Security encryption protection method for air cooling control data
By symmetric encryption processing and multi-stage key management of air-cooled control data, the problem of data transmission security threats of substation air-cooled control devices is solved, the security encryption protection of data is realized, and the security and reliability of the system is improved.
Patent Information
- Application Number
- CN202510419813.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-03
AI Technical Summary
The air-cooled control device of the substation faces multiple security threats during data transmission, including data leakage and tampering risks, and traditional single encryption method is difficult to deal with complex security threats. How to build a multi-level and comprehensive security protection system to protect data security while ensuring the availability and flexibility of the system has become a core issue.
The symmetric encryption algorithm is used to encrypt the air-cooled control data, and the encryption key is generated and managed through the key management system, including the master key and the sub-key obtained by the master key, to perform integrity verification, generate verification values, transmit encrypted data and verification values, and the target device uses the encryption key to decrypt and verify data integrity.
Through the multi-level key dispersion mechanism and symmetric encryption algorithm, the secure encryption protection of air-cooled control data is realized, which improves the security and reliability of the system and ensures the integrity and security of the data during transmission.
Smart Images

Figure CN119996068A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data encryption, and in particular relates to a secure encryption protection method for air cooling control data. Background Art
[0002] As a key device of the power system, the secure transmission and processing of the operating data of the substation air-cooling control device is crucial to ensure the stable operation of the power grid. However, in actual applications, the operating environment of the substation is complex and changeable, and data transmission faces multiple security threats. The connection between the internal network of the substation and the external network increases the risk of data leakage, and malicious attackers may steal sensitive data through network vulnerabilities. The air-cooling control device is widely distributed, and the communication between the sub-control modules is susceptible to interference and tampering, making it difficult to ensure data integrity. The transmission security of control instructions is directly related to the accuracy of equipment operation, and once tampered with, serious consequences may occur. The complexity of key management increases the difficulty of system maintenance. How to balance system efficiency while ensuring security has become a major challenge. The traditional single encryption method has been unable to cope with increasingly complex security threats. How to build a multi-level, all-round security protection system to ensure the availability and flexibility of the system while protecting data security has become a core issue that needs to be solved in this field. Summary of the invention
[0003] The purpose of the present invention is to solve the deficiencies of the prior art and to provide a method for securely encrypting and protecting air cooling control data.
[0004] To achieve the above purpose, the technical solution adopted by the present invention is as follows: A method for secure encryption protection of air cooling control data comprises the following steps: Step (1), obtaining operation data collected by the air cooling control device; wherein the operation data at least includes status data and control instruction data; Step (2), encrypting the running data using a symmetric encryption algorithm to generate encrypted data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), performing integrity check on the encrypted data and generating a check value; Step (5), transmitting the encrypted data and the check value to the target device; Step (6), using the encryption key to decrypt the encrypted data through the target device to obtain the decrypted running data, and verifying the integrity of the decrypted running data according to the check value.
[0005] Further, preferably, the method for secure encryption protection of air cooling control data comprises the following steps: Step (1), collecting operating data of the substation air cooling control device through a data acquisition module to obtain raw data including voltage, current and power factor; Step (2), using the national secret security chip to perform symmetrical encryption on the collected operation data to generate encrypted ciphertext data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), calculating the MAC value of the ciphertext data according to the symmetric encryption algorithm, and using the MAC value as the integrity check value; Step (5), uploading the encrypted ciphertext data and MAC value to the centralized control module through the transmission channel; Step (6), obtaining a complete data packet, using the national secret security chip in the centralized control module to decrypt the received ciphertext data to obtain the restored operation data; The decrypted operation data is verified according to the received MAC value to determine the integrity and correctness of the data. If the verification passes, the decrypted voltage, current and power factor data are analyzed by the centralized control module to generate corresponding control instruction data; Step (7), using a symmetric encryption algorithm to encrypt the control instruction data and calculate the MAC value to obtain an encrypted instruction data packet, and sending the encrypted instruction data packet to the sub-control module through a transmission channel to obtain an executable control instruction.
[0006] Furthermore, preferably, in step (2), during the encryption process, the national encryption security chip generates a symmetric key and obtains a fixed key length; The running status data is grouped and cut according to the symmetric key to obtain grouped data blocks; The grouped data blocks are encrypted group by group using a symmetric encryption algorithm to obtain encrypted running data; In step (4), the MAC value is calculated for the encrypted operation data through the national secret security chip, and the MAC value is used as the integrity check value; then the encrypted operation data and the integrity check value are obtained, and a transmission data packet containing the check value is generated; In step (7), the transmission data packet is sent to the sub-control module through the transmission channel; the data transmission is determined to be completed, and if the sub-control module receives the transmission data packet, the encrypted operating data in the data packet is decrypted using the symmetric key to obtain the decrypted operating data; Perform integrity check based on the decrypted running data and the MAC value in the transmission data packet to determine whether the data is consistent; If the integrity check passes, the sub-control module executes the corresponding control instruction according to the decrypted operation data and obtains the execution result.
[0007] Furthermore, preferably, when the national secret security chip generates a symmetric key, the symmetric key is generated through a multi-level key dispersion mechanism, the symmetric key is dispersed from the root key into a business key, and the business key is further dispersed into a terminal key and stored in the national secret security chip; specifically: The business root key is obtained by performing distributed calculations using the SM1 cryptographic algorithm through the master key; Perform a decentralized operation based on the business root key and input parameters to generate an application key; The business data is encrypted by using the application key to obtain the business subkey; Generate a terminal key by combining the service subkey and the terminal identification information; The terminal key is encrypted and stored through the built-in algorithm of the national secret security chip to determine the storage location; Obtain the storage address of the terminal key and record the distributed hierarchical relationship through the key management system; If the terminal initiates a data request, the business subkey is called according to the recorded hierarchical relationship to verify the legitimacy; If it is legal, the service root key is used to decrypt the terminal key to obtain the plaintext key, and the terminal data is encrypted according to the plaintext key to obtain the encryption result.
[0008] Furthermore, preferably, in step (2), a symmetric encryption algorithm is used to encrypt the collected data in groups, and a symmetric key of a fixed length is obtained according to the group encryption result to encrypt each group of data; In step (6), the centralized control module uses the corresponding symmetric key to decrypt the encrypted operation data, obtains the decrypted operation data through the decryption process, and extracts the data content therein; Based on the decrypted running data, the MAC value used for verification is calculated and compared with the received MAC value. If the comparison results are consistent, it is judged that the data integrity verification has passed and it is determined that the running data has not been tampered with.
[0009] Further, preferably, the method for secure encryption protection of air cooling control data further comprises the following steps: Generate a public and private key pair of asymmetric encryption algorithm in the centralized control module through the national secret security chip to obtain the public key and private key; The private key is stored in the national security chip of the centralized control module to ensure that the private key is protected by hardware; Obtain the public key and transmit it to the sub-control module, determine whether the sub-control module has received the public key, store the received public key through the national secret security chip of the sub-control module, and obtain the deployment of the public key in the sub-control module; Use the centralized control module to initiate the identity authentication process and generate identity authentication data; Encrypt the identity authentication data using a public key to obtain the encrypted identity authentication data; Obtain the encrypted identity authentication data and send it to the centralized control module to determine that the data transmission is complete; Decrypt the received encrypted data according to the private key to obtain the decrypted identity authentication data; The legitimacy of the sub-control module's identity is determined by comparing the decrypted data with the initial identity authentication data.
[0010] Further, preferably, the centralized control module generates identity authentication data, and uses a private key to sign the authentication data to obtain a signature result; The signature result is sent to the sub-control module through the transmission channel; The sub-control module receives the signature result; The sub-control module obtains the public key of the centralized control module and verifies the legitimacy of the signature result through the public key; if the verification is successful, the sub-control module uses the public key to encrypt the identity authentication data to obtain the encrypted authentication data; The encrypted authentication data is returned to the centralized control module through the transmission channel; The centralized control module receives the encrypted data, and the centralized control module uses the private key to decrypt the encrypted data to obtain the decrypted identity authentication data; The decrypted identity authentication data is compared with the original identity authentication data to determine whether the comparison results are consistent; if the comparison is consistent, the centralized control module generates an authentication pass message and sends it to the sub-control module through the transmission channel; The sub-control module receives the authentication pass message and obtains the interaction permission.
[0011] Further, preferably, the identity authentication data is generated by using a random number generation algorithm to obtain unique identity authentication data; The centralized control module encrypts the identity authentication data through the public key of the sub-control module to obtain the encrypted identity authentication data; The centralized control module sends the encrypted identity authentication data to the sub-control module through the communication channel; The sub-control module receives the encrypted identity authentication data, verifies the data integrity using its own public key and obtains the encrypted content; The sub-control module processes the encrypted identity authentication data through a symmetric encryption algorithm to generate returned encrypted identity authentication data; The sub-control module sends the returned encrypted identity authentication data and transmits it to the centralized control module through the communication channel; The centralized control module receives the returned encrypted identity authentication data, and uses the private key to decrypt the encrypted identity authentication data to obtain the decrypted identity authentication data; The centralized control module compares the decrypted authentication data with the original authentication data and determines the consistency through a byte matching algorithm. If the consistency is determined to be good, the centralized control module generates an authentication pass message and sends it to the sub-control module through an encrypted channel.
[0012] Furthermore, preferably, the identity authentication data is generated by a national secret security chip, and a unique authentication identifier is obtained by using a random number generation algorithm; The centralized control module obtains the public key of the sub-control module and encrypts the identity authentication data using an asymmetric encryption algorithm to obtain ciphertext data; The centralized control module sends the encrypted data through the transmission channel, and the sub-control module receives the encrypted data and stores it in the local buffer area; The sub-control module extracts the ciphertext data encrypted by the public key through the built-in national secret security chip, and uses the corresponding private key to decrypt and obtain the original identity authentication data; The sub-control module transmits the decrypted authentication data back through the encrypted channel, and the centralized control module receives the returned data and stores it in the temporary verification area; The centralized control module verifies the received return data and the initially generated identity authentication data through a comparison algorithm to determine whether the two are consistent; If the comparison results are consistent, the centralized control module generates an authentication pass message using the built-in key, and uses the sub-control module public key to encrypt the encrypted authentication message; The centralized control module sends an encrypted authentication message through the transmission channel, and the sub-control module receives the encrypted authentication message and decrypts it through the private key to obtain a plain text authentication pass message; The sub-control module confirms the legitimacy of the identity by parsing the plaintext authentication message, obtains the business interaction authority and enters the normal business interaction state.
[0013] Furthermore, preferably, in step (7), corresponding control instruction data is generated according to the operation data; the control instruction data is encrypted by a block encryption method using a symmetric encryption algorithm to obtain encrypted control instruction data; Obtain the encrypted control instruction data and use the SHA-256 algorithm to calculate the integrity check value; According to the integrity check value, the check value is attached to the end of the encrypted control instruction data to form a complete data packet, and then the encrypted control instruction data with the check value is sent to the sub-control module through the transmission channel; Obtain the data received by the sub-control module, use the same SHA-256 algorithm and key to calculate the check value, and determine whether it is consistent with the received check value; If the check values are consistent, it is determined that the data has not been tampered with, and available control instruction data is obtained for executing the adjustment operation of the cooling system.
[0014] In the present invention, the terminal is a terminal device for the management personnel to finally display and receive data.
[0015] The present invention performs integrity check on encrypted data to obtain encrypted data; uses a preset integrity algorithm and subkey to calculate a check value of a fixed length for the encrypted data; appends the check value to the encrypted data to form a data packet to be transmitted, decrypts the encrypted data using an encryption key through a target device, and obtains the same subkey as that used for encryption from a key management system; decrypts the encrypted data using the subkey according to a decryption algorithm corresponding to that used for encryption to obtain decrypted running data; calculates a check result of the decrypted running data based on the check value and the same integrity algorithm and compares it with the received check value.
[0016] The present invention obtains operating data collected by an air-cooling control device, obtains status data from a centralized control module of the air-cooling control device; obtains control instruction data from a sub-control module; pre-processes the status data and the control instruction data to generate operating data in a unified format, transmits encrypted data and a check value to a target device, and encapsulates the encrypted data and the check value into a transmission data packet through a preset communication channel; uses a symmetric encryption system to perform secondary encryption on the transmission data packet to generate a secondary encrypted data packet; and transmits the secondary encrypted data packet to the target device.
[0017] Compared with the prior art, the present invention has the following beneficial effects: The present invention adopts a multi-level key dispersion mechanism to generate symmetric keys, protects key security through a national secret security chip, uses a symmetric encryption algorithm to encrypt operation data, uses an asymmetric encryption algorithm to generate a public-private key pair, realizes identity authentication of the sub-control module, and ensures the security of the command by encrypting and transmitting control instruction data. At the same time, through the comprehensive use of multiple encryption technologies and security mechanisms, the safe collection, transmission and processing of the operation data of the substation air cooling control device can be realized, which effectively improves the safety and reliability of the system and provides a strong guarantee for the safe and stable operation of the substation equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 This is a flow chart of the method for secure encryption protection of air cooling control data of the present invention; DETAILED DESCRIPTION
[0019] The present invention is further described in detail below in conjunction with embodiments.
[0020] Those skilled in the art will appreciate that the following examples are only used to illustrate the present invention and should not be considered to limit the scope of the present invention. If no specific techniques or conditions are specified in the examples, the techniques or conditions described in the literature in the art or the product specifications are used. If the manufacturer of the materials or equipment used is not specified, they are all conventional products that can be purchased. Example 1
[0021] A method for secure encryption protection of air cooling control data comprises the following steps: Step (1), obtaining operation data collected by the air cooling control device; wherein the operation data at least includes status data and control instruction data; Step (2), encrypting the running data using a symmetric encryption algorithm to generate encrypted data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), performing integrity check on the encrypted data and generating a check value; Step (5), transmitting the encrypted data and the check value to the target device; Step (6), using the encryption key to decrypt the encrypted data through the target device to obtain the decrypted running data, and verifying the integrity of the decrypted running data according to the check value. Example 2
[0022] A method for secure encryption protection of air cooling control data comprises the following steps: Step (1), collecting operating data of the substation air cooling control device through a data acquisition module to obtain raw data including voltage, current and power factor; Step (2), using the national secret security chip to perform symmetrical encryption on the collected operation data to generate encrypted ciphertext data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), calculating the MAC value of the ciphertext data according to the symmetric encryption algorithm, and using the MAC value as the integrity check value; Step (5), uploading the encrypted ciphertext data and MAC value to the centralized control module through the transmission channel; Step (6), obtaining a complete data packet, using the national secret security chip in the centralized control module to decrypt the received ciphertext data to obtain the restored operation data; The decrypted operation data is verified according to the received MAC value to determine the integrity and correctness of the data. If the verification passes, the decrypted voltage, current and power factor data are analyzed by the centralized control module to generate corresponding control instruction data; Step (7), using a symmetric encryption algorithm to encrypt the control instruction data and calculate the MAC value to obtain an encrypted instruction data packet, and sending the encrypted instruction data packet to the sub-control module through a transmission channel to obtain an executable control instruction.
[0023] Specifically: Collect the operating data of the substation air cooling control device and obtain the original data including voltage 220V, current 50A and power factor 0.9; The collected operation data is symmetrically encrypted using the national security chip SM4 algorithm to generate encrypted ciphertext data with a key length of 128 bits; Generate and manage encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by dispersing the master key; Calculate the MAC value of the ciphertext data according to the symmetric encryption algorithm HMAC-SM3, determine the integrity check information of the data, and generate a 32-byte check code; Upload the encrypted ciphertext data and MAC value to the centralized control module through the transmission channel; Obtain a complete data packet, the format of which includes ciphertext data and checksum, and use the SM4 algorithm of the national secret security chip in the centralized control module to decrypt the received ciphertext data to obtain the restored operating data, including voltage 220V, current 50A and power factor 0.9; The decrypted operation data is verified according to the received MAC value to determine the integrity and correctness of the data. If the check code matches, the verification is passed. If the verification passes, the decrypted voltage, current and power factor data are analyzed by the centralized control module to generate corresponding control instruction data. The control instruction includes adjusting the voltage to 230V and the current to 55A. The symmetric encryption algorithm SM4 is used to encrypt the control instruction data and calculate the MAC value to obtain the encrypted instruction data packet. The key length is 128 bits and the check code is 32 bytes. The encrypted instruction data packet is sent to the sub-control module through the transmission channel to obtain the executable control instruction. After receiving the sub-control module, the voltage and current adjustment operations are performed. Example 3
[0024] A method for secure encryption protection of air cooling control data comprises the following steps: Step (1), collecting operating data of the substation air cooling control device through a data acquisition module to obtain raw data including voltage, current and power factor; Step (2), using the national secret security chip to perform symmetrical encryption on the collected operation data to generate encrypted ciphertext data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), calculating the MAC value of the ciphertext data according to the symmetric encryption algorithm, and using the MAC value as the integrity check value; Step (5), uploading the encrypted ciphertext data and MAC value to the centralized control module through the transmission channel; Step (6), obtaining a complete data packet, using the national secret security chip in the centralized control module to decrypt the received ciphertext data to obtain the restored operation data; The decrypted operation data is verified according to the received MAC value to determine the integrity and correctness of the data. If the verification passes, the decrypted voltage, current and power factor data are analyzed by the centralized control module to generate corresponding control instruction data; Step (7), using a symmetric encryption algorithm to encrypt the control instruction data and calculate the MAC value to obtain an encrypted instruction data packet, and sending the encrypted instruction data packet to the sub-control module through a transmission channel to obtain an executable control instruction.
[0025] In step (2), during the encryption process, the national security chip generates a symmetric key and obtains a fixed key length; The running status data is grouped and cut according to the symmetric key to obtain grouped data blocks; The grouped data blocks are encrypted group by group using a symmetric encryption algorithm to obtain encrypted running data; In step (4), the MAC value is calculated for the encrypted operation data through the national secret security chip, and the MAC value is used as the integrity check value; then the encrypted operation data and the integrity check value are obtained, and a transmission data packet containing the check value is generated; In step (7), the transmission data packet is sent to the sub-control module through the transmission channel; the data transmission is determined to be completed, and if the sub-control module receives the transmission data packet, the encrypted operating data in the data packet is decrypted using the symmetric key to obtain the decrypted operating data; Perform integrity check based on the decrypted running data and the MAC value in the transmission data packet to determine whether the data is consistent; If the integrity check passes, the sub-control module executes the corresponding control instruction according to the decrypted operation data and obtains the execution result.
[0026] Specifically: The national secret security chip in the centralized control module generates a symmetric key, and the AES-256 algorithm is used to generate a 256-bit key. The running status data is grouped and cut according to the symmetric key, and the data is grouped into 128-bit groups to obtain grouped data blocks; The AES-256 algorithm is used to encrypt the grouped data blocks one by one, and the ECB mode is used to encrypt each group of data to obtain the encrypted running data; The MAC value of the encrypted running data is calculated through the national secret security chip, and the HMAC-SHA256 algorithm is used to perform hash operation on the encrypted data to obtain a 32-byte integrity check value; Obtain the encrypted operating data and integrity check value, concatenate the encrypted data and the check value in a fixed format, generate a transmission data packet containing the check value, send the transmission data packet to the sub-control module through the transmission channel, and encrypt and transmit the transmission data packet using the TLS1.3 protocol; Determine that the data transmission is completed. If the sub-control module receives the transmission data packet, it uses the symmetric key to decrypt the encrypted operating data in the data packet, and uses the AES-256 algorithm to decrypt the encrypted data to obtain the decrypted operating data; Perform integrity check based on the decrypted running data and the MAC value in the transmission data packet. Use the HMAC-SHA256 algorithm to calculate the check value of the decrypted data and compare it with the check value in the transmission packet to determine whether the data is consistent. If the integrity check passes, the sub-control module executes the corresponding control instructions according to the decrypted operation data, parses the control parameters in the data packet and executes the control logic to obtain the execution result. Example 4
[0027] The difference between Example 4 and Example 3 is that: When the national secret security chip generates a symmetric key, it generates the symmetric key through a multi-level key dispersion mechanism. The symmetric key is dispersed from the root key to the business key, and the business key is further dispersed into the terminal key and stored in the national secret security chip; specifically: The business root key is obtained by performing distributed calculations using the SM1 cryptographic algorithm through the master key; Perform a decentralized operation based on the business root key and input parameters to generate an application key; The business data is encrypted by using the application key to obtain the business subkey; Generate a terminal key by combining the service subkey and the terminal identification information; The terminal key is encrypted and stored through the built-in algorithm of the national secret security chip to determine the storage location; Obtain the storage address of the terminal key and record the distributed hierarchical relationship through the key management system; If the terminal initiates a data request, the business subkey is called according to the recorded hierarchical relationship to verify the legitimacy; If it is legal, the service root key is used to decrypt the terminal key to obtain the plaintext key, and the terminal data is encrypted according to the plaintext key to obtain the encryption result.
[0028] The rest are the same.
[0029] Specifically: The master key is decentralized through the SM1 cryptographic algorithm, using a 128-bit key length and a specific dispersion factor to generate the business root key; The business root key is combined with input parameters, such as business identifier and timestamp, to perform a decentralized operation and generate an application key; The application key is used to encrypt the business data, and the SM4 algorithm is used for group encryption to obtain the business subkey; The service subkey and the terminal identification information are combined and calculated to generate the terminal key through a hash function; The terminal key is encrypted and stored using the AES algorithm built into the national security chip. The storage location is determined to be the key storage area of the chip. The key management system obtains the storage address of the terminal key and records the distributed hierarchical relationship, including the association information of the master key, business root key, business subkey and terminal key. If the terminal initiates a data request, the business subkey is called for verification based on the recorded hierarchical relationship, and the hash value is calculated using the SM3 algorithm to determine the legitimacy; If it is legal, the service root key is used to decrypt the terminal key to obtain the plaintext key. The plaintext key performs encryption operations on the terminal data and uses the SM2 algorithm for asymmetric encryption to obtain the encryption result. Example 5
[0030] The difference between Example 5 and Example 2 is that: In step (2), a symmetric encryption algorithm is used to encrypt the collected data in groups, and a symmetric key of a fixed length is obtained according to the group encryption result to encrypt each group of data; In step (6), the centralized control module uses the corresponding symmetric key to decrypt the encrypted operation data, obtains the decrypted operation data through the decryption process, and extracts the data content therein; According to the decrypted running data, the MAC value used for verification is calculated and compared with the received MAC value. If the comparison results are consistent, it is judged that the data integrity verification has passed and it is determined that the running data has not been tampered with; The rest are the same.
[0031] Specifically: Collect the operating status data such as voltage, current, active power and reactive power, and use the national secret symmetric encryption algorithm SM4 to encrypt the collected data in groups, with each 128 bits being encrypted as a group; According to the block encryption result, a fixed-length symmetric key is obtained, the key length is 256 bits, each group of data is encrypted to generate an encrypted 128-bit ciphertext, and the encrypted running data is obtained through encryption. The HMAC-SHA256 algorithm is used to calculate the corresponding MAC value to ensure data integrity. Use TLS secure transmission channel to transmit encrypted operation data and calculated MAC value to the centralized control module; During the transmission process, the AES-256 encryption algorithm is used to protect the transmission channel. After obtaining the transmitted data, the centralized control module uses the corresponding symmetric key to decrypt the encrypted operation data, and uses the SM4 algorithm to decrypt the 128-bit ciphertext group by group to restore it to the original data. Through the decryption process, the decrypted operation data is obtained and the data content is extracted, including the specific values of voltage and current; According to the decrypted operating data, the HMAC-SHA256 algorithm is used to recalculate the MAC value used for verification and compare it with the received MAC value. If the comparison results are consistent, the data integrity verification is judged to be passed and it is determined that the operating data has not been tampered with; then the current transformer operating status information, including power factor and operating time, is obtained, and subsequent processing is performed based on this information to generate control instructions or risk warnings. Example 6
[0032] The difference between Example 6 and Example 4 is that it further includes the following steps: Generate a public and private key pair of asymmetric encryption algorithm in the centralized control module through the national secret security chip to obtain the public key and private key; The private key is stored in the national secret security chip of the centralized control module to ensure that the private key is protected by hardware; the public key is obtained and transmitted to the sub-control module, and it is determined that the sub-control module receives the public key, and the received public key is stored in the national secret security chip of the sub-control module to obtain the deployment of the public key in the sub-control module; Use the centralized control module to initiate the identity authentication process and generate identity authentication data; Encrypt the identity authentication data by using the public key to obtain the encrypted authentication data; Obtain the encrypted authentication data and send it to the centralized control module to determine that the data transmission is complete; Decrypt the received encrypted data according to the private key to obtain the decrypted identity authentication data; The legitimacy of the sub-control module's identity is determined by comparing the decrypted data with the initial identity authentication data.
[0033] The rest are the same.
[0034] Specifically: the following steps are also included: Use the RSA-2048 algorithm to generate public and private keys. The length of the public key is 2048 bits, and the length of the private key is 2048 bits. The private key is stored in the national security chip of the centralized control module, and the PKCS#11 standard interface is used to implement hardware protection of the private key to ensure that the private key does not leave the host encryption server; Obtain the public key and transmit it to the sub-control module, encrypt and transmit the public key through the TLS 1.3 protocol, determine whether the sub-control module returns a confirmation signal after receiving the public key, store the received public key through the national secret security chip of the sub-control module, and use the storage area of the national secret security chip to save the public key to ensure the integrity and security of the public key; The centralized control module is used to initiate the identity authentication process, generate a 128-bit random number as the identity authentication data, ensure the uniqueness and unpredictability of the data, encrypt the identity authentication data through the public key, and use the RSA-2048 algorithm to encrypt the data to generate encrypted identity authentication data; Obtain the encrypted authentication data and send it to the centralized control module, transmit the encrypted data through the MQTT protocol, determine the completion of data transmission and record the transmission log; Decrypt the received encrypted data according to the private key, use the RSA-2048 algorithm to decrypt the data, and obtain the decrypted identity authentication data; The decrypted data is compared with the initial identity authentication data, and the data consistency is verified by a byte-by-byte comparison method. After the legitimacy of the sub-control module identity is determined, the authentication result is recorded. Example 7
[0035] The difference between Example 7 and Example 6 is that: The centralized control module generates identity authentication data and uses a private key to sign the authentication data to obtain a signature result; The signature result is sent to the sub-control module through the transmission channel; The sub-control module receives the signature result; The sub-control module obtains the public key of the centralized control module and verifies the legitimacy of the signature result through the public key; if the verification is successful, the sub-control module uses the public key to encrypt the identity authentication data to obtain the encrypted authentication data; The encrypted authentication data is returned to the centralized control module through the transmission channel; The centralized control module receives the encrypted data, and the centralized control module uses the private key to decrypt the encrypted data to obtain the decrypted identity authentication data; The decrypted identity authentication data is compared with the original identity authentication data to determine whether the comparison results are consistent; if the comparison is consistent, the centralized control module generates an authentication pass message and sends it to the sub-control module through the transmission channel; the sub-control module receives the authentication pass message and obtains the interaction permission.
[0036] The rest are the same.
[0037] Specifically: Generate identity authentication data containing the random number 12345, use the national secret SM2 algorithm and private key to sign the authentication data, and obtain the signature result; The signature result is transmitted to the sub-control module via TCP / IP protocol; The sub-control module receives the signature result and stores it in the cache; The sub-control module obtains the public key of the centralized control module from the key management system, verifies the legitimacy of the signature result through the public key and SM2 algorithm, and confirms whether the signature is generated by the centralized control module; if the verification is successful, the sub-control module uses the public key and SM2 algorithm to encrypt the identity authentication data, and the encrypted identity authentication data is 256 bytes long; The encrypted authentication data is returned to the centralized control module via TCP / IP protocol; The centralized control module receives the encrypted data and stores it in the memory. The centralized control module uses the private key and the SM2 algorithm to decrypt the encrypted data and obtain the decrypted identity authentication data 12345; The decrypted authentication data is compared with the original authentication data to determine whether the two are completely consistent; if the comparison is consistent, the centralized control module generates an authentication pass message containing an "authentication successful" status code and sends it to the sub-control module via the TCP / IP protocol; the sub-control module receives the authentication pass message, parses the status code and obtains subsequent business interaction permissions to complete the authentication process. Example 8
[0038] The difference between Example 8 and Example 7 is that: Generate identity authentication data, and use a random number generation algorithm to obtain unique identity authentication data; The centralized control module encrypts the identity authentication data through the public key of the sub-control module to obtain the encrypted identity authentication data; The centralized control module sends the encrypted identity authentication data to the sub-control module through the communication channel; The sub-control module receives the encrypted identity authentication data, verifies the data integrity using its own public key and obtains the encrypted content; The sub-control module processes the encrypted identity authentication data through a symmetric encryption algorithm to generate returned encrypted identity authentication data; The sub-control module sends the returned encrypted identity authentication data and transmits it to the centralized control module through the communication channel; The centralized control module receives the returned encrypted identity authentication data, and uses the private key to decrypt the encrypted identity authentication data to obtain the decrypted identity authentication data; The centralized control module compares the decrypted authentication data with the original authentication data and determines the consistency through a byte matching algorithm. If the consistency is determined to be good, the centralized control module generates an authentication pass message and sends it to the sub-control module through an encrypted channel.
[0039] The rest are the same.
[0040] Specifically: The centralized control module uses a random number generation algorithm to generate a 128-bit identity authentication data, for example, using the AES algorithm to generate a random number "3f7a9b2c4d5e6f78"; The centralized control module uses the public key of the sub-control module and the RSA-2048 algorithm to encrypt the identity authentication data to obtain the encrypted identity authentication data "a1b2c3d4e5f6g7h8"; The centralized control module transmits the encrypted authentication data to the sub-control module via TCP / IP protocol, with a data packet size of 256 bytes; The sub-control module receives the encrypted authentication data, verifies the data integrity using its own public key through the RSA-2048 algorithm, and parses the encrypted content "a1b2c3d4e5f6g7h8"; The sub-control module performs hash calculation on the encrypted authentication data using the SHA-256 algorithm to generate the returned encrypted authentication data "x9y8z7w6v5u4t3s2"; The sub-control module transmits the returned encrypted identity authentication data to the centralized control module via the UDP protocol, and the data packet size is 128 bytes; The centralized control module receives the returned encrypted authentication data, and uses its own private key to decrypt the data using the RSA-2048 algorithm to obtain the decrypted authentication data "3f7a9b2c4d5e6f78"; The centralized control module compares the decrypted authentication data with the original authentication data through a byte matching algorithm to determine whether the two are completely consistent; if the consistency is determined, the centralized control module generates an authentication pass message "success", encrypts it with the AES-256 algorithm, and sends it to the sub-control module through the SSL channel. Example 9
[0041] The difference between Example 9 and Example 8 is that: Generate identity authentication data through the national secret security chip, and use the random number generation algorithm to obtain a unique authentication identifier; The centralized control module obtains the public key of the sub-control module and encrypts the identity authentication data using an asymmetric encryption algorithm to obtain ciphertext data; The centralized control module sends the encrypted data through the transmission channel, and the sub-control module receives the encrypted data and stores it in the local buffer area; The sub-control module extracts the ciphertext data encrypted by the public key through the built-in national secret security chip, and uses the corresponding private key to decrypt and obtain the original identity authentication data; The sub-control module transmits the decrypted authentication data back through the encrypted channel, and the centralized control module receives the returned data and stores it in the temporary verification area; The centralized control module verifies the received return data and the initially generated identity authentication data through a comparison algorithm to determine whether the two are consistent; If the comparison results are consistent, the centralized control module generates an authentication pass message using the built-in key, and uses the sub-control module public key to encrypt the encrypted authentication message; The centralized control module sends an encrypted authentication message through the transmission channel, and the sub-control module receives the encrypted authentication message and decrypts it through the private key to obtain a plain text authentication pass message; The sub-control module confirms the legitimacy of the identity by parsing the plaintext authentication message, obtains the business interaction authority and enters the normal business interaction state.
[0042] The rest are the same.
[0043] Specifically: The centralized control module generates identity authentication data through the built-in national secret security chip and uses a random number generation algorithm to generate a unique authentication identifier with a length of 128 bits; The centralized control module obtains the public key of the sub-control module, which is generated based on the RSA2048 algorithm, and encrypts the identity authentication data through an asymmetric encryption algorithm to generate ciphertext data; The centralized control module sends the encrypted data through the transmission channel, and the sub-control module receives the encrypted data and stores it in the local buffer area; The sub-control module extracts the ciphertext data encrypted by the public key through the built-in national secret security chip, decrypts it using the corresponding RSA2048 private key, and restores the original identity authentication data; The sub-control module transmits the decrypted authentication data back through the encrypted channel, and the centralized control module receives the returned data and stores it in the temporary verification area; The centralized control module generates a hash value of the initial authentication data using the SHA-256 algorithm and compares it with the hash value of the returned data to determine whether the two are consistent; If the comparison results are consistent, the centralized control module generates an authentication pass message using the built-in AES256 algorithm and uses the sub-control module public key encryption to generate an encrypted authentication message; The centralized control module sends an encrypted authentication message through the transmission channel, and the sub-control module receives the encrypted authentication message and decrypts it through the RSA2048 private key to obtain a plain text authentication pass message; The sub-control module confirms the legitimacy of the identity by parsing the plaintext authentication message, obtains the business interaction authority and enters the normal business interaction state. Example 10
[0044] The difference between Example 10 and Example 9 is that: Obtain the decrypted operation data and confirm the data content including voltage 220V, current 10A, active power 5kW, reactive power 3kVar, power factor 0.8, electric energy 50kWh, and operation time 8 hours; Generate corresponding control instruction data according to the operation data, including instructions for adjusting the cooling fan speed to 1500rpm and starting the standby cooling module; use the AES symmetric encryption algorithm, use a 256-bit key to encrypt the control instruction data, and divide the control instruction data into 128-bit data blocks through group encryption, encrypt them block by block, and obtain the encrypted control instruction data; Obtain the encrypted control instruction data and use the SHA-256 algorithm to calculate the integrity check value; According to the integrity check value, the check value is attached to the end of the encrypted control instruction data to form a complete data packet, and then the encrypted control instruction data with the check value is sent to the sub-control module through the transmission channel; Obtain the data received by the sub-control module, use the same SHA-256 algorithm and key to calculate the check value, and determine whether it is consistent with the received check value; If the check values are consistent, it is determined that the data has not been tampered with, and available control instruction data is obtained for executing the adjustment operation of the cooling system.
[0045] The rest are the same.
[0046] Specifically: The centralized control module uses the SM4 symmetric encryption algorithm and a 128-bit key to encrypt the control instruction data including the "start fan" instruction to generate encrypted control instruction data; Calculate the MAC value of the encrypted data through the HMAC-SM3 algorithm to generate a 32-byte checksum; transmit the encrypted control instruction data and MAC value to the sub-control module through the TCP / IP protocol, and record the transmission success status; After receiving the data, the sub-control module checks whether the data packet length is 160 bytes to confirm the integrity of the data packet; if the data packet is complete, the sub-control module uses the same 1 2 The 8-bit SM4 key decrypts the encrypted control instruction data to obtain the original instruction "start the fan"; the received MAC value is extracted according to the decrypted data to obtain the information to be verified; the sub-control module uses the HMAC-SM3 algorithm to recalculate the MAC value of the decrypted instruction data to generate a new 32-byte verification code; The recalculated MAC value is compared byte by byte with the received MAC value. If they are consistent, it is confirmed that the instruction data has not been tampered with and the instruction is determined to be legal. The sub-control module executes the fan start operation according to the legal instruction "start the fan" to complete the instruction processing.
[0047] The above shows and describes the basic principles, main features and advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments, and the above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.
Claims
1. A method for secure encryption protection of air cooling control data, characterized in that: The steps include: Step (1), obtaining operation data collected by the air cooling control device; wherein the operation data at least includes status data and control instruction data; Step (2), encrypting the running data using a symmetric encryption algorithm to generate encrypted data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), performing integrity check on the encrypted data and generating a check value; Step (5), transmitting the encrypted data and the check value to the target device; Step (6), using the encryption key to decrypt the encrypted data through the target device to obtain the decrypted running data, and verifying the integrity of the decrypted running data according to the check value.
2. The method for secure encryption protection of air cooling control data according to claim 1, characterized in that: The steps include: Step (1), collecting operating data of the substation air cooling control device through a data acquisition module to obtain raw data including voltage, current and power factor; Step (2), using the national secret security chip to perform symmetrical encryption on the collected operation data to generate encrypted ciphertext data; Step (3), generating and managing encryption keys through a key management system; wherein the encryption keys include a master key and subkeys obtained by distributing the master key; Step (4), calculating the MAC value of the ciphertext data according to the symmetric encryption algorithm, and using the MAC value as the integrity check value; Step (5), uploading the encrypted ciphertext data and MAC value to the centralized control module through the transmission channel; Step (6), obtaining a complete data packet, using the national secret security chip in the centralized control module to decrypt the received ciphertext data to obtain the restored operation data; The decrypted operation data is verified according to the received MAC value to determine the integrity and correctness of the data. If the verification passes, the decrypted voltage, current and power factor data are analyzed by the centralized control module to generate corresponding control instruction data; Step (7), using a symmetric encryption algorithm to encrypt the control instruction data and calculate the MAC value to obtain an encrypted instruction data packet, and sending the encrypted instruction data packet to the sub-control module through a transmission channel to obtain an executable control instruction.
3. The method for secure encryption protection of air cooling control data according to claim 2, characterized in that: In step (2), during the encryption process, the national security chip generates a symmetric key and obtains a fixed key length; The running status data is grouped and cut according to the symmetric key to obtain grouped data blocks; The grouped data blocks are encrypted group by group using a symmetric encryption algorithm to obtain encrypted running data; In step (4), the MAC value is calculated for the encrypted operation data through the national secret security chip, and the MAC value is used as the integrity check value; then the encrypted operation data and the integrity check value are obtained, and a transmission data packet containing the check value is generated; In step (7), the transmission data packet is sent to the sub-control module through the transmission channel; Determine that the data transmission is completed, and if the sub-control module receives the transmission data packet, use the symmetric key to decrypt the encrypted operating data in the data packet to obtain the decrypted operating data; Perform integrity check based on the decrypted running data and the MAC value in the transmission data packet to determine whether the data is consistent; If the integrity check passes, the sub-control module executes the corresponding control instruction according to the decrypted operation data and obtains the execution result.
4. The method for secure encryption protection of air cooling control data according to claim 3, characterized in that: When the national secret security chip generates a symmetric key, it generates the symmetric key through a multi-level key dispersion mechanism. The symmetric key is dispersed from the root key to the business key, and the business key is further dispersed into the terminal key and stored in the national secret security chip; specifically: The business root key is obtained by performing distributed calculations using the SM1 cryptographic algorithm through the master key; Perform a decentralized operation based on the business root key and input parameters to generate an application key; The business data is encrypted by using the application key to obtain the business subkey; Generate a terminal key by combining the service subkey and the terminal identification information; The terminal key is encrypted and stored through the built-in algorithm of the national secret security chip to determine the storage location; Obtain the storage address of the terminal key and record the distributed hierarchical relationship through the key management system; If the terminal initiates a data request, the business subkey is called according to the recorded hierarchical relationship to verify the legitimacy; If it is legal, the service root key is used to decrypt the terminal key to obtain the plaintext key, and the terminal data is encrypted according to the plaintext key to obtain the encryption result.
5. The method for secure encryption protection of air cooling control data according to claim 2, characterized in that: In step (2), a symmetric encryption algorithm is used to encrypt the collected data in groups, and a symmetric key of a fixed length is obtained according to the group encryption result to encrypt each group of data; In step (6), the centralized control module uses the corresponding symmetric key to decrypt the encrypted operation data, obtains the decrypted operation data through the decryption process, and extracts the data content therein; Based on the decrypted running data, the MAC value used for verification is calculated and compared with the received MAC value. If the comparison results are consistent, it is judged that the data integrity verification has passed and it is determined that the running data has not been tampered with.
6. The method for secure encryption protection of air cooling control data according to any one of claims 2 to 5, characterized in that: The following steps are also included: Generate a public and private key pair of asymmetric encryption algorithm in the centralized control module through the national secret security chip to obtain the public key and private key; The private key is stored in the national security chip of the centralized control module to ensure that the private key is protected by hardware; Obtain the public key and transmit it to the sub-control module, determine whether the sub-control module has received the public key, store the received public key through the national secret security chip of the sub-control module, and obtain the deployment of the public key in the sub-control module; Use the centralized control module to initiate the identity authentication process and generate identity authentication data; Encrypt the identity authentication data using a public key to obtain the encrypted identity authentication data; Obtain the encrypted identity authentication data and send it to the centralized control module to determine that the data transmission is complete; Decrypt the received encrypted data according to the private key to obtain the decrypted identity authentication data; The legitimacy of the sub-control module's identity is determined by comparing the decrypted data with the initial identity authentication data.
7. The method for secure encryption protection of air cooling control data according to claim 6, characterized in that: The centralized control module generates identity authentication data and uses a private key to sign the authentication data to obtain a signature result; The signature result is sent to the sub-control module through the transmission channel; The sub-control module receives the signature result; The sub-control module obtains the public key of the centralized control module and verifies the legitimacy of the signature result through the public key; If the verification is successful, the sub-control module uses the public key to encrypt the identity authentication data to obtain the encrypted authentication data; The encrypted authentication data is returned to the centralized control module through the transmission channel; The centralized control module receives the encrypted data, and the centralized control module uses the private key to decrypt the encrypted data to obtain the decrypted identity authentication data; The decrypted identity authentication data is compared with the original identity authentication data to determine whether the comparison results are consistent; if the comparison is consistent, the centralized control module generates an authentication pass message and sends it to the sub-control module through the transmission channel; The sub-control module receives the authentication pass message and obtains the interaction permission.
8. The method for secure encryption protection of air cooling control data according to claim 7, characterized in that: Generate identity authentication data, and use a random number generation algorithm to obtain unique identity authentication data; The centralized control module encrypts the identity authentication data through the public key of the sub-control module to obtain the encrypted identity authentication data; The centralized control module sends the encrypted identity authentication data to the sub-control module through the communication channel; The sub-control module receives the encrypted identity authentication data, verifies the data integrity using its own public key and obtains the encrypted content; The sub-control module processes the encrypted identity authentication data through a symmetric encryption algorithm to generate returned encrypted identity authentication data; The sub-control module sends the returned encrypted identity authentication data and transmits it to the centralized control module through the communication channel; The centralized control module receives the returned encrypted identity authentication data, and uses the private key to decrypt the encrypted identity authentication data to obtain the decrypted identity authentication data; The centralized control module compares the decrypted authentication data with the original authentication data and determines the consistency through a byte matching algorithm. If the consistency is determined to be good, the centralized control module generates an authentication pass message and sends it to the sub-control module through an encrypted channel.
9. The method for secure encryption protection of air cooling control data according to claim 8, characterized in that: Generate identity authentication data through the national secret security chip, and use the random number generation algorithm to obtain a unique authentication identifier; The centralized control module obtains the public key of the sub-control module and encrypts the identity authentication data using an asymmetric encryption algorithm to obtain ciphertext data; The centralized control module sends the encrypted data through the transmission channel, and the sub-control module receives the encrypted data and stores it in the local buffer area; The sub-control module extracts the ciphertext data encrypted by the public key through the built-in national secret security chip, and uses the corresponding private key to decrypt and obtain the original identity authentication data; The sub-control module transmits the decrypted authentication data back through the encrypted channel, and the centralized control module receives the returned data and stores it in the temporary verification area; The centralized control module verifies the received return data and the initially generated identity authentication data through a comparison algorithm to determine whether the two are consistent; If the comparison results are consistent, the centralized control module generates an authentication pass message using the built-in key, and uses the sub-control module public key to encrypt the encrypted authentication message; The centralized control module sends an encrypted authentication message through the transmission channel, and the sub-control module receives the encrypted authentication message and decrypts it through the private key to obtain a plain text authentication pass message; The sub-control module confirms the legitimacy of the identity by parsing the plaintext authentication message, obtains the business interaction authority and enters the normal business interaction state.
10. The method for secure encryption protection of air cooling control data according to claim 2, characterized in that: In step (7), corresponding control instruction data is generated according to the operation data; the control instruction data is encrypted by a symmetric encryption algorithm through a block encryption method to obtain encrypted control instruction data; Obtain the encrypted control instruction data and use the SHA-256 algorithm to calculate the integrity check value; According to the integrity check value, the check value is attached to the end of the encrypted control instruction data to form a complete data packet, and then the encrypted control instruction data with the check value is sent to the sub-control module through the transmission channel; Obtain the data received by the sub-control module, use the same SHA-256 algorithm and key to calculate the check value, and determine whether it is consistent with the received check value; If the check values are consistent, it is determined that the data has not been tampered with, and available control instruction data is obtained for executing the adjustment operation of the cooling system.
Citation Information
Patent Citations
System and method for authenticating credible identities on basis of safety chips
CN104580250A
Secure communication method and secure communication system of self-service device, and self-service device
CN107786550A
Vehicle data uploading method, device, vehicle, system and storage medium
CN113542428A
Internet of Things security operation system based on block chain
CN116346427A
Bidirectional identity authentication and encryption communication method based on HART-IP protocol
CN119402199A