Electric power industrial control system private cloud data complete homomorphic encryption method based on ECC

By adopting the ECC-based fully homomorphic encryption method in the private cloud of the power industrial control system, the problem of insufficient security, real-time and reliability of data transmission is solved, and high security and high efficiency data transmission is achieved.

CN120074787APending Publication Date: 2025-05-30CHINA DATANG CORP SCI & TECH RES INST CO LTD EAST CHINA BRANCH +6
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510116235.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The security, real-time and reliability of private cloud data transmission in power industrial control systems are highly required, and the existing technology is difficult to meet these needs.

Method used

The fully homomorphic encryption method of private cloud data based on ECC is adopted. By generating an elliptical curve and random basis point, selecting the prime number private key, determining the plaintext sequence, and dividing the similarity of random numbers into similarity and non-similarity random number sequences by measuring the similarity of random numbers, and selecting the appropriate homomorphic method for encryption and decryption.

Benefits of technology

It significantly improves the security and real-time nature of private cloud data transmission in the power industrial control system, enhances the confidentiality and privacy of data, and meets the security evaluation requirements of commercial password standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074787A_ABST
    Figure CN120074787A_ABST
Patent Text Reader

Abstract

The invention provides a power industrial control system private cloud data complete homomorphic encryption method based on ECC, and belongs to the field of power industrial control system network security protection, an elliptic curve E and a random base point G are generated on a finite field F (p), a prime number private key k is selected, and plaintext points (P1, P2,... Pn) of plaintext sequences (M1, M2,... Mn) coded on the elliptic curve E are determined; generating pseudo-random numbers, and measuring the similarity of the pseudo-random numbers to obtain a non-similarity pseudo-random number sequence and a similarity pseudo-random number sequence; selecting a non-similarity multiplication homomorphism or a non-similarity addition homomorphism based on the non-similarity pseudo-random number sequence, selecting a similarity multiplication homomorphism or a similarity addition homomorphism based on the similarity pseudo-random number sequence, and generating a public key Q; in a non-similarity multiplication homomorphism or a non-similarity addition homomorphism, encrypting to obtain a ciphertext, and in a similarity multiplication homomorphism or a similarity addition homomorphism, introducing a salting value, and encrypting to obtain a ciphertext; and plaintext points (P1, P2,... Pn) are obtained through decryption, so that the security, real-time performance and reliability of private cloud data transmission of the electric power industrial control system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of network security protection for power industrial control systems and private cloud data security encryption, and particularly to a fully homomorphic encryption method for private cloud data of power industrial control systems. Background Art

[0002] When performing encryption and decryption operations on the private cloud of a power industrial control system, it is necessary to consider the security and timeliness of private cloud data transmission. Especially when a large amount of private power production data is stored in the cloud, data security becomes an important guarantee factor. When a large amount of private power production data is encrypted, decrypted, and interacted with the cloud, the throughput performance and computing performance of data transmission are also factors that must be considered. The national cryptography algorithm SM2 is based on the principle of elliptic curve cryptography (ECC) and is widely used for private cloud storage and transmission encryption, with good data encryption, decryption, and anti-attack capabilities. For example, in the Chinese patent application for invention "Encryption Method Based on ECC and Homomorphic Encryption" with the publication number CN109768864A, the elliptic curve encryption technology and homomorphic encryption technology are combined, taking into account the high computing efficiency, high security of elliptic curve encryption, and the advantage of ciphertext computability of homomorphic encryption. However, it is hardly applied in the private cloud of power industrial control systems. With the construction of smart power plants, a large amount of data needs to be stored and interacted in the cloud. Considering the high requirements of the private cloud of power industrial control systems for data security and data interactivity, there is an urgent need for a national cryptography algorithm with higher security and stronger controllability to ensure the security of power production data. Summary of the Invention

[0003] The technical problem to be solved by the present invention is how to improve the security, real-time performance, and reliability of private cloud data transmission in power industrial control systems.

[0004] The present invention solves the above technical problem through the following technical solutions: A fully homomorphic encryption method for private cloud data of a power industrial control system based on ECC, including the following steps:

[0005] Step 1: Generate an elliptic curve E and a random base point G over the finite field F(p), select a prime private key k, and determine the plaintext sequence (M 1 , M 2 , … M n ) at the plaintext points (P 1 , P 2 , … P n ) encoded on the elliptic curve E;

[0006] Step 2: Generate pseudo-random numbers. By measuring the similarity of the pseudo-random numbers, obtain a non-similar pseudo-random number sequence (r 1 , r 2 , … r n ) and a similar pseudo-random number sequence (r 1 ′, r2 ′,…r m ′);

[0007] Step 3. Based on the non - similarity pseudo - random number sequence (r 1 , r 2 , … r n ), select non - similarity multiplicative homomorphism or non - similarity additive homomorphism. Based on the similarity pseudo - random number sequence (r 1 ′, r 2 ′, … r m ′), select similarity multiplicative homomorphism or similarity additive homomorphism, and generate the public key Q according to the private key k and the random base point G;

[0008] Step 4. Under non - similarity multiplicative homomorphism or non - similarity additive homomorphism, encrypt the plaintext points (P 1 , P 2 , … P n ) to obtain the ciphertext. Under similarity multiplicative homomorphism or similarity additive homomorphism, introduce a salt value, and encrypt the plaintext points (P 1 , P 2 , … P n ) with the public key Q and the salt value to obtain the ciphertext;

[0009] Step 5. Decrypt the ciphertext with the private key k to obtain the plaintext points (P 1 , P 2 , … P n ), and then obtain the plaintext sequence (M 1 , M 2 , … M n ).

[0010] In view of the high requirements for security and interactivity in the data transmission of the private cloud of the power industrial control system, relying on the national cryptographic algorithm SM2 ECC, when determining random numbers, the present invention classifies random numbers into similarity random number sequences and non - similarity random number sequences by measuring the similarity of random numbers, replacing the random number generation method in the original national cryptographic algorithm SM2 ECC, which can greatly increase the difficulty of deciphering the ciphertext of the original national cryptographic algorithm SM2 ECC and improve the security of data storage and transmission in the private cloud of the power industrial control system. Then, based on the non - similarity pseudo - random number sequence, select non - similarity multiplicative homomorphism or non - similarity additive homomorphism, and based on the similarity pseudo - random number sequence, select similarity multiplicative homomorphism or similarity additive homomorphism. For each homomorphism method, adopt different encryption and decryption calculation methods, with low transmission latency and strong system operation performance, replacing the fully homomorphic encryption algorithm in the original national cryptographic algorithm SM2 ECC, which can greatly improve the real - time performance and reliability of data transmission in the private cloud of the power industrial control system.

[0011] Preferably, the step 2 includes:

[0012] 2.1. Select a random number k 0 as the initial seed point, and 2 ≤ k 0 ≤ p, where p is a large prime number, p represents the order of the base point, and k 0 is a prime number, that is, its greatest common divisor is only 1 and k 0 itself;

[0013] 2.2. Introduce a time function factor δ, which varies linearly with the system time to generate a pseudo-random number r i :

[0014]

[0015] In formula (1), mod p means taking the remainder when the random number is divided by p, and i = 1, 2,... n;

[0016] 2.3. Calculate the similarity metric value of two pseudo-random numbers using the cosine similarity theorem. The calculation method is as follows:

[0017]

[0018] In formula (2), Sim(r 1 , r 2 ) represents the similarity metric value of pseudo-random numbers r 1 and r 2 , and Sim(r 1 , r 2 ) ranges from [0, 1];

[0019] 2.4. If the similarity metric value Sim(r 1 , r 2 ) is less than the threshold, the pseudo-random numbers are not similar, and the pseudo-random numbers are classified into the non-similar pseudo-random number sequence (r 1 , r 2 ,... r n ). If the similarity metric value Sim(r 1 , r 2 ) is greater than the threshold, the pseudo-random numbers are similar, and the pseudo-random numbers are classified into the similar pseudo-random number sequence (r 1 ′, r 2 ′,... r m ′).

[0020] Measuring the similarity of random numbers using the cosine similarity theorem can well measure the similarity between two vectors, and has the characteristics of strong accuracy and high robustness.

[0021] Preferably, in step 4, under non-similar multiplicative homomorphism, use the public key Q for the plaintext points (P 1 , P 2 ,... P n) The calculation method for encrypting to obtain ciphertext is as follows:

[0022]

[0023] Among them, A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is represented as Among them and can be expressed as follows:

[0024]

[0025] Here, record Then can be expressed as:

[0026]

[0027] Preferably, in the non - similarity additive homomorphism in step 4, using the public key Q to encrypt the plaintext points (P 1 , P 2 , … P n ) to obtain ciphertext, the calculation method is:

[0028]

[0029] Among them, A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is represented as Among them and can be expressed as follows:

[0030]

[0031] Here, record Then can be expressed as:

[0032]

[0033] Preferably, in the similarity multiplicative homomorphism in step 4, introduce a salt value π, π = k'·G, where k' represents a random private key and k' ≠ k; using the public key Q and the salt value π to encrypt the plaintext points (P 1 , P 2 , … P n ) to obtain ciphertext, the calculation method is:

[0034]

[0035] Among them, A i and B iAll represent ciphertext points, i = 1, 2, … n, and the ciphertext is represented as where and can be expressed as follows:

[0036]

[0037] Here, denote then can be denoted as:

[0038]

[0039] Preferably, in the similarity addition homomorphism of step 4, a salt value λ is introduced, λ = k”·G, where k” represents a random private key, and k” ≠ k' ≠ k. Using the public key Q and the salt value λ to encrypt the plaintext points (P 1 , P 2 , … P n ) to obtain the ciphertext calculation method is:

[0040]

[0041] where A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is represented as where and can be expressed as follows:

[0042]

[0043]

[0044] Here, denote then can be denoted as:

[0045]

[0046] Preferably, in the non - similarity multiplication homomorphism of step 5, using the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2 , … P n ) the calculation method is:

[0047]

[0048] Obtain the dot product of the plaintext points on the elliptic curve to achieve non - similarity multiplication homomorphism.

[0049] Preferably, in the non - similarity addition homomorphism of step 5, using the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2,…P n ) is calculated as follows:

[0050]

[0051] Get the accumulation of plaintext points on the elliptic curve to achieve non-similarity additive homomorphism.

[0052] Preferably, in the similarity multiplicative homomorphism in step 5, the ciphertext is decrypted with the private key k to obtain the plaintext points (P 1 ,P 2 ,…P n ) is calculated as follows:

[0053]

[0054] Get the dot product of plaintext points on the elliptic curve to achieve similarity multiplicative homomorphism.

[0055] Preferably, in the similarity additive homomorphism in step 5, the ciphertext is decrypted with the private key k to obtain the plaintext points (P 1 ,P 2 ,…P n ) is calculated as follows:

[0056]

[0057] Get the accumulation of plaintext points on the elliptic curve to achieve similarity additive homomorphism.

[0058] The method for fully homomorphic encryption of private cloud data of a power industrial control system based on ECC of the present invention is applied to the network communication layer, computing device layer and application data layer of the power industrial control system, which can improve the privacy and confidentiality of data transmission at the three levels, meet the security evaluation requirements of existing commercial cipher standards, solve the difficult problem of high-risk commercial cipher evaluation of power industrial control systems and private clouds, and has the advantages of scientific rationality, strong applicability, good effect, etc., realizing the improvement of the storage security and operation performance of private cloud data in power industrial control systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 It is a flowchart of the method for fully homomorphic encryption of private cloud data of a power industrial control system based on ECC provided by an embodiment of the present invention;

[0060] Figure 2 It is a flowchart of generating a non-similarity pseudo-random number sequence and a similarity pseudo-random number sequence in the method for fully homomorphic encryption of private cloud data of a power industrial control system based on ECC provided by an embodiment of the present invention;

[0061] Figure 3 It is a schematic diagram of the method for fully homomorphic encryption of private cloud data of a power industrial control system based on ECC provided by an embodiment of the present invention;

[0062] Figure 4 The schematic diagram of the encryption and decryption positions of the fully homomorphic encryption method for private cloud data of the power industrial control system based on ECC provided by the embodiment of the present invention;

[0063] Figure 5 The topology diagram of the encryption and decryption of the fully homomorphic encryption method for private cloud data of the power industrial control system based on ECC provided by the embodiment of the present invention. Detailed implementation manners

[0064] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the following combines specific embodiments and refers to the accompanying drawings to clearly and completely describe the technical solutions of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts belong to the scope of protection of the present invention.

[0065] Explanation of related technical terms:

[0066] Homomorphism: Let R and S represent two rings. Homomorphism can be simply understood as a certain mapping from R to S, that is: R→S.

[0067] Additive homomorphism: Randomly select two elements x and y from the ring R. According to the homomorphism property, we can get: means that x and y first perform an addition operation in the ring R and then perform a homomorphism operation, and then they can be mapped into the ring S. means that first perform a homomorphism operation on x, map it into the ring S, then perform a homomorphism operation on y, map it into the ring S, and finally perform an addition operation in the ring S. It can be seen that the order of addition and mapping in additive homomorphism can be swapped, and the two results are equal.

[0068] Multiplicative homomorphism: Randomly select two elements x and y from the ring R. According to the homomorphism property, we can get: means that x and y first perform a multiplication operation in the ring R and then perform a homomorphism operation, and then they can be mapped into the ring S. means that first perform a homomorphism operation on x, map it into the ring S, then perform a homomorphism operation on y, map it into the ring S, and finally perform a multiplication operation in the ring S. It can be seen that the order of multiplication and mapping in multiplicative homomorphism can be swapped, and the two results are equal.

[0069] Homomorphic encryption (HE) is to perform homomorphic operations on ciphertext data to obtain an output. Decrypting this output results in the same result as the output obtained by processing the unencrypted original data using the same method. The result obtained by performing operations on homomorphically encrypted data and then decrypting is the same as the result obtained by directly performing operations on the plaintext.

[0070] Fully homomorphic encryption means that it must satisfy both additive homomorphic encryption and multiplicative homomorphic encryption. If both properties are satisfied simultaneously, the encryption algorithm is called fully homomorphic encryption.

[0071] As Figure 1 and Figure 4 shown, this embodiment provides a method for fully homomorphic encryption of private cloud data in a power industrial control system based on ECC, which is mainly applied to the transmission link, interface machine, and virtualized cloud server of the power industrial control system. Refer to Figure 5 , the power industrial control system includes Production Area I, Production Area II, Production Area III, and Production Area IV. Production Area I is a DCS system, which includes a distributed processing unit and a station control layer. The station control layer includes a virtualized cloud server, a historical database, an engineer station, an operator station, an interface machine, etc. Production Area II is an SIS system, which includes a virtualized cloud server, a DCS interface machine, a common interface machine, a mirror server, an SIS server, a core switch, a real-time server, etc. Since the NCS system has data encryption and decryption security protection capabilities on the dispatching data network side with a longitudinal encryption device, it is not considered here temporarily.

[0072] The transmission link of the power industrial control system includes: the link from the on-site measurement points of the DCS system in Production Area I to the station control layer switch, the transmission link between Production Area I and the network isolation device in Production Area II, the transmission link between Production Area II and the network isolation device in Production Area III, and the transmission link between Production Area III and Production Area IV. When applied to the interface machine and the virtualized cloud server, it specifically involves the ECC encryption and decryption operations of the SSL client of the interface machine itself and the encryption machine of the virtualized cloud server.

[0073] The method includes the following steps:

[0074] Step 1: Generate an elliptic curve E and a random base point G over the finite field F(p), select a prime private key k, and determine the plaintext sequence (M 1 , M 2 , … M n ) at the plaintext points (P 1 , P 2 , … P n ) encoded on the elliptic curve E.

[0075] Step 2: Generate a pseudo-random number. By measuring the similarity of the pseudo-random number, obtain a non-similar pseudo-random number sequence (r1 , r 2 , … r n ), and the similarity pseudo - random number sequence (r 1 ′, r 2 ′, … r m ′). As Figure 2 shown, step 2 specifically includes the following steps:

[0076] 2.1. Select an initial seed point, and select a random number k 0 as the initial seed point, and 2 ≤ k 0 ≤ p, where p is a large prime number, p represents the order of the base point, and k 0 is a prime number, that is, its greatest common divisor is only 1 and k 0 itself.

[0077] 2.2. Generate pseudo - random numbers. Introduce a time - function factor δ, and δ changes linearly with the system time. Then the method for generating the pseudo - random number r i is as follows:

[0078]

[0079] In formula (1), mod p represents the remainder of the random number divided by p, and i = 1, 2, … n.

[0080] 2.3. Measure the similarity of the pseudo - random numbers. Generate pseudo - random numbers r 1 and r 2 according to formula (1). The cosine similarity theorem can well measure the similarity between two vectors, with the characteristics of strong accuracy and high robustness. Use the cosine similarity theorem to measure the similarity between two random numbers. The specific calculation method is as follows:

[0081]

[0082] In formula (2), Sim(r 1 , r 2 ) represents the similarity measurement value of the pseudo - random numbers r 1 and r 2 , and Sim(r 1 , r 2 ) ranges from [0, 1]. According to the properties of the cosine similarity theorem, a similarity measurement value of 1 indicates the strongest correlation between two vectors. According to the properties of the normal distribution, [0, 1] can be approximately considered to follow a normal distribution. Then the interval value 1 / 2 can be equally considered as the threshold judgment condition for whether the pseudo - random numbers r 1 and r 2 are similar.

[0083] 2.4. The present invention sets the threshold to 1 / 2. If the similarity measurement value Sim(r 1 , r2 ) If it is less than the threshold, the pseudo-random numbers are not similar, and the pseudo-random numbers are classified into the non-similar pseudo-random number sequence (r 1 , r 2 , … r n ). If the similarity metric value Sim(r 1 , r 2 ) is greater than the threshold, the pseudo-random numbers are similar, and the pseudo-random numbers are classified into the similar pseudo-random number sequence (r 1 ′, r 2 ′, … r m ′). Finally, the non-similar pseudo-random number sequence (r 1 , r 2 , … r n ) and the similar pseudo-random number sequence (r 1 ′, r 2 ′, … r m ) are obtained.

[0084] Since in the random number generation stage of the original national cryptographic algorithm SM2 ECC, the random numbers are randomly generated according to the algorithm mechanism with certain rules, if homomorphic addition or homomorphic multiplication is adaptively selected according to the similarity metric, there is a risk of being deciphered by a cryptanalyst who is familiar with the rules. In the random number generation method of the present invention, a similar random number sequence and a non-similar random number sequence are obtained by measuring the similarity of random numbers, and the encryption and decryption are designed according to the similarity size. Compared with the random number generation method in the original national cryptographic algorithm SM2 ECC, the difficulty of deciphering the ciphertext can be greatly improved, and the security of data storage and transmission in the private cloud of the power industrial control system can be improved. Perform IPsec VPN anti-attack pseudo-random number generation operations on the data collected and transmitted from the on-site measurement points of the DCS system in Production Area I to the station control layer switch, perform IPsec VPN anti-attack pseudo-random number generation operations on the transmission link between the network gates in Production Area I and Production Area II, perform IPsec VPN anti-attack pseudo-random number generation operations on the transmission link between the network gates in Production Area II and Production Area III, perform IPsec VPN anti-attack pseudo-random number generation operations on the transmission link between the network gates in Production Area III and Production Area IV, perform encryption machine anti-attack pseudo-random number generation operations on the virtualized cloud server, and perform SSL client anti-attack pseudo-random number generation operations on the interface machine.

[0085] Step 3: Select non-similar multiplicative homomorphism or non-similar additive homomorphism based on the non-similar pseudo-random number sequence (r 1 , r 2 , … r n ), and select similar multiplicative homomorphism or similar additive homomorphism based on the similar pseudo-random number sequence (r 1 ′, r 2 ′, … r m′) Select similarity multiplicative homomorphism or similarity additive homomorphism, and generate the public key Q according to the private key k and the random base point G.

[0086] As Figure 3 shown, the present invention divides the homomorphism method into four homomorphism methods: non-similarity multiplicative homomorphism, non-similarity additive homomorphism, similarity multiplicative homomorphism, and similarity additive homomorphism. When determining which homomorphism method to select, addition and multiplication are determined according to the existing selection method during the execution of the ECC algorithm, and the selection of non-similarity and similarity is based on the similarity of the pseudo-random number sequence obtained in step 2. Based on the non-similarity pseudo-random number sequence (r 1 , r 2 , … r n ), select non-similarity multiplicative homomorphism or non-similarity additive homomorphism. Based on the similarity pseudo-random number sequence (r 1 ′, r 2 ′, … r m ′), select similarity multiplicative homomorphism or similarity additive homomorphism. For each homomorphism method, the encryption and decryption methods used are different. The calculation method of the public key Q is:

[0087] Q = k·G (3)

[0088] where k is the private key and G is the random base point.

[0089] Step 4: Under non-similarity multiplicative homomorphism or non-similarity additive homomorphism, encrypt the plaintext points (P 1 , P 2 , … P n ) with the public key Q to obtain the ciphertext. Under similarity multiplicative homomorphism or similarity additive homomorphism, introduce a salt value, and encrypt the plaintext points (P 1 , P 2 , … P n ) with the public key Q and the salt value to obtain the ciphertext.

[0090] In step 4, under non-similarity multiplicative homomorphism, the calculation method of encrypting the plaintext points (P 1 , P 2 , … P n ) with the public key Q to obtain the ciphertext is:

[0091]

[0092] where A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is expressed as where and can be expressed as follows:

[0093]

[0094] It is recorded here that Then It can be expressed as:

[0095]

[0096] Under non - similarity additive homomorphism, using the public key Q to encrypt the plaintext points (P 1 , P 2 , … P n ) to obtain the ciphertext, the calculation method is:

[0097]

[0098] Among them, A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is expressed as Among them and can be expressed as follows:

[0099]

[0100] It is recorded here that Then It can be expressed as:

[0101]

[0102] Under similarity multiplicative homomorphism, introduce a salt value π, π = k'·G, where k' represents a random private key and k' ≠ k. Using the public key Q and the salt value π to encrypt the plaintext points (P 1 , P 2 , … P n ) to obtain the ciphertext, the calculation method is:

[0103]

[0104] Among them, A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is expressed as Among them and can be expressed as follows:

[0105]

[0106] It is recorded here that Then It can be recorded as:

[0107]

[0108] Under the similarity addition homomorphism, a salt value λ is introduced, where λ = k''·G, k'' represents a random private key, and k'' ≠ k' ≠ k. The plaintext points (P 1 , P 2 , … P n ) are encrypted using the public key Q and the salt value λ, and the calculation method of the ciphertext is as follows:

[0109]

[0110] Among them, A i and B i both represent ciphertext points, i = 1, 2, … n, and the ciphertext is represented as Among them and can be expressed as follows:

[0111]

[0112] Here, it is denoted as Then can be denoted as:

[0113]

[0114] Under the similarity multiplication homomorphism and the similarity addition homomorphism, by introducing a salt value, the influence of similarity on the security of the algorithm can be eliminated.

[0115] Step 5: Use the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2 , … P n ), and then obtain the plaintext sequence (M 1 , M 2 , … M n ).

[0116] In the said Step 5, under the non - similarity multiplication homomorphism, the calculation method of using the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2 , … P n ) is as follows:

[0117]

[0118] Obtain the dot product of the plaintext points on the elliptic curve to achieve non - similarity multiplication homomorphism.

[0119] Under the non - similarity addition homomorphism, the calculation method of using the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2 , … P n ) is as follows:

[0120]

[0121] Obtain the accumulation of plaintext points on the elliptic curve to achieve non-similarity additive homomorphism.

[0122] Under similarity multiplicative homomorphism, use the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2 , … P n ) and the calculation method is:

[0123]

[0124] Obtain the dot product of plaintext points on the elliptic curve to achieve similarity multiplicative homomorphism.

[0125] Under similarity additive homomorphism, use the private key k to decrypt the ciphertext to obtain the plaintext points (P 1 , P 2 , … P n ) and the calculation method is:

[0126]

[0127] Obtain the accumulation of plaintext points on the elliptic curve to achieve similarity additive homomorphism.

[0128] In the process of decrypting the ciphertext, there is no need to decrypt the ciphertext in the cloud. According to multiplicative homomorphism or additive homomorphism, the ciphertext can be decrypted, which can improve the operation efficiency of algorithm encryption and decryption, ensure the real-time performance and privacy of data transmission, and at the same time improve the cloud load capacity and ensure the reliability of cloud data transmission.

[0129] In view of the high requirements for security and interactivity in the data transmission of the private cloud of the power industrial control system, relying on the national cryptography algorithm SM2 ECC, when determining random numbers, the random numbers are divided into a sequence of similar random numbers and a sequence of non-similar random numbers by measuring the similarity of the random numbers, replacing the random number generation method in the original national cryptography algorithm SM2 ECC, which can greatly increase the difficulty of deciphering the ciphertext of the original national cryptography algorithm SM2 ECC and improve the security of data storage and transmission in the private cloud of the power industrial control system. Then, based on the sequence of non-similar pseudo-random numbers, non-similar multiplicative homomorphisms or non-similar additive homomorphisms are selected, and based on the sequence of similar pseudo-random numbers, similar multiplicative homomorphisms or similar additive homomorphisms are selected. For each homomorphic method, different encryption and decryption calculation methods are adopted, with low transmission latency and strong system operation performance, replacing the fully homomorphic encryption algorithm in the original national cryptography algorithm SM2 ECC. In terms of real-time performance, the present invention can transmit a large amount of generated data simultaneously and reduce the computing load on the cloud, significantly improving the real-time performance of private cloud data transmission. In addition, the present invention adopts a similarity-based fully homomorphic encryption method, increasing the difficulty of deciphering the password and further improving the security and reliability of private cloud data transmission in the power industrial control system. In addition, the salt value introduced in the similarity random number encryption method can greatly increase the difficulty of deciphering the ciphertext.

[0130] The method for fully homomorphic encryption of private cloud data in the power industrial control system based on ECC of the present invention is applied to the network communication layer, computing device layer and application data layer of the power industrial control system, which can improve the privacy and confidentiality of data transmission at the three levels, meet the security evaluation requirements of existing commercial cryptography standards, and solve the difficult problem of high-risk commercial cryptography evaluation in the power industrial control system and private cloud. It has the advantages of scientific rationality, strong applicability, good effect, etc., realizes the improvement of the security and operation performance of private cloud data storage in the power industrial control system, solves the problems of weak anti-attack ability and transmission efficiency of private cloud data in the power industrial control system, improves the compliance of commercial cryptography security evaluation in the power industrial control system and the password security protection ability of the private cloud, provides an innovative data security encryption method for the field of network security protection of the power industrial control system and private cloud data security encryption, and provides a replicable template for data security protection and commercial cryptography security evaluation in the power industrial control system. The hardware of the present invention is all commercially available products, and the software is compiled based on communication technology and cryptography technology, which is easy to implement.

[0131] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A fully homomorphic encryption method for private cloud data of power industrial control system based on ECC, characterized by: The following steps are involved: Step 1: Generate elliptic curve E and random base point G on finite field F(p), select prime private key k, determine plaintext sequence (M1, M2, ... M n ) is encoded on the elliptic curve E. n ); Step 2: Generate pseudo-random numbers, and obtain a series of non-similar pseudo-random numbers (r1, r2, ... r n ) and similar pseudo-random number series (r1′, r2′, … r m ′); Step 3: Based on the non-similar pseudo-random number series (r1, r2, ... r n ) selects non-similar multiplication homomorphism or non-similar addition homomorphism, based on the similarity of the pseudo-random number sequence (r1′, r2′, … r m ′) Select similarity multiplication homomorphism or similarity addition homomorphism, and generate a public key Q based on the private key k and the random base point G; Step 4: Under non-similar multiplication homomorphism or non-similar addition homomorphism, use the public key Q to perform a search on the plaintext points (P1, P2, ... P n ) is encrypted to obtain the ciphertext. Under the similarity multiplication homomorphism or similarity addition homomorphism, the salt value is introduced and the plaintext point (P1, P2, ... P n ) is encrypted to obtain the ciphertext; Step 5: Use the private key k to decrypt the ciphertext to get the plaintext point (P1, P2, ... P n ), and then get the plaintext sequence (M1,M2,…M n ).

2. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 1 is characterized in that: The step 2 comprises: 2.

1. Select a random number k0 as the initial seed point, and 2≤k0≤p, where p is a large prime number, p represents the order of the base point, and k0 is a prime number, that is, its greatest common divisor is only 1 and k0 itself; 2.

2. Introduce the time function factor δ, which changes linearly with the system time to generate a pseudo-random number r i : In formula (1), modp represents the remainder when a random number is divided by p, i = 1, 2, ... n; 2.

3. Use the cosine similarity theorem to calculate the similarity measure of two pseudo-random numbers. The calculation method is as follows: In formula (2), Sim(r1, r2) represents the similarity measure between pseudo-random numbers r1 and r2, and the value range of Sim(r1, r2) is [0, 1]; 2.

4. If the similarity measure Sim(r1,r2) is less than the threshold, the pseudo-random numbers are not similar and are classified into the non-similar pseudo-random number series (r1,r2,…r n ), if the similarity measure Sim(r1,r2) is greater than the threshold, the pseudo-random numbers are similar, and the pseudo-random numbers are classified into the similarity pseudo-random number series (r1′,r2′,…r m ′).

3. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 1 is characterized in that: In step 4, the public key Q is used to perform the non-similar multiplication homomorphism on the plaintext points (P1, P2, ...P n ) is encrypted to obtain the ciphertext as follows: Among them, A i and B i All represent ciphertext points, i = 1, 2, ... n, and the ciphertext is expressed as in and It can be expressed as follows: Here is the record but It can be expressed as:

4. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 1 is characterized in that: In the non-similar additive homomorphism in step 4, the public key Q is used to perform the operations on the plaintext points (P1, P2, ... P n ) is encrypted to obtain the ciphertext as follows: Among them, A i and B i All represent ciphertext points, i = 1, 2, ... n, and the ciphertext is expressed as in and It can be expressed as follows: Here is the record but It can be expressed as:

5. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 1 is characterized in that: In the step 4, under the similarity multiplication homomorphism, a salt value π is introduced, π=k'·G, where k' represents a random private key and k'≠k; the plaintext points (P1, P2, ...P n ) is encrypted to obtain the ciphertext as follows: Among them, A i and B i All represent ciphertext points, i = 1, 2, ... n, and the ciphertext is expressed as in and It can be expressed as follows: Here is the record but It can be written as:

6. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 1 is characterized in that: In the similarity addition homomorphism in step 4, a salt value λ is introduced, λ = k"·G, where k" represents a random private key, and k"≠k'≠k, and the plaintext points (P1, P2, ...P n ) is encrypted to obtain the ciphertext as follows: Among them, A i and B i All represent ciphertext points, i = 1, 2, ... n, and the ciphertext is expressed as in and It can be expressed as follows: Here is the record but It can be written as:

7. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 3 is characterized in that: In the non-similar multiplication homomorphism in step 5, the ciphertext is decrypted with the private key k to obtain the plaintext point (P1, P2, ... P n ) is calculated as: The dot product of the elliptic curve plaintext is obtained to achieve non-similarity multiplication homomorphism.

8. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 4 is characterized in that: In step 5, under the non-similar additive homomorphism, the ciphertext is decrypted with the private key k to obtain the plaintext point (P1, P2, ... P n ) is calculated as: The elliptic curve plaintext points are accumulated to achieve non-similarity addition homomorphism.

9. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 5 is characterized in that: In the step 5, under the similarity multiplication homomorphism, the ciphertext is decrypted with the private key k to obtain the plaintext point (P1, P2, ... P n ) is calculated as: The dot product of the elliptic curve plaintext is obtained to achieve similarity multiplication homomorphism.

10. The method for fully homomorphic encryption of private cloud data of an electric power industrial control system based on ECC according to claim 6 is characterized in that: In step 5, under the similarity addition homomorphism, the ciphertext is decrypted with the private key k to obtain the plaintext point (P1, P2, ... P n ) is calculated as: The elliptic curve plaintext points are accumulated to achieve similarity additive homomorphism.

Citation Information

Patent Citations

  • Encryption method based on ECC and homomorphic encryption

    CN109768864A