Information security protection method and system for electric power acquisition terminal equipment
By adopting dynamic unique identification, multi-factor key generation, layered challenge response, high-dimensional abnormal behavior detection and multi-stage key update methods on power acquisition terminal equipment, the security threats faced by the equipment are solved, and the information security protection capabilities and overall security of the system are improved.
Patent Information
- Application Number
- CN202411886362.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-12-20
AI Technical Summary
Due to its openness and network interconnection characteristics, power acquisition terminal devices face serious security threats, including data tampering, identity forgery and information leakage. The traditional encryption and identity verification mechanisms in the existing technology are difficult to deal with these threats.
A method for information security protection of power acquisition terminal equipment is proposed, including generating dynamic unique identifiers, multi-factor key generation mechanisms, layered challenge response mechanisms, high-dimensional abnormal behavior detection and multi-stage key update mechanisms, to enhance the device's identity authentication, key generation and abnormal detection capabilities.
Through dynamic unique identification and multi-factor key generation mechanism, the security and dynamic nature of device identity authentication and key generation are improved. The hierarchical challenge response mechanism enhances the complexity and security of the authentication process, high-dimensional abnormal behavior detection improves the monitoring and detection capabilities of device behavior, and the multi-stage key update mechanism ensures continuous encryption protection for long-term running devices.
Smart Images

Figure CN120012126A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security protection of power acquisition terminal equipment, and in particular to an information security protection method for power acquisition terminal equipment. Background Art
[0002] With the development of smart grid and Internet of Things technology, power collection terminal equipment plays an increasingly important role in power monitoring and management. Power collection terminal equipment is usually used to monitor power data in real time, including parameters such as current, voltage, power factor, etc., and transmit the data to the central system through wireless communication. These terminal devices provide basic data support for the optimization management, fault detection, load forecasting, etc. of the power system. However, due to the openness and network interconnection characteristics of power collection terminal equipment, these devices face serious security threats, including data tampering, identity forgery, information leakage, etc. Therefore, how to protect the security of power collection terminal equipment while ensuring data accuracy has become a problem to be solved.
[0003] In the actual application of power collection terminal equipment, information security issues are particularly prominent. Existing technologies usually use traditional encryption and authentication mechanisms to protect the security of device communications, but due to the increasingly advanced technical means of attackers, the protection capabilities of these traditional mechanisms are gradually insufficient. For example, although the common cryptography-based authentication method can effectively prevent man-in-the-middle attacks and replay attacks, with the improvement of computing power, password cracking attacks have gradually become a threat, resulting in increased risks of leakage and tampering of device information. In addition, existing technologies generally ignore the security of the device itself and the detection of abnormal behavior. Attackers can bypass existing security protection mechanisms by forging device identities or tampering with device behavior data.
[0004] Therefore, in order to improve the security of power collection terminal equipment, this case proposes a method and system for information security protection of power collection terminal equipment. The solution proposes new identity authentication and abnormal behavior detection methods to adapt to the characteristics of long-term operation and dynamic behavior changes of equipment. These methods should have higher security, dynamic adaptability and computing efficiency, be able to effectively respond to current security threats, and ensure the authenticity and reliability of equipment data. Summary of the invention
[0005] The present invention provides a method and system for protecting information security of electric power acquisition terminal equipment, which promotes solving the problems mentioned in the above background technology.
[0006] The present invention provides the following technical solution: a method for protecting information security of power collection terminal equipment, comprising: S1. Generate a dynamic unique identifier, including: S11, multi-dimensional data collection of equipment hardware characteristics; Obtain device hardware characteristic parameters H={h1,h2,h3,h4}, where h1 is the device serial number, h2 is the MAC address, h3 is the CPU ID, and h4 is the storage device number; Among them, each h i It is a numeric type used to represent hardware characteristics; Convert the hardware characteristics to binary representation and split into bit level representation: B i ={b i1 ,b i2 ,……,b ij}, ; Among them, b ij Yes i The binary digit of h i The number of digits, Indicates rounding up; S12, high-dimensional transformation of hardware features; Define a transformation matrix T, wherein the transformation matrix T is specifically an n×m random matrix; ; Among them, t nm It is the element of matrix T, representing the mapping relationship of hardware features; Use matrix multiplication to convert the hardware feature matrix M H By mapping the transformation matrix to the new space, a new high-dimensional feature matrix is obtained: ; in, is the transpose of the hardware feature matrix, M T It is the characteristic matrix after high-dimensional transformation; S13, generating dynamic disturbance; Generate dynamic disturbance factors , whose value includes time factor and noise factor: ; in, is the frequency of the disturbance, t is the current timestamp, is random noise, conforming to the Gaussian distribution h t ~ N (0,s 2 ); The disturbance factor d t Add to the mapping matrix to generate a hardware signature matrix containing the perturbations: ; S14, generating a final dynamic unique identifier; Use nonlinear activation function to generate the final unique identifier UID t ; ; in, f is a non-linear activation function that maps the input to a specific range; is a high-dimensional feature matrix The value of row i and column j; is the exponential decay factor; n is the total number of rows of the high-dimensional feature matrix; m is the number of columns of the high-dimensional feature matrix; S2, multi-factor key generation mechanism; S3, layered challenge response mechanism; S4, high-dimensional abnormal behavior detection; S5. Multi-stage key update mechanism.
[0007] Optionally, the multi-factor key generation mechanism specifically includes: S21, generating seeds; Through the hash function and the unique identifier UID t Generate a key seed: ; S22, introducing environmental parameter disturbance; Use sensors to obtain environmental parameters; The sensors include a temperature sensor, a humidity sensor and a geographic location sensor; The environmental parameters include temperature, humidity and geographical location; Assume that the environmental parameter E t ={e1,e2,e3}, where the environmental parameters are specifically e1 for temperature, e2 for humidity, and e3 for geographic location; Calculate the disturbance coefficient D t As an environmental parameter, the effect on the key: ; in, is the norm of the environmental parameter vector, indicating the total amount of environmental parameters, is the time-dependent modulation frequency, t is the timestamp, For E t The i-th element in ; S23, generating a final key; Combined with key seed K seed and environmental disturbances D t Generate the final key: ; Among them, ⊕ represents the bitwise XOR operation, exp(-e i ) is the exponential decay of the environmental parameter, indicating that the influence of environmental factors on the key decreases over time. For E t The i-th element in .
[0008] Optionally, the hierarchical challenge response mechanism specifically includes: S31, generate hierarchical challenges; S32, response calculation; Get the variables needed for response calculation; The variables include R t (i) and K final ; The R t (i) ={r t (i)j} is the i-th layer challenge data, r t (i)j is the jth component in the i-th layer of challenge data; K final The key generated jointly by the device and the authentication server is used for encryption and authentication processes; Use the response calculation formula to calculate the response value. The response calculation formula is: ; Among them, S t (i) is the response value of the i-th layer, indicating the response of the device according to the key and challenge data; cos(j) is the weighting factor, indicating the contribution weight of different positions in the challenge data; is the jth component of the i-th layer challenge data; is the key; S33, response verification; S34, Enhancement of the layered challenge verification process; The dynamic adjustment formula is: ; Among them, D t ={d it}, is the disturbance matrix, which represents the disturbance factor at time t; D t ' is the perturbation matrix dynamically adjusted according to the failure level i, used to generate the next challenge; α i To dynamically adjust the factor, control the weight of the disturbance during the challenge process; Dynamic challenge generation formula: ; Among them, R t (i+1) is the i+1th layer of challenge data, based on the dynamically adjusted perturbation matrix D t'Generate new challenge data; M H is the hardware feature matrix of the device; () is a hash operation.
[0009] Optionally, the generating of the hierarchical challenge specifically includes: Get the variables needed for the stratification challenge; The variables specifically include: H , D t , i and t; The M H ={m ij} is the device hardware feature matrix, which represents the hardware information of the device. Each m ij is the jth component of the i-th hardware feature; D t ={d it} is the environmental disturbance matrix, which represents the disturbance value at timestamp t. Each d it is the i-th perturbation factor, controlling the difficulty of challenge generation; i is the level index of the current challenge, indicating that the difficulty of the challenge increases; t is the timestamp, indicating the current time point, controlling the dynamic changes of the disturbance; Use the challenge generation formula to generate the challenge value of the challenge data. The challenge generation formula is: ; The R t (i) is the challenge data of the i-th layer, indicating the challenge value generated based on the device characteristics and disturbances; Hash(x) represents the hash operation on the data x to generate a challenge value of a fixed length; i·D t Denotes the perturbation matrix D t Impact on the current level i.
[0010] Optionally, the response verification specifically includes: S331, calculating the expected response value; ; Among them, S expected (i) The expected response value calculated by the authentication server, indicating the received challenge data R t (i) and key K final Calculated response; S332, response verification; ; Among them, S t (i) The response value calculated for the device; S expected(i) The expected response value calculated for the authentication server; Indicates the preset tolerance error threshold.
[0011] Optionally, the high-dimensional abnormal behavior detection specifically includes: Collect device behavior data and define the behavior data set as a matrix X : ; Among them, x mn is the nth feature of the mth behavior; Map the behavior data into a high-dimensional space to obtain a new feature matrix Y : ; Among them, W is the mapping matrix, s is the activation function, b is the bias term, and X T is the transpose of the data matrix X; Calculate the abnormality D(x) of each behavior data i ): ; Among them, y i is the result of the behavioral data projection, m Y is the mean of the behavioral data set, s Y is the standard deviation of the behavior data set, D(x i ) indicates the abnormality degree of the behavior data.
[0012] Optionally, the multi-stage key update mechanism specifically includes: S51, update factor calculation; Use dynamic unique identifier UID t and the disturbance d t Generate update factor U t : ; Among them, d t is a disturbance, UID t is a unique identifier, U t is the update factor; S52, update in stages; At each stage, the update factor U t Key K t To update: ; Among them, ⊕ represents the bitwise XOR operation, indicating the change of the key at each stage; S53, synchronizing the final key; At the end of the session, the keys K of all phases aret and update factor U t Perform synthesis to generate session keys: ; Among them, K session is the final session key and T is the number of key update phases.
[0013] A system for implementing the information security protection method of the power collection terminal equipment, comprising: Sensor module: temperature sensor, humidity sensor and geographic location sensor, wherein the temperature sensor is used to obtain temperature data, the humidity sensor is used to obtain humidity data, and the geographic location sensor is used to obtain device geographic location data; Session module: used for the session between the device and the authentication server; Computing module: used to perform data calculations.
[0014] The present invention has the following beneficial effects: 1. By collecting the hardware feature parameters of the device, such as the device serial number, MAC address, CPU ID, and storage device number, and converting them into binary representation, a unique set of hardware features is generated for each device. These hardware features cannot be easily forged or modified, and can effectively prevent attackers from bypassing system authentication by forging device identities. In addition, the multi-dimensional data collection of hardware features also provides a sufficient basis for the subsequent generation of dynamic unique identifiers, enhancing the reliability of identity recognition. After the hardware features are transformed into high dimensions using the transformation matrix, the originally simpler hardware features can be mapped to a higher-dimensional space. In this way, even if the attacker analyzes the original hardware features, it is difficult to reverse the true identity of the device from them. High-dimensional mapping increases the complexity of device identification, making it more difficult to tamper with or forge hardware features, effectively enhancing the security of identity authentication. Dynamic perturbation factors, including time factors and noise factors, introduce time changes and random noise, causing the device identifier to change over time. The introduction of perturbation factors ensures that the unique identification of the device not only depends on the hardware features, but also changes dynamically with each authentication process. This dynamic nature effectively prevents identity replay attacks or forgery attacks, making each identity authentication timely and unpredictable, greatly improving the security of the system. The dynamic unique identifier UID generated by the nonlinear activation function is t, combining hardware features, perturbation factors and activation functions, so that the identification of each device is not only related to its hardware features, but also has the dynamics of time and noise. This mechanism makes the identification of the device more complex and unpredictable, further improves the resistance to malicious attacks, and avoids security issues such as replay attacks and identity forgery that are prone to traditional methods using static identification. The multi-factor key generation mechanism generates security keys by combining multiple security factors, such as device hardware features, environmental parameters and timing factors, to solve the risk of traditional single-key authentication mechanisms being vulnerable to brute force cracking or key leakage. The multi-factor mechanism can effectively improve the randomness and unpredictability of key generation, enhance the security of the key itself, and ensure that data encryption and identity authentication in device communications are more secure. In the layered challenge response mechanism, by setting multiple levels of security challenges, it is ensured that the device must pass multiple levels of authentication every time it interacts, thereby reducing the security risks caused by single point failures. Each layer of challenge and response has the characteristics of dynamic generation, so that even if the attacker obtains part of the response data, it cannot easily decrypt or forge the correct response, which significantly improves the protection capability. High-dimensional abnormal behavior detection can detect potential security threats to devices in complex environments by analyzing the behavioral characteristics of devices in multi-dimensional space. This method not only solves the limitations of anomaly detection based on traditional rules, but also dynamically adapts to changes in device behavior and promptly detects potential security threats, such as abnormal behavior after the device has been tampered with or controlled. In addition, behavioral models based on high-dimensional data can effectively improve the accuracy of anomaly detection and reduce false positives and negatives. The multi-stage key update mechanism ensures that long-term running devices are always under secure encryption protection by regularly updating keys and combining device behavior characteristics. This mechanism can prevent attackers from cracking device communication content by capturing and analyzing old keys, providing continuous security, especially in long-term power collection terminal devices, avoiding large-scale security risks caused by key leakage.
[0015] 2. Through UID t The hashing process makes the key seed of each device unique and unpredictable. Traditional key generation methods may have the risk of key duplication or predictability, but the introduction of hash functions avoids this situation and improves the security and uniqueness of the key from the source. This method also ensures that the key seed generated by each device is dynamically changed, increasing the system's anti-attack capability. Environmental parameters such as temperature, humidity and geographic location are collected through sensors, and the disturbance coefficient D is introduced tTo increase the dynamics and randomness of key generation. Environmental parameters change over time, so each time a key is generated, the dynamic changes of the environment are taken into account, which enhances the unpredictability of the key. The introduction of environmental disturbances effectively prevents attackers from obtaining the key generation rules through static analysis or reverse engineering, thereby improving the key's anti-cracking ability. Changes in environmental factors make the key have time-varying characteristics. Even if an attacker obtains the key at a certain moment, it is impossible to deduce the key at a subsequent moment. When generating the final key, the key seed and environmental disturbance are combined, and the final key is generated through a bitwise XOR operation. The exponential decay of environmental parameters reflects that the impact of the environment on key generation gradually weakens over time. This process ensures that the final key not only depends on the static characteristics of the device hardware, but also combines the dynamic changes of the external environment, making the key more complex, dynamic and unpredictable. The use of bitwise XOR operations further increases the security of key generation. Even if a factor is known by an attacker, it is still difficult to deduce the complete information of the key.
[0016] 3. In the traditional identity authentication mechanism, usually only a single-level challenge response process is relied on, which is vulnerable to man-in-the-middle attacks or replay attacks. However, through the layered challenge generation mechanism of step S31, each layer of challenge data is based on the key generated by the device and the authentication server, and the challenge data of each layer is different from the data of the previous layer. This multi-level and multi-dimensional challenge makes it difficult for attackers to bypass the authentication process by simply stealing or replaying data. This hierarchical structure enhances the complexity and security of identity authentication and prevents passive cracking of single challenge data. In the response calculation, the response value of each layer is generated by combining the weighting factor and key of the challenge data, so that the calculation of the response value of each layer depends not only on the identity information of the device, but also on the weight of the challenge data. This design solves the problem that the traditional response value is fixed and easy to predict. The calculation result of each response is closely related to the position and content in the challenge data, which increases the variability and complexity of the authentication process and avoids the risk of being simply simulated and forged. In the response verification process, the authentication server determines whether the device is a legitimate device by verifying whether the response value is correct. This step ensures that the challenge at each layer must match the expected response value of the device, greatly improving the reliability of the authentication process and preventing identity fraud or man-in-the-middle attacks. At the same time, only the correct device can generate the expected response value in each layer of challenge, thereby further strengthening the trust relationship between the device and the server. Step S34 introduces a dynamic adjustment factor and dynamically adjusts the challenge through the perturbation matrix, enhancing the adaptability and anti-attack ability of the challenge response mechanism. In the traditional mechanism, once a layer of the authentication process fails, it may cause the interruption of the entire authentication process. In this step, by dynamically adjusting and generating new challenge data, the difficulty of the challenge can be adjusted according to the failed level, making the challenge of the next layer more difficult, thereby preventing attackers from continuing to forge identities through simple reverse or cracking methods. This dynamic adjustment ensures that the challenge response mechanism can still maintain a high degree of security in the face of complex attacks.
[0017] 4. Variables include device hardware feature matrix, environmental perturbation matrix, challenge level index and timestamp. The device hardware feature matrix contains the unique hardware information of the device, while the environmental perturbation matrix reflects the impact of the environment on challenge generation. Through the combination of these variables, the hardware features of the device can be combined with the dynamic changes of environmental factors to generate more complex and variable challenge data. This method avoids the problem of isolated treatment of device hardware features and environmental factors in traditional authentication methods, enhances the real-time and adaptability of challenges, and improves the system's ability to cope with complex attacks. The challenge generation formula combines the device hardware feature matrix and the environmental perturbation matrix to generate challenge data for each layer according to the level index and timestamp. This generation method combines the influence of the perturbation matrix with the challenge level index, so that as the challenge level increases, the computational complexity of the challenge gradually increases, and the difficulty of the challenge gradually increases. The generation of challenge data not only considers the static characteristics of the device, but also introduces the dynamic changes of the environment, thereby increasing the complexity and unpredictability of the challenge, and effectively preventing the risk of cracking the authentication mechanism through simple reverse analysis or replay attacks. As the level index increases, the influence of the perturbation matrix gradually increases, and the computational complexity of the challenge gradually increases with the level. This design solves the problem that traditional challenge generation is difficult to deal with advanced attacks. As the level increases, the computational complexity of the challenge increases, which can resist stronger attackers and more complex attack methods. The increased complexity of the challenge process means that even if an attacker obtains the challenge data of a certain layer, he cannot directly infer the challenge data of the next layer, which effectively improves the security of the system.
[0018] 5. In the traditional authentication mechanism, the calculation of the response value is usually based on the operation of simple keys and challenge data, which is vulnerable to the risk of man-in-the-middle attacks or tampering. In step S331, the authentication server calculates the expected response value based on the received challenge data and key, and compares it with the calculation result of the device. This design ensures that the authentication server can calculate the expected response value through a complex formula, thereby effectively preventing the simple behavior of forging or tampering with the response data. In this way, the verification process of the response value becomes more accurate and secure, and the credibility of the authentication is enhanced. Through step S332, the fault tolerance problem in identity authentication is solved. In this step, the authentication server verifies the identity of the device by comparing the response value calculated by the device with the expected response value and comparing it with the preset tolerance error threshold. If the response value exceeds the preset tolerance error threshold, the authentication request will be deemed invalid. This design effectively solves the problem of insufficient error tolerance in traditional authentication and avoids authentication failure caused by minor errors. The setting of the tolerance error threshold makes the authentication process not only accurate, but also able to maintain the stability of the system and the user experience in the face of calculation deviations within a certain range, thereby improving the fault tolerance of the system. By comparing the expected response value with the actual response value, the problem of response forgery and tampering is solved. The calculation of the expected response value depends on the unique key of the device and the received challenge data, while the response value calculated by the device is calculated based on the same challenge data and the private key of the device. Through this comparison mechanism, even if an attacker attempts to forge the response data or a middleman tampers with the data, due to the lack of the correct key and hardware information, a response consistent with the expected response value cannot be generated, thus effectively avoiding forgery and tampering attacks.
[0019] 6. By collecting device behavior data and defining the behavior data set as a matrix X step, the problem of lack of unified standards and multi-dimensional feature integration of behavior data is solved. In this step, the behavior data is defined as a matrix X, where x mnRepresents the nth feature of the mth behavior. This step effectively converts the device's behavior data into a unified format and provides a complete view of the behavior data through the integration of multi-dimensional features. In this way, the behavior data is standardized and the multi-dimensional features of each piece of behavior data are fully considered, so that the subsequent analysis can more comprehensively capture the multi-dimensional information of the device behavior, laying the foundation for the detection of abnormal behavior. By mapping the behavior data to a high-dimensional space, a new feature matrix Y is obtained, which solves the problem of information loss caused by low data dimensions. The behavior data X is mapped to a high-dimensional space to obtain a new feature matrix Y, where W is the mapping matrix, b is the bias term, and the activation function is used to enhance the nonlinear expression of the data. This step increases the data dimension and performs nonlinear transformation on the data, so that the data can be better expressed in a high-dimensional space, thereby retaining more useful information and avoiding the loss of feature information caused by low-dimensional mapping. Through mapping, the potential pattern of the behavior data is captured more accurately, providing a richer feature representation for subsequent abnormal behavior detection. By calculating the abnormality of each piece of behavior data, the problem of recognition accuracy of abnormal behavior is solved. In this step, the abnormality D(xi) of each behavior data is calculated, where yi is the result of the projection of the behavior data, Y is the mean of the behavior data set, and σ is the standard deviation of the behavior data set. By calculating the abnormality, the system can quantify the degree of deviation of each behavior data from normal behavior. If the deviation exceeds a certain threshold, it is judged as abnormal behavior. This step effectively solves the problem that traditional anomaly detection methods cannot accurately identify small deviations or complex abnormal patterns. Through high-dimensional space mapping and standard deviation calculation, the degree of abnormality of behavior data can be accurately measured, improving the accuracy and reliability of anomaly detection. By judging whether the behavior is abnormal based on the abnormality, the problem of the singleness of the detection strategy is solved. The high-dimensional abnormal behavior detection mechanism does not rely on a single threshold judgment, but comprehensively considers the projection results and statistical characteristics of the data, such as the mean and standard deviation, making the calculation of the abnormality more detailed and accurate. This process can flexibly respond to complex and changeable behavior patterns, avoiding the misjudgment or missed judgment problems that may occur in traditional methods based on fixed thresholds. At the same time, the system can adapt to the behavioral characteristics of different devices or users, thereby providing dynamic and intelligent anomaly detection capabilities.
[0020] 7. Use dynamic unique identifier UID t and the disturbance factor t to generate the update factor U t Update factor U tThe unique identification of the device and dynamic disturbance are combined to ensure that each key update is unique and dynamic, avoiding the potential security risks caused by the long-term use of static keys. The introduction of dynamic factors makes the key update no longer a simple static operation, but a dynamic process based on device status and environmental changes, which effectively prevents the key from being attacked by replay attacks and prediction attacks. t By bitwise XOR operation and update factor U t This step avoids the singleness and irreversibility of the key update process through multiple phase-by-phase updates, and improves the security of the key. Each key update depends on the key of the previous stage and the dynamically generated update factor, which makes the key change more complicated and increases the difficulty for attackers to crack. The phase-by-phase update not only increases the strength of the key, but also ensures that even if the keys of some stages are leaked, the entire key process still has a high security. At the end of the session, the keys and update factors of all stages are combined to generate the session key. This step ensures the integrity and consistency of the key by combining the keys and update factors of all stages. This mechanism solves the coordination problem in key management and avoids security vulnerabilities caused by inconsistent keys or untimely synchronization in different stages. At the same time, the generated session key has strong encryption protection capabilities, ensuring the security of data transmission during the session. Traditional key update mechanisms often rely on only a single update operation, while the multi-stage key update mechanism increases the complexity of key changes through multiple update steps, preventing the risk of key being cracked or leaked by force. By updating the keys independently at each stage, the complexity and update frequency of the keys are greatly improved, making it difficult to infer the contents of the entire key chain even if the keys of a certain stage are mastered by an attacker, thereby greatly improving the overall security. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the process of the present invention. DETAILED DESCRIPTION
[0022] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0023] Example, see Figure 1 , a method for protecting information security of power collection terminal equipment, comprising: S1. Generate a dynamic unique identifier, including: S11, multi-dimensional data collection of equipment hardware characteristics; Obtain device hardware characteristic parameters H={h1,h2,h3,h4}, where h1 is the device serial number, h2 is the MAC address, h3 is the CPU ID, and h4 is the storage device number; Among them, each h i It is a numeric type used to represent hardware characteristics; Convert the hardware characteristics to binary representation and split into bit level representation: B i ={b i1 ,b i2 ,……,b ij}, ; Among them, b ij Yes i The binary digit of h i The number of digits, Indicates rounding up; S12, high-dimensional transformation of hardware features; Define a transformation matrix T, wherein the transformation matrix T is specifically an n×m random matrix; ; Among them, t nm It is the element of matrix T, representing the mapping relationship of hardware features; Use matrix multiplication to convert the hardware feature matrix M H By mapping the transformation matrix to the new space, a new high-dimensional feature matrix is obtained: ; in, is the transpose of the hardware feature matrix, M T It is the characteristic matrix after high-dimensional transformation; S13, generating dynamic disturbance; Generate dynamic disturbance factors , whose value includes time factor and noise factor: ; in, is the frequency of the disturbance, t is the current timestamp, is random noise, conforming to the Gaussian distribution h t ~ N (0,s 2 ); The disturbance factor d t Add to the mapping matrix to generate a hardware signature matrix containing the perturbations: ; S14, generating a final dynamic unique identifier; Use nonlinear activation function to generate the final unique identifier UID t ; ; in, f is a non-linear activation function that maps the input to a specific range; is a high-dimensional feature matrix The value of row i and column j; is the exponential decay factor; n is the total number of rows of the high-dimensional feature matrix; m is the number of columns of the high-dimensional feature matrix; S2, multi-factor key generation mechanism; S3, layered challenge response mechanism; S4, high-dimensional abnormal behavior detection; S5. Multi-stage key update mechanism.
[0024] By collecting the hardware characteristic parameters of the device, such as the device serial number, MAC address, CPU ID, and storage device number, and converting them into binary representation, a unique set of hardware characteristics is generated for each device. These hardware characteristics cannot be easily forged or modified, which can effectively prevent attackers from bypassing system authentication by forging device identities. In addition, the multi-dimensional data collection of hardware characteristics also provides a sufficient basis for the subsequent dynamic unique identification generation, enhancing the reliability of identity recognition. After the hardware characteristics are transformed into a high-dimensional space using the transformation matrix, the originally simple hardware characteristics can be mapped to a higher-dimensional space. In this way, even if the attacker analyzes the original hardware characteristics, it is difficult to reverse the true identity of the device from them. High-dimensional mapping increases the complexity of device identification, making it more difficult to tamper with or forge hardware characteristics, effectively enhancing the security of identity authentication. Dynamic perturbation factors, including time factors and noise factors, introduce time changes and random noise, causing the device identifier to change over time. The introduction of perturbation factors ensures that the unique identification of the device not only depends on the hardware characteristics, but also changes dynamically with each authentication process. This dynamic nature effectively prevents identity replay attacks or forgery attacks, making each identity authentication timely and unpredictable, greatly improving the security of the system. The dynamic unique identifier UID generated by the nonlinear activation function is t, combining hardware features, perturbation factors and activation functions, so that the identification of each device is not only related to its hardware features, but also has the dynamics of time and noise. This mechanism makes the identification of the device more complex and unpredictable, further improves the resistance to malicious attacks, and avoids security issues such as replay attacks and identity forgery that are prone to traditional methods using static identification. The multi-factor key generation mechanism generates security keys by combining multiple security factors, such as device hardware features, environmental parameters and timing factors, to solve the risk of traditional single-key authentication mechanisms being vulnerable to brute force cracking or key leakage. The multi-factor mechanism can effectively improve the randomness and unpredictability of key generation, enhance the security of the key itself, and ensure that data encryption and identity authentication in device communications are more secure. In the layered challenge response mechanism, by setting multiple levels of security challenges, it is ensured that the device must pass multiple levels of authentication every time it interacts, thereby reducing the security risks caused by single point failures. Each layer of challenge and response has the characteristics of dynamic generation, so that even if the attacker obtains part of the response data, it cannot easily decrypt or forge the correct response, which significantly improves the protection capability. High-dimensional abnormal behavior detection can detect potential security threats to devices in complex environments by analyzing the behavioral characteristics of devices in multi-dimensional space. This method not only solves the limitations of anomaly detection based on traditional rules, but also dynamically adapts to changes in device behavior and promptly detects potential security threats, such as abnormal behavior after the device has been tampered with or controlled. In addition, behavioral models based on high-dimensional data can effectively improve the accuracy of anomaly detection and reduce false positives and negatives. The multi-stage key update mechanism ensures that long-term running devices are always under secure encryption protection by regularly updating keys and combining device behavior characteristics. This mechanism can prevent attackers from cracking device communication content by capturing and analyzing old keys, providing continuous security, especially in long-term power collection terminal devices, avoiding large-scale security risks caused by key leakage.
[0025] The multi-factor key generation mechanism specifically includes: S21, generating seeds; Through the hash function and the unique identifier UID t Generate a key seed: ; S22, introducing environmental parameter disturbance; Use sensors to obtain environmental parameters; The sensors include a temperature sensor, a humidity sensor and a geographic location sensor; The environmental parameters include temperature, humidity and geographical location; Assume that the environmental parameter E t={e1,e2,e3}, where the environmental parameters are specifically e1 for temperature, e2 for humidity, and e3 for geographic location; Calculate the disturbance coefficient D t As an environmental parameter, the effect on the key: ; in, is the norm of the environmental parameter vector, indicating the total amount of environmental parameters, is the time-dependent modulation frequency, t is the timestamp, For E t The i-th element in ; S23, generating a final key; Combined with key seed K seed and environmental disturbances D t Generate the final key: ; Among them, ⊕ represents the bitwise XOR operation, exp(-e i ) is the exponential decay of the environmental parameter, indicating that the influence of environmental factors on the key decreases over time. For E t The i-th element in .
[0026] By UID t The hashing process makes the key seed of each device unique and unpredictable. Traditional key generation methods may have the risk of key duplication or predictability, but the introduction of hash functions avoids this situation and improves the security and uniqueness of the key from the source. This method also ensures that the key seed generated by each device is dynamically changed, increasing the system's anti-attack capability. Environmental parameters such as temperature, humidity and geographic location are collected through sensors, and the disturbance coefficient D is introduced tTo increase the dynamics and randomness of key generation. Environmental parameters change over time, so each time a key is generated, the dynamic changes of the environment are taken into account, which enhances the unpredictability of the key. The introduction of environmental disturbances effectively prevents attackers from obtaining the key generation rules through static analysis or reverse engineering, thereby improving the key's anti-cracking ability. Changes in environmental factors make the key have time-varying characteristics. Even if an attacker obtains the key at a certain moment, it is impossible to deduce the key at a subsequent moment. When generating the final key, the key seed and environmental disturbance are combined, and the final key is generated through a bitwise XOR operation. The exponential decay of environmental parameters reflects that the impact of the environment on key generation gradually weakens over time. This process ensures that the final key not only depends on the static characteristics of the device hardware, but also combines the dynamic changes of the external environment, making the key more complex, dynamic and unpredictable. The use of bitwise XOR operations further increases the security of key generation. Even if a factor is known by an attacker, it is still difficult to deduce the complete information of the key.
[0027] The layered challenge response mechanism specifically includes: S31, generate hierarchical challenges; S32, response calculation; Get the variables needed for response calculation; The variables include R t (i) and K final ; The R t (i) ={r t (i)j} is the i-th layer challenge data, r t (i)j is the jth component in the i-th layer of challenge data; K final The key generated jointly by the device and the authentication server is used for encryption and authentication processes; Use the response calculation formula to calculate the response value. The response calculation formula is: ; Among them, S t (i) is the response value of the i-th layer, indicating the response of the device according to the key and challenge data; cos(j) is the weighting factor, indicating the contribution weight of different positions in the challenge data; is the jth component of the i-th layer challenge data; is the key; S33, response verification; S34, Enhancement of the layered challenge verification process; The dynamic adjustment formula is: ; Among them, D t={d it}, is the disturbance matrix, which represents the disturbance factor at time t; D t ' is the perturbation matrix dynamically adjusted according to the failure level i, used to generate the next challenge; α i To dynamically adjust the factor, control the weight of the disturbance during the challenge process; Dynamic challenge generation formula: ; Among them, R t (i+1) is the i+1th layer of challenge data, based on the dynamically adjusted perturbation matrix D t 'Generate new challenge data; M H is the hardware feature matrix of the device; () is a hash operation.
[0028] In traditional identity authentication mechanisms, usually only a single-level challenge response process is relied upon, which is vulnerable to man-in-the-middle attacks or replay attacks. However, through the layered challenge generation mechanism of step S31, each layer of challenge data is based on the key generated by the device and the authentication server, and the challenge data of each layer is different from the data of the previous layer. This multi-level and multi-dimensional challenge makes it difficult for attackers to bypass the authentication process by simply stealing or replaying data. This hierarchical structure enhances the complexity and security of identity authentication and prevents passive cracking of single challenge data. In the response calculation, the response value of each layer is generated by combining the weighting factor and key of the challenge data, so that the calculation of the response value of each layer depends not only on the identity information of the device, but also on the weight of the challenge data. This design solves the problem that the traditional response value is fixed and easy to predict. The calculation result of each response is closely related to the position and content in the challenge data, which increases the variability and complexity of the authentication process and avoids the risk of being simply simulated and forged. In the response verification process, the authentication server determines whether the device is a legitimate device by verifying whether the response value is correct. This step ensures that the challenge at each layer must match the expected response value of the device, greatly improving the reliability of the authentication process and preventing identity fraud or man-in-the-middle attacks. At the same time, only the correct device can generate the expected response value in each layer of challenge, thereby further strengthening the trust relationship between the device and the server. Step S34 introduces a dynamic adjustment factor and dynamically adjusts the challenge through the perturbation matrix, enhancing the adaptability and anti-attack ability of the challenge response mechanism. In the traditional mechanism, once a layer of the authentication process fails, it may cause the interruption of the entire authentication process. In this step, by dynamically adjusting and generating new challenge data, the difficulty of the challenge can be adjusted according to the failed level, making the challenge of the next layer more difficult, thereby preventing attackers from continuing to forge identities through simple reverse or cracking methods. This dynamic adjustment ensures that the challenge response mechanism can still maintain a high degree of security in the face of complex attacks.
[0029] The generation of layered challenges specifically includes: Get the variables needed for the stratification challenge; The variables specifically include: H , D t , i and t; The M H ={m ij} is the device hardware feature matrix, which represents the hardware information of the device. Each m ij is the jth component of the i-th hardware feature; D t ={d it} is the environmental disturbance matrix, which represents the disturbance value at timestamp t. Each d it is the i-th perturbation factor, controlling the difficulty of challenge generation; i is the level index of the current challenge, indicating that the difficulty of the challenge increases. As the number of levels increases, the computational complexity of the challenge gradually increases; t is the timestamp, indicating the current time point, controlling the dynamic changes of the disturbance; Use the challenge generation formula to generate the challenge value of the challenge data. The challenge generation formula is: ; The R t (i) is the challenge data of the i-th layer, indicating the challenge value generated based on the device characteristics and disturbances; Hash(x) represents the hash operation on the data x to generate a challenge value of a fixed length; i·D t Denotes the perturbation matrix D t The impact on the current level i. As i increases, the effect of disturbance increases, generating more complex challenges.
[0030] The variables include the device hardware feature matrix, the environmental perturbation matrix, the challenge level index, and the timestamp. The device hardware feature matrix contains the unique hardware information of the device, while the environmental perturbation matrix reflects the impact of the environment on the generation of the challenge. Through the combination of these variables, the hardware features of the device can be combined with the dynamic changes of environmental factors to generate more complex and variable challenge data. This method avoids the problem of isolated treatment of device hardware features and environmental factors in traditional authentication methods, enhances the real-time and adaptability of the challenge, and improves the system's ability to cope with complex attacks. The challenge generation formula combines the device hardware feature matrix and the environmental perturbation matrix to generate challenge data for each layer according to the level index and timestamp. This generation method combines the influence of the perturbation matrix with the challenge level index, so that as the challenge level increases, the computational complexity of the challenge gradually increases, and the difficulty of the challenge gradually increases. The generation of challenge data not only considers the static characteristics of the device, but also introduces the dynamic changes of the environment, thereby increasing the complexity and unpredictability of the challenge, and effectively preventing the risk of cracking the authentication mechanism through simple reverse analysis or replay attacks. As the level index increases, the influence of the perturbation matrix gradually increases, and the computational complexity of the challenge gradually increases with the level. This design solves the problem that traditional challenge generation is difficult to deal with advanced attacks. As the level increases, the computational complexity of the challenge increases, which can resist stronger attackers and more complex attack methods. The increased complexity of the challenge process means that even if an attacker obtains the challenge data of a certain layer, he cannot directly infer the challenge data of the next layer, which effectively improves the security of the system.
[0031] The response verification specifically includes: S331, calculating the expected response value; ; Among them, S expected (i) The expected response value calculated by the authentication server, indicating the received challenge data R t (i) and key K final Calculated response; S332, response verification; ; Among them, S t (i) The response value calculated for the device; S expected (i) The expected response value calculated for the authentication server; Indicates the preset tolerance error threshold.
[0032] In the traditional authentication mechanism, the calculation of the response value is usually based on the operation of simple keys and challenge data, which is vulnerable to the risk of man-in-the-middle attacks or tampering. In step S331, the authentication server calculates the expected response value based on the received challenge data and key, and compares it with the calculation result of the device. This design ensures that the authentication server can calculate the expected response value through a complex formula, thereby effectively preventing the simple behavior of forging or tampering with the response data. In this way, the verification process of the response value becomes more accurate and secure, and the credibility of the authentication is enhanced. Through step S332, the fault tolerance problem in identity authentication is solved. In this step, the authentication server verifies the identity of the device by comparing the response value calculated by the device end with the expected response value and comparing it with the preset tolerance error threshold. If the response value exceeds the preset tolerance error threshold, the authentication request will be deemed invalid. This design effectively solves the problem of insufficient error tolerance in traditional authentication and avoids authentication failure caused by minor errors. The setting of the tolerance error threshold makes the authentication process not only accurate, but also able to maintain the stability of the system and the user experience when facing a certain range of calculation deviations, thereby improving the fault tolerance of the system. By comparing the expected response value with the actual response value, the problem of response forgery and tampering is solved. The calculation of the expected response value depends on the unique key of the device and the received challenge data, while the response value calculated by the device is calculated based on the same challenge data and the private key of the device. Through this comparison mechanism, even if an attacker attempts to forge the response data or a middleman tampers with the data, due to the lack of the correct key and hardware information, a response consistent with the expected response value cannot be generated, thus effectively avoiding forgery and tampering attacks.
[0033] The high-dimensional abnormal behavior detection specifically includes: Collect device behavior data and define the behavior data set as a matrix X : ; Among them, x mn is the nth feature of the mth behavior; Map the behavior data into a high-dimensional space to obtain a new feature matrix Y : ; Among them, W is the mapping matrix, s is the activation function, b is the bias term, and X T is the transpose of the data matrix X; Calculate the abnormality D(x) of each behavior data i ): ; Among them, y i is the result of the behavioral data projection, m Y is the mean of the behavioral data set, sY is the standard deviation of the behavior data set, D(x i ) indicates the abnormality degree of the behavior data.
[0034] By collecting device behavior data and defining the behavior data set as a matrix X step, the problem of lack of unified standards and multi-dimensional feature integration of behavior data is solved. In this step, the behavior data is defined as a matrix X, where x mn Represents the nth feature of the mth behavior. This step effectively converts the device's behavior data into a unified format and provides a complete view of the behavior data through the integration of multi-dimensional features. In this way, the behavior data is standardized and the multi-dimensional features of each piece of behavior data are fully considered, so that the subsequent analysis can more comprehensively capture the multi-dimensional information of the device behavior, laying the foundation for the detection of abnormal behavior. By mapping the behavior data to a high-dimensional space, a new feature matrix Y is obtained, which solves the problem of information loss caused by low data dimensions. The behavior data X is mapped to a high-dimensional space to obtain a new feature matrix Y, where W is the mapping matrix, b is the bias term, and the activation function is used to enhance the nonlinear expression of the data. This step increases the data dimension and performs nonlinear transformation on the data, so that the data can be better expressed in a high-dimensional space, thereby retaining more useful information and avoiding the loss of feature information caused by low-dimensional mapping. Through mapping, the potential pattern of the behavior data is captured more accurately, providing a richer feature representation for subsequent abnormal behavior detection. By calculating the abnormality of each piece of behavior data, the problem of recognition accuracy of abnormal behavior is solved. In this step, the abnormality D(xi) of each behavior data is calculated, where yi is the result of the projection of the behavior data, Y is the mean of the behavior data set, and σ is the standard deviation of the behavior data set. By calculating the abnormality, the system can quantify the degree of deviation of each behavior data from normal behavior. If the deviation exceeds a certain threshold, it is judged as abnormal behavior. This step effectively solves the problem that traditional anomaly detection methods cannot accurately identify small deviations or complex abnormal patterns. Through high-dimensional space mapping and standard deviation calculation, the degree of abnormality of behavior data can be accurately measured, improving the accuracy and reliability of anomaly detection. By judging whether the behavior is abnormal based on the abnormality, the problem of the singleness of the detection strategy is solved. The high-dimensional abnormal behavior detection mechanism does not rely on a single threshold judgment, but comprehensively considers the projection results and statistical characteristics of the data, such as the mean and standard deviation, making the calculation of the abnormality more detailed and accurate. This process can flexibly respond to complex and changeable behavior patterns, avoiding the misjudgment or missed judgment problems that may occur in traditional methods based on fixed thresholds. At the same time, the system can adapt to the behavioral characteristics of different devices or users, thereby providing dynamic and intelligent anomaly detection capabilities.
[0035] The multi-stage key update mechanism specifically includes: S51, update factor calculation; Use dynamic unique identifier UID t and the disturbance d t Generate update factor U t : ; Among them, d t is a disturbance, UID t is a unique identifier, U t is the update factor; S52, update in stages; At each stage, the update factor U t Key K t To update: ; Among them, ⊕ represents the bitwise XOR operation, indicating the change of the key at each stage; S53, synchronizing the final key; At the end of the session, the keys K of all phases are t and update factor U t Perform synthesis to generate session keys: ; Among them, K session is the final session key and T is the number of key update phases.
[0036] Use dynamic unique identifier UID t and the disturbance factor t to generate the update factor U t Update factor U t The unique identification of the device and dynamic disturbance are combined to ensure that each key update is unique and dynamic, avoiding the potential security risks caused by the long-term use of static keys. The introduction of dynamic factors makes the key update no longer a simple static operation, but a dynamic process based on device status and environmental changes, which effectively prevents the key from being attacked by replay attacks and prediction attacks. t By bitwise XOR operation and update factor U tThis step avoids the singleness and irreversibility of the key update process through multiple phase-by-phase updates, and improves the security of the key. Each key update depends on the key of the previous stage and the dynamically generated update factor, which makes the key change more complicated and increases the difficulty for attackers to crack. The phase-by-phase update not only increases the strength of the key, but also ensures that even if the keys of some stages are leaked, the entire key process still has a high security. At the end of the session, the keys and update factors of all stages are combined to generate the session key. This step ensures the integrity and consistency of the key by combining the keys and update factors of all stages. This mechanism solves the coordination problem in key management and avoids security vulnerabilities caused by inconsistent keys or untimely synchronization in different stages. At the same time, the generated session key has strong encryption protection capabilities, ensuring the security of data transmission during the session. Traditional key update mechanisms often rely on only a single update operation, while the multi-stage key update mechanism increases the complexity of key changes through multiple update steps, preventing the risk of key being cracked or leaked by force. By updating the keys independently at each stage, the complexity and update frequency of the keys are greatly improved, making it difficult to infer the contents of the entire key chain even if the keys of a certain stage are mastered by an attacker, thereby greatly improving the overall security.
[0037] This embodiment also provides a system for a method for protecting information security of a power collection terminal device, including: Sensor module: temperature sensor, humidity sensor and geographic location sensor, wherein the temperature sensor is used to obtain temperature data, the humidity sensor is used to obtain humidity data, and the geographic location sensor is used to obtain device geographic location data; Session module: used for the session between the device and the authentication server; Computing module: used to perform data calculations.
[0038] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.
[0039] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for protecting information security of power collection terminal equipment, characterized in that: include: S1. Generate a dynamic unique identifier, including: S11, multi-dimensional data collection of equipment hardware characteristics; Obtain device hardware characteristic parameters H={h1,h2,h3,h4}, where h1 is the device serial number, h2 is the MAC address, h3 is the CPU ID, and h4 is the storage device number; Among them, each h i It is a numeric type used to represent hardware characteristics; Convert the hardware characteristics to binary representation and split into bit level representation: B i ={b i1 ,b i2 ,……,b ij }, ; Among them, b ij Yes i The binary digit of h i The number of digits, Indicates rounding up; S12, high-dimensional transformation of hardware features; Define a transformation matrix T, wherein the transformation matrix T is specifically an n×m random matrix; ; Among them, t nm It is the element of matrix T, representing the mapping relationship of hardware features; Use matrix multiplication to convert the hardware feature matrix M H By mapping the transformation matrix to the new space, a new high-dimensional feature matrix is obtained: ; in, is the transpose of the hardware feature matrix, M T It is the characteristic matrix after high-dimensional transformation; S13, generating dynamic disturbance; Generate dynamic disturbance factors , whose value includes time factor and noise factor: ; in, is the frequency of the disturbance, t is the current timestamp, is random noise, conforming to the Gaussian distribution h t ~ N (0,s 2 ); The disturbance factor d t Add to the mapping matrix to generate a hardware signature matrix containing the perturbations: ; S14, generating a final dynamic unique identifier; Use nonlinear activation function to generate the final unique identifier UID t ; ; in, f is a non-linear activation function that maps the input to a specific range; is a high-dimensional feature matrix The value of row i and column j; is the exponential decay factor; n is the total number of rows of the high-dimensional feature matrix; m is the number of columns of the high-dimensional feature matrix; S2, multi-factor key generation mechanism; S3, layered challenge response mechanism; S4, high-dimensional abnormal behavior detection; S5. Multi-stage key update mechanism.
2. A method for protecting information security of power collection terminal equipment according to claim 1, characterized in that: The multi-factor key generation mechanism specifically includes: S21, generating seeds; Through the hash function and the unique identifier UID t Generate a key seed: ; S22, introducing environmental parameter disturbance; Use sensors to obtain environmental parameters; The sensors include a temperature sensor, a humidity sensor and a geographic location sensor; The environmental parameters include temperature, humidity and geographical location; Assume that the environmental parameter E t ={e1,e2,e3}, where the environmental parameters are specifically e1 for temperature, e2 for humidity, and e3 for geographic location; Calculate the disturbance coefficient D t As an environmental parameter, the effect on the key: ; in, is the norm of the environmental parameter vector, indicating the total amount of environmental parameters, is the time-dependent modulation frequency, t is the timestamp, For E t The i-th element in ; S23, generating a final key; Combined with key seed K seed and environmental disturbances D t Generate the final key: ; Among them, ⊕ represents the bitwise XOR operation, exp(-e i ) is the exponential decay of the environmental parameter, indicating that the influence of environmental factors on the key decreases over time. For E t The i-th element in .
3. A method for protecting information security of power collection terminal equipment according to claim 2, characterized in that: The layered challenge response mechanism specifically includes: S31, generate hierarchical challenges; S32, response calculation; Get the variables needed for response calculation; The variables include R t (i) and K final ; The R t (i) ={r t (i)j } is the i-th layer challenge data, r t (i)j is the jth component in the i-th layer of challenge data; K final The key generated jointly by the device and the authentication server is used for encryption and authentication processes; Use the response calculation formula to calculate the response value. The response calculation formula is: ; Among them, S t (i) is the response value of the i-th layer, indicating the response of the device according to the key and challenge data; cos(j) is the weighting factor, indicating the contribution weight of different positions in the challenge data; is the jth component of the i-th layer challenge data; is the key; S33, response verification; S34, Enhancement of the layered challenge verification process; The dynamic adjustment formula is: ; Among them, D t ={d it }, is the disturbance matrix, which represents the disturbance factor at time t; D t ' is the perturbation matrix dynamically adjusted according to the failure level i, used to generate the next challenge; α i To dynamically adjust the factor, control the weight of the disturbance during the challenge process; Dynamic challenge generation formula: ; Among them, R t (i+1) is the i+1th layer of challenge data, based on the dynamically adjusted perturbation matrix D t 'Generate new challenge data; M H is the hardware feature matrix of the device; () is a hash operation.
4. A method for protecting information security of power collection terminal equipment according to claim 3, characterized in that: The generation of layered challenges specifically includes: Get the variables needed for the stratification challenge; The variables specifically include: H , D t , i and t; The M H ={m ij } is the device hardware feature matrix, which represents the hardware information of the device. Each m ij is the jth component of the i-th hardware feature; D t ={d it } is the environmental disturbance matrix, which represents the disturbance value at timestamp t. it is the i-th perturbation factor, controlling the difficulty of challenge generation; i is the level index of the current challenge, indicating that the difficulty of the challenge increases; t is the timestamp, indicating the current time point, controlling the dynamic changes of the disturbance; Use the challenge generation formula to generate the challenge value of the challenge data. The challenge generation formula is: ; The R t (i) is the challenge data of the i-th layer, indicating the challenge value generated based on the device characteristics and disturbances; Hash(x) represents the hash operation on the data x to generate a challenge value of a fixed length; i·D t Denotes the perturbation matrix D t Impact on the current level i.
5. A method for protecting information security of power collection terminal equipment according to claim 4, characterized in that: The response verification specifically includes: S331, calculating the expected response value; ; Among them, S expected (i) The expected response value calculated by the authentication server, indicating the received challenge data R t (i) and key K final Calculated response; S332, response verification; ; Among them, S t (i) The response value calculated for the device; S expected (i) The expected response value calculated for the authentication server; Indicates the preset tolerance error threshold.
6. A method for protecting information security of power collection terminal equipment according to claim 5, characterized in that: The high-dimensional abnormal behavior detection specifically includes: Collect device behavior data and define the behavior data set as a matrix X : ; Among them, x mn is the nth feature of the mth behavior; Map the behavior data into a high-dimensional space to obtain a new feature matrix Y : ; Among them, W is the mapping matrix, s is the activation function, b is the bias term, and X T is the transpose of the data matrix X; Calculate the abnormality D(x) of each behavior data i ): ; Among them, y i is the result of the behavioral data projection, m Y is the mean of the behavioral data set, s Y is the standard deviation of the behavior data set, D(x i ) indicates the abnormality degree of the behavior data.
7. A method for protecting information security of power collection terminal equipment according to claim 6, characterized in that: The multi-stage key update mechanism specifically includes: S51, update factor calculation; Use dynamic unique identifier UID t and the disturbance d t Generate update factor U t : ; Among them, d t is a disturbance, UID t is a unique identifier, U t is the update factor; S52, update in stages; At each stage, the update factor U t Key K t To update: ; Among them, ⊕ represents the bitwise XOR operation, indicating the change of the key at each stage; S53, synchronizing the final key; At the end of the session, the keys K of all phases are t and update factor U t Perform synthesis to generate session keys: ; Among them, K session is the final session key and T is the number of key update phases.
8. A system using the information security protection method for power collection terminal equipment according to claim 7, characterized in that: include: Sensor module: temperature sensor, humidity sensor and geographic location sensor, wherein the temperature sensor is used to obtain temperature data, the humidity sensor is used to obtain humidity data, and the geographic location sensor is used to obtain device geographic location data; Session module: used for the session between the device and the authentication server; Computing module: used to perform data calculations.
Citation Information
Patent Citations
Lightweight Internet of Things equipment bidirectional authentication and secure communication method and system
CN117997516A
Smart card with enhanced security and implementation method thereof
CN118607019A
Encryption method and related equipment
CN119129003A
Biometric identification platform
US20190220583A1
Cited By
Sensing data chip-level dynamic key negotiation method
CN120433934A
Security detection method, system and device of Internet of Things equipment and medium
CN121173495A