A multi-authorization center attribute-based encryption method and system for smart grid

By introducing a distributed attribute-based encryption method with multiple authorization centers in the smart grid, the problem of single authorization centers in the smart grid is solved, the attribute management efficiency and security are improved, user permission revocation is supported, and global key updates are avoided.

CN115987504BActive Publication Date: 2025-05-06国家电网有限公司客户服务中心
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211665933.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-23
Publication Date
2025-05-06
Estimated Expiration
2042-12-23

AI Technical Summary

Technical Problem

There is a problem of a single authorization center in the smart grid, which cannot meet the requirements of multi-users, multiple applications, and fine-grained attribute encryption, and there is a hidden danger of internal attacks on malicious sites.

Method used

A distributed attribute-based encryption method for multi-authorization centers is designed. By introducing multiple attribute key authorization centers into the smart grid, each authorization center only manages the user attributes of this domain, improving the efficiency of attribute management, and supporting user permission revocation to avoid global key updates.

Benefits of technology

It is effectively compatible with smart grid environment, improves attribute management efficiency, prevents conspiracy and forgery attacks, supports user permission revocation, and avoids global key updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987504B_ABST
    Figure CN115987504B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-authorization center attribute-based encryption method and system for smart grids, which aims to protect data privacy in the process of information sharing of power terminals, meet the application requirements of revocable user permissions, ensure the security and efficiency of power grid data sharing in a multi-domain environment, and is suitable for application in a smart grid cloud storage platform where multiple systems coexist. Currently, the existing smart grid data encryption methods have a single authorization center and cannot simultaneously meet the attribute encryption requirements of multiple users, multiple applications, and fine-grained. The present invention designs a multi-authorization center attribute encryption method, including system initialization, attribute key generation, message encryption, message decryption, and attribute key revocation steps. The present invention can be effectively compatible with the smart grid environment. In each authorization, only the user attributes of the domain need to be managed, which improves the efficiency of attribute management and effectively prevents collusion attacks and forgery attacks. The system supports user permission revocation and avoids global key updates.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology, and relates to a multi-authorization center attribute-based encryption method and system, and in particular to a multi-authorization center attribute-based encryption method and system for a smart grid. Background Art

[0002] Smart grid is a modern power transmission and management system that provides dynamic and efficient real-time services to power grid users. Through intelligent sensors, edge computing devices, wireless networks, and automatic control systems, it realizes the coordination and real-time interaction of various departments in the power grid, as well as automatic monitoring of power consumption at the consumer end, in order to optimize the management and operation of the power grid. Compared with traditional power grids, smart grids have many participating entities and high information integration, making the network environment more complex. Faced with massive, distributed, multi-source and heterogeneous information, smart grids inevitably have information security risks.

[0003] In response to the security and privacy issues of smart grids, researchers at home and abroad have proposed attribute-based fine-grained encryption schemes to protect the security and reliability of grid data in channels and promote grid users and numerous power stations to participate in distributed energy transactions. However, the scheme has a single authorization center and cannot meet the application requirements of distributed multi-domain management. Due to the concentration of power in the authorization center, there is a problem of internal attacks by malicious sites, such as malicious sites stealing and modifying grid data, or providing data to unauthorized third parties.

[0004] The above problems restrict the development of smart grid. Summary of the invention

[0005] The purpose of the present invention is to protect the data privacy in the process of power terminal information sharing, meet the application requirements of revocable user permissions, ensure the security and efficiency of power grid data sharing in a multi-domain environment, and provide a distributed attribute-based encryption method and system for multiple authorization centers in a smart grid application environment. It is suitable for use in a smart grid cloud storage platform with multiple systems coexisting.

[0006] The technical solution adopted by the method of the present invention is: a multi-authorization center attribute-based encryption method for smart grids, comprising the following steps:

[0007] Step 1: System initialization;

[0008] Generate system parameters And open through the smart grid; where G1 is the additive cyclic group The q-order generator on e(G1,G1) is a generator of the multiplicative cyclic group, and the bilinear pairing mapping relationship e: Secure one-way hash function H:{0,1} * →Zq , Z q is a set of integers from 0 to q, N is the number of attribute key authorization centers;

[0009] The attribute key authority AIA initializes the attribute domain and the public and private keys of AIA; for each attribute i in the attribute domain, the number of attributes is n, and AIA k Randomly select α i , Calculate the public key where i∈{1,2,…,n}; AIA k Safely store the private key SK k ={α i ,y i}, public key PK k,i Among them, AIA k is the kth AIA; N is the number of attribute key authorization centers; is a set of integers consisting of integers 1, 2, …, q-1;

[0010] Step 2: Key generation: User GID sends the service attribute list to be requested to the base station BS and cloud server CS connected to it, and BS and CS assign corresponding attribute private keys to it;

[0011] Step 3: The power grid terminal ET encrypts the message m to be transmitted; the power grid terminal ET uses the n×l attribute encryption access control matrix A and the attribute public key set {K k,i}, for information m∈{0,1} * Encryption is performed, wherein the attribute encryption access control matrix A and the attribute mapping relationship are represented as ρ;

[0012] Step 4: After receiving the encrypted message from the power terminal ET, the user GID uses the corresponding attribute key to decrypt it.

[0013] The technical solution adopted by the system of the present invention is: a multi-authorization center attribute-based encryption system for smart grids, including the following modules:

[0014] Module 1, used for system initialization;

[0015] Generate system parameters And open through the smart grid; where G1 is the additive cyclic group The q-order generator on e(G1,G1) is a generator of the multiplicative cyclic group, and the bilinear pairing mapping relationship e: Secure one-way hash function H:{0,1} * →Z q , Z qis an integer set from 0 to q, N is the number of attribute key authorization centers;

[0016] The attribute key authority AIA initializes the attribute domain and the public and private keys of AIA; for each attribute i in the attribute domain, the number of attributes is n, and AIA k Randomly select α i , Calculate the public key where i∈{1,2,…,n}; AIA k Safely store the private key SK k ={α i ,y i}, public key P k,i Among them, AIA k is the kth AIA; N is the number of attribute key authorization centers; is a set of integers consisting of integers 1, 2, …, q-1;

[0017] Module 2, for key generation; the user GID sends a list of service attributes to be requested to the base station BS and cloud server CS connected to it, and the BS and CS assign corresponding attribute private keys to it;

[0018] Module 3 is used for the power grid terminal ET to encrypt the message m to be transmitted; the power grid terminal ET uses the n×l attribute encryption access control matrix A and the attribute public key set {PK k,i}, for information m∈{0,1} * Encryption is performed, wherein the attribute encryption access control matrix A and the attribute mapping relationship are represented as ρ;

[0019] Module 4 is used for the user GID to decrypt the ciphertext message sent by the power terminal ET using the corresponding attribute key.

[0020] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0021] The existing smart grid data encryption methods have a single authorization center and cannot meet the requirements of multi-user, multi-application, and fine-grained attribute encryption at the same time. The multi-authorization center attribute encryption method designed by the present invention can be effectively compatible with the smart grid environment. Each authorization only needs to manage the user attributes of the domain, which improves the efficiency of attribute management and effectively prevents collusion attacks and forgery attacks. The system supports user authority revocation and avoids global key updates. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 is a flow chart of an embodiment of the present invention. DETAILED DESCRIPTION

[0023] In order to facilitate ordinary technicians in the field to understand and implement the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the implementation examples described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0024] Reference Figure 1 The present invention proposes a multi-authorization center attribute-based encryption method for smart grids, (1) system initialization; (2) attribute key generation; (3) message encryption; (4) message decryption; (5) attribute key revocation.

[0025] (1) System initialization: Generate system parameters, and the attribute key authority AIA initializes the attribute domain and the public and private keys of AIA;

[0026] a) System parameter generation: The smart grid system selects safe bilinear pairing parameters Among them, G1 is the additive cyclic group The q-order generator on e(G1,G1) is a generator of the multiplicative cyclic group, and the bilinear pairing mapping relationship e: Next, the system selects a secure one-way hash function Generate system parameters And open through smart grid. Among them, Z q is a set of integers from 0 to q, N is the number of attribute key authorization centers;

[0027] b) AIA initialization: In this phase, AIA initializes the attribute domain and AIA public and private keys. In the system, the base station BS and the cloud server CS act as N attribute key authorization centers AIA and manage different attribute domains. For each attribute i in the domain, AIA k Randomly select α i , calculate Where i∈{1,2,…,n}. AIA k Safely store the private key SK k ={α i ,y i}, public key PK k,i .

[0028] (2) Key generation: The algorithm generates a user key. The user GID sends a list of service attributes to be requested to the base station BS and cloud server CS connected to it. The BS and CS assign corresponding attribute private keys to it. The specific process is as follows:

[0029] a) After receiving the attribute i requested by the user, BS uses the AIA private key to calculate K GID,i =α i G1+y( i +H(GID))-1 G1, K GID,i Transmit to the user GID through a secure channel;

[0030] b) After receiving the attribute j requested by the user, CS uses the AIA private key to calculate K GID,j =α j G1+(y j +H(GID)) -1 G1, K GID,j Transmitted to the user's GID through a secure channel.

[0031] c) User GID securely stores the attribute keys obtained from BS and CS.

[0032] (3) Message encryption: The power grid terminal ET encrypts the message to be transmitted. The power grid terminal uses the n×l matrix A and the attribute public key set {PK k,i}, for information m∈{0,1} * Encryption is performed, where the matrix and attribute mapping relationship is expressed as ρ, A x represents the x-th row vector of the access control matrix A. The specific encryption process is as follows:

[0033] a) Terminal ET selects a random number and a random vector The first element of the random vector v must be a random number s, using λ x Indicates A x ·;in, is a set of non-zero integers, is a vector consisting of l non-zero integer sets, A x represents the x-th row vector of the access control matrix A;

[0034] b) Then, the terminal ET selects a random vector The first element of the random vector w must be 0, and w x Indicates A x ·;

[0035] c) The terminal is each row vector A in A x Select random numbers r respectively x , calculate C0 = Me (G1, G1) s , C 2,x =y ρx r x G1, 4,x =r x G1; where ρ(·) is the mapping relationship between matrix A and attribute number, e(·,· is the bilinear pair mapping relationship, α ρ(x)α for i = ρ(x) i ,y ρ(x) y for j = ρ(x) j ;

[0036] d) The terminal sends the encryption result To subscribers.

[0037] (4) Message decryption: After receiving the ciphertext message from the power terminal ET, the user GID uses the corresponding attribute key to decrypt it. The specific process is as follows:

[0038] a) User GID parses the ciphertext message CT and obtains

[0039] User GID checks whether the attribute private key it owns satisfies the matrix A and its mapping relationship ρ; if so, it executes the subsequent steps; if not, it returns decryption failure;

[0040] b) User GID calculation

[0041] c) Next, select x random numbers So that∑ x c x A x =(1,0,…,0), and calculate

[0042]

[0043] d) User GID calculates the plain text of the message M = C0e (G1, G1) -s .

[0044] (5) User revocation: When the user GID stops subscribing to messages, the user attributes can be revoked. The specific process is as follows:

[0045] a) The user's GID notifies the base station BS connected to it, and the BS initializes the public-private key pair (SK K ,PK K ) and publish the new public key in the system;

[0046] b) Except for the GID of the user to be revoked, the BS redistributes keys to other users connected to it to avoid key redistribution for other users not connected to this BS.

[0047] The present invention can be effectively compatible with the smart grid environment. In each authorization, only the user attributes of the domain need to be managed, which improves the efficiency of attribute management and effectively prevents collusion attacks and forgery attacks. The system supports user authority revocation and avoids global key updates.

[0048] It should be understood that the above description of the preferred embodiment is relatively detailed and cannot be regarded as limiting the scope of patent protection of the present invention. Under the enlightenment of the present invention, ordinary technicians in this field can also make substitutions or modifications without departing from the scope of protection of the claims of the present invention, which all fall within the scope of protection of the present invention. The scope of protection requested for the present invention shall be based on the attached claims.

Claims

1. A multi-authorization center attribute-based encryption method for smart grid, characterized in that: The following steps are involved: Step 1: System initialization; Generate system parameters And open through the smart grid; where G1 is the additive cyclic group The q-order generator on e(G1,G1) is a multiplicative cyclic group. Generators of bilinear pairings Secure one-way hash function H:{0,1} * →Z q , Z q is a set of integers from 0 to q, N is the number of attribute key authorization centers; The attribute key authority AIA initializes the attribute domain and the public and private keys of AIA; for each attribute i in the attribute domain, the number of attributes is n, and AIA k Random Selection Calculate the public key where i∈{1,2,…,n}; AIA k Safely store the private key SK k ={α i ,y i }, public key PK k,i Among them, AIA k is the kth AIA; N is the number of attribute key authorization centers; is a set of integers consisting of integers 1, 2, …, q-1; Step 2: Key generation: User GID sends the service attribute list to be requested to the base station BS and cloud server CS connected to it, and BS and CS assign corresponding attribute private keys to it; The specific implementation of step 2 includes the following sub-steps: Step 2.1: After receiving the attribute i requested by the user, BS uses the AIA private key to calculate the private key K of the user GID attribute i GID,i =α i G1+(y i +H(GID)) -1 G1, K GID,i Transmit to the user GID through a secure channel; Step 2.2: After receiving the attribute j requested by the user, CS uses the AIA private key to calculate the private key K of the user's GID attribute j GID,j =α j G1+(y j +H(GID)) -1 G1, K GID,j Transmit to the user GID through a secure channel; Step 2.3: User GID securely stores the attribute key obtained from BS and CS; Step 3: The power grid terminal ET encrypts the message m to be transmitted; the power grid terminal ET uses the n×l attribute encryption access control matrix A and the attribute public key set {PK k,i }, for information m∈{0,1} * Encryption is performed, wherein the attribute encryption access control matrix A and the attribute mapping relationship are represented as ρ; Step 4: After receiving the encrypted message from the power terminal ET, the user GID uses the corresponding attribute key to decrypt it.

2. The multi-authorization center attribute-based encryption method for smart grid according to claim 1 is characterized in that: In step 1, the base station BS and the cloud server CS in the system act as N attribute key authorization centers AIA and manage different attribute domains.

3. The multi-authorization center attribute-based encryption method for smart grid according to claim 1 is characterized in that: The specific implementation of step 3 includes the following sub-steps: Step 3.1: Terminal ET selects a random number and a random vector The first element of the random vector v must be a random number s, using λ x Indicates A x v; where is a set of non-zero integers, is a vector consisting of l non-zero integer sets, A x represents the x-th row vector of the access control matrix A; Step 3.2: Terminal ET selects a random vector The first element of the random vector w must be 0, and w x Indicates A x ·w; Step 3.3: Terminal ET is each row vector A in A. x Select random numbers r respectively x , calculate C0 = M·e(G1,G1) s , C 2,x =y ρ(x) r x G1,C 3,x =α ρ(x) r x G1+w x G1,C 4,x =r x G1; where ρ(·) is the mapping relationship between matrix A and attribute number, e(·,·) is the bilinear pair mapping relationship, α ρ(x) α for i = ρ(x) i ,y ρ(x) y for j = ρ(x) j ; Step 3.4: Terminal ET sends the encryption result To subscribers.

4. The multi-authorization center attribute-based encryption method for smart grid according to claim 3 is characterized in that: The specific implementation of step 4 includes the following sub-steps: Step 4.1: User GID parses the ciphertext message CT and obtains Step 4.2: User GID checks whether the attribute private key it owns satisfies the matrix A and its mapping relationship ρ; if so, it executes the subsequent steps; if not, it returns decryption failure; Step 4.3: User GID calculation Step 4.4: Pick x random numbers So that∑ x c x A x =(1,0,…,0), and calculate Step 4.5: User GID calculates the message plaintext M=C0e(G1,G1) -s .

5. The multi-authorization center attribute-based encryption method for smart grid according to any one of claims 1 to 4, characterized in that: When the user GID stops subscribing to messages, the user attributes can be revoked. The specific process is as follows: (1) The user's GID notifies the base station BS connected to it, and the BS initializes the public-private key pair (SK K ,PK K ) and publish the new public key in the system; (2) Except for the GID of the user to be revoked, the BS redistributes keys to other users connected to it to avoid key redistribution for other users not connected to this BS.

6. A multi-authorization center attribute-based encryption system for smart grid, characterized in that: Includes the following modules: Module 1, used for system initialization; Generate system parameters And open through the smart grid; where G1 is the additive cyclic group The q-order generator on e(G1,G1) is a multiplicative cyclic group. Generators of bilinear pairings Secure one-way hash function H:{0,1} * →Z q , Z q is a set of integers from 0 to q, N is the number of attribute key authorization centers; The attribute key authority AIA initializes the attribute domain and the public and private keys of AIA; for each attribute i in the attribute domain, the number of attributes is n, and AIA k Random Selection Calculate the public key where i∈{1,2,…,n}; AIA k Safely store the private key SK k ={α i ,y i }, public key PK k,i Among them, AIA k is the kth AIA; N is the number of attribute key authorization centers; is a set of integers consisting of integers 1, 2, …, q-1; Module 2, for key generation; the user GID sends a list of service attributes to be requested to the base station BS and cloud server CS connected to it, and the BS and CS assign corresponding attribute private keys to it; Module 2 includes the following submodules: Module 2.1, after receiving the attribute i requested by the user, BS uses the AIA private key to calculate the private key K of the user GID attribute i GID,i =α i G1+(y i +H(GID)) -1 G1, K GID,i Transmit to the user GID through a secure channel; Module 2.2, after CS receives attribute j requested by the user, it uses the AIA private key to calculate the private key K of user GID attribute j GID,j =α j H1+(y j +H(GID)) -1 G1, K GID,j Transmit to the user GID through a secure channel; Module 2.3, used for user GID to securely store attribute keys obtained from BS and CS; Module 3 is used for the power grid terminal ET to encrypt the message m to be transmitted; the power grid terminal ET uses the n×l attribute encryption access control matrix A and the attribute public key set {PK k,i }, for information m∈{0,1} * Encryption is performed, wherein the attribute encryption access control matrix A and the attribute mapping relationship are represented as ρ; Module 4 is used for the user GID to decrypt the ciphertext message sent by the power terminal ET using the corresponding attribute key.

Citation Information

Patent Citations

  • Multi-authorization attribute-based encryption method, system, device and computer medium

    CN108989037A

  • Multi-authority attribute-based encryption method based on blockchain

    CN113193953A