A method and system for protecting electric power information based on secure communication protocol

By adjusting the data packet size and introducing randomness and pseudo-data packets through a layered secure communication protocol, the problem of man-in-the-middle attacks is solved, the security and privacy of the power system are protected, and the stable operation of the power grid is ensured.

CN119865368BActive Publication Date: 2025-09-05STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510046070.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-09-05
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

Existing power communication systems have made progress in data content encryption, but lack data packet feature analysis protection against man-in-the-middle attacks. Attackers can infer the operating status, topology and power consumption patterns of the power grid by analyzing the size, time interval and transmission path of the data packets, posing a threat to power grid security.

Method used

A layered secure communication protocol is established, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer. By adjusting the packet size, introducing randomness and pseudo-packets, the periodicity and spatiotemporal correlation of the packets are broken, and data recovery and integrity verification are performed in combination with the power grid topology information.

Benefits of technology

It effectively hides node load information, destroys attackers' inference of power grid patterns through data packet feature analysis, protects the power grid's operating status and key node information, and ensures data integrity and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119865368B_ABST
    Figure CN119865368B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of power systems and provides a power information protection method and system based on a secure communication protocol, comprising establishing a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer; a collection device registers and obtains power grid topology information, the collection device adjusts the size of the obtained data packet according to the power grid topology information in the data obfuscation layer, and encrypts the adjusted data in the encryption and verification layer; the intermediate node introduces randomness to the received data in the transmission optimization layer according to preset rules and disturbs the periodic characteristics; after the data center receives the data packet, the data is removed from the disturbance according to the preset rules in the transmission optimization layer; the data after the disturbance is removed is decrypted in the encryption and verification layer; the original data is restored according to the power grid topology information in the data obfuscation layer; and the integrity of the data is verified through a data signature in the encryption and verification layer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of power systems, and in particular relates to a power information protection method and system based on a secure communication protocol. Background Art

[0002] With the development of intelligent and information-based power systems, the transmission of power information plays a vital role in grid operation. To ensure the safe and stable operation of the grid, power information must be exchanged in real time between data collection devices, transmission nodes, and data centers. This data, including key operating parameters such as load, voltage, and power, exhibits a high degree of temporal and spatial correlation and cyclical characteristics.

[0003] In existing power communication systems, even if the data content is protected by encryption technology, attackers can still conduct man-in-the-middle attacks and analyze the external characteristics of data packets (such as packet size, transmission time interval, path information, etc.) to infer the operating status, geographical distribution and power consumption patterns of the power grid.

[0004] A man-in-the-middle attack is a cyberattack that intercepts and forges communication packets to obtain sensitive information. For power systems, attackers can obtain valuable information simply by analyzing the following characteristics of the packets without decrypting the data content:

[0005] Packet size is often directly related to the amount of information being transmitted. For example, high-load nodes collect large amounts of data, and their packets are typically larger than those from low-load nodes. By capturing and comparing packet sizes, attackers can determine the load distribution characteristics of nodes and, in turn, infer the operating status of the power grid.

[0006] The transmission of power information is highly cyclical. For example, voltage and load data are typically collected and transmitted at fixed intervals (such as 10 milliseconds or 1 second). By analyzing the intervals between data packets, attackers can infer the sampling period of the power system and, therefore, understand the operating rhythm of the power grid.

[0007] The transmission paths of data packets between different nodes reflect the topology of the power grid. By analyzing the transmission paths and identification information of data packets, attackers can construct the logical topology of the power grid and identify the locations and functions of key nodes.

[0008] By capturing and analyzing the size of data packets and their transmission intervals, attackers can obtain regional electricity usage characteristics and trends. This information can be used to predict peak load times and even identify specific users' electricity usage behavior, posing a threat to user privacy.

[0009] The topology of the power grid and the distribution of node loads are crucial information for power systems. Once attackers identify key nodes, they can launch more targeted attacks (such as physical damage or denial-of-service attacks) against these nodes, paralyzing the power grid.

[0010] Based on the acquired spatiotemporal information, attackers can construct fake data packets to confuse data center decisions. For example, they can forge high-load data packets and transmit them to the dispatch center, causing incorrect dispatch operations and thus affecting the stable operation of the power grid.

[0011] Current power communication systems have made significant progress in data content encryption, but effective protection against man-in-the-middle attacks involving packet feature analysis remains lacking. Due to the spatiotemporal correlation and cyclical nature of power information, attackers can obtain information about the grid's operating patterns and topology through external feature analysis without decrypting the data. Therefore, further protection of power information is needed to ensure both operational security and information privacy. Summary of the Invention

[0012] In order to solve the problems in the prior art, the present invention provides a power information protection method based on a secure communication protocol, comprising the following steps:

[0013] Establish a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer;

[0014] Deploy a communication module supporting the layered security communication protocol between the power information collection equipment, the transmission intermediate node and the data center;

[0015] The collection device registers and obtains the power grid topology information, the collection device adjusts the size of the obtained data packet according to the power grid topology information at the data obfuscation layer, and encrypts the adjusted data at the encryption and verification layer;

[0016] The intermediate node introduces randomness to the received data in the transmission optimization layer according to preset rules, and disturbs the periodic characteristics;

[0017] After the data center receives the data packet, it removes the disturbance data according to the preset rules at the transmission optimization layer; decrypts the data after the disturbance is removed at the encryption and verification layer; restores the original data according to the power grid topology information at the data obfuscation layer; and verifies the integrity of the data through the data signature at the encryption and verification layer.

[0018] Furthermore, adjusting the size of the obtained data packet according to the power grid topology information at the data obfuscation layer includes:

[0019] The collection device calculates the node importance score S based on the adjacency relationship and weight information of the nodes in the topology structure;

[0020] According to the score S, the nodes are divided into the following three categories:

[0021] When S>T1, the data packet is adjusted to 150% to 200% of the original size;

[0022] When T2 <= S <= T1, the data packet is adjusted to 120% to 150% of the original size;

[0023] When S<T2, the data packet is adjusted to 100% to 120% of the original size;

[0024] Wherein, T1 and T2 are predefined score thresholds;

[0025] Fill the original data packet with virtual data segments, the length and content of which are dynamically adjusted according to the node importance score. The filled data segment contains the node identifier, the topological relationship hash value and the virtual data length, which are used for subsequent data recovery;

[0026] Introduce random perturbations into the adjusted data packet, and the adjustment range is dynamically set according to the score;

[0027] Attach a recovery metadata segment to the header or tail of the data packet, and the content includes: the size of the original data packet; the length and position of the filled data; the random perturbation offset value; the node identifier and the topological relationship hash value.

[0028] Furthermore, introducing randomness to the received data in the transmission optimization layer includes:

[0029] Calculate the periodic characteristics of the current node according to the node identifier and topological information included in the recovery metadata segment of the data packet;

[0030] Introduce a random offset value to adjust the transmission time interval of the data packet, and the offset value is generated according to the following rules:

[0031] Offset value = basic transmission interval * (1 + random perturbation factor)

[0032] Wherein, the random perturbation factor is a random value between -0.2 and 0.2;

[0033] Randomly group the data packets according to the topological adjacency information and node priorities;

[0034] Within each group of data packets, rearrange the transmission order of the data packets;

[0035] Randomly select a transmission path from the available next-hop nodes according to the adjacency relationship of the current node;

[0036] Generate pseudo data packets according to the node priorities and topological information. The pseudo data packets contain randomly generated virtual data and identifiers, which are used to obfuscate the characteristics of the real data packets.

[0037] Furthermore, removing disturbance data according to the preset rules at the transmission optimization layer includes:

[0038] Adjust the parameters based on the time interval in the metadata to restore the original transmission time interval sequence of the data packets;

[0039] Restore the original order of the data packets based on the order adjustment rules in the metadata;

[0040] Identify and remove dummy packets based on the dummy packet identifier and insertion position in the metadata segment.

[0041] Furthermore, restoring the original data based on the grid topology information at the data obfuscation layer includes:

[0042] Remove the virtual padding data according to the padding data position and length recorded in the metadata segment;

[0043] The node identifier and topology relationship hash value in the data packet are compared with the grid topology information to verify the topological consistency of the node;

[0044] If the verification is successful, the obfuscated data is decoded to restore the temporal and spatial correlation characteristics of the data;

[0045] Reconstruct the original data content based on the inverse operation of the obfuscation rules.

[0046] The present invention also provides a power information protection system based on a secure communication protocol, comprising the following modules:

[0047] A management module for establishing a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer;

[0048] A collection device, wherein the collection device is installed with the layered secure communication protocol, the collection device registers and obtains power grid topology information, the collection device adjusts the size of the obtained data packet according to the power grid topology information at the data obfuscation layer, and encrypts the adjusted data at the encryption and verification layer;

[0049] An intermediate node, wherein the intermediate node installs the layered secure communication protocol and introduces randomness to the received data at the transmission optimization layer according to preset rules to perturb the periodic characteristics;

[0050] A data center is provided, wherein the data center is installed with the layered secure communication protocol. After receiving a data packet, the data center removes disturbance data according to the preset rules at the transmission optimization layer; decrypts the data after disturbance removal at the encryption and verification layer; restores the original data according to the power grid topology information at the data obfuscation layer; and verifies the integrity of the data through a data signature at the encryption and verification layer.

[0051] Further, adjusting the size of the obtained data packet according to the power grid topology structure information in the data obfuscation layer includes:

[0052] The acquisition device calculates the node importance score S according to the adjacency relationship and weight information of the nodes in the topology structure;

[0053] According to the score S, the nodes are divided into the following three categories:

[0054] When S>T1, the data packet is adjusted to 150% to 200% of the original size;

[0055] When T2<=S<=T1, the data packet is adjusted to 120% to 150% of the original size;

[0056] When S<T2, the data packet is adjusted to 100% to 120% of the original size;

[0057] Among them, T1 and T2 are predefined score thresholds;

[0058] Fill the original data packet with virtual data segments, the length and content of which are dynamically adjusted according to the node importance score. The filled data segment includes the node identifier, the topology relationship hash value, and the virtual data length, which are used for subsequent data recovery;

[0059] Introduce random perturbations into the adjusted data packet, and the adjustment range is dynamically set according to the score;

[0060] Attach a recovery metadata segment to the data packet header or tail, and the content includes: the size of the original data packet; the length and position of the filled data; the random perturbation offset value; the node identifier and the topology relationship hash value.

[0061] Further, introducing randomness to the received data in the transmission optimization layer includes:

[0062] Calculate the periodic characteristics of the current node according to the node identifier and topology information included in the recovery metadata segment of the data packet;

[0063] Introduce a random offset value to adjust the transmission time interval of the data packet, and the offset value is generated according to the following rules:

[0064] Offset value = basic transmission interval * (1 + random perturbation factor)

[0065] Among them, the random perturbation factor is a random value between -0.2 and 0.2;

[0066] Randomly group the data packets according to the topological adjacency information and node priorities;

[0067] Within each group of data packets, rearrange the transmission order of the data packets;

[0068] According to the adjacency relationship of the current node, a transmission path is randomly selected from the available next-hop nodes;

[0069] A pseudo data packet is generated based on node priority and topology information. The pseudo data packet contains randomly generated virtual data and identifiers to confuse the characteristics of real data packets.

[0070] Furthermore, removing disturbance data according to the preset rules at the transmission optimization layer includes:

[0071] Adjust the parameters based on the time interval in the metadata to restore the original transmission time interval sequence of the data packets;

[0072] Restore the original order of the data packets based on the order adjustment rules in the metadata;

[0073] Identify and remove dummy packets based on the dummy packet identifier and insertion position in the metadata segment.

[0074] Furthermore, restoring the original data based on the grid topology information at the data obfuscation layer includes:

[0075] Remove the virtual padding data according to the padding data position and length recorded in the metadata segment;

[0076] The node identifier and topology relationship hash value in the data packet are compared with the grid topology information to verify the topological consistency of the node;

[0077] If the verification is successful, the obfuscated data is decoded to restore the temporal and spatial correlation characteristics of the data;

[0078] Reconstruct the original data content based on the inverse operation of the obfuscation rules.

[0079] This invention effectively solves the problem of man-in-the-middle attacks in the background art, which analyze the spatiotemporal and periodic information of the power grid through data packets, by designing a power information protection method and system based on a secure communication protocol. Specific beneficial effects are as follows:

[0080] At the data obfuscation layer of the data collection device, collected data is dynamically padded or fragmented to decouple packet size from actual load. By randomly filling virtual data segments or fragmenting and reassembling the original data, the packet size varies randomly within a preset range. This prevents attackers from directly inferring load information from packet size, hiding the true node load and thus protecting the grid's operational status.

[0081] At the transmission optimization layer, a random time offset mechanism is introduced. While maintaining overall transmission efficiency, this mechanism disrupts fixed time intervals by randomly delaying or advancing packet transmissions. Furthermore, the insertion position and transmission timing of dummy packets are dynamically adjusted to further disrupt periodicity. The packet transmission intervals no longer exhibit fixed periodic characteristics, making it difficult for attackers to infer the sampling period and system rhythm through time interval analysis, thereby concealing the operating patterns of the power system.

[0082] Dynamic path selection is performed at intermediate nodes, randomly adjusting the transmission path of data packets so that the same data packet passes through different transmission nodes. Furthermore, dummy packets are generated with similar size and identity to real packets to confuse attackers. Dynamic path selection and dummy packet insertion significantly increase the randomness of data transmission paths, making it difficult for attackers to infer the power grid topology by analyzing paths and node identities, effectively protecting critical node information.

[0083] By appending recovery metadata segments to data packets (such as padding data location, perturbation rules, and path selection identifiers), the data center can restore the original data according to the recovery rules. Simultaneously, hash value checksums and digital signature verification are performed at the encryption and verification layer to ensure the integrity and authenticity of the restored data. The data center can accurately restore the perturbed data without compromising the correctness of the original data, thus ensuring data integrity and the reliability of grid operation decisions.

[0084] This invention effectively addresses the man-in-the-middle attack problem mentioned in the background art by perturbing and dynamically obfuscating characteristics such as packet size, time interval, transmission path, and node identification. Its beneficial effects are reflected in privacy protection, enhanced anti-analysis capabilities, guaranteed data availability, and improved system security, comprehensively enhancing the security and reliability of power information. BRIEF DESCRIPTION OF THE DRAWINGS

[0085] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0086] Figure 1 It is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0087] Below, the invention is preferably described with reference to the accompanying drawings and specific embodiments.

[0088] This embodiment solves the above problem through the following steps:

[0089] In one embodiment, reference Figure 1 The present invention provides a power information protection method based on a secure communication protocol. This method establishes a multi-layered secure communication protocol framework and combines technical means such as data packet obfuscation, encryption and verification, and transmission optimization to achieve secure transmission of power information between power information collection equipment, transmission intermediate nodes, and data centers. Specifically, this method includes perturbation processing of periodic and spatiotemporal correlation characteristics, application of dynamic encryption mechanisms, and data recovery and integrity verification based on the power grid topology structure, so as to effectively prevent data feature leakage and ensure the confidentiality, integrity, and anti-attack capability of information transmission. Specifically, the method includes the following steps:

[0090] Step S10: establishing a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer.

[0091] The data obfuscation layer is used to obfuscate the original data packets of power information, including but not limited to adjusting the data packet size, introducing virtual filler data, changing the transmission order and time interval of the data packets, so as to disrupt the periodicity and spatiotemporal correlation characteristics of the data; the data obfuscation layer combines the power grid topology information and implements multi-level data perturbation between the collection equipment, intermediate nodes and data centers by setting obfuscation rules to enhance data privacy.

[0092] The encryption and verification layer is used to encrypt and verify the obfuscated data, including using a symmetric encryption algorithm to encrypt the data content to ensure the confidentiality of the data, and using digital signatures or hash verification technology to verify the integrity of the data packet; the encryption and verification layer realizes the secure distribution of keys between the communicating parties, and combines the identifier of the data packet to ensure that the data is tamper-proof and anti-forgery during the transmission process.

[0093] The transmission optimization layer is used to optimize the transmission path and transmission timing of encrypted data packets, including a camouflage strategy based on a randomized path selection mechanism, dynamic transmission frequency adjustment, and traffic characteristics to further conceal the characteristics of data transmission; the transmission optimization layer combines preset rules and real-time monitoring information to dynamically adjust the path, interval, and priority of data packet transmission, thereby ensuring data transmission efficiency while preventing attackers from obtaining data characteristics through traffic analysis.

[0094] Through the above-mentioned layered design, the secure communication protocol can achieve multi-level protection of power information during collection, transmission and processing, and improve the privacy, reliability and anti-attack capability of data transmission.

[0095] Step S20: deploying a communication module supporting the layered security communication protocol between the power information collection device, the transmission intermediate node and the data center.

[0096] In the power information collection equipment, a communication module supporting the data obfuscation layer, encryption and verification layer is configured. The communication module includes a data collection unit, an obfuscation processing unit and an encryption unit. The data collection unit is used to obtain power grid operation status information, including but not limited to parameters such as voltage, current, and power; the obfuscation processing unit adjusts the collected data according to the power grid topology information, specifically including filling virtual data or adjusting the data packet size to conceal periodic characteristics; the encryption unit uses a symmetric encryption algorithm to encrypt the adjusted data, and adds an identifier to mark the source and order of the data packet.

[0097] In the intermediate transmission node, a communication module that supports the data obfuscation layer and the transmission optimization layer is configured. The communication module includes a data receiving unit, a disturbance processing unit and a path optimization unit. The data receiving unit is used to receive encrypted data packets from the acquisition device; the disturbance processing unit introduces randomness to the received data packets according to preset rules, including disrupting the transmission order of the data packets, modifying the transmission interval and forging virtual data packets; the path optimization unit dynamically selects the transmission path based on the real-time network status to conceal the temporal and spatial correlation of the data.

[0098] In the data center, a communication module that supports the full functions of the layered security communication protocol is configured. The communication module includes a data receiving unit, a decryption and verification unit, a data recovery unit and a storage unit. The data receiving unit is used to receive obfuscated encrypted data packets from the transmission intermediate node; the decryption and verification unit decrypts the data packet content using a key and verifies the integrity of the data packet using a digital signature or hash value; the data recovery unit recovers the decrypted data packet according to the power grid topology information and obfuscation rules, including restoring the original size, transmission order and timestamp of the data; the storage unit is used to store the recovered data in a database for subsequent analysis and processing.

[0099] In step S30, the collection device registers and obtains the grid topology information, adjusts the obtained data packet to a preset size according to the grid topology information at the data obfuscation layer, and encrypts the adjusted data at the encryption and verification layer.

[0100] The collection device initiates a registration request to the data center through the communication module, and the request includes the device identification, geographical location and supported communication capabilities of the collection device.

[0101] The data center verifies the legitimacy of the data collection device and distributes the grid topology information to the data collection device after verification. The information includes:

[0102] Node location and type: including substation, line node or load terminal;

[0103] Node adjacency: describes the physical or logical connection relationship between nodes;

[0104] Topological weight information: such as the load level and operating status of the lines between nodes;

[0105] Node priority: Determine the importance of nodes based on sensitivity grading.

[0106] The acquisition device initializes the data packet adjustment rules and recovery parameters according to the power grid topological structure information to support adjustment and restoration operations.

[0107] The acquisition device performs the following adjustment steps on the collected data packets according to the power grid topological structure information at the data obfuscation layer:

[0108] Step 31: Determine the data packet adjustment rules

[0109] The acquisition device calculates the node importance score S according to the adjacency relationship and weight information of the nodes in the topological structure. The formula is as follows:

[0110] S = ɑ * W + β * N + γ * P

[0111] Where,

[0112] W is the load weight of the line where the node is located;

[0113] N is the number of node adjacency relationships (i.e., the number of adjacent nodes);

[0114] P is the sensitivity grading of the node;

[0115] ɑ, β, γ are adjustment weight coefficients, which are dynamically set according to the power grid operation requirements.

[0116] According to the score S, the nodes are divided into the following three categories:

[0117] High-importance nodes (S > T1): The data packet is adjusted to 150% to 200% of the original size;

[0118] Medium-importance nodes (T2 <= S <= T1): The data packet is adjusted to 120% to 150% of the original size;

[0119] Low-importance nodes (S < T2): The data packet is adjusted to 100% to 120% of the original size.

[0120] Where, T1 and T2 are predefined score thresholds.

[0121] Step 32: Generate the padding data segment

[0122] Fill the virtual data segment in the original data packet. The length and content are dynamically adjusted according to the node importance score. The padding data segment contains the node identifier, topological relationship hash value, and virtual data length for subsequent data recovery.

[0123] Step 33: Random Perturbations

[0124] Random perturbations are introduced into the adjusted data packets, and the adjustment range is dynamically set according to the score.

[0125] For example, for a node with a score of 1.8 (high importance), the random perturbation range is set to ±50 bytes.

[0126] Step 34: Embed Recovery Information

[0127] The recovery metadata segment is appended to the packet header or tail, including:

[0128] Original packet size;

[0129] Fill data length and position;

[0130] Random perturbation offset value;

[0131] Node identifier and topology relationship hash value.

[0132] Power information has obvious temporal and spatial correlations, and the transmission characteristics of data (such as packet size, time interval, and path selection) directly reflect the topological structure of the power grid, the operating status of nodes, and load distribution.

[0133] By associating the adjustment of data packets with the grid topology information, differentiated data processing can be implemented based on the unique status and adjacency of each node, ensuring that the adjusted data does not expose its true spatiotemporal correlation characteristics.

[0134] Fixed sizes lack randomness, allowing attackers to identify specific patterns by observing data flow characteristics and thus bypass security measures. This invention uses a random perturbation mechanism to randomly distribute the size of data packets within a certain range, making it more difficult for attackers to analyze and prevent them from inferring patterns.

[0135] After completing the adjustment of the data obfuscation layer, the acquisition device performs the following encryption processing on the adjusted data packet at the encryption and verification layer:

[0136] Use a symmetric encryption algorithm (such as AES-GCM) to generate a ciphertext data packet;

[0137] Calculate the hash value of the data packet for subsequent verification;

[0138] Combine the ciphertext and the recovery metadata segment to form a complete data packet.

[0139] For example:

[0140] A data acquisition device is located at a substation node in a power grid. This node is adjacent to two line nodes. The line load weight is 80%, and the node sensitivity level is 2. The weight coefficients are set to ɑ = 0.5, β = 0.3, γ = 0.2, and the scoring thresholds T1 = 1.5 and T2 = 1.0.

[0141] Calculate node importance score:

[0142] S=0.5*0.8+0.3*2+0.2*2=1.9

[0143] According to the score, the node is a high-importance node.

[0144] Adjustment rules:

[0145] The original data packet size is 1000 bytes;

[0146] According to the high importance rule, the adjustment range is 150% to 200%, and the adjusted size is 1800 bytes;

[0147] The random perturbation is set to ±50 bytes, and the adjusted packet size is 1850 bytes.

[0148] Fill the dummy data segment:

[0149] The length of the padded dummy data is 800 bytes;

[0150] The virtual data segment contains the node identifier, topology hash value and recovery information.

[0151] Embed recovery metadata segment:

[0152] Original data packet size: 1000 bytes;

[0153] Padding length: 800 bytes;

[0154] Random perturbation offset value: +50 bytes;

[0155] Recovery information: node identifier and topology hash value.

[0156] Encryption processing:

[0157] Use AES-GCM encryption to generate ciphertext;

[0158] Calculate the hash value and append it to the packet header;

[0159] Combine the ciphertext and recovery metadata segments to form a complete encrypted package.

[0160] By embedding detailed recovery metadata during the adjustment process and combining it with fixed rule identifiers and offset records, the adjustment mechanism of the present invention achieves complete reversibility of data packet adjustments. At the same time, it relies on topology information to assist in recovery, ensuring that the data center can accurately restore the original data, thereby taking into account both data privacy and availability.

[0161] In step S40, the intermediate node introduces randomness to the received data in the transmission optimization layer according to a preset rule, and disturbs the periodic characteristics.

[0162] The intermediate nodes perform the following random perturbation operations on the received data packets at the transmission optimization layer according to the preset rules:

[0163] Step 41: Adjust the packet transmission interval

[0164] Calculate the periodicity characteristics of the current node based on the node identifier and topology information contained in the recovered metadata segment of the data packet;

[0165] A random offset value is introduced to adjust the transmission interval of data packets. The offset value is generated according to the following rules:

[0166] Offset value = basic transmission interval * (1 + random perturbation factor)

[0167] The random perturbation factor is a random value between -0.2 and 0.2;

[0168] For example, assuming that the basic transmission interval is 100 milliseconds and the random perturbation factor is 0.15, the transmission interval after the shift is 115 milliseconds.

[0169] Step 42: Change the order of data packet transmission

[0170] Randomly group data packets based on topological adjacency information and node priority;

[0171] Within each group of data packets, rearrange the transmission order of the data packets;

[0172] For example, assume that the order of received data packets is A, B, C, D, and after grouping, they are adjusted to group 1 (B, D) and group 2 (A, C), and the transmission order is B, D, A, C.

[0173] Step 43: Dynamically Adjust the Transmission Path

[0174] According to the adjacency relationship of the current node, a transmission path is randomly selected from the available next-hop nodes;

[0175] To ensure the security of data packets, a path identifier is appended to the recovery metadata segment to support path verification and optimization in the data center;

[0176] For example, it is assumed that the connection between the current node and the next-hop node is Node1 and Node2, and Node2 is randomly selected as the next-hop transmission node.

[0177] Step 44: Introducing a fake packet

[0178] Generate a pseudo data packet based on node priority and topology information. The pseudo data packet contains randomly generated virtual data and identifiers to obfuscate the characteristics of the real data packet.

[0179] Set the size of the pseudo-packet to be similar to that of the real packet to increase the difficulty of packet feature analysis;

[0180] For example, if the size of the real data packet is 1500 bytes, a dummy data packet with a size of 1400 to 1600 bytes is generated and inserted into the transmission queue.

[0181] By introducing a transmission optimization method with random perturbations, the present invention can effectively break the periodic characteristics and spatiotemporal correlation of data, making it difficult for attackers to obtain valuable information through traffic analysis, while ensuring that the data center can correctly restore data by recovering metadata segments.

[0182] In step S50, after the data center receives the data packet, it removes the disturbance data according to the preset rules at the transmission optimization layer; decrypts the data after the disturbance is removed at the encryption and verification layer; restores the original data according to the power grid topology information at the data obfuscation layer; and verifies the integrity of the data through the data signature at the encryption and verification layer.

[0183] The data center receives a data packet from a transmission intermediate node through a communication module, wherein the data packet includes an original data portion and a restored metadata segment;

[0184] At the transport optimization layer, the data center first parses the metadata section of the data packet to extract the following information:

[0185] The perturbation rules required for recovery (including time intervals, path selection, and sequence adjustment information);

[0186] Packet identifier and topology information hash value;

[0187] The length and position of the padding data;

[0188] Hash values ​​and data signatures of encrypted data.

[0189] Based on the parsed metadata segments, the data center performs the following steps to remove the perturbations introduced during transmission:

[0190] Step 511: Restore transmission time interval

[0191] Adjust the parameters based on the time interval in the metadata to restore the original transmission time interval sequence of the data packets;

[0192] For example, if the disturbance time interval of data packet A is 120 milliseconds and the recovery parameter is -20 milliseconds, the interval after recovery is 100 milliseconds.

[0193] Step 512: Rearrange the transmission order

[0194] Restore the original order of the data packets based on the order adjustment rules in the metadata;

[0195] For example, if the receiving order is C, A, B, and the recovery rule is [2, 3, 1], the order after restoration is A, B, C.

[0196] Step 513: Eliminate fake data packets

[0197] Identify and remove dummy packets based on dummy packet identifiers and insertion positions in the metadata segment;

[0198] For example, if the data packet sequence is A, X (dummy data packet), and B, and the metadata indicates that the dummy data packet X is located at the second position, then X is removed to obtain the sequence A and B.

[0199] After removing the disturbed data, the data center decrypts the data packet. The specific steps are as follows:

[0200] Step 521: Extracting Encrypted Data

[0201] Extract the encrypted raw data portion from the packet, ignoring other metadata content.

[0202] Step 522: Decryption operation

[0203] Use the preset symmetric key (such as the AES-GCM key) to decrypt the encrypted data to obtain the obfuscated data content;

[0204] For example, if the ciphertext size of the encrypted data packet is 1500 bytes, after decryption, it is restored to 1200 bytes of original data containing obfuscated data.

[0205] Step 523: Verify decryption integrity

[0206] Calculate the hash value of the decrypted data and compare it with the hash value in the data packet to verify the integrity of the decrypted data;

[0207] Exemplarily, the decrypted data hash value is 0x12345, which is consistent with the appended hash value, confirming that the decryption is successful.

[0208] After decryption is completed, the data center restores the original data packet content based on the power grid topology information in the data obfuscation layer. The specific steps are as follows:

[0209] Step 531: Remove padding data

[0210] Remove the virtual padding data according to the padding data position and length recorded in the metadata segment;

[0211] For example, if the padding data is 500 bytes long and is located at the end of the data packet, 700 bytes of real data are obtained after removal.

[0212] Step 532: Reconstruct data based on topology information

[0213] The node identifier and topology relationship hash value in the data packet are compared with the grid topology information to verify the topological consistency of the node;

[0214] If the verification is successful, the obfuscated data is decoded to restore the temporal and spatial correlation characteristics of the data;

[0215] For example, if the node identifier indicates that the data originates from substation A, and the topology hash value is 0x56789, which is consistent with the grid topology record, the recovery operation can continue.

[0216] Step 533: Restore original data order and content

[0217] Reconstruct the original data content based on the inverse operation of the obfuscation rules;

[0218] Exemplarily, the order of the obfuscated data is [3, 1, 2], the restoration rule indicates the order is [1, 2, 3], and the restored data is the original data.

[0219] After restoring the original data, the data center verifies the integrity of the restored data to ensure that the data has not been tampered with. The specific steps are as follows:

[0220] Step 541: Calculate the data signature

[0221] Generate a hash value for the recovered data and generate a digital signature based on the preset private key;

[0222] Exemplarily, the hash value of the calculated recovery data is 0xABCDE, and the digital signature is SI G123.

[0223] Step 542: Verify signature consistency

[0224] Compare the generated digital signature with the additional signature in the data packet to verify the authenticity of the data;

[0225] Exemplarily, the signature in the data packet is SIG123, which is consistent with the generated signature, and the verification is successful.

[0226] Through multi-step processing of transmission optimization layer, encryption and verification layer and data obfuscation layer, the present invention can accurately restore the original data, while verifying the integrity and authenticity of the data, ensuring the security and availability of the transmitted data.

[0227] On the other hand, the present invention also provides a power information protection system based on a secure communication protocol, comprising:

[0228] A management module for establishing a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer;

[0229] A collection device, wherein the collection device is installed with the layered secure communication protocol, the collection device registers and obtains power grid topology information, the collection device adjusts the size of the obtained data packet according to the power grid topology information at the data obfuscation layer, and encrypts the adjusted data at the encryption and verification layer;

[0230] An intermediate node, wherein the intermediate node installs the layered secure communication protocol and introduces randomness to the received data at the transmission optimization layer according to preset rules to perturb the periodic characteristics;

[0231] A data center is provided, wherein the data center is installed with the layered secure communication protocol. After receiving a data packet, the data center removes disturbance data according to the preset rules at the transmission optimization layer; decrypts the data after disturbance removal at the encryption and verification layer; restores the original data according to the power grid topology information at the data obfuscation layer; and verifies the integrity of the data through a data signature at the encryption and verification layer.

[0232] The prior art mentioned in the above background technology section and specific embodiments section of the present invention can be regarded as part of the present invention and used to understand the meaning of some technical features or parameters.

Claims

1. A power information protection method based on a secure communication protocol, characterized in that: The method comprises the following steps: Establish a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer; Deploy a communication module supporting the layered security communication protocol between the power information collection equipment, the transmission intermediate node and the data center; The collection device registers and obtains the power grid topology information, the collection device adjusts the size of the obtained data packet according to the power grid topology information at the data obfuscation layer, and encrypts the adjusted data at the encryption and verification layer; The intermediate node introduces randomness to the received data in the transmission optimization layer according to preset rules, and disturbs the periodic characteristics; After receiving the data packet, the data center removes the disturbed data according to the preset rules at the transmission optimization layer; Decrypt the data after removing disturbances at the encryption and verification layer; In the data obfuscation layer, the original data is restored based on the grid topology information; Verify data integrity through data signatures at the encryption and verification layer; Adjusting the size of the obtained data packet according to the power grid topology information at the data obfuscation layer includes: The collection device calculates the node importance score S based on the adjacency relationship and weight information of the nodes in the topology structure; Fill the original data packet with a virtual data segment. The length and content are dynamically adjusted according to the node importance score. The filled data segment contains the node identifier, topology relationship hash value and virtual data length for subsequent data recovery. Introducing random perturbations into the adjusted data packets, with the adjustment range dynamically set based on the score; Append a recovery metadata segment to the header or tail of the data packet, including: original data packet size; padding data length and position; random perturbation offset value; node identifier and topology relationship hash value; Introducing randomness into received data at the transmission optimization layer includes: Calculate the periodicity characteristics of the current node based on the node identifier and topology information contained in the recovered metadata segment of the data packet; A random offset value is introduced to adjust the transmission interval of data packets. The offset value is generated according to the following rules: Offset value = basic transmission interval (1+random perturbation factor) The random perturbation factor is a random value between -0.2 and 0.2; Randomly group data packets based on topological adjacency information and node priority; Within each group of data packets, rearrange the transmission order of the data packets; According to the adjacency relationship of the current node, a transmission path is randomly selected from the available next-hop nodes; A pseudo data packet is generated based on node priority and topology information. The pseudo data packet contains randomly generated virtual data and identifiers to confuse the characteristics of real data packets.

2. The power information protection method based on the secure communication protocol according to claim 1, characterized in that: At the transmission optimization layer, according to the preset rules, removing disturbance data includes: Adjust the parameters according to the time interval in the metadata to restore the original transmission time interval sequence of the data packets; Restore the original order of the data packets based on the order adjustment rules in the metadata; Identify and remove dummy packets based on the dummy packet identifier and insertion position in the metadata segment.

3. The power information protection method based on a secure communication protocol according to claim 1, characterized in that: Restoring the original data based on the grid topology information at the data obfuscation layer includes: Remove the virtual padding data according to the padding data position and length recorded in the metadata segment; The node identifier and topology relationship hash value in the data packet are compared with the grid topology information to verify the topological consistency of the node; If the verification is successful, the obfuscated data is decoded to restore the temporal and spatial correlation characteristics of the data; Reconstruct the original data content based on the inverse operation of the obfuscation rules.

4. A power information protection system based on a secure communication protocol, characterized in that: The system comprises: A management module for establishing a layered secure communication protocol, including a data obfuscation layer, an encryption and verification layer, and a transmission optimization layer; A collection device, wherein the collection device is installed with the layered secure communication protocol, the collection device registers and obtains power grid topology information, the collection device adjusts the size of the obtained data packet according to the power grid topology information at the data obfuscation layer, and encrypts the adjusted data at the encryption and verification layer; An intermediate node, wherein the intermediate node installs the layered secure communication protocol and introduces randomness to the received data at the transmission optimization layer according to preset rules to perturb the periodic characteristics; A data center, wherein the data center is installed with the layered secure communication protocol. After receiving a data packet, the data center removes disturbance data according to the preset rules at the transmission optimization layer; decrypts the data after the disturbance is removed at the encryption and verification layer; restores the original data based on the power grid topology information at the data obfuscation layer; and verifies the integrity of the data through data signatures at the encryption and verification layer; Adjusting the size of the obtained data packet according to the power grid topology information at the data obfuscation layer includes: The collection device calculates the node importance score S based on the adjacency relationship and weight information of the nodes in the topology structure; Fill the original data packet with a virtual data segment. The length and content are dynamically adjusted according to the node importance score. The filled data segment contains the node identifier, topology relationship hash value and virtual data length for subsequent data recovery. Introducing random perturbations into the adjusted data packets, with the adjustment range dynamically set based on the score; Append a recovery metadata segment to the header or tail of the data packet, including: original data packet size; padding data length and position; random perturbation offset value; node identifier and topology relationship hash value; Introducing randomness into received data at the transmission optimization layer includes: Calculate the periodicity characteristics of the current node based on the node identifier and topology information contained in the recovered metadata segment of the data packet; A random offset value is introduced to adjust the transmission interval of data packets. The offset value is generated according to the following rules: Offset value = basic transmission interval (1+random perturbation factor) The random perturbation factor is a random value between -0.2 and 0.2; Randomly group data packets based on topological adjacency information and node priority; Within each group of data packets, rearrange the transmission order of the data packets; According to the adjacency relationship of the current node, a transmission path is randomly selected from the available next-hop nodes; A pseudo data packet is generated based on node priority and topology information. The pseudo data packet contains randomly generated virtual data and identifiers to confuse the characteristics of real data packets.

5. The power information protection system based on the secure communication protocol according to claim 4, characterized in that: At the transmission optimization layer, according to the preset rules, removing disturbance data includes: Adjust the parameters according to the time interval in the metadata to restore the original transmission time interval sequence of the data packets; Restore the original order of the data packets based on the order adjustment rules in the metadata; Identify and remove dummy packets based on the dummy packet identifier and insertion position in the metadata segment.

6. The power information protection system based on the secure communication protocol according to claim 4, characterized in that: Restoring the original data based on the grid topology information at the data obfuscation layer includes: Remove the virtual padding data according to the padding data position and length recorded in the metadata segment; The node identifier and topology relationship hash value in the data packet are compared with the grid topology information to verify the topological consistency of the node; If the verification is successful, the obfuscated data is decoded to restore the temporal and spatial correlation characteristics of the data; Reconstruct the original data content based on the inverse operation of the obfuscation rules.

Citation Information

Patent Citations

  • Secure dynamic communication network and protocol

    CN107750441A

  • Secret-related environment wireless communication method

    CN115802340A