Equipment authentication method and device of power terminal, electronic equipment and storage medium

By performing local sensitive hash calculations on the factory parameters of power terminal equipment, generating secret values ​​and signing authentication, the risk of privacy leakage during the equipment authentication process is solved, and higher security and reliability are achieved.

CN119995900AActive Publication Date: 2025-05-13STATE GRID HENAN INFORMATION & TELECOMM CO

Patent Information

Application Number
CN202510212643.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-13
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

During the existing power terminal authentication process, the device cannot generate and manage private keys independently, and relies heavily on the trust of the key generation center, resulting in the risk of privacy leakage.

Method used

By performing local sensitive hash calculations on the factory parameters of the device, secret values ​​are generated, and signature authentication is performed based on the secret values, device private keys and the public keys of the authentication server, replacing the real identity of the device, avoiding direct exposure of the real identity of the device.

Benefits of technology

Enhance the security of device authentication, reduce the risks caused by identity information leakage, and improve the reliability of verification results through a multi-level key verification mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995900A_ABST
    Figure CN119995900A_ABST
Patent Text Reader

Abstract

The invention provides an equipment authentication method and device for a power terminal, electronic equipment and a storage medium, and the method comprises the steps: carrying out the local sensitive hash calculation of factory parameters of to-be-verified equipment, and obtaining a secret value; and signing the equipment access message based on the secret value, the equipment private key and a public key of an authentication server to obtain signature authentication information, and sending the signature authentication information to the authentication server, so that the authentication server receives the signature authentication information and sends the signature authentication information to the authentication server based on the equipment public key, a public key of a key generation center and a private key of the authentication server. And verifying the signature authentication information, and determining a verification result. Based on the pseudonym and the secret value generated by information fusion, the real identity of the equipment can be prevented from being directly exposed, and the security risk caused by identity information leakage is reduced. Verification is carried out based on the equipment public key, the public key of the key generation center and the private key of the authentication server, a key verification mechanism provides multi-level verification guarantee, and the reliability of a verification result is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a device authentication method, device, electronic device and storage medium for a power terminal. Background Art

[0002] The existing power terminal authentication process generally uses an identity-based encryption (IBE) system for authentication, specifically by using a certificate management and device signature scheme to verify device access. During the authentication process of the IBE system, the device cannot independently generate and manage its own private key, and is heavily dependent on trust in the key generation center. At this point, the key authorization agency can decrypt any message sent through the IBE system, which will lead to privacy leakage to a certain extent.

[0003] How to improve the security of equipment authentication in power terminals is an important issue that needs to be urgently addressed in the industry. Summary of the invention

[0004] The present invention provides a device authentication method, a device, an electronic device and a storage medium for a power terminal, so as to improve the security of the device authentication of the power terminal.

[0005] The present invention provides a device authentication method for a power terminal, which is applied to a device to be authenticated, and comprises: Perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain a secret value of the device to be verified, where the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity; Based on the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be authenticated is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center and the private key generated locally by the device to be authenticated, and the pseudonym of the device to be authenticated is generated based on the public key of the tracking organization and the device ID of the device to be authenticated; The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0006] According to a device authentication method for a power terminal provided by the present invention, the process of determining the device private key includes: Sending the pseudonym to the key generation center, so that the key generation center generates a first private key based on the private key of the key generation center and the pseudonym, and sends the first private key to the device to be verified; The first private key is received, and the device private key is determined based on the first private key and a private key locally generated by the device to be verified.

[0007] The present invention also provides a device authentication method for a power terminal, which is applied to a verification server and includes: Receive signature authentication information sent by the device to be verified, where the signature authentication information is obtained by signing a device access message initiated by the device to be verified based on a secret value of the device to be verified, a device private key, and a public key of an authentication server, where the secret value of the device to be verified is obtained by performing a local sensitive hash calculation on factory parameters of the device to be verified, where the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity, where the device private key is determined based on a pseudonym of the device to be verified, a private key of a key generation center, and a private key locally generated by the device to be verified, where the pseudonym of the device to be verified is generated based on a public key of a tracking agency and a device ID of the device to be verified; Based on the device public key, the public key of the key generation center and the private key of the authentication server, the signature authentication information is verified to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0008] According to a device authentication method for a power terminal provided by the present invention, after determining the verification result of the device to be verified, the method further includes: If it is determined that the device to be verified has passed the verification, approving the access of the device to be verified; When it is determined that the device to be verified fails verification, a pseudonym of the device to be verified is obtained, and the pseudonym is sent to the tracking agency, so that after receiving the pseudonym, the tracking agency parses the pseudonym based on a private key to determine the device ID of the device to be verified.

[0009] According to the present invention, a method for authenticating a power terminal device further includes: In the case where the device to be verified is a plurality of devices of the same category, aggregating signature authentication information of the plurality of devices of the same category to obtain an aggregate signature; Based on the aggregate signature, aggregate verification is performed on the multiple devices of the same category.

[0010] The present invention also provides a device authentication device for a power terminal, which is applied to a device to be verified, and the device comprises: A secret value calculation module, used to perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified, wherein the factory parameters include one or more of the device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identity; A message signing module, used to sign the device access message initiated by the device to be verified based on the secret value, the device private key and the public key of the authentication server to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center and the private key generated locally by the device to be verified, and the pseudonym of the device to be verified is generated based on the public key of the tracking organization and the device ID of the device to be verified; A sending module is used to send the signature authentication information to the authentication server, so that after the authentication server receives the signature authentication information, it verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0011] The present invention also provides an equipment authentication device for a power terminal, which is applied to a verification server, and the device comprises: A receiving module, configured to receive signature authentication information sent by a device to be verified, wherein the signature authentication information is obtained by signing a device access message initiated by the device to be verified based on a secret value of the device to be verified, a device private key, and a public key of an authentication server, wherein the secret value of the device to be verified is obtained by performing a local sensitive hash calculation on factory parameters of the device to be verified, wherein the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity, wherein the device private key is determined based on a pseudonym of the device to be verified, a private key of a key generation center, and a private key generated locally by the device to be verified, and wherein the pseudonym of the device to be verified is generated based on a public key of a tracking agency and a device ID of the device to be verified; The verification module is used to verify the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determine the verification result of the device to be verified. The device public key is generated based on the device private key.

[0012] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the processor executes the program, an equipment authentication method for a power terminal as described in any one of the above is implemented.

[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the device authentication method for a power terminal as described in any one of the above is implemented.

[0014] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the device authentication method for a power terminal as described in any one of the above is implemented.

[0015] The device authentication method, device, electronic device and storage medium of the power terminal provided by the present invention can avoid directly exposing the real identity of the device and reduce the security risks caused by the leakage of identity information by generating a pseudonym for the device to replace the real identity identification of the device. The secret value is generated based on the fusion of information such as device fingerprint, location information, IP address, etc., so that the secret value itself does not directly correspond to a specific sensitive information. For example, the device fingerprint is changing. After combining with other information, the attacker cannot simply parse it from the secret value, which further enhances the privacy protection capability and brings higher security to the terminal device access. At the same time, when verifying the signature authentication information, the authentication server verifies based on the device public key, the public key of the key generation center and the private key of the authentication server. The key verification mechanism provides multi-level verification guarantees and improves the reliability of the verification results. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0017] Figure 1 This is one of the flow charts of the device authentication method of the power terminal provided by the present invention.

[0018] Figure 2 It is a schematic diagram of the secret value generation process provided by the present invention.

[0019] Figure 3 This is the second flow chart of the device authentication method for the power terminal provided by the present invention.

[0020] Figure 4 It is a schematic diagram of the verification feedback process provided by the present invention.

[0021] Figure 5 It is a schematic diagram of the multi-device access structure provided by the present invention.

[0022] Figure 6 This is one of the structural schematic diagrams of the equipment authentication device of the power terminal provided by the present invention.

[0023] Figure 7 This is the second structural schematic diagram of the equipment authentication device of the power terminal provided by the present invention.

[0024] Figure 8 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0026] Figure 1 This is one of the flow charts of the device authentication method for the power terminal provided by the present invention, such as Figure 1 As shown, the method includes the following: Step 110, performing local sensitive hash calculation on the factory parameters of the device to be verified to obtain a secret value of the device to be verified, wherein the factory parameters include one or more of a device fingerprint, a device location information, a device IP address information, a device factory timestamp, and a device unique identity; Step 120, based on the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be authenticated is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center and the private key generated locally by the device to be authenticated, and the pseudonym of the device to be authenticated is generated based on the public key of the tracking organization and the device ID of the device to be authenticated; Step 130, sending the signature authentication information to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0027] The following takes the device to be verified executing the device authentication method of the power terminal provided by the present invention as an example to explain the technical solution of the present invention in detail.

[0028] It should be noted that the device to be verified is any device that needs to be connected to the power terminal. Before the device to be verified is connected to the power terminal, the device to be verified will send a signed access request to the verification server. The verification server performs identity authentication on the device to be verified based on the received signed access request, and after determining that the verification is passed, it approves the device to be verified to access the power terminal.

[0029] In step 110, local sensitive hash calculation is performed on the factory parameters of the device to be verified to obtain a secret value of the device to be verified, where the factory parameters include one or more of the device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identification.

[0030] Specifically, the factory parameters of the device to be verified are obtained. The device to be verified uses its own device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identity as inputs of the local sensitive hash to calculate the secret value of the device to be verified.

[0031] Among them, since the same batch of devices in similar geographical locations have the characteristics of similar installation time and the same manufacturer model, their feature distributions are similar. Therefore, by adjusting the threshold of the locally sensitive hash, devices with similar feature distributions can be mapped to the same secret value. Since the timestamp is added, the secret value generated each time will not be the same.

[0032] It should be noted that the unique identity of the device is a unique secret seed value generated before the device leaves the factory and is stored in the secure hardware of the device to be verified.

[0033] In step 120, based on the secret value, the device private key, and the public key of the authentication server, the device access message initiated by the device to be verified is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified, and the pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.

[0034] Before the device to be verified is to be connected to the power terminal device, the device to be verified needs to generate a device access message and sign the device access message to obtain signature authentication information for verification.

[0035] Specifically, the device to be verified first applies to the Tracking Agency (TRA) for its own pseudonym information, and then all signature authentication processes are carried out using this pseudonym. And when there is a problem with the device, the TRA agency can use its own private key to reveal the device. Among them, the tracking agency is used to generate a pseudonym for the device and trace the device when there is a problem with the device. Among them, the pseudonym is the starting information carrier of the entire process, in order to conceal the real identity information to a certain extent, and at the same time it can participate in the key generation process as a recognizable identifier.

[0036] The device to be verified sends the device ID to the tracking agency. The tracking agency generates a pseudonym for the device to be verified based on the received device ID of the device to be verified and the public key of the tracking agency, and feeds the generated pseudonym back to the device to be verified.

[0037] The device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center, and the private key generated locally by the device to be authenticated.

[0038] Specifically, the process of generating the device private key can be: The device to be verified sends the pseudonym to the Key Generation Center (KGC). The Key Generation Center is a key entity in the field of information security responsible for key generation, management and distribution. Its core function is to generate various types of keys, including symmetric keys, private keys and public keys in asymmetric key pairs, etc.

[0039] After receiving the pseudonym, the key generation center generates a partial private key for the device to be verified based on the pseudonym and the private key of the key generation center, and sends the partial private key to the device to be verified through a secure channel.

[0040] After receiving the partial private key, the device to be verified generates a device private key based on the partial private key and the private key generated locally by the device to be verified. After the device to be verified generates the device private key, it generates the corresponding device public key based on the device private key.

[0041] After obtaining the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be verified is signed based on the secret value, the device private key and the public key of the authentication server to obtain signature authentication information.

[0042] In step 130, the signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature information based on the device public key, the public key of the key generation center, and the private key of the authentication server to determine the verification result of the device to be verified. The device public key is generated based on the corresponding device private key.

[0043] The device to be verified sends the signature authentication information to the authentication server. After receiving the signature authentication information, the authentication server verifies the signature information based on the device public key, the public key of the key generation center, and the private key of the authentication server. It should be noted that the device public key and the public key of the key generation center are publicly available and can be obtained by the authentication server.

[0044] Optionally, the specific verification process may be: When the device to be verified leaves the factory, the device manufacturer needs to add the same unique device identity to devices of the same type. This can be achieved through a hardware security module (HMS) or a security chip.

[0045] Given a security parameter , initialization algorithm The algorithm takes the security parameters as input and generates the public parameters .choose , Two groups and The key generation center KGC randomly selects a ,in For a model KGC will randomly select As your own private key , Tracking agency TRA randomly selected As TRA's private key , . Choose a hash function , .in, is the private key of KGC, It is the private key of TRA.

[0046] The common parameters are: ; in, is the order of the group, is a bilinear map, is the public key of KGC, It is the public key of TRA.

[0047] The device identifier of the device to be verified is ,use The public key calculates its own pseudonym, pseudonym ,in .

[0048] The device to be verified sends its pseudonym FID to ,after Use your own private key to generate a partial private key for the device. and sends it to the device through a secure channel. It is a partial private key generated by KGC for the device.

[0049] The device to be verified gets its own Then, randomly select , get the device private key , and further generate the device public key .

[0050] The schematic diagram of the secret value generation process of the device to be verified can be as follows: Figure 2 As shown in the schematic diagram of the secret value generation process provided by the present invention, the device to be verified locally extracts the device fingerprint , device location information encoding , device IP address information , the PRG result calculated by the device factory timestamp and the device unique identity (in Identifies the timestamp value of the nearest integer point in the current time) as a locality sensitive hash function Input, calculate the secret value .

[0051] calculate ,in is the calculated secret value of the device to be verified. Then the device to be verified sends a message to the device access Calculate the signature, which is determined by and It consists of two parts: ; in, The public key of the verifier.

[0052] Send the signature to the verification server .

[0053] After the verification server receives the single signature sent by the device, the verification process is as follows: ; in, The private key for the authentication server.

[0054] If the verification passes, the signature is proven to be valid, otherwise the signature is rejected.

[0055] The device authentication method for the power terminal provided by the present invention can avoid directly exposing the real identity of the device and reduce the security risks caused by the leakage of identity information by generating a pseudonym for the device to replace the real identity identification of the device. The secret value is generated based on the fusion of information such as device fingerprint, location information, IP address, etc., so that the secret value itself does not directly correspond to a specific sensitive information. For example, the device fingerprint is changing. After combining with other information, the attacker cannot simply parse it from the secret value, which further enhances the privacy protection capability and brings higher security to the terminal device access. At the same time, when verifying the signature information, the authentication server verifies based on the device public key, the public key of the key generation center and the private key of the authentication server. The key verification mechanism provides multi-level verification guarantees and improves the reliability of the verification results.

[0056] In one embodiment, the process of determining the device private key includes: sending the pseudonym to the key generation center so that the key generation center generates a first private key based on the private key of the key generation center and the pseudonym, and sends the first private key to the device to be verified; receiving the first private key, and determining the device private key based on the first private key and the private key generated locally by the device to be verified.

[0057] When the pseudonym is sent to the Key Generation Center (KGC), KGC will use its internal complex key generation algorithm to deeply integrate its own private key with the incoming pseudonym to obtain the first private key.

[0058] Then, KGC sends the generated first private key to the device to be verified through a pre-set secure communication channel.

[0059] After receiving the first private key, the device to be verified integrates the first private key and the private key generated locally by the device to be verified to obtain a device private key.

[0060] The generated device private key combines the authority and core encryption resources of KGC with the unique attributes of the device to be verified, providing a solid guarantee for the safe operation of the subsequent identity authentication process of the device to be verified.

[0061] Figure 3 The second flow chart of the device authentication method for the power terminal provided by the present invention is as follows: Figure 3 The device authentication method of the power terminal provided by the present invention is applied to the verification server, and the method comprises the following steps: Step 310, receiving signature authentication information sent by the device to be verified, the signature authentication information is obtained by signing a device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key and the public key of the authentication server, the secret value of the device to be verified is obtained by performing local sensitive hash calculation on the factory parameters of the device to be verified, the factory parameters include one or more of the device fingerprint, device location information, device IP address information, device factory timestamp and device unique identity, the device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center and the private key locally generated by the device to be verified, and the pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified; Step 320, based on the device public key, the public key of the key generation center and the private key of the authentication server, the signature authentication information is verified to determine the verification result of the device to be verified, and the device public key is generated based on the device private key.

[0062] The following takes the verification server executing the device authentication method of the power terminal provided by the present invention as an example to explain the technical solution of the present invention in detail.

[0063] It should be noted that the device to be verified is any device that needs to be connected to the power terminal. Before the device to be verified is connected to the power terminal, the device to be verified will send a signed access request to the verification server. The verification server performs identity authentication on the device to be verified based on the received signed access request, and after determining that the verification is passed, it approves the device to be verified to access the power terminal.

[0064] In step 320, signature authentication information sent by the device to be verified is received.

[0065] Specifically, the signature authentication information is generated by the device to be verified.

[0066] The device to be verified obtains the factory parameters of the device to be verified. The device to be verified uses its own device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identity as inputs of the local sensitive hash to calculate the secret value of the device to be verified.

[0067] Among them, since the same batch of devices in similar geographical locations have the characteristics of similar installation time and the same manufacturer model, their feature distributions are similar. Therefore, by adjusting the threshold of the locally sensitive hash, devices with similar feature distributions can be mapped to the same secret value. Since the timestamp is added, the secret value generated each time will not be the same.

[0068] It should be noted that the unique identity of the device is a unique secret seed value generated before the device leaves the factory and is stored in the secure hardware of the device to be verified.

[0069] Before the device to be verified is to be connected to the power terminal device, the device to be verified needs to generate a device access message and sign the device access message to obtain signature authentication information for verification.

[0070] Specifically, the device to be verified first applies to the Tracking Agency (TRA) for its own pseudonym information, and then all signature authentication processes are carried out using this pseudonym. And when there is a problem with the device, the TRA agency can use its own private key to reveal the device. Among them, the tracking agency is used to generate a pseudonym for the device and trace the device when there is a problem with the device. Among them, the pseudonym is the starting information carrier of the entire process, in order to conceal the real identity information to a certain extent, and at the same time it can participate in the key generation process as a recognizable identifier.

[0071] The device to be verified sends the device ID to the tracking agency. The tracking agency generates a pseudonym for the device to be verified based on the received device ID of the device to be verified and the public key of the tracking agency, and feeds the generated pseudonym back to the device to be verified.

[0072] The device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center, and the private key generated locally by the device to be authenticated.

[0073] Specifically, the process of generating the device private key can be: The device to be verified sends the pseudonym to the Key Generation Center (KGC). The Key Generation Center is a key entity in the field of information security responsible for key generation, management and distribution. Its core function is to generate various types of keys, including symmetric keys, private keys and public keys in asymmetric key pairs, etc.

[0074] After receiving the pseudonym, the key generation center generates a partial private key for the device to be verified based on the pseudonym and the private key of the key generation center, and sends the partial private key to the device to be verified through a secure channel.

[0075] After receiving the partial private key, the device to be verified generates a device private key based on the partial private key and the private key generated locally by the device to be verified. After the device to be verified generates the device private key, it generates the corresponding device public key based on the device private key.

[0076] After obtaining the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be verified is signed based on the secret value, the device private key and the public key of the authentication server to obtain signature authentication information.

[0077] The device to be verified sends the signature authentication information to the authentication server. After receiving the signature authentication information, the authentication server further implements the subsequent verification process.

[0078] In step 320, the signature authentication information is verified based on the device public key, the public key of the key generation center, and the private key of the authentication server to determine the verification result of the device to be verified.

[0079] Optionally, the specific verification process may be: When the device to be verified leaves the factory, the device manufacturer needs to add the same unique device identity to devices of the same type. This can be achieved through a hardware security module (HMS) or a security chip.

[0080] Given a security parameter , initialization algorithm The algorithm takes the security parameters as input and generates the public parameters .choose , Two groups and The key generation center KGC randomly selects a ,in For a model KGC will randomly select As your own private key , Tracking agency TRA randomly selected As TRA's private key , . Choose a hash function , .in, is the private key of KGC, It is the private key of TRA.

[0081] The common parameters are: ; in, is the order of the group, is a bilinear map, is the public key of KGC, It is the public key of TRA.

[0082] The device identifier of the device to be verified is ,use The public key calculates its own pseudonym, ,in .

[0083] The device to be verified sends its pseudonym FID to ,after Use your own private key to generate a partial private key for the device. and sends it to the device through a secure channel. It is a partial private key generated by KGC for the device.

[0084] The device to be verified gets its own Then, randomly select , get the device private key , and further generate the device public key .

[0085] The device fingerprint to be extracted locally by the device to be verified , device location information encoding , device IP address information , the PRG result calculated by the device factory timestamp and the device unique identity (in Identifies the timestamp value of the nearest integer point in the current time) as a locality sensitive hash function Input, calculation .

[0086] calculate ,in is the calculated secret value of the device to be verified. Then the device to be verified sends a message to the device access Calculate the signature, which is determined by and It consists of two parts: ; in, The public key of the verifier.

[0087] Send the signature to the verification server .

[0088] After the verification server receives the single signature sent by the device, the verification process is as follows: ; in, The private key for the authentication server.

[0089] If the verification passes, the signature is proven to be valid, otherwise the signature is rejected.

[0090] The device authentication method for the power terminal provided by the present invention can avoid directly exposing the real identity of the device and reduce the security risks caused by the leakage of identity information by generating a pseudonym for the device to replace the real identity identification of the device. The secret value is generated based on the fusion of information such as device fingerprint, location information, IP address, etc., so that the secret value itself does not directly correspond to a specific sensitive information. For example, the device fingerprint is changing. After combining with other information, the attacker cannot simply parse it from the secret value, which further enhances the privacy protection capability and brings higher security to the terminal device access. At the same time, when verifying the signature information, the authentication server verifies based on the device public key, the public key of the key generation center and the private key of the authentication server. The key verification mechanism provides multi-level verification guarantees and improves the reliability of the verification results.

[0091] In one embodiment, after determining the verification result of the device to be verified, it also includes: if it is determined that the verification of the device to be verified is passed, approving the access of the device to be verified; if it is determined that the verification of the device to be verified is not passed, obtaining the pseudonym of the device to be verified, and sending the pseudonym to the tracking agency, so that after the tracking agency receives the pseudonym, it resolves the pseudonym based on the private key to determine the device ID of the device to be verified.

[0092] The specific verification feedback process can be as follows Figure 4 The verification feedback process diagram provided by the present invention is shown as follows. The device to be verified generates a pseudonym and further generates a secret value. The device to be verified signs the device access message initiated by the device to be verified based on the secret value, the device private key and the public key of the authentication server, obtains the signature authentication information, and sends the signature authentication information to the authentication server to execute the verification process.

[0093] After the authentication server verifies the signature information based on the device public key, the public key of the key generation center and its own private key, it determines that the device to be verified has passed the verification, and then approves the device to access the power terminal system.

[0094] If the authentication server determines that the device to be authenticated fails the authentication, it indicates that there is doubt about the identity of the device, which may be an illegal device trying to access in disguise, or the signature authentication information of the device has been tampered with. At this time, the system will take further measures to track the true identity of the device.

[0095] Get the pseudonym of the device to be verified. The pseudonym plays a role in protecting the true identity of the device during the device access authentication process, but in the event of a failed authentication, it becomes an important clue to track the true identity of the device. The system sends the pseudonym to the tracking agency TRA to implement the traceability process.

[0096] Optionally, when the verification server finds that the device to be verified is abnormal, the pseudonym of the device to be verified can be sent to the tracking agency TRA, which decrypts the device identity to achieve accurate traceability of the device. The real identity of the device is .

[0097] In one embodiment, it also includes: when the device to be verified is a plurality of devices of the same category, aggregating signature authentication information of the plurality of devices of the same category to obtain an aggregate signature; and performing aggregate verification on the plurality of devices of the same category based on the aggregate signature.

[0098] The structural diagram of multiple devices accessing can be as follows: Figure 5 As shown in the schematic diagram of the multi-device access structure provided by the present invention, multiple devices to be connected to the power terminal may include multiple smart meters, multiple smart terminals, and multiple smart charging piles. Devices of the same type generate the same secret value for signature and auxiliary authentication process. Multiple devices to be verified send signature authentication information to the authentication server for aggregate verification. When tracing is required, the authentication server implements the tracing process of the device based on sending a pseudonym to TRA.

[0099] Optionally, the aggregate verification process can be: When the verifier collects a batch of signature authentication information of the same category of devices, the signature authentication information can be aggregated to obtain the aggregated signature. for: ; The aggregate signature is then verified. If an anomaly is found during the signature authentication information collection process , then it is reasonable to pay attention to the signature authentication information, because according to the way the secret value is generated, the same type of devices within a certain range will generate the same Therefore, if an abnormal , reasonable suspicion may be cast on the signature.

[0100] After the verification server aggregates the signature authentication information, it can use the device's pseudonym, the KGC's public key, and the device's public key to verify the aggregated signature using the following formula: ; Efficient aggregation and verification, only three pairing operations are required during the verification process, with fewer pairing times and lower storage overhead. At the same time, the device fingerprint and aggregate signature are combined to achieve a dual authentication solution with signature authentication as the main method and device fingerprint as the auxiliary authentication method, bringing higher security to terminal device access.

[0101] Figure 6This is one of the structural schematic diagrams of the equipment authentication device for the power terminal provided by the present invention. Figure 6 The device authentication device of the power terminal provided by the present invention comprises: The secret value calculation module 610 is used to perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified, where the factory parameters include one or more of the device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identification; A message signing module 620 is used to sign the device access message initiated by the device to be verified based on the secret value, the device private key and the public key of the authentication server to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center and the private key generated locally by the device to be verified, and the pseudonym of the device to be verified is generated based on the public key of the tracking organization and the device ID of the device to be verified; The sending module 630 is used to send the signature authentication information to the authentication server, so that after the authentication server receives the signature authentication information, it verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0102] In one embodiment, the message signing module 620 is specifically used to: The process of determining the device private key includes: Sending the pseudonym to the key generation center, so that the key generation center generates a first private key based on the private key of the key generation center and the pseudonym, and sends the first private key to the device to be verified; The first private key is received, and the device private key is determined based on the first private key and a private key locally generated by the device to be verified.

[0103] Figure 7 The second structural diagram of the equipment authentication device for the power terminal provided by the present invention. Figure 7 The device authentication device of the power terminal provided by the present invention comprises: A receiving module 710 is used to receive signature authentication information sent by a device to be verified, where the signature authentication information is obtained by signing a device access message initiated by the device to be verified based on a secret value of the device to be verified, a device private key, and a public key of an authentication server, where the secret value of the device to be verified is obtained by performing a local sensitive hash calculation on factory parameters of the device to be verified, where the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity, where the device private key is determined based on a pseudonym of the device to be verified, a private key of a key generation center, and a private key locally generated by the device to be verified, where the pseudonym of the device to be verified is generated based on a public key of a tracking agency and a device ID of the device to be verified; The verification module 720 is used to verify the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determine the verification result of the device to be verified. The device public key is generated based on the device private key.

[0104] In one embodiment, the verification module 720 is specifically used to: After determining the verification result of the device to be verified, the method further includes: If it is determined that the device to be verified has passed the verification, approving the access of the device to be verified; When it is determined that the device to be verified fails verification, a pseudonym of the device to be verified is obtained, and the pseudonym is sent to the tracking agency, so that after receiving the pseudonym, the tracking agency parses the pseudonym based on a private key to determine the device ID of the device to be verified.

[0105] In one embodiment, the verification module 720 is further specifically configured to: In the case where the device to be verified is a plurality of devices of the same category, aggregating signature authentication information of the plurality of devices of the same category to obtain an aggregate signature; Based on the aggregate signature, aggregate verification is performed on the multiple devices of the same category.

[0106] Figure 8 An example of a physical structure diagram of an electronic device is shown in FIG. Figure 8As shown, the electronic device may include: a processor 810, a communication interface 820, a memory 830 and a communication bus 840, wherein the processor 810, the communication interface 820 and the memory 830 communicate with each other through the communication bus 840. The processor 810 may call the logic instructions in the memory 830 to execute the device authentication method of the power terminal, the method comprising: performing local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified, the factory parameters including one or more of the device fingerprint, the device location information, the device IP address information, the device factory timestamp and the device unique identity; Based on the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be authenticated is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center and the private key generated locally by the device to be authenticated, and the pseudonym of the device to be authenticated is generated based on the public key of the tracking organization and the device ID of the device to be authenticated; The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0107] In addition, the logic instructions in the above-mentioned memory 830 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0108] On the other hand, the present invention further provides a computer program product, the computer program product includes a computer program, the computer program can be stored on a non-transitory computer-readable storage medium, when the computer program is executed by a processor, the computer can execute the device authentication method of the power terminal provided by the above methods, the method comprising: performing local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified, the factory parameters including one or more of the device fingerprint, device location information, device IP address information, device factory timestamp and device unique identification; Based on the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be authenticated is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center and the private key generated locally by the device to be authenticated, and the pseudonym of the device to be authenticated is generated based on the public key of the tracking organization and the device ID of the device to be authenticated; The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0109] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which is implemented when the computer program is executed by a processor to execute the device authentication method of the power terminal provided by the above methods, the method comprising: performing a local sensitive hash calculation on the factory parameters of the device to be verified to obtain a secret value of the device to be verified, the factory parameters including one or more of the device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identification; Based on the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be authenticated is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center and the private key generated locally by the device to be authenticated, and the pseudonym of the device to be authenticated is generated based on the public key of the tracking organization and the device ID of the device to be authenticated; The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

[0110] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0111] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A device authentication method for a power terminal, characterized in that: Applicable to the equipment to be verified, including: Perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain a secret value of the device to be verified, where the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity; Based on the secret value, the device private key and the public key of the authentication server, the device access message initiated by the device to be authenticated is signed to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be authenticated, the private key of the key generation center and the private key generated locally by the device to be authenticated, and the pseudonym of the device to be authenticated is generated based on the public key of the tracking organization and the device ID of the device to be authenticated; The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

2. The device authentication method of the power terminal according to claim 1, characterized in that: The process of determining the device private key includes: Sending the pseudonym to the key generation center, so that the key generation center generates a first private key based on the private key of the key generation center and the pseudonym, and sends the first private key to the device to be verified; The first private key is received, and the device private key is determined based on the first private key and a private key locally generated by the device to be verified.

3. A device authentication method for a power terminal, characterized in that: Applicable to the authentication server, including: Receive signature authentication information sent by the device to be verified, where the signature authentication information is obtained by signing a device access message initiated by the device to be verified based on a secret value of the device to be verified, a device private key, and a public key of an authentication server, where the secret value of the device to be verified is obtained by performing a local sensitive hash calculation on factory parameters of the device to be verified, where the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity, where the device private key is determined based on a pseudonym of the device to be verified, a private key of a key generation center, and a private key locally generated by the device to be verified, where the pseudonym of the device to be verified is generated based on a public key of a tracking agency and a device ID of the device to be verified; Based on the device public key, the public key of the key generation center and the private key of the authentication server, the signature authentication information is verified to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

4. The device authentication method of the power terminal according to claim 3, characterized in that: After determining the verification result of the device to be verified, the method further includes: If it is determined that the device to be verified has passed the verification, approving the access of the device to be verified; When it is determined that the device to be verified fails verification, a pseudonym of the device to be verified is obtained, and the pseudonym is sent to the tracking agency, so that after receiving the pseudonym, the tracking agency parses the pseudonym based on a private key to determine the device ID of the device to be verified.

5. The device authentication method of the power terminal according to claim 3, characterized in that: Also includes: In the case where the device to be verified is a plurality of devices of the same category, aggregating signature authentication information of the plurality of devices of the same category to obtain an aggregate signature; Based on the aggregate signature, aggregate verification is performed on the multiple devices of the same category.

6. An equipment authentication device for a power terminal, characterized in that: Applied to a device to be verified, the device comprises: A secret value calculation module, used to perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified, wherein the factory parameters include one or more of the device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identity; A message signing module, used to sign the device access message initiated by the device to be verified based on the secret value, the device private key and the public key of the authentication server to obtain signature authentication information, wherein the device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center and the private key generated locally by the device to be verified, and the pseudonym of the device to be verified is generated based on the public key of the tracking organization and the device ID of the device to be verified; A sending module is used to send the signature authentication information to the authentication server, so that after the authentication server receives the signature authentication information, it verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server to determine the verification result of the device to be verified, and the device public key is generated based on the corresponding device private key.

7. An equipment authentication device for a power terminal, characterized in that: Applied to a verification server, the device comprises: A receiving module, configured to receive signature authentication information sent by a device to be verified, wherein the signature authentication information is obtained by signing a device access message initiated by the device to be verified based on a secret value of the device to be verified, a device private key, and a public key of an authentication server, wherein the secret value of the device to be verified is obtained by performing a local sensitive hash calculation on factory parameters of the device to be verified, wherein the factory parameters include one or more of a device fingerprint, device location information, device IP address information, a device factory timestamp, and a device unique identity, wherein the device private key is determined based on a pseudonym of the device to be verified, a private key of a key generation center, and a private key generated locally by the device to be verified, and wherein the pseudonym of the device to be verified is generated based on a public key of a tracking agency and a device ID of the device to be verified; The verification module is used to verify the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determine the verification result of the device to be verified. The device public key is generated based on the device private key.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the device authentication method for the power terminal as described in claim 1 or 2 is implemented, or the device authentication method for the power terminal as described in any one of claims 3 to 5 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the device authentication method for a power terminal as described in claim 1 or 2 is implemented, or the device authentication method for a power terminal as described in any one of claims 3-5 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the device authentication method for a power terminal as described in claim 1 or 2 is implemented, or the device authentication method for a power terminal as described in any one of claims 3-5 is implemented.

Citation Information

Patent Citations

  • Intelligent lock identity authentication method based on certificateless

    CN109243020A

  • Blockchain anti-signature traceable certificateless blind signature generation method

    CN112532394A

  • Identity-based anonymous authentication method, server and user terminal equipment

    CN114513316A

  • Power Internet of Things terminal certificateless authentication method, device and system

    CN116582256A

  • Identity authentication method, device and equipment based on certificateless signature

    CN117955677A

Cited By

  • Equipment network access method and device, electronic equipment, storage medium and program product

    CN121510009A