Lightweight access method and system for distributed photovoltaic grid connection based on certificateless encryption

Through a certificateless encrypted distributed photovoltaic grid-connected lightweight access method and the use of handheld terminals for key management and distribution, low-cost, highly reliable and secure access to distributed photovoltaic terminals is achieved, solving the security authentication and data encryption issues of distributed photovoltaic terminal equipment, and ensuring the safe and stable operation of the power system.

CN116193434BActive Publication Date: 2025-09-19STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211531461.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-01
Publication Date
2025-09-19
Estimated Expiration
2042-12-01

AI Technical Summary

Technical Problem

In existing technologies, distributed photovoltaic terminal equipment lacks effective security authentication and data encryption measures, which increases the risk of cyber attacks. In addition, highly invasive security protection measures are difficult to implement, threatening the safe and stable operation of the power system.

Method used

A lightweight access method for distributed photovoltaic grid-connected devices based on certificateless encryption is adopted. Key management and distribution are carried out through handheld terminals for on-site operations in the power system. Identity authentication and data encryption transmission between distributed photovoltaic data collectors and power system side fusion terminals are realized. National secret algorithms and encryption chips are used for lightweight identity authentication and data encryption.

Benefits of technology

It achieves low-cost, low-intrusion, and highly reliable secure access to distributed photovoltaic terminals, ensures the secure transmission of power system control instructions and collected data, reduces the burden of system key management, and covers business scenarios of the power grid cloud, pipe, edge, and end.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116193434B_ABST
    Figure CN116193434B_ABST
Patent Text Reader

Abstract

A method and system for lightweight access to distributed photovoltaic grid-connected systems based on certificateless encryption includes: establishing a communication connection between a handheld terminal and a fusion terminal, and performing bidirectional identity authentication using the encryption chip's built-in key; distributing a certificateless key based on a national secret algorithm to the fusion terminal; establishing a communication connection between the handheld terminal and a distributed photovoltaic data collector, and distributing the certificateless key based on a national secret algorithm to the distributed photovoltaic data collector; and performing identity authentication and encrypted data transmission between the photovoltaic data collector and the fusion terminal, thereby achieving lightweight access to distributed photovoltaic grid-connected systems. This invention ensures secure access to a large number of distributed photovoltaic terminals and enables reliable transmission of control commands and collected data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power distribution network security protection, and relates to a distributed photovoltaic grid-connected lightweight access method and system based on certificateless encryption. Background Art

[0002] In recent years, large-scale power outages due to cyber attacks have occurred frequently, and critical information infrastructure such as electricity has become an important target of cyber attacks. With the accelerated advancement of new power systems, the development of new energy is showing a trend of both centralized and distributed development. Photovoltaic and other social asset equipment from different investment entities are connected to the power system, and distributed photovoltaic terminals have experienced explosive growth and massive access. There are many manufacturers of distributed photovoltaic and other equipment, and their security protection levels vary. They are often directly exposed to the outdoors and are less controlled by the power grid. In the absence of effective security authentication and monitoring and perception methods, when connected to the edge of the power grid IoT equipment, there is a high possibility of counterfeit equipment accessing and attacking the business main station, which can seriously lead to security incidents such as tampering of control instructions. Therefore, the current distributed photovoltaic grid-connected security protection has the following technical requirements:

[0003] (1) The current power system mainly uses the Modbus transmission protocol for distributed photovoltaic grid-connected terminal devices. Network security protection measures are not considered in the terminal itself and the communication protocol. In the absence of protection measures such as identity authentication and data encryption, the power system is exposed to network security risks such as identity deception and man-in-the-middle attacks.

[0004] (2) The power system currently relies on encryption chips based on national secret algorithms for terminal access. Considering factors such as the investment cost of distributed photovoltaic terminal equipment, the power system's highly intrusive security protection measures are difficult to implement and apply to distributed photovoltaic terminals;

[0005] (3) If the public key and identity are bound by means of certificates, there will be a complex key negotiation process, which requires a large amount of computing resources and storage space. Considering the software and hardware resources of distributed photovoltaic terminal equipment, it is difficult to bear the consumption of computing resources such as key negotiation and data encryption.

[0006] In summary, the large-scale development of distributed photovoltaics and the integration of massive numbers of terminal devices have blurred the boundaries of the power system and increased its exposure to attacks. Furthermore, highly invasive authentication methods for power systems are difficult to apply to social assets. The direct connection of massive numbers of terminals without security measures to the grid can become a springboard for attacks, directly impacting the safe and stable operation of the power grid. Summary of the Invention

[0007] To address the deficiencies in the prior art, the present invention provides a lightweight distributed photovoltaic grid-connected access method and system based on certificateless encryption, ensuring secure access to massive distributed photovoltaic terminals and enabling reliable transmission of control instructions and collected data.

[0008] The present invention adopts the following technical solutions.

[0009] A lightweight distributed photovoltaic grid-connected access method based on certificateless encryption uses a power system field operation handheld terminal for key management and distribution to achieve identity authentication and data encryption transmission between a distributed photovoltaic data collector and a power system side fusion terminal. The method includes the following steps:

[0010] Step 1: The handheld terminal establishes a communication connection with the fusion terminal and completes two-way identity authentication based on the built-in key of the encryption chip;

[0011] Step 2: The handheld terminal distributes a certificateless key based on the national encryption algorithm to the fusion terminal;

[0012] Step 3: The handheld terminal establishes a communication connection with the distributed photovoltaic data collector and completes the certificateless key distribution based on the national secret algorithm of the distributed photovoltaic data collector;

[0013] Step 4: Based on steps 2 and 3, perform identity authentication and data encryption transmission between the photovoltaic data collector and the fusion terminal to achieve lightweight access to the distributed photovoltaic grid.

[0014] Preferably, the handheld terminal, the fusion terminal and the distributed photovoltaic data are all connected by Bluetooth communication.

[0015] Preferably, in step 1, both the handheld terminal and the fusion terminal device are equipped with an encryption chip, which stores the key distributed by the unified cryptographic service platform of the power system. The handheld terminal and the fusion terminal rely on the built-in encryption chip of the device for identity authentication, and the two complete two-way identity authentication. After the verification is passed, the session is valid for 2 minutes, and the authentication becomes invalid after the timeout.

[0016] Preferably, step 1 specifically includes:

[0017] Step 11: The handheld terminal takes the serial number of the handheld device as a hash, signs the hash data, and sends the signature data, serial number, and certificate to the fusion terminal via Bluetooth communication;

[0018] Step 12: The fusion terminal uses the root certificate to verify the certificate sent by the handheld terminal, extracts the public key from the certificate, verifies the signature, and then uses its own serial number as a hash signature. The signature data, serial number, certificate, and verification results are sent to the handheld terminal.

[0019] Step 13: The handheld terminal uses the root certificate to verify the certificate sent by the fusion terminal, extracts the public key from the certificate, and verifies the signature.

[0020] Preferably, step 2 specifically includes:

[0021] Step 21: The fusion terminal sends the identity authentication result and the private key generation trigger message to the handheld terminal;

[0022] Step 22: The handheld terminal calls the national encryption algorithm interface, generates a private key application message, and sends it to the fusion terminal;

[0023] Step 23: The fusion terminal calls the national encryption algorithm interface to generate a private key and sends the private key message to the handheld terminal;

[0024] Step 24: The handheld terminal calls the national encryption algorithm interface, updates the key, and feeds back the update result to the fusion terminal.

[0025] Preferably, step 3 specifically includes:

[0026] Step 31: The handheld terminal establishes a connection with the photovoltaic data collector;

[0027] Step 32: The photovoltaic data collector sends a private key generation trigger message to the handheld terminal;

[0028] Step 33: The handheld terminal calls the national secret algorithm interface, generates a private key application message, and sends it to the photovoltaic data collector;

[0029] Step 34: The photovoltaic data collector calls the national secret algorithm interface to generate a private key and sends the message to the handheld terminal;

[0030] Step 35: The handheld terminal calls the national encryption algorithm interface, updates the key, and feeds back the update result to the photovoltaic data collector.

[0031] Preferably, the interface is a national cryptographic algorithm KGC interface.

[0032] Preferably, in step 4, identity authentication and data encryption transmission between the photovoltaic data collector and the fusion terminal are performed based on the extended DL / T 698.45-2017 protocol.

[0033] Preferably, step 4 specifically includes:

[0034] Step 41: The fusion terminal obtains the ID and key version of the key device to be downloaded;

[0035] Step 42: The photovoltaic data collector calls the interface provided by the encryption algorithm library to obtain the key status, that is, the algorithm library status, obtains the device ID, and responds to the fusion terminal;

[0036] Step 43: The fusion terminal confirms whether to proceed to the next step based on the returned algorithm library status. When the key distribution is completed, it proceeds to the next step.

[0037] Step 44: The fusion terminal and the photovoltaic data collector start identity authentication, and the fusion terminal calls the algorithm library interface to obtain the fusion terminal calculation parameters;

[0038] Step 44: The photovoltaic data collector calls the algorithm library interface to obtain the collector calculation parameters;

[0039] Step 45: The fusion terminal calls the algorithm library interface to obtain ciphertext 1, and sends ciphertext 1 + TID to the photovoltaic data collector;

[0040] Among them, ciphertext 1 includes M1 and S1. M1 is obtained by encrypting the random number RN1 through the ID of the fusion terminal, and S1 is obtained by signing M1 with the collector private key DS2;

[0041] Step 46: The photovoltaic data collector calls the algorithm library interface to decrypt ciphertext 1. If the decryption fails, the authentication failure is returned. If the decryption succeeds, the algorithm library interface is called to obtain ciphertext 2 and return it to the fusion terminal.

[0042] Among them, successful decryption means using the fusion terminal private key DS1 to decrypt M1 and obtain RN1;

[0043] Ciphertext 2 includes M2 and S2, where M2 is obtained by encrypting the random number RN2 using the collector's ID, and S2 is obtained by signing M2 using the fusion terminal private key DS1.

[0044] Step 47: The fusion terminal calls the algorithm library interface to decrypt the ciphertext 2 to obtain RN2.

[0045] A lightweight distributed photovoltaic grid-connected access system based on certificateless encryption, including:

[0046] The handheld terminal and fusion terminal identity authentication module is used to establish a communication connection between the handheld terminal and the fusion terminal, and completes two-way identity authentication based on the built-in key of the encryption chip;

[0047] The fusion terminal key distribution module is used for handheld terminals to distribute certificateless keys based on national encryption algorithms to fusion terminals;

[0048] The data collector key distribution module is used to establish a communication connection between the handheld terminal and the distributed photovoltaic data collector and complete the key distribution of the distributed photovoltaic data collector;

[0049] The photovoltaic data collector and fusion terminal identity authentication and data transmission module is used to perform identity authentication and data encryption transmission between the photovoltaic data collector and the fusion terminal, realizing lightweight access to distributed photovoltaic grid connection.

[0050] A terminal includes a processor and a storage medium; the storage medium is used to store instructions;

[0051] The processor is configured to operate according to the instructions to execute the steps of the method.

[0052] A computer-readable storage medium stores a computer program, which implements the steps of the method when executed by a processor.

[0053] The beneficial effects of the present invention are as follows:

[0054] The present invention starts from the security requirements of distributed photovoltaic grid-connected devices receiving power system control instructions, and performs certificateless password authentication based on the national secret algorithm under the premise of ensuring low cost, low intrusion and high reliability, and expands the existing DL / T 698.45-2017 protocol to realize the identity authentication and encrypted transmission of edge devices such as power system fusion terminals and distributed photovoltaic collection terminals (the present invention does not involve encrypted transmission, and can write identity authentication, key exchange, and signature verification), thereby ensuring that power system control instructions and collected data are not tampered with, providing security protection technology for the large-scale construction of distributed photovoltaics, and realizing hierarchical authentication security protection for lightweight terminal access.

[0055] (1) The present invention combines the characteristics of distributed photovoltaic services and proposes a hierarchical authentication concept. Based on the "cloud, pipe, edge, and end" business system, cloud-edge authentication still uses the unified cryptographic service platform of the power system to issue digital certificates, and relies on encryption chip storage to achieve two-way identity authentication; edge-end authentication takes into account the problems of insufficient computing resources of end devices, unstable communication environment, and limited storage space, and proposes a lightweight edge-end identity authentication method based on soft encryption. Through certificateless soft encryption of the national secret algorithm, identity authentication and data encryption transmission between distributed photovoltaic collection terminals and power system edge devices are realized. The user's public key can be directly calculated using the user identifier and device parameters. Before signature verification, there is no need to exchange public key certificates between users and the key amount is very small, which greatly reduces the system key management burden and ensures the low cost, low intrusion and high reliability of distributed photovoltaic grid-connected security protection;

[0056] (2) The present invention fully considers the specific implementation difficulty and is compatible with existing operating habits. It proposes a method for distributing keys using handheld terminals on site in the power system. The handheld terminal is selected as the key generation center KGC (key generation center) to generate a combination of partial private keys and user secret values. It does not use certificates to bind public keys and identities, and does not rely entirely on KGC to generate user private keys. It realizes key management and distribution under a certificateless cryptographic system. Bluetooth communication is used between the handheld terminal and the fusion terminal and collector, which belongs to a near-field low-risk communication scenario, achieving the goals of low transformation cost and low implementation difficulty.

[0057] (3) The lightweight access method proposed by the present invention enables the handheld terminal and the power system side device to achieve identity authentication between the two by relying on the original asymmetric algorithm key of the device based on the PKI system; on the basis of successful identity authentication, the handheld terminal issues a certificateless key to the side device, and the edge devices such as the fusion terminal have the key for authentication with the distributed photovoltaic collection terminal. The handheld terminal establishes communication with the distributed photovoltaic collection terminal through Bluetooth and issues a certificateless key to the photovoltaic collection terminal. The photovoltaic collection terminal has the key for authentication with the power system side device, which improves the current situation of the lack of network security protection of distributed photovoltaic terminals and covers the security authentication to the entire business scenario of the power grid cloud, pipe, edge, and end. It can also be extended to business systems such as the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 It is a schematic diagram showing the principle of implementing the method of the present invention;

[0059] Figure 2 This is a flow chart of key distribution between a handheld terminal and a fusion terminal according to the present invention;

[0060] Figure 3 This is a flow chart of key distribution between the handheld terminal and the photovoltaic collector of the present invention;

[0061] Figure 4 This is the authentication flow chart of the integrated terminal and collector of the present invention. DETAILED DESCRIPTION

[0062] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. The embodiments described in this application are only part of the embodiments of the present invention, not all of them. Based on the spirit of the present invention, other embodiments obtained by ordinary technicians in this field without making creative efforts are all within the scope of protection of the present invention.

[0063] like Figure 1As shown, embodiment 1 of the present invention provides a lightweight access method for distributed photovoltaic grid-connected connection based on certificateless encryption, adopts a power system on-site operation handheld terminal for key management and distribution, and adopts the key distributed by the handheld terminal to realize the identity authentication and encrypted transmission between the power system side device and the photovoltaic collection terminal: the communication between the power system side device and the photovoltaic collection terminal is realized through HPLC to establish a communication connection; the power system side device and the photovoltaic collection terminal perform key negotiation and identity authentication; the power system side device and the photovoltaic collection terminal successfully authenticate each other, negotiate symmetric algorithm keys, ensure data transmission security, and thus reduce the computing resources of the photovoltaic collection terminal.

[0064] In a preferred but non-limiting embodiment of the present invention, the method comprises the following steps:

[0065] Step 1: The handheld terminal establishes a Bluetooth communication connection with the fusion terminal and completes identity authentication based on the built-in key of the encryption chip.

[0066] Edge devices such as handheld terminals and integrated terminals are equipped with built-in encryption chips that store the keys distributed by the unified cryptographic service platform of the power system. To ensure the security of Bluetooth near-field communication between handheld terminals and integrated terminals, both first rely on the original built-in encryption chips of the devices for identity authentication.

[0067] Specific as Figure 2 As shown, the implementation steps are as follows:

[0068] Step 11: The handheld terminal takes the serial number of the handheld device as a hash, signs the hash data, and sends the signature data, serial number, and certificate to the fusion terminal via Bluetooth communication;

[0069] Step 12: The fusion terminal uses the root certificate to verify the certificate sent by the handheld terminal, extracts the public key from the certificate, verifies the signature, and then uses its own serial number as a hash signature. The signature data, serial number, certificate, and verification results are sent to the handheld terminal.

[0070] Step 13: The handheld terminal uses the root certificate to verify the certificate sent by the fusion terminal, extracts the public key from the certificate, and verifies the signature.

[0071] At this point, the handheld terminal and the converged terminal have completed two-way identity authentication. After the verification is passed, the session is valid for 2 minutes and the authentication becomes invalid after the timeout.

[0072] Step 2: The handheld terminal distributes the certificateless key based on the national encryption algorithm to the edge devices such as the converged terminal, as follows: Figure 2 , the implementation steps are as follows:

[0073] Step 21: The fusion terminal sends the identity authentication result and the private key generation trigger message to the handheld terminal;

[0074] Step 22: The handheld terminal calls the KGC interface, generates a private key application message, and sends it to the fusion terminal;

[0075] Step 23: The fusion terminal calls the KGC interface to generate a private key and sends the private key message to the handheld terminal.

[0076] Step 24: The handheld terminal calls the KGC interface to update the key and feeds back the update result (success / failure) to the fusion terminal.

[0077] Further preferably, key management and issuance in a certificateless system are performed based on the SM2 certificateless cryptographic system.

[0078] The user public key can be directly calculated using the user ID and system parameters. Therefore, before signature verification, there is no need to exchange public key certificates between users, and there is no need to support the complex process of certificate management. The amount of keys stored on the platform is very small. As the number of terminal devices increases, the amount of keys remains almost unchanged, which greatly reduces the system key management burden. It can support massive user IDs and is particularly suitable for distributed photovoltaic business scenarios.

[0079] Step 3: The handheld terminal establishes a Bluetooth communication connection with the distributed photovoltaic data collector and completes the key distribution of the distributed photovoltaic data collector, such as Figure 3 As shown, the implementation steps are as follows:

[0080] Step 31: The handheld terminal establishes a Bluetooth connection with the photovoltaic data collector;

[0081] Step 32: The photovoltaic data collector sends a private key generation trigger message to the handheld terminal;

[0082] Step 33: The handheld terminal calls the KGC interface, generates a private key application message, and sends it to the photovoltaic data collector;

[0083] Step 34: The photovoltaic data collector calls the KGC interface to generate a private key and sends the message to the handheld terminal;

[0084] Step 35: The handheld terminal calls the KGC interface to update the key and feeds back the update result (success / failure) to the photovoltaic data collector.

[0085] Step 4: Based on the extended DL / T 698.45-2017 protocol, the identity authentication and data encryption transmission of the photovoltaic data collector and the fusion terminal are implemented to achieve lightweight access to the distributed photovoltaic grid and ensure the security of the interaction between the control instructions and the collected data of the distributed photovoltaic collector and the fusion terminal.

[0086] In order to ensure the security and reliability of the communication protocol and the promotion of the standard, the DL / T 698.45-2017 protocol is adopted. The DL / T698.45-2017 protocol originally has encryption and authentication functions. After further expansion, it can meet the authentication and encrypted transmission of edge devices such as photovoltaic data collectors and fusion terminals.

[0087] like Figure 4 As shown, the implementation steps are as follows:

[0088] Step 41: The fusion terminal obtains the ID and key version of the key device to be downloaded;

[0089] Step 42: The photovoltaic data collector calls the interface provided by the encryption algorithm library to obtain the key status, that is, the algorithm library status, obtains the device ID, and responds to the fusion terminal;

[0090] Step 43: The fusion terminal confirms whether to proceed to the next step based on the returned algorithm library status; when the key distribution is completed, proceed to the next step;

[0091] Step 44: The fusion terminal and the photovoltaic data collector start identity authentication, and the fusion terminal calls the algorithm library interface to obtain the fusion terminal calculation parameters;

[0092] Step 44: The photovoltaic data collector calls the algorithm library interface to obtain the collector calculation parameters;

[0093] Step 45: The fusion terminal calls the algorithm library interface to obtain ciphertext 1 (M1+S1), and sends ciphertext 1+TID to the photovoltaic data collector;

[0094] Among them, ciphertext 1 includes M1 and S1. M1 is obtained by encrypting the random number RN1 through the ID of the fusion terminal, and S1 is obtained by signing M1 with the collector private key DS2;

[0095] Step 46: The photovoltaic data collector calls the algorithm library interface to decrypt ciphertext 1. If the decryption fails, the authentication failure message is returned. If the decryption succeeds, the algorithm library interface is called to obtain ciphertext 2 (M2+S2), and the ciphertext 2 (M2+S2) is returned to the fusion terminal.

[0096] Among them, successful decryption means using the fusion terminal private key DS1 to decrypt M1 and obtain RN1;

[0097] Ciphertext 2 includes M2 and S2, where M2 is obtained by encrypting the random number RN2 using the collector's ID, and S2 is obtained by signing M2 using the fusion terminal private key DS1.

[0098] Step 47: The fusion terminal calls the algorithm library interface to decrypt the ciphertext 2 to obtain RN2.

[0099] The photovoltaic data collector mentioned above is a device that collects data from photovoltaic grid-connected inverters, combiner boxes, weather stations, and electricity meters in photovoltaic power plants and transmits it to the photovoltaic control system via GPRS, Ethernet, WIFI, 3G, etc.

[0100] The aforementioned converged terminal is an edge device within the "cloud-pipe-edge-device" architecture of State Grid Corporation of China's smart IoT system. It features information collection, IoT proxy, and edge computing capabilities, supporting marketing, power distribution, and emerging businesses. Utilizing a hardware platform, software-based functionality, modularized structure, hardware and software decoupling, and adaptive communication protocol design, it meets the requirements of high-performance concurrency, large-capacity storage, and multiple collection objects. This intelligent converged terminal integrates functions such as power supply and consumption information collection in distribution stations, data collection from various collection terminals or energy meters, equipment status monitoring, communication networking, local analysis and decision-making, and collaborative computing.

[0101] Embodiment 2 of the present invention provides a distributed photovoltaic grid-connected lightweight access system based on certificateless encryption, including:

[0102] The handheld terminal and fusion terminal identity authentication module is used to establish a communication connection between the handheld terminal and the fusion terminal, and completes two-way identity authentication based on the built-in key of the encryption chip;

[0103] The fusion terminal key distribution module is used for handheld terminals to distribute certificateless keys based on national encryption algorithms to fusion terminals;

[0104] The data collector key distribution module is used to establish a communication connection between the handheld terminal and the distributed photovoltaic data collector and complete the key distribution of the distributed photovoltaic data collector;

[0105] The photovoltaic data collector and fusion terminal identity authentication and data transmission module is used to perform identity authentication and data encryption transmission between the photovoltaic data collector and the fusion terminal, realizing lightweight access to distributed photovoltaic grid connection.

[0106] A terminal includes a processor and a storage medium; the storage medium is used to store instructions;

[0107] The processor is configured to operate according to the instructions to execute the steps of the method.

[0108] A computer-readable storage medium stores a computer program, which implements the steps of the method when executed by a processor.

[0109] The beneficial effects of the present invention are as follows:

[0110] The present invention starts from the security requirements of distributed photovoltaic grid-connected devices receiving power system control instructions, and performs certificateless password authentication based on the national secret algorithm under the premise of ensuring low cost, low intrusion and high reliability, and expands the existing DL / T 698.45-2017 protocol to realize the identity authentication and encrypted transmission of edge devices such as power system fusion terminals and distributed photovoltaic collection terminals (the present invention does not involve encrypted transmission, and can write identity authentication, key exchange, and signature verification), thereby ensuring that power system control instructions and collected data are not tampered with, providing security protection technology for the large-scale construction of distributed photovoltaics, and realizing hierarchical authentication security protection for lightweight terminal access.

[0111] (1) The present invention combines the characteristics of distributed photovoltaic services and proposes a hierarchical authentication concept. Based on the "cloud, pipe, edge, and end" business system, cloud-edge authentication still uses the unified cryptographic service platform of the power system to issue digital certificates, and relies on encryption chip storage to achieve two-way identity authentication; edge-end authentication takes into account the problems of insufficient computing resources of end devices, unstable communication environment, and limited storage space, and proposes a lightweight edge-end identity authentication method based on soft encryption. Through certificateless soft encryption of the national secret algorithm, identity authentication and data encryption transmission between distributed photovoltaic collection terminals and power system edge devices are realized. The user's public key can be directly calculated using the user identifier and device parameters. Before signature verification, there is no need to exchange public key certificates between users and the key amount is very small, which greatly reduces the system key management burden and ensures the low cost, low intrusion and high reliability of distributed photovoltaic grid-connected security protection;

[0112] (2) The present invention fully considers the specific implementation difficulty and is compatible with existing operating habits. It proposes a method for distributing keys using handheld terminals on site in the power system. The handheld terminal is selected as the key generation center KGC (key generation center) to generate a combination of partial private keys and user secret values. It does not use certificates to bind public keys and identities, and does not rely entirely on KGC to generate user private keys. It realizes key management and distribution under a certificateless cryptographic system. Bluetooth communication is used between the handheld terminal and the fusion terminal and collector, which belongs to a near-field low-risk communication scenario, achieving the goals of low transformation cost and low implementation difficulty.

[0113] (3) The lightweight access method proposed by the present invention enables the handheld terminal and the power system side device to achieve identity authentication between the two by relying on the original asymmetric algorithm key of the device based on the PKI system; on the basis of successful identity authentication, the handheld terminal issues a certificateless key to the side device, and the edge devices such as the fusion terminal have the key for authentication with the distributed photovoltaic collection terminal. The handheld terminal establishes communication with the distributed photovoltaic collection terminal through Bluetooth and issues a certificateless key to the photovoltaic collection terminal. The photovoltaic collection terminal has the key for authentication with the power system side device, which improves the current situation of the lack of network security protection of distributed photovoltaic terminals and covers the security authentication to the entire business scenario of the power grid cloud, pipe, edge, and end. It can also be extended to business systems such as the Internet of Things.

[0114] The present disclosure may be a system, method and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0115] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination thereof. As used herein, a computer-readable storage medium is not to be construed as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through an electrical wire.

[0116] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.

[0117] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as "C" language or similar programming languages. Computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., utilizing an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be personalized by utilizing the state information of the computer-readable program instructions. The electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.

[0118] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A lightweight distributed photovoltaic grid-connected access method based on certificateless encryption uses handheld terminals for power system field operations for key management and distribution, enabling identity authentication and data encryption transmission between distributed photovoltaic data collectors and power system-side fusion terminals. Features include: The handheld terminal, the fusion terminal, and the distributed photovoltaic data collector are all connected by Bluetooth communication; the method includes the following steps: Step 1: The handheld terminal establishes a communication connection with the fusion terminal and completes two-way identity authentication based on the built-in key of the encryption chip; Step 2: The handheld terminal distributes a certificateless key based on the national encryption algorithm to the fusion terminal; Step 3: The handheld terminal establishes a communication connection with the distributed photovoltaic data collector and completes the certificateless key distribution based on the national secret algorithm of the distributed photovoltaic data collector; Step 4: Based on steps 2 and 3, the identity authentication and data encryption transmission between the photovoltaic data collector and the fusion terminal are carried out based on the extended DL / T 698.45-2017 protocol to achieve lightweight access to the distributed photovoltaic grid.

2. The distributed photovoltaic grid-connected lightweight access method based on certificateless encryption according to claim 1 is characterized by: In step 1, both the handheld terminal and the fusion terminal are equipped with encryption chips, which store the keys distributed by the unified cryptographic service platform of the power system. The handheld terminal and the fusion terminal rely on the built-in encryption chips to perform identity authentication. The two complete two-way identity authentication. After the verification is passed, the session is valid for 2 minutes. After the timeout, the authentication becomes invalid.

3. The distributed photovoltaic grid-connected lightweight access method based on certificateless encryption according to claim 1 is characterized in that: Step 1 specifically includes: Step 11: The handheld terminal takes the serial number of the handheld device as a hash, signs the hash data, and sends the signature data, serial number, and certificate to the fusion terminal via Bluetooth communication; Step 12: The fusion terminal uses the root certificate to verify the certificate sent by the handheld terminal, extracts the public key from the certificate, verifies the signature, and then uses its own serial number as a hash signature. The signature data, serial number, certificate, and verification results are sent to the handheld terminal. Step 13: The handheld terminal uses the root certificate to verify the certificate sent by the fusion terminal, extracts the public key from the certificate, and verifies the signature.

4. The distributed photovoltaic grid-connected lightweight access method based on certificateless encryption according to claim 1 is characterized in that: Step 2 specifically includes: Step 21: The fusion terminal sends the identity authentication result and the private key generation trigger message to the handheld terminal; Step 22: The handheld terminal calls the national encryption algorithm interface, generates a private key application message, and sends it to the fusion terminal; Step 23: The fusion terminal calls the national encryption algorithm interface to generate a private key and sends the private key message to the handheld terminal; Step 24: The handheld terminal calls the national encryption algorithm interface, updates the key, and feeds back the update result to the fusion terminal.

5. The distributed photovoltaic grid-connected lightweight access method based on certificateless encryption according to claim 1 is characterized in that: Step 3 specifically includes: Step 31: The handheld terminal establishes a connection with the photovoltaic data collector; Step 32: The photovoltaic data collector sends a private key generation trigger message to the handheld terminal; Step 33: The handheld terminal calls the national secret algorithm interface, generates a private key application message, and sends it to the photovoltaic data collector; Step 34: The photovoltaic data collector calls the national secret algorithm interface to generate a private key and sends the message to the handheld terminal; Step 35: The handheld terminal calls the national encryption algorithm interface, updates the key, and feeds back the update result to the photovoltaic data collector.

6. The distributed photovoltaic grid-connected lightweight access method based on certificateless encryption according to claim 4 or 5, characterized in that: The interface is the national cryptographic algorithm KGC interface.

7. The distributed photovoltaic grid-connected lightweight access method based on certificateless encryption according to claim 1 is characterized in that: Step 4 specifically includes: Step 41: The fusion terminal obtains the ID and key version of the key device to be downloaded; Step 42: The photovoltaic data collector calls the interface provided by the encryption algorithm library to obtain the key status, that is, the algorithm library status, obtains the device ID, and responds to the fusion terminal; Step 43: The fusion terminal confirms whether to proceed to the next step based on the returned algorithm library status. When the key distribution is completed, it proceeds to the next step. Step 44: The fusion terminal and the photovoltaic data collector start identity authentication, and the fusion terminal calls the algorithm library interface to obtain the fusion terminal calculation parameters; Step 44: The photovoltaic data collector calls the algorithm library interface to obtain the collector calculation parameters; Step 45: The fusion terminal calls the algorithm library interface to obtain ciphertext 1, and sends ciphertext 1 + TID to the photovoltaic data collector; Among them, ciphertext 1 includes M1 and S1. M1 is obtained by encrypting the random number RN1 through the ID of the fusion terminal, and S1 is obtained by signing M1 with the collector private key DS2; Step 46: The photovoltaic data collector calls the algorithm library interface to decrypt ciphertext 1. If the decryption fails, the authentication failure is returned. If the decryption succeeds, the algorithm library interface is called to obtain ciphertext 2 and return it to the fusion terminal. Among them, successful decryption means using the fusion terminal private key DS1 to decrypt M1 and obtain RN1; Ciphertext 2 includes M2 and S2, where M2 is obtained by encrypting the random number RN2 using the collector's ID, and S2 is obtained by signing M2 using the fusion terminal private key DS1. Step 47: The fusion terminal calls the algorithm library interface to decrypt the ciphertext 2 to obtain RN2.

8. A distributed photovoltaic grid-connected lightweight access system based on certificateless encryption, used to implement the method described in any one of claims 1 to 7, characterized in that: The access system includes: The handheld terminal and fusion terminal identity authentication module is used to establish a communication connection between the handheld terminal and the fusion terminal, and completes two-way identity authentication based on the built-in key of the encryption chip; The fusion terminal key distribution module is used for handheld terminals to distribute certificateless keys based on national encryption algorithms to fusion terminals; The data collector key distribution module is used to establish a communication connection between the handheld terminal and the distributed photovoltaic data collector and complete the key distribution of the distributed photovoltaic data collector; The photovoltaic data collector and fusion terminal identity authentication and data transmission module is used to perform identity authentication and data encryption transmission between the photovoltaic data collector and the fusion terminal, realizing lightweight access to distributed photovoltaic grid connection.

9. A terminal comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is configured to operate according to the instructions to execute the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Identity authentication and secret key negotiation method and device in communication network

    CN101267301A

  • Lightweight access authentication method and system for power Internet of Things equipment based on IBC system

    CN113704736A

  • SM9 secret key infrastructure and security system

    CN113872760A