Power system space entity cross-system authentication method and device based on alliance chain
Patent Information
- Application Number
- CN202411646126.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-18
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2044-11-18
AI Technical Summary
在公开密钥基础建设(Public Key Infrastructure,PKI)系统中通常包含一个证书颁发机构(Certificate Authority,CA),负责验证电力系统实体,并对可信实体颁发数字证书,这种策略提供了一种直接有效的认证方案,但集中式认证策略可能导致严重的算力瓶颈与潜在的安全隐患;另一种方案是基于分布式账本技术(如拜占庭系统、区块链、联盟链等),实体的身份标识作为交易数据存储在数据链中,由分布式网络进行维护,电力系统基于链上数据实现可信的实体身份认证与访问管理,然而分布式账本的引入带来了更大的数据存储与计算开销,并且经典的分布式账本如区块链具有公开性、透明性等特点,链上数据可信不可篡改,同时也对任何用户透明可访问(包括其历史版本),这带来了前所未有的隐私安全挑战,即在基于分布式账本技术的跨系统认证技术中,不能直接在链上公开传输实体隐私数据,也不能使用私有数据(如签名私钥)参与链上运算
Smart Images

Figure CN119519984B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power system security technology, and in particular to a method and apparatus for cross-system authentication of spatial entities in power systems based on consortium blockchain. Background Technology
[0002] The power grid space is exhibiting trends towards intelligence, diversification, and complexity, typically comprising multiple independent power systems that provide services and resources to entities within their respective grid spaces. When grid entities engage in cross-system resource access, cross-system authentication technologies are required. Considering the intelligent development trend of power systems and the complex and diverse types of entities, resources, and services within these systems, universal and scalable authentication technologies become crucial for meeting multi-dimensional permission verification and access control needs.
[0003] Compared to traditional identity authentication, cross-system authentication presents significant challenges. First, different power network systems exhibit heterogeneity, with power equipment from various suppliers using different communication protocols and security standards. This necessitates that identity authentication technologies support diverse system characteristics. Second, as critical infrastructure, power systems require a balance between high security and high response efficiency. This necessitates that the authentication process meet real-time operation and response speed requirements, while also possessing strong anti-forgery and anti-attack capabilities. Furthermore, traditional identity authentication frameworks typically introduce a central management body (e.g., a system administrator) responsible for identity management and access control. This architecture is difficult to apply in cross-system authentication: on the one hand, cross-system authentication often involves higher throughput overhead, burdening the central management body with computational resources, making it a bottleneck for the entire power system's computing power; on the other hand, the central management body is generally considered trustworthy, possessing access data for all entities in cyberspace during identity authentication and access control. This security assumption also introduces potential security vulnerabilities in cross-system authentication.
[0004] A traditional cross-system authentication scheme is based on public-key cryptography to achieve secure identity management and authentication. Public Key Infrastructure (PKI) systems typically include a Certificate Authority (CA) responsible for verifying power system entities and issuing digital certificates to trusted entities. This strategy provides a direct and effective authentication solution, but centralized authentication strategies can lead to severe computational bottlenecks and potential security vulnerabilities. Another approach is based on distributed ledger technology (such as Byzantine Fault Tolerance, blockchain, and consortium blockchains). Entity identity identifiers are stored as transaction data on the blockchain and maintained by a distributed network. The power system uses on-chain data to achieve trusted entity identity authentication and access management. However, the introduction of distributed ledgers brings greater data storage and computational overhead. Furthermore, classic distributed ledgers like blockchains are characterized by openness and transparency; on-chain data is trustworthy and immutable, and transparently accessible to any user (including its historical versions). This presents unprecedented privacy and security challenges. Specifically, in cross-system authentication technologies based on distributed ledger technology, entity privacy data cannot be directly transmitted publicly on the blockchain, nor can private data (such as signature private keys) be used in on-chain computations.
[0005] In summary, improving the reliability of cross-system identity authentication has become an urgent problem to be solved. Summary of the Invention
[0006] This application provides a method and apparatus for cross-system authentication of spatial entities in a power system based on a consortium blockchain, in order to improve the reliability of cross-system identity authentication.
[0007] In a first aspect, embodiments of this application provide a cross-system authentication method for spatial entities in a power system based on a consortium blockchain, including:
[0008] Extract the entity features of each spatial entity in the power system, wherein the entity features include static feature vectors and dynamic behavior sequences;
[0009] Based on the entity characteristics of each spatial entity, a Merkel forest corresponding to each spatial entity is established;
[0010] Obtain a joint signature from authorized agencies across systems as authorization credentials for cross-system access;
[0011] The Merkel forest information and the joint signature information are stored using a consortium blockchain.
[0012] Based on the Merkel forest information, the joint signature information, and the authorization credential, cross-system identity authentication is performed using a zero-knowledge proof algorithm.
[0013] Secondly, embodiments of this application also provide a cross-system authentication device for power system spatial entities based on a consortium blockchain, comprising:
[0014] The feature extraction module is used to extract the entity features of each spatial entity in the power system. The entity features include static feature vectors and dynamic behavior sequences.
[0015] A module is established to build a Merkle forest corresponding to each of the spatial entities based on the entity characteristics of each of the spatial entities.
[0016] The signature acquisition module is used to obtain the joint signature of the cross-system authorization authorities, which serves as the authorization credential for cross-system access;
[0017] The evidence storage module is used to store the information of the Merkel forest and the information of the joint signature through the consortium blockchain;
[0018] The authentication module is used to perform cross-system identity authentication based on the Merkel forest information, the joint signature information, and the authorization credential, using a zero-knowledge proof algorithm.
[0019] Thirdly, embodiments of this application provide an electronic device, including:
[0020] One or more processors;
[0021] Storage device for storing one or more programs;
[0022] When the one or more programs are executed by the one or more processors, the one or more processors implement the cross-system authentication method for power system spatial entities based on consortium blockchains as described in the first aspect.
[0023] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the cross-system authentication method for power system spatial entities based on consortium blockchain as described in the first aspect.
[0024] Fifthly, embodiments of this application also provide a computer program product, including a computer program and / or instructions, which, when executed by a processor, implement the cross-system authentication method for power system spatial entities based on consortium blockchain as described in any of the above embodiments.
[0025] This application provides a method and apparatus for cross-system authentication of spatial entities in a power system based on a consortium blockchain. The method includes: extracting entity features of each spatial entity in the power system, the entity features including a static feature vector and a dynamic behavior sequence; establishing a Merkel forest corresponding to each spatial entity based on its entity features; obtaining a joint signature from a cross-system authorization authority as an authorization credential for cross-system access; storing the information of the Merkel forest and the joint signature using a consortium blockchain; and performing cross-system identity authentication based on a zero-knowledge proof algorithm using the Merkel forest information, the joint signature information, and the authorization credential. This technical solution utilizes the static and dynamic features of spatial entities to construct a Merkel forest. Based on this, it combines joint signatures, a consortium blockchain, and a zero-knowledge proof algorithm to achieve reliable cross-system identity authentication while ensuring security. It is applicable to various power systems and has scalability. Attached Figure Description
[0026] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0027] Figure 1 A flowchart illustrating a cross-system authentication method for spatial entities in a power system based on a consortium blockchain, provided for embodiments of this application;
[0028] Figure 2 A schematic diagram of a graphical structure of a Merkel forest provided in an embodiment of this application;
[0029] Figure 3 A schematic diagram illustrating the construction of a consortium blockchain network based on a smart power system, provided as an embodiment of this application;
[0030] Figure 4 A schematic diagram illustrating the use of general zero-knowledge proofs for identity authentication and authorization verification of a spatial entity, as provided in an embodiment of this application.
[0031] Figure 5 A schematic diagram illustrating a cross-system identity authentication process for spatial entities based on a consortium blockchain, provided as an embodiment of this application;
[0032] Figure 6 A schematic diagram of the structure of a power system spatial entity cross-system authentication device based on consortium blockchain provided in this application embodiment;
[0033] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0034] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present application, not the entire structure.
[0035] Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the steps as sequential processes, many of these steps can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the steps can be rearranged. The process can be terminated when its operation is complete, but may also have additional steps not included in the figures. The process can correspond to a method, function, procedure, subroutine, subroutine, etc.
[0036] It should be noted that the concepts of "first" and "second" mentioned in the embodiments of this application are only used to distinguish different devices, modules, units or other objects, and are not used to limit the order or interdependence of the functions performed by these devices, modules, units or other objects.
[0037] Furthermore, the embodiments and features described in this application may be combined with each other, unless otherwise specified.
[0038] The acquisition, storage, use, and processing of data in this application all comply with the relevant provisions of national laws and regulations.
[0039] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the relevant content of the solution.
[0040] Figure 1 This application provides a flowchart of a method for cross-system authentication of spatial entities in a power system based on a consortium blockchain. This embodiment is applicable to cross-system identity authentication for different power systems. Specifically, this method can be executed by a device for cross-system authentication of spatial entities in a power system based on a consortium blockchain. This device can be implemented through software and / or hardware and integrated into an electronic device. The electronic device includes, but is not limited to, devices with data processing capabilities such as computers, smartphones, or servers, and can be a spatial entity in the power system or a control device in the power system.
[0041] like Figure 1 As shown, the method specifically includes the following steps:
[0042] S110. Extract the entity features of each spatial entity in the power system, wherein the entity features include static feature vectors and dynamic behavior sequences.
[0043] In this embodiment, a spatial entity (which can be simply referred to as an entity) can refer to any individual in a power system that has resource and service needs, such as active users, communication nodes, or power equipment, for example, user equipment. Entity characteristics include static characteristics and dynamic behavioral characteristics. Static characteristics can be characteristics that do not change over time and can be represented in the form of a vector, while dynamic behavioral characteristics can be characteristics that change over time and can be represented in the form of a sequence.
[0044] S120. Based on the entity characteristics of each spatial entity, establish a Merkle forest corresponding to each spatial entity;
[0045] In this embodiment, for each spatial entity, a corresponding Merkle tree (also called a hash tree) can be constructed based on the entity's characteristics. The Merkle trees of all spatial entities form a Merkle forest. A Merkle tree is a hierarchical data structure that represents a set of data as a cryptographic hash tree. Each node in the Merkle tree is labeled with the cryptographic hash value of a data block. In other words, a unique identifier can be generated for each spatial entity using a Merkle tree. By using Merkle trees, the hash values of data can be efficiently calculated and compared, thereby efficiently verifying and storing large amounts of data.
[0046] S130. Obtain a joint signature from cross-system authorization authorities as an authorization credential for cross-system access.
[0047] In this embodiment, multi-party threshold signature technology is used to achieve concurrent collaborative authorization for cross-system access. Specifically, a joint signature service can be provided to users, working in conjunction with the cryptographic module software on the mobile device to complete digital signature calculations, achieving key security, algorithm security, and identity authentication, ensuring the security and integrity of users and data. In this process, private data (such as a signature private key) and a public key can be used to achieve joint signatures. There can be one or more authorizing agencies (also known as access control agencies), which can be located in different power systems than the spatial entities currently requiring cross-system access. Each authorizing agency can generate a corresponding sub-signature, and these sub-signatures are combined to obtain a joint signature (also known as an aggregated signature), using the joint signatures of all authorizing agencies as the authorization credential for cross-system access.
[0048] S140. The Merkel forest information and the joint signature information are stored in the consortium blockchain.
[0049] Specifically, a consortium blockchain is a type of blockchain that falls between public and private blockchains, allowing for a degree of public and private data and transactions. It can be viewed as a distributed ledger technology between public and private blockchains, jointly managed by multiple trusted institutions. Unlike the complete openness of public blockchains and the complete closedness of private blockchains, consortium blockchains only allow pre-defined participants to perform block verification and consensus, allowing for a degree of public and private data and transactions, and can be applied to cross-system identity authentication scenarios. In this embodiment, Merkel forest information (such as entity information, resource information, and access policies) and joint signature information (such as public key certificates) are stored on the consortium blockchain. Based on this, entities can publicly transmit private data on the chain, and can also use private data (such as signing private keys) to participate in on-chain computations.
[0050] S150. Based on the Merkel forest information, the joint signature information, and the authorization credential, perform cross-system identity authentication using a zero-knowledge proof algorithm.
[0051] Specifically, by utilizing the Merkel Forest information and joint signature information stored in the consortium blockchain, and based on authorization credentials, cross-system identity verification and authorization can be achieved using zero-knowledge proof algorithms. Zero-knowledge proof is a cryptographic tool that allows mutually untrusted communicating parties to prove the validity of a proposition without revealing any additional information. Applied to identity authentication, it enables entities to prove their identity and gain access without disclosing their identity information to the accessing party. By utilizing the Merkel Forest information, joint signature information, and authorization credentials, and based on zero-knowledge proof algorithms, reliable cross-system identity authentication can be achieved while ensuring security.
[0052] This application provides a method for cross-system authentication of power system entities based on a consortium blockchain. This method solves the problems of cross-system identity verification and resource access control in the power network space. By extracting static feature vectors and dynamic behavior sequences of network space entities, it generates unique identifiers for entities using Merkle trees, organizes the power system entity states based on Merkle forests, and uses a consortium blockchain to achieve reliable cross-system transfer of entity identity trust. It completes cross-system identity verification and authorization based on general zero-knowledge proof technology. This provides a more feasible and reliable solution for cross-system identity management and access control in smart power systems. By utilizing consortium blockchains and zero-knowledge proof technology, it achieves secure and efficient cross-system identity authentication, providing reliable support for the safe development and operation of power systems. Furthermore, this method has good versatility and scalability, and can be applied to any power system or newly added power systems.
[0053] In one embodiment, extracting entity features for each spatial entity in the power system includes:
[0054] For each spatial entity, static features are extracted and a static feature vector is established based on the entity type. The dynamic behavior sequence is based on the chain of dynamic behaviors of the spatial entity within a set time window. The entity type includes at least one of the following: active user, power equipment; the static features include at least one of the following: entity identifier, entity type, entity identity information, entity biometrics, entity hardware features, entity permission digital credentials; and the dynamic behaviors include at least one of the following: login information, operation behavior, operation frequency.
[0055] For example, extracting entity features may include the following steps:
[0056] Step 1.1: For entities in the power system network space, they are defined as any individual with resource and service needs, such as active users, communication nodes, and power equipment. Entity characteristics are divided into static and dynamic features, which are extracted separately to comprehensively represent the characteristics of network space entities.
[0057] Step 1.2: For static features of cyberspace entities, the main focus is on entity identifiers (IDs), entity type, entity identity information, biometrics, hardware features, and / or entity authorization digital credentials. Appropriate feature extraction strategies can be selected based on the entity type. For example, for active users, their identity information, biometric information, and physical identity credentials can be collected; for power equipment, its manufacturer information, model information, and hardware feature information can be collected. Static entity attributes are collected through information gathering, network testing, and other methods to establish static feature vectors.
[0058] Step 1.3: For the dynamic characteristics of cyberspace entities, the main focus is on entity login information (such as time, space, network and / or device), operational behaviors (such as resource access, permission requests and / or cross-system authorization), and / or operation frequency. Appropriate feature extraction strategies can be selected based on the entity type. For example, for active users, it is necessary to detect their login habits and resource access habits, which can be analyzed in conjunction with user profiles established by the power service system; for power equipment, it is necessary to detect its working patterns and working status. The dynamic behavior chain of the entity within a time window is extracted and stored as a dynamic behavior sequence.
[0059] Based on this, by comprehensively and accurately extracting the entity features of spatial entities, a reliable foundation is provided for identity authentication such as signatures and authorizations.
[0060] In one embodiment, a Merkel forest corresponding to each spatial entity is established based on the entity characteristics of each spatial entity, including:
[0061] For each spatial entity, a Merkle tree corresponding to the spatial entity is constructed based on the static feature vector and dynamic behavior sequence of the spatial entity, and the root node of the Merkle tree is used as the unique identifier of the spatial entity; wherein, the static features and dynamic behaviors of the spatial entity are the leaf nodes of the Merkle tree.
[0062] A Merkel forest is constructed based on the Merkel trees corresponding to each spatial entity, and the root node of the Merkel forest is used as the credential of the internal state of the power system; wherein, the Merkel trees corresponding to each spatial entity are all leaf nodes of the Merkel forest.
[0063] For example, establishing a Merkel forest may include the following steps:
[0064] Step 2.1: For a cyberspace entity, organize its static feature vectors and dynamic behavior sequences into a list to construct a Merkle tree. At this point, both the static features and dynamic behaviors of the cyberspace entity serve as leaf nodes of the Merkle tree, and any small change in any attribute of the entity will have an uncontrollable impact on the Merkle tree.
[0065] Step 2.2: Use the generated Merkel tree root node as the unique identifier of the cyberspace entity, and use its traceability and immutability to uniquely identify the entity's identity.
[0066] Step 2.3: For entities within the power system, organize all Merkle trees into a list to build a Merkle forest. Specifically, a Merkle tree is a binary tree structure based on a hash digest algorithm. Leaf nodes store the hash value of a data block; non-leaf nodes store the mixed hash of the values of their two child nodes. Based on this merging rule, the process recursively moves upwards until a root node is obtained. Due to the characteristics of the hash function and the Merkle tree structure, any tiny change in any data block will cause a change in the Merkle tree root. The Merkle forest is structurally isomorphic to the Merkle tree. In this embodiment, the Merkle tree built by each spatial entity within the power system serves as a leaf node in the Merkle forest, such as... Figure 2 As shown, Merkle trees can be used to grasp the state of each spatial entity in a fine-grained manner, while Merkle forests can be used to grasp the overall state of all spatial entities in a coarse-grained manner, effectively establishing the binding relationship between entities and the power system.
[0067] Step 2.4: Use the generated Merkel forest root node as proof of the current internal state of the power system.
[0068] Based on this, sufficient evidence is provided for cross-system identity authentication, thereby improving the security and reliability of cross-system identity authentication.
[0069] In one embodiment, the cross-system authorization authority includes at least two sub-authorities; obtaining the joint signature of the cross-system authorization authority as an authorization credential for cross-system access includes:
[0070] The private key corresponding to the global public key is divided into multiple signing private key fragments, which are distributed to each organization, and the global public key is stored. For space entities with cross-system access requirements, access requests and authorization applications are sent to each sub-organization, so that each sub-organization verifies the entity's identity and access request, and then uses the corresponding signing private key fragment to execute the signature algorithm to generate a signature. If the number of signatures obtained reaches a set threshold, a joint signature is generated based on the signatures obtained from each sub-organization using the Lagrange interpolation method. If the number of signatures obtained reaches the set threshold, the joint signature is verified by the global public key and used as an authorization credential for cross-system identity authentication.
[0071] For example, obtaining a joint signature may include the following steps:
[0072] Step 3.1: For cross-system authorized agencies deployed in the power system, distribute threshold signature key fragments to each sub-agency to generate joint signatures. Store the global public key (pk) for verifying the joint signature. In multi-party threshold signatures, the signing private key is held by multiple participants, and each participant can generate a signature independently. When the number of signatures reaches the threshold, a valid joint signature can be synthesized.
[0073] For example, for (t,n)-TSS, there are n participants, and at least t participants are needed to generate a valid joint signature. Let the global public key be (pk) and its corresponding private key be sk, which needs to be divided into n private key fragments. To do this, we first choose a polynomial of degree t-1, f(x) = sk + a1x + ... + a t-1 x t-1 The lowest-order coefficient is the global private key. For the i-th participant, calculate sk. i =f(x) i ) as its private key fragment.
[0074] For example, multi-party threshold signatures can be used with the Elliptic Curve Digital Signature Algorithm (ECDSA). In a joint signature, each participant only needs to use a fragment of their private key to execute the signature algorithm. Assume the signature generated by the i-th participant is ρ. i At this point, Lagrange interpolation is performed on the signature, i.e., the following calculation is made: σ = ∑λ i σ i , where λ i These are the Lagrange interpolation coefficients: This allows for the generation of a joint signature. When the number of participants in the joint signature reaches t, the signature σ can be authenticated using the global public key pk.
[0075] Step 3.2: For cyberspace entities with cross-system resource access needs, submit access requests and authorization applications to different authorized sub-organizations. The authorized sub-organizations verify the cyberspace entity's characteristic information and issue authorizations for valid applications. Specifically, each sub-organization can use its private key to shard the cyberspace entity's identity and access request, and then send it to the cyberspace entity.
[0076] Step 3.3: When the number of collected signatures reaches the threshold, the signatures can be aggregated to obtain a valid joint signature, which can be used as an authorization credential for cross-system identity authentication.
[0077] Based on this, by obtaining joint signatures from authorized agencies across systems, valid credentials are provided for cross-system identity authentication, thereby improving the security and reliability of cross-system identity authentication.
[0078] In one embodiment, the Merkel forest information includes the root node of the Merkel forest, and the joint signature information includes the global public key (pk).
[0079] Figure 3 This diagram illustrates a consortium blockchain built upon a power system. (For example...) Figure 3 As shown, Merkel forest information (such as entity information, resource information, access policies, etc.) and joint signature information (such as public key certificates) are stored on the consortium blockchain. The advantage of using a consortium blockchain is that spatial entities can publicly transmit private data on the chain, and can also use private data (such as signing private keys) to participate in on-chain computation.
[0080] In one embodiment, cross-system identity authentication is performed based on a zero-knowledge proof algorithm, using information from the Merkel forest, information from the joint signature, and authorization credentials. This includes:
[0081] For spatial entities that have cross-system access requirements, a valid proof required for the spatial entity to access the target system is generated based on the zero-knowledge proof document in the consortium blockchain. The zero-knowledge proof document includes information about the Merkel forest and the joint signature.
[0082] An access request is sent to the target system to request the target system to authenticate the spatial entity. The access request includes valid proof. Valid proof includes: the spatial entity holds authorization credentials for cross-system access; the static and dynamic characteristics of the spatial entity are respectively bound to the authorization credentials; and both the static and dynamic characteristics of the spatial entity meet the cross-system access requirements.
[0083] For example, the cross-system authentication process may include the following steps:
[0084] Step 5.1, as follows Figure 4As shown, the proof proposition and its objective are first clearly defined, such as authentication, authorization verification, and access control. Based on this, the power system performs initial setup for the zero-knowledge proof algorithm, which is determined by the specific algorithm content. The initialization of the zero-knowledge proof algorithm includes trust settings, such as setting the Common Reference String (CRS), arithmetic representation, and key generation. The power system then publishes the zero-knowledge proof documentation (including supported algorithms and auxiliary proof data such as the global public key) on the consortium blockchain.
[0085] Taking active users in the power system as an example, static feature vectors are extracted based on their user information, equipment information, network information, and other attributes. These vectors include entity identifier (ID), entity type (ROLE), entity identity information (IP or MAC address), and entity hardware characteristics (hostname, system version, processor version and model). Dynamic behavior sequences are extracted based on their resource access, service access, and permission request behaviors. These sequences include multiple timestamps and the corresponding geographical location, operation behavior (login), and details (IP address, device type, resource type) for each timestamp.
[0086] Then, Merkle trees are constructed based on static feature vectors and dynamic behavior sequences. For example, the SHA256 hash digest algorithm can be used to construct Merkle trees, where the root node of the Merkle tree serves as a unique identifier for the entity. The Merkle trees of each spatial entity constitute a Merkle forest, where the root node is used to represent the current state of the power system.
[0087] In a power system, three authorized (sub)organizations can be set up. Each (sub)organization holds a fragment of the private key for multi-party threshold signatures and stores the global public key. For example, the Elliptic Curve Digital Signature Algorithm (ECDSA) is used, which employs the standard curve of an elliptic curve algorithm (such as secp256k1). For cross-system access requests submitted by entities in the power network space, each organization generates a sub-signature. Finally, an aggregate signature is obtained based on a sufficient number of sub-signatures, and the aggregate signature is verified using the global public key.
[0088] Based on this, the access control rules for cross-system resource access in the power system are defined as follows: using the static feature vector of the terminal device, dynamic behavior sequence, entity identity identifier, power system status identifier, and cross-system access authorization, zero-knowledge proof is performed based on the Groth16 algorithm to achieve cross-system identity authentication.
[0089] Step 5.2: For cyberspace entities with cross-system resource access needs, utilize on-chain auxiliary data and the algorithm supported by the target system to generate a valid proof. The cyberspace entity generates a valid proof and sends it as an access request to the target system for authentication. Specifically, the proof mainly includes:
[0090] The spatial entity holds valid identity credentials of the original power system, which can be further verified by the entity's identity credentials and the Merkel Forest of the original power system;
[0091] Spatial entities possess static and dynamic characteristics that are bound to authorization credentials, which can be further proven using Merkle trees;
[0092] The static and dynamic characteristics of spatial entities satisfy the requirements for cross-system resource access, which can be determined by specific access restriction policies;
[0093] Spatial entities hold corresponding access authorization credentials for cross-system resources, which can be verified by joint signature authorization and global public key.
[0094] Step 5.3: For network entities with cross-system resource access needs, the power system authenticates their access requests. Specifically, this is done by verifying the validity of zero-knowledge proofs, thus achieving reliable identity verification, authorization verification, and access control without leaking privacy data.
[0095] Zero-knowledge proofs allow a prover to demonstrate the correctness of a statement to a verifier without revealing any other information. For example, given a target constraint set C and a public input x (also known as auxiliary input), a zero-knowledge proof demonstrates that the prover holds a private input w satisfying:
[0096] (x,w)∈L={(x,w):C(x,w)=1}
[0097] In a general zero-knowledge proof system, the prover can transform the target problem into a specific form of arithmetic circuit and securely prove its correctness. One type of general zero-knowledge proof system is a concise, non-interactive zero-knowledge proof, where the verification algorithm can be Groth16 or Plonk, etc. These algorithms exhibit conciseness and non-interactive characteristics, allowing the prover to verify the correctness of the target problem in a constant number of operations, regardless of the size or complexity of the target problem. For cross-system authentication of power network entities based on consortium blockchains, this characteristic can effectively control the transmission and verification overhead generated during identity authentication, meeting the usability and reliability requirements of power system identity authentication.
[0098] Based on this, in cross-system authentication of entities in power network space, general zero-knowledge proof technology can realize any form of identity verification, authorization verification, and access control. At the same time, its zero-knowledge nature ensures that entity information will not be leaked in the process, providing a general, secure, and reliable solution.
[0099] Figure 5 This is a schematic diagram illustrating a cross-system identity authentication process for spatial entities based on a consortium blockchain, as provided in an embodiment of this application. Figure 5 As shown, for each entity in the entity set, entity features are extracted and a Merkle tree is built to obtain a unique identity identifier. Then, a Merkle forest is built for the entity set as a system state credential. Based on this system state credential, combined with the global public key of each permission management agency (cross-system authorization agency) and zero-knowledge proof auxiliary data, the consortium blockchain is used to process cross-system access requests of entities and realize the identity authentication of entities.
[0100] Figure 6 This is a schematic diagram of a consortium blockchain-based cross-system authentication device for power system spatial entities, provided as an embodiment of this application. The consortium blockchain-based cross-system authentication device for power system spatial entities provided in this embodiment includes:
[0101] The feature extraction module 210 is used to extract the entity features of each spatial entity in the power system, wherein the entity features include static feature vectors and dynamic behavior sequences;
[0102] Module 220 is used to establish a Merkle forest corresponding to each of the spatial entities based on the entity characteristics of each of the spatial entities.
[0103] The signature acquisition module 230 is used to acquire the joint signature of cross-system authorization authorities as an authorization credential for cross-system access;
[0104] The evidence storage module 240 is used to store the information of the Merkel forest and the information of the joint signature through the consortium blockchain;
[0105] The authentication module 250 is used to perform cross-system identity authentication based on the Merkel forest information, the joint signature information, and the authorization credential, using a zero-knowledge proof algorithm.
[0106] The device uses a neural network model to predetermine the encoding parameters corresponding to different complexity levels. During the encoding process, it selects appropriate target encoding parameters according to the complexity level, thereby improving the quality and efficiency of cross-system authentication of spatial entities in the power system based on consortium blockchain.
[0107] In one embodiment, the feature extraction module 210 is specifically used for:
[0108] For each spatial entity, static features of the spatial entity are extracted and a static feature vector is established according to the entity type of the spatial entity. The chain of dynamic behavior of the spatial entity within a set time window is used as a dynamic behavior sequence.
[0109] The entity type includes at least one of the following: active user, power equipment;
[0110] The static features include at least one of the following: entity identifier, entity type, entity identity information, entity biometrics, entity hardware features, and entity authorization digital credentials;
[0111] The dynamic behaviors include at least one of the following: login information, operation behavior, and operation frequency.
[0112] In one embodiment, the establishment module 220 is specifically used for:
[0113] For each spatial entity, a Merkle tree corresponding to the spatial entity is constructed based on the static feature vector and dynamic behavior sequence of the spatial entity, and the root node of the Merkle tree is used as the unique identifier of the spatial entity; wherein, the static features and dynamic behaviors of the spatial entity are both leaf nodes of the Merkle tree;
[0114] A Merkel forest is constructed based on the Merkel trees corresponding to each spatial entity, and the root node of the Merkel forest is used as the credential of the internal state of the power system; wherein, the Merkel trees corresponding to each spatial entity are all leaf nodes of the Merkel forest.
[0115] In one embodiment, the cross-system authorization agency includes at least two sub-agency units;
[0116] The signature acquisition module 230 is specifically used for:
[0117] The private key corresponding to the global public key is divided into multiple signing private key fragments, and the corresponding signing private key fragments are distributed to each of the aforementioned institutions, while the global public key is stored.
[0118] For spatial entities that have cross-system access requirements, access requests and authorization applications are sent to each of the sub-organizations, so that each of the sub-organizations, after verifying the entity identity and access requirements of the spatial entity, uses the corresponding signature private key to shard and execute the signature algorithm to generate a signature.
[0119] If the number of signatures obtained reaches a set threshold, a joint signature is generated based on the signatures of each sub-organization using the Lagrange interpolation method.
[0120] If the number of signatures obtained reaches a set threshold, the joint signature is verified by the global public key and used as an authorization credential for cross-system identity authentication.
[0121] In one embodiment, the information of the Merkel forest includes the root node of the Merkel forest, and the information of the joint signature includes the global public key.
[0122] In one embodiment, the authentication module 250 is specifically used for:
[0123] For a spatial entity that has cross-system access requirements, a valid proof required for the spatial entity to access the target system is generated based on the zero-knowledge proof document in the consortium blockchain, wherein the zero-knowledge proof document includes information about the Merkel forest and information about the joint signature;
[0124] Send an access request to the target system to request the target system to authenticate the spatial entity, the access request including the valid proof;
[0125] The valid proof includes:
[0126] The spatial entity holds authorization credentials for cross-system access;
[0127] The static and dynamic characteristics of the spatial entity are respectively bound to the authorization credential;
[0128] Both the static and dynamic characteristics of the spatial entity satisfy the cross-system access requirements.
[0129] The power system spatial entity cross-system authentication device based on consortium blockchain provided in this application embodiment can be used to execute the power system spatial entity cross-system authentication method based on consortium blockchain provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0130] Figure 7 A schematic diagram of an electronic device 10, which can be used to implement embodiments of this application, is shown. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device 10 may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, user equipment, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.
[0131] like Figure 7As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0132] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks and wireless networks.
[0133] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above.
[0134] In some embodiments, the methods described above can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the methods described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the methods of any of the embodiments described above by any other suitable means (e.g., by means of firmware).
[0135] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0136] Computer programs used to implement the methods of this application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0137] In the context of this application, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0138] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device 10, which includes: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device 10. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0139] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0140] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0141] This application also provides a computer program product, including a computer program and / or instructions, which, when executed by a processor, implement the cross-system authentication method for power system spatial entities based on consortium blockchain as described in any of the above embodiments.
[0142] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.
[0143] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A cross-system authentication method for spatial entities in a power system based on a consortium blockchain, characterized in that, include: Extract the entity features of each spatial entity in the power system, wherein the entity features include static feature vectors and dynamic behavior sequences; Based on the entity characteristics of each spatial entity, a Merkel forest corresponding to each spatial entity is established; A joint signature from a cross-system authorization authority is obtained as an authorization credential for cross-system access; wherein, the cross-system authorization authority includes at least two sub-institutions; each sub-institution uses its corresponding signature private key to fragment and execute a signature algorithm to generate a signature; a joint signature is generated based on the obtained signatures of each sub-institution using the Lagrange interpolation method; The Merkel forest information and the joint signature information are stored using a consortium blockchain. Based on the Merkel forest information, the joint signature information, and the authorization credential, cross-system identity authentication is performed using a zero-knowledge proof algorithm, including: For a spatial entity that has cross-system access requirements, a valid proof required for the spatial entity to access the target system is generated based on the zero-knowledge proof document in the consortium blockchain, wherein the zero-knowledge proof document includes information about the Merkel forest and information about the joint signature; Send an access request to the target system to request the target system to authenticate the spatial entity, the access request including the valid proof; Based on the entity characteristics of each spatial entity, a Merkel forest corresponding to each spatial entity is established, including: For each spatial entity, a Merkle tree corresponding to the spatial entity is constructed based on the static feature vector and dynamic behavior sequence of the spatial entity, and the root node of the Merkle tree is used as the unique identifier of the spatial entity; wherein, the static features and dynamic behaviors of the spatial entity are both leaf nodes of the Merkle tree; A Merkel forest is constructed based on the Merkel trees corresponding to each spatial entity, and the root node of the Merkel forest is used as the credential of the internal state of the power system; wherein, the Merkel trees corresponding to each spatial entity are all leaf nodes of the Merkel forest. The Merkle tree is a hierarchical data structure, and each node in the Merkle tree is labeled with the cryptographic hash value of a data block.
2. The method according to claim 1, characterized in that, The extraction of entity features for each spatial entity in the power system further includes: For each spatial entity, static features of the spatial entity are extracted and a static feature vector is established according to the entity type of the spatial entity. The chain of dynamic behavior of the spatial entity within a set time window is used as a dynamic behavior sequence. The entity type includes at least one of the following: active user, power equipment; The static features include at least one of the following: entity identifier, entity type, entity identity information, entity biometrics, entity hardware features, and entity authorization digital credentials; The dynamic behaviors include at least one of the following: login information, operation behavior, and operation frequency.
3. The method according to claim 1, characterized in that, Obtain a joint signature from cross-system authorization authorities as authorization credentials for cross-system access, including: The private key corresponding to the global public key is divided into multiple signing private key fragments, and the corresponding signing private key fragments are distributed to each of the sub-organizations, and the global public key is stored. For spatial entities that have cross-system access requirements, access requests and authorization applications are sent to each of the aforementioned sub-organizations so that each of the aforementioned sub-organizations can verify the entity identity and access requirements of the spatial entity. If the number of signatures obtained reaches a set threshold, the joint signature is verified by the global public key and used as an authorization credential for cross-system identity authentication.
4. The method according to claim 3, characterized in that, The information in the Merkel forest includes the root node of the Merkel forest, and the information in the joint signature includes the global public key.
5. The method according to claim 1, characterized in that, in, The valid proof includes: The spatial entity holds authorization credentials for cross-system access; The static and dynamic characteristics of the spatial entity are respectively bound to the authorization credential; Both the static and dynamic characteristics of the spatial entity satisfy the cross-system access requirements.
6. A cross-system authentication device for spatial entities in a power system based on a consortium blockchain, characterized in that, include: The feature extraction module is used to extract the entity features of each spatial entity in the power system. The entity features include static feature vectors and dynamic behavior sequences. A module is established to build a Merkle forest corresponding to each of the spatial entities based on the entity characteristics of each spatial entity. The signature acquisition module is used to acquire the joint signature of the cross-system authorization authority as an authorization credential for cross-system access; wherein, the cross-system authorization authority includes at least two sub-institutions; each sub-institution uses its corresponding signature private key to fragment and execute a signature algorithm to generate a signature; and a joint signature is generated based on the acquired signatures of each sub-institution using the Lagrange interpolation method. The evidence storage module is used to store the information of the Merkel forest and the information of the joint signature through the consortium blockchain; The authentication module is used to perform cross-system identity authentication based on the Merkel forest information, the joint signature information, and the authorization credential, using a zero-knowledge proof algorithm. The establishment module is specifically used for: For each spatial entity, a Merkle tree corresponding to the spatial entity is constructed based on the static feature vector and dynamic behavior sequence of the spatial entity, and the root node of the Merkle tree is used as the unique identifier of the spatial entity; wherein, the static features and dynamic behaviors of the spatial entity are both leaf nodes of the Merkle tree; A Merkel forest is constructed based on the Merkel trees corresponding to each spatial entity, and the root node of the Merkel forest is used as the credential of the internal state of the power system; wherein, the Merkel trees corresponding to each spatial entity are all leaf nodes of the Merkel forest. The Merkle tree is a hierarchical data structure, and each node in the Merkle tree is labeled with the cryptographic hash value of a data block; The authentication module is specifically used for: For a spatial entity that has cross-system access requirements, a valid proof required for the spatial entity to access the target system is generated based on the zero-knowledge proof document in the consortium blockchain, wherein the zero-knowledge proof document includes information about the Merkel forest and information about the joint signature; An access request is sent to the target system to request the target system to authenticate the spatial entity, and the access request includes the valid proof.
7. An electronic device, characterized in that, include: At least one processor; A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the cross-system authentication method for power system spatial entities based on a consortium blockchain as described in any one of claims 1-5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the cross-system authentication method for power system spatial entities based on any one of claims 1-5.
9. A computer program product comprising a computer program and / or instructions, characterized in that, When the computer program and / or instructions are executed by the processor, they implement the cross-system authentication method for power system spatial entities based on any one of claims 1-5.
Citation Information
Patent Citations
Decentralized data storage and processing for IoT devices
CN110024352A