An intelligent power grid identity authentication system based on physical unclonable functions
Through a lightweight authentication system based on physically non-cloneable functions, the problem of device authentication difficulties and vulnerability in smart grids is solved, and low overhead, secure end-to-end authentication and anonymity protection are achieved.
Patent Information
- Application Number
- CN202310207018.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-06
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2043-03-06
AI Technical Summary
The existing smart grid authentication mechanism is not applicable to grid smart devices (such as sensors and smart meters) that do not have complex computing functions, and is vulnerable to network and physical attacks, resulting in frequent network failures.
The identity authentication system based on the physically uncloned function is adopted, and authentication between devices is achieved through lightweight hashing operations and exclusive OR operations, and the physically uncloned function is used to resist attacks and negotiate a secure session key.
It realizes end-to-end authentication with low computing overhead, resists network and physical attacks, provides anonymity and privacy protection, prevents replay attacks, and ensures session key security.
Smart Images

Figure CN116436597B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of smart grid, and particularly relates to a smart grid identity authentication system based on physical unclonable function (PUF). Background Art
[0002] Smart grid plays an important role in the demand response management of modern smart cities using ICT (Information and Communication Technology). In a smart grid environment, grid intelligent devices such as sensors and smart meters are widely used. For example, sensors are deployed on high-voltage power lines. The basic task of each sensor is to monitor the physical state of the high-voltage supply line. If any break or damage occurs in the power supply line, the sensor node will immediately forward the sensed data to the gateway. After obtaining the sensing data, the gateway will forward the received data together with its current location to the control center via the Internet. The control center collects the sensing data and analyzes it, and based on the analysis result, the control center detects the line fault and notifies the recovery team.
[0003] Smart grid may be subject to cyber attacks, which may lead to network failures. For example, an attacked grid intelligent device may pass maliciously tampered false data to the control center through the gateway, resulting in the concealment or false reporting of faults. In addition, for grid intelligent devices in an unmanned supervision environment, in addition to facing the risk of cyber attacks, they may also face physical attacks such as directly tampering with the memory. Therefore, the probability of network failures caused by unmanned grid intelligent devices is higher. Therefore, it is necessary to introduce an identity authentication mechanism in the smart grid system so that the entities in the system can securely transmit data after authenticating each other.
[0004] However, most of the existing authentication mechanisms require complex cryptographic operations on the authentication entities, which are not applicable to grid intelligent devices such as sensors and smart meters that do not have complex computing functions. Summary of the Invention
[0005] To solve the above problems existing in the prior art, the present invention provides a smart grid identity authentication system based on physical unclonable function (PUF).
[0006] The technical problems to be solved by the present invention are realized through the following technical solutions:
[0007] A smart grid identity authentication system based on physical unclonable function (PUF) includes: grid intelligent devices, a gateway, and a control center; wherein,
[0008] The grid intelligent device is configured to send a first message Msg1 to the gateway; wherein, Msg1 = {S1, S2, L i}, S1 = ID e⊕(r1||r2), S2 = h(ID e ||ID g ||K e ||r1||r2)); L i is the challenge information, and L i belongs to the challenge information sequence {L1, L2, … L n}}, n ≥ 2; The challenge information sequence is generated by the control center during the registration process of grid intelligent devices and sent to the grid intelligent devices; ID e is the identity identifier of the grid intelligent device, and ID g is the identity identifier of the gateway; K e is the first temporary key calculated by the control center during the registration process of grid intelligent devices and sent to the grid intelligent devices; r1 and r2 are two random numbers selected by the grid intelligent device; h() represents the hash operation, || represents the character concatenation operation, and ⊕ represents the exclusive-or operation;
[0009] The gateway is used to generate the second message Msg2 and send it to the control center after receiving Msg1; where, Msg2 = {S1, S2, L i , ID g , G1, G2}, G1 = K g ⊕(r3||r4||LI g ), G2 = h(ID g ||K g ||r3||r4); K g is the second temporary key calculated by the control center during the gateway registration process and sent to the gateway; r3 and r4 are two random numbers selected by the gateway; LI g is the location identifier of the gateway;
[0010] The control center is used to extract S1, S2, L i , ID g , G1 and G2 from Msg2 after receiving Msg2; Determine the corresponding ID i and the challenge response pair (L e , R i ) according to L i ; where, R i is the response made by the grid intelligent device based on its physical unclonable function to L i , and (L i , R i ) belongs to the challenge response pair sequence {(L1, R1), (L2, R2) … (L n , R n ), {(L1, R1), (L2, R2) … (L n , R n)} is sent by the grid intelligent device to the control center during the grid intelligent device registration process;
[0011] The control center is also used to calculate ID e ⊕ S1 and extract r1 and r2 from the calculation result ID e ⊕ S1 = (r1||r2); calculate S2’ = h(ID e ||ID g ||K e ||r1||r2), if S2’ = S2, then the grid intelligent device is authenticated; it is also used to calculate G1⊕K g and extract r3 and r4 from the calculation result G1⊕K g = (r3||r4||LI g ) and calculate G2’ = h(ID g ||K g ||r3||r4), if G2’ = G2, then the gateway is authenticated;
[0012] The control center is also used to calculate the shared key SK = h(ID g ||r1||r3||r5), and send the third message Msg3 to the gateway; where Msg3 = {C1, C2, C3, C4}, C1 = r3⊕(r1||r5), C2 = r2⊕(r3||r5||L i ), C3 = h(ID g ||K g ||r4||SK), C4 = h(ID e ||K e ||r2||R i ||SK);
[0013] The gateway is also used to, after receiving Msg3, calculate r3⊕C1, extract r1 and r5 from the calculation result r3⊕C1 = (r1||r5), and calculate the shared key SK = h(ID g ||r1|r3||r5); calculate C3’ = h(ID g ||K g ||r4||SK), if C3’ = C3, then the control center is authenticated; send the fourth message Msg4 = {C2, C4} to the grid intelligent device;
[0014] The grid intelligent device is also used to, after receiving Msg4, calculate r2⊕C2, extract r3 and r5 from the calculation result r2⊕C2 = (r3||r5||L i ), and calculate the shared key SK = h(ID g ||r1||r3||r5); calculate R i ’←PUFi (L i ), and calculate C4’ = h(ID e ||K e ||r2||R i ’||SK). If C4’ = C4, then the authentication of the control center is passed. Among them, PUF i() represents the physical unclonable function, and R i ’ represents the response re - made by the power grid intelligent device based on its physical unclonable function to L i .
[0015] The power grid intelligent device, the gateway, and the control center perform data transmission based on the shared key SK.
[0016] Optionally, the control center is further configured to extract LI g from the calculation result G1⊕K g =(r3||r4||LI g ), and determine the location of the gateway by using LI g .
[0017] Optionally, in the registration process of the power grid intelligent device,
[0018] the power grid intelligent device is configured to send a registration request of the power grid intelligent device to the control center. The registration request of the power grid intelligent device carries the identity identifier ID e of the power grid intelligent device;
[0019] The control center is configured to, in response to the registration request of the power grid intelligent device, calculate the first temporary key K e =h(ID e ||MSK), and generate the challenge information sequence {L1, L2, … L n} for the power grid intelligent device; send K e and the generated challenge information sequence {L1, L2, … L n} to the power grid intelligent device. Among them, MSK is the master key of the control center;
[0020] The power grid intelligent device is further configured to, after receiving Ke and the challenge information sequence {L1, L2, … L n} sent by the control center, generate the challenge response pair sequence {(L1, R1), (L2, R2) … (L n , R n )} based on its physical unclonable function and send it to the control center;
[0021] The control center is further configured to store the ID e of the power grid intelligent device, K e , {(L1, R1), (L2, R2) … (L n , Rn )} to complete the registration of grid intelligent devices.
[0022] Optionally, in the grid intelligent device registration process,
[0023] The control center is also used to check whether there is already a registered grid intelligent device with the identity ID in the grid intelligent device registration request when receiving the grid intelligent device registration request e ; if not, continue to complete the registration of the grid intelligent device in response to the grid intelligent device registration request, and if so, reject the grid intelligent device registration request.
[0024] Optionally, in the gateway registration process,
[0025] The gateway is used to send a gateway registration request to the control center; the gateway registration request carries the identity ID of the gateway g ;
[0026] The control center is used to calculate the second temporary key K g = h(ID g ||MSK); store K g and send K g to the gateway; where MSK is the master key of the control center;
[0027] The gateway is also used to store the K sent by the control center g for backup.
[0028] Optionally, in the gateway registration process,
[0029] The control center is also used to check whether there is already a registered gateway with the identity ID in the gateway registration request when receiving the gateway registration request g ; if not, continue to complete the registration of the gateway in response to the gateway registration request, and if so, reject the gateway registration request.
[0030] Optionally, the grid intelligent device is also used to trigger the restart of the grid intelligent device registration process when L i has finished taking C n .
[0031] Optionally, n = 5.
[0032] Optionally, the grid intelligent device is also used to delete L i ' ← PUF i (L i ) and then delete L i ;
[0033] The control center is also used to delete (L n ,R n ) after sending the third message Msg3 to the gateway.
[0034] The intelligent power grid authentication system based on physical unclonable function provided by the present invention has the following beneficial effects:
[0035] (1) In the present invention, the power grid intelligent device, the control center and the gateway only need to perform lightweight hash operations, exclusive OR operations, character splicing operations, etc. Among them, the power grid intelligent device performs three hash operations, the gateway performs three hash operations, and the control center performs seven hash operations. Therefore, compared with the commonly used public key encryption in the existing authentication mechanism, the computational overhead of implementing identity authentication in the present invention is very low, and the problem that devices such as sensors and smart meters cannot participate in identity authentication due to insufficient computing power is solved.
[0036] (2) The physical unclonable function is deployed in the power grid intelligent device of the present invention. If an attempt is made to tamper with or damage the memory of the power grid intelligent device, the response R of the power grid intelligent device will i change, so that the expected output will not be generated during the authentication process, resulting in authentication failure. In addition, even if the power grid intelligent device is stolen, the opponent cannot capture its PUF from the power grid intelligent device, so it can resist cloning and physical attacks. In addition, the use of the physical unclonable function makes the power grid intelligent device free from the problem of key leakage.
[0037] (3) The present invention realizes end-to-end mutual authentication between the power grid intelligent device and the control center, and between the gateway and the control center. Among them, the power grid intelligent device completes the authentication of the control center through the secret {ID e ,<Li,R i >,K e ,r2} shared with the control center and the key SK. The gateway completes the authentication of the control center through the secret {K g ,r4} shared with the control center and the key SK. The control center completes the authentication of the sensor through the secret {ID e ,K e} shared with the sensor and the random numbers {r1,r2} generated by the sensor. The control center completes the authentication of the gateway through the secret {K g} shared with the gateway and the random numbers {r3,r4} generated by the gateway.
[0038] (4) Provide a secure session key and forward secrecy: The grid intelligent device, gateway, and control center negotiate a session key SK for subsequent secure communication. This session key is calculated based on the random number provided by the grid intelligent device, the random number provided by the gateway, and the random number provided by the control center. Therefore, no third party can obtain this session key in advance, ensuring the security of the session key. Compared with the existing authentication mechanism where an attacker can calculate the session key using public parameters, the session key in the present invention cannot be obtained by any third party, so forward secrecy can be provided.
[0039] (5) Resist replay attacks: If an attempt is made to launch a replay attack when the gateway sends the second message Msg2 to the control center, the attack will not succeed. This is because the grid intelligent device uses a new challenge message Li each time it initiates authentication, and the control center also determines the identity ID of the grid intelligent device based on the new challenge message Li. e . And after each authentication is completed, both the grid intelligent device and the control center will discard the used challenge message Li and challenge response message R i . Therefore, if an opponent replays the message Msg2, the authentication will fail because the Li in the replayed Msg2 has been used.
[0040] (6) The grid intelligent device participating in the authentication in the present invention has anonymity. During its registration phase, the grid intelligent device sends its true identity identifier ID e to the control center through a secure channel. Subsequently, during the entire authentication process, it does not transmit its true identity, but instead uses random numbers and XOR operations to mask the identity identifier of the grid intelligent device. An attacker cannot obtain the true identity of the grid intelligent device, and user behavior cannot be traced, achieving privacy protection for the grid intelligent device. In the subsequent authentication and key negotiation protocol, the control center determines the true identity of the grid intelligent device through Li. Therefore, the present invention can not only protect the true identity of the sensor but also achieve untraceability of user behavior.
[0041] In summary, the present invention realizes lightweight authentication in the smart grid system, can achieve end-to-end mutual authentication, has security features such as anonymity and untraceability, can resist various network attacks such as replay attacks and impersonation attacks, and has the ability to resist physical attacks on grid intelligent devices.
[0042] The following will further elaborate on the present invention in conjunction with the accompanying drawings. Description of the Drawings
[0043] Figure 1 is a schematic diagram of an intelligent grid identity authentication system implemented based on physical unclonable functions provided by an embodiment of the present invention;
[0044] Figure 2 It is a schematic diagram of the power grid intelligent device registration process in the embodiments of the present invention;
[0045] Figure 3 It is a schematic diagram of the gateway registration process in the embodiments of the present invention;
[0046] Figure 4 It is a schematic diagram of the identity authentication process in the embodiments of the present invention. Detailed implementation manners
[0047] The following further describes the present invention in detail with reference to specific embodiments, but the implementation manners of the present invention are not limited thereto.
[0048] In order to implement effective identity authentication in the smart grid system, an embodiment of the present invention provides a smart grid identity authentication system implemented based on physical unclonable functions. Refer to Figure 1 As shown, the system includes: a power grid intelligent device, a gateway, and a control center. It can be understood that there is more than one gateway and power grid intelligent device in the actual system.
[0049] Among them, both the power grid intelligent device and the gateway need to be registered in the control center.
[0050] Refer to Figure 2 As shown, the power grid intelligent device registration process includes:
[0051] (1) The power grid intelligent device sends a power grid intelligent device registration request to the control center; the power grid intelligent device registration request carries the identity identifier ID of the power grid intelligent device e ;
[0052] (2) In response to the power grid intelligent device registration request, the control center calculates the first temporary key K e = h(ID e ||MSK), and generates a challenge information sequence {L1, L2,... Ln} for the power grid intelligent device;
[0053] (3) The control center sends K e and the generated challenge information sequence {L1, L2,... Ln} to the power grid intelligent device; where MSK is the master key of the control center;
[0054] (4) After receiving K e and {L1, L2,... Ln} sent by the control center, the power grid intelligent device generates a challenge response pair sequence {(L1, R1), (L2, R2)... (L n , R n )} based on its physical unclonable function;
[0055] (5) The grid intelligent device sends {(L1, R1), (L2, R2) … (L n , R n )} to the control center;
[0056] (6) The control center stores the ID of the grid intelligent device e , K e , {(L1, R1), (L2, R2) … (L n , R n )} to complete the registration of the grid intelligent device.
[0057] In addition, in the above grid intelligent device registration process, the control center is also used to check whether there is already a registered grid intelligent device with the identity identifier ID in the grid intelligent device registration request when receiving the grid intelligent device registration request e ; if not, continue to complete the registration for the grid intelligent device in response to the grid intelligent device registration request, if so, reject the grid intelligent device registration request.
[0058] See Figure 3 shown, the gateway registration process includes:
[0059] (1) The gateway sends a gateway registration request to the control center; the gateway registration request carries the identity identifier ID of the gateway g ;
[0060] (2) The control center responds to the gateway registration request and calculates the second temporary key K g = h(ID g || MSK); stores K g ; where MSK is the master key of the control center;
[0061] (3) The control center sends K g to the gateway;
[0062] (4) The gateway stores the K sent by the control center g for backup.
[0063] In addition, in this gateway registration process, when receiving the gateway registration request, the control center can also check whether there is already a registered gateway with the identity identifier ID in the gateway registration request g ; if not, continue to complete the registration for the gateway in response to the gateway registration request, if so, reject the gateway registration request.
[0064] After the grid intelligent device and the gateway are registered in the control center, they can perform identity authentication in the system.
[0065] See Figure 4As shown in the figure, the identity authentication process in the embodiment of the present invention includes:
[0066] (1) The power grid intelligent device sends the first message Msg1 to the gateway.
[0067] Among them, Msg1 = {S1, S2, L i}, S1 = ID e ⊕(r1||r2), S2 = h(ID e ||ID g ||K e ||r1||r2); L i is the challenge information, L i belongs to the challenge information sequence {L1, L2,... L n}, n≥2; the challenge information sequence is generated by the control center during the registration process of the power grid intelligent device and sent to the power grid intelligent device; ID e is the identity identifier of the power grid intelligent device, ID g is the identity identifier of the gateway; K e is the first temporary key calculated by the control center during the registration process of the power grid intelligent device and sent to the power grid intelligent device; r1 and r2 are two random numbers selected by the power grid intelligent device; h() represents the hash operation, || represents the character concatenation operation, and ⊕ represents the exclusive OR operation.
[0068] (2) After receiving Msg1, the gateway generates the second message Msg2 based on Msg1 and sends it to the control center.
[0069] Among them, Msg2 = {S1, S2, L i , ID g , G1, G2}, G1 = K g ⊕(r3||r4||LI g ), G2 = h(ID g ||K g ||r3||r4); K g is the second temporary key calculated by the control center during the registration process of the gateway and sent to the gateway; r3 and r4 are two random numbers selected by the gateway; LI g is the location identifier of the gateway;
[0070] (3) After receiving Msg2, the control center extracts S1, S2, L i , ID g , G1 and G2 from Msg2; determines the corresponding ID i and the challenge response pair (L e , R i , R i ) according to L e ⊕S1 and extracts the calculation result IDe Extract r1 and r2 from ⊕S1 = (r1||r2); calculate S2’ = h(ID e ||ID g ||K e ||r1||r2). If S2’ = S2, then authenticate the grid intelligent device; calculate G1⊕K g and extract r3 and r4 from the calculation result G1⊕K g = (r3||r4||LI g ). Calculate G2’ = h(ID g ||K g ||r3||r4). If G2’ = G2, then authenticate the gateway; calculate the shared key SK = h(ID g ||r1||r3||r5), calculate C1 = r3⊕(r1||r5), C2 = r2⊕(r3||r5||L i ), C3 = h(ID g ||K g ||r4||SK), C4 = h(ID e ||K e ||r2||R i ||SK); generate the third message Msg3, Msg3 = {C1, C2, C3, C4}.
[0071] Among them, R i is the response of the grid intelligent device based on its physical unclonable function to L i . (L i , R i ) belongs to the challenge-response pair sequence {(L1, R1), (L2, R2)…(L n , R n ), and {(L1, R1), (L2, R2)…(L n , R n )} is sent by the grid intelligent device to the control center during the grid intelligent device registration process;
[0072] (4) The control center sends the third message Msg3 to the gateway.
[0073] (5) After receiving Msg3, the gateway calculates r3⊕C1, extracts r1 and r5 from the calculation result r3⊕C1 = (r1||r5), and calculates the shared key SK = h(ID g ||r1|r3||r5); calculate C3’ = h(ID g ||K g ||r4||SK). If C3’ = C3, then authenticate the control center.
[0074] (6) The gateway sends the fourth message Msg4 = {C2, C4} to the grid intelligent device.
[0075] (7) After receiving Msg4, the grid intelligent device calculates r2 ⊕ C2, extracts r3 and r5 from the calculation result r2 ⊕ C2 = (r3||r5||L i ), and calculates the shared key SK = h(ID g ||r1||r3||r5); calculates R i ’ ← PUF i (L i ), and calculates C4’ = h(ID e ||K e ||r2||R i ’||SK). If C4’ = C4, the authentication to the control center is passed.
[0076] Wherein, PUF i () represents the physical unclonable function, and R i ’ represents the response re - made by the grid intelligent device based on its physical unclonable function to L i .
[0077] In one embodiment, in step (3) of the authentication process, the control center can also extract LI from the calculation result G1 ⊕ K g = (r3||r4||LI g ), so as to determine the location of the gateway by using LI g . g
[0078] So far, the identity authentication process is completed, and the grid intelligent device, the gateway, and the control center can perform data transmission based on the shared key SK.
[0079] In one embodiment, the grid intelligent device is also used to trigger the restart of the grid intelligent device registration process when L i has finished fetching C n .
[0080] Exemplarily, n can be equal to 5. That is, after the grid intelligent device has performed 5 - time identity authentication according to the above - mentioned grid intelligent device registration process, the grid intelligent device restarts the registration process, obtains a new challenge information sequence from the control center, and correspondingly generates a new {(L1, R1), (L2, R2)…(L n , R n )} and sends it to the control center, and the control center correspondingly updates the {(L1, R1), (L2, R2)…(L n , R n )} stored for the grid intelligent device.
[0081] It should be noted that n = 5 is only an example and does not limit the embodiments of the present invention. In practice, it can be flexibly configured according to the processing capabilities of grid intelligent devices.
[0082] In one embodiment, in the above identity authentication process, the control center is further configured to delete (L n , R n ) after sending the third message Msg3 to the gateway; correspondingly, the grid intelligent device deletes L i ’ ← PUF i (L i ) and then deletes L i .
[0083] That is to say, both the grid intelligent device and the control center discard each used (L i , R i ). In this way, when an attacker wants to carry out a network attack by replaying the message Msg2 (assuming it contains L3), the control center has already discarded the used (L3, R3). Therefore, the authentication of the attacker will fail, effectively resisting the replay attack.
[0084] The intelligent grid identity authentication system implemented based on the physical unclonable function provided by the embodiments of the present invention has the following beneficial effects:
[0085] (1) In the embodiments of the present invention, the grid intelligent device, the control center, and the gateway only need to perform lightweight hash operations, exclusive OR operations, and character splicing operations, etc. Among them, the grid intelligent device performs three hash operations, the gateway performs three hash operations, and the control center performs seven hash operations. Therefore, compared with the commonly used public key encryption in the existing authentication mechanism, the computational overhead for implementing identity authentication in the embodiments of the present invention is very low, solving the problem that devices such as sensors and smart meters cannot participate in identity authentication due to insufficient computing power.
[0086] (2) In the embodiments of the present invention, a physical unclonable function is deployed in the grid intelligent device. If an attempt is made to tamper with or damage the memory of the grid intelligent device, the response R i of the grid intelligent device will change, resulting in an unexpected output during the authentication process, and thus the authentication fails. In addition, even if the grid intelligent device is stolen, an opponent cannot capture its PUF from the grid intelligent device. Therefore, it can resist cloning and physical attacks. In addition, the use of the physical unclonable function makes the grid intelligent device free from the problem of key leakage.
[0087] (3) The embodiments of the present invention achieve end-to-end mutual authentication between the grid intelligent device and the control center, and between the gateway and the control center. Among them, the grid intelligent device shares a secret {ID e, <Li, R i >, K e , r2}, and the secret key SK to complete the authentication of the control center. The gateway uses the secret {K g , r4} and the secret key SK shared with the control center to complete the authentication of the control center. The control center uses the secret {ID e , K e} shared with the sensor and the random numbers {r1, r2} generated by the sensor to complete the authentication of the sensor. The control center uses the secret {K g} shared with the gateway and the random numbers {r3, r4} generated by the gateway to complete the authentication of the gateway.
[0088] (4) Provide a secure session key and forward secrecy: The grid intelligent device, the gateway, and the control center will negotiate a session key SK for subsequent secure communication. The session key is calculated based on the random number provided by the grid intelligent device, the random number provided by the gateway, and the random number provided by the control center. Therefore, no third party can obtain the session key in advance, ensuring the security of the session key. Compared with the existing authentication mechanism where an attacker can calculate the session key using public parameters, the session key in the embodiments of the present invention cannot be obtained by any third party, so forward secrecy can be provided.
[0089] (5) Resist replay attacks: If an attempt is made to initiate a replay attack when the gateway sends the second message Msg2 to the control center, it is impossible to succeed. This is because the grid intelligent device uses a new challenge message Li each time it initiates authentication, and the control center also determines the identity ID of the grid intelligent device based on the new challenge message Li e . Moreover, after each authentication is completed, both the grid intelligent device and the control center will discard the used challenge message Li and the challenge response message R i . Therefore, if an opponent replays the message Msg2, the authentication will fail because the Li in the replayed Msg2 is old.
[0090] (6) The grid intelligent device participating in the authentication in the embodiments of the present invention has anonymity. The grid intelligent device sends its true identity identifier ID e to the control center through a secure channel during its registration phase. Subsequently, during the entire authentication process, it does not transmit its true identity, but instead uses random numbers and XOR operations to mask the identity identifier of the grid intelligent device. An attacker cannot obtain the true identity of the grid intelligent device, and user behavior cannot be traced, achieving privacy protection for the grid intelligent device. In the subsequent authentication and key negotiation protocol, the control center determines the true identity of the grid intelligent device through Li. Therefore, the embodiments of the present invention can not only protect the true identity of the sensor, but also achieve untraceability of user behavior.
[0091] In summary, the embodiment of the present invention realizes lightweight authentication in the smart grid system, can achieve end-to-end mutual authentication, has security features such as anonymity and untraceability, can resist various network attacks such as replay attacks and impersonation attacks, and has the ability to resist physical attacks on grid intelligent devices.
[0092] It should be noted that the terms "first", "second", etc. are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described here can be implemented in an order other than those illustrated or described here. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure.
[0093] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0094] Although the present application has been described in conjunction with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other changes of the disclosed embodiments by viewing the accompanying drawings and the disclosure content. In the description of the present invention, the term "including" does not exclude other components or steps, the term "a" or "one" does not exclude a plurality of cases, and the meaning of "a plurality" is two or more unless otherwise specifically defined. In addition, certain measures are described in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0095] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited only to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. An intelligent power grid identity authentication system implemented based on physical unclonable functions, characterized in that, Including: Grid intelligent devices, gateways, and control centers; among them, A smart grid device for sending a first message Msg1 to a gateway; where Msg1 = {S1, S2, L i}, S2 = h(ID e || ID g || K e || r1 || r2); L i is a challenge message, and L i belongs to the challenge message sequence {L1, L2, … L n}, n ≥ 2; the challenge message sequence is generated by the control center during the registration process of the smart grid device and sent to the smart grid device; ID e is the identity identifier of the smart grid device, and ID g is the identity identifier of the gateway; K e is the first temporary key calculated by the control center during the registration process of the smart grid device and sent to the smart grid device; r1 and r2 are two random numbers selected by the smart grid device; h() represents a hash operation, || represents a character concatenation operation, represents an exclusive - or operation; A gateway, which is used to generate a second message Msg2 based on Msg1 and send it to the control center after receiving Msg1; where Msg2 = {S1, S2, L i , ID g , G1, G2}, G2 = h(ID g || K g || r3 || r4); K g is the second temporary key calculated and sent to the gateway by the control center during the gateway registration process; r3 and r4 are two random numbers selected by the gateway; LI g is the location identifier of the gateway; The control center is used to extract S1, S2, and L from Msg2 after receiving Msg2. i 、ID g , G1 and G2; according to L i Determine the corresponding ID e and challenge response pair (L i ,R i ), where R i It is the smart device of the power grid based on its physical unclonable function to L i The response made, (L i ,R i ) belongs to the challenge-response pair sequence {(L1,R1),(L2,R2)…(L n ,R n )},{(L1,R1),(L2,R2)…(L n ,R n )} is sent by the power grid smart device to the control center during the power grid smart device registration process; The control center is also used to calculate and extract r1 and r2 from the calculation result ; calculate S2’ = h(ID e ||ID g ||K e ||r1||r2), if S2’ = S2, then authenticate the grid intelligent device; is also used to calculate and extract r3 and r4 from the calculation result ; calculate G2’ = h(ID g ||K g ||r3||r4), if G2’ = G2, then authenticate the gateway; The control center is also used to calculate the shared key SK = h(ID g ||r1||r3||r5), and send the third message Msg3 to the gateway; where Msg3 = {C1, C2, C3, C4}, C3 = h(ID g ||K g ||r4||SK), C4 = h(ID e ||K e ||r2||R i ||SK); The gateway is also used to calculate r3⊕C1 after receiving Msg3, extract r1 and r5 from the calculation result and calculate the shared key SK = h(ID g ||r1|r3||r5); calculate C3’ = h(ID g ||K g ||r4||SK), if C3’ = C3, then pass the authentication of the control center; send the fourth message Msg4 = {C2, C4} to the power grid intelligent device; The smart grid device is also used to calculate after receiving Msg4 Extract r3 and r5 from the calculation result and calculate the shared key SK = h(ID g ||r1||r3||r5); Calculate R i ’ ← PUF i (L i ), and calculate C4’ = h(ID e ||K e ||r2||R i ’||SK). If C4’ = C4, the authentication of the control center is passed; where PUF i() represents the physical unclonable function, and R i ’ represents the response re - made by the smart grid device based on its physical unclonable function to L i . The grid intelligent devices, gateways, and control centers perform data transmission based on the shared key SK.
2. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 1, characterized in that The control center is also used to extract LI from the calculation result and use LI g to determine the location of the gateway. g 3. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 1, characterized in that, In the registration process of the grid intelligent device, A power grid intelligent device is used to send a registration request of the power grid intelligent device to a control center; the identity identifier ID of the power grid intelligent device is carried in the registration request of the power grid intelligent device e ; A control center, which is configured to calculate the first temporary key K in response to the grid intelligent device registration request e = h(ID e || MSK), and generate the challenge information sequence {L1, L2, … L n} for the grid intelligent device; send K e and the generated challenge information sequence {L1, L2, … L n} to the grid intelligent device; where MSK is the master key of the control center; The power grid intelligent device is also used to generate the challenge response pair sequence {(L1, R1), (L2, R2),... (L n} after receiving Ke and the challenge information sequence {L1, L2,... L n , R n )} sent by the control center and send it to the control center; The control center is also used to store the IDs of the smart grid devices e , K e , {(L1, R1), (L2, R2)…(L n , R n )} to complete the registration of the smart grid devices.
4. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 3, wherein In the registration process of the grid intelligent device, The control center is also used to check whether there is already a registered grid intelligent device with the identity ID in the grid intelligent device registration request when receiving the grid intelligent device registration request e ; if not, continue to complete the registration for the grid intelligent device in response to the grid intelligent device registration request, and if so, reject the grid intelligent device registration request.
5. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 1, wherein, In the gateway registration process, The gateway is used to send a gateway registration request to the control center; The gateway registration request carries the identity identifier ID of the gateway g ; A control center, which is configured to calculate the second temporary key K in response to the gateway registration request, where K g = h(ID g ||MSK); store K g and send K g to the gateway; where MSK is the master key of the control center. The gateway is also used to store K sent by the control center g Standby 6. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 5, characterized in that In the gateway registration process, The control center is further configured to, when receiving the gateway registration request, check whether there is already a registered gateway with the identity ID in the gateway registration request g ; if not, continue to complete the registration for the gateway in response to the gateway registration request, and if so, reject the gateway registration request.
7. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 1 or 3, characterized in that The power grid intelligent device is also used when L i has finished fetching C n to trigger the restart of the registration process of the power grid intelligent device.
8. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 7, characterized in that, n=5。 9. The intelligent power grid identity authentication system implemented based on physical unclonable functions according to claim 1 or 3, characterized in that The power grid intelligent device is also used for calculating R i ’ ← PUF i (L i ) and then deleting L i ; The control center is also used to delete (L n ,R n ) after sending the third message Msg3 to the gateway.