Distributed power distribution terminal identity authentication method and device based on blockchain technology

CN117793713BActive Publication Date: 2026-08-11STATE GRID HEBEI ELECTRIC POWER RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0007]本发明实施例提供了一种基于区块链技术的分布式配电终端身份认证方法及装置,以解决按照目前的区块链技术进行配电终端身份认证时,配电终端的算力以便难以达到共识机制所需的算力的问题

Benefits of technology

[0046]本发明实施例提供一种基于区块链的分布式配电终端身份认证方法及装置,通过先将两个变电站之间的馈线上的各个配电终端作为主节点建立区块链网络,然后按照预设规则根据各个主节点的属性信息对各个主节点进行共识,确定当前有效节点之后的下一有效节点,从而无需基于复杂的工作量证明方式对各个主节点进行共识,进而减少对作为主节点的各个配电终端的算力要求。在此基础上,通过有效节点在区块链网络上写入或修改业务身份信息和业务关键配置信息,并根据区块链网络上的各个主节点的业务身份信息和业务关键配置信息,验证接收的业务数据对应的源主节点是否对应合法接收身份信息和/或发送的业务数据对应的目标主节点是否对应合法发送身份信息,可以利用区块链技术去中心化、不可篡改等特点,只允许通过认证的有效节点写入或修改业务身份信息和业务关键配置信息,从而防止配电终端因伪终端攻击或交互信息被篡改而造成开关误动,大大提高配电终端的信息防护水平,进而提高供电可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117793713B_ABST
    Figure CN117793713B_ABST
Patent Text Reader

Abstract

This invention provides a distributed power distribution terminal identity authentication method and device based on blockchain technology, belonging to the field of power distribution terminal security protection. The method includes: establishing a blockchain network with each power distribution terminal on a feeder between two substations as master nodes; achieving consensus among master nodes based on their attribute information according to preset rules to determine valid nodes; writing or modifying business identity information and key business configuration information on the blockchain network through valid nodes; and verifying whether the source master node corresponding to the received business data corresponds to legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to legitimate sending identity information based on the business identity information and key business configuration information of each master node. This invention can prevent the tampering of business identity information and key business configuration information based on blockchain technology and reduce the computing power requirements of the consensus mechanism on the power distribution terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power distribution terminal security protection technology, and in particular to a distributed power distribution terminal identity authentication method and device based on blockchain technology. Background Technology

[0002] Improved relay protection and self-healing control in distribution networks are key technologies for enhancing power supply reliability. Existing centralized and conventional local feeder automation systems, while capable of fault isolation and self-healing, fall short of requirements due to long isolation times and frequent outages. Intelligent distributed distribution protection and self-healing control systems, based on direct peer-to-peer exchange of real-time data between intelligent terminals (including relay protection devices), enable autonomous judgment, decision-making, and collaborative operation. This allows for rapid fault isolation and reduced outage time, representing the future development direction for distribution network protection and control in central urban areas.

[0003] With the widespread application of 5G technology, distribution network technicians have attempted to apply it to intelligent distributed distribution network protection, achieving good results. The future distribution network will inevitably be a true distribution Internet of Things (IoT) based on high-speed communication, where various distribution terminals communicate with each other. However, intelligent distributed feeder automation or differential protection based on 5G wireless communication currently uses proprietary protocols from various manufacturers, such as the R-GOOSE protocol. These protocols typically transmit data in plaintext, resulting in low security and extremely high risks. Compared to fiber optic intelligent distributed distribution network protection, from a security perspective, relying on wireless communication for horizontal information transmission between distribution terminals is more vulnerable to network security attacks, such as creating fake terminals, intercepting messages, and tampering with messages.

[0004] The existing identity authentication system relies solely on communication between the power distribution terminal's built-in encryption chip and the main station's security gateway and encryption machine to achieve identity authentication and information encryption. This system is highly centralized, and there are currently no requirements for horizontal authentication and encryption mechanisms between power distribution terminals. Because intelligent distributed distribution network protection systems directly trip the distribution network switches, if fault signals are intercepted and tampered with, or if individual power distribution terminals are compromised, it will cause widespread tripping of power distribution terminal devices within the area, resulting in erroneous protection tripping and power outages. This severely affects power supply reliability and may even cause serious social impacts.

[0005] Blockchain, as an emerging transaction technology, employs a decentralized ledger approach, recording the interaction information of each transaction participant in a chain structure and securely storing transaction information in blocks. The entire transaction information utilizes modern cryptographic algorithms to ensure its integrity, immutability, and non-repudiation, effectively solving challenges such as the large number of participants and transaction security in power distribution networks. However, the consensus mechanism of blockchain technology typically uses proof-of-work, which consumes significant computing resources, a requirement that is generally difficult for distributed power distribution terminals to meet.

[0006] For example, Chinese patent CN202010795733.4, published on November 13, 2020, describes a blockchain-based anti-tampering technology for power distribution terminals. Although the power distribution control center performs a backup storage of the node identity authentication information and data authentication information of the target task, and broadcasts it to each power distribution terminal authentication node for a second backup storage, so as to record the anti-tampering of the target task on the power distribution terminal authentication node, it does not consider the requirements of the consensus mechanism on the computing power of the power distribution terminal when the power distribution control center and each power distribution terminal form a blockchain. Summary of the Invention

[0007] This invention provides a distributed power distribution terminal identity authentication method and apparatus based on blockchain technology to solve the problem that the computing power of the power distribution terminal is insufficient to meet the computing power required for the consensus mechanism when performing power distribution terminal identity authentication using current blockchain technology.

[0008] In a first aspect, embodiments of the present invention provide a blockchain-based distributed power distribution terminal identity authentication method, comprising:

[0009] Establish a blockchain network by using each power distribution terminal on the feeder between the two substations as the master node;

[0010] According to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node.

[0011] The effective nodes write or modify business identity information and key business configuration information on the blockchain network. The business identity information is the identity information of each master node regarding the target business, and the key business configuration information represents the legitimate receiving identity information and legitimate sending identity information of the target business.

[0012] Based on the business identity information and key business configuration information of each master node, verify whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information.

[0013] In one possible implementation, the attribute information of each master node includes the first-time information of each master node accessing the blockchain network;

[0014] The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes:

[0015] Based on the first time information corresponding to each master node, the master node corresponding to the first time information that is incremented or decremented relative to the current valid node is determined as the next valid node after the current valid node.

[0016] In one possible implementation, the attribute information of each master node includes second time information of the last time each master node wrote or modified the business identity information and the business key configuration information;

[0017] The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes:

[0018] Based on the second time information corresponding to each master node, the master node corresponding to the earliest time information in each of the second time information is determined as the next valid node after the current valid node.

[0019] In one possible implementation, based on the second time information corresponding to each of the master nodes, the master node corresponding to the earliest time information in each of the second time information is determined as the next valid node after the current valid node, including:

[0020] Each master node, based on the second time information corresponding to each master node, records the master node corresponding to the earliest time information in each of the second time information as the target valid node, and encrypts the target valid node and broadcasts it to other master nodes in the blockchain network;

[0021] Within a preset time period, each master node receives and decrypts the target valid node sent by other master nodes in the blockchain network, and determines whether the number of the same target valid node among the target valid nodes is greater than a set threshold.

[0022] If the number of identical target valid nodes among all the target valid nodes is greater than the set threshold, then the identical target valid nodes among all the target valid nodes are determined as the next valid node after the current valid node;

[0023] If the number of identical target valid nodes among the various target valid nodes is less than or equal to the set threshold, then a consensus failure message is broadcast to the blockchain network.

[0024] In one possible implementation, the attribute information of each master node includes the device number corresponding to each master node;

[0025] The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes:

[0026] Based on the device number corresponding to each master node, the master node corresponding to the device number that increments or decrements relative to the current valid node is determined as the next valid node after the current valid node.

[0027] In one possible implementation, the attribute information of each master node includes the device number of each master node;

[0028] The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes:

[0029] Obtain the total number of all master nodes in the blockchain network, calculate the remainder when the set random number provided by the blockchain network is divided by the total number, and determine the master node corresponding to the device number with the same remainder as the next valid node after the current valid node.

[0030] In one possible implementation, the effective node writes or modifies business identity information and key business configuration information on the blockchain network, including:

[0031] The business applications on each power distribution terminal are connected to the blockchain network as light nodes.

[0032] Based on the write or modify request of the light node, the valid node writes or modifies the business identity information and the key business configuration information on the blockchain network.

[0033] In one possible implementation, based on the write or modify request of the light node, the valid node writes or modifies the business identity information and the key business configuration information on the blockchain network, including:

[0034] Based on the write or modify request of the light node, determine whether the light node has write or modify permissions;

[0035] When the light node has write or modify permissions, it can write or modify the business identity information and the key business configuration information on the blockchain network through the valid node.

[0036] In one possible implementation, based on the business identity information and key business configuration information of each master node, verifying whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information includes:

[0037] When the light node receives or sends business data, it downloads the business identity information and key business configuration information of each master node from the blockchain network.

[0038] Based on the business identity information of each master node, determine the business identity information of the source master node corresponding to the received business data and / or the business identity information of the target master node corresponding to the sent business data, and record them as the business identity information to be verified.

[0039] Verify whether the identity information of the service to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the key configuration information of the service;

[0040] If the identity information to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the business key configuration information, then the source master node and / or target master node corresponding to the identity information to be verified are determined to correspond to the legitimate receiving identity information and / or the legitimate sending identity information.

[0041] Secondly, embodiments of the present invention provide a blockchain-based distributed power distribution terminal identity authentication device, comprising:

[0042] The blockchain establishment module is used to establish a blockchain network by using each power distribution terminal on the feeder between two substations as the master node.

[0043] The consensus module is used to reach a consensus among the master nodes according to the attribute information of each master node based on preset rules, and to determine the next valid node after the current valid node.

[0044] The processing module is used to write or modify business identity information and business key configuration information on the blockchain network through the valid nodes. The business identity information is the identity information of each master node about the target business, and the business key configuration information represents the legitimate receiving identity information and legitimate sending identity information of the target business.

[0045] The authentication module is used to verify, based on the business identity information and the business key configuration information of each master node, whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information.

[0046] This invention provides a blockchain-based distributed power distribution terminal identity authentication method and apparatus. First, a blockchain network is established by treating each power distribution terminal on the feeder between two substations as master nodes. Then, consensus is reached among the master nodes according to preset rules based on their attribute information to determine the next valid node after the current valid node. This eliminates the need for complex proof-of-work methods to reach consensus among the master nodes, thus reducing the computational power requirements on each power distribution terminal acting as a master node. Furthermore, valid nodes write or modify business identity information and key business configuration information on the blockchain network. Based on the business identity information and key business configuration information of each master node on the blockchain network, the source master node corresponding to the received business data is verified to have legitimate receiving identity information, and / or the target master node corresponding to the sent business data is verified to have legitimate sending identity information. Leveraging the decentralized and immutable characteristics of blockchain technology, only authenticated valid nodes are allowed to write or modify business identity information and key business configuration information. This prevents power distribution terminals from malfunctioning due to fake terminal attacks or tampering of interactive information, significantly improving the information protection level of the power distribution terminals and thus enhancing power supply reliability. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 This is a flowchart illustrating the implementation of the blockchain-based distributed power distribution terminal identity authentication method provided in this embodiment of the invention.

[0049] Figure 2 This is an application scenario diagram of the blockchain-based distributed power distribution terminal identity authentication method provided in the embodiments of the present invention;

[0050] Figure 3 This is a schematic diagram of the structure of a blockchain network provided in an embodiment of the present invention;

[0051] Figure 4 This is a schematic diagram of the structure of a blockchain-based distributed power distribution terminal identity authentication device provided in an embodiment of the present invention. Detailed Implementation

[0052] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of the invention. However, those skilled in the art will understand that the invention can be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods are omitted so as not to obscure the description of the invention with unnecessary detail.

[0053] To make the objectives, technical solutions, and advantages of the present invention clearer, specific embodiments will be described below in conjunction with the accompanying drawings.

[0054] Figure 1 The implementation flowchart of the blockchain-based distributed power distribution terminal identity authentication method provided in the embodiments of the present invention is described in detail below:

[0055] Step 101: Establish a blockchain network by using each power distribution terminal on the feeder between the two substations as the master node.

[0056] In this embodiment, considering that only the distribution terminals on a feeder line have the need for business interaction, the distribution terminals on the feeder line between two substations can be used as master nodes to establish a blockchain network.

[0057] For example, such as Figure 2 As shown, each distribution terminal on each radial or daisy-chain 10KV feeder can be combined into a blockchain network.

[0058] In this network, all power distribution terminals on the feeder between the two substations can be interconnected through wireless communication networks such as 5G to form a blockchain network.

[0059] When each power distribution terminal connects to the blockchain network, it can perform blockchain layer identity authentication based on the SM2 national cryptographic algorithm, etc. After successful authentication, it can connect to the blockchain network.

[0060] After the distribution terminals on the feeder between two substations form a blockchain network, the identity ID information and key parameter configuration information of each distribution terminal can be stored in a distributed database based on the blockchain network. This prevents tampering with the identity ID information and key parameter configuration information of each distribution terminal by fake terminals, which could cause malfunctions in the switches. This improves the information protection level of the distribution terminals and thus enhances the reliability of power supply.

[0061] Step 102: According to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node.

[0062] Combination Figure 3 As shown, the blockchain layer in the power distribution terminal can include various distributed database nodes. Each power distribution terminal, acting as a blockchain master node, can include blockchain security mechanisms, blockchain consensus mechanisms, and blockchain service interfaces. The business layer in the power distribution terminal can act as a light node in the form of a business application, thereby completing tasks such as sending and receiving data based on the business identity ID information and key parameter configuration information of the power distribution terminal stored in the blockchain master node.

[0063] Typically, blockchains use complex proof-of-work methods to determine the valid nodes with the authority to provide blocks and write or modify data through a consensus mechanism. However, the individual distribution terminals on the feeder between two substations usually have low computing power and cannot support complex proof-of-work consensus methods. Therefore, this embodiment uses simple preset rules to achieve consensus based on the attribute information of each master node, thereby reducing the computing power requirements of the distribution terminals when forming a blockchain.

[0064] In the process of the power distribution terminal acting as the master node to reach consensus on each master node according to the attribute information of each master node in accordance with the preset rules, each power distribution terminal can use a dedicated encryption algorithm to encrypt the determined target valid node, and use the corresponding decryption algorithm to decrypt it to obtain the target valid node determined by other power distribution terminals. Thus, based on each target valid node, the next valid node after the current valid node is determined, so that data can be written or modified in the blockchain network based on the next valid node.

[0065] Step 103: Write or modify business identity information and key business configuration information on the blockchain network through valid nodes.

[0066] Among them, business identity information is the identity information of each master node regarding the target business, and business key configuration information represents the legitimate receiving identity information and legitimate sending identity information of the target business.

[0067] Step 104: Based on the business identity information and key business configuration information of each master node, verify whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information.

[0068] For example, the business identity information of each master node may include business frame streams such as APPID and MAC address to characterize the node identity of each master node at the business layer. Business-critical configuration information describes the legitimate receiving and sending identity information of the business based on the business identity information of each master node.

[0069] In this embodiment, firstly, valid nodes write or modify key business configuration information representing the legitimate receiving and sending identity information of the target business, as well as the identity information of each master node regarding the target business, on the blockchain network. Then, based on the legitimate receiving and sending identity information corresponding to the key business configuration information, the legitimacy of the source master node (i.e., source terminal node) corresponding to the received business data and / or the target master node (i.e., target terminal node) corresponding to the sent business data is verified. If the distribution terminal's identity is legitimate, it can interact with other distribution terminals for application information; otherwise, it cannot interact with other distribution terminals for application information.

[0070] This invention establishes a blockchain network by first designating each distribution terminal on the feeder between two substations as master nodes. Then, according to preset rules and the attribute information of each master node, consensus is reached to determine the next valid node after the current valid node. This eliminates the need for complex proof-of-work methods to achieve consensus among master nodes, thus reducing the computational power requirements on each distribution terminal acting as a master node. Furthermore, valid nodes write or modify business identity information and key configuration information on the blockchain network. Based on the business identity information and key configuration information of each master node on the blockchain network, the source master node corresponding to the received business data is verified to have legitimate receiving identity information, and / or the target master node corresponding to the sent business data is verified to have legitimate sending identity information. Leveraging the decentralized and immutable characteristics of blockchain technology, only authenticated valid nodes are allowed to write or modify business identity information and key configuration information. This prevents malfunctions caused by pseudo-terminal attacks or tampering of interactive information, significantly improving the information protection level of distribution terminals and ultimately enhancing power supply reliability.

[0071] In one embodiment, the attribute information of each master node may include the first-time information of each master node accessing the blockchain network.

[0072] Accordingly, according to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node. This may include:

[0073] Based on the first-time information corresponding to each master node, the master node corresponding to the first-time information that is increasing or decreasing relative to the current valid node is determined as the next valid node after the current valid node.

[0074] In this embodiment, after each power distribution terminal master node connects to the blockchain network, to facilitate consensus, valid nodes can be initialized based on the time each master node connects to the blockchain network. That is, if master node A, master node B, and master node C connect to the blockchain network sequentially, master node A can be determined as the valid node first. After master node A provides blocks for writing or modifying business identity information and key business configuration information, master node B and master node C can be determined as the next valid nodes in sequence. Alternatively, master node C can be determined as the valid node first, and then master node B and master node A can be determined as the next valid nodes in sequence. Another option is to determine master node B as the valid node first, and then master node C and master node A, or master node A and master node C, can be determined as the next valid nodes in sequence.

[0075] This embodiment does not limit the specific order of determining the next valid node. It is sufficient to ensure that each master node has the opportunity to be a valid node according to the first-time information corresponding to each master node and the preset rules.

[0076] In one embodiment, the attribute information of each master node may include second time information of the last time each master node wrote or modified business identity information and business key configuration information.

[0077] Accordingly, according to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node. This may include:

[0078] Based on the second time information corresponding to each master node, the master node corresponding to the earliest time information in each second time information is determined as the next valid node after the current valid node.

[0079] In this embodiment, after determining the valid nodes according to the time when the master node accesses the blockchain network during initialization, the time when each master node provides a block to write or modify business identity information and key business configuration information can be recorded in the blockchain network. That is, the second time information corresponding to each master node. Based on the master node corresponding to the earliest time information in each second time information, each master node is sequentially designated as a valid node.

[0080] For example, the second time information corresponding to master node A, master node B, and master node C is time 1, time 2, and time 3, respectively. Since time 1 is the earliest time information, master node A can be determined as a valid node first. After master node A, as a valid node, writes or modifies the business identity information and key business configuration information, the second time information corresponding to master node A can be updated to time 4. At this time, time 2 is the earliest time information, so the corresponding master node B is determined as a valid node, and so on.

[0081] In this embodiment, considering that the consensus mechanism in the blockchain is the core of achieving decentralization, and that the 5G-based Feeder Terminal Unit (FTU) uses an embedded system with relatively weak computing power, a time-based proof-of-work approach is adopted instead of a proof-of-work approach. This involves identifying the feeder terminal with the earliest last block submission time among all feeder terminals in the blockchain network, and using a dedicated encryption algorithm such as the SM3 national cryptographic algorithm to achieve consensus among all feeder terminals, thus enabling the new block to be added to the chain. This approach reduces the computing power requirements of the feeder terminals by using the last block submission time (i.e., second time information) that can be directly obtained from the blockchain network.

[0082] Optionally, based on the second time information corresponding to each master node, the master node corresponding to the earliest time information in each second time information is determined as the next valid node after the current valid node, which may include:

[0083] Each master node, based on the second time information corresponding to each master node, records the master node corresponding to the earliest time information in each second time information as the target valid node, and then encrypts the target valid node and broadcasts it to other master nodes in the blockchain network.

[0084] Within a preset time period, each master node receives and decrypts the target valid nodes sent by other master nodes in the blockchain network, and determines whether the number of identical target valid nodes among the target valid nodes is greater than a set threshold.

[0085] If the number of identical target valid nodes among all target valid nodes is greater than a set threshold, then the identical target valid nodes among all target valid nodes will be determined as the next valid node after the current valid node.

[0086] If the number of identical target valid nodes among all target valid nodes is less than or equal to a set threshold, then a consensus failure message is broadcast to the blockchain network.

[0087] This embodiment describes the specific process of determining the next valid node after the current valid node based on the earliest time information among the second time information corresponding to each master node. First, each master node, based on the preset rule of determining the master node corresponding to the earliest time information among the second time information as the next valid node, identifies the earliest power distribution terminal among all power distribution terminals that last provided a block in the blockchain network, and designates it as node m. Then, node m is packaged into a block, which is then encrypted and broadcast to other master nodes in the blockchain network, completing each master node's vote. If, within the specified valid time, more than a set threshold (e.g., more than half) of the master nodes generate the same vote, the block and vote are packaged together, signed with a private key, and broadcast. All master nodes in the network receive the valid block provided by the valid node and add the valid block to the blockchain network they maintain. If the valid time is exceeded or consensus fails (e.g., no more than half of the master nodes generate the same vote), the block is discarded and consensus failure information is broadcast. Then, the process of finding the earliest power distribution terminal among all the power distribution terminals that last provided a block in the blockchain network and subsequent steps is repeated to begin the next round of consensus and block formation.

[0088] In this embodiment, a dedicated encryption algorithm, such as the SM3 national cryptographic algorithm, is used to enable all power distribution terminals to reach a consensus and recognize the power distribution terminal that last provided a block in the blockchain. This enables the new block to be added to the chain, and the business identity information and key business configuration information of the power distribution terminal are stored based on the new block to ensure that they are tamper-proof.

[0089] In one embodiment, the attribute information of each master node may include the device number corresponding to each master node.

[0090] Accordingly, according to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node. This may include:

[0091] Based on the device number corresponding to each master node, the master node corresponding to the device number that increments or decrements relative to the current valid node is determined as the next valid node after the current valid node.

[0092] In this embodiment, the master node corresponding to the device number that increments or decrements relative to the current valid node can also be determined as the next valid node after the current valid node based on the device number corresponding to each master node. This reduces the computing power requirement of the power distribution terminal by using the directly obtainable device number.

[0093] In one embodiment, the attribute information of each master node may include the device number of each master node.

[0094] Accordingly, according to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node. This may include:

[0095] Obtain the total number of master nodes in the blockchain network, calculate the remainder when the set random number provided by the blockchain network is divided by the total number, and determine the master node corresponding to the device number with the same remainder as the next valid node after the current valid node.

[0096] In this embodiment, in addition to considering determining valid nodes in ascending or descending order of device number, it is also possible to consider determining valid nodes by sampling the remainder of the machine.

[0097] For example, if the total number of master nodes in the blockchain network is 5, and the device numbers corresponding to each master node are 0, 1, 2, 3, and 4 respectively, a random number 18 is obtained from the blockchain network, and the remainder when 18 is divided by 5 is calculated, which is 3. Then, the master node corresponding to device number 3 is determined as a valid node.

[0098] It should be noted that in this embodiment, the total number of all master nodes in the blockchain network, the device number corresponding to each master node, and the random number obtained from the blockchain network are all examples and do not constitute a limitation.

[0099] In one embodiment, the attribute information of each master node may include information on the number of times each master node has been a valid node.

[0100] Accordingly, according to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node. This may include:

[0101] Based on the count information corresponding to each master node, the master node corresponding to the count information with the fewest counts is determined as the next valid node after the current valid node.

[0102] In this embodiment, based on the frequency information corresponding to each master node, the master node corresponding to the minimum frequency information is determined as the next valid node after the current valid node. Thus, based on a simple rule, each master node has an equal chance of being a valid node.

[0103] Optionally, writing or modifying business identity information and key business configuration information on the blockchain network through valid nodes may include:

[0104] Business applications on each power distribution terminal are connected to the blockchain network as light nodes; based on the write or modify requests of the light nodes, business identity information and key business configuration information are written or modified on the blockchain network through valid nodes.

[0105] Combination Figure 3 As shown in this embodiment, after establishing a blockchain network with each distribution terminal on the feeder between two substations as a master node, the business applications on each distribution terminal can be connected to the blockchain network as light nodes. Then, based on the write or modify requests of the light nodes, the valid nodes write or modify the business identity information and key business configuration information on the blockchain network. In subsequent business interaction scenarios such as receiving or sending business data, the source master node corresponding to the received business data and / or the target master node corresponding to the sent business data can be verified based on the business identity information and key business configuration information stored in the blockchain network. This prevents tampering with the business identity information and key business configuration information by fake terminals or interaction information, which could cause malfunctions in the switch, thereby improving the information protection level of the distribution terminal and ultimately improving the reliability of power supply.

[0106] Optionally, based on write or modify requests from light nodes, writing or modifying business identity information and key business configuration information on the blockchain network through valid nodes may include:

[0107] Based on the write or modify request of the light node, determine whether the light node has write or modify permissions; when the light node has write or modify permissions, write or modify business identity information and key business configuration information on the blockchain network through the valid node.

[0108] In this embodiment, to avoid too many light nodes issuing write or modification requests, write or modification permissions can be granted to only a few light nodes. For example, write or modification permissions can be granted only to the power distribution terminals corresponding to major devices such as the main station or server. After a light node issues a write or modification request, it is first determined whether the light node has write or modification permissions. When a light node has write or modification permissions, it can write or modify business identity information and key business configuration information on the blockchain network through a valid node. Other master nodes besides the valid node verify the written or modified business identity information and key business configuration information. If the verification passes, the written or modified business identity information and key business configuration information can be stored on the blockchain network and saved through various distributed database nodes. If the verification fails, the corresponding information can be discarded.

[0109] Optionally, based on the business identity information and key business configuration information of each master node, verifying whether the source master node corresponding to the received business data corresponds to legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to legitimate sending identity information may include:

[0110] When a light node receives or sends business data, it downloads the business identity information and key business configuration information of each master node from the blockchain network.

[0111] Based on the business identity information of each master node, determine the business identity information of the source master node corresponding to the received business data and / or the business identity information of the target master node corresponding to the sent business data, and record them as the business identity information to be verified.

[0112] Verify whether the identity information of the business to be verified belongs to the legitimate receiving identity information and / or legitimate sending identity information in the business's key configuration information.

[0113] If the identity information to be verified belongs to the legitimate receiving identity information and / or legitimate sending identity information in the business key configuration information, then the source master node and / or target master node corresponding to the identity information to be verified are determined to be the legitimate receiving identity information and / or legitimate sending identity information.

[0114] This embodiment illustrates the process by which each power distribution terminal's business application, acting as a light node, accesses content in a distributed database:

[0115] In this approach, the business layer application app of each power distribution terminal is regarded as a light node in the blockchain network. This node does not need to store the transaction data of the entire blockchain network, but only needs to download and verify the necessary data.

[0116] First, the business layer app can act as a light node, providing its identity verification and sending an access request to the blockchain network. After successful identity verification, the business layer app, as a light node, accesses the content in the distributed database node. If identity verification fails, a warning is issued to the requesting business layer app node indicating it lacks permission to access the data, and the access request is then sent to the blockchain network for storage.

[0117] In this context, the business layer app acts as a light node to access the content in the distributed database node. In other words, the business layer app, as a light node, downloads the key business configuration information in the blockchain network. The business layer app on the power distribution terminal sends and receives business data by comparing the list of legitimate identities (i.e., legitimate receiving identity information and legitimate sending identity information) in the key business configuration information. Only data frames with legitimate identities are processed, meaning that data interaction is only performed with the power distribution terminal master node that has been authenticated in the blockchain network.

[0118] For example, the business layer app on the power distribution terminal can send business data such as equipment electrical quantity information to other legitimate power distribution terminals, or obtain business data such as equipment electrical quantity information from other legitimate power distribution terminals, in order to achieve rapid fault isolation. For instance, it can send or obtain information such as the overcurrent protection values ​​of stages I, II, and III, forward blocking values, and reverse blocking values ​​of the power distribution terminal to other legitimate power distribution terminals, in order to achieve rapid fault isolation.

[0119] For example, the business data sent or received by the business layer app can be determined based on a preset model description file; this example does not limit this.

[0120] This embodiment leverages the decentralized and immutable characteristics of blockchain technology, applying it to the field of power distribution terminal security. Power distribution terminals are added to the blockchain network as master nodes. Simple, pre-defined rules, such as proof-of-time, are used to determine the valid nodes providing blocks. A relative proof-of-work approach reduces the computational power requirements of the power distribution terminals, improving the effective applicability of blockchain technology. Furthermore, valid nodes store business identity information and key configuration information in the blockchain network, ensuring that the business identity information corresponding to each power distribution terminal cannot be tampered with. This enhances the self-defense capabilities of the power distribution terminals, preventing malfunctions caused by fake terminal attacks or tampered interaction information, significantly improving the information protection level of the power distribution terminals. Based on the characteristic that lower communication latency for sending and receiving GOOSE data frames in the power distribution terminal leads to faster fault isolation, business applications, acting as light nodes, access key configuration information in the blockchain network. This allows subsequent processing only on legitimate business data, increasing the verification speed of each data frame, achieving rapid fault isolation, and improving work efficiency.

[0121] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0122] The following are device embodiments of the present invention. For details not described in detail, please refer to the corresponding method embodiments described above.

[0123] Figure 4 The diagram illustrates the structure of a blockchain-based distributed power distribution terminal identity authentication device according to an embodiment of the present invention. For ease of explanation, only the parts relevant to the embodiment of the present invention are shown, and are described in detail below:

[0124] like Figure 4 As shown, the blockchain-based distributed power distribution terminal identity authentication device includes: a blockchain establishment module 41, a consensus module 42, a processing module 43, and an authentication module 44.

[0125] Blockchain establishment module 41 is used to establish a blockchain network by using each power distribution terminal on the feeder between the two substations as the master node.

[0126] The consensus module 42 is used to reach a consensus on each of the master nodes according to the attribute information of each master node according to preset rules, and to determine the next valid node after the current valid node.

[0127] Processing module 43 is used to write or modify business identity information and business key configuration information on the blockchain network through the effective node. The business identity information is the identity information of each master node about the target business, and the business key configuration information represents the legitimate receiving identity information and legitimate sending identity information of the target business.

[0128] The authentication module 44 is used to verify, based on the business identity information and the business key configuration information of each master node, whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information.

[0129] This invention establishes a blockchain network by first designating each distribution terminal on the feeder between two substations as master nodes. Then, according to preset rules and the attribute information of each master node, consensus is reached to determine the next valid node after the current valid node. This eliminates the need for complex proof-of-work methods to achieve consensus among master nodes, thus reducing the computational power requirements on each distribution terminal acting as a master node. Furthermore, valid nodes write or modify business identity information and key configuration information on the blockchain network. Based on the business identity information and key configuration information of each master node on the blockchain network, the source master node corresponding to the received business data is verified to have legitimate receiving identity information, and / or the target master node corresponding to the sent business data is verified to have legitimate sending identity information. Leveraging the decentralized and immutable characteristics of blockchain technology, only authenticated valid nodes are allowed to write or modify business identity information and key configuration information. This prevents malfunctions caused by pseudo-terminal attacks or tampering of interactive information, significantly improving the information protection level of distribution terminals and ultimately enhancing power supply reliability.

[0130] In one possible implementation, the attribute information of each master node includes the first time information of each master node accessing the blockchain network; the consensus module 42 can be used to determine the master node corresponding to the first time information that is incremented or decremented relative to the current valid node as the next valid node after the current valid node, based on the first time information corresponding to each master node.

[0131] In one possible implementation, the attribute information of each master node includes second time information of the last time the master node wrote or modified the business identity information and the business key configuration information; the consensus module 42 can be used to determine the master node corresponding to the earliest time information in each of the second time information as the next valid node after the current valid node, based on the second time information corresponding to each master node.

[0132] In one possible implementation, the consensus module 42 can be used for each master node to record the master node corresponding to the earliest time information in each of the second time information as the target valid node according to the second time information corresponding to each master node, and to encrypt the target valid node and broadcast it to other master nodes in the blockchain network.

[0133] Within a preset time period, each master node receives and decrypts the target valid node sent by other master nodes in the blockchain network, and determines whether the number of the same target valid node among the target valid nodes is greater than a set threshold.

[0134] If the number of identical target valid nodes among all the target valid nodes is greater than the set threshold, then the identical target valid nodes among all the target valid nodes are determined as the next valid node after the current valid node;

[0135] If the number of identical target valid nodes among the various target valid nodes is less than or equal to the set threshold, then a consensus failure message is broadcast to the blockchain network.

[0136] In one possible implementation, the attribute information of each master node includes the device number corresponding to each master node; the consensus module 42 can be used to determine the master node corresponding to the device number that increments or decrements the device number relative to the current valid node as the next valid node after the current valid node, based on the device number corresponding to each master node.

[0137] In one possible implementation, the attribute information of each master node includes the device number of each master node; the consensus module 42 can be used to obtain the total number of all master nodes in the blockchain network, calculate the remainder when the set random number provided by the blockchain network is divided by the total number, and determine the master node corresponding to the device number with the same remainder as the next valid node after the current valid node.

[0138] In one possible implementation, the processing module 43 can be used to connect the business applications on each power distribution terminal as light nodes to the blockchain network.

[0139] Based on the write or modify request of the light node, the valid node writes or modifies the business identity information and the key business configuration information on the blockchain network.

[0140] In one possible implementation, the processing module 43 can be used to determine whether the light node has write or modify permissions based on the write or modify request of the light node.

[0141] When the light node has write or modify permissions, it can write or modify the business identity information and the key business configuration information on the blockchain network through the valid node.

[0142] In one possible implementation, the authentication module 44 can be used to download the business identity information and the key business configuration information of each master node from the blockchain network when the light node receives or sends business data.

[0143] Based on the business identity information of each master node, determine the business identity information of the source master node corresponding to the received business data and / or the business identity information of the target master node corresponding to the sent business data, and record them as the business identity information to be verified.

[0144] Verify whether the identity information of the service to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the key configuration information of the service;

[0145] If the identity information to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the business key configuration information, then the source master node and / or target master node corresponding to the identity information to be verified are determined to correspond to the legitimate receiving identity information and / or the legitimate sending identity information.

[0146] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0147] Those skilled in the art will recognize that the templates, units, and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0148] If the module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the above embodiments of the blockchain-based distributed power distribution terminal identity authentication method. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory, a random access memory, an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.

[0149] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A distributed power distribution terminal identity authentication method based on blockchain technology, characterized in that, include: Establish a blockchain network by using each power distribution terminal on the feeder between the two substations as the master node; According to preset rules, consensus is reached among the master nodes based on their attribute information to determine the next valid node after the current valid node. The attribute information of each master node includes the first time information of each master node accessing the blockchain network, the second time information of each master node last writing or modifying the business identity information and the business key configuration information, and / or the device number corresponding to each master node. The next valid node writes or modifies business identity information and business key configuration information on the blockchain network. The business identity information is the identity information of each master node regarding the target business, and the business key configuration information represents the legitimate receiving identity information and legitimate sending identity information of the target business. Based on the business identity information and key business configuration information of each master node, verify whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information; Specifically, writing or modifying business identity information and key business configuration information on the blockchain network through the next valid node includes: The business applications on each power distribution terminal are connected to the blockchain network as light nodes. Based on the write or modify request of the light node, the business identity information and the key business configuration information are written or modified on the blockchain network through the next valid node; Specifically, based on the business identity information and key business configuration information of each master node, verifying whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information includes: When the light node receives or sends business data, it downloads the business identity information and key business configuration information of each master node from the blockchain network. Based on the business identity information of each master node, determine the business identity information of the source master node corresponding to the received business data and / or the business identity information of the target master node corresponding to the sent business data, and record them as the business identity information to be verified. Verify whether the identity information of the service to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the key configuration information of the service; If the identity information to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the business key configuration information, then the source master node and / or target master node corresponding to the identity information to be verified are determined to correspond to the legitimate receiving identity information and / or the legitimate sending identity information.

2. The distributed power distribution terminal identity authentication method based on blockchain technology according to claim 1, characterized in that, The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes: Based on the first time information corresponding to each master node, the master node corresponding to the first time information that is incremented or decremented relative to the current valid node is determined as the next valid node after the current valid node.

3. The distributed power distribution terminal identity authentication method based on blockchain technology according to claim 1, characterized in that, The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes: Based on the second time information corresponding to each master node, the master node corresponding to the earliest time information in each of the second time information is determined as the next valid node after the current valid node.

4. The distributed power distribution terminal identity authentication method based on blockchain technology according to claim 3, characterized in that, Based on the second time information corresponding to each of the master nodes, the master node corresponding to the earliest time information in each of the second time information is determined as the next valid node after the current valid node, including: Each master node, based on the second time information corresponding to each master node, records the master node corresponding to the earliest time information in each of the second time information as the target valid node, and broadcasts the target valid node to other master nodes in the blockchain network; Within a preset time period, each master node receives the target valid nodes sent by other master nodes in the blockchain network, and determines whether the number of the same target valid nodes among the target valid nodes is greater than a set threshold. If the number of identical target valid nodes among all the target valid nodes is greater than the set threshold, then the identical target valid nodes among all the target valid nodes are determined as the next valid node after the current valid node; If the number of identical target valid nodes among the various target valid nodes is less than or equal to the set threshold, then a consensus failure message is broadcast to the blockchain network.

5. The distributed power distribution terminal identity authentication method based on blockchain technology according to claim 1, characterized in that, The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes: Based on the device number corresponding to each master node, the master node corresponding to the device number that increments or decrements relative to the current valid node is determined as the next valid node after the current valid node.

6. The distributed power distribution terminal identity authentication method based on blockchain technology according to claim 1, characterized in that, The step of reaching a consensus among the master nodes according to preset rules based on their attribute information, and determining the next valid node after the current valid node, includes: Obtain the total number of all master nodes in the blockchain network, calculate the remainder when the set random number provided by the blockchain network is divided by the total number, and determine the master node corresponding to the device number with the same remainder as the next valid node after the current valid node.

7. The distributed power distribution terminal identity authentication method based on blockchain technology according to claim 1, characterized in that, Based on the write or modify request of the light node, the next valid node writes or modifies the business identity information and the key business configuration information on the blockchain network, including: Based on the write or modify request of the light node, determine whether the light node has write or modify permissions; When the light node has write or modify permissions, it writes or modifies the business identity information and the key business configuration information on the blockchain network through the next valid node.

8. A distributed power distribution terminal identity authentication device based on blockchain technology, characterized in that, include: The blockchain establishment module is used to establish a blockchain network by using each power distribution terminal on the feeder between two substations as the master node. The consensus module is used to reach a consensus among the master nodes according to preset rules based on the attribute information of each master node, and to determine the next valid node after the current valid node; wherein, the attribute information of each master node includes the first time information of each master node accessing the blockchain network, the second time information of each master node last writing or modifying the business identity information and the business key configuration information, and / or the device number corresponding to each master node; The processing module is used to write or modify business identity information and business key configuration information on the blockchain network through the next valid node. The business identity information is the identity information of each master node about the target business, and the business key configuration information represents the legitimate receiving identity information and legitimate sending identity information of the target business. The authentication module is used to verify, based on the business identity information and the business key configuration information of each master node, whether the source master node corresponding to the received business data corresponds to the legitimate receiving identity information and / or whether the target master node corresponding to the sent business data corresponds to the legitimate sending identity information. Specifically, the processing module is used for: The business applications on each power distribution terminal are connected to the blockchain network as light nodes. Based on the write or modify request of the light node, the business identity information and the key business configuration information are written or modified on the blockchain network through the next valid node; Specifically, the authentication module is used for: When the light node receives or sends business data, it downloads the business identity information and key business configuration information of each master node from the blockchain network. Based on the business identity information of each master node, determine the business identity information of the source master node corresponding to the received business data and / or the business identity information of the target master node corresponding to the sent business data, and record them as the business identity information to be verified. Verify whether the identity information of the service to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the key configuration information of the service; If the identity information to be verified belongs to the legitimate receiving identity information and / or the legitimate sending identity information in the business key configuration information, then the source master node and / or target master node corresponding to the identity information to be verified are determined to correspond to the legitimate receiving identity information and / or the legitimate sending identity information.

Citation Information

Patent Citations

  • Power distribution terminal tamper-proofing technology and system based on blockchain technology

    CN111931248A

  • Power system terminal identity authentication method based on block chain

    CN116389019A