Power grid data aggregation method, system, electronic device and storage medium
By introducing trusted certification agencies, smart meters, edge gateways, control centers and management servers into the power grid system, and using encryption and homomorphic ciphertext conversion technology, the data security risks in the power grid system are solved, and the high security and fine-grained analysis capabilities of data are achieved.
Patent Information
- Application Number
- CN202411517969.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-28
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-10-28
AI Technical Summary
In the prior art, the power grid system has a major security risk. Attackers can obtain data in the power grid system channel through illegal means or perform tampering operations, resulting in active or passive attacks.
A power grid data aggregation method is adopted to initialize system parameters and key distribution through a trusted authentication agency. The smart meter encrypts the power data and sends it to the edge gateway. The edge gateway converts the symmetrical ciphertext into homomorphic ciphertext and sends it to the control center. The control center conducts statistical analysis and sends the analysis results to the management server. The management server adjusts the power grid data based on the analysis results.
The data during communication is encrypted through encryption algorithms to ensure the security of the data and support fine-grained analysis of dense data, which improves the robustness of the system and solves the security risks existing in the existing technology.
Smart Images

Figure CN119416238B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data aggregation, and in particular, to a power grid data aggregation method, system, electronic device, and storage medium. Background Art
[0002] With the wide application of technologies such as artificial intelligence, 5G communication, and big data in various fields, smart grids are gradually replacing traditional grids to provide efficient and reliable uninterrupted power supply for households and enterprises. As the next-generation power grid, smart grids utilize advanced information and communication technologies to achieve two-way communication between users and service providers, and efficiently coordinate the production, distribution, transmission, and control of power resources.
[0003] In the prior art, attackers can easily obtain the data transmitted in the power grid system channel or perform corresponding tampering operations through illegal means, thereby launching active attacks or passive attacks, posing significant security risks. Summary of the Invention
[0004] In view of this, this application provides a power grid data aggregation method, system, electronic device, and storage medium to solve the problem of significant security risks in the prior art.
[0005] To achieve the above object, this application provides the following technical solutions:
[0006] The first aspect of this application discloses a power grid data aggregation method, which is applied to a power grid data aggregation system. The power grid data aggregation system includes a management server, a trusted certification authority, a control center, smart meters, and edge gateways. Among them, the power grid data aggregation method includes:
[0007] The trusted certification authority performs system parameter initialization and key distribution;
[0008] The smart meters encrypt the collected power data to obtain the symmetric ciphertext of the power data, and send the symmetric ciphertext of the power data to the edge gateways according to a preset time period;
[0009] The edge gateways convert the symmetric ciphertext into a homomorphic ciphertext and send it to the control center;
[0010] The control center performs statistical analysis on the homomorphic ciphertext, generates an analysis result, and sends it to the management server;
[0011] The management server adjusts the power grid data according to the analysis result.
[0012] Optionally, in the above method, when the trusted certification authority performs system parameter initialization and key distribution, it includes:
[0013] Determine the maximum circuit depth based on the set of fine-grained analysis operation types announced by the management server;
[0014] Generate a key through a homomorphic encryption algorithm and send the key to each of the smart meters.
[0015] Optionally, in the above solution, the smart meter encrypts the collected power data to obtain a symmetric ciphertext of the power data, including:
[0016] Collect the original power data and perform compression processing;
[0017] Encrypt the compressed power data through a symmetric encryption algorithm to obtain the symmetric ciphertext.
[0018] Optionally, in the above method, the edge gateway converts the symmetric ciphertext into a homomorphic ciphertext, including:
[0019] Determine whether there are faulty smart meters;
[0020] If it is determined that there are faulty smart meters, perform fault recovery for the faulty smart meters;
[0021] If it is determined that there are no faulty smart meters, perform aggregation verification on the symmetric ciphertext;
[0022] If the aggregation verification passes, use the homomorphic encryption algorithm to convert the symmetric ciphertext into a homomorphic ciphertext.
[0023] Optionally, in the above method, after the smart meter encrypts the collected power data to obtain a symmetric ciphertext of the power data, it further includes:
[0024] Perform power expansion on the homomorphic ciphertext based on the set of fine-grained analysis operation types announced by the management server.
[0025] Optionally, in the above method, the control center performs statistical analysis on the homomorphic ciphertext to generate an analysis result, including:
[0026] Perform legality verification on the homomorphic ciphertext;
[0027] If the verification passes, perform homomorphic addition on the homomorphic ciphertext to obtain an aggregation vector;
[0028] Decrypt the aggregation vector to obtain a decryption result vector;
[0029] Based on the decryption result vector, perform processing according to a preset processing strategy to obtain analysis results under different processing strategies; wherein, the processing strategies include basic statistic calculation, billing strategy correction, ladder pricing, and deep learning.
[0030] The management server adjusts the power grid data according to the analysis results, including:
[0031] For the analysis results calculated from the basic statistics, backing up the analysis results calculated from the basic statistics to the power consumption database;
[0032] For the analysis results of the billing policy correction, correcting the billing policy according to the analysis results of the billing policy correction;
[0033] For the analysis results of the tiered pricing, backing up the analysis results of the tiered pricing in the pricing database and adjusting the pricing weights according to the usage of various power resources in the current system;
[0034] For the analysis results of the deep learning, performing a gradient descent algorithm according to the analysis results of the deep learning to optimize the pre-constructed model.
[0035] A second aspect of the present application discloses a power grid data aggregation system, which includes a management server, a trusted certification authority, a control center, smart meters, and edge gateways;
[0036] The trusted certification authority is used for system parameter initialization and key distribution;
[0037] The smart meters are used for encrypting the collected power data to obtain the symmetric ciphertext of the power data, and sending the symmetric ciphertext of the power data to the edge gateways according to a preset time period;
[0038] The edge gateways are used for converting the symmetric ciphertext into a homomorphic ciphertext and sending it to the control center;
[0039] The control center is used for statistically analyzing the homomorphic ciphertext, generating analysis results, and sending them to the management server;
[0040] The management server is used for adjusting the power grid data according to the analysis results.
[0041] A third aspect of the present application discloses an electronic device, including:
[0042] One or more processors;
[0043] A storage device on which one or more programs are stored;
[0044] When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method described in any one of the first aspect of the present invention.
[0045] A fourth aspect of the present application discloses a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any one of the first aspect of the present invention is implemented.
[0046] As can be seen from the above technical solution, a power grid data aggregation method provided by the present application is applied to a power grid data aggregation system. Among them, a trusted certification authority performs system parameter initialization and key distribution. The smart meter encrypts the collected power data to obtain a symmetric ciphertext of the power data, and sends the symmetric ciphertext of the power data to the edge gateway according to a preset time period. The edge gateway converts the symmetric ciphertext into a homomorphic ciphertext and sends it to the control center. The control center performs statistical analysis on the homomorphic ciphertext, generates an analysis result, and sends it to the management server. The management server adjusts the power grid data according to the analysis result. It can be seen that the present application uses an encryption algorithm to encrypt the data in the communication process, ensures the security of the data, and supports fine-grained analysis of the ciphertext data, improving the robustness of the system. Solve the problem of large security risks existing in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0048] Figure 1 It is a flowchart of a power grid data aggregation method disclosed in an embodiment of the present application;
[0049] Figure 2 It is a schematic diagram of a power grid data aggregation system disclosed in an embodiment of the present application;
[0050] Figure 3 It is a comparison diagram of the computing overhead of the power grid data aggregation method disclosed in an embodiment of the present application and the prior art on resource-constrained terminal devices;
[0051] Figure 4 It is a comparison diagram of the computing overhead of the power grid data aggregation method disclosed in an embodiment of the present application and the prior art on the control center;
[0052] Figure 5 It is a comparison diagram of the communication overhead between the smart meter and the edge device side of the power grid data aggregation method disclosed in an embodiment of the present application and the prior art;
[0053] Figure 6 It is a comparison diagram of the communication overhead between the edge device and the control center side of the power grid data aggregation method disclosed in an embodiment of the present application and the prior art;
[0054] Figure 7 Schematic diagram of an electronic device disclosed in an embodiment of the present application. Specific embodiments
[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0056] In the present application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0057] Moreover, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0058] As can be seen from the background technology, in the prior art, attackers can easily obtain the data transmitted in the power grid system channel or perform corresponding tampering operations through illegal means, thereby launching active attacks or passive attacks, posing a relatively large security risk.
[0059] In view of this, the present application provides a power grid data aggregation method, system, electronic device and storage medium to solve the problem of relatively large security risks in the prior art.
[0060] An embodiment of the present application provides a power grid data aggregation method, which is applied to a power grid data aggregation system, as Figure 1 shown, and specifically includes:
[0061] S101. A trusted certification authority performs system parameter initialization and key distribution.
[0062] It should be noted that the power grid data aggregation system can be referred to Figure 2 , and includes a management server, a trusted certification authority, a control center, smart meters, and edge gateways.
[0063] The trusted certification authority is used to initialize system parameters and distribute keys;
[0064] The smart meter is used to encrypt the collected power data to obtain the symmetric ciphertext of the power data, and send the symmetric ciphertext of the power data to the edge gateway according to a preset time period;
[0065] The edge gateway is used to convert the symmetric ciphertext into a homomorphic ciphertext and send it to the control center;
[0066] The control center is used to perform statistical analysis on the homomorphic ciphertext, generate an analysis result, and send it to the management server;
[0067] The management server is used to adjust the power grid data according to the analysis result.
[0068] Among them, the trusted certification authority is responsible for initializing system parameters and distributing keys, and at the same time assisting the management server to distribute fine-grained analysis tasks, and assisting the smart meter to generate and distribute zero and random numbers (performed in the offline stage, without establishing a secure channel between smart meters). After completing the above parameter generation and distribution operations in the initialization stage, the trusted certification authority goes offline and only comes back online when the system topology structure undergoes a huge adjustment to complete key distribution and the regeneration of zero and random numbers.
[0069] Optionally, in another embodiment of the present application, an implementation manner of step S101 may include:
[0070] Determine the maximum circuit depth based on the set of fine-grained analysis operation types announced by the management server.
[0071] Generate a key through a homomorphic encryption algorithm and send the key to each smart meter.
[0072] It should be noted that the initialization of system parameters and key distribution mainly includes a fine-grained operation negotiation sub-stage, a related parameter and key generation sub-stage, and a random number distribution and sharing sub-stage.
[0073] (1) Fine-grained operation negotiation sub-stage: The management server determines the data analysis type Among them, MEAN, QMEAN, HMEAN, VAR, STD, BSC, DP, and DL represent the arithmetic mean, quadratic mean, harmonic mean, variance, standard deviation, and three types of advanced statistical requirements: Billing Strategy Correction (BSC), Differential Pricing (DP), and Deep Learning (DL), respectively. The trusted certification authority is generally considered a completely trusted institution, responsible for generating and broadcasting public parameters during the initialization phase, generating encryption key pairs and signature key pairs, and distributing them to the corresponding entities through a secure channel. The trusted certification authority determines the maximum required circuit depth according to the set of data analysis types selected by the management server. Where S represents the set of fine-grained data analysis types published by the management server, and S i is a subset of S, L represents the required circuit depth, and then broadcasts the type set S to the edge gateway.
[0074] (2) Related parameter and key generation sub-phase:
[0075] (a) The trusted certification authority generates the corresponding parameters of the BGV algorithm PP1 = {params1, params2,..., params j : = (R, d j , n j , q j , χ j , N j ) ← E.Setup(1 λ , 1 (j+1)·μ )}, where PP1 represents the necessary system parameters of the BGV algorithm, and E.Setup(1 λ , 1 (j+1)·μ ) represents the initialization setting function, λ represents the security parameter received by the algorithm, 1 λ represents the length of the random seed bit, j represents the upper limit of the number of homomorphic operations, R = Z[x] / (x d +1) represents the domain, d j represents the degree of the ring, n j represents the dimension, q j represents the odd modulus, χ j represents the noise distribution, and N j = n j ·polylog(q j );
[0076] (b) Pasta corresponding parameters Among them, the parameters represent the S-boxes S feistel (·) and S cube (·) required to generate the PASTA-π permutation, as well as the affine mapping Aj,N,i (·) and sequential matrix
[0077] (c) Parameters PP3 related to sequential aggregation signature based on FALCON = {enc, dec, H1, H2, Order SM , Order EG , Order S ′ M}, where enc represents the encoding function, dec represents the decoding function, H1, H2 represent two types of hash functions, Order SM represents the signature aggregation order, Order S ′ M represents the alternate signature order when the system fails;
[0078] (d) Public parameters required for the threshold secret sharing algorithm where p represents a prime number, n represents the number of all participating parties in the secret sharing, represents n different random vectors;
[0079] (e) Data dimension conversion parameters PP5 = {q, Q, θ}, where q represents a prime number, Q represents the product of k pairs of relatively prime prime numbers, and θ represents a vector;
[0080] (f) Threshold of the number of newly added users in the user registration stage PP6 = K;
[0081] The trusted certification authority generates BGV fully homomorphic public and private key pairs where represents the public key, represents the private key, Pasta symmetric key K SE , perform homomorphic operations on the symmetric key and send the ciphertext C KHE to the edge gateway, generate the meter aggregation signature and verification public and private key pairs Generate the gateway aggregation signature and verification public and private key pairs
[0082] (3) Random number distribution and sharing sub - stage, as Figure 4 shown, the random number distribution and sharing sub - stage included in the initialization stage of the present invention includes the following steps:
[0083] Step 1, the control center generates corresponding random numbers for each set of meters in different regions and sends them to the trusted certification authority;
[0084] Step 2, the trusted certification authority receives the random numbers and counts the number of meters n in the region SM , performs random number splitting, and the calculation formula is as follows:
[0085]
[0086] The electricity meter receives the random number r ij as the secret to be shared;
[0087] Step 3: The smart electricity meter selects a random integer to construct a vector a and generates a shared vector that satisfies the following calculation formula:
[0088] ss i,j =(<I (j) , a> + e i ) mod p;
[0089] where ss i,j represents the secret fragment sent by the electricity meter SM i to the electricity meter SM j , I (j) represents a random vector, and e i represents noise;
[0090] Step 4: The electricity meters complete the sending and receiving of their respective random numbers, receive their own shared secret shares, and store them in the database.
[0091] S102: The smart electricity meter encrypts the collected power data to obtain the symmetric ciphertext of the power data, and sends the symmetric ciphertext of the power data to the edge gateway according to a preset time period.
[0092] It should be noted that the smart electricity meter encrypts the collected power data to obtain the symmetric ciphertext of the power data, and regularly sends the symmetric ciphertext of the power data to the edge gateway at a preset time period, so that the edge gateway can report the encrypted multi-dimensional power data to the control center.
[0093] Optionally, in another embodiment of the present application, an implementation manner of step S102 may include:
[0094] Collect the original power data and perform compression processing.
[0095] Encrypt the compressed power data through a symmetric encryption algorithm to obtain the symmetric ciphertext.
[0096] It should be noted that the smart electricity meter collects the original power data and compresses it into one-dimensional data. The compression operation is performed through the following formula:
[0097] m i = d i,1 θ1 + d i,2 θ2 + … + d i,k θ k mod Q;
[0098] where d i =(d i,1, d i,2 , …, d i,k ) represents the smart meter SM i The original power data collected, θ i =(θ1, θ2, …, θ k ) represents a vector;
[0099] Subsequently, the smart meter uses random numbers for data masking to generate m i = m i + r ij .
[0100] Then the processed data is encoded into a vector to be encrypted, and the PASTA symmetric encryption algorithm is executed to generate a ciphertext vector
[0101] Finally, referring to the signature aggregation order, the corresponding signature private key is received to generate a signature σ, and the following data packet is formed by encapsulation:
[0102] D i = C i || T i || σ;
[0103] where || represents the concatenation relationship, and T i represents the current time.
[0104] S103. The edge gateway converts the symmetric ciphertext into a homomorphic ciphertext and sends it to the control center.
[0105] It should be noted that the edge gateway acts as an intermediate device between the smart meter and the control center, receives the symmetric ciphertext uploaded by the smart meter, and performs a hybrid homomorphic encryption operation to convert it into a homomorphic ciphertext. The homomorphic ciphertext is evaluated according to the evaluation task distributed by the management server in the initialization phase, which is convenient for subsequent statistical analysis.
[0106] Optionally, in another embodiment of the present application, an implementation manner of step S103 may include:
[0107] Determine whether there is a faulty smart meter.
[0108] If it is determined that there is a faulty smart meter, then perform fault recovery for the faulty smart meter.
[0109] If it is determined that there is no faulty smart meter, then perform aggregation verification on the symmetric ciphertext.
[0110] If the aggregation verification passes, then use the homomorphic encryption algorithm to convert the symmetric ciphertext into a homomorphic ciphertext.
[0111] It should be noted that the edge gateway processes the data sent by the smart meter, specifically including: a fault recovery sub-phase and a conversion evaluation sub-phase.
[0112] Fault recovery sub-phase:
[0113] Step 1: If the edge gateway does not receive all the data packets sent by the electric meters, it is determined that some smart electric meters have failed, and the system enters the fault recovery sub-phase;
[0114] Step 2: The edge gateway broadcasts the set S of the identities of the faulty electric meters. After receiving the identity identifiers, the normally operating electric meters execute the CVP approximation algorithm on the full-rank lattice L MI,N,p and the target vector t' to recover the corresponding secret ss j ;
[0115] The lattice-based secret sharing algorithm approximately solves the CVP problem through the Babai nearest plane algorithm to restore the shared secret. By generating public parameters, generating shared secrets, and defining a full-rank square matrix, the CVP approximation algorithm is executed on the lattice and the target vector to achieve the purpose of recovering the secret.
[0116] Step 3: After the edge gateway completes the restoration of the random numbers corresponding to all the faulty electric meters, it encrypts the sum result of the random numbers using the fully homomorphic encryption public key and stores the ciphertext, and calculates according to the following formula:
[0117]
[0118] where C FTHE represents the ciphertext, FHE.Enc(·) represents the encryption algorithm in the BVG fully homomorphic encryption algorithm, PP1 represents the system parameters necessary for the BGV algorithm, represents the public key of the BVG fully homomorphic algorithm, represents that the edge gateway completes the restoration of the random numbers corresponding to all the faulty electric meters.
[0119] Conversion evaluation sub-phase:
[0120] Step 1: If there is no fault in the gateway control area or the fault recovery is successfully completed, the system enters the conversion evaluation sub-phase;
[0121] Step 2: The edge gateway receives the sequential aggregate signature uploaded by the normal electric meter cluster, selects the corresponding public key set and the corresponding data packet set, and inputs them into the verification function to execute the signature generation algorithm in reverse order to obtain x0←dec(z0,α1), where x0←0 n ,α1←0 n-k , x0 represents the result of the decoding function generated by the aggregate signature algorithm in the sequential aggregate signature based on FALCON. If x0 = 0 n holds, it indicates that the aggregate verification passes;
[0122] Step 3. If the verification is passed, encrypt the received message using the fully homomorphic public key, and execute the following algorithm to generate the ciphertext:
[0123]
[0124] Step 4. Determine that the decryption evaluation function is the Pasta decryption algorithm, and call the homomorphic evaluation function to perform the decryption evaluation operation on the fully homomorphic ciphertext:
[0125]
[0126] where FHE.Eval(·) represents the decryption evaluation operation, represents the BVG fully homomorphic public key, and Dec KHE (·) represents the decryption algorithm, represents the fully homomorphic ciphertext;
[0127] Step 5. If a failure occurred in the previous stage, the final encrypted result should also be added with the ciphertext corresponding to the missing random number to generate the final ciphertext HEC i = HEC i + C FTHE .
[0128] Optionally, in another embodiment of the present application, the above step S103 may further include:
[0129] Performing power expansion on the homomorphic ciphertext based on the set of fine-grained analysis operation types announced by the management server.
[0130] It should be noted that the edge gateway determines the specific expansion power required according to the set S of fine-grained analysis types broadcast by the management server during the initialization stage. Taking square expansion as an example, the description is as follows:
[0131] Step 1. The edge gateway successfully obtains the homomorphic ciphertext HEC i of the normal working smart meter data, and calls the homomorphic multiplication operation to perform square expansion on the ciphertext. The formula is as follows:
[0132]
[0133] where FHE.Mult(·) represents the homomorphic multiplication operation;
[0134] Step 2. The edge gateway obtains the power expansion result and packs it to form the ciphertext processing result, and submits it according to the following formula:
[0135]
[0136] Step 3. The edge gateway calls the signature algorithm according to the aggregation order and in combination with its own signature private key to generate the sequential aggregation signature σ′, and the gateway constructs the data packet D j = PCj ||T j ||σ′。
[0137] S104. The control center performs statistical analysis on the homomorphic ciphertext, generates an analysis result, and sends it to the management server.
[0138] It should be noted that the control center performs statistical analysis on the homomorphic ciphertext, generates an analysis result, and sends it to the management server to evaluate the basic statistics and advanced analysis results, providing support for the decision-making of the management server.
[0139] Optionally, in another embodiment of the present application, an implementation manner of the above step S104 may include:
[0140] Perform a legality verification on the homomorphic ciphertext.
[0141] If the verification passes, perform homomorphic addition on the homomorphic ciphertext to obtain an aggregation vector.
[0142] Decrypt the aggregation vector to obtain a decryption result vector.
[0143] Based on the decryption result vector, perform processing according to a preset processing strategy to obtain analysis results under different processing strategies; wherein, the processing strategies include basic statistic calculation, billing strategy correction, step pricing, and deep learning.
[0144] It should be noted that the control center receives the data packets uploaded by the edge gateway and sequentially verifies the legality of the time stamp and the signature;
[0145] If the above verification passes, perform homomorphic addition on the ciphertext to obtain the final aggregation vector
[0146] The control center performs a decryption operation to obtain a decryption result vector Calculate through the following formula:
[0147]
[0148] where represents the final aggregation vector, s Lmax represents the maximum value of the required circuit depth under the vector s;
[0149] Perform random number elimination and use the Chinese Remainder Theorem to restore any-dimensional data d l = E modq i , 1 ≤ l ≤ k.
[0150] The control center obtains the high-power aggregation result of any-dimensional data and performs the following fine-grained analysis operations:
[0151] Basic statistic calculation: For data dimension u, the control center combines d u , to calculate the basic statistic through the following formula:
[0152] MEAN = d u / n SM
[0153]
[0154] Billing policy correction: For s ≥ 3 billing policies, the control center decrypts to obtain the corresponding electricity data billing results M sum,1 , M sum,2 ,..., M sum,s , calculates the sum of squares between groups and the sum of squares within groups for hypothesis testing and evaluation; after the evaluation, the control center compares the evaluation result with the threshold F C and sends the correction result D CC =(R price ) to the management server. The calculation formula is as follows:
[0155]
[0156] Step - by - step pricing: The control center decrypts and packages the step - by - step pricing result D cc =(p1,..., p k ) and sends it to the management server for subsequent adjustment;
[0157] Deep learning: After the control center completes the restoration of the data UD u corresponding to dimension u, it performs Taylor expansion on the function to be evaluated and constructs an approximate result, and packages all the approximate results D CC =(Eva1,..., Eva k ) and sends them to the management server for subsequent adjustment.
[0158] S105. The management server adjusts the power grid data according to the analysis result.
[0159] It should be noted that the management server is connected to the control center. In the initialization stage, it will issue fine - grained analysis tasks, receive the analysis results uploaded by the control center, and adjust the power grid data according to the analysis results, such as performing electricity price adjustment and other operations. The management server is connected to two secure databases, namely the electricity consumption database and the pricing database, which are used to save the regional electricity consumption records and billing records respectively, to achieve the macro - control of the overall electricity consumption of the large - scale smart grid.
[0160] Optionally, in another embodiment of the present application, an implementation manner of the above step S105 may include:
[0161] For the analysis results of basic statistic calculation, back up the analysis results of basic statistic calculation to the power consumption database.
[0162] For the analysis results of billing policy correction, correct the billing policy according to the analysis results of billing policy correction.
[0163] For the analysis results of tiered pricing, back up the analysis results of tiered pricing in the pricing database, and adjust the pricing weights according to the usage of various power resources in the current system.
[0164] For the analysis results of deep learning, execute the gradient descent algorithm according to the analysis results of deep learning to optimize the pre-constructed model.
[0165] It should be noted that the management server makes corresponding adjustments according to the analysis results uploaded by the control center. If the management server receives the analysis results of basic statistic calculation, it backs up the analysis results in the power consumption database, and the arithmetic mean and variance are used as important references for measuring the regional power consumption situation.
[0166] If the management server receives the analysis results of billing policy correction, it corrects the billing policy according to the comparison result between the evaluation value uploaded by the control center and the threshold F C and broadcasts a more reasonable billing policy PS new .
[0167] If the management server receives the analysis results of tiered pricing, it backs up the current pricing results in the pricing database and adjusts the pricing weights according to the usage of various power resources in the current system, and broadcasts the new tiered pricing weights (ω′1,...,ω′ k ).
[0168] If the management server receives the analysis results of deep learning, it executes the gradient descent algorithm according to the analysis results of deep learning to optimize the pre-constructed model to improve the model accuracy.
[0169] In a power grid data aggregation method provided by this application, it is applied to a power grid data aggregation system. Among them, a trusted certification authority initializes system parameters and distributes keys. The smart meter encrypts the collected power data to obtain the symmetric ciphertext of the power data, and sends the symmetric ciphertext of the power data to the edge gateway according to a preset time period. The edge gateway converts the symmetric ciphertext into a homomorphic ciphertext and sends it to the control center. The control center performs statistical analysis on the homomorphic ciphertext, generates analysis results, and sends them to the management server. The management server adjusts the power grid data according to the analysis results. It can be seen that this application uses an encryption algorithm to encrypt the data in the communication process, ensures the security of the data, and supports fine-grained analysis of the ciphertext data, improving the robustness of the system. It solves the problem of large security risks in the existing technology.
[0170] In another embodiment of the present application, the design realizes the dynamic change of the system topology in the user dynamic joining and revocation phases:
[0171] (1) Dynamic joining: When a new user registers, the trusted certification authority needs to be awakened to complete the distribution of public parameters and keys. The dynamic joining operation is divided into the following steps:
[0172] Step 1, the trusted certification authority simultaneously sends a random number r′ to the new user and the control center through a secure channel ik , and the control center securely records the random number corresponding to the newly registered user and eliminates it during the final data restoration process;
[0173] Step 2, if the number of newly registered users exceeds the threshold K, the entire system re-executes the zero-sum random number allocation;
[0174] (2) Dynamic revocation:
[0175] Step 1, the electricity meter to be revoked sends a data packet containing the Pasta symmetric encryption ciphertext and timestamp to the edge gateway
[0176] Step 2, the edge gateway performs ciphertext type conversion and then forwards it to the control center;
[0177] Step 3, the control center decrypts to restore the random number r jj and removes it from its own database.
[0178] To verify the usability of the present invention, the following will show and explain the test results and related operation overheads of the designed privacy-preserving data aggregation protocol under simulation. The relevant configurations are shown in Table 1:
[0179] Table 1
[0180]
[0181] As Figure 3 shown, in the present invention, the smart electricity meter only needs to perform one Pasta symmetric encryption operation and one FALCON signature operation to generate an ordered aggregation signature. The calculation overhead on the electricity meter side is much smaller than that of other mainstream schemes such as MMSDA, and it is more suitable for smart electricity meter devices widely deployed in resource-constrained environments in large-scale smart grids.
[0182] As Figure 4 shown, the control center of the present invention needs to execute one FALCON aggregation signature verification algorithm, and then a total of P·n MD times of BGV homomorphic addition operations and P times of BGV homomorphic decryption operations; although the overhead of the designed scheme on the control center side is relatively large compared with other schemes, this scheme realizes high data availability at the cost of less computational overhead growth.
[0183] As Figure 5 and Figure 6 shown, in the designed solution of the present invention, the terminal device only needs to transmit the symmetric ciphertext and the post-quantum signature to the middle-layer gateway, and the communication cost between the electric meter and the gateway is relatively low. Although this communication cost is higher than the mainstream solution that uses the traditional public key cryptosystem to implement data encryption operations, the proposed solution has anti-quantum characteristics and higher security. The solution designed by the present invention concentrates a large amount of data analysis operations on the middle-layer device, and provides support for fine-grained analysis operations in the lattice at the cost of a large communication overhead between the gateway and the control center, improving the availability of power data.
[0184] The present invention combines a hybrid homomorphic encryption system and data masking to better ensure the confidentiality and privacy of the collected and aggregated power consumption data. The fine-grained analysis operations performed by the middle-layer device are based on homomorphic ciphertexts, and the analysis conclusions do not disclose any confidential information of the power consumption data. Sensitive data is masked by random masks. Under the assumption that smart meters cannot communicate directly during the execution of the solution, other smart meters and external adversaries cannot obtain the data masks, and passive adversaries cannot restore the masks without collecting a specified number of secrets. The present invention uses the Pasta algorithm and the BGV algorithm together to form a hybrid homomorphic encryption system, thereby ensuring the confidentiality of power data. In addition, the solution uses the sequential aggregation signature based on FALCON to ensure the authenticity and integrity of user power data, and can resist key recovery attacks, signature forgery attacks, hybrid attacks combining the meet-in-the-middle algorithm and the key recovery algorithm, and algebraic attacks against the rich algebraic structure of FALCON. The present invention introduces a timestamp mechanism to resist active attacks such as tampering attacks, replay attacks, and man-in-the-middle attacks, and at the same time has a certain fault tolerance characteristic and supports quick recovery from failures.
[0185] Another embodiment of the present application also provides an electronic device, as Figure 7 shown, specifically including:
[0186] One or more processors 701.
[0187] A storage device 702, on which one or more programs are stored.
[0188] When the one or more programs are executed by the one or more processors 701, the one or more processors 701 are caused to implement the method according to any one of the above embodiments.
[0189] Another embodiment of the present application also provides a computer storage medium, on which a computer program is stored, wherein the computer program, when executed by a processor, implements the method according to any one of the above embodiments.
[0190] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for a system or system embodiment, since it is basically similar to a method embodiment, the description is relatively simple. For the relevant parts, reference can be made to the description of the method embodiment. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.
[0191] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0192] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for aggregating power grid data, characterized in that: Applied to a power grid data aggregation system, the power grid data aggregation system includes a management server, a trusted authentication agency, a control center, a smart meter, and an edge gateway; wherein the power grid data aggregation method includes: The trusted certification authority performs system parameter initialization and key distribution; The smart meter encrypts the collected power data to obtain a symmetric ciphertext of the power data, and sends the symmetric ciphertext of the power data to the edge gateway according to a preset time period; The edge gateway converts the symmetric ciphertext into a homomorphic ciphertext and sends it to the control center; The control center performs statistical analysis on the homomorphic ciphertext, generates analysis results, and sends them to the management server; wherein the analysis results include analysis results of basic statistical quantity calculation, analysis results of billing policy modification, analysis results of tiered pricing, and analysis results of deep learning; The management server adjusts the power grid data according to the analysis result; The management server adjusts the power grid data according to the analysis result, including: With respect to the analysis result of the basic statistical quantity calculation, backing up the analysis result of the basic statistical quantity calculation into the power consumption database; For the analysis result of the billing policy revision, the billing policy is revised according to the analysis result of the billing policy revision; For the analysis result of the step-by-step pricing, the analysis result of the step-by-step pricing is backed up in a pricing database, and the pricing weight is adjusted according to the usage of various types of power resources in the current system; With respect to the analysis results of the deep learning, a gradient descent algorithm is executed according to the analysis results of the deep learning to optimize the pre-built model.
2. The method according to claim 1, characterized in that The trusted authentication authority performs system parameter initialization and key distribution, including: Determining a maximum circuit depth based on a set of fine-grained analysis operation types published by the management server; A key is generated by a homomorphic encryption algorithm and the key is sent to each of the smart meters.
3. The method according to claim 1, characterized in that The smart meter encrypts the collected power data to obtain a symmetric ciphertext of the power data, including: Collect raw power data and compress it; The compressed power data is encrypted using a symmetric encryption algorithm to obtain the symmetric ciphertext.
4. The method according to claim 1, characterized in that The edge gateway converts the symmetric ciphertext into a homomorphic ciphertext, including: Determine if there is a faulty smart meter; If a faulty smart meter is determined, fault recovery is performed on the faulty smart meter; If it is determined that there is no faulty smart meter, performing aggregate verification on the symmetric ciphertext; If the aggregate verification passes, the symmetric ciphertext is converted into homomorphic ciphertext using a homomorphic encryption algorithm.
5. The method according to claim 1, characterized in that The smart electric meter encrypts the collected power data to obtain the symmetric ciphertext of the power data, and further includes: The homomorphic ciphertext is quadratically expanded based on a set of fine-grained analysis operation types published by the management server.
6. The method according to claim 1, characterized in that The control center performs statistical analysis on the homomorphic ciphertext to generate analysis results, including: Verifying the legitimacy of the homomorphic ciphertext; If the verification is successful, homomorphic addition is performed on the homomorphic ciphertext to obtain an aggregate vector; Decrypting the aggregate vector to obtain a decryption result vector; Based on the decryption result vector, processing is performed according to a preset processing strategy to obtain analysis results under different processing strategies; wherein the processing strategies include basic statistical quantity calculation, billing strategy modification, tiered pricing and deep learning.
7. A power grid data aggregation system, characterized in that: The power grid data aggregation system includes a management server, a trusted authentication agency, a control center, a smart meter, and an edge gateway; The trusted authentication authority is used to perform system parameter initialization and key distribution; The smart meter is used to encrypt the collected power data to obtain a symmetric ciphertext of the power data, and send the symmetric ciphertext of the power data to the edge gateway according to a preset time period; The edge gateway is used to convert the symmetric ciphertext into a homomorphic ciphertext and send it to the control center; The control center is used to perform statistical analysis on the homomorphic ciphertext, generate analysis results, and send them to the management server; wherein the analysis results include analysis results of basic statistical quantity calculation, analysis results of billing policy modification, analysis results of tiered pricing, and analysis results of deep learning; The management server is used to adjust the power grid data according to the analysis result; Wherein, the management server is also used for: With respect to the analysis result of the basic statistical quantity calculation, backing up the analysis result of the basic statistical quantity calculation into the power consumption database; For the analysis result of the billing policy revision, the billing policy is revised according to the analysis result of the billing policy revision; For the analysis result of the step-by-step pricing, the analysis result of the step-by-step pricing is backed up in a pricing database, and the pricing weight is adjusted according to the usage of various types of power resources in the current system; With respect to the analysis results of the deep learning, a gradient descent algorithm is executed according to the analysis results of the deep learning to optimize the pre-built model.
8. An electronic device, characterized in that: include: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors are enabled to implement the method according to any one of claims 1 to 6.
9. A computer storage medium, characterized in that A computer program is stored thereon, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.