Key distribution and authentication method for distribution network protection multicast message system
By employing a decentralized multicast communication network in the power distribution network protection system, generating an initial session key using a master public key and hash algorithm, and performing timestamp authentication, the security and low latency issues of multicast data in 5G networks are solved, enabling rapid key distribution and identity authentication.
Patent Information
- Application Number
- CN202411407980.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-10
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-10-10
AI Technical Summary
In power distribution network protection systems, 5G network wireless communication faces security threats. It is necessary to ensure the security and authentication of multicast data to prevent unauthorized users from eavesdropping and tampering, while also meeting the low latency requirements for information transmission.
A decentralized multicast communication network is adopted. The master public key and master private key are generated through group security nodes. Key initialization and encrypted transmission are performed between nodes. The initial session key is generated using a hash algorithm, and identity authentication is performed based on timestamps. Asymmetric encryption algorithm is used for signing and verification.
It achieves rapid key distribution and authentication, reduces network interaction traffic, ensures the security of multicast messages, and meets the low latency requirements of power distribution protection devices.
Smart Images

Figure CN119299162B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for transmitting digital information, and more particularly to a method for securely transmitting digital information. Background Technology
[0002] Multicast communication is a communication mechanism that allows information to be transmitted simultaneously from one or more senders to multiple receivers in a network. In distribution network protection systems, it is used for horizontal GOOSE message communication. In traditional distribution network protection systems, horizontal GOOSE message communication is conducted via wired media such as optical fibers. With the development of 5G technology and the gradual improvement of 5G networks, 5G networks can perform intelligent analysis and respond to anomaly information in real time. Therefore, 5G technology is used in distribution network protection systems to achieve faster and more accurate power grid control.
[0003] However, information transmission via 5G wireless networks faces more severe security threats, necessitating the assurance that only authorized users can join specific multicast groups or receive multicast data. Therefore, for multicast environments, an authentication mechanism is needed to verify user identities and determine user permission to join the multicast network based on predefined policies. Secondly, it is also necessary to protect multicast data from tampering and eavesdropping during transmission, such as using encryption technology to prevent unauthorized users from reading content. Therefore, in multicast environments, key distribution and authentication methods for multicast networks need to be designed to ensure the security of information transmitted within the multicast environment. Summary of the Invention
[0004] Purpose of the invention: In view of the above-mentioned prior art, a key distribution and authentication method for a distribution network protection multicast message system is proposed, which can realize fast key distribution and authentication in a decentralized multicast communication network.
[0005] Technical solution: A key distribution and authentication method for a distribution network protection multicast message system, wherein network nodes communicate in a group manner, including a group security node and several child nodes; the method includes:
[0006] Step 1: The group of security nodes obtains the identification information of its devices, generates a master public key and a master private key, and securely transmits the master public key to each child node;
[0007] Step 2: Each child node generates its own public and private keys based on the identification information in its respective device;
[0008] Step 3: Each child node encrypts its own public key and its own device identification information based on the master public key distributed by the group security node and transmits them to the group security node. The group security node then receives the encrypted public key and decrypts it using the master private key.
[0009] Step 4: Based on the identification information of all node devices it has obtained, and based on the current timestamp information and randomness, the group security node generates an initial session key for each node using a hash algorithm;
[0010] Step 5: Based on the public key information of each node, the group security nodes distribute the initial session keys of all nodes to each child node. Then, each child node decrypts the initial session keys of all nodes based on its own private key.
[0011] Step 6: When the time for authentication is reached in the network, each child node uses its private key to sign its own device identification information and authentication time information, and then transmits the signed information to the group security node.
[0012] Step 7: After receiving the signature information sent by the child node, the group security node uses the child node's public key for verification, and then compares the difference between the authentication time information and the timestamp information. When the absolute value of the difference is less than the threshold and the device's identification information is accurate, the group security node completes the identity authentication of the child node.
[0013] Furthermore, in step 1, the secure transfer is based on wired transmission or manual copying.
[0014] Furthermore, in step 1, the device identification information is obtained based on the device's MAC address, IP address, and motherboard number.
[0015] Furthermore, in steps 4 and 7, the timestamp information is standard clock information obtained by the satellite positioning and navigation module through satellite navigation signals.
[0016] Furthermore, in steps 6 and 7, signing and verification involve using the private key of an asymmetric encryption algorithm to sign the transmitted information and using the public key of an asymmetric encryption algorithm to verify the received information.
[0017] Furthermore, in step 7: the threshold is the maximum transmission delay that the multicast network can tolerate.
[0018] Furthermore, in step 1, the device identification information is obtained by converting the two sets of MAC addresses into binary bits and concatenating them, based on the MAC address of the power distribution protection device to which it is connected and the MAC address of the device itself used to connect to the power distribution protection device.
[0019] Furthermore, in step 1, the device identification information is obtained by converting the two sets of MAC addresses into binary bits and performing an XOR operation on them, based on the MAC address of the power distribution protection device to which the device is connected and the MAC address of the device itself used to connect to the power distribution protection device.
[0020] Furthermore, in step 1, the master public key and master private key are generated using an asymmetric encryption / decryption algorithm or an asymmetric encryption algorithm.
[0021] Furthermore, in step 4, the hash algorithm is an algorithm that generates a fixed-length result based on an input sequence of arbitrary length.
[0022] Beneficial Effects: The method of this invention includes a key initialization process, an initial key distribution process, and an authentication process. The key initialization process comprises three steps: generating and distributing a master key pair, generating an identifier-based key, and transmitting user key pairs. The initial key distribution process comprises two steps: initial key generation and initial key distribution. The authentication process comprises two steps: signing based on accurate time and verification based on accurate time difference. This method enables rapid key distribution and authentication in multicast environments, reducing network interaction traffic used for key distribution and authentication, and is suitable for multicast environments of power distribution protection devices. By implementing this method, multicast messages can be securely protected to ensure the security of multicast information in power distribution protection devices and meet the requirements of low latency information transmission. Attached Figure Description
[0023] Figure 1 This is a general flowchart of the method of the present invention;
[0024] Figure 2 This is a flowchart illustrating the generation and distribution of master key pairs during the key initialization process in the method of this invention;
[0025] Figure 3 This is a schematic diagram illustrating a method for obtaining device identifiers based on MAC addresses.
[0026] Figure 4 This is a schematic diagram illustrating the process of key generation based on identifiers and transmission of user key pairs during key initialization in the method of the present invention;
[0027] Figure 5 This is a schematic diagram of the initial key distribution process in the method of the present invention;
[0028] Figure 6 This is a schematic diagram of the identity authentication process in the method of the present invention. Detailed Implementation
[0029] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the invention.
[0030] Power distribution protection devices need to send multicast messages during operation. With the development of 5G technology, these devices will be able to send multicast messages wirelessly. However, eavesdropping and spoofing attacks are common in wireless environments. Therefore, security protection for multicast messages is necessary to ensure the security of multicast information from power distribution protection devices. Furthermore, because the information transmitted by power distribution protection devices has very high latency requirements, the security protection measures must ensure low processing latency.
[0031] In this embodiment, it is assumed that there are four power distribution protection devices in the network, each equipped with a communication node device, denoted as nodes A, B, C, and D respectively. These four power distribution protection devices are in the same group and need to transmit information to each other via multicast. Among these four power distribution protection devices, node A is designated as the group's security node, responsible for coordinating the security of the entire group. All four power distribution protection devices can obtain accurate system time based on the time synchronization module.
[0032] like Figure 1 As shown, this method includes a key initialization process, an initial key distribution process, and an authentication process. The key initialization process comprises three steps: generating and distributing a master key pair, identifier-based key generation, and user key pair transmission. The initial key distribution process comprises two steps: initial key generation and initial key distribution. The authentication process comprises two steps: signature based on accurate time and verification based on accurate time difference.
[0033] First, each node in the group performs a key initialization process. Figure 2 The process of generating and distributing the master key pair during the key initialization process of this invention is illustrated below:
[0034] During key initialization, group security node A can obtain the identification information ID of its device. A Generate master public key and the master private key like Figure 3 As shown, device identification information ID A The device's identification information (ID) can be obtained by combining the MAC address of the power distribution protection device it is connected to with its own MAC address used to connect to the power distribution protection device. These two MAC addresses are converted to binary bits and then concatenated to obtain the device's ID. A Alternatively, convert the two sets of MAC addresses into binary bits and then perform an XOR operation to obtain the device's identification information (ID). A The master public and master private keys can be generated using asymmetric encryption algorithms, such as the Chinese national cryptographic algorithms SM2 and SM9, or using asymmetric encryption algorithms such as RSA. Furthermore, device identification information can be replaced with IP addresses other than MAC addresses, motherboard serial numbers, etc.
[0035] The master public key and master private key are trusted by the entire group and used securely by the group. Node A transmits the identification information ID securely. A Generate master public key and the master private key All or part of the information is passed to nodes B, C, and D.
[0036] like Figure 2 As shown, node A will identify the information ID. A Generate master public key and the master private key Provide this information to nodes B, C, and D. Considering that different encryption algorithms require different information, node A could also simply provide the generated master public key. The data is then transmitted to nodes B, C, and D. Secure transmission methods include wired transmission and manual copying.
[0037] After generating and distributing the master key pair during key initialization, it is necessary to implement identifier-based key generation and user key pair transmission. For example... Figure 4 As shown, each node in the group (nodes B, C, and D, excluding node A) is identified by its device ID. B ID C ID D Generate your own public key and private key The generation method can also employ the aforementioned asymmetric encryption / decryption algorithm or asymmetric encryption algorithm. Then, nodes B, C, and D use the master public key distributed by group security node A. The public key generated for it and device identification information ID B ID C ID D After encryption, the data is transmitted to node A. The specific processing steps are as follows:
[0038] Node B,
[0039] Node C,
[0040] Node D, in, This represents the encrypted information of nodes B, C, and D. E() represents the encryption algorithm, and || represents concatenation. Here, it means that the public key and the identification information are concatenated and then encrypted before being sent.
[0041] Node A uses its master private key Decryption is performed to obtain the transmitted information. The specific processing steps are as follows:
[0042] Information about node B
[0043] Information about node C
[0044] Information about node D Where D() represents the decryption algorithm. The encryption and decryption algorithms are asymmetric encryption and decryption algorithms, such as the Chinese national cryptographic algorithms SM2 and SM9, or asymmetric encryption algorithms such as RSA.
[0045] After processing, group security node A obtains the identification information (ID) of all other nodes in the group. B ID C IDD and public key information
[0046] After the key initialization process is completed, the initial key is distributed within the group, and the implementation process is as follows: Figure 5 As shown. Group security node A uses the identification information (ID) of all nodes it obtains. B ID C ID D Select the accurate timestamp information transmitted by the current time synchronization module. The initial session key for each node is generated using a hash algorithm H(), along with a self-generated random variable X. The specific process is as follows:
[0047] Node B,
[0048] Node C,
[0049] Node D, in, These are the initial session keys for nodes B, C, and D, respectively. The hash algorithm is an algorithm that generates a fixed-length result based on an input sequence of arbitrary length, such as the SM3 national cryptographic algorithm. Precise timestamp information. It can be standard clock information obtained from satellite navigation signals by the BeiDou module or other satellite positioning and navigation modules. The random quantity X is a random number generated based on existing random algorithms, and there are no other requirements for the random number.
[0050] Node A based on the identification information ID A Timestamp information Simultaneously generate the initial session key with the self-generated random variable X. Initial session key K within the group Ses1 It contains the initial session key for each node in the group generated by node A:
[0051]
[0052] Group security node A uses the public key information it obtains from all nodes. The initial session key within the group is distributed to each node, and the specific process is as follows:
[0053] Node B,
[0054] Node C,
[0055] Node D, in, These represent the encrypted ciphertexts of nodes B, C, and D, respectively.
[0056] Each node in the group is based on its own private key. Decryption yields the initial session keys for all nodes, i.e., the initial session keys within the group. The specific processing steps are as follows:
[0057] Node B,
[0058] Node C,
[0059] Node D,
[0060] Through the above processing steps, each node in the group obtains the initial session key for each node in the group.
[0061] When authentication of devices within a group is required, the process is as follows: Figure 6 As shown. When nodes B, C, and D in the network reach the point where authentication is required, their private keys are used based on the precise time. Its identification information ID B ID C ID D and time information The signing process is as follows:
[0062] Node B,
[0063] Node C,
[0064] Node D, Among them, S B S C S D These represent the information after nodes B, C, and D have signed, respectively.
[0065] Nodes B, C, and D transmit the signed information to group security node A. After receiving the signed information from nodes B, C, and D, group security node A authenticates the information using the public keys of nodes B, C, and D. The verification process is as follows:
[0066] Information about node B
[0067] Information about node C
[0068] Information about node D
[0069] Node A is based on precise timestamp information Compare the time information transmitted by nodes B, C, and D. and The difference. When time information The exact time of node A error Less than threshold T Thres And the device's identification information ID B ID C ID D If the authentication is accurate, node A completes the authentication of nodes B, C, and D. The threshold T... Thres This can be the maximum transmission delay that the multicast network can tolerate.
[0070] The above description is merely a preferred embodiment of the present invention and should not be construed as limiting the scope of the present invention. Therefore, any equivalent variations made in accordance with the claims of the present invention are still within the scope of the present invention.
Claims
1. A key distribution and authentication method for a distribution network protection multicast message system, characterized in that, Network nodes communicate in a group, which includes a group security node and several child nodes; the method includes: Step 1: The group of security nodes obtains the identification information of its devices, generates a master public key and a master private key, and securely transmits the master public key to each child node; Step 2: Each child node generates its own public and private keys based on the identification information in its respective device; Step 3: Each child node encrypts its own public key and its own device identification information based on the master public key distributed by the group security node and transmits them to the group security node. The group security node then receives the encrypted public key and decrypts it using the master private key. Step 4: Based on the identification information of all node devices it has obtained, and based on the current timestamp information and randomness, the group security node generates an initial session key for each node using a hash algorithm; Step 5: Based on the public key information of each node, the group security nodes distribute the initial session keys of all nodes to each child node. Then, each child node decrypts the initial session keys of all nodes based on its own private key. Step 6: When the time for authentication is reached in the network, each child node uses its private key to sign its own device identification information and authentication time information, and then transmits the signed information to the group security node. Step 7: After receiving the signature information sent by the child node, the group security node uses the child node's public key for verification, and then compares the difference between the authentication time information and the timestamp information. When the absolute value of the difference is less than the threshold and the device's identification information is accurate, the group security node completes the identity authentication of the child node.
2. The key distribution and authentication method for a distribution network protection multicast message system according to claim 1, characterized in that, In step 1, the secure transfer is based on wired transmission or manual copying.
3. The key distribution and authentication method for a distribution network protection multicast message system according to claim 1, characterized in that, In step 1, the device identification information is obtained based on the device's MAC address, IP address, and motherboard number.
4. The key distribution and authentication method for a distribution network protection multicast message system according to claim 1, characterized in that, In steps 4 and 7, the timestamp information is standard clock information obtained by the satellite positioning and navigation module through satellite navigation signals.
5. The key distribution and authentication method for a distribution network protection multicast message system according to claim 1, characterized in that, In steps 6 and 7, signing and verification involve using the private key of an asymmetric encryption algorithm to sign the transmitted information and using the public key of an asymmetric encryption algorithm to verify the received information.
6. The key distribution and authentication method for a distribution network protection multicast message system according to claim 1, characterized in that, In step 7: the threshold is the maximum transmission delay that the multicast network can tolerate.
7. The key distribution and authentication method for a distribution network protection multicast message system according to claim 3, characterized in that, In step 1, the device identification information is obtained by converting the two sets of MAC addresses into binary bits and then concatenating them to obtain the device identification information. The MAC addresses are based on the MAC address of the power distribution protection device to which the device is connected and the MAC address of the device itself used to connect to the power distribution protection device.
8. The key distribution and authentication method for a distribution network protection multicast message system according to claim 3, characterized in that, In step 1, the device identification information is obtained by converting the two sets of MAC addresses into binary bits and performing an XOR operation on them, based on the MAC address of the power distribution protection device to which the device is connected and the MAC address of the device itself used to connect to the power distribution protection device.
9. The key distribution and authentication method for a distribution network protection multicast message system according to any one of claims 1-8, characterized in that, In step 1, the master public key and master private key are generated using an asymmetric encryption / decryption algorithm or an asymmetric encryption algorithm.
10. The key distribution and authentication method for a distribution network protection multicast message system according to claim 1 or 4, characterized in that, In step 4, the hash algorithm is an algorithm that generates a fixed-length result based on an input sequence of arbitrary length.
Citation Information
Patent Citations
Identity authentication method and system based on spatial network
CN116471037A
Cloud side-end integrated identity authentication method and system for distributed energy storage system
CN118353634A