Power terminal device authentication method and device, electronic equipment and storage medium
By generating secret values through local sensitive hash calculations on the factory parameters of power terminal equipment, and combining pseudonyms and multi-level key verification mechanisms, the problem of device privacy leakage in existing technologies is solved, achieving higher security and reliability authentication.
Patent Information
- Application Number
- CN202510212643.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-02-25
AI Technical Summary
In the existing power terminal authentication process, devices cannot generate and manage private keys independently, and rely heavily on key generation centers, resulting in a high risk of privacy leaks.
The secret value is generated by performing local sensitive hash calculation on the factory parameters of the device to be verified. This secret value is then combined with the device's private key and the authentication server's public key for signature authentication. A pseudonym is used to replace the device's real identity, and a multi-level key verification mechanism is employed for authentication.
It improves the security of power terminal equipment authentication, reduces the risk of identity information leakage, enhances privacy protection capabilities, and ensures the reliability of verification results through multi-level verification.
Smart Images

Figure CN119995900B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a device authentication method, apparatus, electronic device, and storage medium for power terminals. Background Technology
[0002] Existing power terminal authentication processes typically employ Identity-Based Encryption (IBE) systems, specifically using certificate management and device signing schemes for device access verification. During IBE authentication, devices cannot autonomously generate and manage their own private keys, relying heavily on trust in a key generation center. In this situation, a key authorization authority can decrypt any message sent through the IBE system, potentially leading to privacy breaches.
[0003] Improving the security of equipment authentication for power terminals is a crucial issue that the industry urgently needs to address. Summary of the Invention
[0004] This invention provides a device authentication method, apparatus, electronic device, and storage medium for power terminals, thereby improving the security of device authentication for power terminals.
[0005] This invention provides a device authentication method for a power terminal, applied to a device to be authenticated, comprising:
[0006] Locally sensitive hash calculation is performed on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier.
[0007] Based on the secret value, the device private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified.
[0008] The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0009] According to a device authentication method for a power terminal provided by the present invention, the process of determining the device private key includes:
[0010] The pseudonym is sent to the key generation center, so that the key generation center generates a first private key based on its private key and the pseudonym, and sends the first private key to the device to be verified.
[0011] Receive the first private key, and determine the device private key based on the first private key and the private key generated locally by the device to be verified.
[0012] This invention also provides a device authentication method for a power terminal, applied to a verification server, comprising:
[0013] The system receives signature authentication information sent by the device to be verified. The signature authentication information is obtained by signing the device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key, and the public key of the authentication server. The secret value of the device to be verified is obtained by performing local sensitive hash calculation based on the factory parameters of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.
[0014] The signature authentication information is verified based on the device's public key, the public key of the key generation center, and the private key of the authentication server to determine the verification result of the device to be verified. The device's public key is generated based on the device's private key.
[0015] According to a device authentication method for a power terminal provided by the present invention, after determining the authentication result of the device to be authenticated, the method further includes:
[0016] If the device to be verified passes the verification, the access of the device to be verified shall be approved;
[0017] If the verification of the device to be verified fails, a pseudonym of the device to be verified is obtained and sent to the tracking agency. After receiving the pseudonym, the tracking agency parses the pseudonym based on its private key to determine the device ID of the device to be verified.
[0018] The device authentication method for a power terminal provided by the present invention further includes:
[0019] When the device to be verified is multiple devices of the same category, the signature authentication information of the multiple devices of the same category is aggregated to obtain an aggregated signature;
[0020] Based on the aggregated signature, aggregated verification is performed on the multiple devices of the same category.
[0021] The present invention also provides a device authentication apparatus for a power terminal, applied to a device to be authenticated, the apparatus comprising:
[0022] The secret value calculation module is used to perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier.
[0023] The message signing module is used to sign the device access message initiated by the device to be verified based on the secret value, the device private key, and the public key of the authentication server to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.
[0024] The sending module is used to send the signature authentication information to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0025] The present invention also provides a device authentication apparatus for a power terminal, applied to a verification server, the apparatus comprising:
[0026] The receiving module is used to receive signature authentication information sent by the device to be verified. The signature authentication information is obtained by signing the device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key, and the public key of the authentication server. The secret value of the device to be verified is obtained by performing local sensitive hash calculation based on the factory parameters of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.
[0027] The verification module is used to verify the signature authentication information based on the device public key, the public key of the key generation center, and the private key of the authentication server, and to determine the verification result of the device to be verified. The device public key is generated based on the device private key.
[0028] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the program to implement the device authentication method for any of the power terminals described above.
[0029] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the device authentication method for a power terminal as described in any of the above.
[0030] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements a device authentication method for a power terminal as described above.
[0031] The device authentication method, apparatus, electronic device, and storage medium for power terminals provided by this invention generate a pseudonym for the device to replace its real identity identifier, thus avoiding direct exposure of the device's true identity and reducing security risks caused by identity information leakage. A secret value is generated based on the fusion of device fingerprints, location information, IP addresses, and other information, ensuring that the secret value itself does not directly correspond to any specific sensitive information. For example, device fingerprints are variable; when combined with other information, attackers cannot simply parse the secret value, further enhancing privacy protection and providing higher security for terminal device access. Simultaneously, when verifying signature authentication information, the authentication server verifies based on the device's public key, the key generation center's public key, and the authentication server's private key. This key verification mechanism provides multi-layered verification protection, improving the reliability of the verification results. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0033] Figure 1 This is one of the flowcharts illustrating the device authentication method for power terminals provided by the present invention.
[0034] Figure 2 This is a schematic diagram of the secret value generation process provided by the present invention.
[0035] Figure 3 This is the second flowchart illustrating the device authentication method for power terminals provided by this invention.
[0036] Figure 4 This is a schematic diagram of the verification feedback process provided by the present invention.
[0037] Figure 5 This is a schematic diagram of the multi-device access structure provided by the present invention.
[0038] Figure 6 This is one of the structural schematic diagrams of the equipment authentication device for power terminals provided by the present invention.
[0039] Figure 7 This is the second structural schematic diagram of the power terminal equipment authentication device provided by the present invention.
[0040] Figure 8 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0042] Figure 1 This is one of the flowcharts illustrating the device authentication method for power terminals provided by the present invention, such as... Figure 1 As shown, the method includes the following:
[0043] Step 110: Perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier.
[0044] Step 120: Based on the secret value, the device private key, and the authentication server's public key, sign the device access message initiated by the device to be verified to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified.
[0045] Step 130: Send the signature authentication information to the authentication server so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center, and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0046] The technical solution of the present invention will be described in detail below, taking the device authentication method of the power terminal provided by the present invention as an example of the device to be verified.
[0047] It should be noted that the device to be verified can be any device that needs to connect to the power terminal. Before connecting to the power terminal, the device to be verified sends a signed access request to the verification server. Based on the received signed access request, the verification server authenticates the device to be verified. If the verification is successful, the server approves the device to connect to the power terminal.
[0048] In step 110, a local sensitive hash calculation is performed on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier.
[0049] Specifically, the factory parameters of the device to be verified are obtained. The device to be verified uses its own device fingerprint, device location information, device IP address information, device manufacturing timestamp, and device unique identifier as input to calculate the secret value of the device to be verified.
[0050] Among them, devices in the same batch that are located in similar geographical locations have similar installation times and the same manufacturer and model, so their feature distributions are similar. Therefore, by adjusting the threshold of local sensitive hashing, devices with similar feature distributions can be mapped to the same secret value. Since a timestamp is added, the secret value generated each time will not be the same.
[0051] It should be noted that the unique identifier of a device is a unique secret seed value generated before the device leaves the factory and stored in the security hardware of the device to be verified.
[0052] In step 120, based on the secret value, the device private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified.
[0053] Before the device to be verified is connected to the power terminal equipment, the device to be verified needs to generate a device access message and sign the device access message to obtain signature authentication information for verification.
[0054] Specifically, the device to be verified first requests its pseudonym information from the Tracking Agency (TRA), and all subsequent signature authentication processes use this pseudonym. Furthermore, when a device malfunctions, the TRA can use its private key to expose the device. The Tracking Agency is responsible for generating the pseudonym for the device and tracing its origin when problems arise. The pseudonym, as the initial information carrier of the entire process, serves to conceal the true identity to some extent while simultaneously acting as a recognizable identifier in the key generation process.
[0055] The device to be verified sends its device ID to the tracking agency. Based on the received device ID and the tracking agency's public key, the tracking agency generates a pseudonym for the device to be verified and sends the generated pseudonym back to the device to be verified.
[0056] The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified.
[0057] Specifically, the process of generating a device private key can be as follows:
[0058] The device to be verified sends a pseudonym to the Key Generation Center (KGC). The Key Generation Center is a key entity in the field of information security responsible for key generation, management and distribution. Its core function is to generate various types of keys, including symmetric keys, private keys and public keys in asymmetric key pairs.
[0059] After receiving the pseudonym, the key generation center generates a partial private key for the device to be verified based on the pseudonym and the private key of the key generation center, and sends the partial private key to the device to be verified through a secure channel.
[0060] After receiving a portion of the private key, the device to be verified generates a device private key based on the portion of the private key and its own locally generated private key. Then, the device to be verified generates a corresponding device public key based on its private key.
[0061] After obtaining the secret value, the device's private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed based on the secret value, the device's private key, and the authentication server's public key to obtain the signature authentication information.
[0062] In step 130, the signature authentication information is sent to the authentication server so that after receiving the signature authentication information, the authentication server verifies the signature information based on the device public key, the public key of the key generation center, and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0063] The device to be verified sends its signature authentication information to the authentication server. Upon receiving the signature authentication information, the authentication server verifies the signature information based on the device's public key, the key generation center's public key, and the authentication server's private key. It should be noted that the device's public key and the key generation center's public key are publicly available and can be obtained by the authentication server.
[0064] Optionally, the specific verification process can be as follows:
[0065] When a device is shipped from the factory, the device manufacturer needs to add the same unique device identifier to devices of the same type. This can be achieved through a Hardware Security Module (HMS) or a security chip.
[0066] Given a security parameter Initialization algorithm The algorithm takes security parameters as input and generates common parameters. .choose , Two groups respectively and The generator. The key generation center KGC randomly selects one. ,in For a module The cyclic group. KGC will randomly select As your own private key , Tracking agency TRA randomly selects As the private key of TRA , Choosing a hash function , .in, This is the private key for KGC. This is the private key for TRA.
[0067] The common parameters are:
[0068] ;
[0069] in, It is the order of the group. It is a bilinear mapping. For KGC's public key, This is the public key for TRA.
[0070] The device identifier of the device to be verified is ,use The public key calculates its own pseudonym, pseudonym ,in .
[0071] The device to be verified sends its pseudonym FID to ,after Generate a partial private key for the device using your own private key. It then sends it to the device via a secure channel. It is a partial private key generated by KGC for the device.
[0072] The device to be verified gets its own Then, randomly select Obtain the device private key And further generate the device public key. .
[0073] A schematic diagram of the secret value generation process for the device to be verified can be shown as follows: Figure 2 As shown in the schematic diagram of the secret value generation process provided by this invention, the device to be verified locally extracts the device fingerprint. Equipment location information encoding Device IP address information The PRG result calculated from the device's manufacturing timestamp and unique device identifier. (in The timestamp value (the integer point closest to the current time) is used as a locality-sensitive hash function. Input, calculate secret value .
[0074] calculate ,in This is the secret value calculated for the device to be verified. The device to be verified then sends a device access message. Calculate the signature, which is generated by and It consists of two parts:
[0075] ;
[0076] in, This is the public key of the verifier.
[0077] Send the signature to the verification server. .
[0078] After the verification server receives a single signature sent by the device, the verification process is as follows:
[0079] ;
[0080] in, To verify the server's private key.
[0081] If the verification passes, the signature is valid; otherwise, the signature is rejected.
[0082] The device authentication method for power terminals provided by this invention generates a pseudonym for the device to replace its real identity, thus avoiding direct exposure of the device's true identity and reducing security risks caused by identity information leakage. A secret value is generated by fusing information such as device fingerprint, location information, and IP address, ensuring that the secret value itself does not directly correspond to any specific sensitive information. For example, device fingerprints are variable; when combined with other information, attackers cannot simply parse the secret value, further enhancing privacy protection and providing higher security for terminal device access. Simultaneously, when verifying signature information, the authentication server verifies based on the device's public key, the key generation center's public key, and the authentication server's private key. This key verification mechanism provides multi-layered verification protection, improving the reliability of the verification results.
[0083] In one embodiment, the process of determining the device private key includes: sending the pseudonym to the key generation center, so that the key generation center generates a first private key based on the private key of the key generation center and the pseudonym, and sends the first private key to the device to be verified; receiving the first private key, and determining the device private key based on the first private key and the private key locally generated by the device to be verified.
[0084] When the pseudonym is sent to the Key Generation Center (KGC), the KGC uses its internal complex key generation algorithm to perform a deep fusion operation between its own private key and the incoming pseudonym to obtain the first private key.
[0085] Then, KGC sends the generated first private key to the device to be verified through a pre-defined secure communication channel.
[0086] After receiving the first private key, the device to be verified integrates the first private key with the private key generated locally on the device to be verified to obtain the device private key.
[0087] The generated device private key combines the authority and core encryption resources of KGC with the unique attributes of the device to be verified, providing a solid guarantee for the secure operation of the device in the subsequent identity verification process.
[0088] Figure 3 This is the second flowchart illustrating the device authentication method for power terminals provided by the present invention, referring to... Figure 3The device authentication method for power terminals provided by this invention is applied to a verification server, and the method includes the following steps:
[0089] Step 310: Receive signature authentication information sent by the device to be verified. The signature authentication information is obtained by signing the device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key, and the public key of the authentication server. The secret value of the device to be verified is obtained by performing local sensitive hash calculation based on the factory parameters of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.
[0090] Step 320: Based on the device public key, the public key of the key generation center, and the private key of the authentication server, the signature authentication information is verified to determine the verification result of the device to be verified. The device public key is generated based on the device private key.
[0091] The technical solution of the present invention will be described in detail below, taking the verification server executing the device authentication method for the power terminal provided by the present invention as an example.
[0092] It should be noted that the device to be verified can be any device that needs to connect to the power terminal. Before connecting to the power terminal, the device to be verified sends a signed access request to the verification server. Based on the received signed access request, the verification server authenticates the device to be verified. If the verification is successful, the server approves the device to connect to the power terminal.
[0093] In step 320, the signature authentication information sent by the device to be verified is received.
[0094] Specifically, the signature authentication information is generated by the device to be verified.
[0095] The device to be verified obtains the device's factory parameters. The device to be verified uses its own device fingerprint, device location information, device IP address information, device manufacturing timestamp, and device unique identifier as input to calculate the device's secret value.
[0096] Among them, devices in the same batch that are located in similar geographical locations have similar installation times and the same manufacturer and model, so their feature distributions are similar. Therefore, by adjusting the threshold of local sensitive hashing, devices with similar feature distributions can be mapped to the same secret value. Since a timestamp is added, the secret value generated each time will not be the same.
[0097] It should be noted that the unique identifier of a device is a unique secret seed value generated before the device leaves the factory and stored in the security hardware of the device to be verified.
[0098] Before the device to be verified is connected to the power terminal equipment, the device to be verified needs to generate a device access message and sign the device access message to obtain signature authentication information for verification.
[0099] Specifically, the device to be verified first requests its pseudonym information from the Tracking Agency (TRA), and all subsequent signature authentication processes use this pseudonym. Furthermore, when a device malfunctions, the TRA can use its private key to expose the device. The Tracking Agency is responsible for generating the pseudonym for the device and tracing its origin when problems arise. The pseudonym, as the initial information carrier of the entire process, serves to conceal the true identity to some extent while simultaneously acting as a recognizable identifier in the key generation process.
[0100] The device to be verified sends its device ID to the tracking agency. Based on the received device ID and the tracking agency's public key, the tracking agency generates a pseudonym for the device to be verified and sends the generated pseudonym back to the device to be verified.
[0101] The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified.
[0102] Specifically, the process of generating a device private key can be as follows:
[0103] The device to be verified sends a pseudonym to the Key Generation Center (KGC). The Key Generation Center is a key entity in the field of information security responsible for key generation, management and distribution. Its core function is to generate various types of keys, including symmetric keys, private keys and public keys in asymmetric key pairs.
[0104] After receiving the pseudonym, the key generation center generates a partial private key for the device to be verified based on the pseudonym and the private key of the key generation center, and sends the partial private key to the device to be verified through a secure channel.
[0105] After receiving a portion of the private key, the device to be verified generates a device private key based on the portion of the private key and its own locally generated private key. Then, the device to be verified generates a corresponding device public key based on its private key.
[0106] After obtaining the secret value, the device's private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed based on the secret value, the device's private key, and the authentication server's public key to obtain the signature authentication information.
[0107] The device to be verified sends its signature authentication information to the authentication server. After receiving the signature authentication information, the authentication server proceeds with the subsequent verification process.
[0108] In step 320, the signature authentication information is verified based on the device public key, the public key of the key generation center, and the private key of the authentication server to determine the verification result of the device to be verified.
[0109] Optionally, the specific verification process can be as follows:
[0110] When a device is shipped from the factory, the device manufacturer needs to add the same unique device identifier to devices of the same type. This can be achieved through a Hardware Security Module (HMS) or a security chip.
[0111] Given a security parameter Initialization algorithm The algorithm takes security parameters as input and generates common parameters. .choose , Two groups respectively and The generator. The key generation center KGC randomly selects one. ,in For a module The cyclic group. KGC will randomly select As your own private key , Tracking agency TRA randomly selects As the private key of TRA , Choosing a hash function , .in, This is the private key for KGC. This is the private key for TRA.
[0112] The common parameters are:
[0113] ;
[0114] in, It is the order of the group. It is a bilinear mapping. For KGC's public key, This is the public key for TRA.
[0115] The device identifier of the device to be verified is ,use The public key is used to calculate its own pseudonym. ,in .
[0116] The device to be verified sends its pseudonym FID to ,after Generate a partial private key for the device using your own private key. It then sends it to the device via a secure channel. It is a partial private key generated by KGC for the device.
[0117] The device to be verified gets its own Then, randomly select Obtain the device private key And further generate the device public key. .
[0118] The device fingerprint extracted locally by the device to be verified Equipment location information encoding Device IP address information The PRG result calculated from the device's manufacturing timestamp and unique device identifier. (in The timestamp value (the integer point closest to the current time) is used as a locality-sensitive hash function. Input, calculation .
[0119] calculate ,in This is the secret value calculated for the device to be verified. The device to be verified then sends a device access message. Calculate the signature, which is generated by and It consists of two parts:
[0120] ;
[0121] in, This is the public key of the verifier.
[0122] Send the signature to the verification server. .
[0123] After the verification server receives a single signature sent by the device, the verification process is as follows:
[0124] ;
[0125] in, To verify the server's private key.
[0126] If the verification passes, the signature is valid; otherwise, the signature is rejected.
[0127] The device authentication method for power terminals provided by this invention generates a pseudonym for the device to replace its real identity, thus avoiding direct exposure of the device's true identity and reducing security risks caused by identity information leakage. A secret value is generated by fusing information such as device fingerprint, location information, and IP address, ensuring that the secret value itself does not directly correspond to any specific sensitive information. For example, device fingerprints are variable; when combined with other information, attackers cannot simply parse the secret value, further enhancing privacy protection and providing higher security for terminal device access. Simultaneously, when verifying signature information, the authentication server verifies based on the device's public key, the key generation center's public key, and the authentication server's private key. This key verification mechanism provides multi-layered verification protection, improving the reliability of the verification results.
[0128] In one embodiment, after determining the verification result of the device to be verified, the method further includes: if the device to be verified passes verification, approving the access of the device to be verified; if the device to be verified fails verification, obtaining a pseudonym of the device to be verified and sending the pseudonym to the tracking agency, so that the tracking agency, upon receiving the pseudonym, parses the pseudonym based on its private key to determine the device ID of the device to be verified.
[0129] The specific verification and feedback process can be as follows: Figure 4 The verification feedback process provided by this invention is illustrated in the diagram. The device to be verified generates a pseudonym and further generates a secret value. Based on the secret value, the device's private key, and the authentication server's public key, the device to be verified signs the device access message initiated by the device to obtain signature authentication information, and sends the signature authentication information to the verification server to execute the verification process.
[0130] Once the authentication server verifies the signature information based on the device's public key, the key generation center's public key, and its own private key, it determines that the device to be verified has passed the verification and approves the device's access to the power terminal system.
[0131] If the authentication server determines that the device to be verified fails the verification, it indicates that the device's identity is questionable. This could be due to an unauthorized device attempting to impersonate the user, or the device's signature authentication information being tampered with. In this case, the system will take further measures to trace the device's true identity.
[0132] Obtain the pseudonym of the device to be verified. The pseudonym plays a crucial role in protecting the true identity of the device during the access authentication process; however, it becomes an important clue for tracing the device's true identity if verification fails. The system sends the pseudonym to the tracing agency TRA to facilitate the source tracing process.
[0133] Optionally, when the verification server detects an anomaly in the device to be verified, it can send the pseudonym of the device to the tracking agency TRA. TRA will then decrypt the device's identity, enabling precise traceability of the device, revealing its true identity. .
[0134] In one embodiment, the method further includes: when the device to be verified is multiple devices of the same category, aggregating the signature authentication information of the multiple devices of the same category to obtain an aggregated signature; and performing aggregated verification on the multiple devices of the same category based on the aggregated signature.
[0135] A schematic diagram of the structure for connecting multiple devices can be shown as follows: Figure 5 As shown in the schematic diagram of the multi-device access structure provided by this invention, the devices for multiple power terminals to be connected may include multiple smart meters, multiple smart terminals, and multiple smart charging piles. Devices of the same type generate the same secret value for signing and assisting the authentication process. Multiple devices to be verified send their signature authentication information to the authentication server for aggregated verification. When traceability is required, the authentication server traces the devices by sending a pseudonym to TRA.
[0136] Optionally, the aggregation verification process can be:
[0137] Once the verifier has collected signature authentication information from a batch of devices of the same category, they can aggregate the signature authentication information to obtain an aggregated signature. for:
[0138] ;
[0139] The aggregated signature is then verified. If any anomalies are found during the signature authentication information collection process... Therefore, it is reasonable to pay attention to this signature authentication information, because according to the way the secret value is generated, similar devices within a certain range will generate the same signature within a certain time period. Therefore, if an abnormality occurs... The signature may be subject to reasonable doubt.
[0140] After the verification server aggregates the signature authentication information, it can use the device's pseudonym, KGC's public key, and the device's public key to verify the aggregated signature using the following formula:
[0141] ;
[0142] The system features efficient aggregation and verification, requiring only three pairing operations during the verification process, resulting in fewer pairing attempts and lower storage overhead. Simultaneously, by combining device fingerprints and aggregated signatures, it achieves a dual authentication scheme with signature authentication as the primary method and device fingerprint authentication as a secondary method, providing enhanced security for terminal device access.
[0143] Figure 6 This is one of the structural schematic diagrams of the equipment authentication device for a power terminal provided by the present invention. (Refer to...) Figure 6 The device authentication apparatus for a power terminal provided by the present invention includes:
[0144] The secret value calculation module 610 is used to perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier.
[0145] The message signing module 620 is used to sign the device access message initiated by the device to be verified based on the secret value, the device private key and the public key of the authentication server to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.
[0146] The sending module 630 is used to send the signature authentication information to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0147] In one embodiment, the message signature module 620 is specifically used for:
[0148] The process of determining the device private key includes:
[0149] The pseudonym is sent to the key generation center, so that the key generation center generates a first private key based on its private key and the pseudonym, and sends the first private key to the device to be verified.
[0150] Receive the first private key, and determine the device private key based on the first private key and the private key generated locally by the device to be verified.
[0151] Figure 7 This is a second structural schematic diagram of the equipment authentication device for the power terminal provided by the present invention. (Refer to...) Figure 7 The device authentication apparatus for a power terminal provided by the present invention includes:
[0152] The receiving module 710 is used to receive signature authentication information sent by the device to be verified. The signature authentication information is obtained by signing the device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key, and the public key of the authentication server. The secret value of the device to be verified is obtained by performing local sensitive hash calculation based on the factory parameters of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified.
[0153] The verification module 720 is used to verify the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and to determine the verification result of the device to be verified. The device public key is generated based on the device private key.
[0154] In one embodiment, the verification module 720 is specifically used for:
[0155] After determining the verification result of the device to be verified, the method further includes:
[0156] If the device to be verified passes the verification, the access of the device to be verified shall be approved;
[0157] If the verification of the device to be verified fails, a pseudonym of the device to be verified is obtained and sent to the tracking agency. After receiving the pseudonym, the tracking agency parses the pseudonym based on its private key to determine the device ID of the device to be verified.
[0158] In one embodiment, the verification module 720 is further configured to:
[0159] When the device to be verified is multiple devices of the same category, the signature authentication information of the multiple devices of the same category is aggregated to obtain an aggregated signature;
[0160] Based on the aggregated signature, aggregated verification is performed on the multiple devices of the same category.
[0161] Figure 8 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 8 As shown, the electronic device may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840, wherein the processor 810, the communications interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 can call logical instructions in the memory 830 to execute a device authentication method for the power terminal. The method includes: performing a local sensitive hash calculation on the factory parameters of the device to be verified to obtain a secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device manufacturing timestamp, and device unique identifier.
[0162] Based on the secret value, the device private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified.
[0163] The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0164] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0165] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program, the computer program being stored on a non-transitory computer-readable storage medium, the computer program being executed by a processor, the computer being able to execute the device authentication method for power terminals provided by the above methods, the method including: performing local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified, the factory parameters including one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier;
[0166] Based on the secret value, the device private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified.
[0167] The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0168] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a device authentication method for a power terminal provided by the methods described above. The method includes: performing a local sensitive hash calculation on the factory parameters of the device to be verified to obtain a secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier.
[0169] Based on the secret value, the device private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified.
[0170] The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key.
[0171] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0172] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0173] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A device authentication method for a power terminal, characterized in that, Applied to the device to be verified, including: Locally sensitive hash calculation is performed on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. Based on the secret value, the device private key, and the authentication server's public key, the device access message initiated by the device to be verified is signed to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the tracking agency's public key and the device ID of the device to be verified. The signature authentication information is sent to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key. The process of determining the device private key includes: The pseudonym is sent to the key generation center, so that the key generation center generates a first private key based on its private key and the pseudonym, and sends the first private key to the device to be verified. Receive the first private key, and determine the device private key based on the first private key and the private key generated locally by the device to be verified.
2. A device authentication method for a power terminal, characterized in that, Applied to the verification server, including: The system receives signature authentication information sent by the device to be verified. The signature authentication information is obtained by signing the device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key, and the public key of the authentication server. The secret value of the device to be verified is obtained by performing local sensitive hash calculation based on the factory parameters of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified. Based on the device's public key, the key generation center's public key, and the authentication server's private key, the signature authentication information is verified to determine the verification result of the device to be verified. The device's public key is generated based on the device's private key. The process of determining the device private key includes: The pseudonym is sent to the key generation center, so that the key generation center generates a first private key based on its private key and the pseudonym, and sends the first private key to the device to be verified. Receive the first private key, and determine the device private key based on the first private key and the private key generated locally by the device to be verified.
3. The device authentication method for power terminals according to claim 2, characterized in that, After determining the verification result of the device to be verified, the method further includes: If the device to be verified passes the verification, the access of the device to be verified shall be approved; If the verification of the device to be verified fails, a pseudonym of the device to be verified is obtained and sent to the tracking agency. After receiving the pseudonym, the tracking agency parses the pseudonym based on its private key to determine the device ID of the device to be verified.
4. The device authentication method for power terminals according to claim 2, characterized in that, Also includes: When the device to be verified is multiple devices of the same category, the signature authentication information of the multiple devices of the same category is aggregated to obtain an aggregated signature; Based on the aggregated signature, aggregated verification is performed on the multiple devices of the same category.
5. A device authentication apparatus for a power terminal, characterized in that, The device includes: The secret value calculation module is used to perform local sensitive hash calculation on the factory parameters of the device to be verified to obtain the secret value of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The message signing module is used to sign the device access message initiated by the device to be verified based on the secret value, the device private key, and the public key of the authentication server to obtain signature authentication information. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified. The sending module is used to send the signature authentication information to the authentication server, so that after receiving the signature authentication information, the authentication server verifies the signature authentication information based on the device public key, the public key of the key generation center and the private key of the authentication server, and determines the verification result of the device to be verified. The device public key is generated based on the device private key. The process of determining the device private key includes: The pseudonym is sent to the key generation center, so that the key generation center generates a first private key based on its private key and the pseudonym, and sends the first private key to the device to be verified. Receive the first private key, and determine the device private key based on the first private key and the private key generated locally by the device to be verified.
6. A device authentication apparatus for a power terminal, characterized in that, The device includes: The receiving module is used to receive signature authentication information sent by the device to be verified. The signature authentication information is obtained by signing the device access message initiated by the device to be verified based on the secret value of the device to be verified, the device private key, and the public key of the authentication server. The secret value of the device to be verified is obtained by performing local sensitive hash calculation based on the factory parameters of the device to be verified. The factory parameters include one or more of the following: device fingerprint, device location information, device IP address information, device factory timestamp, and device unique identifier. The device private key is determined based on the pseudonym of the device to be verified, the private key of the key generation center, and the private key generated locally by the device to be verified. The pseudonym of the device to be verified is generated based on the public key of the tracking agency and the device ID of the device to be verified. The verification module is used to verify the signature authentication information based on the device public key, the public key of the key generation center, and the private key of the authentication server, and to determine the verification result of the device to be verified. The device public key is generated based on the device private key. The process of determining the device private key includes: The pseudonym is sent to the key generation center, so that the key generation center generates a first private key based on its private key and the pseudonym, and sends the first private key to the device to be verified. Receive the first private key, and determine the device private key based on the first private key and the private key generated locally by the device to be verified.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the device authentication method for a power terminal as described in claim 1, or implements the device authentication method for a power terminal as described in any one of claims 2 to 4.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the device authentication method for a power terminal as described in claim 1, or implements the device authentication method for a power terminal as described in any one of claims 2-4.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the device authentication method for a power terminal as described in claim 1, or implements the device authentication method for a power terminal as described in any one of claims 2-4.
Citation Information
Patent Citations
Intelligent lock identity authentication method based on certificateless
CN109243020A
Identity authentication method, device and equipment based on certificateless signature
CN117955677A