Security protection method, device and product of power cloud platform

By performing multiple blocking and random reorganization of power data and using multi-key sequence encryption, the problem of low encryption security in the prior art is solved and higher data security is achieved.

CN120034361APending Publication Date: 2025-05-23STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510058044.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

When encrypting power data in the prior art, the key is single and the segmentation method is simple and easy to perform, resulting in low encryption security and easy to be cracked.

Method used

By performing two blocking processing on the power data, two block sets are generated, and the data blocks of one block set are used to randomly reorganize the data blocks of the other block set to form several reorganized data blocks. Then, two key sequences are generated using the two encryption key functions, and the two data sub-blocks of each recombinant data block are encrypted.

Benefits of technology

It improves the difficulty of data reorganization and encryption cracking, significantly improves the security of power data encryption, making it difficult for stealers to restore the original data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034361A_ABST
    Figure CN120034361A_ABST
Patent Text Reader

Abstract

The invention discloses a security protection method, device and product for a power cloud platform, and the method comprises the steps: obtaining final divided data blocks of power data in a manner of carrying out the random recombination of the data blocks in one block set through two times of blocking, and carrying out the random recombination of the data blocks in the other block set; therefore, the recombined data blocks obtained through division contain the information of the data blocks with different lengths, on the basis, even if a stealer splices the data blocks according to the sequence after cracking and encryption, original data cannot be obtained through reduction, and therefore the data recombining difficulty is improved; meanwhile, when encryption is carried out, the recombined data block is divided into two data sub-blocks, and the two data sub-blocks are encrypted by using different keys, so that the encryption cracking difficulty can be improved, and the encryption security is further improved; therefore, the invention provides a brand-new secure storage method for the power data, and the method is very suitable for large-scale application and popularization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of security protection of electric power cloud platforms, and specifically relates to a security protection method, device and product for electric power cloud platforms. Background Art

[0002] With the rapid development of smart grid, energy internet and other businesses, and the massive access of mobile terminals, cloud computing is profoundly affecting power-related business systems that are closely related to mobile terminals. Cloud computing provides elastic and scalable computing and storage capabilities for all types of users. It provides resources to users in the form of services through the Internet, and users in different regions can use them on demand. Therefore, this convenience has promoted the rapid development and expansion of cloud computing in the power sector.

[0003] Electricity data refers to the data generated during the operation of distribution stations, including a large amount of electricity marketing data, electricity customer data, personal electricity consumption information and other sensitive data. These data have the potential security risk of privacy leakage in the process of generation, transmission, storage, processing and sharing. Therefore, in order to ensure the storage security of electricity data on the cloud platform, it is necessary to encrypt the massive amount of electricity data stored. The process is as follows: first, the source data is divided in sequence according to a fixed length, and then the divided data is encrypted and reassembled to obtain the encrypted source data. However, the above encryption technology has the following shortcomings: (1) A single key is often used for encryption of massive data. In this way, it is easy for thieves to crack and restore the source data, resulting in low encryption security. (2) The above segmentation method is simple and easy to implement, which can increase the confidentiality of user data to a certain extent, but its reassembly difficulty is relatively low. After cracking the encryption, the thief can easily restore the source data according to the information and sequence of the segmented data, which further reduces the encryption security. Therefore, based on the above shortcomings, how to provide a security protection method, device and product for an electric cloud platform with high encryption security has become an urgent problem to be solved. Summary of the invention

[0004] The purpose of the present invention is to provide a security protection method, device and product for an electric power cloud platform, so as to solve the problem of low encryption security of electric power data existing in the prior art.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions:

[0006] In a first aspect, a security protection method for an electric power cloud platform is provided, comprising:

[0007] Obtain power data stored in the power cloud platform;

[0008] The power data is processed into blocks to obtain two block sets, wherein the number of data blocks in the two block sets is different;

[0009] Using data blocks in one of the two block sets, randomly reorganize the data blocks in the other block set, so as to obtain a plurality of reorganized data blocks after the random reorganization process;

[0010] Constructing two encryption key functions, and using the two encryption key functions to generate a first key sequence and a second key sequence;

[0011] Divide each reassembled data block into blocks to obtain data sub-blocks corresponding to each reassembled data block, wherein the number of data sub-blocks corresponding to any reassembled data block is two;

[0012] Using the first key sequence and the second key sequence, encrypting two data sub-blocks corresponding to each reorganized data block to obtain two encrypted data sub-blocks corresponding to each reorganized data block after encryption, wherein the two data sub-blocks corresponding to any reorganized data block are encrypted using different key sequences;

[0013] Encrypted power data is generated based on the two encrypted data sub-blocks corresponding to each reorganized data block, so as to complete the security protection of the power data after the encrypted power data is obtained.

[0014] Based on the above disclosed content, when the present invention divides the power data on the power cloud platform into blocks, it will first divide it into two block sets with different numbers of blocks; then, using the data blocks in one of the block sets, the data blocks in the other block set are randomly reorganized to obtain a number of reorganized data blocks; then, the present invention uses two encryption key functions to generate two key sequences, and blocks each reorganized data block again to obtain two data sub-blocks corresponding to each reorganized data block; then, the above-mentioned two key sequences are used to encrypt the two data sub-blocks corresponding to each reorganized data block respectively, so as to obtain two encrypted data sub-blocks corresponding to each reorganized data block; finally, based on the above-mentioned encrypted data sub-blocks, encrypted power data can be generated, thereby completing the security protection of the power data.

[0015] Through the above design, the present invention obtains the final divided data blocks of power data by dividing the data twice and using the data blocks in one of the block sets to randomly reorganize the data blocks in the other block set; in this way, the reorganized data blocks obtained by division contain information of data blocks of different lengths. Based on this, even if the thief splices the data blocks in sequence after cracking the encryption, the original data cannot be restored, thereby increasing the difficulty of data reorganization; at the same time, when encrypting, the present invention divides the reorganized data block into two data sub-blocks, and uses different keys to encrypt the two data sub-blocks, thereby increasing the difficulty of encryption cracking, thereby further improving the security of encryption; in this way, the present invention provides a new secure storage method for power data, which is very suitable for large-scale application and promotion.

[0016] In a possible design, the block set includes a first block set and a second block set, wherein the power data is processed in blocks to obtain two block sets, including:

[0017] Acquire a first number of blocks and a second number of blocks, and based on the second number of blocks or the first number of blocks, perform block processing on the power data to obtain the first block set;

[0018] Calculate the product of the number of the first blocks and the number of the second blocks, and use the product as the calibration number;

[0019] Determining whether the length of the power data is equal to an integer multiple of the calibrated number;

[0020] If not, adjusting the power data to obtain adjusted power data, wherein the length of the adjusted power data is equal to an integer multiple of the calibrated number;

[0021] The adjusted power data is processed in blocks according to the calibrated number to obtain the second block set.

[0022] In a possible design, the block set includes a first block set and a second block set, and the number of data blocks in the second block set is greater than the number of data blocks in the first block set;

[0023] The data blocks in one of the two block sets are used to perform random reorganization processing on the data blocks in the other block set, so as to obtain a number of reorganized data blocks after the random reorganization processing, including:

[0024] Performing random grouping processing on the data blocks in the second block set to obtain a plurality of data groups, wherein the number of the data groups is the same as the number of the data blocks in the first block set;

[0025] The data blocks in each data group are randomly merged to obtain the merged data corresponding to each data group;

[0026] A combined data is respectively allocated to each data block in the first block set, and each combined data and the data block corresponding to each combined data are spliced ​​together to obtain a plurality of reorganized data blocks after the splicing process.

[0027] In one possible design, two encryption key functions are used to generate a first key sequence and a second key sequence, including:

[0028] Based on the power data, determining initial values ​​of two encryption key functions;

[0029] Using the initial values ​​of the two encryption key functions, iteratively processing the two encryption key functions, so as to generate two first initial key sequences and two second initial key sequences after the iterative processing;

[0030] Key obfuscation processing is performed on the two first initial key sequences and the two second initial key sequences, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing.

[0031] In one possible design, based on the power data, initial values ​​of two encryption key functions are determined, including:

[0032] Performing a hash operation on the power data to obtain power hash data;

[0033] Dividing the power hash data into 8 hash values, wherein the 8 hash values ​​have the same length;

[0034] Based on the eight hash values, the initial values ​​of the two encryption key functions are calculated using the following formulas (1) and (2);

[0035]

[0036] In the above formula (1), represents the initial value of one of the two encryption key functions, z 1 ,z 2 ,z 3 ,z 4 Represents the first 4 hash values ​​among the 8 hash values, Represents the exclusive OR operation;

[0037] In the above formula (2), represents the initial value of the other encryption key function in the two encryption key functions, z 5 ,z 6 ,z 7 ,z 8Indicates the last 4 hash values ​​out of 8.

[0038] In one possible design, performing key obfuscation processing on two first initial key sequences and two second initial key sequences to obtain a first key sequence and a second key sequence after the key obfuscation processing includes:

[0039] Using the two first initial key sequences, a first pre-obfuscation key sequence and a second pre-obfuscation key sequence are generated, and according to the two second initial key sequences, a third pre-obfuscation key sequence and a fourth pre-obfuscation key sequence are generated;

[0040] Key obfuscation processing is performed on the first pre-obfuscated key sequence and the third pre-obfuscated key sequence, and key obfuscation processing is performed on the second pre-obfuscated key sequence and the fourth pre-obfuscated key sequence, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing.

[0041] In one possible design, two first initial key sequences are used to generate a first pre-obfuscated key sequence and a second pre-obfuscated key sequence, including:

[0042] For any first initial key sequence, the following formula (3) is used to calculate the pre-obfuscated key corresponding to each initial key in any first initial key sequence;

[0043]

[0044] In the above formula (3), x k represents the kth initial key in any first initial key sequence, represents the pre-obfuscated key corresponding to the kth initial key, represents a floor sign, a is a positive integer, mod represents a modulo operation, wherein k=1, 2, ..., K, and K is the length of any first initial key sequence;

[0045] Using the pre-obfuscated keys corresponding to the initial keys, a pre-obfuscated key sequence corresponding to any one of the first initial key sequences is formed, wherein the pre-obfuscated key sequence corresponding to any one of the first initial key sequences is the first pre-obfuscated key sequence or the second pre-obfuscated key sequence;

[0046] Correspondingly, performing key obfuscation processing on the first pre-obfuscated key sequence and the third pre-obfuscated key sequence, and performing key obfuscation processing on the second pre-obfuscated key sequence and the fourth pre-obfuscated key sequence, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing, comprises:

[0047] The first pre-obfuscation key sequence and the third pre-obfuscation key sequence are subjected to an XOR operation, and the second pre-obfuscation key sequence and the fourth pre-obfuscation key sequence are subjected to an XOR operation, so as to obtain the first key sequence and the second key sequence after the XOR operation.

[0048] In a second aspect, a safety protection device for an electric power cloud platform is provided, comprising:

[0049] An acquisition unit, used for acquiring power data stored in the power cloud platform;

[0050] A data reorganization unit, used for performing block processing on the power data to obtain two block sets, wherein the number of data blocks in the two block sets is different;

[0051] The data reorganization unit is further used to use the data blocks in one of the two block sets to perform random reorganization processing on the data blocks in the other block set, so as to obtain a plurality of reorganized data blocks after the random reorganization processing;

[0052] A key unit, used to construct two encryption key functions, and generate a first key sequence and a second key sequence using the two encryption key functions;

[0053] An encryption unit, used for processing each reassembled data block into blocks to obtain data sub-blocks corresponding to each reassembled data block, wherein the number of data sub-blocks corresponding to any reassembled data block is two;

[0054] an encryption unit, configured to perform encryption processing on two data sub-blocks corresponding to each reorganized data block using the first key sequence and the second key sequence, so as to obtain two encrypted data sub-blocks corresponding to each reorganized data block after encryption processing, wherein the two data sub-blocks corresponding to any reorganized data block use different key sequences when being encrypted;

[0055] The encryption unit is also used to generate encrypted power data based on the two encrypted data sub-blocks corresponding to each reorganized data block, so as to complete the security protection of the power data after obtaining the encrypted power data.

[0056] According to a third aspect, another security protection device for an electric power cloud platform is provided. Taking the device as an electronic device as an example, the device includes a memory, a processor and a transceiver which are communicatively connected in sequence, wherein the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the security protection method for the electric power cloud platform as in the first aspect or any possible design in the first aspect.

[0057] In a fourth aspect, a storage medium is provided, on which instructions are stored. When the instructions are executed on a computer, the security protection method for the electric power cloud platform as in the first aspect or any possible design in the first aspect is executed.

[0058] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the security protection method for the electric power cloud platform as described in the first aspect or any possible design of the first aspect.

[0059] Beneficial effects:

[0060] (1) The present invention obtains the final divided data blocks of power data by dividing the data into two blocks and using the data blocks in one of the block sets to randomly reorganize the data blocks in the other block set; thus, the reorganized data blocks obtained by division contain information of data blocks of different lengths. Based on this, even if the thief splices the data blocks in sequence after cracking the encryption, he cannot restore the original data, thereby increasing the difficulty of data reorganization; at the same time, when encrypting, the present invention divides the reorganized data block into two data sub-blocks and uses different keys to encrypt the two data sub-blocks, thereby increasing the difficulty of encryption cracking, thereby further improving the security of encryption; thus, the present invention provides a new secure storage method for power data, which is very suitable for large-scale application and promotion. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 A schematic diagram of the steps of the safety protection method for the electric power cloud platform provided by an embodiment of the present invention;

[0062] Figure 2 A schematic diagram of the structure of a safety protection device for an electric power cloud platform provided by an embodiment of the present invention;

[0063] Figure 3 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0064] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structure of the drawings is only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention.

[0065] It should be understood that although the terms first, second, etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another unit. For example, a first unit can be referred to as a second unit, and similarly, a second unit can be referred to as a first unit without departing from the scope of the exemplary embodiments of the present invention.

[0066] It should be understood that the term "and / or" that may appear in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can represent three situations: A exists alone, B exists alone, and A and B exist at the same time. The term " / and" that may appear in this article describes another type of association object relationship, indicating that two relationships may exist. For example, A / and B can represent two situations: A exists alone, and A and B exist alone. In addition, the character " / " that may appear in this article generally indicates that the previous and next associated objects are in an "or" relationship.

[0067] Example:

[0068] See also Figure 1 As shown, the security protection method for the electric power cloud platform provided in this embodiment performs two different numbers of block divisions before encrypting the electric power data to obtain two block sets; then, the data blocks in the block set with a large number of blocks are used to randomly reorganize the data blocks in the other block set, so as to merge the data blocks in the block set with a large number of blocks with the data blocks in the other block set, thereby obtaining a number of reorganized data blocks; then, two encryption key functions are used to generate two key sequences; then, each reorganized data block is divided into two data sub-blocks, and two key sequences are used to encrypt the two data sub-blocks corresponding to each reorganized data block (that is, the two data sub-blocks are respectively encrypted). A key sequence should be used); finally, each encrypted data sub-block can be used to generate encrypted power data, thereby completing the security protection of the power data; in this way, the method adopts multiple block divisions and random reorganizations to perform data segmentation, and different encryption keys are used during encryption. Based on this, compared with traditional technologies, the difficulty of data reorganization and the difficulty of data encryption cracking are improved, thereby improving the security of power data encryption; among them, for example, the method can be but not limited to running on the power cloud platform side. It can be understood that the aforementioned execution subject does not constitute a limitation on the embodiments of the present application. Accordingly, the operation steps of the method can be but not limited to the following steps S1 to S7.

[0069] S1. Obtain the power data stored in the power cloud platform; in the specific implementation, the power cloud platform is connected to various power equipment, power operation equipment, power equipment, user terminals, etc., and can receive the data sent by the aforementioned devices in real time; at the same time, for example, the aforementioned power data may include but is not limited to: equipment operation data, power marketing data, power customer data, personal power consumption information, etc.; in this way, the aforementioned data contains a large amount of sensitive information, therefore, in order to ensure the storage security of data in the power cloud platform, it is necessary to perform security protection on the stored data.

[0070] Among them, this embodiment adopts data encryption to perform data security protection, and on the basis of traditional data encryption, improvements are made from the data block segmentation and encryption means before encryption to improve the security of power data encryption; optionally, the data block segmentation process of power data before encryption can be but not limited to as shown in the following steps S2 and S3.

[0071] S2. The power data is processed in blocks to obtain two block sets, wherein the numbers of data blocks in the two block sets are different; in specific applications, this embodiment first divides the power data into two block sets (i.e., a first block set and a second block set) with different numbers of data blocks, and then, using the data blocks in the block set with a larger number of blocks, randomly reorganizes the data blocks in the other block set, so that the final data blocks contain a large amount of interference information, thereby increasing the difficulty of data reorganization.

[0072] Optionally, for example but not limited to, the following steps S21 to S25 may be used to perform block processing of power data.

[0073] S21. Obtain the first number of blocks and the second number of blocks, and based on the second number of blocks or the first number of blocks, perform block processing on the power data to obtain the first block set; in specific implementation, the first number of blocks and the second number of blocks can be set according to the size of the power data; optionally, this embodiment preferentially sets the first number of blocks and the second number of blocks to 5 and 10; of course, the above examples are only for illustration and are not limited to this.

[0074] In this way, it is equivalent to dividing the power data into 5 data blocks or 10 data blocks to obtain the first block set; of course, this embodiment preferably divides the power data into 5 data blocks to form the first block set; and after completing the first block processing of the power data, the second block processing can be performed, and the process is shown in the following steps S22 to S25.

[0075] S22. Calculate the product of the first number of blocks and the second number of blocks, and use the product as the calibration number; in this embodiment, the calibration number is equivalent to 50; then, the power data can be adjusted according to the calibration number so as to complete the second block division of the power data; wherein, the data adjustment process is shown in the following steps S23 and S24.

[0076] S23. Determine whether the length of the power data is equal to an integer multiple of the calibrated number; in this embodiment, if the length of the power data is equal to an integer multiple of the calibrated number, then the following step S25 can be directly executed, otherwise, the length adjustment is required, and the process is shown in the following step S24.

[0077] S24. If not, adjust the power data to obtain adjusted power data, wherein the length of the adjusted power data is equal to an integer multiple of the calibrated number; in specific applications, the power data is usually converted into a binary vector before processing, and therefore, zero padding is performed after the power data to complete the length adjustment of the power data, thereby obtaining the adjusted power data; then, the adjusted power data can be divided into blocks, and the process is shown in the following step S25.

[0078] S25. According to the calibrated number, the adjusted power data is divided into blocks to obtain the second block set; in the present embodiment, it is equivalent to taking the calibrated number as the number of blocks for the adjusted power data, and then dividing the adjusted power data into blocks based on this; for example, on the basis of the foregoing, the calibrated number is 50, and the length of the adjusted power data is 100, then the second block set contains 50 data blocks with a length of 2.

[0079] In this way, through the aforementioned steps S21 to S25, the power data can be divided twice to obtain two block sets with different numbers of blocks; then, data reorganization can be performed based on the aforementioned two block sets to obtain the final data block corresponding to the power data, wherein the data reorganization process can be but is not limited to as shown in the following step S3.

[0080] S3. Using the data blocks in one of the two block sets, randomly reorganize the data blocks in the other block set to obtain a number of reorganized data blocks after the random reorganization process; in specific implementation, after the two block divisions in the aforementioned step S2, the number of data blocks in the second block set is actually the product of the number of the first blocks and the number of the second blocks, so the number of data blocks in the second block set is greater than that in the first block set; based on this, this embodiment is based on the second block set to randomly reorganize the various data blocks in the first block set, wherein the specific process of random reorganization can be but is not limited to as shown in the following steps S31 to S33.

[0081] S31. Randomly group the data blocks in the second block set to obtain a number of data groups, wherein the number of data groups is the same as the number of data blocks in the first block set; in this embodiment, it is equivalent to randomly grouping the data blocks in the second block set according to the number of data blocks in the first block set; for example, the number of data in the first block set is 5, and the number of data in the second block set is 50, then the data blocks in the second block set are divided into 5 data groups, each data group contains 10 data blocks; of course, the data blocks in each data group are randomly combined.

[0082] In this way, after the random grouping of the data blocks in the second block set is completed, the data blocks in each data group can be merged to obtain merged data; wherein, the data merging process can be but is not limited to the step S32 shown below.

[0083] S32. Randomly merge the data blocks in each data group to obtain merged data corresponding to each data group; in this embodiment, a random method is used to merge the data blocks in the data group, which can increase the clutter of the information and make the merged data have no merging rules, thereby increasing the difficulty of illegal reorganization of subsequent data.

[0084] After obtaining the merged data corresponding to each data group, the data blocks in the first block set can be reorganized based on the merged data to obtain reorganized data blocks; wherein the generation process of the reorganized data blocks is shown in the following step S33.

[0085] S33. Assign a merged data to each data block in the first block set respectively, and splice each merged data with the data blocks corresponding to each merged data, so as to obtain a number of reorganized data blocks after the splicing process; in a specific implementation, a merged data is randomly assigned to each data block in the first block set, and then each merged data is spliced ​​before or after the corresponding data block, so as to obtain a number of reorganized data blocks.

[0086] In this way, through the aforementioned steps S2, S3 and corresponding sub-steps, this embodiment performs two different number of block divisions on the power data; then, the data blocks in the second block set are divided into several data groups, and the data blocks in each data group are randomly merged to obtain several merged data; finally, a merged data is assigned to each data block in the first block set, and each merged data is spliced ​​with the corresponding data block to obtain several reorganized data blocks; in this way, each reorganized data block contains a large amount of interference information; based on this, without knowing the block division rules, it is difficult for the thief to obtain the original data by reorganizing the reorganized data blocks; therefore, the difficulty of data reorganization is increased, thereby improving the security of encryption.

[0087] After the power data is divided into blocks, encryption processing can be performed; in this embodiment, two key sequences are generated, and then each reorganized data block is divided into two data sub-blocks; then, the two key sequences are used to encrypt each data sub-block, thereby completing the encryption protection of the power data.

[0088] Optionally, the process of generating the two key sequences may be, but is not limited to, as shown in the following step S4.

[0089] S4. Construct two encryption key functions, and use the two encryption key functions to generate a first key sequence and a second key sequence; in specific implementation, the two encryption key functions may be, but are not limited to, two-dimensional chaotic key functions, and their expressions may be, but are not limited to, as shown in the following formulas (4) and (5).

[0090]

[0091] The above formula (4) represents the first encryption key function of the two encryption key functions, represents the state value of the first encryption key function at the sth iteration, represents the state value of the first encryption key at the s+1th iteration, δ,P represents the system parameter of the first encryption key function; in this embodiment, δ is greater than 500, and P is a positive integer.

[0092] The above formula (5) represents the second encryption key function of the two encryption key functions, represents the state value of the second encryption key function at the sth iteration, represents the state value of the second encryption key at the s+1th iteration, β, r, d, and L all represent system parameters of the second encryption key function; where, for example, β, r, and d can be, but are not limited to, set to 9, 1, and 0.25, respectively, and L is a positive integer; meanwhile, in the above formulas (4) and (5), mod represents a modulo operation.

[0093] Based on this, the two encryption key functions mentioned above can be used to generate the first key sequence and the second key sequence; further, the specific generation process of the two key sequences mentioned above can be but is not limited to the following steps S41 to S43.

[0094] S41. Based on the power data, determine the initial values ​​of two encryption key functions; in specific implementation, for example, but not limited to, first perform a hash operation on the power data to obtain power hash data; then, divide the power hash data into 8 hash values ​​of the same length; then, calculate the initial values ​​of the two encryption key functions based on the 8 hash values.

[0095] In this embodiment, the length of the aforementioned power hash data is taken as 128, so each hash value is 16 bits in length; of course, different hash algorithms can also be used to obtain power hash data of different lengths, which can be selected according to actual use and is not limited to the aforementioned example.

[0096] At the same time, for example, but not limited to, the following formulas (1) and (2) can be used to obtain the initial values ​​of the two encryption key functions.

[0097]

[0098] In the above formula (1), represents the initial value of one of the two encryption key functions (i.e., the initial value of the first encryption key function mentioned above), z 1 ,z 2 ,z 3 ,z 4 Represents the first 4 hash values ​​among the 8 hash values, represents the XOR operation; in the above formula (2), represents the initial value of the other encryption key function of the two encryption key functions (i.e., the initial value of the second encryption key function mentioned above), and z 5 ,z 6 ,z 7 ,z 8 It means the last 4 hash values ​​among the 8 hash values.

[0099] In this way, after the initial values ​​of the two encryption key functions are calculated through the aforementioned step S41, the function iteration can be performed based on the initial values ​​to obtain the initial key sequence corresponding to each encryption key function; wherein the function iteration process is shown in the following step S42.

[0100] S42. Using the initial values ​​of the two encryption key functions, the two encryption key functions are iteratively processed to generate two first initial key sequences and two second initial key sequences after the iterative processing; in the specific implementation, the initial values ​​of the two encryption key functions are substituted into their respective functions to perform function iteration; based on this, when the iteration is completed, each encryption key function can obtain the corresponding iterative sequence of x and y, and the iterative sequence of x and y is the initial key sequence corresponding to each encryption key function; at the same time, in order to ensure the discreteness of the key sequence, this embodiment discards the first 300 values ​​in the two first initial key sequences and the two second initial key sequences (that is, the first 300 iterative values ​​are discarded).

[0101] Thus, after obtaining the two first initial key sequences and the two second initial key sequences corresponding to the two encryption key functions, in order to improve the security of the keys, this embodiment further performs an obfuscation process on them, and the process is shown in the following step S43.

[0102] S43. Perform key obfuscation processing on the two first initial key sequences and the two second initial key sequences to obtain the first key sequence and the second key sequence after the key obfuscation processing; in this embodiment, for example, but not limited to, the following steps S43a and S43b can be used to complete the obfuscation processing of the aforementioned first initial key sequence and the second initial key sequence.

[0103] S43a. Using the two first initial key sequences, a first pre-obfuscated key sequence and a second pre-obfuscated key sequence are generated, and based on the two second initial key sequences, a third pre-obfuscated key sequence and a fourth pre-obfuscated key sequence are generated; in the specific implementation, any initial key sequence is taken as an example to illustrate the generation process of the corresponding pre-obfuscated key sequence.

[0104] For any first initial key sequence, for example but not limited to, the following formula (3) may be used to calculate the pre-obfuscated key corresponding to each initial key in any first initial key sequence.

[0105]

[0106] In the above formula (3), x k represents the kth initial key in any first initial key sequence, represents the pre-obfuscated key corresponding to the kth initial key, represents the floor sign, a is a positive integer, and mod represents the modulo operation, wherein k=1, 2, ..., K, and K is the length of any of the first initial key sequences; in a specific implementation, the value of a is 5 for example.

[0107] Thus, based on the aforementioned formula (3), the pre-obfuscated key corresponding to each initial key in any first initial key sequence can be calculated; then, using the pre-obfuscated keys corresponding to each initial key, the pre-obfuscated key sequence corresponding to any first initial key sequence can be formed; of course, the pre-obfuscated key sequence corresponding to any first initial key sequence is the first pre-obfuscated key sequence or the second pre-obfuscated key sequence.

[0108] Therefore, after obtaining the pre-obfuscated key sequence corresponding to each initial key sequence through the aforementioned formula (3), the obfuscation processing of each pre-obfuscated key sequence can be performed, and the process is as follows:

[0109] In specific application, this embodiment performs key obfuscation processing on the first pre-obfuscated key sequence and the third pre-obfuscated key sequence, and performs key obfuscation processing on the second pre-obfuscated key sequence and the fourth pre-obfuscated key sequence, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing.

[0110] Specifically, the first pre-obfuscated key sequence and the third pre-obfuscated key sequence are subjected to an XOR operation, and the second pre-obfuscated key sequence and the fourth pre-obfuscated key sequence are subjected to an XOR operation, so that after the XOR operation, the first key sequence and the second key sequence are obtained.

[0111] Thus, through the aforementioned steps S41 to S43, two key sequences for data encryption can be obtained; then, encryption processing of each reorganized data block can be performed based on the aforementioned two key sequences; wherein, the encryption process can be but is not limited to as shown in the following steps S5 and S6.

[0112] S5. Divide each reorganized data block into blocks to obtain data sub-blocks corresponding to each reorganized data block, wherein the number of data sub-blocks corresponding to any reorganized data block is two; in specific implementation, it is equivalent to dividing each reorganized data block into two data sub-blocks, so that the two data sub-blocks corresponding to each reorganized data block can be encrypted using the two key sequences mentioned above; optionally, any reorganized data block can be divided according to a preset ratio to obtain two corresponding data sub-blocks; of course, the preset ratio refers to a length ratio, such as dividing according to a ratio of 3:7 or a ratio of 5:5.

[0113] After completing the block processing of each reassembled data block, the two key sequences mentioned above can be used to perform encryption processing on each reassembled data block, and the process can be but not limited to the following step S6.

[0114] S6. Use the first key sequence and the second key sequence to encrypt the two data sub-blocks corresponding to each reorganized data block, so as to obtain two encrypted data sub-blocks corresponding to each reorganized data block after the encryption process, wherein the two data sub-blocks corresponding to any reorganized data block use different key sequences when encrypting; in a specific implementation, for any reorganized data block, use the first key sequence to encrypt one of the encrypted data sub-blocks of the any reorganized data block, and use the second key sequence to encrypt the other encrypted data sub-block of the any reorganized data block, so as to obtain the two encrypted data sub-blocks corresponding to the any reorganized data block; at the same time, when encrypting, perform an XOR operation on the first key sequence and one of the encrypted data sub-blocks of the any reorganized data block to obtain the corresponding encrypted data sub-block; of course, the encryption operation of the other data sub-block is also the same, which will not be repeated here.

[0115] In this way, after completing the encryption processing of each data sub-block, splicing is performed to obtain encrypted power data, and the process can be but not limited to the following step S7.

[0116] S7. Generate encrypted power data based on the two encrypted data sub-blocks corresponding to each reorganized data block, so as to complete the security protection of the power data after obtaining the encrypted power data; in specific applications, the two encrypted data sub-blocks corresponding to each reorganized data block are merged to obtain several encrypted reorganized data blocks; then, the several encrypted reorganized data blocks are merged again; in this way, the encrypted power data can be obtained; finally, the encrypted power data can be used to replace the power data stored in the power cloud platform, so as to achieve the purpose of power data security protection.

[0117] Therefore, through the security protection method of the electric power cloud platform described in detail in the aforementioned steps S1 to S7, the present invention adopts a method of multiple block divisions and random reorganization to perform data segmentation, and different encryption keys are used during encryption. Based on this, compared with traditional technologies, the difficulty of data reorganization and the difficulty of data encryption cracking are improved, thereby improving the security of electric power data encryption; therefore, the present invention is very suitable for large-scale application and promotion.

[0118] like Figure 2 As shown, the second aspect of this embodiment provides a hardware device for implementing the security protection method of the electric power cloud platform described in the first aspect of the embodiment. Taking the device as an electric power cloud platform as an example, it may include but is not limited to:

[0119] The acquisition unit is used to acquire the power data stored in the power cloud platform.

[0120] The data reorganization unit is used to perform block processing on the power data to obtain two block sets, wherein the number of data blocks in the two block sets is different.

[0121] The data reorganization unit is also used to use the data blocks in one of the two block sets to perform random reorganization processing on the data blocks in the other block set, so as to obtain a number of reorganized data blocks after the random reorganization processing.

[0122] The key unit is used to construct two encryption key functions and generate a first key sequence and a second key sequence using the two encryption key functions.

[0123] The encryption unit is used to process each reorganized data block into blocks to obtain data sub-blocks corresponding to each reorganized data block, wherein the number of data sub-blocks corresponding to any reorganized data block is two.

[0124] The encryption unit is used to use the first key sequence and the second key sequence to perform encryption processing on the two data sub-blocks corresponding to each reorganized data block, so as to obtain two encrypted data sub-blocks corresponding to each reorganized data block after the encryption processing, wherein the two data sub-blocks corresponding to any reorganized data block use different key sequences when encrypting.

[0125] The encryption unit is also used to generate encrypted power data based on the two encrypted data sub-blocks corresponding to each reorganized data block, so as to complete the security protection of the power data after obtaining the encrypted power data.

[0126] The working process, working details and technical effects of the device provided in this embodiment can be found in the first aspect of the embodiment and will not be described in detail here.

[0127] like Figure 3 As shown, the third aspect of this embodiment provides another security protection device for an electric power cloud platform. Taking the device as an electronic device as an example, it includes: a memory, a processor and a transceiver that are communicatively connected in sequence, wherein the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the security protection method for the electric power cloud platform as described in the first aspect of the embodiment.

[0128] For example, the memory may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, first-in-first-out memory (FIFO) and / or first-in-last-out memory (FILO), etc. Specifically, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). At the same time, the processor may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state.

[0129] In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. For example, the processor may not be limited to a microprocessor of the STM32F105 series, a reduced instruction set computer (RISC) microprocessor, an X86 or other architecture processor, or a processor with an integrated embedded neural network processor (NPU); the transceiver may be, but is not limited to, a wireless fidelity (WIFI) wireless transceiver, a Bluetooth wireless transceiver, a general packet radio service technology (Genera l Packet Rad ioService, GPRS) wireless transceiver, a ZigBee protocol (a low-power LAN protocol based on the IEEE 802.15.4 standard, ZigBee) wireless transceiver, a 3G transceiver, a 4G transceiver and / or a 5G transceiver, etc. In addition, the device may also include, but is not limited to, a power module, a display screen and other necessary components.

[0130] The working process, working details and technical effects of the electronic device provided in this embodiment can be found in the first aspect of the embodiment and will not be described in detail here.

[0131] The fourth aspect of this embodiment provides a storage medium that stores instructions including the security protection method for the electric power cloud platform described in the first aspect of the embodiment, that is, the storage medium stores instructions, and when the instructions are run on a computer, the security protection method for the electric power cloud platform described in the first aspect of the embodiment is executed.

[0132] The storage medium refers to a carrier for storing data, which may include but is not limited to a floppy disk, a CD, a hard disk, a flash memory, a USB flash drive and / or a memory stick, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0133] The working process, working details and technical effects of the storage medium provided in this embodiment can be found in the first aspect of the embodiment and will not be described in detail here.

[0134] The fifth aspect of this embodiment provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the security protection method for the electric power cloud platform as described in the first aspect of the embodiment, wherein the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0135] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A security protection method for an electric power cloud platform, characterized in that: include: Obtain power data stored in the power cloud platform; The power data is processed into blocks to obtain two block sets, wherein the number of data blocks in the two block sets is different; Using data blocks in one of the two block sets, randomly reorganize the data blocks in the other block set, so as to obtain a plurality of reorganized data blocks after the random reorganization process; Constructing two encryption key functions, and using the two encryption key functions to generate a first key sequence and a second key sequence; Divide each reassembled data block into blocks to obtain data sub-blocks corresponding to each reassembled data block, wherein the number of data sub-blocks corresponding to any reassembled data block is two; Using the first key sequence and the second key sequence, encrypting two data sub-blocks corresponding to each reorganized data block to obtain two encrypted data sub-blocks corresponding to each reorganized data block after encryption, wherein the two data sub-blocks corresponding to any reorganized data block are encrypted using different key sequences; Encrypted power data is generated based on the two encrypted data sub-blocks corresponding to each reorganized data block, so as to complete the security protection of the power data after the encrypted power data is obtained.

2. The method according to claim 1, characterized in that The block set includes a first block set and a second block set, wherein the power data is processed in blocks to obtain two block sets, including: Acquire a first number of blocks and a second number of blocks, and based on the second number of blocks or the first number of blocks, perform block processing on the power data to obtain the first block set; Calculate the product of the number of the first blocks and the number of the second blocks, and use the product as the calibration number; Determining whether the length of the power data is equal to an integer multiple of the calibrated number; If not, adjusting the power data to obtain adjusted power data, wherein the length of the adjusted power data is equal to an integer multiple of the calibrated number; The adjusted power data is processed in blocks according to the calibrated number to obtain the second block set.

3. The method according to claim 1, characterized in that The block set includes a first block set and a second block set, and the number of data blocks in the second block set is greater than the number of data blocks in the first block set; The data blocks in one of the two block sets are used to perform random reorganization processing on the data blocks in the other block set, so as to obtain a number of reorganized data blocks after the random reorganization processing, including: Performing random grouping processing on the data blocks in the second block set to obtain a plurality of data groups, wherein the number of the data groups is the same as the number of the data blocks in the first block set; The data blocks in each data group are randomly merged to obtain the merged data corresponding to each data group; A combined data is respectively allocated to each data block in the first block set, and each combined data and the data block corresponding to each combined data are spliced ​​together to obtain a plurality of reorganized data blocks after the splicing process.

4. The method according to claim 1, characterized in that Generating a first key sequence and a second key sequence using two encryption key functions, comprising: Based on the power data, determining initial values ​​of two encryption key functions; Using the initial values ​​of the two encryption key functions, iteratively processing the two encryption key functions, so as to generate two first initial key sequences and two second initial key sequences after the iterative processing; Key obfuscation processing is performed on the two first initial key sequences and the two second initial key sequences, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing.

5. The method according to claim 4, characterized in that Based on the power data, initial values ​​of two encryption key functions are determined, including: Performing a hash operation on the power data to obtain power hash data; Dividing the power hash data into 8 hash values, wherein the 8 hash values ​​have the same length; Based on the eight hash values, the initial values ​​of the two encryption key functions are calculated using the following formulas (1) and (2); In the above formula (1), represents the initial value of one of the two encryption key functions, z1, z2, z3, z4 represent the first four hash values ​​of the eight hash values, and ⊕ represents an exclusive-OR operation; In the above formula (2), represents the initial value of the other encryption key function of the two encryption key functions, and z5, z6, z7, z8 represent the last 4 hash values ​​of the 8 hash values.

6. The method according to claim 5, characterized in that Performing key obfuscation processing on two first initial key sequences and two second initial key sequences to obtain a first key sequence and a second key sequence after the key obfuscation processing, including: Using the two first initial key sequences, a first pre-obfuscation key sequence and a second pre-obfuscation key sequence are generated, and according to the two second initial key sequences, a third pre-obfuscation key sequence and a fourth pre-obfuscation key sequence are generated; Key obfuscation processing is performed on the first pre-obfuscated key sequence and the third pre-obfuscated key sequence, and key obfuscation processing is performed on the second pre-obfuscated key sequence and the fourth pre-obfuscated key sequence, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing.

7. The method according to claim 6, characterized in that Using two first initial key sequences, generating a first pre-obfuscated key sequence and a second pre-obfuscated key sequence, comprising: For any first initial key sequence, the following formula (3) is used to calculate the pre-obfuscated key corresponding to each initial key in any first initial key sequence; In the above formula (3), x k represents the kth initial key in any first initial key sequence, represents the pre-obfuscated key corresponding to the kth initial key, represents a floor sign, a is a positive integer, mod represents a modulo operation, wherein k=1, 2, ..., K, and K is the length of any first initial key sequence; Using the pre-obfuscated keys corresponding to the initial keys, a pre-obfuscated key sequence corresponding to any one of the first initial key sequences is formed, wherein the pre-obfuscated key sequence corresponding to any one of the first initial key sequences is the first pre-obfuscated key sequence or the second pre-obfuscated key sequence; Correspondingly, performing key obfuscation processing on the first pre-obfuscated key sequence and the third pre-obfuscated key sequence, and performing key obfuscation processing on the second pre-obfuscated key sequence and the fourth pre-obfuscated key sequence, so as to obtain the first key sequence and the second key sequence after the key obfuscation processing, comprises: The first pre-obfuscation key sequence and the third pre-obfuscation key sequence are subjected to an XOR operation, and the second pre-obfuscation key sequence and the fourth pre-obfuscation key sequence are subjected to an XOR operation, so as to obtain the first key sequence and the second key sequence after the XOR operation.

8. A safety protection device for an electric power cloud platform, characterized in that: include: An acquisition unit, used for acquiring power data stored in the power cloud platform; A data reorganization unit, used for performing block processing on the power data to obtain two block sets, wherein the number of data blocks in the two block sets is different; The data reorganization unit is further used to use the data blocks in one of the two block sets to perform random reorganization processing on the data blocks in the other block set, so as to obtain a plurality of reorganized data blocks after the random reorganization processing; A key unit, used to construct two encryption key functions, and generate a first key sequence and a second key sequence using the two encryption key functions; An encryption unit, used for processing each reassembled data block into blocks to obtain data sub-blocks corresponding to each reassembled data block, wherein the number of data sub-blocks corresponding to any reassembled data block is two; an encryption unit, configured to perform encryption processing on two data sub-blocks corresponding to each reorganized data block using the first key sequence and the second key sequence, so as to obtain two encrypted data sub-blocks corresponding to each reorganized data block after encryption processing, wherein the two data sub-blocks corresponding to any reorganized data block use different key sequences when being encrypted; The encryption unit is also used to generate encrypted power data based on the two encrypted data sub-blocks corresponding to each reorganized data block, so as to complete the security protection of the power data after obtaining the encrypted power data.

9. A safety protection device for an electric power cloud platform, characterized in that: include: A memory, a processor and a transceiver that are sequentially communicatively connected, wherein the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the security protection method for the electric power cloud platform as described in any one of claims 1 to 7.

10. A computer program product comprising instructions, characterized in that When the instruction is executed on a computer, the computer is caused to execute the safety protection method for the electric power cloud platform as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • A data encryption method and device

    CN109040090A

  • Cloud storage data confidentiality protection method

    CN110213354A

  • Distributed cloud security storage method and system and storage medium

    CN113641648A

  • Data processing method, device, equipment, system and readable storage medium

    CN114995770A

  • Network security protection method and system for power system communication

    CN118101197A