A Human-Machine Cloud Terminal Security Encryption Method and Device for Power Systems

Through the security encryption method of human-machine cloud terminal of the power system, multiple encryption and decryption processes are used to solve data security problems in the power grid scheduling system, ensuring the security and reliability of data transmission, and improving the security of the power grid.

CN115967538BActive Publication Date: 2025-07-29NARI TECH CO LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211485155.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-07-29
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

The existing power grid scheduling technical support system is difficult to adapt to the requirements of safe and stable operation of UHV large power grids, and there are safety hazards such as illegal data acquisition and illegal service call.

Method used

The power system human-computer cloud terminal security encryption method is adopted, through multiple encryption and decryption processes, the power system application private key and the public key of the unified query service module are used to encrypt and legitimacy verification to ensure the security of data transmission.

Benefits of technology

It effectively avoids illegal data acquisition and illegal service calls, ensures the security, accuracy and reliability of scheduling data, and improves the security of the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967538B_ABST
    Figure CN115967538B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for secure encryption of a human-machine cloud terminal in a power system. The method includes obtaining a secondary encrypted message incoming from the cloud terminal, decrypting it with the private key of the power system application to obtain a primary encrypted message, sending the primary encrypted message to a permission service module for decryption, verifying the legality of the data after decryption, encrypting the returned primary encrypted message again with the public key of the unified query service module, and sending the re-encrypted message to the unified query service module. After receiving the re-encrypted message, the unified query service module decrypts it with the private key to obtain the primary encrypted message, sends the primary encrypted message to the permission service module for decryption, verifies the legality of the data after decryption, and returns the data to the power system application if it is legal. The present invention ensures the process security and data security of the cloud terminal application in the power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and device for secure encryption of a human-machine cloud terminal in a power system, belonging to the field of information security of power system and automation technology. Background Art

[0002] In recent years, with the in-depth development of the construction of a strong and intelligent power grid, the form and operation characteristics of the power grid will undergo major changes, posing new and higher requirements for the power grid's ability to control large power grids, conduct large-scale resource optimization allocation, as well as the integrated operation management and informatization, automation, and interaction levels of power grid dispatching.

[0003] Currently, there are various data interaction and access scenarios in the new generation of control systems, which may cause risks such as illegal data acquisition and illegal service invocation during attack and defense drills and security protection tests. As an important means to ensure the safe, high-quality, and economic operation of the power grid, the existing power grid dispatching technical support system has difficulty meeting the requirements of the safe and stable operation of ultra-high voltage large power grids. There is an urgent need for a secure program call and encryption method to eliminate the security hazards in the communication between the human-machine cloud terminal and the human-machine interaction server, and support the safe and stable operation of the new generation of power grid dispatching technical support system. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a method and device for secure encryption of a human-machine cloud terminal in a power system, which can better solve the problems of the operation and data acquisition security of the current power system configuration software.

[0005] To achieve the above purpose, the present invention is implemented by the following technical solutions:

[0006] In the first aspect, the present invention provides a method for secure encryption of a human-machine cloud terminal in a power system, which is applied to a power system application in a cloud terminal. The method includes:

[0007] Obtain a secondary encrypted message passed in by the cloud terminal, and decrypt it with the private key of the power system application to obtain a primary encrypted message. The secondary encrypted message is obtained by the cloud terminal after acquiring the user input data and encrypting it twice;

[0008] Send the primary encrypted message to the permission service module in the server for decryption and re-encryption, and receive the primary encrypted message returned by the permission service module. The primary encrypted message returned by the permission service module is obtained by decrypting the received primary encrypted message by the permission service module, verifying the legality of the data, and re-encrypting it if it is legal;

[0009] Use the public key of the unified query service module in the server to encrypt the once-encrypted message returned by the permission service module again, and send the re-encrypted message to the unified query service module. After the unified query service module receives the re-encrypted message, it decrypts it with the private key, and the unified query service module sends the once-encrypted message obtained by decryption to the permission service module for re-decryption. After decryption, it returns to the unified query service module to verify the legality of the decrypted data. If it is legal, it returns the decrypted data to the power system application;

[0010] Receive the data returned by the unified query service module after verification of legality and make a response.

[0011] Further, the obtaining of the twice-encrypted message passed in by the cloud terminal and decrypting it with the private key of the power system application includes:

[0012] Obtain the twice-encrypted session_a_b_str message sent by the cloud terminal, deserialize it to obtain the session_a_b ciphertext, and decrypt it with the private key of the power system application to obtain the once-encrypted session_a ciphertext.

[0013] Further, the using of the public key of the unified query service module in the server to encrypt the once-encrypted message returned by the permission service module again and sending the re-encrypted message to the unified query service module includes:

[0014] Merge the session_a ciphertext returned by the permission service module with the timestamp into a new data content, encrypt it again with the public key of the unified query service module in the server, and send the obtained re-encrypted message to the unified query service module.

[0015] In a second aspect, the present invention provides a power system human-machine cloud terminal security encryption method applied to a cloud terminal. The method includes:

[0016] Obtain the data input by the user and obtain the twice-encrypted message through two-time encryption;

[0017] Send the twice-encrypted message to the power system application.

[0018] Further, the method further includes:

[0019] Obtain the data input by the user, send it to the permission service module for legality judgment, and encrypt the corresponding generated session plaintext with the public key of the cloud terminal to generate a session ciphertext, so as to verify the legality of the data through the permission service module. After verification of legality, generate the session plaintext corresponding to the current data, encrypt the session plaintext with the public key of the cloud terminal to generate a session ciphertext, and return it to the cloud terminal;

[0020] Obtain the session ciphertext sent by the permission service module, decrypt the session ciphertext using the private key of the cloud terminal to obtain the session plaintext;

[0021] Encrypt the session plaintext using the public key of the permission service module to obtain the session_a ciphertext;

[0022] Encrypt the session_a ciphertext using the public key of the power system application to obtain the session_a_b ciphertext;

[0023] Perform serialization processing on the session_a_b ciphertext to obtain the string session_a_b_str message, and pass it to the power system application in the form of startup parameters.

[0024] Thirdly, the present invention provides a power system human-machine cloud terminal security encryption method, which is applied to the unified query service module of the server. The method includes:

[0025] Receive the re-encrypted message sent by the power system application, decrypt it using the private key to obtain the once-encrypted message;

[0026] Send the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, return the data to the power system application for response.

[0027] Further, the receiving the re-encrypted message sent by the power system application, decrypting it using the private key to obtain the once-encrypted message includes:

[0028] Receive the encrypted message sent by the power system application, decrypt the encrypted message using the private key of the unified query service module to obtain the session_a ciphertext and the timestamp.

[0029] Further, the sending the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, return the data to the power system application for response includes:

[0030] Verify whether the session_a ciphertext and the timestamp are legal messages. If the message is legal, send the session_a ciphertext to the permission service module. The permission service module receives the session_a ciphertext, decrypts it using the private key of the permission service module to obtain the session original text, performs legality verification on the session original text, and returns the session original text and the session verification result to the unified query service;

[0031] Receive the session original text and session verification result returned by the permission service module, and verify their legality. If legal, return the session original text to the power system application for response.

[0032] Fourthly, the present invention provides a power system human-machine cloud terminal security encryption device for use in a power system application. The device includes:

[0033] A first decryption module, configured to obtain a secondarily encrypted message passed in by the cloud terminal, and decrypt it with the private key of the power system application to obtain a primarily encrypted message. The secondarily encrypted message is obtained by the cloud terminal acquiring user input data and encrypting the data twice.

[0034] A first verification module, configured to send the primarily encrypted message to the permission service module in the server for decryption and re-encryption, and receive the primarily encrypted message returned by the permission service module. The primarily encrypted message returned by the permission service module is obtained by the permission service module decrypting the received primarily encrypted message to verify the legality of the data, and re-encrypting it if legal.

[0035] A first encryption module, configured to use the public key of the unified query service module in the server to encrypt the primarily encrypted message returned by the permission service module again, and send the re-encrypted message to the unified query service module, so that after the unified query service module receives the re-encrypted message, it decrypts it with the private key, and the unified query service module sends the decrypted primarily encrypted message to the permission service module for re-decryption. After decryption, the unified query service module returns to verify the legality of the decrypted data. If legal, it returns the decrypted data to the power system application.

[0036] A receive response module, configured to receive the data returned by the unified query service module after verification and perform a response.

[0037] Further, the first decryption module includes:

[0038] A first decryption unit, configured to obtain the secondarily encrypted session_a_b_str message sent by the cloud terminal, perform deserialization to obtain the session_a_b ciphertext, and decrypt it with the private key of the power system application to obtain the primarily encrypted session_a ciphertext.

[0039] Further, the first encryption module includes:

[0040] A first encryption unit, configured to merge the session_a ciphertext returned by the permission service module with the timestamp into a new data content, encrypt it again with the public key of the unified query service module in the server, and send the obtained re-encrypted message to the unified query service module.

[0041] In a fifth aspect, the present invention provides a power system human-machine cloud terminal security encryption device for a cloud terminal. The device includes:

[0042] A second encryption module, configured to obtain data input by a user and obtain a second encrypted message after two encryptions;

[0043] A sending module, configured to send the second encrypted message to a power system application.

[0044] Furthermore, the device further includes:

[0045] A data message acquisition and sending module, configured to obtain data input by a user, send it to an authorization service module for legality judgment, and encrypt the corresponding generated session plaintext with the public key of the cloud terminal to generate a session ciphertext, so as to verify the legality of the data through the authorization service module. After the verification is legal, generate a session plaintext corresponding to the current data, encrypt the session plaintext with the public key of the cloud terminal, generate a session ciphertext, and return it to the cloud terminal;

[0046] A session ciphertext decryption module, configured to obtain the session ciphertext sent by the authorization service module and decrypt the session ciphertext with the private key of the cloud terminal to obtain a session plaintext;

[0047] A session plaintext encryption module, configured to encrypt the session plaintext with the public key of the authorization service module to obtain a session_a ciphertext;

[0048] A session_a ciphertext encryption module, configured to encrypt the session_a ciphertext with the public key of the power system application to obtain a session_a_b ciphertext;

[0049] A processing module, configured to perform serialization processing on the session_a_b ciphertext to obtain a string session_a_b_str message, and pass it to the power system application in the form of startup parameters.

[0050] In a sixth aspect, the present invention provides a power system human-machine cloud terminal security encryption device for a unified query service module. The device includes:

[0051] A second decryption module, configured to receive the re-encrypted message sent by the power system application and decrypt it with the private key to obtain a first encrypted message;

[0052] The second verification module is used to send the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, the data is returned to the power system application for response.

[0053] Further, the second decryption module includes:

[0054] The second decryption unit is used to receive the encrypted message sent by the power system application, decrypt the encrypted message using the private key of the unified query service module, and obtain the session_a ciphertext and timestamp.

[0055] Further, the second verification module includes:

[0056] The first verification unit is used to verify whether the session_a ciphertext and timestamp are legal messages. If the message is legal, the session_a ciphertext is sent to the permission service module. The permission service module receives the session_a ciphertext, decrypts it using the private key of the permission service module to obtain the session original text, verifies the legality of the session original text, and returns the session original text and the session verification result to the unified query service;

[0057] The second verification unit is used to receive the session original text and the session verification result returned by the permission service module and verify their legality. If it is legal, the session original text is returned to the power system application for response.

[0058] Compared with the prior art, the beneficial effects achieved by the present invention:

[0059] The present invention provides a power system human-machine cloud terminal security encryption method and device, which solves problems such as software security authentication login, program security authentication startup, and service security authentication call in the field of power dispatching control systems, effectively avoids risks such as illegal data acquisition and illegal service call. It eliminates the security hidden danger in the communication between the human-machine cloud terminal and the human-machine interaction server, ensures the security, accuracy, and reliability of dispatching data, makes the dispatching monitoring method safer, improves the power grid security, and has good application prospects. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 Schematic diagram of cloud terminal user authentication involved in the present invention;

[0061] Figure 2 Schematic diagram of interaction permission information between the cloud terminal and the application app involved in the present invention;

[0062] Figure 3 Schematic diagram of mutual access between the human-machine cloud terminal and the unified query service involved in the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0063] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the protection scope of the present invention.

[0064] Embodiment 1, as Figures 1 to 3 shown, the power system human-machine cloud terminal security encryption method provided in this embodiment specifically involves the following steps in its application process:

[0065] 1. Cloud terminal user authentication process

[0066] The cloud desktop program of the cloud terminal logs in.

[0067] The permission service judges the login information and generates the session plaintext corresponding to this login.

[0068] The permission service encrypts the session with the public key of the cloud terminal to generate the session ciphertext and returns it to the cloud desktop of the cloud terminal.

[0069] The cloud desktop program of the cloud terminal obtains the encrypted session, decrypts it with the private key of the cloud desktop program of the cloud terminal, and obtains the plaintext session.

[0070] 2. Interaction process between the cloud terminal and the power system application APP

[0071] The cloud desktop of the cloud terminal has obtained the session through the user login interface before.

[0072] The cloud terminal starts the application store client through the cloud desktop program, and obtains the application certificate and the app binary file through the application store when downloading the application app.

[0073] The cloud desktop program of the cloud terminal encrypts the session with the public key of the permission service to obtain session_a.

[0074] The cloud desktop of the cloud terminal encrypts session_a with the public key of the application app to obtain session_a_b, serializes and processes session_a_b into a string session_a_b_str, and passes it to the application app in the form of startup parameters.

[0075] The application app obtains session_a_b_str, deserializes it to obtain session_a_b, and decrypts it with its own private key to obtain session_a.

[0076] The application app uses session_a and uses the permission service interface for permission verification.

[0077] 3. Process for the human-machine cloud terminal APP to access the unified query service

[0078] The cloud terminal APP decrypts the session information in the parameter with its own private key to obtain session_a (the ciphertext encrypted by the permission public key), combines it with the request data packet, timestamp and other information into new data content, encrypts it again with the public key of the unified query service, and sends the ciphertext to the unified query service;

[0079] The unified query service decrypts the message with its own private key to obtain the ciphertext session_a and the timestamp;

[0080] The unified query service judges the timestamp to determine whether it is a legal message. If the message is legal, it continues to call the session authentication interface of the permission service to verify session_a;

[0081] The permission service receives session_a, decrypts it with its own private key to obtain the original session text, judges its legality, and returns the result to the unified query service;

[0082] The unified query service judges the return of the session authentication interface. If it is legal, it continues to parse the data packet for subsequent queries.

[0083] Embodiment 2. This embodiment provides a method for secure encryption of a human-machine cloud terminal in a power system, which is applied to the power system application in the cloud terminal. The method includes:

[0084] Obtain the secondary encrypted message passed in by the cloud terminal, and decrypt it with the private key of the power system application to obtain the primary encrypted message. The secondary encrypted message is obtained by the cloud terminal acquiring the user input data and encrypting the data twice;

[0085] Send the primary encrypted message to the permission service module in the server for decryption and re-encryption, and receive the primary encrypted message returned by the permission service module. The primary encrypted message returned by the permission service module is obtained by decrypting the received primary encrypted message by the permission service module to verify the legality of the data and re-encrypting it if it is legal;

[0086] Use the public key of the unified query service module in the server to encrypt the primary encrypted message returned by the permission service module again, and send the re-encrypted message to the unified query service module. After the unified query service module receives the re-encrypted message, it decrypts it with the private key, and the unified query service module sends the decrypted primary encrypted message to the permission service module for re-decryption. After decryption, it returns to the unified query service module to verify the legality of the decrypted data. If it is legal, it returns the decrypted data to the power system application;

[0087] Receive the data returned by the unified query service module after verification and make a response.

[0088] Specifically, obtaining the secondarily encrypted message transmitted by the cloud terminal and decrypting it with the private key of the power system application to obtain the primarily encrypted message includes:

[0089] Obtain the secondarily encrypted session_a_b_str message sent by the cloud terminal, deserialize it to obtain the session_a_b ciphertext, and decrypt it with the private key of the power system application to obtain the primarily encrypted session_a ciphertext.

[0090] Specifically, using the public key of the unified query service module in the server to encrypt the primarily encrypted message returned by the permission service module again and sending the re-encrypted message to the unified query service module includes:

[0091] Merge the session_a ciphertext returned by the permission service module with the timestamp into new data content, encrypt it again with the public key of the unified query service module in the server, and send the obtained re-encrypted message to the unified query service module.

[0092] Embodiment 3 provides a power system human-machine cloud terminal security encryption method applied to the cloud terminal. The method includes:

[0093] Obtain the data input by the user and obtain the secondarily encrypted message through two-time encryption;

[0094] Send the secondarily encrypted message to the power system application.

[0095] Specifically, the method further includes:

[0096] Obtain the data input by the user, send it to the permission service module for legality judgment, and encrypt the corresponding generated session plaintext with the public key of the cloud terminal to generate the session ciphertext, so as to verify the legality of the data through the permission service module. After the verification is legal, generate the session plaintext corresponding to the current data, encrypt the session plaintext with the public key of the cloud terminal to generate the session ciphertext, and return it to the cloud terminal;

[0097] Obtain the session ciphertext sent by the permission service module, decrypt the session ciphertext with the private key of the cloud terminal to obtain the session plaintext;

[0098] Encrypt the session plaintext with the public key of the permission service module to obtain the session_a ciphertext;

[0099] Encrypt the session_a ciphertext with the public key of the power system application to obtain the session_a_b ciphertext;

[0100] Serialize the ciphertext of session_a_b to obtain the string session_a_b_str message, and pass it to the power system application through the startup parameter method.

[0101] Example 4. This example provides a secure encryption method for the human-machine cloud terminal of the power system, which is applied to the unified query service module of the server. The method includes:

[0102] Receive the re-encrypted message sent by the power system application, and decrypt it using the private key to obtain the once-encrypted message.

[0103] Send the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, return the data to the power system application for response.

[0104] Specifically, the step of receiving the re-encrypted message sent by the power system application, decrypting it using the private key to obtain the once-encrypted message includes:

[0105] Receive the encrypted message sent by the power system application, and decrypt the encrypted message using the private key of the unified query service module to obtain the session_a ciphertext and the timestamp.

[0106] Specifically, the step of sending the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data, and if it is legal, returning the data to the power system application for response includes:

[0107] Verify whether the session_a ciphertext and the timestamp are legal messages. If the message is legal, send the session_a ciphertext to the permission service module. The permission service module receives the session_a ciphertext, decrypts it using the private key of the permission service module to obtain the session original text, verifies the legality of the session original text, and returns the session original text and the session verification result to the unified query service.

[0108] Receive the session original text and the session verification result returned by the permission service module and verify their legality. If it is legal, return the session original text to the power system application for response.

[0109] Example 5. This example provides a secure encryption device for the human-machine cloud terminal of the power system, which is used in the power system application. The device includes:

[0110] The first decryption module is used to obtain the twice-encrypted message passed in by the cloud terminal and decrypt it using the private key of the power system application to obtain the once-encrypted message. The twice-encrypted message is obtained by the cloud terminal acquiring the user input data and encrypting the data twice.

[0111] The first verification module is used to send the primary encrypted message to the permission service module in the server for decryption and re-encryption, and receive the primary encrypted message returned by the permission service module; among them, the primary encrypted message returned by the permission service module is obtained by decrypting the received primary encrypted message by the permission service module to verify the legality of the data and then re-encrypting it.

[0112] The first encryption module is used to re-encrypt the primary encrypted message returned by the permission service module using the public key of the unified query service module in the server, and send the re-encrypted message to the unified query service module, so that after receiving the re-encrypted message, the unified query service module decrypts it using the private key, and the unified query service module sends the decrypted primary encrypted message to the permission service module for re-decryption. After decryption, it returns to the unified query service module to verify the legality of the decrypted data. If it is legal, it returns the decrypted data to the power system application.

[0113] The receiving and response module is used to receive the data returned by the unified query service module after verification and make a response.

[0114] Specifically, the first decryption module includes:

[0115] The first decryption unit is used to obtain the secondarily encrypted session_a_b_str message sent by the cloud terminal, deserialize it to obtain the session_a_b ciphertext, and decrypt it using the private key of the power system application to obtain the primary encrypted session_a ciphertext.

[0116] Specifically, the first encryption module includes:

[0117] The first encryption unit is used to merge the session_a ciphertext returned by the permission service module with the timestamp into a new data content, re-encrypt it using the public key of the unified query service module in the server, and send the obtained re-encrypted message to the unified query service module.

[0118] Embodiment 6. This embodiment provides a power system human-machine cloud terminal security encryption device for a cloud terminal. The device includes:

[0119] The second encryption module is used to obtain the data input by the user and obtain the secondarily encrypted message through two encryptions.

[0120] The sending module is used to send the secondarily encrypted message to the power system application.

[0121] Specifically, the device further includes:

[0122] The data packet acquisition and sending module is used to acquire the data input by the user, send it to the permission service module for legality judgment, and encrypt the generated session plaintext with the public key of the cloud terminal to generate a session ciphertext, so as to verify the legality of the data through the permission service module. After the verification is legal, generate the session plaintext corresponding to the current data, encrypt the session plaintext with the public key of the cloud terminal, generate a session ciphertext, and return it to the cloud terminal;

[0123] The session ciphertext decryption module is used to acquire the session ciphertext sent by the permission service module and decrypt the session ciphertext with the private key of the cloud terminal to obtain the session plaintext;

[0124] The session plaintext encryption module is used to encrypt the session plaintext with the public key of the permission service module to obtain a session_a ciphertext;

[0125] The session_a ciphertext encryption module is used to encrypt the session_a ciphertext with the public key of the power system application to obtain a session_a_b ciphertext;

[0126] The processing module is used to perform serialization processing on the session_a_b ciphertext to obtain a string session_a_b_str packet and pass it to the power system application in the form of startup parameters.

[0127] Embodiment 7. This embodiment provides a power system human-machine cloud terminal security encryption device for the unified query service module. The device includes:

[0128] The second decryption module is used to receive the re-encrypted packet sent by the power system application and decrypt it with the private key to obtain a once-encrypted packet;

[0129] The second verification module is used to send the once-encrypted packet obtained by decryption to the permission service module to verify the legality of the data. If it is legal, return the data to the power system application for response.

[0130] Specifically, the second decryption module includes:

[0131] The second decryption unit is used to receive the encrypted packet sent by the power system application and decrypt the encrypted packet with the private key of the unified query service module to obtain a session_a ciphertext and a timestamp.

[0132] Specifically, the second verification module includes:

[0133] The first verification unit is used to verify whether the session_a ciphertext and the timestamp are legal messages. If the message is legal, it sends the session_a ciphertext to the permission service module. The permission service module decrypts the received session_a ciphertext with its private key to obtain the session original text, verifies the legality of the session original text, and returns the session original text and the session verification result to the unified query service.

[0134] The second verification unit is used to receive the session original text and the session verification result returned by the permission service module and verify their legality. If they are legal, it returns the session original text to the power system application for response.

[0135] Example 8. This example provides an electronic device, including a processor and a storage medium.

[0136] The storage medium is used to store instructions.

[0137] The processor is used to operate according to the instructions to execute the steps of the method according to any one of Embodiment 2.

[0138] Example 9. This example provides an electronic device, including a processor and a storage medium.

[0139] The storage medium is used to store instructions.

[0140] The processor is used to operate according to the instructions to execute the steps of the method according to any one of Embodiment 3.

[0141] Example 10. This example provides an electronic device, including a processor and a storage medium.

[0142] The storage medium is used to store instructions.

[0143] The processor is used to operate according to the instructions to execute the steps of the method according to any one of Embodiment 4.

[0144] Example 11. This example provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the method according to any one of Embodiment 2.

[0145] Example 12. This example provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the method according to any one of Embodiment 3.

[0146] Example 13 provides a computer-readable storage medium storing a computer program which, when executed by a processor, implements the steps of the method according to any one of Examples 4.

[0147] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

[0148] Those skilled in the art should understand that the embodiments of the present disclosure may be provided as a method, a system or a computer program product. Therefore, the present disclosure may take the form of an all-hardware embodiment, an all-software embodiment or an embodiment combining software and hardware aspects. Moreover, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0149] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0150] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0152] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present disclosure rather than limit the scope of its protection. Although the present disclosure has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that after reading the present disclosure, various changes, modifications or equivalent substitutions can still be made to the specific implementation manners of the invention. However, these changes, modifications or equivalent substitutions are all within the scope of protection of the claims pending for publication.

Claims

1. A method for secure encryption of a human-machine cloud terminal in a power system, characterized in that, Applied to the power system application in the cloud terminal, the method includes: Obtain the secondarily encrypted message passed in by the cloud terminal, and decrypt it with the private key of the power system application to obtain the first encrypted message. Herein, the secondarily encrypted message is obtained by the cloud terminal after acquiring the user input data and encrypting the data twice. Send the first encrypted message to the permission service module in the server for decryption and re-encryption, and receive the first encrypted message returned by the permission service module. Among them, the first encrypted message returned by the permission service module is obtained by decrypting the received first encrypted message by the permission service module to verify the legality of the data, and then re-encrypting it if it is legal. Use the public key of the unified query service module in the server to re-encrypt the first encrypted message returned by the permission service module, and send the re-encrypted message to the unified query service module. So that after the unified query service module receives the re-encrypted message, it decrypts it with the private key, and the unified query service module sends the decrypted first encrypted message to the permission service module for re-decryption. After decryption, it returns to the unified query service module to verify the legality of the decrypted data. If it is legal, it returns the decrypted data to the power system application. Receive the data returned by the unified query service module after verification of legality and make a response.

2. The human-machine cloud terminal security encryption method for a power system according to claim 1, wherein, The step of obtaining the secondarily encrypted message passed in by the cloud terminal and decrypting it with the private key of the power system application to obtain the first encrypted message includes: Obtain the secondarily encrypted session_a_b_str message sent by the cloud terminal, deserialize it to obtain the session_a_b ciphertext, and decrypt it with the private key of the power system application to obtain the first encrypted session_a ciphertext.

3. The method for securely encrypting a human-machine cloud terminal of a power system according to claim 2, characterized in that, The step of using the public key of the unified query service module in the server to re-encrypt the first encrypted message returned by the permission service module and sending the re-encrypted message to the unified query service module includes: Merge the session_a ciphertext returned by the permission service module with the timestamp into a new data content, re-encrypt it with the public key of the unified query service module in the server, and send the obtained re-encrypted message to the unified query service module.

4. A method for secure encryption of a human-machine cloud terminal in a power system, characterized in that, Applied to the cloud terminal, the method includes: Obtain the user input data and obtain the secondarily encrypted message after encrypting it twice. Send the secondarily encrypted message to the power system application. The method further includes: Obtain the user input data, send it to the permission service module for legality judgment, and encrypt the corresponding generated session plaintext with the public key of the cloud terminal to generate the session ciphertext, so as to verify the legality of the data through the permission service module. After verification of legality, generate the session plaintext corresponding to the current data, encrypt the session plaintext with the public key of the cloud terminal to generate the session ciphertext, and return it to the cloud terminal. Obtain the session ciphertext sent by the permission service module, decrypt the session ciphertext with the private key of the cloud terminal to obtain the session plaintext. Encrypt the plaintext session with the public key of the permission service module to obtain the ciphertext session_a; Encrypt the ciphertext session_a with the public key of the power system application to obtain the ciphertext session_a_b; Perform serialization processing on the ciphertext session_a_b to obtain the string session_a_b_str message, and pass it to the power system application in the form of startup parameters.

5. A method for secure encryption of a human-machine cloud terminal in a power system, characterized in that, Applied to the unified query service module of the server, the method includes: Receive the re-encrypted message sent by the power system application, and decrypt it with the private key to obtain the once-encrypted message; Send the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, return the data to the power system application for response; The receiving the re-encrypted message sent by the power system application and decrypting it with the private key to obtain the once-encrypted message includes: Receive the encrypted message sent by the power system application, and decrypt the encrypted message with the private key of the unified query service module to obtain the ciphertext session_a and the timestamp; The sending the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, return the data to the power system application for response includes: Verify whether the ciphertext session_a and the timestamp are legal messages. If the message is legal, send the ciphertext session_a to the permission service module. The permission service module receives the ciphertext session_a, decrypts it with the private key of the permission service module to obtain the session plaintext, performs legality verification on the session plaintext, and returns the session plaintext and the session verification result to the unified query service module; Receive the session plaintext and the session verification result returned by the permission service module and verify their legality. If it is legal, return the session plaintext to the power system application for response.

6. A human-machine cloud terminal security encryption device for a power system, characterized in that, Used in the power system application, the device includes: The first decryption module is used to obtain the twice-encrypted message passed in by the cloud terminal, and decrypt it with the private key of the power system application to obtain the once-encrypted message. The twice-encrypted message is obtained by the cloud terminal obtaining the user input data and encrypting the data twice; The first verification module is used to send the once-encrypted message to the permission service module in the server for decryption and re-encryption, and receive the once-encrypted message returned by the permission service module. The once-encrypted message returned by the permission service module is obtained by the permission service module decrypting the once-encrypted message it receives, verifying the legality of the data, and re-encrypting it if it is legal; The first encryption module is used to encrypt the once-encrypted message returned by the permission service module again using the public key of the unified query service module in the server, and send the re-encrypted message to the unified query service module. After the unified query service module receives the re-encrypted message, it decrypts it using the private key, and the unified query service module sends the decrypted once-encrypted message to the permission service module for re-decryption. After decryption, it returns to the unified query service module to verify the legality of the decrypted data. If it is legal, it returns the decrypted data to the power system application; The receiving and response module is used to receive the data returned by the unified query service module after verification and make a response.

7. The human-machine cloud terminal security encryption device for a power system according to claim 6, characterized in that, The first decryption module includes: The first decryption unit is used to obtain the twice-encrypted session_a_b_str message sent by the cloud terminal, deserialize it to obtain the session_a_b ciphertext, and decrypt it using the private key of the power system application to obtain the once-encrypted session_a ciphertext.

8. The human-machine cloud terminal security encryption device for a power system according to claim 6, characterized in that, The first encryption module includes: The first encryption unit is used to merge the session_a ciphertext returned by the permission service module with the timestamp into a new data content, encrypt it again using the public key of the unified query service module in the server, and send the obtained re-encrypted message to the unified query service module.

9. A human-machine cloud terminal security encryption device for a power system, characterized in that, For the cloud terminal, the device includes: The second encryption module is used to obtain the data input by the user and obtain the twice-encrypted message through two encryptions; The sending module is used to send the twice-encrypted message to the power system application; The device further includes: The data message acquisition and sending module is used to obtain the data input by the user, send it to the permission service module for legality judgment, and encrypt the corresponding generated session plaintext using the public key of the cloud terminal to generate the session ciphertext, so as to verify the legality of the data through the permission service module. After verification, generate the session plaintext corresponding to the current data, encrypt the session plaintext using the public key of the cloud terminal to generate the session ciphertext, and return it to the cloud terminal; The session ciphertext decryption module is used to obtain the session ciphertext sent by the permission service module and decrypt the session ciphertext using the private key of the cloud terminal to obtain the session plaintext; The session plaintext encryption module is used to encrypt the session plaintext using the public key of the permission service module to obtain the session_a ciphertext; The session_a ciphertext encryption module is used to encrypt the session_a ciphertext using the public key of the power system application to obtain the session_a_b ciphertext; The processing module is used to serialize the session_a_b ciphertext to obtain the string session_a_b_str message and pass it to the power system application in the form of startup parameters.

10. A human-machine cloud terminal security encryption device for a power system, characterized in that, For the unified query service module, the device includes: The second decryption module is used to receive the re-encrypted message sent by the power system application, decrypt it using the private key to obtain the once-encrypted message; The second verification module is used to send the once-encrypted message obtained by decryption to the permission service module to verify the legality of the data. If it is legal, the data is returned to the power system application for response; The second decryption module includes: The second decryption unit is used to receive the encrypted message sent by the power system application, decrypt the encrypted message using the private key of the unified query service module, and obtain the session_a ciphertext and the timestamp; The second verification module includes: The first verification unit is used to verify whether the session_a ciphertext and the timestamp are legal messages. If the message is legal, the session_a ciphertext is sent to the permission service module. The permission service module receives the session_a ciphertext, decrypts it using the private key of the permission service module to obtain the session original text, verifies the legality of the session original text, and returns the session original text and the session verification result to the unified query service module; The second verification unit is used to receive the session original text and the session verification result returned by the permission service module and verify their legality. If it is legal, the session original text is returned to the power system application for response.

11. An electronic device, characterized in that: It includes a processor and a storage medium; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method according to any one of claims 1 to 3.

12. An electronic device, characterized in that: It includes a processor and a storage medium; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method according to claim 4.

13. An electronic device, characterized in that: It includes a processor and a storage medium; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method according to claim 5.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 3.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, it implements the steps of the method according to claim 4.

16. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, it implements the steps of the method according to claim 5.

Citation Information

Patent Citations

  • Power transaction method, device and system and trusted cloud platform

    CN110795767A