Power system hierarchical authentication method and system based on blockchain and zero-knowledge proof
Through blockchain and zero-knowledge proof technology, the power system hierarchical authentication method is designed, which solves the complexity and inefficiency of traditional power system authentication methods in multi-level permission management and cross-trust domain authentication, and realizes efficient and secure device authentication and resource access control.
Patent Information
- Application Number
- CN202510496263.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-04-21
AI Technical Summary
Traditional power system authentication methods have complexity and inefficiency problems in multi-level permission management and cross-trust domain authentication, and centralized architecture leads to performance bottlenecks and data integrity risks.
Blockchain and zero-knowledge proof technology are adopted to design a hierarchical authentication mechanism, and the fast and secure authentication of devices across trust domains is achieved through pseudo-identity authentication and verification algorithms. The immutability of blockchain and the privacy protection characteristics of zero-knowledge proof are utilized to ensure the transparency and security of device identity and permissions.
It improves the security and efficiency of device authentication, adapts to multi-level permission management, ensures the security and privacy of cross-trust domain communication, reduces authentication delay and communication overhead, and achieves efficient resource access control.
Smart Images

Figure CN120030522B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power system analysis, and in particular relates to a power system hierarchical authentication method and system based on blockchain and zero-knowledge proof. Background Art
[0002] As critical infrastructure in modern society, the power system provides electricity for industrial production, commercial activities, and daily life, and is a vital pillar for ensuring the stable operation of society. As the intelligentization of power systems continues to accelerate, a large number of smart devices and IoT technologies have been introduced into the power system, greatly improving the efficiency of power production, transmission, and distribution. However, the interconnection and interoperability of these devices also pose significant security challenges. In particular, authentication between devices in different permission domains is a key strategic component in permission management, as it ensures the security of information and operations, thereby ensuring the safe and stable operation of the system.
[0003] Traditional power system authentication methods typically rely on centralized authentication servers. This centralized architecture often becomes a performance bottleneck when faced with a large number of devices simultaneously initiating authentication requests, leading to delays in the authentication process and, in turn, impacting the system's real-time performance. Furthermore, centralized server database storage methods struggle to effectively prevent data tampering when handling large volumes of data and frequent data exchange, compromising data integrity and reliability. Traditional authentication methods also suffer from complexity and inefficiencies in multi-level permission management and cross-trust domain authentication, making them difficult to adapt to the diverse and dynamic demands of modern power systems. Summary of the Invention
[0004] The present invention provides a power system hierarchical authentication method and system based on blockchain and zero-knowledge proof, which are used to solve the technical problems of complexity and low efficiency in multi-level authority management and cross-trust domain authentication.
[0005] In a first aspect, the present invention provides a power system hierarchical authentication method based on blockchain and zero-knowledge proof, comprising:
[0006] When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ;
[0007] equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed;
[0008] equipment Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
[0009] In a second aspect, the present invention provides a power system hierarchical authentication system based on blockchain and zero-knowledge proof, comprising:
[0010] Processing module, configured as a device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ;
[0011] The first verification module is configured as a device According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed;
[0012] The second verification module is configured as a device Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
[0013] According to a third aspect, an electronic device is provided, comprising: at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can perform the steps of the power system hierarchical authentication method based on blockchain and zero-knowledge proof according to any embodiment of the present invention.
[0014] In a fourth aspect, the present invention also provides a computer-readable storage medium having a computer program stored thereon. When the program instructions are executed by a processor, the processor executes the steps of the power system hierarchical authentication method based on blockchain and zero-knowledge proof of any embodiment of the present invention.
[0015] The power system hierarchical authentication method and system based on blockchain and zero-knowledge proof in this application designs a multi-level authority authentication method according to the importance and authority level of equipment and users, introduces blockchain technology and zero-knowledge proof technology, and realizes a hierarchical authentication mechanism, which not only solves the complexity and inefficiency problems of traditional authentication methods in multi-level authority management, but also greatly improves the security and efficiency of cross-trust domain authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0017] Figure 1 A flowchart of a power system hierarchical authentication method based on blockchain and zero-knowledge proof provided in one embodiment of the present invention;
[0018] Figure 2 A block diagram of a hierarchical authentication system for a power system based on blockchain and zero-knowledge proof, provided in accordance with an embodiment of the present invention;
[0019] Figure 3 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0021] See also Figure 1 , which shows a flowchart of a power system hierarchical authentication method based on blockchain and zero-knowledge proof in this application.
[0022] like Figure 1 As shown in FIG, the power system hierarchical authentication method based on blockchain and zero-knowledge proof specifically includes the following steps:
[0023] Step S101: When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment .
[0024] Step S102, equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Authentication failed.
[0025] Step S103, equipment Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
[0026] It should be noted that in the device With equipment After mutual authentication is successful, the device The first pseudo-identity and equipment Second pseudo-identity Form a session key generation request , and generate a session key request Sent to the central processing system CPS, the central processing system CPS receives the session key generation request Then generate a random number n, and then according to the random number n, the first pseudo identity , Second fake identity Generate Devices With equipment The session key between , then the central processing system CPS equipment Public key The session key is encrypted using the encryption algorithm E Encrypt and obtain the encrypted session key , then the central processing system CPS will encrypt the session key Send to device ,equipment Use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , while the device The second session key and the corresponding second pseudo-identity Record to local storage, then the device Use equipment Public key The session key is encrypted using the encryption algorithm E Encrypt and obtain the second encrypted session key , then the device The second encrypted session key Send to device ,equipment Receive the second encrypted session key Post-use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , the last device The second session key And the corresponding first pseudo-identity Record to local storage.
[0027] The method of this embodiment, by establishing a hierarchical trust domain, can assign devices to different security levels according to their permissions and sensitivity, effectively isolating potential security risks. A cross-trust domain authentication method is designed to further ensure secure data exchange between devices, maintaining a high degree of security and privacy even between different trust levels. The immutability of blockchain technology and the privacy protection characteristics of zero-knowledge proof ensure the transparency and immutability of all transactions and operations, providing a safe, reliable and private protection mechanism for the power system. The zero-knowledge proof method allows devices to prove their identity and permissions without leaking any sensitive information. In summary, this hierarchical authentication method based on blockchain and zero-knowledge proof provides a new solution for the power system, which can effectively improve the security and efficiency of equipment authentication in modern power systems.
[0028] In a specific embodiment, the registration of the electric power equipment is as follows:
[0029] equipment Note Before sending a registration request to the Central Processing System (CPS), The identity problem to be proved is converted into an arithmetic circuit C, and then the arithmetic circuit C and the security parameter Enter into the Setup operation to generate a certification key and verification key , and then the proof key of the identity to be proved , Public Statement and witnesses Input into the proof operation to generate a zero-knowledge proof ,in, It is a unary representation used to pass relevant information about security parameters. Indicates that the proof key and verification key used in the zero-knowledge proof process are generated based on the security parameters and arithmetic circuit through the Setup operation.
[0030] equipment The device The first pseudo-identity , public key and zero-knowledge proof Form a registration tuple ,equipment Send registration tuple to the central processing system CPS To generate a registration request, the central processing system CPS receives the registration tuple After that, verify the first pseudo-identity received Is it repeated? If the first pseudo identity If it is repeated, the registration request will be rejected;
[0031] After the central processing system CPS successfully verifies, it will record the device on the blockchain. Create a target node and register the tuple Stored in the target node, the device The first pseudo-identity Associated with the target node's account address, finally, the central processing system CPS returns a reply Give equipment , to inform the device Registration is complete.
[0032] In another specific embodiment, the power devices in the same trust domain authenticate each other as follows:
[0033] When the device When domain authentication is required, the device The device The first pseudo-identity Send to the central processing system CPS to form a certification request ;
[0034] The Central Processing System (CPS) receives a certification request Then, according to the first pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the central processing system CPS will first pseudo identity Perform zero-knowledge proof authentication and pass the first verification key First public statement and the first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed;
[0035] equipment After the authentication is successful, the central processing system CPS Importance of equipment Assigning permission levels After the allocation is completed, the first pseudo identity and permission levels Recorded in local storage, the central processing system CPS sends a reply authentication reply Give equipment .
[0036] Specifically, the central processing system CPS is based on the authority level The trust domain is defined as 3 levels, namely: high-level trust domain Intermediate trust domain ; Low-level trust domain .
[0037] The method of this application can achieve the following technical effects:
[0038] (1) Adapting to multi-level cross-trust domain scenarios: Devices are assigned to different trust domains (high-level trust domain, intermediate trust domain, and low-level trust domain) based on their permission levels. Each trust domain has its own unique security requirements and access permission settings. In this way, devices of different levels can operate securely within their respective trust domains. When a device needs to make a request across trust domains, the legitimacy and security of the request are ensured by exchanging zero-knowledge proofs and a two-way authentication process.
[0039] (2) Efficient authentication and communication: During the registration and authentication process, devices can quickly authenticate their identities using pre-generated proof keys and verification keys, reducing manual intervention and improving authentication efficiency. After successful cross-trust domain authentication, the central processing system generates a session key and transmits the session key using the device's public key encryption, ensuring secure transmission and storage of the session key. The use of session keys ensures efficient and secure communication between devices.
[0040] (3) Distributed node rapid authentication: This invention utilizes blockchain technology to store the device’s registration information on the blockchain, allowing any blockchain node to quickly access and verify the device’s registration information. This decentralized storage method eliminates the risk of single points of failure and improves the reliability and efficiency of authentication. Through zero-knowledge proof technology, devices can quickly generate and verify identity proofs without transmitting sensitive information, reducing communication overhead and delays during the authentication process.
[0041] (4) Implementing resource access restrictions: After successful device authentication, different permission levels are assigned to the device, and resource access control is performed based on the permission level. Devices in higher-level trust domains can access more sensitive and important resources, while the access rights of devices in lower-level trust domains are strictly restricted. When accessing within a domain, devices can only access resources permitted by their permission level; when communicating across trust domains, an enhanced cross-trust domain authentication process ensures that each communication is carried out under the premise of controllability and compliance with policies, further ensuring the security of resources.
[0042] (5) Ensure system security: Through zero-knowledge proof technology, identity authentication is performed without leaking sensitive device information, which greatly improves the privacy protection level of the device and prevents information leakage and identity forgery.
[0043] See also Figure 2 , which shows a structural block diagram of a power system hierarchical authentication system based on blockchain and zero-knowledge proof in this application.
[0044] like Figure 2 As shown, the power system hierarchical authentication system 200 includes a processing module 210 , a first verification module 220 and a second verification module 230 .
[0045] Among them, the processing module 210 is configured to When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ;
[0046] The first verification module 220 is configured as a device According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed;
[0047] The second verification module 230 is configured as a device Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
[0048] It should be understood that Figure 2 Modules and references documented in Figure 1 Therefore, the operations and features described above for the method and the corresponding technical effects also apply to Figure 2 The modules in it will not be described in detail here.
[0049] In other embodiments, embodiments of the present invention further provide a computer-readable storage medium having a computer program stored thereon, wherein when the program instructions are executed by a processor, the processor is caused to execute the power system hierarchical authentication method based on blockchain and zero-knowledge proof in any of the above method embodiments;
[0050] As an embodiment, the computer-readable storage medium of the present invention stores computer-executable instructions, and the computer-executable instructions are configured as follows:
[0051] When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ;
[0052] equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed;
[0053] equipment Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
[0054] The computer-readable storage medium may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the power system hierarchical authentication system based on blockchain and zero-knowledge proof, etc. In addition, the computer-readable storage medium may include a high-speed random access memory, and may also include a memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state memory device. In some embodiments, the computer-readable storage medium may optionally include a memory remotely located relative to the processor, and these remote memories may be connected to the power system hierarchical authentication system based on blockchain and zero-knowledge proof via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0055] Figure 3 Schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Figure 3 As shown, the device includes: a processor 310 and a memory 320. The electronic device may also include: an input device 330 and an output device 340. The processor 310, the memory 320, the input device 330 and the output device 340 may be connected via a bus or other means. Figure 3 The example of the connection via bus is taken. The memory 320 is the computer-readable storage medium mentioned above. The processor 310 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions and modules stored in the memory 320, that is, implements the power system hierarchical authentication method based on blockchain and zero-knowledge proof in the above method embodiment. The input device 330 can receive input digital or character information, and generate key signal input related to user settings and function control of the power system hierarchical authentication system based on blockchain and zero-knowledge proof. The output device 340 may include a display device such as a display screen.
[0056] The electronic device can execute the method provided by the embodiment of the present invention, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not fully described in this embodiment, please refer to the method provided by the embodiment of the present invention.
[0057] As an embodiment, the electronic device is applied to a power system hierarchical authentication system based on blockchain and zero-knowledge proof, and is used for a client, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:
[0058] When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ;
[0059] equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed;
[0060] equipment Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
[0061] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods of each embodiment or certain portions of the embodiments.
[0062] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A power system hierarchical authentication method based on blockchain and zero-knowledge proof, characterized in that: include: When the device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ; equipment According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
2. A power system hierarchical authentication method based on blockchain and zero-knowledge proof according to claim 1, characterized in that: The method further comprises: Power equipment registration, specifically: equipment Note Before sending a registration request to the Central Processing System (CPS), The identity problem to be proved is converted into an arithmetic circuit C, and then the arithmetic circuit C and the security parameter Enter into the Setup operation to generate a certification key and verification key , and then the proof key of the identity to be proved , Public Statement and witnesses Input into the proof operation to generate a zero-knowledge proof ; equipment The device The first pseudo-identity , public key and zero-knowledge proof Form a registration tuple ,equipment Send registration tuple to the central processing system CPS To generate a registration request, the central processing system CPS receives the registration tuple After that, verify the first pseudo-identity received Is it repeated? If the first pseudo identity If it is repeated, the registration request will be rejected; After the central processing system CPS successfully verifies, it will record the device on the blockchain. Create a target node and register the tuple Stored in the target node, the device The first pseudo-identity Associated with the target node's account address, finally, the central processing system CPS returns a reply Give equipment , to inform the device Registration is complete.
3. A power system hierarchical authentication method based on blockchain and zero-knowledge proof according to claim 1, characterized in that: The method further comprises: Mutual authentication of power equipment within the same trust domain, specifically: When the device When domain authentication is required, the device The device The first pseudo-identity Send to the central processing system CPS to form a certification request ; The Central Processing System (CPS) receives a certification request Then, according to the first pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the central processing system CPS will first pseudo identity Perform zero-knowledge proof authentication and pass the first verification key First public statement and the first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; equipment After the authentication is successful, the central processing system CPS Importance of equipment Assigning permission levels After the allocation is completed, the first pseudo identity and permission levels Recorded in local storage, the central processing system CPS sends a reply authentication reply Give equipment .
4. A power system hierarchical authentication method based on blockchain and zero-knowledge proof according to claim 1, characterized in that: in, On the device With equipment After mutual authentication is successful, the method includes: The device The first pseudo-identity and equipment Second pseudo-identity Form a session key generation request , and generate a session key request Sent to the central processing system CPS, the central processing system CPS receives the session key generation request Then generate a random number n, and then according to the random number n, the first pseudo identity , Second fake identity Generate Devices With equipment The session key between , then the central processing system CPS equipment Public key The session key is encrypted using the encryption algorithm E Encrypt and obtain the encrypted session key , then the central processing system CPS will encrypt the session key Send to device ,equipment Use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , while the device The second session key and the corresponding second pseudo-identity Record to local storage, then the device Use equipment Public key The session key is encrypted using the encryption algorithm E Encrypt and obtain the second encrypted session key , then the device The second encrypted session key Send to device ,equipment Receive the second encrypted session key Post-use equipment Private key After decryption with decryption algorithm D, the second session key is obtained , the last device The second session key And the corresponding first pseudo-identity Record to local storage.
5. A power system hierarchical authentication system based on blockchain and zero-knowledge proof, characterized in that: include: Processing module, configured as a device When cross-trust domain communication is required, the device The device The first pseudo-identity , the request information initiated Composing a cross-trust domain request , then the device Cross-trust domain requests Send to the central processing system CPS, the central processing system CPS according to the device Request Information , select one and request information Devices in the corresponding domain Second pseudo-identity , and then use the second pseudo identity Compose a reply , and send a reply Give equipment ; The first verification module is configured as a device According to the response received The second pseudo-identity in , the device The first pseudo-identity and request information to be communicated Forming an authentication request , and the authentication request Through a second pseudo-identity Send to device ,equipment Upon receipt of the certification request The first pseudo-identity Extract the registration tuple from the corresponding node on the blockchain , then the device For the first pseudo-identity Perform zero-knowledge proof authentication and set the device First verification key ,equipment First public statement and equipment The first zero-knowledge proof Input into the verification algorithm Verify, and obtain the first verification result through the verification algorithm Verify , when the first verification result is obtained Time display device Verification is successful, on the contrary, when the first verification result is obtained Time display device Verification failed; The second verification module is configured as a device Authentication successful device After that, the equipment Send Reply Authentication Reply Give equipment ,equipment Receive certification response Then, according to the second pseudo identity Extract the registration tuple from the corresponding node on the blockchain , then the device The second pseudo-identity Perform zero-knowledge proof authentication and set the device Second verification key ,equipment Second public statement and equipment The second zero-knowledge proof Input into the verification algorithm Verify, and obtain the second verification result through the verification algorithm Verify , when the second verification result is obtained Time display device Verification is successful, on the contrary, when the second verification result is obtained Time display device Authentication failed.
Citation Information
Patent Citations
Zero-knowledge proof and cross-chain based access control method and system and storage medium
CN116800435A
Cross-domain authentication method based on zero-knowledge proof
CN119449283A