list in the offline server's own memory. At the same time, each terminal device stores its assigned device number and device random number in a device tag in its own memory.

[0016] S103: The offline server collects the public key of each initial trusted terminal device, and stores the device number and corresponding public key of each initial trusted terminal device into a public key list in the memory of all initial trusted terminal devices.

[0017] Further preferably, in the trusted network access step, the trusted terminal device that initiates the trust challenge is randomly selected.

[0018] Further preferably, the trusted network access includes the following steps:

[0019] S201: The terminal device requesting access generates a key pair according to a unified public key system algorithm and stores it in a key tag in its own memory;

[0020] S202: The offline server assigns a device number and a device random number to the terminal device requesting access and stores them in a device list in the offline server's own memory. At the same time, the terminal device requesting access saves its assigned device number and device random number in a device tag in its own memory.

[0021] S203: The offline server randomly selects multiple trusted terminal devices from its own device list as trust challengers of the terminal device requesting access, and saves the device numbers and device random numbers of the selected multiple trust challengers into the challenger list of the terminal device memory requesting access;

[0022] S204: The terminal device requesting access sends a broadcast message to other trusted terminal devices in the power Internet of Things to request a trust challenge, wherein the broadcast message sent by the terminal device requesting access includes the device numbers of three trust challengers in the challenge list stored in its own memory;

[0023] S205: The trusted terminal device in the power Internet of Things receives the broadcast message requesting a trust challenge sent by the terminal device requesting access, and checks whether the challenger device number in the message contains its own device number. If so, the trusted terminal device sends a trust challenge message to the terminal device requesting access; otherwise, the trusted terminal device ignores the broadcast message requesting a trust challenge.

[0024] S206: After receiving the trust challenge messages from all trust challengers, the terminal device requesting access sends challenge response messages to each trust challenger. The trust challenger checks the received challenge response messages and the response results. If the response results are correct, the trust challenger searches for the device number of the terminal device requesting access in the challenged list in the trust challenger's memory and increases the challenge counter value of the found record by 1. If the response results are incorrect, no action is taken.

[0025] S207: After the trusted challenger checks that the response result is correct, it broadcasts a challenge success message to the power Internet of Things. The challenge success message includes the device number and device public key of the challenged party. After receiving the challenge success message, other trusted terminal devices in the power Internet of Things search for the record of the challenged party's device number in the challenged party list in their own memory and increase the challenge counter value of the found record by 1.

[0026] S208: After all trust challengers have sent challenge success messages, the counter value of the challenged record corresponding to the terminal device requesting access in the challenged list in the memory of the existing trusted terminal device in the power Internet of Things is added to the number of trust challengers. At this time, the existing trusted terminal device in the power Internet of Things writes the device number and device public key of the challenged device into the public key list in its own memory, and then deletes the challenged record corresponding to the terminal device requesting access in the challenged list in its own memory;

[0027] S209: After the terminal device requesting access becomes a trusted terminal device in the power Internet of Things, it randomly starts trusted communication with one of the trusted terminal devices of the trust challenger, and requests the trust challenger to send a public key list to itself; the selected trust challenger responds to the request of the new terminal device requesting access, and sends the complete public key list in its own memory to the terminal device requesting access.

[0028] Further preferably, the trust challenger sends a challenge message, and the challenged responds to the challenge response message, including the following steps:

[0029] S20601: The trust challenger generates a random number nrv and sends a challenge message to the challenged. The content of the challenge message is: strcat (challenger's device number, random number nrv), where the strcat() function represents multiple strings in the concatenation parameter table.

[0030] S20602: The challenged party receives the challenge message sent by the trusting challenger, generates a challenge response message, and sends it to the trusting challenger. The content of the challenge response message is: strcat(challenged party's device number, challenged party's device public key, Hval-old), where Hval-old = H(strcat(challenger's device number, random number nrv, challenger's device random number)), where the H() function represents a hash function in the encryption algorithm, and the challenger's device random number is obtained from the challenger list in the challenged party's memory.

[0031] S20603: The trusted challenger receives the challenge response message returned by the challenged and checks the response result. The method for the trusted challenger to check the response result is as follows: the trusted challenger separates the challenged device number, the challenged device public key, and the hash function value Hval-old from the received response message. The trusted challenger recalculates Hval-new = H(strcat(challenger's device number, random number nrv, challenger's device random number)) and compares it with the Hval-old value. If the two are the same, the response result is correct, otherwise the response result is incorrect.

[0032] Further preferably, the trusted data communication means that both communicating parties have performed two-way identity authentication, and the transmitted data is encrypted data.

[0033] Further preferably, the trusted communication between terminal device A and terminal device B includes the following steps:

[0034] S301: Terminal device A generates a random number A and sends it to terminal device B. Terminal device B uses its own private key to encrypt the received random number A to obtain a signature value Sign_B. Terminal device B generates a random number B and sends the random number B and signature value Sign_B to terminal device A.

[0035] S302: Terminal device A receives the message sent back by terminal device B, searches for terminal device B's public key based on the device number of terminal device B in the public key list in terminal device A's memory, uses the found public key of terminal device B to decrypt the signature value Sign_B, and compares the decrypted value with the random number A sent previously. If the two are the same, terminal device B is proven to be trustworthy. Otherwise, terminal device B is untrustworthy, and terminal device A terminates communication with terminal device B.

[0036] S303: Terminal device A uses its own private key to encrypt the received random number B to obtain the signature value Sign_A. Terminal device A then sends the signature value to terminal device B. Terminal device B receives the message sent back by terminal device A, searches for terminal device A's public key in the public key list in terminal device B's memory based on terminal device A's device number, decrypts the signature value Sign_A using the found public key of terminal device A, and compares the decrypted value with the random number B sent previously. If the two are the same, terminal device A is proven to be trustworthy. Otherwise, terminal device A is untrustworthy, and terminal device B terminates communication with terminal device A.

[0037] S304: Terminal device B randomly generates a symmetric encryption key Key, encrypts the symmetric encryption key Key using the public key of terminal device A, and sends the encrypted key to terminal device A.

[0038] S305: Terminal device A receives the encrypted symmetric encryption key sent by terminal device B and decrypts it using its own private key to obtain the symmetric encryption key Key;

[0039] S306: Terminal device A encrypts the plaintext data to be sent to terminal device B using the symmetric encryption key Key to obtain the ciphertext data and sends it to terminal device B;

[0040] S307: Terminal device B receives the ciphertext data sent by terminal device A and decrypts the ciphertext data using the symmetric encryption key Key to obtain the plaintext data.

[0041] S308: Terminal device B encrypts the plaintext data to be sent to terminal device A using the symmetric encryption key Key to obtain the ciphertext data and sends it to terminal device A.

[0042] S309: Terminal device A receives the ciphertext data sent by terminal device B, and uses the symmetric encryption key Key to decrypt the ciphertext data to obtain the plaintext data.

[0043] Further preferably, the trusted network exit includes the following steps:

[0044] S401: Physically remove a trusted terminal device A from the trusted power Internet of Things;

[0045] S402: Delete the device number and device random number record corresponding to the trusted terminal device A from the device list of the offline server storage.

[0046] The present invention also provides a completely peer-to-peer trusted electric power Internet of Things, comprising a plurality of Internet of Things terminal devices and an offline server;

[0047] The IoT terminal device includes a memory, wherein the memory stores a key tag, a device tag, a public key list, a challenger list, and a challenged list;

[0048] The key tag of the IoT terminal device is used to store the device's own private key and public key for identity authentication in trusted communication between devices;

[0049] The device tag of the IoT terminal device is used to store the device number and device random number assigned to the device by the offline server;

[0050] The public key list of the Internet of Things terminal device is a list storing public key records of multiple trusted terminal devices in the trusted power Internet of Things, each record in the list includes a device number and a corresponding device public key;

[0051] The challenger list of the IoT terminal device is used to store the device record of the trusted challenger randomly selected by the offline server, which is called the challenger record. The challenger record in the list includes the device number and the corresponding device random number;

[0052] The challenged list of the IoT terminal device stores a record of the terminal device that first accesses the trusted power IoT, which is called a challenged record. The challenged record in the list includes the device number, device public key and challenge counter of the challenged device;

[0053] A device list is stored in the memory of the offline server. Each device record stored in the device list includes a device number and a device random number assigned to the device by the offline server.

[0054] Preferably, the offline server is stored independently and is not connected to the trusted power Internet of Things in any form.

[0055] The present invention provides a method for establishing a fully peer-to-peer trusted electric power Internet of Things. When an IoT terminal device first accesses the trusted Internet of Things, the offline server first obtains challenge knowledge. Only the terminal device that has obtained the challenge knowledge can successfully pass the trust challenges of multiple random challengers in the trusted electric power Internet of Things and eventually become a trusted terminal device. Since the trust challenges are random and multiple challenges, the probability risk of counterfeit devices successfully passing the trust challenges through guessing attacks is reduced. The trusted electric power Internet of Things established using the method of the present invention is a peer-to-peer trusted network. Authentication between devices does not require the participation of an online authentication server or other trusted third party, thereby improving the efficiency of device identity authentication during the communication process. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0058] Figure 1 A flowchart of a method for establishing a fully peer-to-peer trusted electric power Internet of Things provided by an embodiment of the present invention;

[0059] Figure 2 A schematic diagram of the process of initializing a trusted electric power Internet of Things in the method for establishing a fully peer-to-peer trusted electric power Internet of Things provided by an embodiment of the present invention;

[0060] Figure 3 A schematic diagram of the trusted network access process in the method for establishing a fully peer-to-peer trusted electric power Internet of Things provided by an embodiment of the present invention;

[0061] Figure 4 A schematic diagram of the trust challenge and response process in the method for establishing a fully peer-to-peer trusted electric power Internet of Things provided by an embodiment of the present invention;

[0062] Figure 5A schematic diagram of the trusted communication process in the method for establishing a fully peer-to-peer trusted electric power Internet of Things provided by an embodiment of the present invention;

[0063] Figure 6 A diagram of the components of a fully peer-to-peer trusted electric power Internet of Things provided in accordance with the disclosed embodiment of the present invention. DETAILED DESCRIPTION

[0064] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent like or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present invention. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present invention, as detailed in the appended claims.

[0065] The present invention provides a method for establishing a completely peer-to-peer trusted power Internet of Things. Figure 1 , including the following steps:

[0066] S1: Initialization of the trusted power Internet of Things: Establishing a minimum-scale peer-to-peer trusted power Internet of Things, which includes multiple trusted terminal devices (three in this embodiment);

[0067] S2: Trusted Network Access: A new terminal device is added to the established peer-to-peer trusted power Internet of Things. A terminal device requesting access can only successfully join the power Internet of Things and become a new trusted terminal device after successfully passing the trust challenge of multiple existing trusted terminal devices in the power Internet of Things. The multiple existing trusted terminal devices that initiate the trust challenge are randomly selected.

[0068] In this embodiment, the number of random challengers is three. To increase the difficulty for a counterfeit device to use a guessing attack to become a trusted terminal device, the number of random challengers is allowed to be more than three, but cannot be greater than the number of trusted terminal devices in the minimum network size formed by the initialization of the trusted power Internet of Things.

[0069] S3: Trusted Communication: Trusted data communication is carried out between any two terminal devices in the Trusted Power Internet of Things. Trusted data communication means that the communicating parties have undergone two-way identity authentication and the transmitted data is encrypted data.

[0070] S4: Trusted network exit: Remove the terminal device connected to the trusted power Internet of Things from the trusted power Internet of Things without affecting the trusted communication of other terminal devices in the trusted power Internet of Things.

[0071] Among them, see Figure 2,Trusted Power Internet of Things initialization, includes the following steps:

[0072] S101: Generate a pair of keys (public key K-pub and private key K-pri) for the three trusted terminal devices included in the trusted power Internet of Things initialization according to a unified public key system algorithm. The key pair of each terminal device is randomly generated by the terminal device itself, and the generated key pair is stored in the key tag in its own memory;

[0073] In this embodiment, the public key standard algorithm SM2 algorithm specified in my country's cryptographic standards is used;

[0074] S102: The offline server assigns a device number and a device random number Dev-nrv to the three initial trusted terminal devices and stores them in a device list in the offline server's own memory. At the same time, each terminal device saves its assigned device number and device random number in a device tag in its own memory;

[0075] To prevent guessing attacks, the random numbers assigned to devices must not be reused. Therefore, the offline server should have as large a space as possible for random numbers generated by the device. In this embodiment, a fixed-length 10-decimal random number is used, and no requirements are placed on the device number.

[0076] In this embodiment, the device list of the offline server is implemented using a sequential table. Each record in the sequential table of the device list includes two data items: a device number and a device random number.

[0077] S103: The offline server collects the public keys of the three initial trusted terminal devices, and stores the device numbers and corresponding public keys of the three initial trusted terminal devices into a public key list in the storage of all three initial trusted terminal devices.

[0078] In this embodiment, the public key list in the memory of the trusted terminal device is implemented using a sequential table, and each record in the sequential table of the public key list includes two data items: the device number and the device public key;

[0079] In this method, all terminal devices involved in the initialization of the trusted power Internet of Things must be trusted, and these devices store the public keys of other devices among each other. During the initialization phase, the public keys of these other devices are provided by an offline server rather than obtained through trusted network access. The offline initialization operation ensures the trustworthiness of all terminal devices in the initialized power Internet of Things. In the initially established trusted power Internet of Things, each trusted terminal device stores the public keys of other terminal devices, so peer-to-peer identity authentication of private key signature and public key verification can be achieved without the participation of an online authentication server. Therefore, the initially established trusted power Internet of Things is a peer-to-peer network.

[0080] Among them, see Figure 3 In the peer-to-peer trusted power Internet of Things, the initial access of a terminal device to the trusted power Internet of Things is called trusted network access, which includes the following steps:

[0081] S201: The terminal device requesting access generates a pair of keys (a public key K-pub and a private key K-pri) according to a unified public key system algorithm. The key pair of the terminal device requesting access is randomly generated by the terminal device itself and is stored in a key tag in its memory.

[0082] In this embodiment, the public key standard algorithm SM2 algorithm specified in my country's cryptographic standards is used;

[0083] S202: The offline server allocates a device number and a device random number to the terminal device requesting access. The offline server stores the device number and the corresponding device random number allocated to the terminal device requesting access in a device list in its own memory. The terminal device requesting access stores the device number and device random number allocated to itself in a device tag in its own memory.

[0084] To prevent guessing attacks, the random number assigned to the device must not be reused. In this embodiment, a fixed-length 10-decimal random number is used.

[0085] S203: The offline server randomly selects three trusted terminal devices from its own device list as trust challengers for the terminal device requesting access; the offline server saves the device numbers and device random numbers of the three selected trust challengers to the challenger list in the memory of the terminal device requesting access;

[0086] In this embodiment, the challenger list in the terminal device memory is implemented using a sequential table. Each record in the challenger list sequential table contains two data items: the device number and the device random number. In this embodiment, since the number of challengers is 3, the challenger list sequential table only contains three records.

[0087] In this embodiment, the terminal device requesting access is represented as Dev, and the three randomly selected challenger terminal devices are represented as Dev1, Dev2, and Dev3. In this embodiment, the initially established trusted power Internet of Things includes three trusted terminal devices. When the fourth terminal device Dev requests access to the trusted power Internet of Things, the three trusted terminal devices included in the initial establishment are selected as trust challengers.

[0088] S204: The terminal device requesting access sends a broadcast message to other trusted terminal devices in the power Internet of Things to request a trust challenge; the broadcast message sent by the terminal device requesting access includes the device numbers of three trust challengers in the challenge list stored in its own memory;

[0089] S205: Other trusted terminal devices in the power Internet of Things receive the broadcast message requesting a trust challenge sent by the terminal device requesting access, and check whether the challenger device number in the message contains their own device number; if so, the trusted terminal device sends a trust challenge message to the terminal device requesting access, otherwise, the trusted terminal device ignores the broadcast message requesting a trust challenge;

[0090] S206: After receiving the trust challenge messages sent by the three trust challengers, the terminal device requesting access sends challenge response messages to the trust challengers respectively; the trust challenger checks the received challenge response messages and the response results. If the response results are correct, the trust challenger searches for the record of the device number of the terminal device requesting access in the challenged list in the trust challenger's memory (if such a record cannot be found, a new record is added to the challenged list in the trust challenger's memory, and the device number and device public key values of the newly added record are assigned to the device number and device public key value of the terminal device requesting access, and the challenge counter value of the newly added record is assigned to 0), and the challenge counter value of the found record is increased by 1; if the response result is incorrect, no processing is performed;

[0091] In this embodiment, the challenged list in the terminal device memory is implemented using a sequential table. Each record in the challenged list sequential table includes three data items: device number, device public key, and challenge counter. In this embodiment, since multiple terminal devices requesting access may request challenges at the same time, the challenged list sequential table may contain multiple challenged records.

[0092] S207: After the trusted challenger checks that the response result is correct, it broadcasts a challenge success message to the power Internet of Things, which includes the device number and device public key of the challenged (i.e., the terminal device requesting access); after receiving the challenge success message, other trusted terminal devices in the power Internet of Things find the record of the challenged device number in the challenged list in their own memory (if no such record is found, a new record is added to the challenged list in their own memory, and the device number and device public key values of the newly added record are assigned to the device number and device public key values of the challenged, and the challenge counter value of the newly added record is assigned to 0), and the challenge counter value of the found record is increased by 1;

[0093] S208: When all three trust challengers send challenge success messages, the counter value of the challenged record corresponding to the terminal device requesting access in the challenged list in the memory of the existing trusted terminal device in the power Internet of Things is accumulated to 3, indicating that the terminal device requesting access has successfully passed the trust challenges of the three trust challengers and can become a trusted terminal device in the power Internet of Things. At this time, the existing trusted terminal device in the power Internet of Things writes the device number and device public key of the challenged device into the public key list in its own memory, and then deletes the challenged record corresponding to the terminal device requesting access in the challenged list in its own memory;

[0094] S209: After the terminal device requesting access becomes a trusted terminal device in the power Internet of Things, it randomly starts trusted communication with one of the three trusted challengers and requests the challenger to send a public key list to itself. The selected challenger responds to the request of the terminal device requesting access and sends the complete public key list in its own memory to the terminal device requesting access.

[0095] After completing the above steps S201 to S209, the terminal device requesting access becomes a trusted terminal device in the power Internet of Things and can conduct fully peer-to-peer trusted communications with other trusted terminal devices in the power Internet of Things; if any of the three trust challenges fails to respond, the terminal device requesting access cannot become a trusted terminal device in the power Internet of Things.

[0096] In this embodiment, the offline server randomly selects three trust challengers. The terminal device requesting access must successfully pass the challenges of all three trust challengers before it can become a trusted terminal device and access the trusted power Internet of Things on a peer-to-peer basis. In other embodiments, more than three random challengers, such as five, are selected. The terminal device requesting access must successfully pass the challenges of all five trust challengers before it can become a trusted terminal device and access the trusted power Internet of Things on a peer-to-peer basis.

[0097] Among them, see Figure 4 , the trust challenger issues a challenge, and the challenged responds to the challenge, including the following steps:

[0098] S20601: The trusted challenger generates a random number nrv and sends a challenge message to the challengee. The content of the challenge message is: strcat (challenger's device number, random number nrv), where the strcat() function represents multiple strings in the concatenation parameter table.

[0099] In this embodiment, a fixed-length device number of the challenger and a fixed-length challenge random number nrv are used, and the two are concatenated and sent as a challenge message to the challenged. The fixed length is used to simplify the program processing.

[0100] S20602: The challenged party receives the challenge message sent by the trusting challenger, generates a challenge response message, and sends it to the trusting challenger. The content of the challenge response message is: strcat(challenged party's device number, challenged party's device public key, Hval-old), where Hval-old = H(strcat(challenger's device number, random number nrv, challenger's device random number)). The H() function represents a hash function in the encryption algorithm, and the challenger's device random number is obtained from the challenger list in the challenged party's memory.

[0101] In this embodiment, the hash function H() uses the SM3 algorithm of my country's cryptographic standard to generate a 256-bit hash value, that is, Hval-old is a 256-bit hash value;

[0102] S20603: The trusted challenger receives the challenge response message returned by the challenged and checks the response result. The trusted challenger checks the response result by separating the challenged device number, the challenged device public key, and the hash function value Hval-old from the received response message. The trusted challenger recalculates Hval-new = H(strcat(challenger's device number, random number nrv, challenger's device random number)). The trusted challenger compares Hval-new and Hval-old. If the two are the same, the response result is correct; otherwise, the response result is incorrect.

[0103] In the above step S20603, if the response result is correct, it indicates that the terminal device requesting access has obtained the challenger's device random number from the offline server, and is thus able to make a correct response to the challenger's challenge; if the response result is incorrect, it indicates that the terminal device requesting access has not obtained the challenger's device random number from the offline server, and is therefore unable to make a correct response to the challenger's challenge; only terminal devices that can make correct responses to all three challenges can become trusted terminal devices and access the Power Internet of Things; otherwise, the terminal device requesting access will be regarded as an untrusted terminal device attempting to access the Power Internet of Things through a guessing attack;

[0104] Among them, see Figure 5 , the trusted communication between two trusted terminal devices (terminal device A and terminal device B) includes the following steps:

[0105] S301: Terminal device A generates a random number A and sends it to terminal device B. Terminal device B uses its own private key to encrypt the received random number A to obtain a signature value Sign_B. Terminal device B generates a random number B and sends the random number B and signature value Sign_B to terminal device A.

[0106] In this embodiment, terminal device B uses its private key to encrypt random number A to generate a digital signature of terminal device B. The public key signature algorithm used is the national secret standard SM2 algorithm. To accelerate the two-way identity authentication process and reduce the number of data packets sent back and forth between the two parties during the authentication process, terminal device B sends its own digital signature to terminal device A to identify itself, and also sends random number B to request verification of terminal device A's identity.

[0107] S302: Terminal device A receives the message sent back by terminal device B, searches for terminal device B's public key based on the device number of terminal device B in the public key list in terminal device A's memory, uses the found public key of terminal device B to decrypt the signature value Sign_B, and compares the decrypted value with the random number A sent previously. If the two are the same, terminal device B is proven to be trustworthy. Otherwise, terminal device B is untrustworthy and terminal device A terminates communication with terminal device B.

[0108] In this embodiment, the algorithm used by terminal device A to verify the digital signature of terminal device B using the public key of terminal device B must be the same as the public key cryptography algorithm used above, that is, the national secret standard algorithm SM2;

[0109] S303: Terminal device A uses its own private key to encrypt the received random number B to obtain the signature value Sign_A. Terminal device A then sends the signature value to terminal device B. Terminal device B receives the message sent back by terminal device A, searches for terminal device A's public key in the public key list in terminal device B's memory based on terminal device A's device number, decrypts the signature value Sign_A using the found public key of terminal device A, and compares the decrypted value with the random number B sent previously. If the two are the same, terminal device A is proven to be trustworthy. Otherwise, terminal device A is untrustworthy and terminal device B terminates communication with terminal device A.

[0110] The above steps S301 to S303 implement bidirectional identity authentication between terminal device A and terminal device B before data communication;

[0111] S304: Terminal device B randomly generates a symmetric encryption key Key (the trusted power Internet of Things is set to use a uniformly designated symmetric encryption algorithm). Terminal device B encrypts the symmetric encryption key Key using the public key of terminal device A and sends it to terminal device A.

[0112] In this embodiment, the symmetric encryption algorithm uses the national secret standard algorithm SM1 to generate a 128-bit symmetric encryption key. Terminal device B uses terminal device A's public key to encrypt the symmetric encryption key Key. Only terminal device A can decrypt it using its own private key. Other eavesdroppers cannot decrypt it, thus ensuring the security of the symmetric encryption key.

[0113] S305: Terminal device A receives the encrypted symmetric encryption key sent by terminal device B and decrypts it using its own private key to obtain the symmetric encryption key Key;

[0114] The above steps S304 to S305 implement the negotiation between the trusted terminal device A and the trusted terminal device B to share the symmetric encryption key;

[0115] S306: Terminal device A encrypts the plaintext data to be sent to terminal device B using the symmetric encryption key Key to obtain the ciphertext data and sends it to terminal device B;

[0116] In this embodiment, after completing bidirectional identity authentication and symmetric key sharing, terminal device A and terminal device B use the symmetric encryption key to encrypt subsequent communication data to form ciphertext transmission, which can ensure the confidentiality and integrity of the transmitted data. In this embodiment, the symmetric encryption algorithm uses the national secret standard algorithm SM1.

[0117] S307: Terminal device B receives the ciphertext data sent by terminal device A and decrypts the ciphertext data using the symmetric encryption key Key to obtain the plaintext data.

[0118] S308: Terminal device B encrypts the plaintext data to be sent to terminal device A using the symmetric encryption key Key to obtain the ciphertext data and sends it to terminal device A.

[0119] S309: Terminal device A receives the ciphertext data sent by terminal device B and decrypts the ciphertext data using the symmetric encryption key Key to obtain the plaintext data.

[0120] Repeating the above steps S306 to S309, bidirectional encrypted data communication is achieved between terminal device A and terminal device B;

[0121] Among them, removing a trusted terminal device A from the trusted power Internet of Things, that is, trusting the network out, includes the following steps:

[0122] S401: Physically remove a trusted terminal device A from the trusted power Internet of Things;

[0123] S402: Delete the device number and device random number record corresponding to the trusted terminal device A from the device list in the offline server storage;

[0124] Among them, see Figure 6 , a fully peer-to-peer trusted power Internet of Things established by the above method includes multiple Internet of Things terminal devices 1 and an offline server 2;

[0125] Among them, multiple Internet of Things terminal devices 1 are connected through a local area network or the Internet. The Internet of Things terminal device 1 can be any general Internet of Things terminal device, but must include an encryption chip, in which the encryption chip can support symmetric encryption, asymmetric encryption, hash function and random number generation function.

[0126] Each IoT terminal device 1 includes a memory, which stores a key tag 11, a device tag 12, a public key list 13, a challenger list 14, and a challenged list 15. The key tag, device tag, and public key list must be stored in a permanent data storage memory of the terminal device and are not affected by power outages. The challenger list and challenged list can be stored in a temporary memory or a permanent data storage memory.

[0127] In this embodiment, all the above lists are implemented using a sequential list structure;

[0128] Among them, the key tag 11 of the IoT terminal device is used to store the device's own private key and public key, which is used for identity authentication of trusted communication between devices;

[0129] The device tag 12 of the IoT terminal device is used to store the device number and device random number assigned to the device by the offline server;

[0130] The device number of an IoT terminal device is the unique identifier of the device;

[0131] The function of the device random number of the IoT terminal device is as follows: when a new terminal device requests to access the trusted power IoT, the new terminal device must prove that it has the trust knowledge of multiple other existing trusted terminal devices (i.e., the device random numbers of multiple other trusted terminal devices) before it can be accepted as trusted by other trusted terminal devices.

[0132] The public key list 13 of the IoT terminal device is a list storing the public key records of all trusted terminal devices in the trusted power IoT. Each record in the list includes a device number and a corresponding device public key. The purpose of this public key list is that when a terminal device needs to verify the digital signature of another terminal device, it can directly use the public key of the other terminal device stored in itself to verify the digital signature without having to obtain the verification public key from the online authentication server.

[0133] The challenger list 14 of the IoT terminal device stores the device records of three trusted challengers randomly selected by the offline server, which are called challenger records. The challenger records in the list include the device number and the corresponding device random number.

[0134] If a terminal device requesting access to the trusted power Internet of Things can obtain the trust knowledge of multiple randomly selected existing trusted terminal devices in the trusted power Internet of Things (i.e., the device random numbers of multiple other trusted terminal devices) from the offline server, then the terminal device is definitely trusted. This is because counterfeit devices or other untrusted devices cannot obtain this trust knowledge from the offline server. Otherwise, the attacker can only be proven to be trustworthy if he can guess the device random numbers of multiple randomly selected challengers correctly, which is extremely unlikely or even impossible.

[0135] The challenged list 15 of the IoT terminal device stores records of terminal devices that first access the trusted power IoT, which are called challenged records. The challenged records in the list include the challenged device number, device public key, and challenge counter.

[0136] Each time the challenged party successfully responds to a challenge, all existing trusted terminal devices in the trusted power Internet of Things will count the challenged party. When the count reaches the number of challengers, all existing trusted terminal devices in the trusted power Internet of Things will add the challenged party's device public key to their own public key lists and accept the challenged party as a trusted terminal device.

[0137] The offline server may be an ordinary personal computer or server, which has the function of generating a device random number through software;

[0138] The offline server memory stores a device list 21. Each device record in the list includes a device number and a device random number assigned to the device by the offline server. The device list is required to be permanently stored and not affected by power outages.

[0139] The offline server is stored independently and is not connected to the trusted power Internet of Things in any form. To ensure the security of the trusted power Internet of Things, the offline server is not allowed to connect to other networks in any form to prevent the leakage of device list data.

[0140] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.

[0141] It should be understood that the present invention is not limited to the above description and that various modifications and changes can be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A method for establishing a fully peer-to-peer trusted electric power Internet of Things, characterized by: The following steps are involved: S1: Initialization of the Trusted Power Internet of Things: Establishing a minimum-scale peer-to-peer trusted power Internet of Things, which includes multiple trusted terminal devices; S2: Trusted Network Access: Connecting a new terminal device to an established peer-to-peer trusted power IoT. A terminal device requesting access can only successfully join the Power IoT and become a new trusted terminal device in the Power IoT after successfully passing the trust challenge of multiple existing trusted terminal devices in the Power IoT. S3: Trusted Communication: Trusted data communication between any two terminal devices in the Trusted Power Internet of Things; S4: Trusted network exit: Remove the terminal device connected to the trusted power Internet of Things from the trusted power Internet of Things without affecting the trusted communication of other terminal devices in the trusted power Internet of Things. Among them, trusted network access includes the following steps: S201: The terminal device requesting access generates a key pair according to a unified public key system algorithm and stores it in a key tag in its own memory; S202: The offline server assigns a device number and a device random number to the terminal device requesting access and stores them in a device list in the offline server's own memory. At the same time, the terminal device requesting access saves its assigned device number and device random number in a device tag in its own memory. S203: The offline server randomly selects multiple trusted terminal devices from its own device list as trust challengers of the terminal device requesting access, and saves the device numbers and device random numbers of the selected multiple trust challengers into the challenger list of the terminal device memory requesting access; S204: The terminal device requesting access sends a broadcast message to other trusted terminal devices in the power Internet of Things to request a trust challenge, wherein the broadcast message sent by the terminal device requesting access includes the device numbers of three trust challengers in the challenge list stored in its own memory; S205: The trusted terminal device in the power Internet of Things receives the broadcast message requesting a trust challenge sent by the terminal device requesting access, and checks whether the challenger device number in the message contains its own device number. If so, the trusted terminal device sends a trust challenge message to the terminal device requesting access; otherwise, the trusted terminal device ignores the broadcast message requesting a trust challenge. S206: After receiving the trust challenge messages from all trust challengers, the terminal device requesting access sends challenge response messages to each trust challenger. The trust challenger checks the received challenge response messages and the response results. If the response results are correct, the trust challenger searches for the device number of the terminal device requesting access in the challenged list in the trust challenger's memory and increases the challenge counter value of the found record by 1. If the response results are incorrect, no action is taken. S207: After the trusted challenger checks that the response result is correct, it broadcasts a challenge success message to the power Internet of Things. The challenge success message includes the device number and device public key of the challenged party. After receiving the challenge success message, other trusted terminal devices in the power Internet of Things search for the record of the challenged party's device number in the challenged party list in their own memory and increase the challenge counter value of the found record by 1. S208: After all trust challengers have sent challenge success messages, the counter value of the challenged record corresponding to the terminal device requesting access in the challenged list in the memory of the existing trusted terminal device in the power Internet of Things is added to the number of trust challengers. At this time, the existing trusted terminal device in the power Internet of Things writes the device number and device public key of the challenged device into the public key list in its own memory, and then deletes the challenged record corresponding to the terminal device requesting access in the challenged list in its own memory; S209: After the terminal device requesting access becomes a trusted terminal device in the power Internet of Things, it randomly starts trusted communication with one of the trusted terminal devices of the trust challenger, and requests the trust challenger to send a public key list to itself; the selected trust challenger responds to the request of the new terminal device requesting access, and sends the complete public key list in its own memory to the terminal device requesting access.

2. The method for establishing a fully peer-to-peer trusted electric power Internet of Things according to claim 1, characterized in that: Initialization of the Trusted Power IoT includes the following steps: S101: Generate a key pair for each trusted terminal device included in the initialization of the trusted power Internet of Things according to a unified public key system algorithm, wherein the key pair includes a public key and a private key, which are randomly generated by the terminal device itself, and the generated key pair is correspondingly stored in a key tag in the memory of the trusted terminal device itself; S102: The offline server assigns a device number and a device random number to each initial trusted terminal device and stores them in a device list in the offline server's own memory. At the same time, each terminal device stores its assigned device number and device random number in a device tag in its own memory. S103: The offline server collects the public key of each initial trusted terminal device, and stores the device number and corresponding public key of each initial trusted terminal device into a public key list in the memory of all initial trusted terminal devices.

3. The method for establishing a fully peer-to-peer trusted electric power Internet of Things according to claim 1, characterized in that: In the trusted network access step, the trusted terminal device that initiates the trust challenge is randomly selected.

4. The method for establishing a fully peer-to-peer trusted electric power Internet of Things according to claim 1, characterized in that: The challenger sends a challenge message, and the challenged responds with a challenge response message, which includes the following steps: S20601: The trust challenger generates a random number nrv and sends a challenge message to the challenged. The content of the challenge message is: strcat (challenger's device number, random number nrv), where the strcat() function represents multiple strings in the concatenation parameter table. S20602: The challenged party receives the challenge message sent by the trusting challenger, generates a challenge response message, and sends it to the trusting challenger. The content of the challenge response message is: strcat(challenged party's device number, challenged party's device public key, Hval-old), where Hval-old = H(strcat(challenger's device number, random number nrv, challenger's device random number)), where the H() function represents a hash function in the encryption algorithm, and the challenger's device random number is obtained from the challenger list in the challenged party's memory. S20603: The trusted challenger receives the challenge response message returned by the challenged and checks the response result. The method for the trusted challenger to check the response result is as follows: the trusted challenger separates the challenged device number, the challenged device public key, and the hash function value Hval-old from the received response message, and the trusted challenger recalculates Hval-new = H(strcat(challenger's device number, random number nrv, challenger's device random number)) and compares it with the Hval-old value. If the two are the same, the response result is correct, otherwise the response result is incorrect.

5. The method for establishing a fully peer-to-peer trusted electric power Internet of Things according to claim 1, characterized in that: The trusted data communication means that both communicating parties have performed two-way identity authentication, and the transmitted data is encrypted data.

6. The method for establishing a fully peer-to-peer trusted electric power Internet of Things according to claim 1, characterized in that: Trusted communication between terminal device A and terminal device B includes the following steps: S301: Terminal device A generates a random number A and sends it to terminal device B. Terminal device B uses its own private key to encrypt the received random number A to obtain a signature value Sign_B. Terminal device B generates a random number B and sends the random number B and signature value Sign_B to terminal device A. S302: Terminal device A receives the message sent back by terminal device B, searches for terminal device B's public key in the public key list in terminal device A's memory based on terminal device B's device number, uses the found public key of terminal device B to decrypt the signature value Sign_B, and compares the decrypted value with the random number A sent previously. If the two are the same, terminal device B is proven to be trustworthy. Otherwise, terminal device B is untrustworthy, and terminal device A terminates communication with terminal device B. S303: Terminal device A uses its own private key to encrypt the received random number B to obtain the signature value Sign_A. Terminal device A then sends the signature value to terminal device B. Terminal device B receives the message sent back by terminal device A, searches for terminal device A's public key based on the device number of terminal device A in the public key list in terminal device B's memory, decrypts the signature value Sign_A using the found public key of terminal device A, and compares the decrypted value with the random number B sent previously. If the two are the same, terminal device A is proven to be trustworthy. Otherwise, terminal device A is untrustworthy and terminal device B terminates communication with terminal device A. S304: Terminal device B randomly generates a symmetric encryption key Key, encrypts the symmetric encryption key Key using the public key of terminal device A, and sends the encrypted key to terminal device A. S305: Terminal device A receives the encrypted symmetric encryption key sent by terminal device B and decrypts it using its own private key to obtain the symmetric encryption key Key; S306: Terminal device A encrypts the plaintext data to be sent to terminal device B using the symmetric encryption key Key to obtain the ciphertext data and sends it to terminal device B; S307: Terminal device B receives the ciphertext data sent by terminal device A and decrypts the ciphertext data using the symmetric encryption key Key to obtain the plaintext data. S308: Terminal device B encrypts the plaintext data to be sent to terminal device A using the symmetric encryption key Key to obtain the ciphertext data and sends it to terminal device A. S309: Terminal device A receives the ciphertext data sent by terminal device B, and uses the symmetric encryption key Key to decrypt the ciphertext data to obtain the plaintext data.

7. The method for establishing a fully peer-to-peer trusted electric power Internet of Things according to claim 1, characterized in that: Trusted network outbound includes the following steps: S401: Physically remove a trusted terminal device A from the trusted power Internet of Things; S402: Delete the device number and device random number record corresponding to the trusted terminal device A from the device list of the offline server storage.

8. A fully peer-to-peer trusted power Internet of Things, characterized by: The method for establishing a fully peer-to-peer trusted electric power Internet of Things is adopted as described in any one of claims 1 to 7, wherein the fully peer-to-peer trusted electric power Internet of Things comprises a plurality of Internet of Things terminal devices (1) and an offline server (2); The IoT terminal device includes a memory, wherein the memory stores a key tag (11), a device tag (12), a public key list (13), a challenger list (14), and a challenged list (15); The key tag (11) of the IoT terminal device is used to store the private key and public key of the device itself, and is used for identity authentication of trusted communication between devices; The device tag (12) of the IoT terminal device is used to store the device number and device random number assigned to the device by the offline server; The public key list (13) of the Internet of Things terminal device is a list storing public key records of multiple trusted terminal devices in the trusted power Internet of Things, each record in the list includes a device number and a corresponding device public key; The challenger list (14) of the IoT terminal device is used to store the device records of the trusted challengers randomly selected by the offline server, which are called challenger records. The challenger records in the list include the device number and the corresponding device random number; The challenged list (15) of the IoT terminal device stores a record of the terminal device that first accesses the trusted power IoT, which is called a challenged record. The challenged record in the list includes the device number, device public key and challenge counter of the challenged device; A device list (21) is stored in the memory of the offline server. Each device record stored in the device list includes a device number and a device random number assigned to the device by the offline server.

9. The fully peer-to-peer trusted electric power Internet of Things according to claim 8, characterized in that: The offline server is stored independently and is not connected to the trusted power Internet of Things in any form.

Citation Information

Patent Citations

  • Self-organizing mobile peer-to-peer mesh network authentication

    US20190068382A1