Power system hierarchical authentication method and system based on block chain and zero-knowledge proof

By adopting a hierarchical authentication method with blockchain and zero-knowledge proof technology in power systems, the complexity and inefficiency of traditional authentication methods in multi-level permission management and cross-trust domain authentication is solved, and efficient and secure device authentication and data exchange are achieved.

CN120030522AActive Publication Date: 2025-05-23STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST +1

Patent Information

Application Number
CN202510496263.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-05-23
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

Traditional power system authentication methods have complexity and inefficiency in multi-level permission management and cross-trust domain authentication, which is difficult to adapt to the needs of diversified equipment and dynamic changes in modern power systems.

Method used

The power system hierarchical authentication method based on blockchain and zero-knowledge proof is adopted, and the device's identity verification is realized through blockchain technology storing the registration information of the device and zero-knowledge proof technology. A multi-level permission authentication mechanism is designed to ensure secure data exchange between devices.

Benefits of technology

It improves the security and efficiency of cross-trust domain authentication, solves the complexity and inefficiency of traditional authentication methods in multi-level permission management, and realizes the transparency and immutability of device authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030522A_ABST
    Figure CN120030522A_ABST
Patent Text Reader

Abstract

The invention discloses a power system hierarchical authentication method and system based on a block chain and zero-knowledge proof. The method comprises a power equipment registration stage, a mutual authentication process of power equipment in the same trust domain and a cross-trust-domain power equipment authentication process. According to the importance and authority levels of equipment and users, a multi-level authority authentication method is designed, a block chain technology and a zero-knowledge proof technology are introduced, a hierarchical authentication mechanism is realized, the problems of complexity and low efficiency of a traditional authentication method in multi-level authority management are solved, and the authentication efficiency is improved. And the security and efficiency of cross-trust domain authentication are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power system analysis, and in particular to a power system hierarchical authentication method and system based on blockchain and zero-knowledge proof. Background Art

[0002] As a key infrastructure of modern society, the power system carries the power supply for industrial production, commercial activities and daily life, and is an important pillar to ensure the stable operation of society. As the intelligentization process of the power system continues to accelerate, a large number of smart devices and Internet of Things technologies have been introduced into the power system, greatly improving the efficiency of power production, transmission and distribution. However, the interconnection and interoperability of these devices also brings significant security challenges, especially in the authentication of devices in different permission domains in permission management, which is a key strategic link because it ensures the security of information and operations to ensure the safe and stable operation of the system.

[0003] Traditional power system authentication methods usually rely on centralized authentication servers. This centralized architecture often becomes a performance bottleneck when a large number of devices initiate authentication requests at the same time, resulting in delays in the authentication process, which in turn affects the real-time performance of the system. In addition, the database storage method of the centralized server is difficult to effectively prevent data from being tampered with when dealing with large amounts of data and frequent data exchanges, thus affecting the integrity and reliability of the data. Traditional authentication methods also have problems of complexity and inefficiency in multi-level authority management and cross-trust domain authentication, and are difficult to adapt to the diverse and dynamically changing needs of equipment in modern power systems. Summary of the invention

[0004] The present invention provides a power system hierarchical authentication method and system based on blockchain and zero-knowledge proof, which are used to solve the technical problems of complexity and low efficiency in multi-level authority management and cross-trust domain authentication.

[0005] In a first aspect, the present invention provides a power system hierarchical authentication method based on blockchain and zero-knowledge proof, comprising: When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ; equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device First Pseudo-Identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

[0006] In a second aspect, the present invention provides a power system hierarchical authentication system based on blockchain and zero-knowledge proof, comprising: Processing module, configured as a device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ; The first verification module is configured as a device According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; The second verification module is configured as a device Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

[0007] According to a third aspect, an electronic device is provided, comprising: at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can perform the steps of the power system hierarchical authentication method based on blockchain and zero-knowledge proof according to any embodiment of the present invention.

[0008] In a fourth aspect, the present invention also provides a computer-readable storage medium having a computer program stored thereon. When the program instructions are executed by a processor, the processor executes the steps of the power system hierarchical authentication method based on blockchain and zero-knowledge proof according to any embodiment of the present invention.

[0009] The electric power system hierarchical authentication method and system based on blockchain and zero-knowledge proof in this application designs a multi-level authority authentication method according to the importance and authority level of equipment and users, introduces blockchain technology and zero-knowledge proof technology, and realizes a hierarchical authentication mechanism, which not only solves the complexity and inefficiency of traditional authentication methods in multi-level authority management, but also greatly improves the security and efficiency of cross-trust domain authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0011] Figure 1 A flowchart of a power system hierarchical authentication method based on blockchain and zero-knowledge proof provided by an embodiment of the present invention; Figure 2 A structural block diagram of a power system hierarchical authentication system based on blockchain and zero-knowledge proof provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0012] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0013] See also Figure 1 , which shows a flowchart of a power system hierarchical authentication method based on blockchain and zero-knowledge proof of the present application.

[0014] like Figure 1 As shown, the power system hierarchical authentication method based on blockchain and zero-knowledge proof specifically includes the following steps: Step S101, when the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Make up a reply , and send a reply Give equipment .

[0015] Step S102, equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device First Pseudo-Identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Authentication failed.

[0016] Step S103, equipment Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

[0017] It should be noted that in the device With equipment After mutual authentication is successful, the device The first pseudo-identity and equipment Second pseudo-identity Make a session key generation request , and generate a session key request Sent to the central processing system CPS, the central processing system CPS receives the session key generation request Then generate a random number n, and then according to the random number n, the first pseudo identity , Second Fake Identity Generate Devices With equipment The session key between , then the central processing system CPS equipment The public key The session key is encrypted using the encryption algorithm E. Encrypt and obtain the encrypted session key , after which the central processing system CPS will encrypt the session key Send to device ,equipment Use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , while the device The second session key and the corresponding second pseudo-identity Record to local storage, then the device Use equipment The public key The session key is encrypted using the encryption algorithm E. Encrypt and obtain the second encrypted session key , then the device The second encrypted session key Send to device ,equipment Receive the second encrypted session key Post-use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , the last device The second session key And the corresponding first pseudo-identity Record to local storage.

[0018] The method of this embodiment, by establishing a hierarchical trust domain, can assign devices to different security levels according to their permissions and sensitivity, effectively isolating potential security risks. A cross-trust domain authentication method is designed to further ensure secure data exchange between devices, maintaining a high degree of security and privacy even between different trust levels. The immutability of blockchain technology and the privacy protection characteristics of zero-knowledge proof ensure the transparency and immutability of all transactions and operations, providing a safe, reliable and private protection mechanism for the power system. The zero-knowledge proof method allows devices to prove their identity and permissions without leaking any sensitive information. In summary, this hierarchical authentication method based on blockchain and zero-knowledge proof provides a new solution for the power system, which can effectively improve the security and efficiency of equipment authentication in modern power systems.

[0019] In a specific embodiment, the electric power equipment is registered as follows: equipment Note Before sending a registration request to the central processing system CPS, The identity problem to be proved is converted into an arithmetic circuit C, and then the arithmetic circuit C and the security parameter Enter into Setup to generate a certification key and verification key , and then the proof key of the identity to be proved , Public Statement and witnesses Input into the proof operation to generate a zero-knowledge proof ,in, It is a unary representation used to pass relevant information about security parameters. Indicates that through the Setup operation, the proof key and verification key for the zero-knowledge proof process are generated based on the security parameters and arithmetic circuit.

[0020] equipment The device The first pseudo-identity , public key and zero-knowledge proof Form a registration tuple ,equipment Send a registration tuple to the central processing system CPS To generate a registration request, the central processing system CPS receives the registration tuple After that, verify the first pseudo-identity received Whether to repeat, if the first pseudo identity If it is repeated, the registration request will be rejected; After successful verification, the central processing system CPS will record the device on the blockchain. Create a target node and register the tuple Stored in the target node, the device The first pseudo-identity Associated with the target node’s account address, finally, the central processing system CPS returns a reply Give equipment , to inform the device Registration is complete.

[0021] In another specific embodiment, the power devices in the same trust domain authenticate each other, specifically: When the device When domain authentication is required, the device The device The first pseudo-identity Send to the central processing system CPS to form a certification request ; The Central Processing System (CPS) receives a certification request Then, according to the first pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the central processing system CPS will first pseudo identity Perform zero-knowledge proof authentication and pass the first verification key First public statement and the first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment After successful authentication, the central processing system CPS uses the first pseudo-identity Importance of equipment Assigning permission levels After the allocation is completed, the first pseudo identity and permission levels Recorded in local storage, the central processing system CPS sends a reply authentication reply Give equipment .

[0022] Specifically, the central processing system CPS is based on the authority level The trust domain is defined into three levels, namely: Advanced trust domain ; Intermediate trust domain ; Low-level trust domain .

[0023] The method of this application can achieve the following technical effects: (1) Adapt to multi-level cross-trust domain scenarios: According to the device's permission level, the device is assigned to different trust domains (high-level trust domain, intermediate trust domain, and low-level trust domain). Each trust domain has its own unique security requirements and access permission settings. In this way, devices of different levels can operate securely in their respective trust domains. When a device needs to make a cross-trust domain request, the legitimacy and security of the cross-trust domain request are ensured by exchanging zero-knowledge proofs and a two-way authentication process.

[0024] (2) Efficient authentication and communication: During the registration and authentication process, the device can quickly authenticate itself through the pre-generated proof key and verification key, which reduces manual intervention and improves authentication efficiency. After successful cross-trust domain authentication, the central processing system generates a session key and transmits the session key through the device's public key encryption to ensure the secure transmission and storage of the session key. The use of session keys ensures the efficiency and security of communication between devices.

[0025] (3) Distributed node fast authentication: The present invention uses blockchain technology to store the device's registration information on the blockchain, so that any blockchain node can quickly access and verify the device's registration information. This decentralized storage method eliminates the risk of single point failure and improves the reliability and efficiency of authentication. Through zero-knowledge proof technology, devices can quickly generate and verify identity proofs without transmitting sensitive information, reducing communication overhead and delays during the authentication process.

[0026] (4) Implementing resource access restrictions: After successful device authentication, different permission levels are assigned to control resource access based on the permission levels. Devices in high-level trust domains can access more sensitive and important resources, while the access rights of devices in low-level trust domains are strictly restricted. When accessing within a domain, devices can only access resources permitted by their permission level; when communicating across trust domains, the enhanced cross-trust domain authentication process ensures that each communication is carried out under the premise of being controllable and compliant with policies, further ensuring the security of resources.

[0027] (5) Ensure system security: Through zero-knowledge proof technology, identity authentication is performed without leaking sensitive device information, which greatly improves the privacy protection level of the device and prevents information leakage and identity forgery.

[0028] See also Figure 2 , which shows a structural block diagram of a power system hierarchical authentication system based on blockchain and zero-knowledge proof in the present application.

[0029] like Figure 2 As shown, the power system hierarchical authentication system 200 includes a processing module 210 , a first verification module 220 and a second verification module 230 .

[0030] The processing module 210 is configured to When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Make up a reply , and send a reply Give equipment ; The first verification module 220 is configured as a device According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device First Pseudo-Identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; The second verification module 230 is configured as a device Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

[0031] It should be understood that Figure 2 Modules and references documented in Figure 1 Therefore, the operations and features described above for the method and the corresponding technical effects are also applicable to Figure 2 The modules in it will not be described in detail here.

[0032] In other embodiments, embodiments of the present invention further provide a computer-readable storage medium having a computer program stored thereon, wherein when the program instructions are executed by a processor, the processor executes the power system hierarchical authentication method based on blockchain and zero-knowledge proof in any of the above method embodiments; As an implementation mode, the computer-readable storage medium of the present invention stores computer-executable instructions, and the computer-executable instructions are configured as follows: When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Make up a reply , and send a reply Give equipment ; equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device First Pseudo-Identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

[0033] The computer-readable storage medium may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the power system hierarchical authentication system based on blockchain and zero-knowledge proof, etc. In addition, the computer-readable storage medium may include a high-speed random access memory, and may also include a memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the computer-readable storage medium may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the power system hierarchical authentication system based on blockchain and zero-knowledge proof via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0034] Figure 3 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention, such as Figure 3 As shown, the device includes: a processor 310 and a memory 320. The electronic device may also include: an input device 330 and an output device 340. The processor 310, the memory 320, the input device 330 and the output device 340 may be connected via a bus or other means. Figure 3 In the example, the connection through the bus is taken as an example. The memory 320 is the computer-readable storage medium mentioned above. The processor 310 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions and modules stored in the memory 320, that is, the power system hierarchical authentication method based on blockchain and zero-knowledge proof of the above method embodiment is implemented. The input device 330 can receive input digital or character information, and generate key signal input related to user settings and function control of the power system hierarchical authentication system based on blockchain and zero-knowledge proof. The output device 340 may include display devices such as display screens.

[0035] The electronic device can execute the method provided by the embodiment of the present invention, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not described in detail in this embodiment, please refer to the method provided by the embodiment of the present invention.

[0036] As an implementation mode, the electronic device is applied to a power system hierarchical authentication system based on blockchain and zero-knowledge proof, and is used for a client, and includes: at least one processor; and a memory connected to the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can: When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Make up a reply , and send a reply Give equipment ; equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device First Pseudo-Identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive the authentication reply After that, according to the second pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , and then the device Will perform zero-knowledge proof authentication on the second pseudo-identity , and will use the device 's second verification key , the device 's second public statement and the device 's second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the obtained second verification result Indicates that the device Verification is successful. On the contrary, when the obtained second verification result Indicates that the device Verification fails.

[0037] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments.

[0038] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.

Claims

1. A power system hierarchical authentication method based on blockchain and zero-knowledge proof, characterized in that: include: When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ; equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

2. According to claim 1, a power system hierarchical authentication method based on blockchain and zero-knowledge proof is characterized in that: The method further comprises: Registration of power equipment, specifically: equipment Note Before sending a registration request to the central processing system CPS, The identity problem to be proved is converted into an arithmetic circuit C, and then the arithmetic circuit C and the security parameter Enter into Setup to generate a certification key and verification key , and then the proof key of the identity to be proved , Public Statement and witnesses Input into the proof operation to generate a zero-knowledge proof ; equipment The device The first pseudo-identity , public key and zero-knowledge proofs Form a registration tuple ,equipment Send a registration tuple to the central processing system CPS To generate a registration request, the central processing system CPS receives the registration tuple After that, verify the first pseudo-identity received Repeat or not, if the first pseudo identity If it is repeated, the registration request will be rejected; After successful verification, the central processing system CPS will record the device on the blockchain. Create a target node and register the tuple Stored in the target node, the device The first pseudo-identity Associated with the target node’s account address, finally, the central processing system CPS returns a reply Give equipment , to inform the device Registration is complete.

3. According to claim 1, a power system hierarchical authentication method based on blockchain and zero-knowledge proof is characterized in that: The method further comprises: Power equipment in the same trust domain authenticates each other, specifically: When the device When domain authentication is required, the device The device The first pseudo-identity Send to the central processing system CPS to form a certification request ; The Central Processing System (CPS) receives a certification request Then, according to the first pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the central processing system CPS will first pseudo identity Perform zero-knowledge proof authentication and pass the first verification key First public statement and the first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment After successful authentication, the central processing system CPS uses the first pseudo-identity Importance of equipment Assigning permission levels After the allocation is completed, the first pseudo identity and permission levels Recorded in local storage, the central processing system CPS sends a reply authentication reply Give equipment .

4. According to claim 1, a power system hierarchical authentication method based on blockchain and zero-knowledge proof is characterized in that: in, On the device With equipment After mutual authentication is successful, the method includes: The device The first pseudo-identity and equipment Second pseudo-identity Make a session key generation request , and generate a session key request Sent to the central processing system CPS, the central processing system CPS receives the session key generation request Then generate a random number n, and then according to the random number n, the first pseudo identity , Second Fake Identity Generate Devices With equipment The session key between , then the central processing system CPS equipment The public key The session key is encrypted using the encryption algorithm E. Encrypt and obtain the encrypted session key , after which the central processing system CPS will encrypt the session key Send to device ,equipment Use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , while the device The second session key and the corresponding second pseudo-identity Record to local storage, then the device Use equipment The public key The session key is encrypted using the encryption algorithm E. Encrypt and obtain the second encrypted session key , then the device The second encrypted session key Send to device ,equipment Receive the second encrypted session key Post-use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , the last device The second session key And the corresponding first pseudo-identity Record to local storage.

5. A power system hierarchical authentication system based on blockchain and zero-knowledge proof, characterized in that: include: Processing module, configured as a device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Make a cross-trust domain request , then the device Cross-trust domain requests Sent to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ; The first verification module is configured as a device According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of a certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and send the device The first verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; The second verification module is configured as a device Authentication successful device After that, the equipment Send Reply Certified Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and send the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.

Citation Information

Patent Citations

  • Block chain-based trusted cross-domain identity authentication method and device

    CN116744297A

  • Zero-knowledge proof and cross-chain based access control method and system and storage medium

    CN116800435A

  • Identity authentication method and system based on block chain and zero-knowledge proof

    CN118646540A

  • Cross-domain authentication method based on zero-knowledge proof

    CN119449283A

  • Apparatus and system for zero-knowledge proof performed in multi-party computation

    US20220329432A1

Cited By

  • Internet of Things equipment authentication and access control method for zero trust

    CN120281585A