Session key determination method and device, computer equipment and storage medium
By using registration centers and blockchain technologies on smart meters to generate and verify keys, the problem of low key security in traditional power grids is solved, and higher information security and session key security are achieved.
Patent Information
- Application Number
- CN202510129095.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-05
- Publication Date
- 2025-05-09
AI Technical Summary
The shared keys of power grid terminals in traditional power grids are low, resulting in threats to information and privacy security.
By implementing a session key determination method on a smart meter, the pseudo-identity information and initial keys are generated and verified using registration center and blockchain technology, and then key negotiation authentication is performed with the edge server based on these keys to determine the session key between the smart meter and the edge server.
Improve the security of the key, and through the combination of multiple verifications and blockchain verification, the accuracy of authentication and the security of the session key are enhanced, avoiding the leakage of identity information.
Smart Images

Figure CN119966623A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of electric meter authentication, and in particular to a method, apparatus, computer equipment, storage medium and computer program product for determining a session key. Background Art
[0002] With the rapid development of power grids, a large number of power grid terminals are connected to the grid, with various types of power grid terminals and various communication methods. Therefore, the security of information in the power grid is a key factor restricting the development of the power grid.
[0003] In traditional technology, in order to protect the information and privacy security of each grid terminal in the power grid, a shared key is configured for each grid terminal before the grid terminal is connected to the grid, and the security of the shared key is relatively low. Summary of the invention
[0004] Based on this, it is necessary to provide a session key determination method, apparatus, computer device, computer-readable storage medium and computer program product that can improve key security in response to the above technical problems.
[0005] In a first aspect, the present application provides a method for determining a session key. Applied to a smart meter, the method comprises:
[0006] When the smart meter completes system initialization, it sends meter information to the registration center; receives pseudo-identity information and initial key fed back by the registration center; the pseudo-identity information and initial key are generated by the registration center when it is determined that the smart meter has passed identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; the meter key of the smart meter is determined based on the initial key; key negotiation authentication is performed with the edge server based on the meter key, and the session key between the smart meter and the edge server is determined.
[0007] In one of the embodiments, the meter information includes meter excitation information, meter response information and meter identity; when the smart meter completes system initialization, sending the meter information to a registration center includes: randomly generating meter excitation information when the smart meter completes system initialization; acquiring meter hardware features and meter identity of the smart meter; performing information conversion on the meter excitation information according to an excitation response function matched with the meter hardware features to obtain meter response information; and sending the meter excitation information, the meter response information and the meter identity to the registration center.
[0008] In one of the embodiments, the meter key includes a meter private key and a meter public key; determining the meter key of the smart meter based on the initial key includes: obtaining a registration generator of the registration center when the registration center completes system initialization; determining the product of the initial key and the registration generator as the meter public key; and determining the initial key as the meter private key.
[0009] In one of the embodiments, the key negotiation authentication is performed with the edge server based on the meter key to determine the session key between the smart meter and the edge server, including: determining a meter random number and a meter timestamp of the smart meter; determining information to be verified of the smart meter according to the meter random number, the meter timestamp and the meter key; sending the information to be verified to the edge server, and obtaining a server random number and a server timestamp fed back by the edge server; the server random number and the server timestamp are sent by the edge server when it is determined that the smart meter has passed the smart contract verification of the blockchain to which the edge server belongs based on the information to be verified; and determining the session key between the smart meter and the edge server based on the information to be verified, the server random number and the server timestamp.
[0010] In one of the embodiments, determining the session key between the smart meter and the edge server based on the information to be verified, the server random number and the server timestamp includes: obtaining the server key when the meter timestamp and the server timestamp meet the timestamp verification condition; determining the session key between the smart meter and the edge server based on the server key, the meter key, the server random number and the meter random number.
[0011] In a second aspect, the present application also provides a session key determination method, which is applied to a registration center, and the method includes:
[0012] Receive meter information sent by a smart meter; the meter information is sent by the smart meter after completing system initialization; authenticate the smart meter based on the meter information; if it is determined that the smart meter passes the identity authentication, generate pseudo-identity information and an initial key for the smart meter; call the smart contract of the blockchain to which the registration center belongs to verify the pseudo-identity information and the initial key; if the pseudo-identity information and the initial key pass the verification, send the pseudo-identity information and the initial key to the smart meter, so that the smart meter determines the meter key based on the initial key, and performs key negotiation authentication with the edge server based on the meter key, so as to determine the session key between the smart meter and the edge server.
[0013] In a third aspect, the present application further provides a session key determination device. Applied to a smart meter, the device comprises:
[0014] An electric meter information sending module is used to send the electric meter information to the registration center when the smart meter completes system initialization; an information receiving module is used to receive the pseudo-identity information and the initial key fed back by the registration center; the pseudo-identity information and the initial key are generated by the registration center when it is determined based on the electric meter information that the smart meter has passed the identity authentication, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; an electric meter key determination module is used to determine the electric meter key of the smart meter based on the initial key; a session key determination module is used to perform key negotiation authentication with the edge server based on the electric meter key, and determine the session key between the smart meter and the edge server.
[0015] In a fourth aspect, the present application further provides a session key determination device. Applied to a registration center, the device comprises:
[0016] An electric meter information receiving module is used to receive the electric meter information sent by the smart meter; the electric meter information is sent by the smart meter when the system initialization is completed; an identity authentication module is used to authenticate the smart meter based on the electric meter information; an information generation module is used to generate pseudo-identity information and an initial key for the smart meter when it is determined that the smart meter passes the identity authentication; an information verification module is used to call the smart contract of the blockchain to which the registration center belongs to verify the pseudo-identity information and the initial key; a key sending module is used to send the pseudo-identity information and the initial key to the smart meter when the pseudo-identity information and the initial key pass the verification, so that the smart meter determines the meter key based on the initial key, and performs key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
[0017] In a fifth aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0018] When the smart meter completes system initialization, it sends meter information to the registration center; receives pseudo-identity information and initial key fed back by the registration center; the pseudo-identity information and initial key are generated by the registration center when it is determined that the smart meter has passed identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; the meter key of the smart meter is determined based on the initial key; key negotiation authentication is performed with the edge server based on the meter key, and the session key between the smart meter and the edge server is determined.
[0019] In a sixth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0020] When the smart meter completes system initialization, it sends meter information to the registration center; receives pseudo-identity information and initial key fed back by the registration center; the pseudo-identity information and initial key are generated by the registration center when it is determined that the smart meter has passed identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; the meter key of the smart meter is determined based on the initial key; key negotiation authentication is performed with the edge server based on the meter key, and the session key between the smart meter and the edge server is determined.
[0021] In a seventh aspect, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0022] When the smart meter completes system initialization, it sends meter information to the registration center; receives pseudo-identity information and initial key fed back by the registration center; the pseudo-identity information and initial key are generated by the registration center when it is determined that the smart meter has passed identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; the meter key of the smart meter is determined based on the initial key; key negotiation authentication is performed with the edge server based on the meter key, and the session key between the smart meter and the edge server is determined.
[0023] The above-mentioned session key determination method, device, computer equipment, storage medium and computer program product, when the smart meter completes system initialization, sends meter information to the registration center, receives pseudo identity information and initial key fed back by the registration center, the pseudo identity information and initial key are generated by the registration center when the smart meter is determined to have passed identity authentication based on the meter information, and sent when the pseudo identity information and initial key are verified by the smart contract of the blockchain to which the registration center belongs. The pseudo identity information can avoid identity information leakage, thereby improving the security of power grid information. The meter key of the smart meter is determined based on the initial key, and the above-mentioned method is used to perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server. On the one hand, multiple verifications are performed through the interaction of the smart meter, the registration center and the edge server, thereby improving the accuracy of authentication, thereby improving the security of the session key. On the other hand, the pseudo identity information and initial key are received when the smart contract of the blockchain to which the registration center belongs is verified, thereby further improving the security of the pseudo identity information and initial key, thereby improving the security of the session key. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 A diagram of an application environment of a method for determining a session key in an embodiment;
[0025] Figure 2 A schematic diagram of a process for determining a session key in an embodiment;
[0026] Figure 3 A schematic diagram of a flow chart of a method for determining a session key applied to a registration center in one embodiment;
[0027] Figure 4 A flowchart of a blockchain-assisted authentication key negotiation method for a smart grid in one embodiment;
[0028] Figure 5 It is a structural block diagram of a session key determination device in one embodiment;
[0029] Figure 6 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0031] The session key determination method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown, the smart meter 102 is connected to the registration center 104 for communication, and the smart meter 102 is connected to the edge server 106 for communication.
[0032] The smart meter 102 can send meter information to the registration center 104 when it completes system initialization. The smart meter 102 can receive pseudo identity information and initial key fed back by the registration center 104. The pseudo identity information and initial key are generated by the registration center 104 when it determines that the smart meter 102 has passed identity authentication based on the meter information, and are sent when the pseudo identity information and initial key are verified by the smart contract of the blockchain to which the registration center 104 belongs. The smart meter 102 can determine its own meter key based on the initial key. The smart meter 102 can determine the session key between the smart meter 102 and the edge server 106 based on key negotiation authentication between itself and the edge server 106.
[0033] Among them, the smart meter 104 can be a device for accurately measuring power consumption and reporting data in real time. The registration center 104 can refer to a registration center server, and the registration center server can be implemented by an independent server or a server cluster composed of multiple servers. The edge server 106 can be implemented by an independent server or a server cluster composed of multiple servers.
[0034] In one embodiment, Figure 2 As shown, a session key determination method is provided, which is applied to Figure 1 The smart meter 102 in FIG. 1 is used as an example for explanation, including:
[0035] S202: When the smart meter completes system initialization, it sends meter information to a registration center.
[0036] Among them, a smart meter (SM) can be a device used to accurately measure electricity consumption and report data in real time. It can regularly collect electricity consumption data for each user and transmit this information through the network. Smart meters can integrate blockchain technology to ensure the security and immutability of data. In addition, smart meters can also participate in the maintenance of distributed ledgers as blockchain nodes, thereby realizing decentralized energy management and transactions.
[0037] The Registration Center (RC) can represent a central server that manages the authentication and registration process of devices. For example, in a smart grid, the Registration Center can receive registration requests from smart meters and / or edge servers and verify the user's identity by calling smart contracts. The Registration Center can also upload registration information to the blockchain to ensure the transparency and security of identity information.
[0038] The meter information may be information required by the smart meter during the meter registration process, for example, the meter information includes meter excitation information, meter response information, meter identity, other meter information, and the like.
[0039] System initialization may refer to an initialization operation performed on a smart meter.
[0040] Specifically, the smart meter can control itself to perform system initialization in response to the smart grid authentication deployment start event. When the smart meter completes system initialization, the smart meter can send meter information to the registration center.
[0041] In one embodiment, the meter information may include meter excitation information and meter response information. The smart meter may directly obtain the meter excitation information and the meter response information in response to the smart grid authentication deployment start event.
[0042] In one embodiment, the smart meter can randomly generate meter excitation information when the system initialization is completed. The smart meter can convert the meter excitation information according to the excitation response function matched with the hardware characteristics of the meter to obtain meter response information.
[0043] S204, receiving the pseudo identity information and initial key fed back by the registration center.
[0044] Among them, the pseudo identity information can be the identity information generated by the registration center for the smart meter. The pseudo identity information replaces the real identity information of the smart meter. By using the pseudo identity information, the real identity of the smart meter can be effectively hidden, preventing attackers from tracing the real identity of the user through power data, thereby protecting the user's privacy.
[0045] The initial key may refer to a key generated by the registration center for the smart table during the registration phase.
[0046] Specifically, the pseudo-identity information and the initial key are generated by the registration center when it is determined based on the meter information that the smart meter has passed the identity authentication, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs.
[0047] Blockchain is a distributed ledger technology that can provide decentralized, transparent and secure data storage solutions. In smart grids, blockchain can be used to record and verify data transactions of smart meters to ensure the authenticity and integrity of the data. In addition, blockchain can also support the execution of smart contracts, thereby automating energy transactions and demand response plans.
[0048] A smart contract can represent an automatically executed computer program, a contract that runs on a computer in cyberspace.
[0049] Specifically, the smart meter can receive the pseudo identity information and initial key fed back by the registration center through a secure channel.
[0050] S206: Determine a meter key of the smart meter based on the initial key.
[0051] The meter key refers to the key for the smart meter that has been successfully registered by the registration center. The meter key can ensure the security of information exchange between the smart meter and the registration center.
[0052] Specifically, the meter terminal can directly encrypt the initial key to obtain the meter key of the smart meter. There are many encryption methods, which are not limited here and can be flexibly selected according to actual conditions.
[0053] In one embodiment, the electric meter key may include an electric meter public key and an electric meter private key. The electric meter terminal may obtain a registration generator from the registration center when the registration center completes system initialization. The electric meter terminal may determine the product of the initial key and the registration generator as the electric meter public key. The electric meter terminal may determine the initial key as the electric meter private key.
[0054] S208: Perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
[0055] Among them, the edge server (ES) can refer to the server deployed at the edge of the network to reduce latency and improve data processing efficiency. In the smart grid, the edge server can process the data from the smart meter and perform preliminary analysis and storage. The edge server and the smart meter can be authenticated and registered through the registration center to ensure the security of communication.
[0056] Smart meters, edge servers, registration centers, and blockchains work together in smart grids to achieve efficient, secure, and transparent energy management and transactions through edge computing and blockchain technologies.
[0057] The session key may represent a key shared between the smart meter and the edge server. The session key may be used for subsequent data encryption transmission.
[0058] Since the hardware resources of smart meters are limited, while the hardware resources of edge servers are much more than those of smart meters, specifically, after completing key negotiation and authentication with edge servers, smart meters can periodically send meter information or electricity usage information to edge servers. The edge servers are used to process meter information or electricity usage information to obtain processing results, and return the processing results to smart meters.
[0059] There are many ways to negotiate key authentication. Specifically, the smart meter can negotiate session keys with the edge server through the ECC protocol (EllipticCurve Cryptography). Specifically, the two parties can use the Diffie-Hellman key exchange protocol to jointly negotiate a shared key for subsequent data encryption transmission. In addition, in order to improve security, an anonymous identity mechanism can also be used to prevent identity leakage.
[0060] Specifically, the smart meter can also determine the meter random number and meter timestamp of the smart meter. The smart meter can determine the information to be verified of the smart meter based on the meter random number, the meter timestamp and the meter key. The smart meter can send the information to be verified to the edge server and obtain the server random number and server timestamp fed back by the edge server. The server random number and server timestamp are sent by the edge server when it is determined based on the information to be verified that the smart meter passes the smart contract verification of the blockchain to which the edge server belongs. The smart meter can determine the session key between the smart meter and the edge server based on the information to be verified, the server random number and the server timestamp.
[0061] In the above session key determination method, when the smart meter completes system initialization, it sends meter information to the registration center, receives pseudo identity information and initial key fed back by the registration center, and the pseudo identity information and initial key are generated by the registration center when the smart meter is determined to have passed identity authentication based on the meter information, and sent when the pseudo identity information and initial key are verified by the smart contract of the blockchain to which the registration center belongs. The pseudo identity information can avoid identity information leakage, thereby improving the security of power grid information. The meter key of the smart meter is determined based on the initial key, and the above method is used to perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server. On the one hand, multiple verifications are performed through the interaction of the smart meter, the registration center, and the edge server, thereby improving the accuracy of authentication, thereby improving the security of the session key. On the other hand, the pseudo identity information and initial key are received when the smart contract of the blockchain to which the registration center belongs is verified, thereby further improving the security of the pseudo identity information and initial key, thereby improving the security of the session key.
[0062] In one embodiment, the meter information includes meter excitation information, meter response information and meter identity. When the smart meter completes system initialization, the meter information is sent to a registration center, including: when the smart meter completes system initialization, randomly generating meter excitation information, obtaining meter hardware features and meter identity of the smart meter, performing information conversion on the meter excitation information according to an excitation response function matched with the meter hardware features to obtain meter response information, and sending the meter excitation information, meter response information and meter identity to the registration center.
[0063] The meter excitation information may be a digital input signal, and the meter response may be a digital output signal.
[0064] Meter hardware characteristics can represent the characteristics of the chip in the smart meter. For example, due to random differences in the chip manufacturing process, unique physical characteristics are generated, which produce unique responses when faced with challenges, thereby enabling device authentication and key exchange.
[0065] The meter identity may refer to an identifier used to identify the uniqueness of a smart meter, for example, the meter number of a smart meter.
[0066] The stimulus response function can be a function used to convert a stimulus to obtain a response. For example, a security function. The security function converts a stimulus to obtain a response, and this process is generally irreversible. For example, the security function can be a PUF (Physical Unclonable Function). For example, SRAM PUF (Static Random Access Memory Physically Unclonable Function) is a static random access memory. SRAM PUF uses the SRAM unit (Static Random-Access Memory) inside the chip to create deviations to generate a unique digital fingerprint. In addition, there are many forms such as optical PUF and electronic PUF, among which electronic PUF uses microphysical parameters inside the circuit, such as time, frequency, etc., to generate a unique response. During the authentication process, PUF works through a challenge-response mechanism, that is, it generates a unique output response to a specific input stimulus, thereby verifying the identity of the device. Specifically, the smart meter can convert the meter stimulus information according to the physical unclonable function matched with the hardware characteristics of the meter to obtain the meter response information.
[0067] In one embodiment, the smart meter can randomly generate an incentive information CHA i , and stored in the memory of the smart meter. Smart meters can use physical unclonable function PUF iGenerate incentive information CHA i Corresponding response information RES i .
[0068] In this embodiment, when the smart meter completes system initialization, the meter excitation information is randomly generated, the meter hardware features and meter identity of the smart meter are obtained, and the meter excitation information is converted according to the excitation response function matched with the meter hardware features to obtain the meter response information, and the meter excitation information, meter response information and meter identity are sent to the registration center, and the security of registration and authentication is improved by using the properties of physical unclonable functions. It is suitable for resource-constrained systems such as smart meters and application scenarios that require high security.
[0069] In one embodiment, the meter key includes a meter private key and a meter public key. The meter key of the smart meter is determined based on the initial key, including: when the registration center completes system initialization, obtaining the registration generator of the registration center, determining the product of the initial key and the registration generator as the meter public key, and determining the initial key as the meter private key.
[0070] Among them, the completion of initialization of the registration center can be represented by randomly selecting a registration generator on the elliptic curve of the finite field.
[0071] Specifically, the smart meter can obtain the registration generator P from the registration center when the registration center completes system initialization. i The product of the registered generator P is determined as the meter public key PK i =x i P. The smart meter can determine the initial key as the meter private key x i .
[0072] Among them, the initial private key x i The generation process includes: the registration center is in the finite field F p The elliptic curve E(F p ) selects a generator P and a cyclic additive group G with a prime order of q; two secure one-way hash functions H1:{0,1}*->Z q and H2:{0,1}*->{0,1} log 2 q ; The registration center selects a random number Mpre∈Z q * As the master private key, the corresponding master public key is M pub =Mpre·P. The master private key Mpre is kept secret, and the public system parameters param:(G,P,q,H1,H2,M pub ). Specifically, the registration center can calculate the initial key x based on the public system parameters i=r i +Mpre·H1(ID i ||PR i ||R i ). Among them, r i Generate a random number for the smart meter, Mpre is the primary private key, H1 is the first one-way hash function, ID i The identity information of the smart meter, PR i The hash value of the meter response information (PR i = H1(RES i ), where RES i is the meter response information), R i is a random value (R i =r i ·P).
[0073] In one embodiment, the smart meter is based on the meter public key PK i =x i P, and the meter private key x i , determine the public and private key pair (PK i , x i )) and confirm that the smart meter has passed the registration of the registration center to complete the registration process.
[0074] In this embodiment, when the registration center completes system initialization, the registration generator of the registration center is obtained, the product of the initial key and the registration generator is determined as the public key of the electricity meter, the initial key is determined as the private key of the electricity meter, and the registration process is completed to provide a basis for subsequent verification.
[0075] In one embodiment, key negotiation and authentication are performed with an edge server based on a meter key to determine a session key between the smart meter and the edge server, including: determining a meter random number and a meter timestamp of the smart meter, determining information to be verified of the smart meter according to the meter random number, the meter timestamp and the meter key, sending the information to be verified to the edge server, and obtaining a server random number and a server timestamp fed back by the edge server, the server random number and the server timestamp are sent by the edge server when it is determined that the smart meter passes the smart contract verification of the blockchain to which the edge server belongs based on the information to be verified, and determining the session key between the smart meter and the edge server based on the information to be verified, the server random number and the server timestamp.
[0076] The meter random number may represent a number randomly generated by the smart meter. For example, the meter random number m i ∈Z q * .
[0077] The meter timestamp can indicate the time when the smart meter generates a random number or calculates the random number. i .
[0078] The information to be verified may be information used to interact with the edge server. The information to be verified may be used for key negotiation authentication between the smart meter and the edge server. The information to be verified may include a meter random number, a meter timestamp, and a meter key. Exemplarily, the information to be verified may be Mes1:(M i , pid i , k, t i ), where M i Can represent meter random number, pid i can represent control parameters (which can be calculated from the meter key and meter random number), k can represent authentication parameters (which can be calculated from the control parameters, meter key, meter random number, and meter timestamp), t i Can represent meter timestamp.
[0079] The server random number can represent a number randomly generated by the edge server. For example, the server random number n j ∈Z q * .
[0080] The server timestamp can indicate the time when the edge server generates a random number or calculates the random number. The server timestamp can be t j .
[0081] Specifically, the edge server can verify the information to be verified, and if the verification is successful, a server random number and a server timestamp can be generated. In one embodiment, the edge server can call the smart contract of the blockchain to which it belongs to verify the information to be verified.
[0082] Specifically, the smart meter may determine a session key between the smart meter and the edge server based on the information to be verified, the server random number, and the server timestamp.
[0083] In one of the embodiments, the smart meter can compare the time difference between the server timestamp and the meter timestamp. If the time difference is within a threshold range, the session key between the smart meter and the edge server can be determined based on the information to be verified, the server random number and the server timestamp.
[0084] In one embodiment, the smart meter may also obtain a server key, and the smart meter determines a session key between the smart meter and the edge server according to the server key, the information to be verified, the server random number, and the server timestamp.
[0085] In this embodiment, the meter random number and meter timestamp of the smart meter are determined, and the information to be verified of the smart meter is determined according to the meter random number, the meter timestamp and the meter key. The information to be verified is sent to the edge server, and the server random number and server timestamp fed back by the edge server are obtained. The server random number and server timestamp are sent by the edge server when it is determined that the smart meter passes the smart contract verification of the blockchain to which the edge server belongs based on the information to be verified. Based on the information to be verified, the server random number and the server timestamp, the session key between the smart meter and the edge server is determined. The smart meter and the edge server exchange information of random numbers and timestamps to obtain an accurate session key to provide a basis for the subsequent encrypted transmission of data.
[0086] In one embodiment, a session key between a smart meter and an edge server is determined based on information to be verified, a server random number, and a server timestamp, including: when the meter timestamp and the server timestamp meet a timestamp verification condition, obtaining a server key, and determining the session key between the smart meter and the edge server based on the server key, the meter key, the server random number, and the meter random number.
[0087] The timestamp verification condition may be a verification condition configured between the meter timestamp and the server timestamp, for example, the time interval between the meter timestamp and the server timestamp is less than a preset time.
[0088] The timestamp verification condition may include a verification condition for the meter timestamp and a verification condition for the server timestamp. For example, the meter timestamp may indicate the time when the smart meter generates the meter random number. The timestamp verification condition may be the time when the edge server receives the meter random number. i ' and the time t at which the random number is generated i The difference between the times is less than a preset value. For another example, the server timestamp can indicate the time when the smart meter receives the server random number. The timestamp verification condition can also be the time when the server random number is generated t j and the time t at which the smart meter receives the random number from the server j 'The difference between the times is less than the preset value.
[0089] The server key may be a key for the edge server that has been successfully registered through the registration center. The server key may ensure the security of information interaction between the edge server and the registration center.
[0090] For example, the smart meter can use the meter timestamp t i and server timestamp t j 'If the timestamp verification conditions are met, obtain the server key PK i .
[0091] Smart meters can be based on the server key PK j 、Meter key PK i , server random number N j 、Meter random number m i , determine the session key SK between the smart meter and the edge server ij =H1(PK i ||PK j ||K3||K4). Among them, K3=m i ·PK j +x i ·N j ; K4=m i ·N j ; where x i Indicates the private key of the meter.
[0092] In this embodiment, when the meter timestamp and the server timestamp meet the timestamp verification condition, the server key is obtained, and the session key between the smart meter and the edge server is determined based on the server key, the meter key, the server random number and the meter random number, thereby improving the accuracy of the session key.
[0093] In one embodiment, Figure 3 As shown, a method for determining a session key applied to a registration center is provided, comprising:
[0094] S302, receiving meter information sent by the smart meter.
[0095] The meter information may be information required by the smart meter during the meter registration process, for example, the meter information includes meter excitation information, meter response information, meter identity, other meter information, and the like.
[0096] The meter information is sent by the smart meter after the system initialization is completed.
[0097] Specifically, before the registration center receives the meter information sent by the smart meter, it performs system initialization. In one embodiment, the registration center initializes the system in the finite field F p The elliptic curve E(F p ) selects a generator P and a cyclic additive group G with a prime order of q; two secure one-way hash functions H1:{0,1}*->Z q and H2:{0,1}*->{0,1} log 2 q ; The registration center selects a random number Mpre∈Z q * As the master private key, the corresponding master public key is M pub=Mpre·P. The master private key Mpre is kept secret, and the public system parameters param:(G,P,q,H1,H2,M pub ).
[0098] In one embodiment, the registry can also create a blockchain for the authentication system. The registry selects trusted members, determines a consensus mechanism (which can be a Byzantine consensus mechanism), and deploys smart contracts to manage the key material table.
[0099] S304, performing identity authentication on the smart meter based on the meter information.
[0100] Identity verification can refer to verification of identity information in the meter information. Specifically, after receiving the identity information of the smart meter, the registration center can check whether the smart meter has been registered according to the identity information, and if it has been registered, terminate the registration request. If it has not been registered, it is determined that the smart meter has passed the identity verification.
[0101] S306: When it is determined that the smart meter has passed the identity authentication, pseudo identity information and an initial key for the smart meter are generated.
[0102] Specifically, the registration center can obtain the meter excitation information and the meter response information. i And the meter response information RES i , determine the meter incentive hash value PC i =H1(CHA i ), and meter response information PR i =H1(RES i ).
[0103] The registration center can generate a central random number r i ∈Z q * .
[0104] The registration center can calculate R i =r i ·P;x i =r i +Mpre·H1(ID i ||PR i ||R i );PK i =x i ·P.
[0105] Among them, ID i It can represent the identity information of the meter, R i Can represent random values, x i Can represent the private key of the meter, PK iCan represent a server key.
[0106] The registration center can use the server key PK i Generate a pseudo identity PID for the smart meter i =H1(PK i ).
[0107] The registration center can use the elliptic curve encryption algorithm to encrypt the SM i ID i C IDi =E Mpub (ID i ).
[0108] The registration center can i ,C IDi ,R i , (PC i ,PR i )) is uploaded to the blockchain and then the secret information is sent through a secure channel (x i ,PID i ) to the smart meter. The pseudo identity information of the smart meter is PID i The initial key of the smart meter is x i The registration center may also verify the secret information first, and then send the verified secret information to the smart meter.
[0109] S308, calling the smart contract of the blockchain to which the registration center belongs to verify the pseudo-identity information and the initial key.
[0110] Specifically, the registry can call the smart contract of the blockchain to which the registry belongs to perform i ,PID i ) for verification.
[0111] Specifically, the verification process may include: i ·P=(r i +Mpre·H1(ID i ||PR i ||R i ))·P, that is, x i P=R i +M pub H1(ID i ||PR i ||R i ) is true. If true, the verification is successful.
[0112] When the pseudo identity information and the initial key are verified, the pseudo identity information and the initial key are sent to the smart meter, so that the smart meter determines the meter key based on the initial key, and performs key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
[0113] In this embodiment, on the one hand, multiple verifications are performed through the interaction of the smart meter, the registration center, and the edge server, thereby improving the accuracy of the authentication and thus improving the security of the session key. On the other hand, the pseudo-identity information and the initial key are received under the verification of the smart contract of the blockchain to which the registration center belongs, thereby further improving the security of the pseudo-identity information and the initial key and thus improving the security of the session key.
[0114] In one embodiment, Figure 4 As shown, a blockchain-assisted authentication key negotiation method for smart grid is provided, and the method is applied to a smart meter for illustration, and the method includes:
[0115] S401, when the smart meter completes system initialization, randomly generates meter excitation information.
[0116] S402, obtaining the meter hardware characteristics and meter identity of the smart meter.
[0117] The meter information includes meter excitation information, meter response information and meter identity.
[0118] S403, converting the meter excitation information according to the excitation response function matched with the meter hardware characteristics to obtain meter response information.
[0119] S404, sending the electric meter excitation information, the electric meter response information and the electric meter identity to the registration center.
[0120] S405, receiving pseudo identity information and initial key fed back by the registration center.
[0121] Among them, the pseudo-identity information and the initial key are generated by the registration center when it is determined that the smart meter has passed the identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs.
[0122] S406: When the registration center completes system initialization, obtain a registration generator of the registration center.
[0123] S407: Determine the product of the initial key and the registration generator as the meter public key.
[0124] The meter key includes the meter private key and the meter public key.
[0125] S408: Determine the initial key as the electricity meter private key.
[0126] S409, determining a meter random number and a meter timestamp of the smart meter.
[0127] S410, determining information to be verified of the smart meter according to the meter random number, the meter timestamp and the meter key.
[0128] S411, sending the information to be verified to the edge server, and obtaining the server random number and server timestamp fed back by the edge server.
[0129] Among them, the server random number and the server timestamp are sent by the edge server when it is determined that the smart meter has passed the smart contract verification of the blockchain to which the edge server belongs based on the information to be verified.
[0130] S412: When the timestamp of the electric meter and the timestamp of the server meet the timestamp verification condition, obtain the server key.
[0131] S413, determining a session key between the smart meter and the edge server based on the server key, the meter key, the server random number and the meter random number.
[0132] The registration process of the edge server in the registration center is similar to the registration process of the smart meter, which will not be repeated here. j If the registration is successful, the edge server ES j The public and private key pair is (PK j , x j ). Otherwise, the edge server ES j Reapply for registration.
[0133] Smart MeterSM i and edge server ES j After successful registration, the two parties authenticate each other in an open environment, at which point blockchain provides trusted support for identity verification.
[0134] (1) Smart Meter SM i To the edge server ES j Make a certification request
[0135] The smart meter generates a meter random number m i ∈Z q * , calculate M i =m i P, pid i =PK i ⊕H2(M i ||m i ·PK j ).
[0136] Assume t i is the meter timestamp, calculate k=m i +x i H1(PK i ||PR i ||pid i ||M i ||t i ).
[0137] Smart meter sends message Mes1:(M i , pid i , k, t i ) to the edge server.
[0138] (2) Edge Server ES j Smart MeterSM i Verify
[0139] Assume t i ' is the moment when the server receives the meter timestamp. If t i -t i '≤Δt, Δt is the threshold, then the timestamp is valid.
[0140] The edge server calculates the public key PK of the smart meter i '=pid i ⊕H2(M i ||x j ·M i ).
[0141] Edge server calculates PID i '=H1(PK i '), call the smart contract and query on the blockchain. If the query fails, the smart meter authentication is unsuccessful; otherwise, verify k·P=(m i +x i H1(PK i ||pid i ||M i ||t i ))·P= Mi+PK i '·H1(PK i '||PR||pid i ||M i ||t i ) is true.
[0142] The edge server selects a random server number n j ∈Z q * , and calculate N j =n j ·P;K1=xj ·M i +n j ·PK i ; K2=n j ·M i .
[0143] If the above verification is successful, then calculate SK ji =H1(PK i '||PK j ||K1||K2),w=H1(SK ji ||K1||K2||t j ).
[0144] The edge server sends a message Mes2:(N j ,w,t j )How to use smart meter.
[0145] (3) Session key generation
[0146] t j ' is the server timestamp, if t j -t j '≤Δt, then the timestamp is valid.
[0147] Smart meter calculation K3=m i ·PK j +x i ·N j ; K4=m i ·N j .
[0148] Smart meter calculation, SK ij =H1(PK i ||PK j ||K3||K4), if H1(SK ij ||K3||K4||t j )=w holds, then SK ij is the session key between the smart meter and the edge server.
[0149] This is because K1=x j ·M i +n j ·PK i =x j ·m i ·P+n j ·x i ·P=PK j ·m i +N j ·x i =K3; K2=n j ·Mi =n j ·m i P=N j ·m i =K4.
[0150] On this basis, when the private key of the smart meter is leaked, the smart meter applies to the registration center for key update. The leakage of the private key of the smart meter will not change the pseudo identity PID of the smart meter i =H1(PK i ) information. The registration center re-registers the smart meter and generates new key material (PID i ,C IDi ,R i ), find and complete the key material update in the smart contract.
[0151] When the edge server finds malicious behavior in the smart meter, it uses pid i ⊕H2(M i ||x j ·M i ) Obtain the public key PK of the smart meter i , by PID i =H1(PK i ) Determine the pseudo identity of the node and look up the corresponding (PID i ,C IDi ,R i ,(PC i ,PR i )), decrypt C IDi , thereby obtaining the true identity of the smart meter. The registry sends a revocation transaction and deletes the record (PID i ,C IDi ,R i , (PC i ,PR i )).
[0152] In this embodiment, when the smart meter completes system initialization, it sends meter information to the registration center, receives pseudo identity information and initial key fed back by the registration center, and the pseudo identity information and initial key are generated by the registration center when the smart meter passes identity authentication based on the meter information, and sent when the pseudo identity information and initial key are verified by the smart contract of the blockchain to which the registration center belongs. The pseudo identity information can avoid identity information leakage, thereby improving the security of power grid information. The meter key of the smart meter is determined based on the initial key, and the above method is used to perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server. On the one hand, multiple verifications are performed through the interaction of the smart meter, the registration center, and the edge server, thereby improving the accuracy of authentication, thereby improving the security of the session key. On the other hand, the pseudo identity information and initial key are received when the smart contract of the blockchain to which the registration center belongs is verified, thereby further improving the security of the pseudo identity information and initial key, thereby improving the security of the session key.
[0153] The above method can also bring the following beneficial effects:
[0154] (1) Using a physical unclonable function, the stimulus-response pair is uploaded to the blockchain and used in the private key generation in the registration phase and the authentication phase k. Since PUF is unclonable, our method is resistant to cloning and physical attacks;
[0155] (2) The session key between SM and ES uses the random number generated by SM and ES, and the random number does not pass through the channel, which makes our scheme have perfect forward and backward security;
[0156] (3) The session key generation is only related to the random number and the public keys of both parties, and has nothing to do with the identity, which has better identity anonymity.
[0157] (4) Using blockchain to store key materials and incentive pairs can prevent the risk of key material tampering and leakage, and improve the security of information interaction. IDi The identity information of malicious nodes can be obtained.
[0158] (5) Assume that the private key x to the smart meter and edge server i and x j Captured, message Mes1=(M i , pid i , k,t i ) and message Mes2:(N j ,w,t j ) is intercepted, because the m required to generate the session key i and n jEach time, it is randomly generated by the smart meter and the edge server. i and n j The data is generated randomly and not through public channels, so our method has perfect forward and backward security.
[0159] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0160] Based on the same inventive concept, the embodiment of the present application also provides a session key determination device for implementing the above-mentioned session key determination method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above-mentioned method, so the specific limitations in one or more session key determination device embodiments provided below can refer to the limitations on the session key determination method above, and will not be repeated here.
[0161] In one embodiment, Figure 5 As shown, a session key determination device is provided, which is applied to a smart meter. The device includes: a meter information sending module 502, an information receiving module 504, a meter key determination module 506 and a session key determination module 508, wherein:
[0162] The meter information sending module 502 is used to send the meter information to the registration center when the smart meter completes system initialization;
[0163] The information receiving module 504 is used to receive the pseudo-identity information and the initial key fed back by the registration center; the pseudo-identity information and the initial key are generated by the registration center when the smart meter is determined to have passed the identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs;
[0164] A meter key determination module 506, configured to determine a meter key of the smart meter based on an initial key;
[0165] The session key determination module 508 is used to perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
[0166] In one of the embodiments, the meter information includes meter excitation information, meter response information and meter identity; the meter information sending module 502 is also used to randomly generate meter excitation information when the smart meter completes system initialization; obtain the meter hardware characteristics and meter identity of the smart meter; according to the excitation response function matched with the meter hardware characteristics, perform information conversion on the meter excitation information to obtain the meter response information; and send the meter excitation information, meter response information and meter identity to the registration center.
[0167] In one of the embodiments, the meter key includes a meter private key and a meter public key; the meter key determination module 506 is also used to obtain a registration generator of the registration center when the registration center completes system initialization; the product of the initial key and the registration generator is determined as the meter public key; and the initial key is determined as the meter private key.
[0168] In one of the embodiments, the session key determination module 508 is also used to determine the meter random number and meter timestamp of the smart meter; determine the information to be verified of the smart meter based on the meter random number, the meter timestamp and the meter key; send the information to be verified to the edge server, and obtain the server random number and server timestamp fed back by the edge server; the server random number and server timestamp are sent by the edge server when it is determined that the smart meter has passed the smart contract verification of the blockchain to which the edge server belongs based on the information to be verified; determine the session key between the smart meter and the edge server based on the information to be verified, the server random number and the server timestamp.
[0169] In one of the embodiments, the session key determination module 508 is also used to obtain the server key when the meter timestamp and the server timestamp meet the timestamp verification condition; based on the server key, the meter key, the server random number and the meter random number, determine the session key between the smart meter and the edge server.
[0170] In one embodiment, a session key determination device is provided, which is applied to a registration center. The device includes: an electric meter information sending module, an information receiving module, an electric meter key determination module and a session key determination module, wherein:
[0171] The electric meter information sending module is used to send the electric meter information to the registration center when the smart electric meter completes system initialization;
[0172] An information receiving module is used to receive the pseudo-identity information and initial key fed back by the registration center; the pseudo-identity information and initial key are generated by the registration center when the smart meter is determined to have passed the identity authentication based on the meter information, and are sent when the pseudo-identity information and initial key are verified by the smart contract of the blockchain to which the registration center belongs;
[0173] An electric meter key determination module, used for determining an electric meter key of a smart electric meter based on an initial key;
[0174] The session key determination module is used to perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
[0175] Each module in the above session key determination device can be implemented in whole or in part by software, hardware or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module.
[0176] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store meter information data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a session key determination method is implemented.
[0177] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0178] In one embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the above method steps are implemented when the processor executes the computer program.
[0179] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the above method steps are implemented.
[0180] In one embodiment, a computer program product is provided, comprising a computer program, which implements the above method steps when executed by a processor.
[0181] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0182] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0183] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A method for determining a session key, characterized in that: Applied to a smart electric meter, the method comprises: When the smart electric meter completes system initialization, sending electric meter information to a registration center; Receive the pseudo-identity information and the initial key fed back by the registration center; the pseudo-identity information and the initial key are generated by the registration center when it is determined that the smart meter has passed the identity authentication based on the meter information, and are sent when the pseudo-identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; Determining a meter key of the smart meter based on the initial key; A key negotiation authentication is performed with the edge server based on the meter key to determine a session key between the smart meter and the edge server.
2. The method according to claim 1, characterized in that The electric meter information includes electric meter excitation information, electric meter response information and electric meter identity; When the smart meter completes system initialization, sending meter information to the registration center includes: When the smart electric meter completes system initialization, randomly generating electric meter excitation information; Obtaining the meter hardware characteristics and meter identity of the smart meter; According to the stimulus response function matched with the hardware characteristics of the electric meter, the electric meter stimulus information is converted to obtain the electric meter response information; The electric meter excitation information, the electric meter response information and the electric meter identity are sent to the registration center.
3. The method according to claim 1, characterized in that The electric meter key includes an electric meter private key and an electric meter public key; The determining the meter key of the smart meter based on the initial key includes: When the registration center completes system initialization, obtaining a registration generator of the registration center; Determine the product of the initial key and the registration generator as the public key of the electricity meter; The initial key is determined as the electricity meter private key.
4. The method according to claim 1, characterized in that: The performing key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server includes: Determine a meter random number and a meter timestamp of the smart meter; Determine the information to be verified of the smart meter according to the meter random number, the meter timestamp and the meter key; Sending the information to be verified to the edge server, and obtaining the server random number and the server timestamp fed back by the edge server; the server random number and the server timestamp are sent by the edge server when it is determined that the smart meter has passed the smart contract verification of the blockchain to which the edge server belongs based on the information to be verified; A session key between the smart meter and the edge server is determined based on the information to be verified, the server random number, and the server timestamp.
5. The method according to claim 4, characterized in that The determining, based on the information to be verified, the server random number and the server timestamp, a session key between the smart meter and the edge server comprises: When the timestamp of the electric meter and the timestamp of the server meet the timestamp verification condition, obtaining a server key; A session key between the smart meter and the edge server is determined based on the server key, the meter key, the server random number, and the meter random number.
6. A method for determining a session key, characterized in that: Applied to a registration center, the method comprises: Receiving meter information sent by a smart meter; the meter information is sent by the smart meter after completing system initialization; Authentication of the smart meter based on the meter information; When it is determined that the smart meter passes the identity authentication, generating pseudo identity information and an initial key for the smart meter; Calling the smart contract of the blockchain to which the registration center belongs to verify the pseudo-identity information and the initial key; When the pseudo-identity information and the initial key are verified, the pseudo-identity information and the initial key are sent to the smart meter, so that the smart meter determines the meter key based on the initial key, and performs key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
7. A session key determination device, characterized in that: Applied to a smart electric meter, the device comprises: An electric meter information sending module, used for sending the electric meter information to a registration center when the smart electric meter completes system initialization; An information receiving module, used to receive the pseudo identity information and the initial key fed back by the registration center; the pseudo identity information and the initial key are generated by the registration center when it is determined based on the meter information that the smart meter passes the identity authentication, and are sent when the pseudo identity information and the initial key are verified by the smart contract of the blockchain to which the registration center belongs; An electric meter key determination module, configured to determine an electric meter key of the smart electric meter based on the initial key; The session key determination module is used to perform key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
8. A session key determination device, characterized in that: Applied to a registration center, the device comprises: An electric meter information receiving module, used for receiving electric meter information sent by a smart electric meter; the electric meter information is sent by the smart electric meter when the system initialization is completed; An identity authentication module, used for performing identity authentication on the smart meter based on the meter information; An information generation module, used to generate pseudo identity information and an initial key for the smart meter when it is determined that the smart meter passes the identity authentication; An information verification module, used to call the smart contract of the blockchain to which the registration center belongs to verify the pseudo-identity information and the initial key; A key sending module is used to send the pseudo-identity information and the initial key to the smart meter when the pseudo-identity information and the initial key are verified, so that the smart meter determines the meter key based on the initial key, and performs key negotiation authentication with the edge server based on the meter key to determine the session key between the smart meter and the edge server.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.