Data protection method, system, device and storage medium
Through identification cryptographic algorithm and digital signature technology, the power consumption data generated by intelligent air opening and micro-disconnection is encrypted, which solves the security problems of power consumption data and control instructions, and improves security and efficiency.
Patent Information
- Application Number
- CN202311162609.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-08
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2043-09-08
AI Technical Summary
In the prior art, the power consumption data generated by intelligent air opening and/or micro-disconnection poses security risks in the data collection, transmission and storage process, and traditional identity authentication methods have security loopholes, which cannot effectively protect the security of power consumption sensitive data and control instructions.
The identification password algorithm (such as SM9) is used to encrypt the power consumption data, and a key is generated through the identity authentication information of the user side, the control instructions are encrypted, and the data transmission security is ensured in combination with digital signature technology.
It realizes the secure encrypted transmission of power consumption data and control instructions, saves the cost of issuing digital certificates, improves communication efficiency, prevents data tampering, and enhances security.
Smart Images

Figure CN117294477B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data encryption technology, and in particular to a data protection method, system, device and storage medium. Background Art
[0002] The existing data generated by smart circuit breakers and / or micro-circuits is not protected, which poses a serious security risk in large-scale, centralized network use. Smart circuit breakers and / or micro-circuits have data collection capabilities, but during the data collection, transmission, and storage processes, power-sensitive data is at risk of being stolen. Furthermore, the control instructions issued by the user-side management platform based on power-sensitive data are vulnerable to network attacks and illegal hijacking.
[0003] Traditional methods of data protection typically rely on traditional identity authentication, typically using a simple username and password. Devices or users use default or weak passwords, making it difficult to avoid database collision attacks, dictionary attacks, and other security vulnerabilities. For example, zombie viruses exploit weak password vulnerabilities to launch attacks. Therefore, symmetric cryptographic machine technology and a key system that combines symmetric and asymmetric algorithms have been introduced to enhance security. However, in symmetric solutions, encryption and decryption use the same key. This approach presents challenges such as key leakage by internal personnel, easy cracking of weak encryption, and difficulty in key distribution and updating. Furthermore, this combined symmetric and asymmetric key system increases the complexity and maintenance costs of digital certificate management. Furthermore, when performing identity authentication and key negotiation between devices, both parties must first exchange digital certificates, reducing communication efficiency. Furthermore, the certificates must be stored locally, consuming storage resources.
[0004] Therefore, there is an urgent need for a data protection method to solve the technical problem of security of power consumption data and control instructions in the existing technology. Summary of the Invention
[0005] The main purpose of the present invention is to provide a data protection method, system, device and storage medium, aiming to solve the technical problem of the security of electricity usage data and control instructions in the prior art.
[0006] To achieve the above object, the present invention provides a data protection method, which includes the following steps:
[0007] Obtaining power consumption data and first identification information generated by the circuit breaker and / or micro-breaker;
[0008] encrypting the electricity usage data according to the first identification information based on an identification cryptographic algorithm, and transmitting the encrypted electricity usage data to a user terminal, so that the user terminal generates a control instruction according to the electricity usage data;
[0009] The identity authentication information of the user terminal is obtained, and a key is sent to the user terminal based on the identity authentication information, where the key is used to encrypt the control instruction to obtain a control instruction ciphertext.
[0010] Optionally, after the step of encrypting the electricity usage data according to the first identification information based on an identification cryptographic algorithm and transmitting the encrypted electricity usage data to the user end, the method further includes:
[0011] Receiving user identification private key application information sent by the user terminal;
[0012] Reviewing the identification information corresponding to the user terminal according to the user identification private key application information to obtain a review result;
[0013] Determining whether the user terminal has access authority based on the audit result;
[0014] If the user has the access permission, a private key for decrypting the ciphertext of the electricity consumption data is generated based on the identification information;
[0015] The private key is sent to the user terminal, so that the user terminal decrypts the electricity usage data ciphertext according to the private key to obtain the electricity usage data.
[0016] Optionally, after the step of determining whether the user terminal has access authority according to the audit result, the method further includes:
[0017] If the user terminal does not have the access authority, a prompt message is sent to the user terminal asking whether to apply for the access authority.
[0018] Optionally, the step of encrypting the electricity usage data according to the first identification information based on an identification cryptographic algorithm and transmitting the encrypted electricity usage data to the user terminal includes:
[0019] According to the first identification information, encrypt the electricity usage data using the identification cryptographic algorithm SM9 to obtain a ciphertext of the electricity usage data;
[0020] When receiving the data request instruction sent by the user terminal, the encrypted electricity usage data is sent to the user terminal.
[0021] Optionally, after the step of obtaining the identity authentication information of the user terminal and sending the key to the user terminal based on the identity authentication information, the method further includes:
[0022] Obtain the control instruction ciphertext, and perform signature verification on the control instruction ciphertext based on digital signature technology to obtain a signature result;
[0023] The signature result is sent to a target terminal device, so that the target terminal device decrypts the control instruction ciphertext in the signature result.
[0024] Optionally, before the step of sending the signature result to a target terminal device so that the target terminal device decrypts the control instruction ciphertext in the signature result, the method further includes:
[0025] Establishing a communication connection with a target terminal device and performing identity authentication on the target terminal device;
[0026] If the target terminal device passes the identity authentication, generating a corresponding decryption private key based on the identification information of the target terminal device;
[0027] The decryption private key is sent to the target terminal device, so that the target terminal device decrypts the control instruction ciphertext to obtain the control instruction.
[0028] Optionally, the step of establishing a communication connection with a target terminal device and performing identity authentication on the target terminal device includes:
[0029] By establishing a communication connection with the target terminal device and sending a random challenge message to the target terminal device;
[0030] Receive a response value generated by the target terminal according to the random challenge information, and perform identity authentication on the target terminal device according to the response value.
[0031] In addition, to achieve the above-mentioned purpose, the present invention further provides a data protection system, which includes:
[0032] A data acquisition module, configured to acquire power consumption data and first identification information generated by a circuit breaker and / or a micro-breaker;
[0033] a data encryption module, configured to encrypt the power usage data according to the first identification information based on an identification cryptographic algorithm, and transmit the encrypted power usage data to a user terminal, so that the user terminal generates a control instruction according to the power usage data;
[0034] The information authentication module is used to obtain the identity authentication information of the user terminal and send a key to the user terminal based on the identity authentication information, wherein the key is used to encrypt the control instruction to obtain a control instruction ciphertext.
[0035] In addition, to achieve the above objectives, the present invention also proposes a data protection device, which includes: a memory, a processor, and a data protection program stored on the memory and executable on the processor, wherein the data protection program is configured to implement the steps of the data protection method described above.
[0036] In addition, to achieve the above-mentioned purpose, the present invention further proposes a storage medium, on which a data protection program is stored. When the data protection program is executed by a processor, the steps of the data protection method described above are implemented.
[0037] The present invention obtains the power consumption data and first identification information generated by the circuit breaker and / or micro-breaker; based on the identification cryptographic algorithm, encrypts the power consumption data according to the first identification information, and transmits the ciphertext of the power consumption data to the user end, so that the user end generates a control instruction according to the power consumption data; obtains the identity authentication information of the user end, and sends a key to the user end based on the identity authentication information, and the key is used to encrypt the control instruction to obtain the ciphertext of the control instruction. Since the present invention encrypts the power consumption data according to the first identification information, transmits the ciphertext of the power consumption data to the user end, and encrypts the control instruction generated by the user end with a key, compared to the existing technology, the present invention encrypts the power consumption data generated by the circuit breaker and / or micro-breaker and the control instruction generated by the user end according to the power consumption data, so that the power consumption data and the control instruction are transmitted in ciphertext, effectively ensuring the security of the power consumption data and the control instruction, and encrypting according to the identification information saves the cost of issuing digital certificates. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is a structural diagram of a data protection device in a hardware operating environment involved in an embodiment of the present invention;
[0039] Figure 2 This is a flow chart of a first embodiment of a data protection method according to the present invention;
[0040] Figure 3 This is a flow chart of a second embodiment of the data protection method of the present invention;
[0041] Figure 4 Schematic diagram of the flow of the third embodiment of the data protection method of the present invention;
[0042] Figure 5 This is a structural block diagram of the data protection system of the present invention.
[0043] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0044] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0045] Reference Figure 1 , Figure 1It is a structural diagram of a data protection device in a hardware operating environment involved in an embodiment of the present invention.
[0046] like Figure 1 As shown, the data protection device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the user interface 1003 may optionally include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk storage. The memory 1005 may optionally be a storage device independent of the aforementioned processor 1001.
[0047] Those skilled in the art will understand that Figure 1 The structure shown in the figure does not constitute a limitation on the data protection device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0048] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating system, a network communication module, a user interface module and a data protection program.
[0049] exist Figure 1 In the data protection device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the data protection device of the present invention can be set in the data protection device, and the data protection device calls the data protection program stored in the memory 1005 through the processor 1001, and executes the data protection method provided by the embodiment of the present invention.
[0050] The embodiment of the present invention provides a data protection method, referring to Figure 2 , Figure 2 Schematic diagram of the flow of the first embodiment of the data protection method of the present invention.
[0051] In this embodiment, the data protection method includes the following steps:
[0052] Step S10: Obtain power consumption data and first identification information generated by the circuit breaker and / or micro-breaker.
[0053] It should be noted that the execution subject of this embodiment may be a computing service device with data processing, network communication, and program execution functions, such as a server, tablet computer, personal computer, mobile phone, etc., or an electronic device or data protection device capable of implementing the above functions. The following uses a data protection device as an example to illustrate this embodiment and the following embodiments.
[0054] It needs to be explained that the above-mentioned circuit breaker can be an intelligent circuit breaker, also known as an intelligent circuit breaker, which is a new upgraded product that integrates traditional circuit breakers with modern scientific and technological means. It is used to monitor power supply and protect the power grid system. When the load of the grid system is continuously overloaded within a set time, a tripping command is issued, and the mechanical actuator of the circuit breaker immediately cuts off the power supply to protect the power grid system.
[0055] Smart micro-circuit breakers, also known as intelligent miniature circuit breakers, are used in low-voltage power distribution networks in indoor buildings and similar locations, including industrial, commercial, and civil construction, as well as infrastructure. These intelligent circuit breakers, used in conjunction with intelligent gateways, provide real-time monitoring of key electrical parameters of power lines, such as voltage, current, power, temperature, leakage, and energy consumption. They offer remote control, early warning protection, short-circuit protection, energy metering, and fault location.
[0056] It needs to be explained that since sensitive information exists in electricity consumption data, it is necessary to ensure the security of electricity consumption data. However, the existing technology does not involve the security protection of electricity consumption data generated by smart circuit breakers / micro-breakers. Therefore, there are serious security risks in large-scale, centralized network use.
[0057] In solutions based on symmetric algorithms, encryption and decryption use the same key. This approach presents problems such as key leakage by internal personnel, easy cracking of low-strength encryption, and difficulty in key distribution and updating. Compared to symmetric algorithms, the PKI (Public Key Infrastructure) key system allows users to generate their own keys, ensuring key security and uniqueness. However, this approach requires applying for and pre-setting the device's own device certificate before the device is released and used. During interaction with the outside world, identity authentication, asymmetric encryption signatures, and other processes are completed through certificates. This not only increases the complexity and maintenance cost of digital certificate management, but also requires both parties to exchange digital certificates first when performing identity authentication and key negotiation between devices, reducing communication efficiency. In addition, the certificates must be stored locally, occupying storage resources.
[0058] Therefore, this solution adopts an identification cryptographic algorithm to encrypt electricity consumption data, and uses the device identification as the public key, which saves the cost of issuing digital certificates and facilitates the interaction between endpoints.
[0059] It is easy to understand that the first identification information may be a unique identification of the smart circuit breaker / smart micro-breaker that generates the power consumption data, such as a hardware identification number, a device ID, etc.
[0060] Step S20: Based on the identification cryptographic algorithm, encrypt the electricity usage data according to the first identification information, and transmit the encrypted electricity usage data to the user terminal, so that the user terminal generates a control instruction according to the electricity usage data.
[0061] It should be noted that the above-mentioned identification algorithm uses the SM9 standard algorithm to implement identity authentication and key agreement protocol, and also supports the SM2 algorithm, supports IEEE's EC-SRP5 password authentication and key agreement protocol, and combines the national secret SM3 and SM4 algorithms to implement data encryption transmission and consistency protection, so that the solution can adapt to the corresponding key management requirements of various scenarios.
[0062] In a specific implementation, according to the first identification information, the electricity usage data is encrypted by the identification cryptographic algorithm SM9 to obtain the electricity usage data ciphertext; when the data request instruction sent by the user end is received, the electricity usage data ciphertext is sent to the user end.
[0063] It should be noted that the above-mentioned user terminal may be a management platform with data processing, network communication and program running functions.
[0064] It's easy to understand that encrypting user data using the SM9 identification cipher algorithm before transmitting it to the user effectively ensures the security of electricity usage data during transmission. The identification information corresponding to the target user is the decryption private key corresponding to the ciphertext of the electricity usage data. Therefore, encryption and decryption based on device identification not only reduces the cost of issuing digital certificates, facilitates interaction between endpoints, and improves communication efficiency.
[0065] Furthermore, after the encrypted electricity usage data is transmitted to the user end, the user end decrypts it based on the device identification information to obtain the corresponding electricity usage data, and then generates corresponding control instructions based on the electricity usage data.
[0066] It should be explained that the above control instructions can be a set of machine instructions with special meanings and operating functions, and power dispatch can be adjusted through control instructions, or they can be other adjustment and control instructions. This embodiment does not limit this.
[0067] Step S30: Acquire the identity authentication information of the user terminal, and send a key to the user terminal based on the identity authentication information, wherein the key is used to encrypt the control instruction to obtain a control instruction ciphertext.
[0068] It should be noted that, in order to ensure the security of the control instructions during transmission, the control instructions may be encrypted at the user end and then sent to the target terminal device.
[0069] It should be explained that the above-mentioned identity authentication information can be a unique identifier that the user can directly use, such as the user's login account, mobile phone number, etc.
[0070] After confirming the user's identity authentication information, a key is sent to the user based on the identity authentication information. The key can be generated based on the identity authentication information using the identification cryptographic algorithm SM9, or it can be generated based on the identity authentication information using other encryption algorithms, which is not limited in this embodiment.
[0071] This embodiment obtains the power consumption data and first identification information generated by the circuit breaker and / or micro-breaker; based on the identification cryptographic algorithm, encrypts the power consumption data according to the first identification information, and transmits the ciphertext of the power consumption data to the user end, so that the user end generates a control instruction according to the power consumption data; obtains the identity authentication information of the user end, and sends a key to the user end based on the identity authentication information, and the key is used to encrypt the control instruction to obtain the ciphertext of the control instruction. Since the present invention encrypts the power consumption data according to the first identification information, transmits the ciphertext of the power consumption data to the user end, and encrypts the control instruction generated by the user end with a key, compared to the prior art, the present invention encrypts the power consumption data generated by the circuit breaker and / or micro-breaker and the control instruction generated by the user end according to the power consumption data, so that the power consumption data and the control instruction are transmitted in ciphertext, effectively ensuring the security of the power consumption data and the control instruction, and encrypting according to the identification information saves the cost of issuing digital certificates and improves communication efficiency.
[0072] refer to Figure 3 , Figure 3 FIG. 4 is a flow chart of a second embodiment of a data protection method according to the present invention.
[0073] Based on the first embodiment above, in this embodiment, after step S20, the following steps are further included:
[0074] Step S201: receiving user identification private key application information sent by the user terminal.
[0075] It should be noted that when the above-mentioned user terminal receives the electricity usage data ciphertext, in order to obtain the corresponding decryption private key to decrypt the electricity usage data ciphertext and obtain the electricity usage data, it is necessary to determine whether the user terminal is the target user terminal with the electricity usage data viewing permission.
[0076] Step S202: review the identification information corresponding to the user terminal according to the user identification private key application information to obtain a review result.
[0077] Step S203: Determine whether the user terminal has access authority based on the audit result.
[0078] It is easy to understand that the above-mentioned user identification private key application information includes the identification information of the above-mentioned user terminal. The identification information can be the user terminal device ID, the hardware identification number of the device, or other identification that can uniquely identify the user terminal. This implementation does not impose any restrictions on this.
[0079] Step S204: If the user has the access permission, a private key for decrypting the ciphertext of the electricity consumption data is generated according to the identification information.
[0080] It should be noted that, if the user terminal does not have the access authority, a prompt message is sent to the user terminal asking whether to apply for the access authority.
[0081] Step S205: Send the private key to the user terminal, so that the user terminal decrypts the electricity usage data ciphertext according to the private key to obtain the electricity usage data.
[0082] This embodiment obtains the electricity consumption data and first identification information generated by the circuit breaker and / or micro-breaker; based on the identification cryptographic algorithm, encrypts the electricity consumption data according to the first identification information, and transmits the ciphertext of the electricity consumption data to the user end; receives the user identification private key application information sent by the user end; reviews the identification information corresponding to the user end according to the user identification private key application information to obtain the review result; determines whether the user end has the review permission according to the review result; if it has the review permission, generates a private key for decrypting the ciphertext of the electricity consumption data based on the identification information; sends the private key to the user end, so that the user end decrypts the ciphertext of the electricity consumption data according to the private key to obtain the electricity consumption data. Compared with the existing technology, the present invention encrypts the electricity consumption data generated by the circuit breaker and / or micro-breaker through the identification cryptographic algorithm SM9 and then transmits the data to the user end. Then, the private key for decrypting the ciphertext of the electricity consumption data is generated according to the identification information corresponding to the user end in the user identification private key application information sent by the user end, which effectively ensures the security of the electricity consumption data, encrypts and decrypts according to the identification information, saves the cost of issuing digital certificates, and improves communication efficiency.
[0083] refer to Figure 4 , Figure 4 FIG. 4 is a flow chart of a third embodiment of a data protection method according to the present invention.
[0084] Based on the above embodiments, in this embodiment, after step S30, the following steps are further included:
[0085] Step S301: Obtain the control instruction ciphertext, and perform signature verification on the control instruction ciphertext based on digital signature technology to obtain a signature result.
[0086] It should be explained that the use of digital signature technology can effectively prevent the above-mentioned control instruction ciphertext from being tampered with, and the signature of the encrypted data can be verified to ensure that the data has not been tampered with.
[0087] Step S302: Send the signature result to a target terminal device, so that the target terminal device decrypts the control instruction ciphertext in the signature result.
[0088] It should be noted that, in order to ensure the security of the control instruction, before the target terminal decrypts the control instruction ciphertext, it also includes: establishing a communication connection with the target terminal device and performing identity authentication on the target terminal device; if the target terminal device passes the identity authentication, generating a corresponding decryption private key based on the identification information of the target terminal device; sending the decryption private key to the target terminal device, so that the target terminal device decrypts the control instruction ciphertext to obtain the control instruction.
[0089] Furthermore, in order to authenticate the target terminal device and ensure the security of the control instructions, a communication connection can be established with the target terminal device, and a random challenge message can be sent to the target terminal device; a response value generated by the target terminal based on the random challenge message can be received, and the target terminal device can be authenticated based on the response value.
[0090] It should be noted that the random challenge information may be a randomly generated identity authentication question related to the device ID of the target terminal device. The response value generated by the target terminal based on the random challenge information may be an answer generated based on the device ID of the target terminal device. The target terminal device is authenticated using the answer.
[0091] This embodiment obtains the power consumption data and first identification information generated by the circuit breaker and / or micro-breaker; based on the identification cryptographic algorithm, encrypts the power consumption data according to the first identification information, and transmits the ciphertext of the power consumption data to the user end, so that the user end generates a control instruction according to the power consumption data; obtains the identity authentication information of the user end, and sends a key to the user end based on the identity authentication information; obtains the control instruction ciphertext, and verifies the signature of the control instruction ciphertext based on the digital signature technology to obtain a signature result; establishes a communication connection with the target terminal device, and authenticates the target terminal device; if the target terminal device passes the identity authentication, generates a corresponding decryption private key based on the identification information of the target terminal device; sends the decryption private key to the target terminal device, so that the target terminal device decrypts the control instruction ciphertext to obtain the control instruction; sends the signature result to the target terminal device, so that the target terminal device decrypts the control instruction ciphertext in the signature result. Compared with the existing technology, the present invention can effectively prevent the above-mentioned control instruction ciphertext from being tampered with by using digital signature technology, and perform signature verification on the encrypted data to ensure that the data has not been tampered with. It establishes a communication connection with the target terminal device and sends a random challenge information to the target terminal device; receives the response value generated by the target terminal according to the random challenge information, and authenticates the target terminal device according to the response value to ensure the security of control instruction transmission.
[0092] In addition, an embodiment of the present invention further provides a storage medium, on which a data protection program is stored. When the data protection program is executed by a processor, the steps of the data protection method described above are implemented.
[0093] Reference Figure 5 , Figure 5 This is a structural block diagram of the data protection system of the present invention.
[0094] like Figure 5 As shown, the data protection system proposed in the embodiment of the present invention includes: a data acquisition module 501, a data encryption module 502 and an information authentication module 503.
[0095] The data acquisition module 501 is used to acquire power consumption data and first identification information generated by the circuit breaker and / or the micro-breaker.
[0096] The data encryption module 502 is used to encrypt the power usage data according to the first identification information based on an identification cryptographic algorithm, and transmit the encrypted power usage data to the user end, so that the user end generates a control instruction based on the power usage data.
[0097] The information authentication module 503 is used to obtain the identity authentication information of the user terminal and send a key to the user terminal based on the identity authentication information. The key is used to encrypt the control instruction to obtain a control instruction ciphertext.
[0098] This system obtains the power consumption data and first identification information generated by the circuit breaker and / or micro-breaker; based on the identification cryptographic algorithm, encrypts the power consumption data according to the first identification information, and transmits the ciphertext of the power consumption data to the user end, so that the user end generates a control instruction according to the power consumption data; obtains the identity authentication information of the user end, and sends a key to the user end based on the identity authentication information, and the key is used to encrypt the control instruction to obtain the ciphertext of the control instruction. Since the present invention encrypts the power consumption data according to the first identification information, transmits the ciphertext of the power consumption data to the user end, and encrypts the control instruction generated by the user end with a key, compared to the existing technology, the present invention encrypts the power consumption data generated by the circuit breaker and / or micro-breaker and the control instruction generated by the user end according to the power consumption data, so that the power consumption data and control instructions are transmitted in ciphertext, effectively ensuring the security of the power consumption data and control instructions, and encrypting according to the identification information saves the cost of issuing digital certificates and improves communication efficiency.
[0099] Based on the above-mentioned first embodiment of the data protection system of the present invention, a second embodiment of the data protection system of the present invention is proposed.
[0100] In this embodiment, the data encryption module 502 is also used to receive user identification private key application information sent by the user terminal; review the identification information corresponding to the user terminal according to the user identification private key application information to obtain a review result; determine whether the user terminal has the review permission based on the review result; if it has the review permission, generate a private key for decrypting the electricity usage data ciphertext based on the identification information; send the private key to the user terminal, so that the user terminal decrypts the electricity usage data ciphertext according to the private key to obtain the electricity usage data.
[0101] The data encryption module 502 is further configured to send a prompt message to the user terminal asking whether to apply for access permission if the user terminal does not have access permission.
[0102] Other embodiments or specific implementations of the data protection system of the present invention can refer to the above-mentioned method embodiments and will not be repeated here.
[0103] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.
[0104] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0105] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0106] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A data protection method, characterized in that: The method comprises the following steps: Obtaining power consumption data and first identification information generated by the circuit breaker and / or micro-breaker; encrypting the electricity usage data according to the first identification information based on an identification cryptographic algorithm, and transmitting the encrypted electricity usage data to a user terminal, so that the user terminal generates a control instruction according to the electricity usage data; Obtaining identity authentication information of the user terminal, and sending a key to the user terminal based on the identity authentication information, wherein the key is used to encrypt the control instruction to obtain a control instruction ciphertext; After the step of encrypting the electricity usage data according to the first identification information based on the identification cryptographic algorithm and transmitting the encrypted electricity usage data to the user end, the method further includes: Receiving user identification private key application information sent by the user terminal; Reviewing the identification information corresponding to the user terminal according to the user identification private key application information to obtain a review result; Determining whether the user terminal has access authority based on the audit result; If the user has the access permission, a private key for decrypting the ciphertext of the electricity consumption data is generated based on the identification information; Sending the private key to the user terminal, so that the user terminal decrypts the ciphertext of the electricity usage data according to the private key to obtain the electricity usage data; After the step of obtaining the identity authentication information of the user terminal and sending the key to the user terminal based on the identity authentication information, the method further includes: Obtain the control instruction ciphertext, and perform signature verification on the control instruction ciphertext based on digital signature technology to obtain a signature result; Sending the signature result to a target terminal device so that the target terminal device decrypts the control instruction ciphertext in the signature result; Before the step of sending the signature result to the target terminal device so that the target terminal device decrypts the control instruction ciphertext in the signature result, the method further includes: Establishing a communication connection with a target terminal device and performing identity authentication on the target terminal device; If the target terminal device passes the identity authentication, generating a corresponding decryption private key based on the identification information of the target terminal device; The decryption private key is sent to the target terminal device, so that the target terminal device decrypts the control instruction ciphertext to obtain the control instruction.
2. The data protection method according to claim 1, wherein: After the step of determining whether the user terminal has the access permission according to the audit result, the method further includes: If the user terminal does not have the access authority, a prompt message is sent to the user terminal asking whether to apply for the access authority.
3. The data protection method according to claim 1, wherein: The step of encrypting the electricity usage data according to the first identification information based on the identification cryptographic algorithm and transmitting the encrypted electricity usage data to the user end includes: According to the first identification information, encrypt the electricity usage data using the identification cryptographic algorithm SM9 to obtain a ciphertext of the electricity usage data; When receiving the data request instruction sent by the user terminal, the encrypted electricity usage data is sent to the user terminal.
4. The data protection method according to claim 1, wherein: The step of establishing a communication connection with the target terminal device and performing identity authentication on the target terminal device includes: By establishing a communication connection with the target terminal device and sending a random challenge message to the target terminal device; Receive a response value generated by the target terminal according to the random challenge information, and perform identity authentication on the target terminal device according to the response value.
5. A data protection system, characterized in that: The system comprises: A data acquisition module, configured to acquire power consumption data and first identification information generated by a circuit breaker and / or a micro-breaker; a data encryption module, configured to encrypt the power usage data according to the first identification information based on an identification cryptographic algorithm, and transmit the encrypted power usage data to a user terminal, so that the user terminal generates a control instruction according to the power usage data; An information authentication module, configured to obtain the identity authentication information of the user terminal and send a key to the user terminal based on the identity authentication information, wherein the key is used to encrypt the control instruction to obtain a control instruction ciphertext; The data encryption module is configured to receive user identification private key application information sent by the user terminal; review the identification information corresponding to the user terminal based on the user identification private key application information to obtain a review result; determine whether the user terminal has access authority based on the review result; if the user terminal has access authority, generate a private key for decrypting the ciphertext of the electricity usage data based on the identification information; and send the private key to the user terminal so that the user terminal decrypts the ciphertext of the electricity usage data based on the private key to obtain the electricity usage data; The information authentication module is further configured to obtain the control instruction ciphertext, perform signature verification on the control instruction ciphertext based on digital signature technology, and obtain a signature result; and send the signature result to the target terminal device so that the target terminal device decrypts the control instruction ciphertext in the signature result; The information authentication module is further used to establish a communication connection with the target terminal device and perform identity authentication on the target terminal device; if the target terminal device passes the identity authentication, a corresponding decryption private key is generated based on the identification information of the target terminal device; the decryption private key is sent to the target terminal device so that the target terminal device decrypts the control instruction ciphertext to obtain the control instruction.
6. A data protection device, characterized in that: The device includes: a memory, a processor, and a data protection program stored in the memory and executable on the processor, wherein the data protection program is configured to implement the steps of the data protection method according to any one of claims 1 to 4.
7. A storage medium, characterized in that: The storage medium stores a data protection program, which, when executed by a processor, implements the steps of the data protection method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Internet of Things safety management system
CN110784491A
Internet of Things terminal data management and control system
CN114389879A
Internet of Things identity authentication method and device and Internet of Things equipment
CN115276998A
Equipment operation and maintenance deployment method and system for encrypting Bluetooth communication based on SM2 cryptographic algorithm
CN116094946A