Power data secure transmission method and system based on hybrid encryption

By obtaining the AES public key ciphertext and calculating the hash value, transmitting data packets using the TLS/SSL protocol, and verifying and decrypting the power data ciphertext. Combined with the blockchain to store and manage public key information, the problems of low ciphertext integrity verification capabilities, poor data verification efficiency and insufficient public key information management in the existing technology are solved, and efficient and secure power data transmission is achieved.

CN119995945AActive Publication Date: 2025-05-13GUIZHOU POWER GRID CO LTD

Patent Information

Application Number
CN202510041629.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-13
Estimated Expiration
2045-01-10

Smart Images

  • Figure CN119995945A_ABST
    Figure CN119995945A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power data secure transmission method and system based on hybrid encryption, and relates to the technical field of electric power data secure transmission, and the method comprises the steps: obtaining an AES public key ciphertext, and calculating a hash value; transmitting the data packet to a data receiver through a TLS / SSL protocol, and verifying the power data ciphertext; and decrypting the power data ciphertext based on the verification result, and storing and managing the public key information of the two parties through the block chain. According to the method, the tamper-proof capability of information in the transmission process is improved, the data secure transmission quality is improved, the security isolation and protection of the power data in Internet transmission are improved, the probability that the data are tampered or forged is reduced, and the security of the power data is improved. Therefore, powerful support is provided for the requirement for data transmission security in high-frequency and big data scenes, the security of data transmission is improved, the transparency and traceability of public key management are also improved, and comprehensive guarantee is provided for secure transmission of power data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power data secure transmission, and in particular to a power data secure transmission method and system based on hybrid encryption. Background Art

[0002] In today's information age, the importance of secure data transmission has become increasingly prominent, especially in the field of power data management. With the popularization of the Internet of Things and smart grids, a large amount of power data needs to be transmitted in the network, and the security and privacy protection of this data has become the focus of research; traditional encryption technologies such as AES (Advanced Encryption Standard) and SSL / TLS (Secure Sockets Layer / Transport Layer Security) protocols, although they provide a certain security guarantee for data transmission, are facing more and more challenges in practical applications. In recent years, although encryption technology and security protocols have been continuously improved, for the secure transmission of power data, there is still a need to further explore more efficient and reliable technical solutions.

[0003] The existing related technologies still have many deficiencies in the secure transmission of power data. In terms of data encryption processing, the traditional AES encryption algorithm has a low data transmission efficiency when processing a large amount of power data due to the complex calculation of its encryption and decryption process, which makes it difficult to meet the needs of real-time monitoring and rapid response. In terms of data transmission integrity verification, although the existing TLS / SSL protocol can ensure the security of data during transmission, its verification mechanism is powerless in the face of increasingly complex network attack methods, and the integrity and anti-tampering capabilities of data need to be improved. The management and update of public key information is another weak link in the existing technology. The leakage or failure of the public key will directly affect the security of data transmission. At present, the storage and update of public keys often rely on a centralized management system, which not only increases the risk of single point failure, but also in a distributed network environment, the synchronization and update efficiency of public keys is low, and it is difficult to adapt to the rapidly changing network environment. In the transmission process of verification data, the existing technology lacks consideration of the unique attributes of power data, which makes it difficult to optimize the encryption and verification process according to the characteristics of power data, thereby affecting the overall performance of data transmission. Therefore, how to achieve efficient and secure transmission of power data has become a technical problem that needs to be solved in this field. Summary of the invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by the present invention is: the existing encrypted data transmission technology has low ciphertext integrity verification capability, poor data verification efficiency, insufficient public key information management, and how to ensure the security and efficiency of data transmission through hybrid encryption technology.

[0006] To solve the above technical problems, the present invention provides the following technical solutions: a method for secure transmission of power data based on hybrid encryption, comprising obtaining AES public key ciphertext and calculating a hash value; transmitting the data packet to the data recipient through the TLS / SSL protocol, and verifying the power data ciphertext; decrypting the power data ciphertext based on the verification result, and storing and managing the public key information of both parties through blockchain.

[0007] As a preferred solution of the method for secure transmission of electric power data based on hybrid encryption described in the present invention, wherein: the obtaining of AES public key ciphertext includes AES encryption of electric power data, ECC encryption of AES public key, and generation of digital signature.

[0008] AES encryption of power data includes the data sender encrypting the power data through the symmetric encryption algorithm AES to obtain the ciphertext of the power data.

[0009] ECC encryption of the AES public key includes encrypting the AES public key by using an asymmetric encryption algorithm ECC to obtain the AES public key ciphertext.

[0010] Generating a digital signature includes using the data sender's ECC private key and ECDSA algorithm to generate a digital signature for the encrypted AES public key ciphertext, thereby verifying the source authenticity and anti-tampering capabilities of the data.

[0011] As a preferred solution of the method for secure transmission of power data based on hybrid encryption described in the present invention, wherein: the calculation of the hash value includes using the SHA-256 algorithm to calculate the hash value of the power data ciphertext and performing integrity verification on the data.

[0012] As a preferred solution of the method for secure transmission of electric power data based on hybrid encryption described in the present invention, wherein: the data receiving party transmitted through the TLS / SSL protocol includes a data sender assembling a complete data packet, and transmitting the data packet to the data receiving party through the TLS / SSL protocol, and the data packet includes electric power data ciphertext, AES public key ciphertext, data hash value, digital signature, sender identity unique identification, and timestamp.

[0013] The data encryption ciphertext includes power data ciphertext and AES public key ciphertext.

[0014] The integrity of the data and whether it has been tampered with are verified based on the data hash value and digital signature.

[0015] The sender's unique identity identifier records the identity information of the data sender.

[0016] The timestamp records the time when the data is sent.

[0017] As a preferred solution of the method for secure transmission of electric power data based on hybrid encryption described in the present invention, wherein: the verification of the electric power data ciphertext includes hash value verification and digital signature verification.

[0018] Hash value verification includes the data receiver recalculating the hash value of the received power data ciphertext and performing a consistency check with the hash value in the data packet. If the check passes, it means the data is consistent.

[0019] Digital signature verification includes the data recipient using the sender's identity to query the data sender's ECC public key from the blockchain, using the data sender's ECC public key and ECDSA algorithm to verify the digital signature, confirming that the data comes from a legitimate sender and has not been tampered with.

[0020] As a preferred solution of the method for secure transmission of power data based on hybrid encryption described in the present invention, wherein: the decryption of the power data ciphertext based on the verification result includes performing the decryption process when the hash value verification and the digital signature verification are correct, and terminating the decryption process if the verification fails, and sending an error code to the data sender.

[0021] The decryption process includes using the queried ECC public key of the data sender to decrypt the AES public key ciphertext through the ECC algorithm to obtain the AES public key, and using the AES public key to decrypt the power data ciphertext through the AES algorithm to obtain the original power data.

[0022] As a preferred solution of the method for secure transmission of power data based on hybrid encryption described in the present invention, the storage and management of the public key information of both parties through blockchain includes sending the ECC public keys of the power data sending server and the receiving server, encrypting the AES key, and verifying the digital signature, binding the public key with the corresponding device ID or user ID, confirming the uniqueness of the identity, setting a clear validity period for each public key, and establishing a dynamic update mechanism for the public key.

[0023] The dynamic public key update mechanism includes generating a new ECC key pair when the public key expires or needs to be updated due to security risks, submitting an update request through the blockchain, including the new public key, device ID, version number of the original public key, and an update certificate signed with the old private key. After the blockchain node verifies the legitimacy of the update request, it writes the new public key into the block through the consensus mechanism to generate a new public key version record.

[0024] Another object of the present invention is to provide a power data security transmission system based on hybrid encryption, which can transmit the data packet to the data recipient through the TLS / SSL protocol and verify the power data ciphertext, thereby solving the problem that the current traditional data transmission security technology contains insufficient protection for data verification and validity.

[0025] As a preferred solution of the hybrid encryption-based power data security transmission system described in the present invention, it includes: a public key ciphertext acquisition module, a data transmission verification module, and a decryption and storage module.

[0026] The public key ciphertext acquisition module is used to obtain the AES public key ciphertext and calculate the hash value; the data transmission verification module is used to transmit the data packet to the data recipient through the TLS / SSL protocol and verify the power data ciphertext; the decryption and storage module is used to decrypt the power data ciphertext based on the verification result, and store and manage the public key information of both parties through the blockchain.

[0027] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement a step of a method for secure transmission of electric power data based on hybrid encryption.

[0028] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a method for secure transmission of electric power data based on hybrid encryption.

[0029] Beneficial effects of the present invention: The hybrid encryption-based power data security transmission method provided by the present invention obtains AES public key ciphertext and calculates hash value, which improves the anti-tampering ability of information during transmission, improves the quality of data security transmission, and effectively reduces the risk of data leakage. The data packet is transmitted to the data recipient through the TLS / SSL protocol, and the power data ciphertext is verified, which improves the security isolation and protection of power data in Internet transmission, reduces the probability of data tampering or forgery, and thus provides strong support for the requirements for data transmission security in high-frequency and big data scenarios. The power data ciphertext is decrypted based on the verification result, and the public key information of both parties is stored and managed through the blockchain, which improves the security of data transmission, and also improves the transparency and traceability of public key management, providing comprehensive protection for the secure transmission of power data. The present invention achieves better results in data transmission security, data integrity verification and public key management flexibility. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0031] Figure 1 An overall flow chart of a method for secure transmission of electric power data based on hybrid encryption provided for the first embodiment of the present invention.

[0032] Figure 2 A power data encryption flow chart of a power data secure transmission method based on hybrid encryption is provided for the second embodiment of the present invention.

[0033] Figure 3 A data transmission detail diagram of a method for secure transmission of electric power data based on hybrid encryption provided in a second embodiment of the present invention.

[0034] Figure 4 A data verification flow chart of a method for secure transmission of electric power data based on hybrid encryption is provided for the second embodiment of the present invention.

[0035] Figure 5 A power data decryption flow chart of a power data secure transmission method based on hybrid encryption provided in the second embodiment of the present invention.

[0036] Figure 6 An overall flow chart of a power data secure transmission system based on hybrid encryption provided for the third embodiment of the present invention. DETAILED DESCRIPTION

[0037] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0038] Example 1, reference Figure 1 , as an embodiment of the present invention, provides a method for secure transmission of electric power data based on hybrid encryption, comprising:

[0039] S1: Obtain the AES public key ciphertext and calculate the hash value.

[0040] Furthermore, obtaining the AES public key ciphertext includes AES encryption of power data, ECC encryption of the AES public key, and generation of a digital signature.

[0041] AES encryption of power data includes the data sender encrypting the power data through the symmetric encryption algorithm AES to obtain the ciphertext of the power data.

[0042] ECC encryption of the AES public key includes encrypting the AES public key by using an asymmetric encryption algorithm ECC to obtain the AES public key ciphertext.

[0043] Generating a digital signature includes using the data sender's ECC private key and ECDSA algorithm to generate a digital signature for the encrypted AES public key ciphertext, thereby verifying the source authenticity and anti-tampering capabilities of the data.

[0044] It should be noted that calculating the hash value includes using the SHA-256 algorithm to calculate the hash value of the power data ciphertext and perform integrity verification on the data.

[0045] It should also be noted that by obtaining the AES public key ciphertext and calculating the hash value, this step ensures the security and integrity of the power data. The data sender uses AES to encrypt the power data to obtain the ciphertext, and uses ECC to encrypt the AES public key to generate the AES public key ciphertext, which effectively prevents the leakage of sensitive data during transmission and ensures that only authorized recipients can decrypt the data. Any slight change in the data will cause a change in the hash value. In view of the uniqueness and integrity of the data, the SHA-256 algorithm is used to calculate the hash value. The generated hash value provides a reliable basis for subsequent data verification. It is particularly important when processing sensitive data, ensuring the confidentiality of the data and providing an effective integrity verification method. The hash value is transmitted with the data in the data packet. The receiver can recalculate the hash value when receiving it and compare it with the hash value sent by the sender to verify the consistency of the data. This mechanism can effectively prevent data tampering in actual operation and improve the overall security of the system. Combined with the ciphertext form of the ECC encrypted public key, it not only improves the security of the public key, but also prevents threats such as man-in-the-middle attacks and data interception. By strengthening the encryption mechanism and integrity verification of the data, a safe and reliable data foundation is provided.

[0046] S2: Transmit the data packet to the data receiver through the TLS / SSL protocol and verify the power data ciphertext.

[0047] Furthermore, the data receiver including the data sender assembles a complete data packet through the TLS / SSL protocol, and transmits the data packet to the data receiver through the TLS / SSL protocol. The data packet includes power data ciphertext, AES public key ciphertext, data hash value, digital signature, sender identity unique identification, and timestamp.

[0048] The data encryption ciphertext includes power data ciphertext and AES public key ciphertext.

[0049] The integrity of the data and whether it has been tampered with are verified based on the data hash value and digital signature.

[0050] The sender's unique identity identifier records the identity information of the data sender.

[0051] The timestamp records the time when the data is sent.

[0052] It should be noted that the verification of the power data ciphertext includes hash value verification and digital signature verification.

[0053] Hash value verification includes the data receiver recalculating the hash value of the received power data ciphertext and performing a consistency check with the hash value in the data packet. If the check passes, it means the data is consistent.

[0054] Digital signature verification includes the data recipient using the sender's identity to query the data sender's ECC public key from the blockchain, using the data sender's ECC public key and ECDSA algorithm to verify the digital signature, confirming that the data comes from a legitimate sender and has not been tampered with.

[0055] It should also be noted that the data packet is transmitted to the data receiver through the TLS / SSL protocol, which effectively ensures the security and privacy of the data in an open network environment; the use of the TLS / SSL protocol ensures that all data is encrypted during transmission to prevent unauthorized access or tampering during transmission. The integrity and legitimacy of the data packet are fully guaranteed before transmission. The data sender integrates the power data ciphertext, AES public key ciphertext, hash value, digital signature, sender identity unique identification and timestamp information to form a powerful security package; on the receiving end, the key to this process is to verify the hash value and digital signature. Recalculating the hash value can ensure The received data is accurate, avoiding the risks of unauthorized tampering. The blockchain is used to query the sender's ECC public key, and the receiver verifies the digital signature to further confirm the legitimacy of the sender's identity, ensuring the credibility of the data source and effectively improving the protection capabilities of the entire communication process. It provides a solid security guarantee for enterprises or institutions when processing sensitive information. The timestamp recorded during the transmission process ensures the time consistency of the data and enhances the management of data timeliness. Through the implementation of the TLS / SSL protocol, data security in complex network environments is improved, providing strong support for meeting the strict requirements for data integrity and security in modern communication processes.

[0056] S3: Decrypt the ciphertext of the power data based on the verification result, and store and manage the public key information of both parties through the blockchain.

[0057] Furthermore, decrypting the power data ciphertext based on the verification result includes performing the decryption process when the hash value verification and the digital signature verification are correct. If the verification fails, the decryption process is terminated and an error code is sent to the data sender.

[0058] The decryption process includes using the queried ECC public key of the data sender to decrypt the AES public key ciphertext through the ECC algorithm to obtain the AES public key, and using the AES public key to decrypt the power data ciphertext through the AES algorithm to obtain the original power data.

[0059] It should be noted that the storage and management of the public key information of both parties through blockchain includes sending the ECC public keys of the power data sending server and the receiving server, encrypting the AES key, and verifying the digital signature, binding the public key with the corresponding device ID or user ID, confirming the uniqueness of the identity, setting a clear validity period for each public key, and establishing a dynamic update mechanism for the public key.

[0060] The dynamic public key update mechanism includes generating a new ECC key pair when the public key expires or needs to be updated due to security risks, submitting an update request through the blockchain, including the new public key, device ID, version number of the original public key, and an update certificate signed with the old private key. After the blockchain node verifies the legitimacy of the update request, it writes the new public key into the block through the consensus mechanism to generate a new public key version record.

[0061] It should also be noted that a strict verification process is used to decide whether to decrypt the data, which effectively prevents the possibility of unauthorized access. Only when the hash value verification and digital signature verification are both passed, the receiver will continue to complete the decryption of the power data ciphertext, and use the ECC public key to decrypt the AES public key ciphertext, ensuring that even if the attacker obtains the data packet, it cannot easily decrypt the valid data, thus protecting sensitive information; combining blockchain technology to store and manage the public key information of both parties improves the overall security and efficiency. The decentralized nature of blockchain ensures that the public key information cannot be tampered with, forming a safe and transparent trust environment in the system; based on the block The dynamic public key update mechanism of the chain ensures that a new ECC key pair can be quickly generated and updated when the public key expires or faces security risks, which increases the system's resilience and self-healing capabilities. Through the consensus mechanism of the blockchain, the security and trust of the system are effectively improved; combined with the binding information of the public key and the device, the uniqueness of the identity is ensured, and the risk of identity forgery is further reduced, providing new ideas and methods for promoting secure data transmission in smart grid and Internet of Things environments in the future; by achieving secure decryption and efficient public key management, it provides strong protection for secure data transmission, while improving the flexible adaptability of the entire system in response to potential security threats in the future.

[0062] Example 2, reference Figure 2-Figure 5 , which is an embodiment of the present invention, provides a method for secure transmission of power data based on hybrid encryption. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0063] First, the experiment selected 1000 independent power data samples, each of which contained user identification, power type, power consumption, and timestamp; at the data sending end, the AES-256 encryption algorithm was used to encrypt the power data; Figure 2, represents the power data encryption process. During the encryption process, a 256-bit key AES_KEY is randomly generated to encrypt the power data and obtain the power data ciphertext CIPHERTEXT_DATA; then, the ECC-521 algorithm is used to encrypt AES_KEY to generate the AES public key ciphertext CIPHERTEXT_AES_KEY. The data sender has a pair of ECC keys ECC_PRIV and ECC_PUB. ECC_PRIV is used to encrypt AES_KEY, and ECC_PUB will be used for the subsequent decryption process of the data receiver; after completing the public key encryption, the SHA-256 hash algorithm is used to calculate the hash value HASH_VALUE of CIPHERTEXT_DATA to ensure the integrity of the data. The hash value will be transmitted together with the data packet for verification by the data receiver; next, refer to Figure 3 , represents the data transmission process. The data sender uses ECC_PRIV and ECDSA algorithms to generate a digital signature DIGITAL_SIGNATURE for CIPHERTEXT_AES_KEY. The digital signature is used to verify the authenticity of the data source and the data's tamper-proof capability. During the data transmission phase, the data sender packages CIPHERTEXT_DATA, CIPHERTEXT_AES_KEY, HASH_VALUE, DIGITAL_SIGNATURE, the sender's unique identifier SENDER_ID, and the timestamp, and sends them to the data receiver through the TLS / SSL protocol, ensuring the security of the data during transmission. See Figure 4 , which is represented as the data verification process. After receiving the data packet, the data receiving end first recalculates the hash value of CIPHERTEXT_DATA and compares it with the received HASH_VALUE to verify the consistency of the data. Then, the data receiving end queries the ECC_PUB corresponding to the SENDER_ID through the blockchain network, and uses the public key and ECDSA algorithm to verify the DIGITAL_SIGNATURE to confirm the legitimacy and non-tampering of the data. After the verification is correct, the data receiving end uses ECC_PUB to decrypt CIPHERTEXT_AES_KEY and recover AES_KEY. Then, AES_KEY is used to decrypt CIPHERTEXT_DATA to obtain the original power data. Figure 5, which is represented as the power data decryption process. The experiment stores and manages the ECC_PUB of the data sending end and the data receiving end through the blockchain network; the blockchain network assigns a unique device ID or user ID to each public key, sets a validity period, and establishes a mechanism for dynamically updating the public key; when the public key needs to be updated, the data sending end generates a new ECC key pair and submits an update request through the blockchain network, including the new public key, device ID, the original public key version number, and the update certificate signed with the old private key; after verifying the legitimacy of the update request, the blockchain node writes the new public key into the block through the consensus mechanism to complete the update of the public key; it can be obtained from the experimental results that the present invention is innovative and practical in the secure transmission of power data, and has advantages in ensuring the uniqueness and security of public key information.

[0064] Example 3, reference Figure 6 , as an embodiment of the present invention, provides a power data security transmission system based on hybrid encryption, including a public key ciphertext acquisition module, a data transmission verification module, and a decryption and storage module.

[0065] The public key ciphertext acquisition module is used to obtain the AES public key ciphertext and calculate the hash value; the data transmission verification module is used to transmit the data packet to the data recipient through the TLS / SSL protocol and verify the power data ciphertext; the decryption and storage module is used to decrypt the power data ciphertext based on the verification result, and store and manage the public key information of both parties through the blockchain.

[0066] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0067] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.

[0068] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0069] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc. It should be noted that the above embodiments are only used to illustrate the technical solution of the present invention and are not limited. Although the present invention is described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention, which should be included in the scope of the claims of the present invention.

[0070] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for secure transmission of electric power data based on hybrid encryption, characterized in that: include: Get the AES public key ciphertext and calculate the hash value; Transmit the data packet to the data receiver through the TLS / SSL protocol and verify the power data ciphertext; The ciphertext of the power data is decrypted based on the verification results, and the public key information of both parties is stored and managed through the blockchain.

2. The method for secure transmission of electric power data based on hybrid encryption according to claim 1, characterized in that: The obtaining of the AES public key ciphertext includes AES encrypting the power data, ECC encrypting the AES public key, and generating a digital signature; AES encryption of power data includes the data sender encrypting the power data through the symmetric encryption algorithm AES to obtain the ciphertext of the power data; ECC encryption of the AES public key includes encrypting the AES public key by using the asymmetric encryption algorithm ECC to obtain the AES public key ciphertext; Generating a digital signature includes using the data sender's ECC private key and ECDSA algorithm to generate a digital signature for the encrypted AES public key ciphertext, thereby verifying the source authenticity and anti-tampering capabilities of the data.

3. The method for secure transmission of electric power data based on hybrid encryption according to claim 2, characterized in that: The calculation of the hash value includes using the SHA-256 algorithm to calculate the hash value of the power data ciphertext and performing integrity verification on the data.

4. The method for secure transmission of electric power data based on hybrid encryption according to claim 3, characterized in that: The data receiving party transmitted via the TLS / SSL protocol includes a data sender assembling a complete data packet and transmitting the data packet to the data receiving party via the TLS / SSL protocol, wherein the data packet includes a power data ciphertext, an AES public key ciphertext, a data hash value, a digital signature, a sender identity unique identifier, and a timestamp; The data encryption ciphertext includes power data ciphertext and AES public key ciphertext; Verify data integrity and whether it has been tampered with based on data hash values ​​and digital signatures; The sender's unique identity identifier records the identity information of the data sender; The timestamp records the time when the data is sent.

5. The method for secure transmission of electric power data based on hybrid encryption according to claim 4, characterized in that: The verification of the power data ciphertext includes hash value verification and digital signature verification; Hash value verification includes the data receiver recalculates the hash value of the received power data ciphertext and performs consistency verification with the hash value in the data packet. If the verification passes, it means the data is consistent; Digital signature verification includes the data recipient using the sender's identity to query the data sender's ECC public key from the blockchain, using the data sender's ECC public key and ECDSA algorithm to verify the digital signature, confirming that the data comes from a legitimate sender and has not been tampered with.

6. The method for secure transmission of electric power data based on hybrid encryption according to claim 5, characterized in that: Decrypting the power data ciphertext based on the verification result includes performing the decryption process when the hash value verification and the digital signature verification are correct, and terminating the decryption process if the verification fails, and sending an error code to the data sender; The decryption process includes using the queried ECC public key of the data sender to decrypt the AES public key ciphertext through the ECC algorithm to obtain the AES public key, and using the AES public key to decrypt the power data ciphertext through the AES algorithm to obtain the original power data.

7. The method for secure transmission of electric power data based on hybrid encryption according to claim 6, characterized in that: The said storage and management of the public key information of both parties through blockchain includes sending the ECC public key of the power data sending server and the receiving server, encrypting the AES key, and verifying the digital signature, binding the public key with the corresponding device ID or user ID, confirming the uniqueness of the identity, setting a clear validity period for each public key, and establishing a dynamic update mechanism for the public key; The dynamic public key update mechanism includes generating a new ECC key pair when the public key expires or needs to be updated due to security risks, submitting an update request through the blockchain, including the new public key, device ID, version number of the original public key, and an update certificate signed with the old private key. After the blockchain node verifies the legitimacy of the update request, it writes the new public key into the block through the consensus mechanism to generate a new public key version record.

8. A system using the hybrid encryption-based power data secure transmission method according to any one of claims 1 to 7, characterized in that: It includes a public key ciphertext acquisition module, a data transmission verification module, and a decryption and storage module; The public key ciphertext acquisition module is used to obtain the AES public key ciphertext and calculate the hash value; The data transmission verification module is used to transmit the data packet to the data recipient through the TLS / SSL protocol and verify the power data ciphertext; The decryption and storage module is used to decrypt the power data ciphertext based on the verification result, and store and manage the public key information of both parties through the blockchain.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method for secure transmission of electric power data based on hybrid encryption according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for secure transmission of electric power data based on hybrid encryption according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Information storage method and device

    CN110535848A

  • Electric power data privacy communication method based on hybrid encryption algorithm

    CN112511304A

  • Information encryption transmission method and device based on block chain

    CN113806772A

  • Data transmission method, device, system and equipment

    CN114024710A

  • Electric power information security system and method based on block chain

    CN115514568A

Cited By

  • Low-altitude flight data safety synchronization method and system based on distributed storage

    CN121151421A