A data security aggregation method for smart meters
By using key homomorphic pseudo-random functions to generate keys in the smart grid and updating the keys in each round of time slots, the problem of data in the prior art being not replaced is solved, and the secure aggregation and privacy protection of data in the smart grid is realized.
Patent Information
- Application Number
- CN202211614811.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-12-14
AI Technical Summary
In a smart grid, existing data encryption methods do not replace the key in multiple consecutive time slots. Attackers can obtain the difference in power consumption between the first and second times by subtracting the ciphertext, which is not safe enough.
The key homomorphic pseudo-random function is used to generate a key, encrypt the data of the smart meter, and use common parameters to generate timestamp information in each round of time slots to generate the respective keys. The aggregator uses and key information to decrypt the aggregate value.
It realizes safe aggregation of meter data in smart grid scenarios, reduces storage overhead, and improves the security of data privacy.
Smart Images

Figure CN116015595B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure data transmission, and in particular to a method for secure data aggregation of a smart meter. Background Art
[0002] The smart grid is built on a high-speed, integrated two-way communication network. It uses advanced sensing and measurement technology, advanced equipment technology, advanced control methods, advanced decision support system technology, etc. to carry out highly integrated transformation on the original transmission and distribution networks to achieve safe, reliable, efficient and economical operation of the power grid.
[0003] The aggregation of multi-level energy consumption data is an important function of smart grids, which is of great significance for monitoring and predicting electricity consumption, network planning and settlement, allocation and balance of loads and resources, and managing national power generation and on-demand pricing.
[0004] With the development of smart grid systems, the ways and processes of using human resources to collect and aggregate energy consumption data are becoming less and less common. Instead, data collection and aggregation tend to rely more and more on direct communication and data transmission between edge sensor devices and central data aggregator nodes. In such a process, the data privacy issues of sensor nodes, i.e. smart meters, have attracted more and more attention. How to achieve data security aggregation with privacy protection in the context of the Internet of Things is a hot research issue.
[0005] In practical applications, in order to achieve security during data transmission, data encryption is the most basic operation. Data encryption provides a certain degree of protection for the interaction between aggregators and smart meters. To achieve the correct aggregation of encrypted data, homomorphic encryption is a common and effective method among existing information encryption methods.
[0006] The article "I have a DREAM! (DiffeRentially privateE smArt Metering)" proposes a smart grid data aggregation scheme, which requires each node participating in the aggregation to store the pairing keys related to the other participating nodes separately, which will bring a large storage overhead.
[0007] In order to solve the above problems, the article "PPFA: Privacy Preserving Fog-enabled Aggregation in Smart Grid" proposes a homomorphic encryption data aggregation scheme. In this method, each smart meter holds a private key, which can encrypt its own plaintext data, and the aggregator has the sum key of the meters participating in the aggregation. Known encryption methods, the aggregator can decrypt the plaintext information of the data aggregation based on the sum key and ciphertext information. Although this method uses homomorphic encryption to encrypt the data, it reduces storage overhead. However, in the application scenario of smart meters, the data is in the form of a data stream and needs to be encrypted multiple times over time. This method has not changed the key in multiple consecutive time slots. The attacker can get the difference between the electricity consumption before and after by subtracting the ciphertext. From the perspective of data privacy security, this is not safe enough. Summary of the invention
[0008] In view of the problems existing in the prior art, this solution proposes a data security aggregation method for smart meters.
[0009] The present invention provides a data security aggregation method for a smart meter, which specifically includes the following steps:
[0010] S1: Build an aggregation system, which includes: N smart meter nodes, aggregators and trusted third-party organizations;
[0011] S2: The trusted third party sends the original key k′ to the smart meter node and aggregator through a trusted channel 1 ,k′ 2 ,…,k′ N-1 ,k′ N and the corresponding sum key K′, satisfying
[0012] S3: The smart meter node and the aggregator obtain the same pseudo-random function public parameters in a negotiated manner or through a trusted third-party organization, and share and generate a timestamp information synchronization clock based on the public parameters;
[0013] S4: In each round of time slots, distributed noise is added to the smart meter node data;
[0014] S5: In each round of time slots, the smart meter nodes use the timestamp information as the input of the pseudo-random function according to the public parameters to generate their own keys;
[0015] S6: Encrypt the data of each smart meter node according to the key of each smart meter node to obtain encrypted ciphertext;
[0016] S7: The smart meter node uploads the encrypted ciphertext to the aggregator;
[0017] S8: The aggregator adds all the received encrypted ciphertexts according to the sum key information obtained in step S2 to obtain the noisy aggregated ciphertext, and decrypts the noisy aggregated ciphertext to obtain the aggregate value.
[0018] Compared with the prior art, the beneficial effects of the present invention include: using a key homomorphic pseudo-random function to generate a key, encrypting and protecting the data of the smart meter, having the effect of homomorphic encryption, and realizing secure aggregation of meter data in a smart grid scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic flow chart of the method of the present invention;
[0020] Figure 2 It is a schematic diagram of the polymerization system structure in the present invention. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0022] Before describing the scheme of the present invention, the general process of the present invention is briefly described as follows:
[0023] A trusted third party distributes the original key k′ to N participating node meters and their corresponding aggregators 1 ,k′ 2 ,…,k′ N-1 ,k′ N and K′, where K′=k′ 1 +k′ 2 ,…,k′ N-1 +k′ N , N is the number of meter nodes participating in the aggregation.
[0024] In each subsequent time slot t, a subkey is generated for each participating smart meter using a key homomorphic pseudo-random function based on a random seed that changes over time, respectively, And the corresponding key information K t Share with aggregators, where
[0025] Afterwards, in each round of aggregation, each meter uses a subkey to encrypt and upload it, and the aggregator uses the sum of the key information and the uploaded ciphertext to decrypt the aggregated plaintext information.
[0026] In the above process, the key generated by the pseudo-random function generator has an error e∈{0,1}. This error has a certain impact on solving the aggregation value of the participating nodes. Therefore, the present invention also eliminates the impact of the error in a certain way.
[0027] For details, please refer to Figure 1 , Figure 1 It is a schematic flow chart of the method of the present invention;
[0028] The present invention provides a data security aggregation method for a smart meter, which specifically includes the following steps:
[0029] S1: Build an aggregation system, please refer to Figure 2 , Figure 2 It is a schematic diagram of the structure of the aggregation system of the present invention; the aggregation system includes: N smart meter nodes, an aggregator and a trusted third party organization;
[0030] S2: The trusted third party sends the original key k′ to the smart meter node and aggregator through a trusted channel 1 ,k′ 2 ,…,k′ N-1 ,k′ N and the corresponding sum key K′, satisfying
[0031] It should be noted that step S2 is specifically as follows:
[0032] S21. A trusted third party randomly generates N vectors of dimension n, denoted as k′ 1 ,k′ 2 ,…,k′ N-1 ,k′ N and send it to N smart meter nodes respectively through a secure channel;
[0033] S22. The trusted third party calculates and keys K′=k′ 1 +k′ 2 ,…,k′ N-1 +k′ N and sends it to the aggregator via a secure channel.
[0034] S3: The smart meter node and the aggregator obtain the same pseudo-random function public parameters in a negotiated manner or through a trusted third-party organization, and share and generate a timestamp information synchronization clock based on the public parameters;
[0035] It should be noted that step S3 is specifically as follows:
[0036] S31, the smart meter node and the aggregator select the modulus q,p of the pseudo-random function and the dimension n of the matrix, and calculate the value
[0037] S32, the smart meter node and the aggregator randomly generate matrices according to the matrix dimension n and the modulus q
[0038] S33. The smart meter nodes and aggregators set a synchronization clock in the system for generating timestamp information. The timestamp information is used to ensure that the smart meter nodes and aggregators have the same input when generating a key stream using a pseudo-random function generator.
[0039] S4: In each round of time slots, distributed noise is added to the smart meter node data;
[0040] It should be noted that step S4 is specifically as follows:
[0041] Step S4 is as follows: in each time slot t, for each meter node data participating in the aggregation Adding Noise Get noisy data Round the noisy data to the nearest integer Where M is an integer, which is the modulus used in the encryption and decryption process; N is the number of meters participating in the aggregation, and the noise Obey N(0,σ 2 )’s Gaussian distribution; Represents the noise value added to the smart meter node i at time slot t.
[0042] S5: In each round of time slots, the smart meter nodes use the timestamp information as the input of the pseudo-random function according to the public parameters to generate their own keys;
[0043] It should be noted that step S5 is specifically as follows: at time slot t, the smart meter node i uses the original key received from the trusted third party organization And according to the synchronized clock in the system, all smart nodes and aggregators share the same input g, according to the pseudo-random function Generate a key vector of dimension n×l, denoted as The aggregator’s key is denoted by K t ;in is a modulo rounding function.
[0044] Regarding the above key generation stage, the specific process is as follows:
[0045] According to the given matrix And a full binary tree T containing at least one node. The values of the leaf nodes of the full binary tree T are represented by 0 or 1. We use g to represent the sequence of values of the leaf nodes from left to right, that is, g = {0, 1} |T| . Define a function: The mathematical formalization is as follows:
[0046]
[0047] The second equation for the piecewise function, defining g l ∈{0,1} |T.l| ,g r ∈{0,1} |T·r| , g l represents the value sequence of the left subtree node, g r Represents the value sequence of the right subtree child nodes.
[0048] Function G -1 The function of (A) is to convert each integer element in the matrix A into a corresponding binary column vector of length l-bits, that is:
[0049] The key vector is generated using a key-homomorphic pseudo-random function (Key-Homomorphic PRF).
[0050] Function family:
[0051]
[0052] It is formally defined by the following parameters: the matrix A binary tree T, modulo p.
[0053] One of the member functions of the function family is used to calculate the key vector, which is defined as follows:
[0054]
[0055] illustrate: S t is the transpose of vector S, is a modulus "rounding" function. For example: Reduce the numbers in the ring q to the ring p.
[0056] Taking smart meter i as an example, at time slot t, meter i uses the original key received from the trusted third party And according to the synchronized clock in the system, all smart nodes and aggregators share the same input g, according to the pseudo-random function mentioned above Generate a key vector of dimension n×l, denoted as The aggregator’s key is denoted by K t .
[0057] Regarding the input g, it represents a sequence of values of a full binary tree leaf node. A simple way to evaluate the input g based on the timestamp information is to convert the timestamp into a binary number and assign each bit to the leaf node in turn. Take the corresponding full binary tree as an input.
[0058] S6: Encrypt the data of each smart meter node according to the key of each smart meter node to obtain encrypted ciphertext;
[0059] It should be noted that step S6 is specifically as follows:
[0060] Step S6 is as follows: for smart meter i, using the generated key stream information At time slot t, the jth key in the key stream is used in turn. For the jth plaintext message Encryption: Calculation
[0061] S7: The smart meter node uploads the encrypted ciphertext to the aggregator;
[0062] S8: The aggregator adds all the received encrypted ciphertexts according to the sum key information obtained in step S2 to obtain the noisy aggregated ciphertext, and decrypts the noisy aggregated ciphertext to obtain the aggregate value.
[0063] It should be noted that in some specific situations, for example, in scenarios where there is a high tolerance for aggregation errors, the aggregation error caused by the key summation error can be ignored.
[0064] This is feasible from a theoretical analysis of the present invention. By conducting enough experiments on data encryption and decryption, it can be roughly observed from the data distribution of the error that the data error roughly obeys the normal distribution of N(0,σ), which is the same as the mean of the Gaussian distribution added in the data cleaning stage and is superimposable. Therefore, when the error requirement is low, the impact of the key error can be ignored.
[0065] When the error effect is ignored, the decryption method is as follows:
[0066] Calculate the sum of all ciphertexts encrypted with the jth key in time slot t, that is, the calculation formula:
[0067]
[0068] Decrypt the aggregate ciphertext using the following formula:
[0069]
[0070] At this point, the aggregator successfully computes the aggregate value with Gaussian distributed noise.
[0071] The above scheme does not process the error generated by the pseudo-random function in calculating the key, that is, it ignores the influence of the error.
[0072] However, in actual situations, it is often necessary to perform certain processing on the above errors. In step S8 of the present application, there are two ways to perform error processing and decryption on the noisy aggregate ciphertext, namely: introducing a new third-party trusted agency to eliminate errors and optimizing the encryption and decryption methods to reduce errors.
[0073] The specific process of decryption in step S8 by introducing a new third-party trusted institution to eliminate errors is as follows:
[0074] S81. Introduce a new third-party trusted agency. According to the timestamp information, it shares the same input g with the smart meter nodes and aggregators. The new third-party trusted agency is responsible for generating the original keys of the smart meter nodes and aggregators during the system startup phase; and calculates the j-th encryption keys of the smart meter nodes and aggregators at time slot t, which are respectively
[0075] S82, calculate the error e according to the above key information:
[0076]
[0077] S83. The new third-party trusted institution sends the error e to the aggregator;
[0078] S84, the aggregator calculates the sum of all ciphertexts encrypted with the jth key in time slot t, that is, the calculation formula:
[0079]
[0080] The aggregator updates the key based on the error e
[0081] The aggregator decrypts the aggregated ciphertext to obtain the aggregated value using the following formula:
[0082]
[0083] The above method requires the introduction of a trusted third-party organization to reduce the impact of key errors, but this solution adds a third-party organization and increases additional communication overhead.
[0084] In this regard, this solution also provides another way to optimize encryption and decryption to reduce errors, as follows:
[0085] In the data encryption stage, the plaintext data is multiplied by an integer multiple of 10 before encryption. The specific steps are as follows:
[0086] Optimized encryption:
[0087] At time slot t, for smart meter node i, it multiplies the jth plaintext by 10 to the zth power, that is, calculates:
[0088] For smart meter node i, use the key stream information generated in the previous step in
[0089] At time slot t, the jth key in the key stream is used in turn. For the jth plaintext information Encryption: Calculation
[0090] The corresponding decryption method after optimized encryption is as follows:
[0091] Calculate the sum of all ciphertexts encrypted with the jth key in time slot t, that is, the calculation formula:
[0092]
[0093] Decrypt the aggregate ciphertext using the following formula:
[0094]
[0095] Divide the plaintext information by 10 z , restore, calculate:
[0096]
[0097] Finally, the aggregate value information is obtained
[0098] The beneficial effects of the present invention are: using a key homomorphic pseudo-random function to generate a key, encrypting and protecting the data of the smart meter, having the effect of homomorphic encryption, and realizing secure aggregation of meter data in a smart grid scenario.
[0099] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0100] The above specific implementations of the present invention do not constitute a limitation on the protection scope of the present invention. Any other corresponding changes and modifications made based on the technical concept of the present invention should be included in the protection scope of the claims of the present invention.
Claims
1. A data security aggregation method for smart meter nodes, Features: Includes the following step: S1: Build an aggregation system, which includes: N smart meter nodes, aggregators and trusted third-party organizations; S2: The trusted third party sends the original key k′ to the smart meter node and aggregator through a trusted channel 1 ,k′ 2 ,…,k′ N-1 ,k′ N and the corresponding sum key K′, satisfying S3: The smart meter node and the aggregator obtain the same pseudo-random function public parameters in a negotiated manner or through a trusted third-party organization, and share and generate a timestamp information synchronization clock based on the public parameters; S4: In each round of time slots, distributed noise is added to the smart meter node data; S5: In each round of time slots, the smart meter nodes use the timestamp information as the input of the pseudo-random function according to the public parameters to generate their own keys; S6: Encrypt the data of each smart meter node according to the key of each smart meter node to obtain encrypted ciphertext; S7: The smart meter node uploads the encrypted ciphertext to the aggregator; S8: The aggregator adds all the received encrypted ciphertexts according to the sum key information obtained in step S2 to obtain the aggregated ciphertext containing noise, and performs error decryption on the aggregated ciphertext containing noise to obtain the aggregated value; In step S8, there are two ways to perform error processing and decryption on the aggregated ciphertext containing noise, namely: introducing a new third-party trusted institution to eliminate errors and optimizing the encryption and decryption method to reduce errors; Step S4 is as follows: in each time slot t, for each meter node data participating in the aggregation Adding Noise Get noisy data Round the noisy data to the nearest integer Where M is an integer, which is the modulus used in the encryption and decryption process; N is the number of meters participating in the aggregation, and the noise Obey N(0,σ 2 )’s Gaussian distribution; represents the noise value added to the smart meter node i at time slot t; Step S5 is as follows: at time slot t, smart meter node i uses the original key received from the trusted third party organization And according to the synchronized clock in the system, all smart nodes and aggregators share the same input g, according to the pseudo-random function Generate a key vector of dimension n×l, denoted as The aggregator’s key is denoted by K t ;in is a modulo rounding function; Step S6 is as follows: for smart meter i, using the generated key stream information At time slot t, the jth key in the key stream is used in turn. For the jth plaintext message Encryption: Calculation 2. A data security aggregation method for a smart meter as claimed in claim 1, Features: Step S2 is specifically as follows: S21. A trusted third party randomly generates N vectors of dimension n, denoted as k′ 1 ,k′ 2 ,…,k′ N-1 ,k′ N and send it to N smart meter nodes respectively through a secure channel; S22. The trusted third party calculates and keys K′=k′ 1 +k′ 2 ,…,k′ N-1 +k′ N and sends it to the aggregator via a secure channel.
3. A data security aggregation method for a smart meter as claimed in claim 1, Features: Step S3 is specifically as follows: S31, the smart meter node and the aggregator select the modulus q,p of the pseudo-random function and the dimension n of the matrix, and calculate the value S32, the smart meter node and the aggregator randomly generate matrices according to the matrix dimension n and the modulus q S33. The smart meter nodes and aggregators set a synchronization clock in the system for generating timestamp information. The timestamp information is used to ensure that the smart meter nodes and aggregators have the same input when generating a key stream using a pseudo-random function generator.
4. A data security aggregation method for smart meter nodes as claimed in claim 1, Features: The specific process of decryption in step S8 by introducing a new third-party trusted institution to eliminate errors is as follows: S81. Introduce a new third-party trusted agency. According to the timestamp information, it shares the same input g with the smart meter nodes and aggregators. The new third-party trusted agency is responsible for generating the original keys of the smart meter nodes and aggregators during the system startup phase; and calculates the j-th encryption keys of the smart meter nodes and aggregators at time slot t, which are respectively S82, calculate the error e according to the above key information: S83. The new third-party trusted institution sends the error e to the aggregator; S84, the aggregator calculates the sum of all ciphertexts encrypted with the jth key in time slot t, that is, the calculation formula: The aggregator updates the key based on the error e The aggregator decrypts the aggregated ciphertext to obtain the aggregated value using the following formula:
5. A data security aggregation method for smart meter nodes as claimed in claim 1, Features: The specific process of reducing the error by optimizing the encryption and decryption method in step S8 is as follows: Optimized encryption: At time slot t, for smart meter node i, it multiplies the jth plaintext by 10 to the zth power, that is, calculates: For smart meter node i, use the key stream information generated in the previous step in At time slot t, the jth key in the key stream is used in turn. For the jth plaintext message 10 z : Encryption: Calculation The corresponding decryption method after optimized encryption is as follows: Calculate the sum of all ciphertexts encrypted with the jth key in time slot t, that is, the calculation formula: Decrypt the aggregate ciphertext using the following formula: Divide the plaintext information by 10 z , restore, calculate: Finally, the aggregate value information is obtained
Citation Information
Patent Citations
Lightweight privacy protection data multistage aggregation method based on fog computing
CN110536259A
Aggregating encrypted network values
CN113498602A