Information Security Protection Method and System for Energy and Power Trading Platform
By adopting zero-knowledge proof, blockchain proof storage and dual homomorphic encryption technology in the energy power trading platform, combined with Shamir secret sharing and BGLS short group signature, the security vulnerabilities and data integrity problems of the energy power trading platform are solved, user privacy protection, transaction legality and data immutability are achieved, and the security and credibility of the system are improved.
Patent Information
- Application Number
- CN202411106429.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-13
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-08-13
AI Technical Summary
The complex network structure of the energy and power trading platform increases the attack surface and potential security vulnerabilities, the data transmission path is complex, the integrity and confidentiality of transaction data are difficult to guarantee, and the reliability and security requirements of identity authentication and access control are not fully met.
Zero-knowledge proof verification is used to obtain user identity pseudonym data, use the distributed alliance chain of blockchain technology for proof storage, and perform dual homomorphic encryption (Paillier semi-homomorphic encryption and BGV full homomorphic encryption), combining the Shamir secret sharing mechanism and the BGLS short group signature algorithm to achieve secure distribution of keys and immutability of data, and fix security vulnerabilities through traceability processing.
Ensure user privacy protection, enhance anonymity, prevent data tampering, improve transaction legality and reliability, realize data immutability and transparency, enhance key security and protection capabilities, and ensure data integrity and credibility.
Smart Images

Figure CN118965399B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to an information security protection method and system for an energy and power trading platform. Background Art
[0002] An energy and power trading platform is a complex system that allows power suppliers and consumers to conduct power trading through a market mechanism. This is an important part of the power market system, and it plays an important role in constructing an effectively competitive market structure and market system, and forming a mechanism in which energy prices are mainly determined by the market. The spot market includes the day-ahead electricity market, the real-time electricity market, etc., which are responsible for the immediate buying and selling of electricity to ensure the real-time balance of the power system. In contrast to the spot market, medium- and long-term trading involves power wholesale trading for multiple years, years, seasons, months, weeks, multiple days, etc. This trading method provides stability and predictability for market participants, helps power enterprises formulate long-term production plans, and provides long-term price expectations for power users. Market participants include power generation enterprises, power grid enterprises, and power users. Power generation enterprises act as suppliers, power grid enterprises are responsible for the transmission and distribution of electricity, and power users participate in market trading according to their own needs.
[0003] However, the information security protection methods of traditional energy and power trading platforms often have the following problems: First, energy and power trading platforms usually involve multiple participants, including power plants, transmission companies, distribution companies, and consumers. This complex network structure makes the data transmission path complex, increasing the attack surface and potential security vulnerabilities. Second, the integrity and confidentiality of transaction data are crucial. Once the data is tampered with or leaked, it will have a serious impact on the fairness of transactions and the interests of participants. Also, ensuring that only authorized users can access the trading platform and related data is an important security requirement. Complex identity authentication and access control mechanisms require a high degree of reliability and security to prevent unauthorized access and data leakage. Summary of the Invention
[0004] Based on this, it is necessary for the present invention to provide an information security protection method and system for an energy and power trading platform to solve at least one of the above technical problems.
[0005] To achieve the above object, an information security protection method for an energy and power trading platform includes the following steps:
[0006] Step S1: Obtain the real identity data of a user, and use the real identity data of the user to perform zero-knowledge proof verification with the energy and power trading platform, so as to obtain the pseudonym data of the user's identity;
[0007] Step S2: Obtain the user's electricity transaction data based on the user identity pseudonym data, conduct transaction conflict detection and arbitration, store the evidence on the distributed consortium chain based on blockchain technology, and perform double homomorphic encryption to generate ciphertext data, where the first homomorphic encryption of the double homomorphic encryption is Paillier semi-homomorphic encryption, and the second homomorphic encryption is BGV full homomorphic encryption;
[0008] Step S3: Share the private key of the Paillier semi-homomorphic encryption to each trusted institution in layers through the Shamir secret sharing mechanism to generate an incomplete key set; use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data;
[0009] Step S4: Verify the ciphertext data according to the group signature data to obtain verification result data; when the verification result data shows successful verification, decrypt the ciphertext data according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, conduct traceability processing and perform vulnerability repair.
[0010] Through zero-knowledge proof verification, the user does not need to disclose real identity information, protecting the user's privacy; by obtaining the user identity pseudonym data, the user can participate anonymously during the transaction process, enhancing the user's anonymity. Through double homomorphic encryption, the user's transaction data is protected during storage and calculation, protecting the user's data privacy; through the detection and arbitration of the user's transaction data, the legality and reliability of the transaction can be ensured, reducing the occurrence of transaction conflicts and providing effective solutions; the distributed consortium chain based on blockchain technology can provide trusted data evidence storage, ensuring the immutability and transparency of transaction data. By sharing the private key to multiple trusted institutions in layers through the Shamir secret sharing mechanism, the security and protection ability of the key are enhanced; using the BGLS short group signature algorithm to sign the ciphertext data can ensure the effectiveness and verifiability of the signature, realizing multi-party collaborative verification. By verifying the group signature data, the integrity and credibility of the ciphertext data can be ensured, effectively preventing data tampering and forgery; when the verification result shows successful verification, use the incomplete key set to decrypt the ciphertext data to obtain plaintext data, providing a basis for subsequent data analysis and application; when the verification result shows failed verification, conduct traceability processing, trace the source of the security vulnerability, and perform repair to improve the security and reliability of the system. In summary, the above steps include privacy protection, anonymity, data privacy protection, transaction conflict detection and arbitration, data evidence storage, key security, group signature mechanism, data integrity and credibility, data decryption, and security vulnerability repair, etc. These effects help protect user privacy, ensure data security, improve transaction reliability, and increase the transparency and credibility of the system.
[0011] Preferably, step S1 includes the following steps:
[0012] Step S11: Obtain the user's real identity data;
[0013] Step S12: Authenticate the authenticity of the user's real identity data through a third-party certification agency, and generate a unique user ID and authentication credential data for the authenticated user's real identity data;
[0014] Step S13: Use the authentication credential data as a commitment to perform identity verification with the energy and power trading platform based on zero-knowledge proof without revealing the unique user ID, thereby obtaining identity verification result data;
[0015] Step S14: After determining that the identity verification result data is valid, generate an anonymous identity identifier for the user, bind it to the unique user ID and store it, thereby obtaining user identity pseudonym data.
[0016] By obtaining the user's real identity data, the present invention can ensure the accuracy and credibility of subsequent verification and authentication processes; by verifying the user's real identity data through a third-party certification agency, the credibility and authority of identity verification are increased; generating a unique user ID can ensure that each user has a unique identifier in the system, facilitating subsequent identity verification and transaction processing. By using zero-knowledge proof, the user does not need to disclose the unique user ID, while ensuring the accuracy of identity verification and protecting the user's privacy; through zero-knowledge proof-based identity verification, the accuracy and credibility of the verification result can be ensured. By generating an anonymous identity identifier, the user can participate in the transaction process anonymously, enhancing the user's anonymity; binding the anonymous identity identifier to the unique user ID and storing it ensures the correlation between the anonymous identity and the real identity, facilitating subsequent data processing and tracking. In summary, the above steps include data accuracy, trusted identity verification, unique user ID generation, privacy protection, identity verification accuracy, anonymity, and data correlation, etc. These effects help to ensure the accuracy of user identity and privacy protection, and achieve trusted identity verification and anonymous transactions in the energy and power trading platform.
[0017] Preferably, step S2 includes the following steps:
[0018] Step S21: Extract the transaction records submitted by the user by the energy and power trading platform according to the user identity pseudonym data, thereby obtaining the user's power trading data, where the user's power trading data includes user pseudonym data, transaction serial number data, grid operator data, user power consumption data, transaction amount data, and transaction time data;
[0019] Step S22: Detect transaction conflicts in the user's power trading data and perform arbitration, thereby obtaining conflict-free transaction data;
[0020] Step S23: Upload the conflict-free transaction data to the distributed consortium chain based on blockchain technology and conduct evidence preservation, so as to generate transaction evidence preservation data;
[0021] Step S24: Use the Paillier semi-homomorphic encryption algorithm to perform the first-level homomorphic encryption on the conflict-free transaction data, so as to obtain semi-homomorphic encrypted ciphertext data;
[0022] Step S25: Use the BGV fully homomorphic encryption algorithm to perform the second-level homomorphic encryption on the semi-homomorphic encrypted ciphertext data, so as to obtain fully homomorphic encrypted ciphertext data;
[0023] Step S26: Bind and package the public key of Paillier semi-homomorphic encryption, the public key of BGV fully homomorphic encryption, and the fully homomorphic encrypted ciphertext data, so as to obtain ciphertext data.
[0024] The present invention ensures the accuracy and integrity of data extraction by extracting user power transaction data according to user identity pseudonym data. By detecting the user power transaction data, potential transaction conflict situations can be discovered in a timely manner to ensure the legality and reliability of transactions; through the arbitration process, transaction conflicts are resolved to ensure the consistency and credibility of transaction data. By uploading transaction data to the distributed consortium chain based on blockchain technology for evidence preservation, the immutability and transparency of transaction data are ensured, and the credibility and traceability of data are improved. Through semi-homomorphic encryption, conflict-free transaction data is encrypted to protect the privacy and confidentiality of transaction data. Through fully homomorphic encryption, the ciphertext data is further encrypted to enhance the security and protection capabilities of the data. By binding and packaging the public key of semi-homomorphic encryption, the public key of fully homomorphic encryption, and the ciphertext data, the integrity and consistency of relevant data are ensured. In summary, the above steps include data extraction accuracy, transaction conflict detection and arbitration, data evidence preservation, data privacy protection, data security, and data integration, etc. These effects help to protect the privacy and security of transaction data, ensure the legality and credibility of transactions, and provide traceable transaction evidence preservation.
[0025] Preferably, step S22 includes the following steps:
[0026] Step S221: Compare the user pseudonym data and the transaction serial number data. When a user initiates two transactions with different serial numbers but exactly the same other fields, it is determined as a transaction double-spending conflict;
[0027] Step S222: Compare the transaction time data and the transaction serial number data. When there is a transaction with an earlier timestamp but a later serial number, or transactions with the same timestamp but different serial numbers, it is determined as a transaction order conflict;
[0028] Step S223: Compare the user's electricity consumption data and transaction amount data. When there is a mismatch between the electricity quantity and the transaction amount, or when the transaction is extracted non-complied with according to the preset validity conditions, it is determined as a transaction validity conflict;
[0029] Step S224: Arbitrarily eliminate any duplicate payment transactions in the user's electricity transaction data with transaction double-payment conflicts, so as to obtain transaction data without duplicate transactions;
[0030] Step S225: Perform serial number adjustment and sorting based on timestamps on the transaction data without duplicate transactions with transaction sequence conflicts, and eliminate transactions with the same timestamp but different serial numbers, so as to obtain transaction data without sequence conflicts;
[0031] Step S226: Eliminate transactions with transaction validity conflicts in the transaction data without sequence conflicts and send an invalid reminder to the user, so as to obtain transaction data without conflicts.
[0032] The present invention can timely detect two transactions initiated by the same user with different serial numbers but exactly the same other fields by comparing the user's pseudonym data and transaction serial number data, avoiding duplicate payments and inconsistent transactions. By comparing the transaction time data and transaction serial number data, it can detect transactions with earlier timestamps but later serial numbers or transactions with the same timestamp but different serial numbers, ensuring the orderliness and consistency of transactions. By comparing the user's electricity consumption data and transaction amount data, it can detect whether the electricity quantity matches the transaction amount, and extract non-complied transactions according to the preset validity conditions, ensuring the validity and compliance of transactions. By eliminating any duplicate payment transactions in the transaction double-payment conflicts, the consistency and accuracy of transaction data are ensured. By performing serial number adjustment and sorting based on timestamps, the transaction data is ensured to be arranged in the correct order, avoiding the situation of transaction sequence conflicts. By eliminating transactions with transaction validity conflicts and sending an invalid reminder to the user, the validity and standardization of transaction data are ensured, enhancing the credibility and compliance of transactions. In summary, the above steps include transaction consistency, transaction orderliness, and transaction validity, etc. These effects help to reduce transaction conflicts, ensure the consistency, orderliness, and validity of transaction data, and improve the accuracy and reliability of transaction processing.
[0033] Preferably, step S23 includes the following steps:
[0034] Step S231: Perform a hash operation on the transaction data without conflicts to generate transaction digital fingerprint data;
[0035] Step S232: Package the transaction digital fingerprint data as a transaction and generate a new transaction data block on the consortium blockchain through a consensus algorithm;
[0036] Step S233: Broadcast the transaction data block to the nodes on the consortium chain through the P2P network and add it to the blockchain, thereby obtaining the updated data of the consortium chain;
[0037] Step S234: Generate the transaction deposit data corresponding to the new transaction data block according to the updated data of the consortium chain.
[0038] Through hash operation, the generated transaction digital fingerprint of the present invention can be used to verify the integrity of the transaction data, ensuring that the data is not tampered with during the transmission and storage processes. Pack the transaction digital fingerprint data into a transaction and generate a new data block on the consortium chain to ensure the consistency and credibility of the transaction data. All consortium chain nodes will reach a consensus and accept the transaction. Broadcast the transaction data block through the P2P network to ensure that all consortium chain nodes can obtain and synchronize the transaction data in a timely manner, realizing the distribution and update of the data. Generate the transaction deposit data corresponding to the new transaction data block according to the updated data of the consortium chain to ensure the immutability and transparency of the transaction data and provide a traceable transaction deposit. In summary, the above steps include data integrity, data consistency, data distribution and synchronization, and data deposit, etc. These effects help to ensure the integrity, consistency and credibility of the transaction data, ensure the security and traceability of the transaction data, and realize the data update and deposit process on the consortium chain.
[0039] Preferably, step S3 includes the following steps:
[0040] Step S31: Split the private key of the Paillier homomorphic encryption into several sub-keys through the threshold sharing technology, thereby obtaining an incomplete key set;
[0041] Step S32: Construct a group consisting of an energy supplier, an energy operator, an energy dispatching center, and user representatives, thereby obtaining a list of group members;
[0042] Step S33: Hierarchically share the incomplete key set to each trusted third-party institution through the Shamir secret sharing mechanism; distribute the incomplete key set to the group members in the list of group members through the trusted third-party institution;
[0043] Step S34: Sign the ciphertext data by a third-party institution using the BGLS short group signature algorithm to obtain the group signature data.
[0044] The present invention divides the private key through threshold sharing technology, which can improve the security of the key. Even if some keys are leaked, the complete private key cannot be restored. Constructing a group and obtaining a list of group members helps to establish a collaborative relationship among various roles in the energy supply chain, promoting information sharing and decision-making cooperation. Through the Shamir secret sharing mechanism, the incomplete key set is hierarchically shared with a trusted third-party institution to ensure the secure management and distribution of keys. At the same time, the incomplete key set is distributed to group members to ensure that group members have the key shares required for decryption. Through the BGLS short group signature algorithm, the ciphertext data can be signed to ensure the integrity and authenticity of the data. The group signature data can be used to verify the source and integrity of the data, ensuring the credibility and immutability of transaction data. In summary, the above steps include key security, organizational collaboration, key management and security, and data signature and verification, etc. These effects help to ensure the security and management of encryption keys, promote collaboration and information sharing among various roles in the energy supply chain, ensure the integrity and credibility of data, and provide a verifiable data source and immutability.
[0045] Preferably, step S4 includes the following steps:
[0046] Step S41: Transmit the group signature data and the ciphertext data to the members in the list of group members;
[0047] Step S42: Perform BGLS signature verification on the ciphertext data according to the group signature data to obtain preliminary verification boolean data;
[0048] Step S43: Extract the signer from the group signature data and judge the legality of the signer's identity information according to the preset white list of trusted institutions to obtain identity verification boolean data;
[0049] Step S44: Extract the timestamp from the group signature data and compare it with the current time to judge whether it exceeds the validity period to obtain timeliness verification boolean data;
[0050] Step S45: Generate verification result data according to the preliminary verification boolean data, the identity verification boolean data, and the timeliness verification boolean data; where when any of the preliminary verification boolean data, the identity verification boolean data, and the timeliness verification boolean data shows False, the verification result data is signature invalid, otherwise the verification result data is signature valid;
[0051] Step S46: If the verification result data shows that the signature is valid, decrypt the ciphertext data according to the incomplete key set to obtain the plaintext data;
[0052] Step S47: If the verification result data shows that the signature is invalid, perform backpropagation-based traceability processing based on the group signature data, ciphertext data, user power transaction data, and transaction evidence data, and perform vulnerability repair.
[0053] The present invention realizes the distribution and sharing of data by transmitting the group signature data and ciphertext data to group members, ensuring that relevant data can reach each member, providing necessary data for subsequent verification and decryption. Through BGLS signature verification, the ciphertext data is verified to ensure the integrity and authenticity of the data, preventing the data from being tampered with or forged during transmission. Through signer extraction and trusted institution white list, the identity of the signer in the group signature data is verified to ensure the legality and credibility of the signer, preventing forged signatures. By extracting the timestamp and comparing it with the current time, it is judged whether the group signature data has exceeded the validity period, ensuring the timeliness of the signature data and preventing the use of expired signature data. The final verification result data is generated based on the boolean data of preliminary verification, identity verification, and timeliness verification, clearly indicating the validity of the signature, providing an accurate result for subsequent operations. When the verification result data shows that the signature is valid, the ciphertext data is decrypted according to the incomplete key set to obtain the original plaintext data, ensuring the readability and availability of the data. When the verification result data shows that the signature is invalid, backpropagation-based traceability processing is performed based on relevant data to trace the reason for the invalid signature and perform corresponding vulnerability repair, improving the security and reliability of the system. In summary, the above steps include data transmission, data integrity verification, identity verification, timeliness verification, signature verification result, data decryption, and security traceability and vulnerability repair, etc. These effects help to ensure the integrity, authenticity, and timeliness of the data, verify the validity of the signature, and perform necessary data decryption and security traceability processing, improving the security and credibility of the system.
[0054] Preferably, step S46 includes the following steps:
[0055] Step S461: When the verification result data shows that the signature is valid, collect incomplete keys according to the group member list to obtain an incomplete key set;
[0056] Step S462: Use the Shamir secret recovery mechanism to reconstruct the Paillier encrypted complete private key from the incomplete key set to obtain the Paillier encrypted complete key;
[0057] Step S463: Use the BGV fully homomorphic encryption key to perform the first decryption on the ciphertext data to obtain the Paillier encrypted data;
[0058] Step S464: Use the Paillier encryption complete key to perform a second decryption on the Paillier encrypted data, thereby obtaining the plaintext data.
[0059] According to the verification result data of the present invention, the signature is valid, indicating that the group members have valid key shares. By collecting the key shares in the group member list, a complete incomplete key set can be restored, providing the necessary key for subsequent decryption. Using the Shamir secret recovery mechanism, a complete Paillier encryption private key can be reconstructed based on the incomplete key set, ensuring the integrity and security of the key and providing the necessary key for subsequent decryption. Using the BGV fully homomorphic encryption key, perform a first decryption on the ciphertext data to convert it into Paillier encrypted data, providing the necessary data preparation for subsequent decryption. Using the Paillier encryption complete key, perform a second decryption on the Paillier encrypted data to restore it to plaintext data, ensuring the readability and availability of the data. In summary, the above steps include key recovery, key integrity and security, data decryption, etc. These effects help to restore a complete key based on the key shares of group members, ensuring the integrity and security of the key. At the same time, perform multiple decryption operations on the ciphertext data to convert it into plaintext data, providing readability and availability.
[0060] Preferably, step S47 includes the following steps:
[0061] Step S471: When the verification result data shows that the signature is invalid, arrange the group signature data, ciphertext data, user power transaction data, and transaction deposit data in the chronological order of the transaction occurrence, thereby forming transaction trace node data;
[0062] Step S472: When the preliminary verification boolean data is False, perform a data consistency check on the transaction trace node data set and mark the inconsistent data nodes, thereby obtaining abnormal node data;
[0063] Step S473: Use the backpropagation mechanism to trace the operation nodes or parties that cause data anomalies for the abnormal node data and conduct an audit, thereby obtaining auxiliary forensics data;
[0064] Step S474: Conduct a root cause analysis based on the auxiliary forensics data and formulate a vulnerability repair plan and measures according to the analysis results;
[0065] Step S475: When the authentication boolean data is False, trace the signer's identity for the group signature data, conduct a risk analysis on each link of the signature permission source and authorization process, and determine the responsible person according to the analysis results;
[0066] Step S476: When the time - effect verification boolean data is False, judge the rationality of the timestamp for the group signature data. If it is reasonable, evaluate the transmission delay to strengthen the management of the signature usage period.
[0067] The present invention arranges the relevant data in the chronological order of transaction occurrence to form transaction trace node data, which is convenient for subsequent data consistency verification and abnormal node tracking. Verify the transaction trace node data set to ensure data consistency, mark the inconsistent data nodes, which helps to identify data anomalies and problems, and provides a basis for subsequent abnormal node tracking and evidence collection. Through the back - propagation mechanism, trace the operation nodes or participants that cause data anomalies, conduct audits, and obtain auxiliary evidence - collection data, which helps to understand the reasons and processes of data anomalies, and provides a basis for subsequent root - cause analysis and vulnerability repair. Conduct root - cause analysis on abnormal nodes based on the auxiliary evidence - collection data, determine the reasons for data anomalies, and formulate corresponding vulnerability repair plans and measures to improve the security and reliability of the system. Trace the signer's identity for the group signature data with the authentication result of False, analyze the risks of each link, and determine the possible responsible persons, which helps to hold accountable and improve the identity authentication mechanism of the system. Judge the rationality of the timestamp for the group signature data with the time - effect verification result of False, evaluate the transmission delay, and strengthen the management of the signature usage period to ensure the timeliness and reliability of the signature data. In summary, the above steps include data sorting, data consistency verification, abnormal node tracking and auditing, root - cause analysis, vulnerability repair, identity tracing and risk analysis, and timestamp rationality judgment and cycle management, etc. These effects help to identify data anomalies and problems, trace the reasons and processes of data anomalies, formulate corresponding vulnerability repair plans and measures, improve the identity authentication mechanism, and strengthen the management of the signature usage period, thereby improving the security, reliability, and credibility of the system.
[0068] The present invention also provides an information security protection system for an energy and power trading platform, which is used for the information security protection method of the above - mentioned energy and power trading platform. The information security protection system for the energy and power trading platform includes:
[0069] A user identity authentication module, which is used to obtain the user's real identity data and use the user's real identity data to perform zero - knowledge proof verification with the energy and power trading platform to obtain the user's identity pseudonym data;
[0070] A transaction data processing module, which is used to obtain the user's power transaction data based on the user's identity pseudonym data, perform transaction conflict detection and arbitration, store the data on a distributed consortium chain based on blockchain technology, and perform double homomorphic encryption to generate ciphertext data, where the first - layer homomorphic encryption of the double homomorphic encryption is Paillier semi - homomorphic encryption, and the second - layer homomorphic encryption is BGV full - homomorphic encryption;
[0071] The key management and signature module is used to hierarchically share the private key of Paillier homomorphic encryption to each trusted institution through the Shamir secret sharing mechanism to generate an incomplete key set; and use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data;
[0072] The ciphertext verification and decryption module is used to verify the ciphertext data according to the group signature data to obtain verification result data; when the verification result data shows successful verification, the ciphertext data is decrypted according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, traceability processing is performed and vulnerability repair is carried out.
[0073] The present invention obtains the real identity data of users and uses zero-knowledge proof to verify with the energy and power trading platform, which can ensure the authenticity of users' identities and privacy protection, and obtain the pseudonym data of users' identities, providing an accurate identity identifier for subsequent transaction data processing. Based on the pseudonym data of users' identities, the power trading data of users is obtained, and the detection and arbitration of transaction conflicts are carried out to ensure the legality and reliability of transactions and avoid potential conflicts and disputes. The transaction data is stored on the distributed consortium chain based on blockchain technology to ensure the immutability and traceability of the transaction data, improving the credibility and security of the transaction data. Double homomorphic encryption, namely Paillier semi-homomorphic encryption and BGV full homomorphic encryption, is used to encrypt the transaction data to protect the privacy and confidentiality of the data, and at the same time realize the calculation and operation in the encrypted state, providing the necessary security support for subsequent group signature and decryption. By sharing the private key of Paillier semi-homomorphic encryption to each trusted institution through the Shamir secret sharing mechanism in layers, an incomplete key set is generated to realize the secure distribution and management of the key, ensuring the confidentiality and reliability of the key. The BGLS short group signature algorithm is used to sign the ciphertext data to obtain the group signature data, realizing the authentication and integrity protection of the data, and ensuring the credibility and traceability of the data in the untrusted environment. The ciphertext data is verified according to the group signature data, and the information of successful verification or failed verification is obtained through the verification result data, ensuring the integrity and credibility of the data and timely discovering potential data anomalies and vulnerabilities. When the verification result data shows successful verification, the ciphertext data is decrypted according to the incomplete key set to obtain the plaintext data, ensuring the readability and availability of the data and providing accurate transaction information. In summary, the above steps include user identity verification and privacy protection, transaction conflict detection and arbitration, storage and anti-tampering, double homomorphic encryption, key management and secure distribution, group signature generation, data verification, and ciphertext decryption, etc. These effects help to ensure the authenticity and privacy protection of users' identities, guarantee the legality and reliability of transactions, improve the credibility and security of data, and realize the encryption, authentication, and decryption of data, ensuring the integrity, readability, and availability of data. Description of the Drawings
[0074] Other features, objects, and advantages of the present invention will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings:
[0075] Figure 1 It is a schematic flow chart of the steps of the information security protection method for the energy and power trading platform of the present invention;
[0076] Figure 2 For Figure 1 It is a detailed schematic flow chart of step S1 in
[0077] Figure 3 For Figure 1 the detailed step - by - step schematic diagram of step S2 in Specific implementation manner
[0078] The following clearly and completely describes the technical method of the present invention for a patent with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those skilled in the art within the scope of the present invention without creative efforts belong to the scope of protection of the present invention.
[0079] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the drawings represent the same or similar parts, so repeated descriptions of them will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor methods and / or microcontroller methods.
[0080] It should be understood that although terms such as "first", "second", etc. may be used here to describe each unit, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit can be called the second unit, and similarly the second unit can be called the first unit. The term "and / or" used here includes any and all combinations of one or more of the listed associated items.
[0081] To achieve the above - mentioned purpose, please refer to Figures 1 to 3 , the present invention provides an information security protection method for an energy and power trading platform, and the method includes the following steps:
[0082] Step S1: Obtain the real - identity data of the user, and use the real - identity data of the user to perform zero - knowledge proof verification with the energy and power trading platform, so as to obtain the user - identity pseudonym data;
[0083] Step S2: Obtain the user's power trading data based on the user - identity pseudonym data, perform transaction conflict detection and arbitration, store the evidence on a distributed consortium chain based on blockchain technology, and perform double homomorphic encryption to generate ciphertext data, where the first - layer homomorphic encryption of the double homomorphic encryption is Paillier semi - homomorphic encryption, and the second - layer homomorphic encryption is BGV full - homomorphic encryption;
[0084] Step S3: Share the private key of Paillier semi-homomorphic encryption to each trusted institution hierarchically through the Shamir secret sharing mechanism to generate an incomplete key set; use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data;
[0085] Step S4: Verify the ciphertext data according to the group signature data to obtain verification result data; when the verification result data shows successful verification, decrypt the ciphertext data according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, perform traceability processing and vulnerability repair.
[0086] In the embodiment of the present invention, refer to Figure 1 As described above, it is a schematic diagram of the step process of an information security protection method for an energy and power trading platform of the present invention. In this example, the information security protection method for the energy and power trading platform includes the following steps:
[0087] Step S1: Obtain the user's real identity data, and use the user's real identity data to perform zero-knowledge proof verification with the energy and power trading platform to obtain the user identity pseudonym data;
[0088] In the embodiment of the present invention, the user provides the energy and power trading platform with his real identity data, such as name, ID number, etc.; the user uses the zero-knowledge proof protocol (such as the Schnorr protocol) to interact with the energy and power trading platform to verify the validity of his real identity data without directly disclosing the identity data itself; after successful verification, the energy and power trading platform generates and assigns a user identity pseudonym data to the user for anonymous identification in subsequent transactions.
[0089] Step S2: Obtain the user's power trading data based on the user identity pseudonym data, perform transaction conflict detection and arbitration, store it on a distributed consortium chain based on blockchain technology, and perform double homomorphic encryption to generate ciphertext data, where the first layer of homomorphic encryption for double homomorphic encryption is Paillier semi-homomorphic encryption, and the second layer of homomorphic encryption is BGV full homomorphic encryption;
[0090] In the embodiment of the present invention, the user's identity pseudonym data is used as an identifier to obtain the user's power trading data in the energy and power trading platform or related data sources; apply a transaction conflict detection algorithm to detect and arbitrate the user's power trading data to ensure the legality and reliability of the transaction; store the transaction data on a distributed consortium chain based on blockchain technology, and perform double homomorphic encryption processing on the transaction data, where Paillier semi-homomorphic encryption is used for the first layer of encryption, and then BGV full homomorphic encryption is used for the second layer of encryption to generate ciphertext data.
[0091] Step S3: Hierarchically share the private key of Paillier homomorphic encryption to each trusted institution through the Shamir secret sharing mechanism to generate an incomplete key set; use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data;
[0092] The embodiment of the present invention generates the private key required for the Paillier homomorphic encryption algorithm; uses the Shamir secret sharing mechanism to split the private key into multiple parts and distributes them to trusted institutions to generate an incomplete key set. The BGLS short group signature algorithm is used to sign the ciphertext data to generate group signature data.
[0093] Step S4: Verify the ciphertext data according to the group signature data to obtain verification result data; when the verification result data shows successful verification, decrypt the ciphertext data according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, perform traceability processing and vulnerability repair.
[0094] The embodiment of the present invention uses the group signature data to verify the ciphertext data to verify the integrity and authenticity of the ciphertext data. The verification result can display information indicating successful or failed verification; when the verification result shows successful verification, use a partial private key in the incomplete key set to decrypt the ciphertext data to obtain plaintext data. The decrypted plaintext data can be used for further analysis and use; when the verification result shows failed verification, traceability processing is required to find out the reason for the failed verification and perform vulnerability repair to ensure the security and reliability of the system.
[0095] Through zero-knowledge proof verification, the user does not need to disclose real identity information, protecting the user's privacy; by obtaining the user's identity pseudonym data, the user can participate anonymously during the transaction process, enhancing the user's anonymity. Through double homomorphic encryption, the user's transaction data is protected during storage and calculation, protecting the user's data privacy; through the detection and arbitration of the user's transaction data, the legality and reliability of the transaction can be ensured, reducing the occurrence of transaction conflicts, and providing effective solutions; the distributed consortium chain based on blockchain technology can provide trusted data storage evidence, ensuring the immutability and transparency of transaction data. Through the Shamir secret sharing mechanism, the private key is hierarchically shared with multiple trusted institutions, enhancing the security and protection ability of the key; using the BGLS short group signature algorithm to sign the ciphertext data can ensure the effectiveness and verifiability of the signature, realizing multi-party collaborative verification. Through the verification of the group signature data, the integrity and credibility of the ciphertext data can be ensured, effectively preventing data tampering and forgery; when the verification result shows successful verification, the incomplete key set is used to decrypt the ciphertext data to obtain the plaintext data, providing a basis for subsequent data analysis and applications; when the verification result shows verification failure, traceability processing is performed, tracing to the source of the security vulnerability and repairing it to improve the security and reliability of the system. In summary, the above steps include privacy protection, anonymity, data privacy protection, transaction conflict detection and arbitration, data storage evidence, key security, group signature mechanism, data integrity and credibility, data decryption, and security vulnerability repair, etc. These effects help to protect user privacy, ensure data security, improve transaction reliability, and increase the transparency and credibility of the system.
[0096] Preferably, step S1 includes the following steps:
[0097] Step S11: Obtain the user's real identity data;
[0098] Step S12: Authenticate the authenticity of the user's real identity data through a third-party certification agency, and generate a unique user ID and authentication credential data for the authenticated user's real identity data;
[0099] Step S13: Use the authentication credential data as a commitment to perform identity verification with the energy and power trading platform based on zero-knowledge proof without disclosing the unique user ID, thereby obtaining the identity verification result data;
[0100] Step S14: After determining that the identity verification result data is a valid identity, generate an anonymous identity identifier for the user and bind it to the unique user ID for storage, thereby obtaining the user's identity pseudonym data.
[0101] As an embodiment of the present invention, refer to Figure 2 as shown, for Figure 1Schematic diagram of the detailed step process of step S1. In the embodiments of the present invention, step S1 includes the following steps:
[0102] Step S11: Obtain the user's real identity data;
[0103] In the embodiments of the present invention, the user provides their real identity data to the user information collection system.
[0104] Step S12: Authenticate the authenticity of the user's real identity data through a third-party certification agency, and generate a unique user ID and authentication credential data for the authenticated user's real identity data;
[0105] In the embodiments of the present invention, the user submits their real identity data to a third-party certification agency; the third-party certification agency verifies the real identity data provided by the user, which can be verified by validating the effectiveness of the ID information, consistency with public records, etc.; after passing the authenticity verification, the third-party certification agency generates a unique user ID and generates corresponding authentication credential data, including the unique user ID and other relevant authentication information.
[0106] Step S13: Use the authentication credential data as a commitment to perform identity verification with the energy and power trading platform based on zero-knowledge proof without disclosing the unique user ID, so as to obtain identity verification result data;
[0107] In the embodiments of the present invention, the user submits the authentication credential data to the energy and power trading platform; using a zero-knowledge proof protocol (such as the Schnorr protocol), the energy and power trading platform interacts with the user to verify the validity of the authentication credential data without directly disclosing the value of the unique user ID; after successful verification, the energy and power trading platform generates identity verification result data, indicating that the user's identity verification is successful.
[0108] Step S14: After determining that the identity verification result data is a valid identity, generate an anonymous identity identifier for the user, bind it to the unique user ID and store it, so as to obtain user identity pseudonym data.
[0109] In the embodiments of the present invention, the energy and power trading platform uses an anonymous identity identifier generation algorithm to generate an anonymous identity identifier for the user; bind the generated anonymous identity identifier to the user's unique user ID and store this binding relationship in the data storage system for subsequent use.
[0110] By obtaining the user's real identity data, the present invention can ensure the accuracy and credibility of subsequent verification and authentication processes; through verification of the user's real identity data by a third-party certification authority, the credibility and authority of identity verification are increased; generating a unique user ID can ensure that each user has a unique identifier in the system, facilitating subsequent identity verification and transaction processing. By using zero-knowledge proofs, users do not need to disclose the unique user ID while ensuring the accuracy of identity verification and protecting user privacy; through identity verification based on zero-knowledge proofs, the accuracy and credibility of verification results can be ensured. By generating an anonymous identity identifier, users can participate in the transaction process anonymously, enhancing user anonymity; binding and storing the anonymous identity identifier with the unique user ID ensures the correlation between the anonymous identity and the real identity, facilitating subsequent data processing and tracking. In summary, the above steps include data accuracy, trusted identity verification, unique user ID generation, privacy protection, identity verification accuracy, anonymity, and data correlation, etc. These effects help to ensure the accuracy of user identity and privacy protection, and achieve trusted identity verification and anonymous transactions in the energy and power trading platform.
[0111] Preferably, step S2 includes the following steps:
[0112] Step S21: Extract the transaction records submitted by the user according to the user identity pseudonym data through the energy and power trading platform, so as to obtain the user's power trading data, where the user's power trading data includes user pseudonym data, transaction serial number data, grid operator data, user power consumption data, transaction amount data, and transaction time data;
[0113] Step S22: Detect transaction conflicts in the user's power trading data and conduct arbitration to obtain conflict-free transaction data;
[0114] Step S23: Upload the conflict-free transaction data to a distributed consortium chain based on blockchain technology and conduct deposit and certification to generate transaction deposit and certification data;
[0115] Step S24: Use the Paillier semi-homomorphic encryption algorithm to perform the first-level homomorphic encryption on the conflict-free transaction data to obtain semi-homomorphic encrypted ciphertext data;
[0116] Step S25: Use the BGV fully homomorphic encryption algorithm to perform the second-level homomorphic encryption on the semi-homomorphic encrypted ciphertext data to obtain fully homomorphic encrypted ciphertext data;
[0117] Step S26: Bind and package the public key of the Paillier semi-homomorphic encryption, the public key of the BGV fully homomorphic encryption, and the fully homomorphic encrypted ciphertext data to obtain ciphertext data.
[0118] As an embodiment of the present invention, refer toFigure 3 As shown in Figure 1 the detailed step - by - step schematic diagram of step S2 in
[0119] Step S21: Extract the transaction records submitted by the user through the energy and power trading platform according to the user identity pseudonym data, so as to obtain the user's power transaction data, where the user's power transaction data includes user pseudonym data, transaction serial number data, grid operator data, user power consumption data, transaction amount data, and transaction time data;
[0120] In the embodiment of the present invention, the user's anonymous identity identifier is obtained by decrypting the user identity pseudonym data; the unique identifier of the transaction is obtained by decrypting the serial number data in the transaction record; the grid operator information in the transaction record is extracted to identify the grid operator executing the transaction; the power consumption information of the user is obtained by decrypting the power consumption data in the transaction record; the amount information of the transaction is obtained by decrypting the amount data in the transaction record; the timestamp in the transaction record is extracted to represent the time when the transaction occurs. The extracted user power transaction data is stored in the data storage system for subsequent use.
[0121] Step S22: Detect transaction conflicts in the user power transaction data and perform arbitration to obtain conflict - free transaction data;
[0122] In the embodiment of the present invention, a conflict detection algorithm is used to detect the user power transaction data to discover possible transaction conflicts. Conflicts may include the following situations: checking whether there is the same transaction serial number data; checking whether there are transactions of the same user and the same time; checking whether the transaction data meets the specified limit conditions, such as the transaction amount exceeding the limit, etc. When a transaction conflict is found, an arbitration mechanism is used to resolve the conflict, such as selecting one of the transactions as the valid transaction, or making an arbitration decision according to specific rules. After arbitration processing, conflict - free transaction data is obtained.
[0123] Step S23: Upload the conflict - free transaction data to a distributed consortium chain based on blockchain technology and perform evidence - keeping to generate transaction evidence - keeping data;
[0124] In the embodiment of the present invention, an evidence - keeping algorithm is used to process the conflict - free transaction data to generate corresponding transaction evidence - keeping data. This may include performing a hash process on the transaction data to generate a unique evidence - keeping identifier and binding the transaction data and the evidence - keeping identifier together. The generated transaction evidence - keeping data is uploaded to a distributed consortium chain based on blockchain technology. This can be operated through a smart contract for transaction evidence - keeping to ensure the security and immutability of the data.
[0125] Step S24: Use the Paillier semi - homomorphic encryption algorithm to perform the first - level homomorphic encryption on the conflict - free transaction data, thereby obtaining semi - homomorphic encrypted ciphertext data;
[0126] In the embodiment of the present invention, the Paillier semi - homomorphic encryption algorithm is used to encrypt the conflict - free transaction data. This may include the following operations: generating Paillier public and private keys for encryption and decryption; using the Paillier public key to encrypt the user's power transaction data to obtain Paillier semi - homomorphic encrypted ciphertext data. In this way, only the entity holding the private key can decrypt and obtain the plaintext data.
[0127] Step S25: Use the BGV fully - homomorphic encryption algorithm to perform the second - level homomorphic encryption on the semi - homomorphic encrypted ciphertext data, thereby obtaining fully - homomorphic encrypted ciphertext data;
[0128] In the embodiment of the present invention, the BGV fully - homomorphic encryption algorithm is used to encrypt the Paillier semi - homomorphic encrypted ciphertext data to obtain BGV fully - homomorphic encrypted ciphertext data. The BGV algorithm provides stronger computing capabilities, allowing complex computing operations to be performed on the ciphertext domain without decryption.
[0129] Step S26: Bind and package the public key of Paillier semi - homomorphic encryption, the public key of BGV fully - homomorphic encryption, and the fully - homomorphic encrypted ciphertext data, thereby obtaining ciphertext data.
[0130] In the embodiment of the present invention, a data packaging tool is used to bind and package the public key of Paillier semi - homomorphic encryption, the public key of BGV fully - homomorphic encryption, and the fully - homomorphic encrypted ciphertext data to obtain the final ciphertext data. This can ensure that all necessary encrypted data is stored or transmitted together for subsequent processing and use.
[0131] The present invention ensures the accuracy and integrity of data extraction by extracting user power transaction data based on user identity pseudonym data. By detecting the user power transaction data, potential transaction conflict situations can be discovered in a timely manner to ensure the legality and reliability of transactions; through the arbitration process, transaction conflicts are resolved to ensure the consistency and credibility of transaction data. By uploading the transaction data to a distributed consortium chain based on blockchain technology for evidence preservation, the immutability and transparency of the transaction data are ensured, improving the credibility and traceability of the data. Through semi - homomorphic encryption, conflict - free transaction data is encrypted to protect the privacy and confidentiality of the transaction data. Through fully - homomorphic encryption, the ciphertext data is further encrypted to enhance the security and protection capabilities of the data. By binding and packaging the public key of semi - homomorphic encryption, the public key of fully - homomorphic encryption, and the ciphertext data, the integrity and consistency of the relevant data are ensured. In summary, the above steps include data extraction accuracy, transaction conflict detection and arbitration, data evidence preservation, data privacy protection, data security, and data integrity, etc. These effects help to protect the privacy and security of transaction data, ensure the legality and credibility of transactions, and provide traceable transaction evidence preservation.
[0132] Preferably, step S22 includes the following steps:
[0133] Step S221: Compare the user pseudonym data and the transaction serial number data. When the same user initiates two transactions with different serial numbers but exactly the same other fields, it is determined as a double - spending conflict of the transaction;
[0134] In the embodiment of the present invention, a data comparison algorithm is used to compare the user pseudonym data and the transaction serial number data in the user power transaction data; when it is found that the same user initiates two transactions with different serial numbers but exactly the same other fields, it is determined as a double - spending conflict of the transaction; the conflict detection result is recorded in the data storage system, and the relevant transactions are marked as double - spending conflicts.
[0135] Step S222: Compare the transaction time data and the transaction serial number data. When there is a transaction with an earlier timestamp but a later serial number, or transactions with the same timestamp but different serial numbers, it is determined as a transaction order conflict;
[0136] In the embodiment of the present invention, a data comparison algorithm is used to compare the transaction time data and the transaction serial number data in the user power transaction data; when there is a transaction with an earlier timestamp but a later serial number, or transactions with the same timestamp but different serial numbers, it is determined as a transaction order conflict; the conflict detection result is recorded in the data storage system, and the relevant transactions are marked as order conflicts.
[0137] Step S223: Compare the user's electricity consumption data and transaction amount data. When there is a mismatch between the electricity quantity and the transaction amount, or when the transaction is extracted non-compliance according to the preset validity conditions, it is determined as a transaction validity conflict.
[0138] In the embodiment of the present invention, a data comparison algorithm is used to compare the user's electricity consumption data and transaction amount data in the user's electricity transaction data; according to the preset validity conditions, the validity of the transaction is checked, including whether the electricity quantity and the transaction amount match and other specified validity conditions; the conflict detection result is recorded in the data storage system, and the relevant transaction is marked as a validity conflict.
[0139] Step S224: Arbitrarily eliminate any duplicate payment transactions in the user's electricity transaction data with transaction double payment conflicts, so as to obtain data without duplicate transactions.
[0140] In the embodiment of the present invention, according to the conflict resolution strategy, one of the conflicting transactions in the transaction double payment conflict is selected as the valid transaction and retained, while the other conflicting transactions are marked as invalid; the transaction status is updated in the data storage system, and the valid and invalid transactions are marked.
[0141] Step S225: Perform a sequence number adjustment and sorting based on the time stamp for the transaction data without duplicate transactions with transaction sequence conflicts, and eliminate transactions with the same time stamp but different sequence numbers, so as to obtain transaction data without sequence conflicts.
[0142] In the embodiment of the present invention, a sorting algorithm is used to sort the transaction data without duplicate transactions based on the time stamp to ensure that the transactions are arranged in chronological order; check the sorted transactions, if there are transactions with the same time stamp but different sequence numbers, eliminate the conflicting transactions among them, and only retain one valid transaction; update the transaction status in the data storage system, and mark the valid and invalid transactions.
[0143] Step S226: Eliminate transactions in the transaction data without sequence conflicts with transaction validity conflicts, and give an invalid reminder to the user, so as to obtain transaction data without conflicts.
[0144] In the embodiment of the present invention, according to the conflict resolution strategy, the transaction validity conflicts in the transaction data without sequence conflicts are resolved, the invalid transactions are eliminated, and the valid transactions are retained; a reminder is sent to the relevant users to notify them that some transactions they initiated are marked as invalid; the transaction status is updated in the data storage system, and the valid and invalid transactions are marked.
[0145] By comparing the user's pseudonym data and the transaction serial number data, the present invention can timely detect two transactions initiated by the same user with different serial numbers but exactly the same other fields, avoiding duplicate payments and inconsistent transactions. By comparing the transaction time data and the transaction serial number data, transactions with earlier timestamps but later serial numbers or transactions with the same timestamps but different serial numbers can be detected, ensuring the sequentiality and consistency of transactions. By comparing the user's electricity consumption data and the transaction amount data, it can be detected whether the electricity consumption matches the transaction amount, and non-compliant extractions of transactions can be performed according to preset validity conditions, ensuring the validity and compliance of transactions. By eliminating any one of the duplicate payment transactions in the transaction double payment conflict, the consistency and accuracy of transaction data are ensured. By sorting the serial numbers based on timestamps, the transaction data is ensured to be arranged in the correct order, avoiding transaction order conflicts. By eliminating transactions with transaction validity conflicts and sending invalid reminders to users, the validity and standardization of transaction data are ensured, enhancing the credibility and compliance of transactions. In summary, the above steps include transaction consistency, transaction sequentiality, and transaction validity, etc. These effects help reduce transaction conflicts, ensure the consistency, sequentiality, and validity of transaction data, and improve the accuracy and reliability of transaction processing.
[0146] Preferably, step S23 includes the following steps:
[0147] Step S231: Perform a hash operation on the conflict-free transaction data to generate transaction digital fingerprint data;
[0148] In the embodiment of the present invention, conflict-free transaction data is prepared; each transaction data is operated using a hash algorithm to generate a unique digital fingerprint; the generated transaction digital fingerprint data is stored in a data storage system.
[0149] Step S232: Package the transaction digital fingerprint data into a transaction and generate a new transaction data block on the consortium chain through a consensus algorithm;
[0150] In the embodiment of the present invention, a certain number of fingerprints are selected from the stored transaction digital fingerprint data to form a new transaction data block; the selected transaction digital fingerprint data is packaged into a new transaction data block using a packaging algorithm; it is verified by nodes on the consortium chain through a consensus algorithm to ensure the validity of the new data block; the generated new transaction data block is stored in a data storage system.
[0151] Step S233: Broadcast the transaction data block to the nodes on the consortium chain through the P2P network and add it to the blockchain to obtain updated consortium chain data;
[0152] In an embodiment of the present invention, the generated transaction data block is broadcast to nodes on the consortium blockchain using a P2P network; the nodes that receive the data block verify it and add it to the blockchain of the consortium blockchain to update the transaction data; and the transaction data on the consortium blockchain is updated in the data storage system.
[0153] Step S234: Generate transaction deposit data corresponding to the new transaction data block according to the updated data of the consortium blockchain.
[0154] In an embodiment of the present invention, a deposit algorithm is used to generate transaction deposit data corresponding to the new transaction data block according to the updated data of the consortium blockchain; the generated transaction deposit data is stored in the data storage system.
[0155] Through hash operation, the generated transaction digital fingerprint can be used to verify the integrity of the transaction data, ensuring that the data has not been tampered with during transmission and storage. The transaction digital fingerprint data is packaged as a transaction and a new data block is generated on the consortium blockchain to ensure the consistency and credibility of the transaction data. All consortium blockchain nodes will reach a consensus and accept the transaction. The transaction data block is broadcast through the P2P network to ensure that all consortium blockchain nodes can obtain and synchronize the transaction data in a timely manner, realizing the distribution and update of the data. Transaction deposit data corresponding to the new transaction data block is generated according to the updated data of the consortium blockchain to ensure the immutability and transparency of the transaction data, providing a traceable transaction deposit. In summary, the above steps include data integrity, data consistency, data distribution and synchronization, and data deposit, etc. These effects help to ensure the integrity, consistency and credibility of the transaction data, ensure the security and traceability of the transaction data, and realize the data update and deposit process on the consortium blockchain.
[0156] Preferably, step S3 includes the following steps:
[0157] Step S31: Split the private key of Paillier homomorphic encryption into several sub-keys through threshold sharing technology, thereby obtaining an incomplete key set;
[0158] In an embodiment of the present invention, the Paillier encryption algorithm is used to generate a public key and a private key; the private key of Paillier homomorphic encryption is split into several sub-keys using threshold sharing technology, and each sub-key is held by a different participating party; an incomplete key set is obtained, where each sub-key only contains a part of the information of the private key.
[0159] Step S32: Construct a group consisting of an energy supplier, an energy operator, an energy dispatching center, and user representatives, thereby obtaining a list of group members;
[0160] In an embodiment of the present invention, a group consisting of an energy supplier, an energy operator, an energy dispatching center, and user representatives is created on a group construction platform; a list of group members is generated, including the identities and relevant information of the members.
[0161] Step S33: Hierarchically share the incomplete key set with each trusted third-party institution through the Shamir secret sharing mechanism; distribute the incomplete key set to the group members in the group member list through the trusted third-party institution;
[0162] In an embodiment of the present invention, the Shamir secret sharing mechanism is used to split the incomplete key set into multiple parts, and these partial keys are distributed to different trusted third-party institutions; the trusted third-party institutions distribute the partial keys they hold to the group members in the group member list to ensure that each member obtains a partial key.
[0163] Step S34: Use the BGLS short group signature algorithm by a third-party institution to sign the ciphertext data to obtain group signature data.
[0164] In an embodiment of the present invention, the third-party institution collects the ciphertext data decrypted by the group members using their private keys, and uses the BGLS short group signature algorithm to sign these ciphertext data to generate group signature data.
[0165] The present invention splits the private key through threshold sharing technology, which can improve the security of the key. Even if some partial keys are leaked, the complete private key cannot be restored. Constructing a group and obtaining a list of group members helps to establish a collaborative relationship among various roles in the energy supply chain, promoting information sharing and decision-making cooperation. Through the Shamir secret sharing mechanism, the incomplete key set is hierarchically shared with trusted third-party institutions to ensure the secure management and distribution of the key. At the same time, the incomplete key set is distributed to group members to ensure that group members have the key shares required for decryption. Through the BGLS short group signature algorithm, the ciphertext data can be signed to ensure the integrity and authenticity of the data. The group signature data can be used to verify the source and integrity of the data, ensuring the credibility and immutability of transaction data. In summary, the above steps include key security, organizational collaboration, key management and security, and data signature and verification, etc. These effects help to ensure the security and management of encryption keys, promote collaboration and information sharing among various roles in the energy supply chain, ensure the integrity and credibility of data, and provide a verifiable data source and immutability.
[0166] Preferably, step S4 includes the following steps:
[0167] Step S41: Transmit the group signature data and the ciphertext data to the members in the group member list;
[0168] In an embodiment of the present invention, a data transmission protocol is used to transmit group signature data and ciphertext data to the members in the group member list, ensuring that the data is transmitted to the correct recipient.
[0169] Step S42: Perform BGLS signature verification on the ciphertext data according to the group signature data, thereby obtaining preliminary verification boolean data;
[0170] In an embodiment of the present invention, the BGLS signature verification algorithm is used to perform verification according to the public key, group signature data, and ciphertext data, obtaining preliminary verification boolean data for representing the verification result.
[0171] Step S43: Extract the signer from the group signature data and judge the legality of the signer's identity information according to the preset trusted authority white list, thereby obtaining identity verification boolean data;
[0172] In an embodiment of the present invention, the identity information of the signer is extracted from the group signature data; according to the preset trusted authority white list, the legality of the signer's identity information is judged, obtaining identity verification boolean data for representing whether the signer's identity information is legal.
[0173] Step S44: Extract the timestamp from the group signature data and compare it with the current time to judge whether it exceeds the validity period, thereby obtaining timeliness verification boolean data;
[0174] In an embodiment of the present invention, the timestamp information is extracted from the group signature data; the timestamp is compared with the current time to judge whether it exceeds the validity period, obtaining timeliness verification boolean data for representing whether the signature is within the validity period.
[0175] Step S45: Generate verification result data according to the preliminary verification boolean data, identity verification boolean data, and timeliness verification boolean data; wherein when any one of the preliminary verification boolean data, identity verification boolean data, and timeliness verification boolean data shows False, the verification result data is that the signature is invalid, otherwise the verification result data is that the signature is valid;
[0176] In an embodiment of the present invention, verification result data is generated according to the results of the preliminary verification boolean data, identity verification boolean data, and timeliness verification boolean data. If any one of the preliminary verification boolean data, identity verification boolean data, or timeliness verification boolean data is False, the validity field of the verification result data is set to False, indicating that the signature is invalid. If the preliminary verification boolean data, identity verification boolean data, and timeliness verification boolean data are all True, the validity field of the verification result data is set to True, indicating that the signature is valid.
[0177] Step S46: If the verification result data shows that the signature is valid, decrypt the ciphertext data according to the incomplete key set, thereby obtaining the plaintext data;
[0178] In an embodiment of the present invention, key fragments in an incomplete key set are used to decrypt ciphertext data to obtain plaintext data. The specific decryption process depends on the encryption algorithm and scheme adopted. The steps include: obtaining sufficient key fragments from the incomplete key set; using the key fragments for decryption operations to restore the ciphertext data to plaintext data.
[0179] Step S47: If the verification result data shows that the signature is invalid, perform traceability processing based on backpropagation according to the group signature data, ciphertext data, user power transaction data, and transaction deposit data, and perform vulnerability repair.
[0180] In an embodiment of the present invention, according to the group signature data, ciphertext data, user power transaction data, and transaction deposit data, a backpropagation-based traceability algorithm is used to trace and analyze the reasons for the invalid signature. The specific steps include: analyzing the association between the group signature data and the ciphertext data to determine the factors that may cause the signature to be invalid. Checking the user power transaction data and transaction deposit data to determine whether there are potential anomalies or attack traces. Using the backpropagation algorithm to trace the root cause of the problem and determine the specific reason for the invalid signature. According to the traceability results, perform vulnerability repair operations to improve the security and effectiveness of the group signature system. The measures include: repairing the discovered security vulnerabilities or weaknesses, such as patching the vulnerabilities in the code, updating components, or fixing configuration problems. Updating the incomplete key set or encryption algorithm to provide stronger security. Strengthening the authentication and access control mechanisms to ensure that only legitimate users can participate in the group signature process. Strengthening the transaction deposit mechanism to ensure the integrity and traceability of transaction records; regularly performing security audits and risk assessments to promptly discover and repair potential vulnerabilities and security threats.
[0181] The present invention realizes the distribution and sharing of data by transmitting group signature data and ciphertext data to group members, ensuring that relevant data can reach each member and providing necessary data for subsequent verification and decryption. Through BGLS signature verification, the ciphertext data is verified to ensure the integrity and authenticity of the data, preventing the data from being tampered with or forged during transmission. Through signer extraction and the trusted institution white list, the identity of the signer in the group signature data is verified to ensure the legality and credibility of the signer and prevent forged signatures. By extracting the timestamp and comparing it with the current time, it is judged whether the group signature data has expired, ensuring the timeliness of the signature data and preventing the use of expired signature data. The final verification result data is generated based on the Boolean data of preliminary verification, identity verification, and timeliness verification, clearly indicating the validity of the signature and providing an accurate result for subsequent operations. When the verification result data shows that the signature is valid, the ciphertext data is decrypted according to the incomplete key set to obtain the original plaintext data, ensuring the readability and availability of the data. When the verification result data shows that the signature is invalid, based on the relevant data, a traceability process based on backpropagation is carried out to trace the reason for the invalid signature and perform corresponding vulnerability repairs, improving the security and reliability of the system. In summary, the above steps include data transmission, data integrity verification, identity verification, timeliness verification, signature verification result, data decryption, and security traceability and vulnerability repair, etc. These effects help to ensure the integrity, authenticity, and timeliness of the data, verify the validity of the signature, and perform necessary data decryption and security traceability processing, improving the security and credibility of the system.
[0182] Preferably, step S46 includes the following steps:
[0183] Step S461: When the verification result data shows that the signature is valid, incomplete key collection is performed according to the group member list, thereby obtaining an incomplete key set;
[0184] In an embodiment of the present invention, according to the group member list, communication is carried out with each group member, and the incomplete key fragments contributed by each member are obtained. The specific steps include: establishing a secure communication channel with each group member; sending a request to each member, asking it to provide the incomplete key fragment it contributed; receiving and verifying the incomplete key fragments provided by each member; combining all valid incomplete key fragments into an incomplete key set.
[0185] Step S462: Use the Shamir secret recovery mechanism to reconstruct the Paillier encrypted complete private key for the incomplete key set, thereby obtaining the Paillier encrypted complete key;
[0186] In an embodiment of the present invention, the Shamir secret recovery mechanism is used to process the incomplete key set to recover the complete private key of Paillier encryption. The specific steps include: determining the required threshold and the parameters of threshold key sharing; using the key fragments in the incomplete key set to perform secret recovery calculations to recover the original private key; and verifying the validity and correctness of the recovered private key.
[0187] Step S463: Use the BGV fully homomorphic encryption key to perform the first-stage decryption on the ciphertext data to obtain the Paillier encrypted data;
[0188] In an embodiment of the present invention, the private key in the BGV fully homomorphic encryption key is used to decrypt the ciphertext data to obtain the Paillier encrypted data. The specific steps include: using the decryption algorithm in the private key to decrypt the ciphertext data; and verifying the validity and correctness of the decryption result.
[0189] Step S464: Use the complete Paillier encryption key to perform the second-stage decryption on the Paillier encrypted data to obtain the plaintext data.
[0190] In an embodiment of the present invention, the private key in the complete Paillier encryption key is used to decrypt the Paillier encrypted data after the first-stage decryption to obtain the plaintext data. The specific steps include: using the decryption algorithm in the private key to decrypt the Paillier encrypted data after the first-stage decryption; and verifying the validity and correctness of the decryption result.
[0191] According to the verification result data of the present invention, the signature is valid, indicating that the group members have valid key shares. By collecting the key shares in the group member list, the complete incomplete key set can be recovered, providing the necessary key for subsequent decryption. Using the Shamir secret recovery mechanism, the complete Paillier encryption private key can be reconstructed from the incomplete key set, ensuring the integrity and security of the key and providing the necessary key for subsequent decryption. Using the BGV fully homomorphic encryption key, the first-stage decryption is performed on the ciphertext data to convert it into Paillier encrypted data, providing the necessary data preparation for subsequent decryption. Using the complete Paillier encryption key, the second-stage decryption is performed on the Paillier encrypted data to restore it to the plaintext data, ensuring the readability and availability of the data. In summary, the above steps include key recovery, key integrity and security, data decryption, etc. These effects help to recover the complete key according to the key shares of the group members, ensuring the integrity and security of the key. At the same time, multiple decryption operations are performed on the ciphertext data to convert it into plaintext data, providing readability and availability.
[0192] Preferably, step S47 includes the following steps:
[0193] Step S471: When the verification result data shows that the signature is invalid, arrange the group signature data, ciphertext data, user power transaction data, and transaction evidence data in the chronological order of transaction occurrence, so as to form transaction trace node data;
[0194] In the embodiment of the present invention, the group signature data, ciphertext data, user power transaction data, and transaction evidence data are arranged in the chronological order of transaction occurrence to form transaction trace node data. The specific steps include: sorting the relevant data in the chronological order of transaction occurrence; combining the sorted data into transaction trace node data. For example, there is a power trading system that includes group signature data, ciphertext data, user power transaction data, and transaction evidence data. When the verification result data shows that the signature of a certain transaction is invalid, according to the timestamp of the transaction, the group signature data, ciphertext data, user power transaction data, and transaction evidence data are arranged in the chronological order of transaction occurrence to form transaction trace node data. For example, if transaction A occurs at time T1, transaction B occurs at time T2, and transaction C occurs at time T3, then the order of the transaction trace node data is: transaction A node data, transaction B node data, transaction C node data.
[0195] Step S472: When the preliminary verification boolean data is False, perform data consistency verification on the transaction trace node data set and mark the inconsistent data nodes to obtain abnormal node data;
[0196] In the embodiment of the present invention, data consistency verification is performed on the transaction trace node data set to detect whether there are inconsistent data nodes. The specific steps include: using a data consistency verification algorithm to verify the transaction trace node data set; detecting whether there are inconsistent situations between data nodes; marking the inconsistent data nodes for subsequent processing and analysis. For example, in a power trading system, data consistency verification is performed on the transaction trace node data set. Suppose there is a set of transaction trace node data. After data consistency verification, it is found that the ciphertext data of transaction A does not match the group signature data of transaction B. Therefore, the transaction A node data is marked as abnormal node data.
[0197] Step S473: Use the backpropagation mechanism to trace the operation nodes or participants that cause data anomalies in the abnormal node data and conduct an audit to obtain auxiliary forensics data;
[0198] In the embodiment of the present invention, a backpropagation mechanism is used to track abnormal node data and find out the operation nodes or participants that cause data anomalies. The specific steps include: starting from the abnormal node, tracking the data flow backward; analyzing the impact of each operation node or participant on the data. Audit: auditing the abnormal node data to obtain auxiliary forensic data. The specific steps include: analyzing information such as the source and modification history of the abnormal node data; collecting other evidence or logs related to the abnormal node data; generating auxiliary forensic data and recording the audit results and related findings. For example, through tracking, it is found that a certain operation node made an incorrect modification to the data during the transaction execution. Then, audit the abnormal node data, analyze the operation records, permissions and other evidence of the operation node to obtain auxiliary forensic data and further confirm the reason for the data anomaly.
[0199] Step S474: Conduct root cause analysis based on the auxiliary forensic data, and formulate a vulnerability repair plan and measures according to the analysis results;
[0200] In the embodiment of the present invention, based on the auxiliary forensic data, a root cause analysis method is used to determine the root cause of the data anomaly. The specific steps include: analyzing the abnormal phenomena and related information in the auxiliary forensic data; using the root cause analysis method for reasoning and tracing to find out the root cause of the data anomaly; according to the results of the root cause analysis, formulating a vulnerability repair plan and measures to repair the vulnerabilities found in the system and strengthen security protection. For example, based on the data obtained from auditing and analysis, it is found that the signature permission of a certain participant is abused, resulting in data anomalies. The root cause analysis reveals a security vulnerability in the system or an imperfect authorization process. According to the results of the root cause analysis, corresponding vulnerability repair plans and measures are formulated, such as fixing the signature permission problem and strengthening the authorization process to prevent similar data anomaly events from occurring again.
[0201] Step S475: When the authentication boolean data is False, trace the identity of the signer of the group signature data, conduct risk analysis on each link of the signature permission source and authorization process, and determine the responsible person according to the analysis results;
[0202] In the embodiment of the present invention, when the authentication Boolean data is False, the real identity of the signer is determined by using the signer identity tracing method. The specific steps include: analyzing the signature information and relevant evidence in the group signature data; tracing the identity of the signer, such as by comparing the public key of the signer or other identity information. Analysis of the source and authorization process of signature authority: Analyze the source and authorization process of signature authority to determine the risks of each link. The specific steps include: tracing the source of signature authority, such as checking authorization records or reviewing relevant documents; analyzing the authorization process of signature authority to understand the operations and participants of each link; using risk analysis methods to evaluate the risk levels of each link. Determination of responsible persons: Determine the responsible persons related to the signer identity tracing and authorization process according to the analysis results. The specific steps include: according to the results of risk analysis, determine the links and responsible persons with risks; investigate and verify relevant information to determine the specific identities of the responsible persons; according to the investigation results and relevant regulations, determine the responsible persons and take corresponding measures. Trace the identity of the signer according to the group signature data to determine the real identity of the signer. At the same time, analyze the source and authorization process of signature authority, such as tracing authorization records and reviewing relevant documents. Use risk analysis methods to evaluate the risk levels of each link and determine the existing risks. According to the analysis results, determine the responsible persons related to the signer identity tracing and authorization process, and take corresponding measures, such as repairing the authorization process and strengthening identity authentication, to reduce the occurrence of similar problems.
[0203] Step S476: When the time limit verification Boolean data is False, judge the rationality of the timestamp for the group signature data. If it is reasonable, evaluate the transmission delay, so as to strengthen the management of the signature usage period.
[0204] In the embodiments of the present invention, a timestamp verification tool is used to verify the timestamps in the group signature data to ensure that they conform to the predetermined timestamp format, range, and accuracy requirements. A time synchronization tool is used to synchronize the time in the system to ensure the accuracy and consistency of the timestamps. It is determined whether the timestamps of the group signature data are within a reasonable range. For example, it is checked whether the timestamps are within the allowable range before and after the current time, and the data with abnormal timestamps is excluded. For example, for an electronic contract to be signed, the system records the signing timestamp. An operator can use the timestamp verification tool to verify the timestamps in the signature data to ensure that they have the correct format, reasonable range, and are synchronized with the system time. If the timestamp exceeds the predetermined range or differs significantly from the system time, it indicates an abnormal situation or potential risk. Transmission delay assessment: A network monitoring tool is used to monitor and record the network delay during the transmission of the signature data to obtain transmission delay-related data; a delay test tool is used to test the network connection to evaluate the network delay situation, including round-trip delay and transmission delay; the transmission delay data is analyzed and compared with a preset delay threshold to determine whether the transmission delay is within an acceptable range. For example, during the voting process, the system records the voting time of each voter and transmits the signature data to the central server for verification and counting. An operator can use the network monitoring tool to monitor the network delay during the transmission process and use the delay test tool to test the network connection to evaluate the transmission delay situation. If the transmission delay exceeds the preset delay threshold, it will affect the accuracy and timeliness of the signature data, and corresponding measures need to be taken, such as optimizing the network connection or adjusting the system configuration.
[0205] The present invention arranges relevant data in chronological order of transaction occurrence to form transaction trace node data, which facilitates subsequent data consistency verification and abnormal node tracking. Verifying the transaction trace node data set to ensure data consistency and marking inconsistent data nodes helps identify data anomalies and problems, providing a basis for subsequent abnormal node tracking and evidence collection. Through a backpropagation mechanism, track the operation nodes or parties causing data anomalies, conduct audits, and obtain auxiliary evidence data, which helps understand the causes and processes of data anomalies and provides a basis for subsequent root cause analysis and vulnerability repair. Conduct root cause analysis on abnormal nodes based on the auxiliary evidence data to determine the causes of data anomalies, and formulate corresponding vulnerability repair plans and measures to improve the security and reliability of the system. Trace the signer's identity for group signature data with a False authentication result, analyze the risks in each link, and determine the responsible person, which helps hold accountable and improve the system's identity authentication mechanism. Judge the rationality of timestamps for group signature data with a False timeliness verification result, evaluate transmission delays, and strengthen the management of the signature usage period to ensure the timeliness and reliability of signature data. In summary, the above steps include data sorting, data consistency verification, abnormal node tracking and auditing, root cause analysis, vulnerability repair, identity tracing and risk analysis, and timestamp rationality judgment and cycle management, etc. These effects help identify data anomalies and problems, trace the causes and processes of data anomalies, formulate corresponding vulnerability repair plans and measures, improve the identity authentication mechanism, and strengthen the management of the signature usage period, thereby enhancing the security, reliability, and credibility of the system.
[0206] The present invention also provides an information security protection system for an energy and power trading platform, which is used for the information security protection method of the above-mentioned energy and power trading platform. The information security protection system for the energy and power trading platform includes:
[0207] A user identity authentication module, which is used to obtain the real identity data of the user and use the real identity data of the user to perform zero-knowledge proof verification with the energy and power trading platform, thereby obtaining the user identity pseudonym data;
[0208] A transaction data processing module, which is used to obtain the user's power transaction data based on the user identity pseudonym data, perform transaction conflict detection and arbitration, store evidence on a distributed consortium chain based on blockchain technology, and perform double homomorphic encryption to generate ciphertext data, where the first layer of homomorphic encryption for double homomorphic encryption is Paillier semi-homomorphic encryption, and the second layer of homomorphic encryption is BGV full homomorphic encryption;
[0209] The key management and signature module is used to hierarchically share the private key of Paillier homomorphic encryption to each trusted institution through the Shamir secret sharing mechanism to generate an incomplete key set; and use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data.
[0210] The ciphertext verification and decryption module is used to verify the ciphertext data according to the group signature data to obtain verification result data; when the verification result data shows successful verification, the ciphertext data is decrypted according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, traceability processing is performed and vulnerability repair is carried out.
[0211] The present invention can ensure the authenticity and privacy protection of the user's identity and obtain the user identity pseudonym data by obtaining the user's real identity data and using zero-knowledge proof verification to verify with the energy and power trading platform, providing an accurate identity identifier for subsequent transaction data processing. Based on the user identity pseudonym data, the user's power trading data is obtained, and the detection and arbitration of transaction conflicts are carried out to ensure the legality and reliability of the transaction and avoid potential conflicts and disputes. The transaction data is stored on the distributed consortium chain based on blockchain technology to ensure the immutability and traceability of the transaction data, improving the credibility and security of the transaction data. Double homomorphic encryption, namely Paillier homomorphic encryption and BGV fully homomorphic encryption, is used to encrypt the transaction data to protect the privacy and confidentiality of the data, and at the same time realize the calculation and operation in the encrypted state, providing the necessary security support for subsequent group signature and decryption. By hierarchically sharing the private key of Paillier homomorphic encryption to each trusted institution through the Shamir secret sharing mechanism to generate an incomplete key set, the secure distribution and management of the key are realized, ensuring the confidentiality and reliability of the key. The BGLS short group signature algorithm is used to sign the ciphertext data to obtain group signature data, realizing the authentication and integrity protection of the data, and ensuring the credibility and traceability of the data in the untrusted environment. The ciphertext data is verified according to the group signature data, and the information of successful or failed verification is obtained through the verification result data to ensure the integrity and credibility of the data and timely discover potential data anomalies and vulnerabilities. When the verification result data shows successful verification, the ciphertext data is decrypted according to the incomplete key set to obtain plaintext data, ensuring the readability and availability of the data and providing accurate transaction information. In summary, the above steps include user identity verification and privacy protection, transaction conflict detection and arbitration, storage and anti-tampering, double homomorphic encryption, key management and secure distribution, group signature generation, data verification and ciphertext decryption, etc. These effects help to ensure the authenticity and privacy protection of the user's identity, guarantee the legality and reliability of the transaction, improve the credibility and security of the data, and realize the encryption, authentication and decryption of the data, ensuring the integrity, readability and availability of the data.
[0212] Therefore, in all respects, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Accordingly, all changes that fall within the meaning and scope of the equivalent elements of the application documents are intended to be embraced within the present invention.
[0213] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather will conform to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. An information security protection method for an energy power trading platform, characterized in that, It includes the following steps: Step S1: Obtain the user's real identity data and use the user's real identity data to conduct zero-knowledge proof verification with the energy and power trading platform, so as to obtain the user identity pseudonym data; Step S2: Obtain the user's power trading data based on the user identity pseudonym data, conduct transaction conflict detection and arbitration, store it on the distributed consortium chain based on blockchain technology, and conduct double homomorphic encryption to generate ciphertext data, where the first homomorphic encryption of the double homomorphic encryption is Paillier semi-homomorphic encryption, and the second homomorphic encryption is BGV fully homomorphic encryption; Step S3: Share the private key of the Paillier semi-homomorphic encryption to each trusted institution in layers through the Shamir secret sharing mechanism to generate an incomplete key set; use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data; Step S4: Verify the ciphertext data according to the group signature data to obtain verification result data; When the verification result data shows successful verification, decrypt the ciphertext data according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, conduct traceability processing and vulnerability repair.
2. The information security protection method of the energy and power trading platform according to claim 1, characterized in that, Step S1 includes the following steps: Step S11: Obtain the user's real identity data; Step S12: Conduct authenticity verification on the user's real identity data through a third-party certification institution, and generate a unique user ID and authentication credential data for the verified user's real identity data; Step S13: Use the authentication credential data as a commitment to conduct identity verification with the energy and power trading platform based on zero-knowledge proof without disclosing the unique user ID, so as to obtain identity verification result data; Step S14: After determining that the identity verification result data is a valid identity, generate an anonymous identity identifier for the user and bind it to the unique user ID for storage, so as to obtain the user identity pseudonym data.
3. The information security protection method for the energy and power trading platform according to claim 2, characterized in that, Step S2 includes the following steps: Step S21: Extract the transaction records submitted by the user by the energy and power trading platform according to the user identity pseudonym data, so as to obtain the user's power trading data, where the user's power trading data includes user pseudonym data, transaction serial number data, grid operator data, user power consumption data, transaction amount data, and transaction time data; Step S22: Conduct transaction conflict detection on the user's power trading data and conduct arbitration to obtain conflict-free transaction data; Step S23: Upload the conflict-free transaction data to the distributed consortium chain based on blockchain technology and conduct archiving to generate transaction archive data; Step S24: Use the Paillier semi-homomorphic encryption algorithm to conduct the first homomorphic encryption on the conflict-free transaction data to obtain semi-homomorphic encrypted ciphertext data; Step S25: Use the BGV fully homomorphic encryption algorithm to conduct the second homomorphic encryption on the semi-homomorphic encrypted ciphertext data to obtain fully homomorphic encrypted ciphertext data; Step S26: Bind and package the public key of the Paillier semi-homomorphic encryption, the public key of the BGV fully homomorphic encryption, and the fully homomorphic encrypted ciphertext data to obtain ciphertext data.
4. The information security protection method of the energy and power trading platform according to claim 3, characterized in that Step S22 includes the following steps: Step S221: Compare the user's pseudonym data and the transaction serial number data. When the same user initiates two transactions with different serial numbers but exactly the same other fields, it is determined as a double-spending conflict of the transaction; Step S222: Compare the transaction time data and the transaction serial number data. When there is a transaction with an earlier timestamp but a later serial number, or transactions with the same timestamp but different serial numbers, it is determined as a transaction order conflict; Step S223: Compare the user's electricity consumption data and the transaction amount data. When there is a mismatch between the electricity quantity and the transaction amount, or the transaction is extracted non-compliance according to the preset validity conditions, it is determined as a transaction validity conflict; Step S224: Arbitrarily eliminate any duplicate payment transactions from the user's electricity transaction data with double-spending conflicts of the transaction, so as to obtain non-duplicate transaction data; Step S225: Perform serial number adjustment and sorting based on the timestamp for the non-duplicate transaction data with transaction order conflicts, and eliminate transactions with the same timestamp but different serial numbers, so as to obtain transaction data without order conflicts; Step S226: Eliminate transactions from the transaction data without order conflicts with transaction validity conflicts, and give an invalid reminder to the user, so as to obtain transaction data without conflicts.
5. The information security protection method for the energy and power trading platform according to claim 4, characterized in that, Step S23 includes the following steps: Step S231: Perform a hash operation on the transaction data without conflicts to generate transaction digital fingerprint data; Step S232: Package the transaction digital fingerprint data into a transaction, and generate a new transaction data block on the consortium blockchain through a consensus algorithm; Step S233: Broadcast the transaction data block to the nodes on the consortium blockchain through the P2P network and add it to the blockchain, so as to obtain updated consortium blockchain data; Step S234: Generate transaction evidence data corresponding to the new transaction data block according to the updated consortium blockchain data.
6. The information security protection method for the energy and power trading platform according to claim 5, wherein Step S3 includes the following steps: Step S31: Split the private key of the Paillier homomorphic encryption into several sub-keys through the threshold sharing technology to obtain an incomplete key set; Step S32: Construct a group consisting of energy suppliers, energy operators, energy dispatching centers, and user representatives to obtain a list of group members; Step S33: Hierarchically share the incomplete key set to each trusted third-party institution through the Shamir secret sharing mechanism; distribute the incomplete key set to the group members in the list of group members through the trusted third-party institution; Step S34: Sign the ciphertext data by the third-party institution using the BGLS short group signature algorithm to obtain group signature data.
7. The information security protection method for the energy and power trading platform according to claim 6, characterized in that, Step S4 includes the following steps: Step S41: Transmit the group signature data and the ciphertext data to the members of the list of group members; Step S42: Perform BGLS signature verification on the ciphertext data according to the group signature data to obtain preliminary verification boolean data; Step S43: Extract the signer of the group signature data and judge the legality of the signer's identity information according to the preset white list of trusted institutions to obtain identity verification boolean data; Step S44: Extract the timestamp of the group signature data and compare it with the current time to judge whether it exceeds the validity period to obtain timeliness verification boolean data; Step S45: Generate verification result data based on the preliminary verification boolean data, authentication boolean data, and timeliness verification boolean data; wherein when any one of the preliminary verification boolean data, authentication boolean data, and timeliness verification boolean data shows False, the verification result data is signature invalid, otherwise the verification result data is signature valid; Step S46: If the verification result data shows that the signature is valid, decrypt the ciphertext data according to the incomplete key set to obtain the plaintext data; Step S47: If the verification result data shows that the signature is invalid, perform traceability processing based on backpropagation on the group signature data, ciphertext data, user electricity transaction data, and transaction deposit data, and perform vulnerability repair.
8. The information security protection method for the energy and power trading platform according to claim 7, characterized in that, Step S46 includes the following steps: Step S461: When the verification result data shows that the signature is valid, collect incomplete keys according to the group member list to obtain an incomplete key set; Step S462: Use the Shamir secret recovery mechanism to reconstruct the Paillier encrypted complete private key for the incomplete key set to obtain the Paillier encrypted complete key; Step S463: Use the BGV fully homomorphic encryption key to perform the first decryption on the ciphertext data to obtain the Paillier encrypted data; Step S464: Use the Paillier encrypted complete key to perform the second decryption on the Paillier encrypted data to obtain the plaintext data.
9. The information security protection method for the energy and power trading platform according to claim 8, characterized in that Step S47 includes the following steps: Step S471: When the verification result data shows that the signature is invalid, arrange the group signature data, ciphertext data, user electricity transaction data, and transaction deposit data in the order of the time of transaction occurrence to form transaction trajectory node data; Step S472: When the preliminary verification boolean data is False, perform data consistency verification on the transaction trajectory node data set and mark the inconsistent data nodes to obtain abnormal node data; Step S473: Use the backpropagation mechanism to trace the operation nodes or parties causing data anomalies for the abnormal node data and perform auditing to obtain auxiliary forensic data; Step S474: Conduct root cause analysis based on the auxiliary forensic data, and formulate vulnerability repair plans and measures according to the analysis results; Step S475: When the authentication boolean data is False, trace the identity of the signer for the group signature data, conduct risk analysis on each link of the signature permission source and authorization process, and determine the responsible person according to the analysis results; Step S476: When the timeliness verification boolean data is False, judge the rationality of the timestamp for the group signature data. If it is reasonable, evaluate the transmission delay to strengthen the management of the signature usage period.
10. An information security protection system for an energy and power trading platform, characterized in that, An information security protection system for an energy and power trading platform for implementing the information security protection method of the energy and power trading platform as claimed in claim 1, the information security protection system of the energy and power trading platform comprising: A user identity authentication module, configured to obtain user real identity data, and use the user real identity data to perform zero-knowledge proof verification with the energy and power trading platform to obtain user identity pseudonym data; A transaction data processing module, which is used to obtain user power transaction data based on user identity pseudonym data, detect and arbitrate transaction conflicts, store evidence on a distributed consortium chain based on blockchain technology, and perform double homomorphic encryption to generate ciphertext data. The first layer of homomorphic encryption in the double homomorphic encryption is Paillier semi-homomorphic encryption, and the second layer of homomorphic encryption is BGV full homomorphic encryption; A key management and signature module, which is used to hierarchically share the private key of Paillier semi-homomorphic encryption to each trusted institution through the Shamir secret sharing mechanism to generate an incomplete key set; use the BGLS short group signature algorithm to sign the ciphertext data to obtain group signature data; A ciphertext verification and decryption module, which is used to verify the ciphertext data according to the group signature data to obtain verification result data; when the verification result data shows successful verification, decrypt the ciphertext data according to the incomplete key set to obtain plaintext data; when the verification result data shows failed verification, perform traceability processing and vulnerability repair.
Citation Information
Patent Citations
Green power consumption authentication data processing method based on block chain and related equipment
CN117036027A
Blockchain-based transaction method and apparatus, and remitter device
US20210058230A1