Communication method for power asset management master station system and mobile terminal

By using TPM and HSM to work in the power asset management system, dynamic encryption algorithms, intelligent security engines, blockchain technology and quantum key distribution technology, security risks and low efficiency in traditional communications are solved, and communication with high security, efficiency and reliability is achieved.

CN119966720APending Publication Date: 2025-05-09NANJING HUASHEYUN INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510133245.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The communication between traditional power asset management systems and mobile terminals poses security risks, including insufficient security, data integrity and authentication issues, key management issues, lack of real-time monitoring and defense mechanisms, and low transmission efficiency.

Method used

TPM and HSM work together, dynamic encryption algorithms, intelligent security engines, blockchain technology, and quantum key distribution technology are adopted to improve the security and efficiency of communication through two-way identity authentication, hashing algorithms, digital signatures, real-time monitoring and multiple encryption layer mechanisms.

Benefits of technology

It significantly improves the security, efficiency and reliability of the communication between the power asset management system and mobile terminals, prevents man-in-the-middle attacks, data tampering and replay attacks, ensures data integrity and key security, and improves the system's defense capabilities and response speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966720A_ABST
    Figure CN119966720A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method for an electric power asset management master station system and a mobile terminal, and provides a powerful hardware isolation and key management mechanism through cooperative work of a TPM (Trusted Platform Module) and an HSM (Home Subscriber Management). A bidirectional identity authentication mechanism and a PKI public key authentication protocol are adopted, it can be ensured that only equipment is authorized to participate in communication, and illegal access and identity forgery are effectively prevented; the intensity and complexity of the encryption algorithm are dynamically adjusted according to the sensitivity of the data and the network environment, and the encryption process is more efficient. In a low-bandwidth network environment, consumption of computing resources is reduced by automatically selecting a more efficient encryption algorithm; and in a high-bandwidth environment, a stronger encryption algorithm is adopted to ensure the security of data transmission. In the data transmission process, the integrity and the source reliability of the data are ensured through a hash algorithm and a digital signature mechanism. Each data packet is added with a hash value, and a receiving end can perform hash value verification after decryption, thereby effectively preventing data from being tampered or lost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power asset management, and in particular to a communication method between a power asset management master station system and a mobile terminal. Background Art

[0002] With the rapid development of information technology, the power asset management system, as an important part of the intelligent upgrade of the power industry, is increasingly becoming a key tool to ensure stable, safe and efficient power operation. Traditional power asset management systems usually rely on centralized data transmission and processing platforms, relying on PC terminals, local area networks and other methods to monitor and transmit equipment data. However, with the development of mobile Internet and Internet of Things technologies, power asset management has gradually begun to expand to mobile terminals (such as smart phones, tablets, etc.) to enhance the flexibility, real-time and remote control capabilities of the system. Especially in the context of the current smart grid and energy Internet, efficient, stable and secure communication between the power asset management master station system and mobile terminals has become one of the core technologies to ensure the operation of the power system.

[0003] However, there are certain security risks in the communication between traditional power asset management systems and mobile terminals, which are specifically manifested in the following aspects:

[0004] 1. Insufficient security: In existing communication methods, data encryption and identity authentication rely on traditional encryption algorithms and key management methods, such as symmetric encryption (AES) and asymmetric encryption (RSA). While these methods improve system performance, they are difficult to resist new network attack methods (such as quantum computing attacks). Existing technologies do not fully consider the security of the communication process and lack a multi-level, dynamically adjusted security mechanism, making the system vulnerable to threats such as man-in-the-middle attacks, data tampering, and replay attacks.

[0005] 2. Data integrity and authentication issues: In traditional solutions, although encryption algorithms are used to ensure data confidentiality, data packets may be tampered with or lost during data transmission. Existing methods usually fail to perform effective hash checks or signature verifications in each data packet, resulting in a lack of reliability assurance of data integrity and source in the system.

[0006] 3. Key management issues: Current systems mostly rely on traditional key management solutions, which pose certain security risks in key exchange, update, and revocation. Especially in the process of certificate and key management, if any link in the system fails or is hacked, the security of the entire communication process may be compromised.

[0007] 4. Lack of real-time monitoring and defense mechanisms: Existing communication solutions fail to monitor and warn of abnormal behaviors in real time during the communication process. Once the system is attacked or there are potential security risks, traditional systems often find it difficult to detect and take protective measures in time.

[0008] 5. Transmission efficiency issues: During data transmission, traditional encryption algorithms often fail to flexibly adjust encryption strength and efficiency according to the actual network environment and data type, resulting in a waste of computing resources during the encryption process, reducing data transmission efficiency, and affecting the real-time and response speed of the system.

[0009] Based on the above problems, the present invention proposes a communication method for the power asset management master station system and the mobile terminal. By adopting a series of innovative technologies such as TPM and HSM collaboration, dynamic encryption algorithm, intelligent security engine, blockchain technology and quantum key distribution technology, the security, efficiency and reliability of communication between the power asset management system and the mobile terminal are significantly improved. Summary of the invention

[0010] The purpose of this section is to summarize some aspects of embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of this application to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.

[0011] Therefore, in order to solve the above technical problems, the present invention provides the following technical solutions: a communication method for a power asset management master station system and a mobile terminal, comprising the following specific steps:

[0012] S1: Each power asset management master station and mobile terminal is equipped with a TPM chip, which provides encryption, decryption and secure storage functions, and ensures data security transmission through hardware isolation protection; at the same time, the master station system is equipped with HSM for high-intensity encryption operations and key management, and works with TPM to achieve key exchange, identity authentication and data encryption;

[0013] S2: Before communication is established, a two-way identity authentication mechanism based on TPM and HSM is used to verify the identities of both parties using a public key authentication protocol (such as PKI) to ensure that only authorized devices participate in communication and prevent illegal access and identity forgery;

[0014] S3: All transmitted data is symmetrically encrypted with high strength (such as AES-256) by HSM at the sending end. The mobile terminal uses TPM to encrypt local data before sending it. The master station decrypts and verifies it through HSM. At the same time, RSA public key encryption is used for key exchange to ensure the security of encryption keys. Key management is jointly managed by HSM and TPM, and keys are securely exchanged through the Diffie-Hellman protocol.

[0015] S4: During data transmission, a hash algorithm (such as SHA-256) is used to calculate the hash value of the data packet and append it. The receiving end decrypts and verifies the hash value to ensure data integrity. For sensitive data, the master station system generates a digital signature through the HSM and appends it. The mobile terminal verifies the signature to ensure that the data source is reliable.

[0016] S5: Establish an encrypted communication channel between the master system and the mobile terminal through a secure communication protocol (such as TLS / SSL). TPM and HSM work together to provide certificate verification and key exchange to ensure channel security.

[0017] S6: Implement real-time monitoring of communication behaviors, use TPM and HSM to detect and report abnormal behaviors, and trigger security alarms; at the same time, record audit logs of all communications and operations, including key management, identity authentication, and data encryption and decryption operations, to facilitate later tracking and analysis.

[0018] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, in which: during the data transmission process between the master station system and the mobile terminal, each data packet is timestamped by adding a timestamp mechanism, and the receiving end performs data synchronization verification by comparing the timestamp and the system time to prevent data packet replay attacks.

[0019] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, the master station system and the mobile terminal dynamically update and revoke certificates through a certificate management system based on TPM and HSM, ensuring that after the device or certificate expires, the system can automatically disable the revoked certificate, further improving the security of the system.

[0020] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, in which: during the communication process, the master station system provides an access control mechanism through the HSM to control the access and operation rights of users with different roles and permissions to the communication data, ensuring that only authorized users can perform sensitive data operations.

[0021] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, wherein: an intelligent security engine based on behavior analysis is used to perform real-time analysis on communication traffic, automatically identify and alarm possible abnormal behaviors, improve the system's defense capability and real-time response capability, and further enhance the security of data transmission; wherein the intelligent security engine analyzes the behavioral patterns of communication data traffic, uses machine learning algorithms to automatically learn and identify normal and abnormal communication characteristics, detects potential threats in real time, and jointly triggers an emergency response mechanism through TPM and HSM to prevent the spread of attacks.

[0022] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, wherein: in the communication process between the mobile terminal and the master station system, a dynamic encryption algorithm is used to adjust the strength of data encryption, and the level and complexity of the encryption algorithm are automatically adjusted according to the sensitivity of the data and the network environment to improve encryption efficiency while ensuring data security; specifically, the system dynamically adjusts the encryption algorithm according to the data type (such as real-time asset data, user operation data, etc.) and network bandwidth (such as 4G, 5G, etc.), such as using a more efficient encryption algorithm in a network environment with lower bandwidth, and using a stronger encryption algorithm in a high-bandwidth network.

[0023] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, wherein: the communication channel between the master station system and the mobile terminal realizes key exchange by using quantum key distribution technology (QKD), and utilizes the non-cloning and non-eavesdropping properties of quantum communication to ensure that the exchange process of communication keys is not eavesdropped or tampered with; wherein, quantum key distribution technology generates and distributes security keys through the principles of quantum entanglement and quantum superposition, and all key exchanges are carried out within the security framework of quantum keys, thereby resisting attacks that traditional cryptography cannot prevent.

[0024] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, after the data reception is completed, the master station system records each communication log into the blockchain through a data log audit system based on blockchain technology, so as to ensure the non-tamperability and traceability of the log information and increase the transparency and security of the data exchange process; the blockchain audit system not only records the communication content in an immutable manner, but also stores each operation in the communication process (such as key exchange, identity authentication, encryption and decryption, etc.) in a chain manner to ensure that all operations are traceable.

[0025] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, in which: during the data transmission process, in order to prevent data loss or damage, the master station system and the mobile terminal adopt an error detection and recovery mechanism based on error correction code (such as Reed-Solomon coding) to perform real-time verification of the transmitted data and automatically correct data errors that may occur during the transmission process; specifically, the system redundantly encodes the data before each data transmission, and the receiving end checks and repairs lost or damaged data packets through an error correction algorithm to ensure the integrity of the communication.

[0026] As a preferred solution of the communication method between the power asset management master station system and the mobile terminal described in the present invention, wherein: during the data transmission process, the master station system and the mobile terminal adopt a multiple encryption layer mechanism, combining symmetric encryption and asymmetric encryption, and using different encryption strategies in different communication stages to improve the security and encryption strength of data transmission; specifically, the system uses asymmetric encryption for key exchange and identity authentication in the initial stage of data transmission, uses symmetric encryption to improve efficiency in the actual stage of data transmission, and uses stronger asymmetric encryption in the sensitive data exchange stage to further enhance security.

[0027] Beneficial effects of the present invention:

[0028] 1. The present invention provides a powerful hardware isolation and key management mechanism by using TPM (Trusted Platform Module) and HSM (Hardware Security Module) to work together. Unlike the prior art that relies on a single hardware encryption component, the collaborative work of TPM and HSM can effectively enhance the security of key exchange, identity authentication and data encryption processes. The use of a two-way identity authentication mechanism and PKI public key authentication protocol can ensure that only authorized devices participate in communication, effectively prevent illegal access and identity forgery, and avoid security vulnerabilities in the identity authentication mechanism in the prior art.

[0029] 2. The present invention achieves a more efficient encryption process by dynamically adjusting the strength and complexity of the encryption algorithm according to the sensitivity of the data and the network environment. In a low-bandwidth network environment, a more efficient encryption algorithm is automatically selected to reduce computing resource consumption; in a high-bandwidth environment, a stronger encryption algorithm is used to ensure the security of data transmission. Compared with the fixed encryption strategy in the prior art, the present invention is more flexible and efficient.

[0030] 3. In the process of data transmission, the present invention ensures the integrity and source reliability of data through hash algorithm and digital signature mechanism. Each data packet is attached with a hash value, and the receiving end can perform hash value verification after decryption, thereby effectively preventing data tampering or loss. Compared with the simple encryption method in the prior art, the present invention can provide stronger data integrity protection and avoid the security loopholes that may exist in the existing scheme.

[0031] 4. The present invention introduces quantum key distribution (QKD) technology, which can achieve extremely high security key exchange during the communication process. QKD is based on the non-cloning and non-eavesdropping properties of quantum mechanics, ensuring that the key exchange process is not eavesdropped or tampered with, greatly enhancing the anti-attack capability of the communication process. The prior art usually relies on traditional key exchange algorithms, which pose serious security risks in the face of future quantum computing attacks.

[0032] 5. The present invention also uses an intelligent security engine based on behavioral analysis to analyze communication traffic in real time, automatically identify and alarm possible abnormal behaviors. This innovative mechanism can timely discover and prevent potential security threats, and improve the system's defense capabilities and response speed. Compared with the traditional solution that lacks real-time monitoring and adaptive defense mechanisms, the present invention has higher security.

[0033] 6. The present invention combines blockchain technology to store all log data in the communication and operation process in a chain, ensuring the immutability and traceability of the logs, and providing strong protection for subsequent security audits and vulnerability tracing. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor. Among them:

[0035] Figure 1 It is the work flow chart of the present invention. DETAILED DESCRIPTION

[0036] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0037] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0038] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0039] Example 1

[0040] Reference Figure 1 , which is the first embodiment of the present invention, provides a communication method between a power asset management master station system and a mobile terminal, comprising the following steps:

[0041] Step S1: The TPM chip works with the HSM;

[0042] In the present invention, TPM (Trusted Platform Module) chips are configured on both the power asset management master station and the mobile terminal. The TPM chip is mainly used to provide encryption, decryption and secure storage functions, and ensures data security transmission through hardware isolation protection. Specifically, the TPM chip processes sensitive data through hardware encryption algorithms to ensure data security. The master station system is configured with an HSM (Hardware Security Module), which is responsible for high-intensity encryption operations and key management to ensure the key security of the system.

[0043] During the communication process, the TPM chip works with the HSM to ensure data protection through key exchange protocols, security authentication mechanisms, and encrypted transmission processes. The TPM generates and stores keys, while the HSM is used for stronger encryption processing and key management. Together, the two ensure the key exchange, identity authentication, and data encryption process.

[0044] Application examples:

[0045] For example, when a mobile terminal establishes communication with the power asset management master station, the TPM chip will verify the identity of the terminal and generate a temporary key for encrypted transmission. The master station HSM decrypts and verifies the temporary key to ensure the security of the identities of both parties. In this way, the communication process between the mobile terminal and the master station is encrypted and protected every time data is exchanged.

[0046] Step S2: two-way identity authentication mechanism;

[0047] Before communication is established, a two-way authentication mechanism based on TPM and HSM is used to verify the identity of the device through a public key authentication protocol (such as PKI). This two-way authentication mechanism effectively prevents illegal access and identity forgery, ensuring that only authorized devices participate in communication. Specifically, both the master station and the mobile terminal are configured with digital certificates, and the RSA algorithm is used for identity authentication to ensure the legitimacy of the identities of both parties.

[0048] Application examples:

[0049] When a mobile terminal attempts to establish a connection with the master station system, the system first uses a public key authentication mechanism based on PKI to verify the legitimacy of the terminal device. If the authentication is successful, the master station sends its public key to the mobile terminal for identity confirmation. Only devices that pass the identity authentication can continue to communicate.

[0050] Step S3: data encryption and key exchange;

[0051] During data transmission, all data is symmetrically encrypted with high strength (such as AES-256) by HSM at the sending end, and the mobile terminal uses TPM to encrypt local data before sending. The master station decrypts and verifies through HSM, and uses RSA public key encryption for key exchange to ensure the security of encryption keys. Key management is jointly managed by TPM and HSM, and keys are securely exchanged through the Diffie-Hellman protocol.

[0052] Application examples:

[0053] In actual applications, the mobile terminal encrypts the transmitted data with AES-256 and sends it to the main station, which decrypts the data through the HSM and verifies the integrity of the data. To ensure the security of the key, the system uses the Diffie-Hellman protocol for key exchange to ensure that the key is not easily cracked even if it is intercepted during data transmission.

[0054] Step S4: Data integrity verification and digital signature;

[0055] During data transmission, a hash algorithm (such as SHA-256) is used to calculate the hash value of the data packet and append it. The receiving end decrypts and verifies the hash value to ensure the integrity of the data. For sensitive data, the master station system generates a digital signature through the HSM and appends it. The mobile terminal verifies the signature to ensure the reliability of the data source.

[0056] Application examples:

[0057] For example, in the real-time monitoring data transmission process of power assets, the master station encrypts the data and adds a digital signature to ensure that the transmitted data has not been tampered with. After the mobile terminal receives the data, it first verifies the source of the data through the digital signature, and then uses the hash algorithm to verify the integrity of the data.

[0058] The detailed process of adding hash value in data packet:

[0059] Hash value generation:

[0060] Before sending data, the sender calculates the hash value of the data packet using a hash algorithm (such as SHA-256).

[0061] The data packet content includes the data header (such as timestamp, sender ID, etc.) and the data body (such as power asset information). The specific process is as follows:

[0062] Data packets are organized into binary streams according to a predefined format.

[0063] The SHA-256 algorithm is used to calculate the hash value of the entire data packet content and generate a fixed-length 256-bit hash value.

[0064] If further security is needed, other metadata (such as a key ID) can be appended to the data packet before performing the hash operation.

[0065] Hash value appended:

[0066] The generated hash value is appended to the end of the data packet to form a "complete data packet".

[0067] Packet format example: [data header][data body][hash value];

[0068] The data header includes a timestamp, sender ID, and sequence number to ensure data uniqueness and prevent replay attacks.

[0069] The data subject is the actual content transmitted, such as power equipment status information.

[0070] Encrypted data packet after appending:

[0071] The complete data packet is encrypted using a symmetric encryption algorithm such as AES-256.

[0072] The encrypted data packets are transmitted via a secure communication channel (such as TLS / SSL).

[0073] Detailed process of hash value verification in data packet

[0074] Data packet reception and decryption:

[0075] The receiving end decrypts the received data packet using the corresponding key and algorithm to restore the original data packet.

[0076] The decrypted data packet still contains the data header, data body and the attached hash value.

[0077] Hash value verification:

[0078] Extract the data header and data body from the decrypted data packet.

[0079] Recalculate the hash value of the extracted data content using a hash algorithm consistent with the sender (such as SHA-256).

[0080] Compare the calculated hash value with the appended hash value.

[0081] If the two are equal, it indicates that the data packet has not been tampered with and data integrity is guaranteed.

[0082] If the two are not equal, it is determined that the data packet may have been tampered with or an error occurred during transmission, and the data packet is discarded and a retransmission request is made to the sender.

[0083] Additional protection measures during data transmission

[0084] Timestamp verification:

[0085] The data header contains a timestamp. The receiving end compares the timestamp with the current system time to ensure the timeliness of the data packet and prevent replay attacks.

[0086] Digital signature assisted verification:

[0087] For sensitive data, the sender can generate a digital signature through HSM, and the receiver uses the corresponding public key to verify the authenticity of the signature and the reliability of the data source.

[0088] The following table shows an example of the data packet format:

[0089] Field Name Byte length describe Data Header 16 Contains metadata such as timestamp, sender ID, etc. Data Subject variable Actual transmitted power asset management data Hash value 32 Fixed-length hash value generated by SHA-256

[0090] Step S5: secure communication protocol (TLS / SSL);

[0091] An encrypted communication channel is established between the main station system and the mobile terminal through a secure communication protocol (such as TLS / SSL). TPM and HSM work together to provide certificate verification and key exchange to ensure the security of the channel.

[0092] Application examples:

[0093] In power asset management applications, the master station and mobile terminals establish an encrypted connection through the SSL / TLS protocol, and all data transmission is protected through encrypted channels to prevent data leakage and theft.

[0094] Step S6: Real-time monitoring and auditing of communication behavior;

[0095] Implement real-time monitoring of communication behaviors, use TPM and HSM to detect and report abnormal behaviors, and trigger security alarms. At the same time, record audit logs of all communications and operations, including key management, identity authentication, and data encryption and decryption operations, to facilitate later tracking and analysis.

[0096] Application examples:

[0097] In the power asset management system, the real-time monitoring component can detect abnormal behaviors such as illegal access or unauthorized operations according to the set security rules, and generate alarms to notify system administrators in time. In addition, all operations and communication logs are recorded to ensure the traceability of system operations.

[0098] Example 2

[0099] The second embodiment of the present invention is different from the first embodiment in that, in order to verify the technical advantages of the present invention, this embodiment conducts a simulation test on the technical solution of the present invention and compares it with the prior art. The following is the specific preparation content and implementation process of the test:

[0100] Test preparation:

[0101] Equipment selection:

[0102] The power asset management master station system is equipped with a server that supports TPM chips and combines it with an HSM module for high-intensity encryption operations and key management.

[0103] The mobile terminal is equipped with a built-in TPM chip and a security authentication protocol stack that supports PKI.

[0104] Security protocols include TLS / SSL, AES-256, RSA, Diffie-Hellman, SHA-256 and other protocols for data encryption and identity authentication.

[0105] The experiment used 4G and 5G network environments to ensure that tests could be performed under different bandwidths.

[0106] Experimental Design:

[0107] Comparison group: This embodiment sets up two comparison groups: one is the existing technology group (using traditional AES encryption and RSA public key exchange, and not using TPM and HSM collaboration), and the other is the present invention group (using TPM and HSM collaboration, dynamic encryption algorithm, blockchain log management and other advanced technologies).

[0108] Measurement content: Communication delay, encryption strength, key exchange time, data integrity verification speed, system responsiveness, etc. of the comparison group and the experimental group. All test data are recorded in real time through the built-in monitoring system.

[0109] Packet marking and timestamp: Add a timestamp mechanism to the data packet and prevent replay attacks through time synchronization verification.

[0110] Implementation process:

[0111] Phase 1: Identity authentication and key exchange:

[0112] In the present invention group, two-way identity authentication and key exchange are realized through the cooperation of TPM and HSM. The communicating parties confirm their identities through the PKI public key authentication protocol, and use the RSA public key encryption algorithm to ensure the security of the key exchange process.

[0113] The comparison group uses the traditional RSA encryption mechanism. Although it can complete identity authentication, the key exchange process is relatively simple and the security is relatively low.

[0114] Phase 2: Data encryption and transmission:

[0115] The experimental group used the AES-256 algorithm for data encryption and combined it with the Diffie-Hellman protocol to implement dynamic key exchange. The system automatically adjusts the encryption algorithm based on the sensitivity of the data and the network bandwidth (for example, using a stronger encryption algorithm in a 5G network and a more efficient encryption method in a 4G network).

[0116] The comparison group used fixed-strength AES encryption during data transmission and did not adjust the dynamic encryption policy.

[0117] Phase 3: Data Integrity and Security:

[0118] The present invention generates a hash value of a data packet through a hash algorithm (such as SHA-256) and adds a digital signature to ensure the integrity and source reliability of the data during transmission.

[0119] The comparison group used conventional encryption methods to ensure data security, but did not attach digital signatures or perform data packet hash value verification, so the data integrity was relatively weak.

[0120] Phase 4: Communications Monitoring and Auditing:

[0121] During the data transmission process, the invention team also analyzes the data flow through the intelligent security engine and monitors the communication behavior in real time. Any anomalies can be quickly identified and an alarm is issued. At the same time, all communication logs will be recorded in the blockchain-based audit system to ensure that the log data cannot be tampered with.

[0122] The comparison group was not configured with an intelligent security engine and did not use blockchain technology for logging.

[0123] The specific experimental data are shown in the following table:

[0124]

[0125] Through the analysis of experimental data, it can be clearly seen that the group of the present invention has significant advantages in many aspects compared with the prior art group:

[0126] Authentication and key exchange efficiency:

[0127] The present invention uses TPM and HSM to work together, making identity authentication and key exchange faster and more secure. Experimental data show that the identity authentication and key exchange time of the present invention group are shortened by 50% and 40% respectively compared with the control group. This advantage enables the power asset management system to complete security authentication more efficiently in frequent communications, thereby improving the system response speed.

[0128] Encryption / decryption efficiency:

[0129] The present invention adopts a dynamic encryption algorithm, which can adjust the encryption strength according to the network bandwidth and data sensitivity, thereby optimizing the encryption and decryption efficiency without sacrificing security. The table shows that the present invention group improves the efficiency by 50% in the encryption and decryption process, especially when the network bandwidth is low, which can ensure the smooth and efficient operation of the system.

[0130] Data integrity and transmission security:

[0131] By introducing hash value verification and digital signature mechanisms, the present invention effectively ensures the integrity of data. Compared with traditional solutions, the data integrity verification time of the present invention group is reduced by one third (5ms vs 15ms), and zero data loss or damage is ensured, greatly improving the reliability of the transmission process.

[0132] Real-time monitoring and safety response capabilities:

[0133] The present invention introduces an intelligent security engine and a blockchain-based log audit system during the communication process to monitor the communication data flow in real time and identify abnormal behavior in a timely manner. Through behavioral analysis, the system can warn of potential security threats in advance and improve the system's real-time response capabilities. At the same time, all operations can be traced through the blockchain audit system to ensure the immutability and transparency of log data.

[0134] Quantum key distribution and anti-attack capabilities:

[0135] Quantum key distribution (QKD) technology is an innovative application of the present invention, which improves the security of key exchange by taking advantage of the non-cloning and non-eavesdropping properties of quantum communication. Compared with traditional cryptographic methods, the present invention has significant advantages in resisting various advanced attacks (such as quantum computing attacks).

[0136] In summary, the present invention not only greatly improves the communication security of the power asset management system by introducing the collaborative work of TPM and HSM, intelligent security engine, dynamic encryption algorithm and quantum key distribution technology, but also outperforms the existing technology in encryption efficiency, data transmission stability and system response speed. These technical advantages make the present invention have broad application prospects and practical value in the power industry and other fields that require high-security communication.

[0137] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A communication method for a power asset management master station system and a mobile terminal, characterized in that: The specific steps include: S1: Each power asset management master station and mobile terminal is equipped with a TPM chip, which provides encryption, decryption and secure storage functions, and ensures data security transmission through hardware isolation protection; at the same time, the master station system is equipped with HSM for high-intensity encryption operations and key management, and works with TPM to achieve key exchange, identity authentication and data encryption; S2: Before communication is established, a two-way identity authentication mechanism based on TPM and HSM is used to verify the identities of both parties using the public key authentication protocol to ensure that only authorized devices participate in communication and prevent illegal access and identity forgery; S3: All transmitted data is symmetrically encrypted with high strength by HSM at the sending end. The mobile terminal uses TPM to encrypt local data before sending it. The master station decrypts and verifies it through HSM. At the same time, RSA public key encryption is used for key exchange to ensure the security of encryption keys. Key management is jointly managed by HSM and TPM, and keys are securely exchanged through the Diffie-Hellman protocol. S4: During data transmission, a hash algorithm is used to calculate the hash value of the data packet and append it. The receiving end decrypts and verifies the hash value to ensure data integrity. For sensitive data, the master station system generates and appends a digital signature through the HSM, and the mobile terminal verifies the signature to ensure the data source is reliable; S5: An encrypted communication channel is established between the master system and the mobile terminal through a secure communication protocol. TPM and HSM work together to provide certificate verification and key exchange to ensure channel security. S6: Implement real-time monitoring of communication behaviors, use TPM and HSM to detect and report abnormal behaviors, and trigger security alarms; at the same time, record audit logs of all communications and operations, including key management, identity authentication, and data encryption and decryption, to facilitate later tracking and analysis.

2. The communication method between the power asset management master station system and the mobile terminal according to claim 1, characterized in that: During the data transmission process between the main station system and the mobile terminal, each data packet is timestamped by adding a timestamp mechanism. The receiving end performs data synchronization verification by comparing the timestamp with the system time to prevent data packet replay attacks.

3. The communication method between the power asset management master station system and the mobile terminal according to claim 2, characterized in that: The master station system and mobile terminals dynamically update and revoke certificates through a certificate management system based on TPM and HSM, ensuring that after the device or certificate expires, the system can automatically disable the revoked certificate, further improving the security of the system.

4. The communication method between the power asset management master station system and the mobile terminal according to claim 3, characterized in that: During the communication process, the master station system provides an access control mechanism through HSM to control the access and operation rights of users with different roles and permissions to communication data, ensuring that only authorized users can perform sensitive data operations.

5. The communication method between the power asset management master station system and the mobile terminal according to claim 4, characterized in that: An intelligent security engine based on behavioral analysis is used to perform real-time analysis of communication traffic, automatically identify and alarm possible abnormal behaviors, improve the system's defense capabilities and real-time response capabilities, and further enhance the security of data transmission. Among them, the intelligent security engine analyzes the behavioral patterns of communication data traffic, uses machine learning algorithms to automatically learn and identify normal and abnormal communication characteristics, detects potential threats in real time, and jointly triggers emergency response mechanisms through TPM and HSM to prevent the spread of attacks.

6. The communication method between the power asset management master station system and the mobile terminal according to claim 5, characterized in that: During the communication process between the mobile terminal and the main station system, a dynamic encryption algorithm is used to adjust the strength of data encryption. The level and complexity of the encryption algorithm are automatically adjusted according to the sensitivity of the data and the network environment to improve encryption efficiency while ensuring data security. Specifically, the system dynamically adjusts the encryption algorithm according to the data type and network bandwidth, such as using a more efficient encryption algorithm in a network environment with lower bandwidth, and using a stronger encryption algorithm in a high-bandwidth network.

7. The communication method between the power asset management master station system and the mobile terminal according to claim 6, characterized in that: The communication channel between the master station system and the mobile terminal realizes key exchange by using quantum key distribution technology, and takes advantage of the non-cloning and non-eavesdropping properties of quantum communication to ensure that the exchange process of communication keys is not eavesdropped or tampered with. Among them, quantum key distribution technology generates and distributes security keys through the principles of quantum entanglement and quantum superposition. All key exchanges are carried out within the security framework of quantum keys, thereby resisting attacks that traditional cryptography cannot prevent.

8. The communication method between the power asset management master station system and the mobile terminal according to claim 7, characterized in that: After the data is received, the master station system records each communication log into the blockchain through a data log audit system based on blockchain technology, ensuring the immutability and traceability of the log information and increasing the transparency and security of the data exchange process. The blockchain audit system not only records the communication content in an immutable manner, but also stores each operation in the communication process in a chain to ensure that all operations are traceable.

9. The communication method between the power asset management master station system and the mobile terminal according to claim 8, characterized in that: During the data transmission process, in order to prevent data loss or damage, the master station system and mobile terminal adopt an error detection and recovery mechanism based on error correction code to perform real-time verification of the transmitted data and automatically correct data errors that may occur during the transmission process; specifically, the system redundantly encodes the data before each data transmission, and the receiving end uses an error correction algorithm to check and repair lost or damaged data packets to ensure the integrity of the communication.

10. The communication method between the power asset management master station system and the mobile terminal according to claim 9, characterized in that: During the data transmission process, the master station system and the mobile terminal adopt a multiple encryption layer mechanism, combining symmetric encryption and asymmetric encryption, and using different encryption strategies in different communication stages to improve the security and encryption strength of data transmission; specifically, the system uses asymmetric encryption for key exchange and identity authentication in the initial stage of data transmission, uses symmetric encryption to improve efficiency in the actual stage of data transmission, and uses stronger asymmetric encryption in the sensitive data exchange stage to further enhance security.

Citation Information

Patent Citations

  • Trusted cloud computing system

    CN117176390A

  • Power system network security communication method

    CN117278214A

  • Credible cloud security level computing system

    CN118862092A

Cited By

  • Power system information secure transmission method, device, equipment and medium

    CN120358025A

  • Intelligent analysis system and method for secure transmission of chip data

    CN120434049A

  • Encrypted wireless communication terminal equipment special for electric power

    CN121012684A

  • A power-specific encrypted wireless communication terminal device

    CN121012684B

  • Third-party payment transaction method and system in weak network environment

    CN121280009A