An encryption method and device for stabilizing high real-time 2M communication

By introducing FPGA to the hardware circuit of the stable control system and randomly updating the seed signal, the problem of 2M communication being vulnerable to network attacks is solved, and high-speed, secure and stable communication is achieved.

CN119402173BActive Publication Date: 2025-05-09NARI TECH CO LTD +2
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510006611.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-05-09
Estimated Expiration
2045-01-03

AI Technical Summary

Technical Problem

The prior art 2M communication in the stable control system is vulnerable to network attacks, resulting in data theft and malicious tampering. The key update process may interrupt the transmission of service packets, and the random number generation method has the risk of cracking.

Method used

The FPGA construction key generation module is introduced into the hardware circuit to encrypt and decrypt the packets, and the periodicity of key generation and update is eliminated by randomly updating the seed signal, thereby enhancing the security of encryption and decryption.

Benefits of technology

It realizes high-speed communication at millisecond level, meets the requirements of high real-time, ensures the security and stability of 2M communication, avoids the risk of interrupting services by key updates, and enhances the randomness and security of keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402173B_ABST
    Figure CN119402173B_ABST
Patent Text Reader

Abstract

The present invention discloses an encryption method and device for stabilizing high real-time 2M communication, including a 2M communication sending end and a receiving end constructing the same random key generation module; the sending end generates a timestamp based on a synchronous clock and sends it to the receiving end, and both ends generate a seed signal based on the timestamp as the initial state of the key generation module; the sending end uses the key generation module to output a key to encrypt the message, and the receiving end uses the output key to decrypt; in the key generation module state update phase, the sending end randomly generates an update sequence number and sends it to the receiving end in a covert manner, and when the message frame sequence processed by both ends reaches the update sequence number, the random seed signal associated with the stabilization service is synchronously updated to update the module state. The present invention uses FPGA to construct a key generation module for message encryption and decryption, with low time overhead, meeting the high real-time requirements of stabilizing 2M communication; randomizing the update module state, eliminating the periodicity of key generation, and greatly enhancing encryption security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of 2M communication security of a stabilization control system, and in particular to an encryption method and device for stabilization control of high-real-time 2M communication. Background Art

[0002] In the stability control system, 2M communication is widely used in the communication between stations. It is suitable for transmitting data and information with high real-time requirements, such as power grid status and control instructions. However, due to the fully transparent characteristics of 2M communication in transmitting data and information, the stability control business is vulnerable to security threats such as sniffing attacks and man-in-the-middle attacks, which may lead to data theft and malicious tampering, causing the stability control device to malfunction and fail to operate, thus seriously affecting the safe and stable operation of the power grid.

[0003] Prior art document 1 (CN113541955A) discloses an encryption method and device for 2M communication of a security control system. The method includes sending an encrypted message from a sender to a receiver, and the encrypted message includes a flag bit, a function code bit, a count bit, a communication information body and a check code; after receiving the message, the receiver will check the count bit and the check code, and after judging that the communication is abnormal, it will feedback the abnormality to the sender and apply for a new key; after receiving the feedback, the sender will change the key and send it to the receiver; the receiver receives the key and writes it successfully, and feedbacks it to the sender; after receiving the feedback, the sender will reset the count bit and send the encrypted information normally; the sender and the receiver will perform encrypted communication based on the key, count value and information body.

[0004] Prior art 2 (CN115529133A) discloses an encryption and decryption processing method and device for dynamic key update of a security chip. The method includes: the first device generates a random number, and sends the random number and the current timestamp to the second device; the first device determines a key generation rule based on the current timestamp, and generates an encryption key based on the key generation rule and the random number; after the second device receives the random number and the current timestamp, when the current timestamp meets the key generation condition, the key generation rule is determined based on the current timestamp, the key generation rule determined by the first device and the second device based on the current timestamp is the same, and a decryption key is generated based on the key generation rule and the random number, and the decryption key and the encryption key are a matching key pair.

[0005] The shortcoming of prior art 1 is that when the receiving party determines that the communication is abnormal, the key is updated, and the update process will block the interaction of business information messages. The two parties need to renegotiate the key through the interaction process, which may cause the loss of key command messages; the shortcoming of prior art 2 is that when the device communication connection reaches the preset time, the key is updated, and the update process will interrupt the transmission of the current business message. In addition, the randomness of the key generation depends on the generation of random numbers, and the random number generation method may be cracked. Summary of the invention

[0006] In order to solve the deficiencies in the prior art, the present invention provides an encryption method and device for stabilizing high-real-time 2M communication, so as to solve the security problem that 2M communication in the power stabilization and control system is vulnerable to network attacks. By introducing FPGA in the hardware circuit to build a key generation module to encrypt and decrypt the message, high-speed communication in milliseconds is achieved, meeting the business requirements for high real-time performance. The output sequence of the key generation module is periodic and easy to be cracked. The present invention eliminates the periodicity by randomly updating the seed signal, greatly enhancing the security of message encryption and decryption, effectively improving the security and stability of 2M communication in the power stabilization and control system, and ensuring the safety and reliability of system operation and data transmission.

[0007] The present invention adopts the following technical solution.

[0008] A first aspect of the present invention provides an encryption method for stabilizing high-real-time 2M communication, which is applied to a power stabilization control system. The power stabilization control system includes a transmitting end and a receiving end. The transmitting end and the receiving end communicate via 2M, including the following contents:

[0009] The sending and receiving ends construct the same random key generation module;

[0010] In the initialization phase, the sender generates a timestamp based on the local synchronization clock and sends it to the receiver. The sender and receiver generate a seed signal based on the timestamp as the initial state of the key generation module.

[0011] During the operation phase, the sending end encrypts the original stabilization and control service message through the key generation module output key and sends it to the receiving end. After receiving it, the receiving end uses the key generation module output key to decrypt the ciphertext and obtain the original stabilization and control service message;

[0012] During the status update phase of the key generation module, the sending end randomly generates an update sequence number and sends it covertly to the receiving end. When the frame sequence number of the stabilization service message at both ends reaches the update sequence number, both ends will synchronously update the status of the key generation module with the random seed signal associated with the stabilization service.

[0013] Optionally, the seed signal is generated by calculating the timestamp using a hash function agreed upon by the transmitter and the receiver in the application scenario, and the hash function includes: SM3 or SHA-1 or SHA-256 or MD5.

[0014] Optionally, the key generated by the key generation module has periodicity, and the key generation module state is randomly and synchronously updated before the key generation reaches its period.

[0015] Optionally, the stabilization control service message includes a frame header, a frame sequence number, an information body, and a frame tail, wherein the value of the frame sequence number changes cyclically, and the state update of the key generation module at the sending end and the receiving end is synchronously updated through the frame sequence number, including:

[0016] The sending end generates a random number in advance that is smaller than the frame number change period, and hides it as the value of the frame number in the stabilization control service message frame and sends it to the receiving end;

[0017] The receiving end parses the message frame, extracts the random number, and returns the confirmation information to the sending end.

[0018] Optionally, before the key generation reaches its period, the key generation module state is randomly updated, including:

[0019] When the sending end and the receiving end need to update their status synchronously, the irregularly changing information body of the stabilization and control service message is extracted; the information body is operated through the agreed hash function to generate a random seed signal associated with the stabilization and control service to update the status of the key generation module.

[0020] Optionally, operating the information body by using an agreed hash function to generate a random seed signal associated with the stabilization service includes:

[0021] Divide the information body into multiple information segments;

[0022] Perform hash calculation on each information segment respectively to obtain multiple hash calculation results;

[0023] Multiple hash calculation results are combined to generate a random seed signal associated with the stabilization service.

[0024] Optionally, the random seed signal associated with the stabilization service is filled into the key generation module in a preset order to update the state of the key generation module, including:

[0025] Fill the random seed signals associated with the stabilization service into the key generation module in order from left to right;

[0026] If the length of the random seed signal is less than the length of the key generation module, the key generation module is filled with zeros until the key generation module is fully filled; and / or,

[0027] If the length of the random seed signal is greater than the length of the key generation module, the excess data after the key generation module is filled in the random seed signal is discarded.

[0028] Optionally, the encryption method further includes: in the 2M communication channel abnormality recovery phase, the sending end and the receiving end set the key generation module based on the initialization phase operation.

[0029] A second aspect of the present invention provides an encryption device for stabilizing high real-time 2M communication, comprising:

[0030] The first module is used to generate a key according to the seed signal, and the generated key is used to encrypt and decrypt the stabilization control service message;

[0031] A second module is used to update the seed signal using a random seed signal associated with the stabilization service;

[0032] The third module is used to randomly generate an update sequence number and send it to the receiving end through a stable control service message;

[0033] When the frame sequence number of the stable control service message of the sending end and the receiving end reaches the update sequence number, the second module of the sending end and the receiving end transmits the updated seed signal to the first module, and the first module generates a new key for 2M communication according to the updated seed signal;

[0034] The fourth module is used to obtain the stabilization and control service message;

[0035] The fifth module is used to encrypt and / or decrypt the stabilization and control service message in the fourth module using the key generated by the first module.

[0036] Optionally, the device comprises: the first module is connected to the second module via a switch;

[0037] When the frame sequence number of the stabilization and control service message at the transmitting end and the receiving end does not reach the update sequence number, the switch is disconnected, the second module stores the stabilization and control service message, and generates a random seed signal according to the stabilization and control service message;

[0038] When the frame number of the stable control service message at the sending end and the receiving end reaches the update number, the switch is closed, the seed signal of the first module is set to the seed signal of the initialization phase, and the random seed signal generated by the second module is transmitted to the first module to complete the update of the seed signal.

[0039] Optionally, the device comprises: the first module and the second module are connected to the fourth module via a first switch, and the first module and the second module are connected to the fifth module via a second switch;

[0040] When the frame sequence numbers of the stabilization service messages at the transmitting end and the receiving end do not reach the update sequence number, the first switch is connected to the second module, and the second switch is connected to the first module;

[0041] When the frame sequence numbers of the stable control service messages at the transmitting end and the receiving end reach the update sequence numbers, the first switch is disconnected from the second module and connected to the first module, and the second switch is disconnected from the first module and connected to the second module.

[0042] The third aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is loaded into the processor, the encryption method for stabilizing high real-time 2M communication is implemented.

[0043] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-mentioned encryption method for stabilizing high-real-time 2M communication.

[0044] Compared with the prior art, the beneficial effects of the present invention include at least:

[0045] The present invention dynamically updates the key in operation based on the synchronization characteristics of stable 2M communication and utilizing the true randomness of the information content in the message without interrupting the current business message interaction; the present invention can continuously update the random key while ensuring that the communication service is not interrupted, without affecting the stable control service.

[0046] The random seed information of the present invention is extracted and generated from the message service information, without the need for additional interactive processes. At the same time, because the service information in the message changes randomly according to the actual operating status, the randomness of the key is guaranteed. The random key can be continuously updated while ensuring that the communication service is not interrupted, without affecting the stable control service. The key is generated through the true randomness of the information in the service message, which fully guarantees the security of the key.

[0047] The present invention eliminates the periodicity of key generation and key update by randomly updating the seed signal, greatly enhances the security of message encryption and decryption, effectively improves the security and stability of 2M communication in the power stabilization and control system, and improves the security and reliability of system operation and data transmission. In addition, by introducing FPGA to build a key generation module in the hardware circuit to encrypt and decrypt the message, high-speed communication in milliseconds is achieved, meeting the business requirements for high real-time performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor. Among them:

[0049] Figure 1 A schematic flow chart of an encryption method for stabilizing high-real-time 2M communication provided by an embodiment of the present invention;

[0050] Figure 2 An overall schematic diagram of an encryption method for stabilizing high-real-time 2M communication provided by an embodiment of the present invention;

[0051] Figure 3 A schematic diagram of the overall process of generating a seed signal according to a timestamp in an encryption method for stabilizing high-real-time 2M communication provided by an embodiment of the present invention;

[0052] Figure 4 An overall schematic diagram of generating a random seed signal according to a stabilization service message in an encryption method for stabilization high real-time 2M communication provided by an embodiment of the present invention;

[0053] Figure 5 A schematic diagram of an encryption device for stabilizing high-real-time 2M communication provided by an embodiment of the present invention;

[0054] Figure 6 A schematic diagram of another encryption device for stabilizing high-real-time 2M communication provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0055] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0056] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0057] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0058] At the same time, in the description of the present invention, it should be noted that the directions or positional relationships indicated by the terms "upper, lower, inner and outer" are based on the directions or positional relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore cannot be understood as limiting the present invention. In addition, the terms "first, second or third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0059] In the present invention, unless otherwise clearly specified and limited, the terms "install, connect, connect" should be understood in a broad sense, for example: it can be a fixed connection, a detachable connection or an integral connection; it can also be a mechanical connection, an electrical connection or a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0060] Combination Figures 1 to 3 As shown, embodiment 1 of the present invention provides a secure encryption method for 2M communication, which is applied to a power grid stabilization control system and specifically includes the following contents:

[0061] S1: The sender and receiver construct the same random key generation module.

[0062] Specifically, the 2M communication sending end and the 2M communication receiving end both use FPGA to build the same random key generation module. In this way, by introducing FPGA to build a key generation module to encrypt and decrypt messages, high-speed communication in milliseconds is achieved, meeting the business's requirements for high real-time performance.

[0063] S2: Initialization phase, the sender generates a timestamp based on the local synchronization clock and sends it to the receiver. The sender and receiver generate a seed signal based on the timestamp as the initial state of the key generation module.

[0064] Specifically, the key generation module uses FPGA to build a circuit generated by multiple triggers and feedback paths. Before the key generation module runs, the seed signal is filled into the trigger as the initial state of the module. During operation, the circuit performs specific logical operations and continuously generates key sequences.

[0065] Furthermore, according to the application scenario, the sender and the receiver agree on a suitable hash function to calculate the timestamp and generate a seed signal. The hash function includes but is not limited to SM3, SHA-1, SHA-256, MD5, etc.

[0066] Generating a seed signal according to a timestamp in S2 includes distributing a timestamp and generating a seed signal.

[0067] Timestamp distribution: In the initialization phase, the sender obtains the current time of the device and converts it into a timestamp, and sends it to the receiver via 2M communication. The receiver receives and saves the timestamp.

[0068] Seed signal generation: The 2M communication sender and the 2M communication receiver perform a hash operation on the timestamp using an agreed hash algorithm to generate a seed signal.

[0069] Optionally, the seed signal has a fixed length.

[0070] Optionally, the seed signal obtained by the hash operation is filled into the key generation module in order from left to right. If the sequence length is less than the fixed length of the seed signal, zero is filled in the highest bit until the seed signal is filled. If the sequence length exceeds the seed signal length, the excess part is directly discarded.

[0071] S3: In the operation phase, the sending end encrypts the original stabilization and control service message through the key generation module output key and sends it to the receiving end. After receiving it, the receiving end uses the key generation module output key to decrypt the ciphertext and obtain the original stabilization and control service message.

[0072] In S3, the sending and receiving ends use the same FPGA to build a random key generation module. The sending end encrypts the original stable control service message with the key generated by this module and sends it. The receiving end uses the same key generation module to decrypt the received ciphertext and restore the original message. The key output of the key generation module at both ends is completely consistent and the operation is synchronized, which ensures accuracy and efficiency in the encryption and decryption process of the service message.

[0073] S4: In the state update phase of the key generation module, the sender randomly generates an update sequence number and sends it to the receiver covertly. When the frame sequence number of the stable control service message at both ends reaches the update sequence number, both ends will synchronously update the state of the key generation module with the random seed signal associated with the stable control service. Furthermore, the key generated by the key generation module has periodicity, and attackers can use its periodicity to crack the key generation module. By randomly and synchronously updating the state of the key generation module before the key generation reaches its period, the periodicity of key generation can be eliminated.

[0074] Furthermore, the synchronous update and stable control 2M service message structure includes a frame header, a frame sequence number, an information body, and a frame tail. The frame sequence number has a wide range of values ​​and changes cyclically. The status update of the key generation module of the sender and the receiver is synchronized through the frame sequence number. During the synchronous update, the sender generates a random number less than the frame sequence number change cycle in advance, and hides it as the value of the frame sequence number in the stable control service message frame and sends it to the receiver. The receiver parses the message frame, extracts the random number, and returns the confirmation information to the sender.

[0075] Furthermore, for random updates, when the sending and receiving ends need to perform status synchronization updates, the irregular stabilization and control service data in the stabilization and control 2M service message information body is extracted, and the information body is operated through the agreed hash algorithm to generate a random seed signal associated with the stabilization and control service to update the status of the key generation module.

[0076] Combination Figure 4 As shown, in S4, the random seed signal associated with the stabilization service is generated by obtaining a random stabilization service message. The stabilization service message structure includes a frame header, a frame sequence number, an information body, and a frame tail. The specific steps include: the key generation module extracts the information body that changes irregularly in the service message after each operation and divides it into segments. Each piece of information is calculated using the agreed hash algorithm, and the hash results of each segment are combined to generate a random seed signal.

[0077] For example, the information body may be evenly divided into a plurality of information segments, such as 4 information segments, 6 information segments, or 8 information segments.

[0078] Optionally, the random seed signal is filled into the key generation module from left to right. If the signal length is less than the key generation module length, zero is filled in the highest bit until the module is filled. If the signal length exceeds the key generation module length, the excess part is directly discarded. The generation of the random stability control service message seed signal is completed.

[0079] S5: In the 2M communication channel abnormal recovery phase, the sending end and the receiving end set the key generation module based on the initialization phase operation.

[0080] Furthermore, 2M communication anomaly refers to communication anomalies or interruptions that occur during 2M communication, including but not limited to device power-on, restart, etc.

[0081] Embodiment 2 of the present invention provides an encryption device for stabilizing high-real-time 2M communication, the device comprising:

[0082] The first module is used to generate a key according to the seed signal, and the generated key is used to encrypt and decrypt the stabilization control service message;

[0083] A second module is used to update the seed signal using a random seed signal associated with the stabilization service;

[0084] The third module is used to randomly generate an update sequence number and send it to the receiving end through a stable control service message;

[0085] When the frame sequence number of the stable control service message of the sending end and the receiving end reaches the update sequence number, the second module of the sending end and the receiving end transmits the updated seed signal to the first module, and the first module generates a new key for 2M communication according to the updated seed signal;

[0086] The fourth module is used to obtain the stabilization and control service message;

[0087] The fifth module is used to encrypt and / or decrypt the stabilization and control service message in the fourth module using the key generated by the first module.

[0088] Optionally, the first module is connected to the second module via a switch; when the frame sequence number of the stable control service message at the sending end and the receiving end does not reach the update sequence number, the switch is disconnected, the second module stores the stable control service message, and generates a random seed signal based on the stable control service message; when the frame sequence number of the stable control service message at the sending end and the receiving end reaches the update sequence number, the switch is closed, the seed signal of the first module is set to the seed signal of the initialization phase, and the random seed signal generated by the second module is transmitted to the first module to complete the update of the seed signal.

[0089] Combination Figure 5 As shown, Figure 5 The key generation module in is the first module, Figure 5 The memory module in is the second module. The memory module has the functions of updating, collecting, storing and processing stable control messages, and generates a random seed signal with stable control business relevance. Through the control of switch C (i.e., memory switch), the seed signal stored in the memory module is input into the key generation module to realize the update of the random seed signal.

[0090] When the key generation module has not reached its operating cycle, switch C is in the off state, the memory module operates independently, and updates, collects, and stores the business message content after each operation in real time. The previously saved business message data is obtained from the cache, and processed through pre-defined operation logic to generate a new random seed signal.

[0091] Before the key generation module reaches its operating cycle, switch C is closed, the memory module is connected to the key generation module, the key generation module is reset to the initial state, and the memory module generates a new random seed signal and fills it into the key generation module to complete the update of the seed signal.

[0092] Optionally, the first module and the second module are connected to the fourth module through the first switch, and the first module and the second module are connected to the fifth module through the second switch; when the frame sequence number of the stable control service message at the sending end and the receiving end does not reach the update sequence number, the first switch is connected to the second module, and the second switch is connected to the first module; when the frame sequence number of the stable control service message at the sending end and the receiving end reaches the update sequence number, the first switch is disconnected from the second module and connected to the first module, and the second switch is disconnected from the first module and connected to the second module.

[0093] Combination Figure 6 As shown, Figure 6 The key generation module 1 is the first module, the key generation module 2 is the second module, C1 is the first switch (i.e., the service message switch), and C2 is the second switch (i.e., the key output switch). In this embodiment, two identical key generation modules are used, one of which is responsible for generating keys to participate in the encryption and decryption operations of the stable control service messages, and the other is responsible for real-time updating, collecting and storing the service message content after each operation, generating seed signals and completing the update. By alternately controlling the connection status of the first switch C1 and the second switch C2 with the two key generation modules, the dynamic replacement of the functions of the two modules is realized, and the update of the random seed signal of the key generation module is completed.

[0094] When the key generation module has not reached the operation cycle, the first switch C1 is connected to the key generation module 2. The second switch C2 is connected to the key generation module 1. The key generation module 1 outputs a sequence for stabilizing the encryption and decryption operations of the service message. The key generation module 2 is responsible for real-time updating, collecting and storing the content of the service message after each operation, and generating a new random seed signal according to the predefined operation logic to update itself.

[0095] When the key generation module reaches the operation cycle, the first switch C1 is disconnected from the key generation module 2 and connected to the key generation module 1. The second switch C2 is disconnected from the key generation module 1 and connected to the key generation module 2. At this time, the functions of the key generation module 1 and the key generation module 2 are dynamically replaced to complete the update of the random seed signal of the key generation module.

[0096] In practical applications, the same encryption device for stabilizing high real-time 2M communication described in Example 2 is installed at the transmitting end and the receiving end in the power stabilization system to implement the encryption method for stabilizing high real-time 2M communication described in Example 1.

[0097] Embodiment 3 of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded into the processor, the encryption method for stabilizing high-real-time 2M communication described in Embodiment 1 is implemented.

[0098] Embodiment 4 of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the encryption method for stabilizing high-real-time 2M communication according to Embodiment 1 is implemented.

[0099] Compared with the prior art, the beneficial effects of the present invention include at least:

[0100] The present invention dynamically updates the key in operation based on the synchronization characteristics of stable 2M communication and utilizing the true randomness of the information content in the message without interrupting the current business message interaction; the present invention can continuously update the random key while ensuring that the communication service is not interrupted, without affecting the stable control service.

[0101] The random seed information of the present invention is extracted and generated from the message service information, without the need for additional interactive processes. At the same time, because the service information in the message changes randomly according to the actual operating status, the randomness of the key is guaranteed. The random key can be continuously updated while ensuring that the communication service is not interrupted, without affecting the stable control service. The key is generated through the true randomness of the information in the service message, which fully guarantees the security of the key.

[0102] The present invention eliminates the periodicity of key generation and key update by randomly updating the seed signal, greatly enhances the security of message encryption and decryption, effectively improves the security and stability of 2M communication in the power stabilization and control system, and improves the security and reliability of system operation and data transmission. In addition, by introducing FPGA to build a key generation module in the hardware circuit to encrypt and decrypt the message, high-speed communication in milliseconds is achieved, meeting the business requirements for high real-time performance.

[0103] The present disclosure may be a system, a method and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0104] A computer-readable storage medium may be a tangible device that can hold and store instructions used by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. More specific examples (a non-exhaustive list) of computer-readable storage media include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination of the above. The computer-readable storage medium used herein is not to be interpreted as a transient signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through a wire.

[0105] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.

[0106] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages, such as Smalltalk, C++, etc., and conventional procedural programming languages, such as "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer, partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect through the Internet). In some embodiments, by using the state information of the computer-readable program instructions to personalize an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit may execute the computer-readable program instructions, thereby implementing various aspects of the present disclosure.

[0107] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. An encryption method for stabilizing high-real-time 2M communication, applied to a power stabilization control system, the power stabilization control system includes a transmitting end and a receiving end, the transmitting end and the receiving end communicate via 2M, characterized in that: Includes the following: The sending and receiving ends construct the same random key generation module; In the initialization phase, the sender generates a timestamp based on the local synchronization clock and sends it to the receiver. The sender and receiver generate a seed signal based on the timestamp as the initial state of the key generation module. During the operation phase, the sending end encrypts the original stabilization and control service message through the key generation module output key and sends it to the receiving end. After receiving it, the receiving end uses the key generation module output key to decrypt the ciphertext and obtain the original stabilization and control service message; In the state update phase of the key generation module, the key generated by the key generation module has periodicity. Before the key generation reaches its period, the state of the key generation module is randomly and synchronously updated. The sending end generates a random number less than the frame number change period in advance as the update number and sends it to the receiving end covertly. When the frame number of the stabilization and control service message at both ends reaches the update number, the two ends will synchronously update the random seed signal associated with the stabilization and control service to update the state of the key generation module; Before the key generation reaches its cycle, the key generation module state is randomly updated, including: When the sending end and the receiving end need to update their status synchronously, the irregularly changing information body of the stabilization and control service message is extracted; the information body is operated through the agreed hash function to generate a random seed signal associated with the stabilization and control service to update the status of the key generation module.

2. The encryption method for stabilizing high-real-time 2M communication according to claim 1, characterized in that: The seed signal is generated by calculating the timestamp using a hash function agreed upon by the sender and the receiver in the application scenario. The hash functions include: SM3, SHA-1, SHA-256, or MD5.

3. The encryption method for stabilizing high real-time 2M communication according to claim 1, characterized in that: The stabilization service message includes a frame header, a frame sequence number, an information body, and a frame tail. The value of the frame sequence number changes cyclically, and the status update of the key generation module at the sender and the receiver is synchronized through the frame sequence number, including: The sending end generates a random number in advance that is smaller than the frame number change period, and hides it as the value of the frame number in the stabilization control service message frame and sends it to the receiving end; The receiving end parses the message frame, extracts the random number, and returns the confirmation information to the sending end.

4. The encryption method for stabilizing high real-time 2M communication according to claim 1, characterized in that: The random seed signal associated with the stabilization service is generated by operating the information body through the agreed hash function, including: Divide the information body into multiple information segments; Perform hash calculation on each information segment respectively to obtain multiple hash calculation results; Multiple hash calculation results are combined to generate a random seed signal associated with the stabilization service.

5. The encryption method for stabilizing high real-time 2M communication according to claim 4, characterized in that: Fill the random seed signal associated with the stabilization service into the key generation module in a preset order to update the state of the key generation module, including: Fill the random seed signals associated with the stabilization service into the key generation module in order from left to right; If the length of the random seed signal is less than the length of the key generation module, the key generation module is filled with zeros until the key generation module is fully filled; and / or, If the length of the random seed signal is greater than the length of the key generation module, the excess data after the key generation module is filled in the random seed signal is discarded.

6. The encryption method for stabilizing high-real-time 2M communication according to any one of claims 1 to 5, characterized in that: The encryption method further comprises: During the abnormal recovery phase of the 2M communication channel, the sender and the receiver set up the key generation module based on the operations in the initialization phase.

7. An encryption device for stabilizing high-real-time 2M communication using the encryption method for stabilizing high-real-time 2M communication as described in any one of claims 1 to 6, characterized in that: include: The first module is used to generate a key according to the seed signal, and the generated key is used to encrypt and decrypt the stabilization control service message; A second module is used to update the seed signal using a random seed signal associated with the stabilization service; The third module is used to randomly generate an update sequence number and send it to the receiving end through a stable control service message; When the frame sequence number of the stable control service message of the sending end and the receiving end reaches the update sequence number, the second module of the sending end and the receiving end transmits the updated seed signal to the first module, and the first module generates a new key for 2M communication according to the updated seed signal; The fourth module is used to obtain the stabilization and control service message; The fifth module is used to encrypt and / or decrypt the stabilization and control service message in the fourth module using the key generated by the first module.

8. The encryption device for stabilizing high real-time 2M communication according to claim 7, characterized in that: The first module is connected to the second module via a switch; When the frame sequence number of the stabilization and control service message at the transmitting end and the receiving end does not reach the update sequence number, the switch is disconnected, the second module stores the stabilization and control service message, and generates a random seed signal according to the stabilization and control service message; When the frame number of the stable control service message at the sending end and the receiving end reaches the update number, the switch is closed, the seed signal of the first module is set to the seed signal of the initialization phase, and the random seed signal generated by the second module is transmitted to the first module to complete the update of the seed signal.

9. The encryption device for stabilizing high real-time 2M communication according to claim 7, characterized in that: The first module and the second module are connected to the fourth module via a first switch, and the first module and the second module are connected to the fifth module via a second switch; When the frame sequence numbers of the stabilization service messages at the transmitting end and the receiving end do not reach the update sequence number, the first switch is connected to the second module, and the second switch is connected to the first module; When the frame sequence numbers of the stable control service messages at the transmitting end and the receiving end reach the update sequence numbers, the first switch is disconnected from the second module and connected to the first module, and the second switch is disconnected from the first module and connected to the second module.

10. An electronic device, comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the encryption method for stabilizing high-real-time 2M communication according to any one of claims 1 to 6.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the encryption method for stabilizing high-real-time 2M communication described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Security control system 2M communication encryption method and device

    CN113541955A

  • Encryption and decryption processing method and device for dynamically updating secret key of security chip

    CN115529133A

  • Intelligent substation communication message integrity protection method

    CN108494722A

  • Message key generation method and device, file encryption method and device, file decryption method and device, equipment and medium

    CN115499118A