Certificate transparency-based power grid certificate monitoring system and method, and electronic equipment
By introducing certificate transparency and blockchain technology into the power grid certificate management system, the certificate chain is generated and verified and stored in smart contracts, the problem of lack of real-time monitoring and audit of power grid certificate management is solved, real-time monitoring of certificates and detection of security threats is realized, and the security of the certificate system is improved.
Patent Information
- Application Number
- CN202311516485.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-16
AI Technical Summary
Traditional Internet certificate management methods are not suitable for power grid scenarios. The certificate management of power grid equipment lacks real-time monitoring and audit mechanisms, which is prone to exposure of the attack surface and is difficult to detect potential security threats such as unauthorized certificate issuance and certificate abuse.
Using a power grid certificate monitoring system based on certificate transparency, through the cooperation between the certificate authority CA server, certificate transparent CT server and Ethereum server, the certificate chain is generated and verified, the hash value is calculated and stored in a smart contract, real-time monitoring and audit of certificates is realized.
Real-time monitoring of the power grid system is realized, and it can audit the issuance and use of multi-level second certificates and the first certificate of power grid equipment, detect potential security threats in real time, and improve the security of the certificate system and data integrity.
Smart Images

Figure CN120017276A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security technology, and in particular relates to a power grid certificate monitoring system, method and electronic equipment based on certificate transparency. Background Art
[0002] Currently, there are many methods for protecting PKI (Public Key Infrastructure) and CA (Certificate Authority). For example, Jiangshan Yu et al. proposed DTKI (Distributed Transparent Key Infrastructure) to address CA security issues. They address the oligopoly of service providers and eliminate reliance on trusted parties. They also formalized the public log data structure and conducted a formal analysis of the security guarantees guaranteed by DTKI. Zhen Li et al. proposed a method for detecting suspected SSL man-in-the-middle attack hosts in the wild and discovered 322,831 forged certificates vulnerable to man-in-the-middle attacks. Maurizio Talamo et al. developed a consensus algorithm based on a blockchain technology. This algorithm retains all the functionality of X.509 certificates and demonstrates a mechanism for achieving rapid consensus. This allows consensus to be reached even if not all participating PKI members participate in the transaction, without requiring advanced trust protocols between PKIs.
[0003] CT (Certificate Transparency) is a technology proposed by Google that aims to protect users from erroneous or maliciously issued certificates by ensuring that domain name certificates in all Internet scenarios are recorded in a publicly auditable append-only log. CT logs are public, which means that anyone can monitor suspicious certificates or improper behavior of certificate authorities. The CT framework includes a Certificate Transparency log, which is a publicly auditable database that can only append certificates. In the context of power monitoring systems, Certificate Transparency logs can help system administrators, equipment managers, and researchers track and audit the issuance and use of certificates and detect potential security threats, such as unauthorized certificate issuance and certificate abuse.
[0004] However, traditional power grid scenarios differ significantly from internet scenarios, making traditional internet certificate management methods unsuitable for power grid scenarios. For example, power grid scenarios do not utilize traditional PKI key generation models; they instead utilize specialized cryptographic algorithms and infrastructure. Furthermore, the power grid's multi-level CAs operate within a strictly physically isolated local area network (LAN) environment, ensuring security solely through the system's employees, with no third-party monitoring or management. Furthermore, due to the importance of confidentiality and data privacy, power grids require multiple manual operations by administrators, exposing more attack surfaces than traditional internet certificate management, requiring monitoring and verification. Summary of the Invention
[0005] To address the above-mentioned problems in the prior art, the present invention provides a power grid certificate monitoring system, method, and electronic device based on certificate transparency. The technical problem to be solved by the present invention is achieved through the following technical solutions:
[0006] In a first aspect, the present invention provides a power grid certificate monitoring system based on certificate transparency, comprising:
[0007] A certificate authority (CA) server is configured to, upon receiving a request from a power grid device, sign an entity of the power grid device, generate a first certificate, send the first certificate to the power grid device, and upload a certificate chain including the first certificate to a Certificate Transparency (CT) server;
[0008] The CT server is configured to calculate a hash value based on the certificate information of the first certificate after the certificate chain passes verification, and upload the obtained CT log to the Ethereum server;
[0009] An Ethereum server, used to manage the CT log via a deployed smart contract.
[0010] In one embodiment of the present invention, the CA server includes n levels of CA organizations connected in sequence, each level of CA organization is used to issue a second certificate for its own next level CA organization, and the nth level CA organization is used to issue the first certificate for the power grid device, wherein multiple second certificates and the first certificate form a certificate chain.
[0011] In one embodiment of the present invention, the entity of the power grid device includes: an ID of the power grid device, a media access control address MAC address, a firmware version, and power consumption.
[0012] In one embodiment of the present invention, the certificate information of the first certificate includes the validity period and the public key copy of the first certificate.
[0013] In a second aspect, the present invention provides a method for monitoring power grid certificates based on certificate transparency, which is applied to the power grid certificate monitoring system based on certificate transparency described in the first aspect;
[0014] The method comprises:
[0015] In response to a request sent by the power grid device, signing an entity of the power grid device to generate a first certificate;
[0016] Sending the first certificate to a power grid device, and forming a certificate chain with the first certificate and a plurality of pre-generated second certificates;
[0017] Verifying the certificate chain, and when the certificate chain passes the verification, calculating a hash value based on the certificate information of the first certificate to obtain a CT log;
[0018] The CT log is managed using smart contracts.
[0019] In one embodiment of the present invention, before the step of signing the entity of the power grid device in response to a request sent by the power grid device and generating the first certificate, the step further includes:
[0020] Multiple second certificates are generated using the n-level CA organization in the CA server.
[0021] In one embodiment of the present invention, the step of generating multiple second certificates using the n-level CA organization in the CA server includes:
[0022] The 1st, 2nd, ..., n-1th level CA organizations respectively issue the second certificate to their own next-level CA organizations;
[0023] In response to a request sent by a power grid device, the step of signing an entity of the power grid device to generate a first certificate includes:
[0024] In response to the request sent by the power grid device, the n-th level CA organization signs the entity of the power grid device to generate a first certificate.
[0025] In one embodiment of the present invention, the certificate chain is verified according to the following steps:
[0026] Verify the first certificate issued by the n-th level CA and the second certificates issued by the n-1, n-2, ..., 1-th level CA in sequence;
[0027] When the first certificate issued by the n-th level CA organization and the second certificates issued by the n-1, n-2, ..., 1-th level CA organizations all pass verification, the certificate chain passes verification.
[0028] In a third aspect, the present invention further provides an electronic device comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0029] Memory for storing computer programs;
[0030] The processor is used to implement the method steps described in the second aspect when executing the program stored in the memory.
[0031] Compared with the prior art, the present invention has the following beneficial effects:
[0032] The present invention provides a power grid certificate monitoring system, method and electronic device based on certificate transparency, which introduces a certificate transparency log. By verifying the certificate chain and storing key certificate information in a specific security data structure, the system can realize real-time monitoring of the power grid system. At the same time, it can audit the issuance and use of multi-level second certificates and the first certificates of power grid equipment, and detect potential security threats in real time, such as unauthorized certificate issuance and certificate abuse.
[0033] In addition, to further ensure the security of the certificate system, the present invention also introduces the security technology of blockchain. Due to its consensus mechanism and hash function mechanism, blockchain can largely protect the integrity and real-time performance of data. By storing the certificate transparency log in a third-party secure data storage - smart contract, the security and trustworthiness of the CT server can be effectively monitored.
[0034] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is a structural diagram of a power grid certificate monitoring system based on certificate transparency provided by an embodiment of the present invention;
[0036] Figure 2 This is a flow chart of a method for monitoring power grid certificates based on certificate transparency provided by an embodiment of the present invention;
[0037] Figure 3 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0038] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.
[0039] Figure 1 This is a structural diagram of a power grid certificate monitoring system based on certificate transparency provided by an embodiment of the present invention. Figure 1As shown, an embodiment of the present invention provides a power grid certificate monitoring system based on certificate transparency, including:
[0040] A certificate authority (CA) server is configured to, upon receiving a request from a power grid device, sign an entity of the power grid device, generate a first certificate, send the first certificate to the power grid device, and upload a certificate chain including the first certificate to a Certificate Transparency (CT) server;
[0041] The CT server is configured to calculate a hash value based on the certificate information of the first certificate after the certificate chain passes verification, and upload the obtained CT log to the Ethereum server;
[0042] Ethereum server for managing CT logs via deployed smart contracts.
[0043] In this embodiment, the certificate transparency-based power grid certificate monitoring system consists of a CA server, a CT server, and an Ethereum server. Specifically, the CA server uses a key generated by a key generation machine independently managed by the power grid to sign the entity of the power grid device and generate a first certificate. Certificate auditing and monitoring play a key role in power grid protection. Certificates, issued by a certificate authority, ensure the trustworthiness of power equipment. This is particularly important in the power grid because valid digital certificates can prevent cyber attackers from masquerading as legitimate nodes or power equipment, thereby protecting power grid equipment, data, and control instructions from tampering or interception.
[0044] Next, the CA server uploads the obtained certificate chain to the CT server; wherein the certificate chain includes the first certificate and multiple second certificates previously generated by the CA server.
[0045] The CT server collects and verifies the certificate chain issued by the CA server. If the certificate chain passes the verification, it calculates the hash value based on the certificate information of the first certificate and stores it in its own data structure to obtain the CT log. The user can query the first certificate by calling the interface. It should be understood that the purpose of CT is to protect users from erroneous or maliciously issued certificates by ensuring that domain name certificates in all Internet scenarios are recorded in a publicly auditable append-only log. The CT log is public and available for public audit and monitoring, that is, anyone can monitor suspicious certificates or improper behavior of certificate issuing authorities. Typically, the CT framework includes a CT log, which is a publicly auditable database that can only append certificates. In the context of power monitoring systems, the CT log can help system administrators, equipment managers, and researchers track and audit the issuance and use of certificates and detect potential security threats, such as unauthorized certificate issuance and certificate abuse.
[0046] Afterwards, the CT server uploads the CT log to the Ethereum server. A smart contract is deployed in the Ethereum server, which stores the CT log in the Ethereum server, achieving the goal of data decentralization and ensuring that the certificate transparency log is intact and cannot be tampered with.
[0047] Of course, in some other embodiments of the present application, the administrator may also use automated detection algorithms to verify and manage the integrity and non-tampering of certificate logs. For example, the administrator may use CT logs as a data set to extract key information about power grid equipment and certificate chains, and use machine learning algorithms to generate a model that can automatically detect forged certificates.
[0048] Exemplarily, the entities of the power grid device include: the ID, MAC address, firmware version, and power consumption of the power grid device, and the certificate information of the first certificate includes the validity period and public key copy of the first certificate.
[0049] Optionally, the CA server includes n levels of CA organizations connected in sequence, each level of CA organization is used to issue a second certificate for its own next level CA organization, and the nth level CA organization is used to issue a first certificate for the power grid device, wherein the multiple second certificates and the first certificate form a certificate chain.
[0050] Specifically, in this embodiment, the CA server includes n-level CA agencies, among which the first-level CA agency is the root CA agency and the rest are sub-CA agencies. In the process of generating a certificate chain, the root CA agency starts and first issues a second certificate to the second-level CA agency, then the second-level CA agency issues a second certificate to the third-level CA agency, and the third-level CA agency issues a second certificate to the fourth-level CA agency... and so on. After the 1st to n-1th-level CA agencies have issued multiple second certificates, the nth-level CA agency responds to the request of the power grid device and issues a first certificate to the power grid device. The first certificate and all the second certificates form a certificate chain.
[0051] Figure 2 This is a flow chart of a method for monitoring power grid certificates based on certificate transparency provided by an embodiment of the present invention. Figure 2 The embodiment of the present invention further provides a method for monitoring power grid certificates based on certificate transparency, which is applied to the above-mentioned power grid certificate monitoring system based on certificate transparency;
[0052] The method includes:
[0053] S201. In response to a request sent by a power grid device, sign an entity of the power grid device to generate a first certificate;
[0054] S202: Send the first certificate to the power grid device, and form a certificate chain with the first certificate and a plurality of pre-generated second certificates;
[0055] S203: Verify the certificate chain, and when the certificate chain passes the verification, calculate a hash value based on the certificate information of the first certificate to obtain a CT log;
[0056] S204. Use smart contracts to manage CT logs.
[0057] It should be noted that, in step S202 , the first certificate may also be manually imported into the power grid device by the user.
[0058] Optionally, before the step of signing the entity of the power grid device in response to the request sent by the power grid device and generating the first certificate, the method further includes:
[0059] Multiple second certificates are generated using the n-level CA organization in the CA server.
[0060] Specifically, the step of generating multiple second certificates using the n-level CA organization in the CA server includes:
[0061] The 1st, 2nd, ..., n-1th level CA organizations respectively issue the second certificate to their own next level CA organizations.
[0062] In this embodiment, the CA server includes n-level CA organizations as an example, where the first-level CA organization is the root CA organization and the rest are sub-CA organizations. When generating the second certificate, it starts with the root CA organization. The root CA organization first issues the second certificate to the second-level CA organization, and then the second-level CA organization issues the second certificate to the third-level CA organization, and the third-level CA organization issues the second certificate to the fourth-level CA organization... and so on, until the 1st to n-1-level CA organizations have issued multiple second certificates.
[0063] Furthermore, in step S201, in response to the request sent by the power grid device, the step of signing the entity of the power grid device and generating a first certificate includes:
[0064] In response to the request sent by the power grid device, the n-th level CA organization signs the entity of the power grid device to generate a first certificate.
[0065] In this embodiment, the nth-level CA organization signs the entities of the grid device, such as the ID, MAC address, firmware version, and power consumption of the grid device, in response to the request of the grid device. The generated first certificate forms a certificate chain with all second certificates.
[0066] Optionally, the above-mentioned power grid certificate monitoring method based on certificate transparency verifies the certificate chain according to the following steps:
[0067] Verify the first certificate issued by the n-th level CA and the second certificates issued by the n-1, n-2, ..., 1-th level CA in sequence;
[0068] When the first certificate issued by the n-th level CA organization and the second certificates issued by the n-1th, n-2th, ..., 1st level CA organizations all pass verification, the certificate chain passes verification.
[0069] It should be noted that the certificate chain verification process is the reverse of the generation process. That is, the first certificate is verified, followed by the second certificate issued by the n-1, n-2, ..., 1st-level CA. The present invention uses a Certificate Transparency log to monitor the security and validity of multiple levels of certificate authorities and certificates by verifying the complete certificate chain and storing key certificate information in a specific secure data structure. Furthermore, considering that CT servers cannot fully guarantee the security of the certificate system, the present invention further utilizes Ethereum smart contract technology to monitor the security and trustworthiness of the Certificate Transparency log server by storing the Certificate Transparency log in a third-party secure data store—a smart contract. Furthermore, the present invention uses a machine learning anomaly detection algorithm to proactively detect suspicious certificates.
[0070] The embodiment of the present invention further provides an electronic device, such as Figure 3 As shown, it includes a processor 301, a communication interface 302, a memory 303 and a communication bus 304, wherein the processor 301, the communication interface 302, and the memory 303 communicate with each other through the communication bus 304.
[0071] Memory 303, for storing computer programs;
[0072] The processor 301 is configured to execute the program stored in the memory 303, and implement the following steps:
[0073] In response to a request sent by the power grid device, signing an entity of the power grid device to generate a first certificate;
[0074] Sending the first certificate to a power grid device, and forming a certificate chain with the first certificate and a plurality of pre-generated second certificates;
[0075] Verifying the certificate chain, and when the certificate chain passes the verification, calculating a hash value based on the certificate information of the first certificate to obtain a CT log;
[0076] The CT log is managed using smart contracts.
[0077] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0078] The communication interface is used for communication between the above electronic device and other devices.
[0079] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.
[0080] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0081] The method provided in the embodiments of the present invention can be applied to electronic devices. Specifically, the electronic devices can be desktop computers, portable computers, smart mobile terminals, servers, etc. This is not limited here; any electronic device that can implement the present invention falls within the scope of protection of the present invention.
[0082] As for the device / electronic device / storage medium embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0083] It should be noted that the device, electronic device and storage medium of the embodiments of the present invention are respectively the device, electronic device and storage medium for applying the above-mentioned power grid certificate monitoring method based on certificate transparency. All embodiments of the above-mentioned power grid certificate monitoring method based on certificate transparency are applicable to the device, electronic device and storage medium, and can achieve the same or similar beneficial effects.
[0084] By using the terminal device provided by the embodiment of the present invention, proper nouns and / or fixed phrases can be displayed for user selection, thereby reducing user input time and improving user experience.
[0085] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "multiple" is two or more, and unless otherwise clearly specified, the description with specific reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification.
[0086] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims.
[0087] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, and all of these should be considered to fall within the scope of protection of the present invention.
Claims
1. A power grid certificate monitoring system based on certificate transparency, characterized in that: include: A certificate authority CA server is used to sign the entity of the power grid device after receiving a request from the power grid device, generate a first certificate, send the first certificate to the power grid device, and upload the certificate chain including the first certificate to the certificate transparency CT server; The CT server is used to calculate a hash value based on the certificate information of the first certificate after the certificate chain passes the verification, and upload the obtained CT log to the Ethereum server; An Ethereum server for managing the CT logs via deployed smart contracts.
2. The power grid certificate monitoring system based on certificate transparency according to claim 1 is characterized in that: The CA server includes n levels of CA organizations connected in sequence, each level of CA organization is used to issue a second certificate for its own next level of CA organization, and the nth level CA organization is used to issue the first certificate for the power grid device, wherein a plurality of the second certificates and the first certificate form a certificate chain.
3. The power grid certificate monitoring system based on certificate transparency according to claim 1 is characterized in that: The entities of the power grid device include: an ID of the power grid device, a media access control address MAC address, a firmware version and power consumption.
4. The power grid certificate monitoring system based on certificate transparency according to claim 3 is characterized in that: The certificate information of the first certificate includes the validity period and the public key copy of the first certificate.
5. A power grid certificate monitoring method based on certificate transparency, characterized in that: Applicable to the power grid certificate monitoring system based on certificate transparency as described in any one of claims 1 to 4; The method comprises: In response to a request sent by a power grid device, signing an entity of the power grid device to generate a first certificate; Sending the first certificate to a power grid device, and forming a certificate chain with the first certificate and a plurality of pre-generated second certificates; Verifying the certificate chain, and when the certificate chain passes the verification, calculating a hash value based on the certificate information of the first certificate to obtain a CT log; The CT log is managed using smart contracts.
6. The method for monitoring power grid certificates based on certificate transparency according to claim 5, characterized in that: In response to a request sent by a power grid device, before the step of signing an entity of the power grid device and generating a first certificate, the step further includes: Multiple second certificates are generated using the n-level CA organization in the CA server.
7. The method for monitoring power grid certificates based on certificate transparency according to claim 6, characterized in that: The step of generating a plurality of second certificates by using the n-level CA organization in the CA server includes: The 1st, 2nd, ..., n-1th level CA organizations respectively issue the second certificate to their own next level CA organizations; In response to a request sent by a power grid device, the step of signing an entity of the power grid device to generate a first certificate includes: In response to the request sent by the power grid device, the nth-level CA organization signs the entity of the power grid device to generate a first certificate.
8. The method for monitoring power grid certificates based on certificate transparency according to claim 7, characterized in that: Follow the steps below to verify the certificate chain: Verify the first certificate issued by the nth level CA and the second certificates issued by the n-1th, n-2th, ..., 1st level CAs in turn; When the first certificate issued by the n-th level CA agency and the second certificates issued by the n-1, n-2, ..., 1-th level CA agencies all pass the verification, the certificate chain passes the verification.
9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing any of the methods described in claims 5-8 when executing a program stored in a memory.
Citation Information
Cited By
Automatic revoking method, device and equipment for abnormal digital certificate based on CT log, storage medium and program product
CN121261900A
Abnormal digital certificate automatic revocation method and device based on CT log, equipment, storage medium and program product
CN121261900B