Distributed power supply password control method and system, terminal equipment and storage medium
By using digital signature and public key encryption technology of symmetric encryption keys in distributed power systems, the problems of complexity of cryptographic algorithms and high computing resource requirements in the prior art are solved, and the effect of reducing system costs and ensuring key security is achieved.
Patent Information
- Application Number
- CN202510267525.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-06
AI Technical Summary
In the prior art, cryptographic algorithms in distributed power systems are too complex and have high demand for computing resources, resulting in increased system costs.
By obtaining a symmetric encryption key in the cloud, and using the cloud private key for digital signature and public key encryption, the target key signature and ciphertext are generated, and transmitted to the secure authentication device for decryption, the decrypted symmetric encryption key is obtained, which is used to encrypt and decrypt the messages to be communicated.
Reduces the demand for computing resources, reduces system costs, and ensures the security and integrity of symmetric encryption keys, preventing keys from being tampered with.
Smart Images

Figure CN120110682A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a distributed power supply password control method, system, terminal equipment and storage medium. Background Art
[0002] In recent years, with the increasing global awareness of environmental protection and the transformation of energy structure, the new energy industry has ushered in new development opportunities, especially the development and utilization of renewable energy has become an important task. In this context, with the continuous development of the new energy industry and the increasing demand for renewable energy, small distributed power systems, such as home solar power generation systems, have become an indispensable part of the power system with their advantages of cleanliness, efficiency and flexibility. With the large-scale access to the power grid of small distributed systems, the widespread application of these systems and their cost sensitivity make it challenging to implement cryptographic technology in distributed systems. Traditional cryptographic algorithms are too complex in the execution process, such as large number decomposition and modular exponentiation operations, which require high computing resources, resulting in high computing power requirements and increased system costs. Summary of the invention
[0003] The embodiments of the present invention provide a distributed power supply cryptographic control method, system, terminal device and storage medium, which can effectively solve the problem that the cryptographic algorithm in the prior art is too complicated during execution, has high requirements for computing resources, leads to high computing power requirements and increased system costs.
[0004] An embodiment of the present invention provides a distributed power supply password control method, which is applicable to the cloud of a distributed power supply password control system; the distributed power supply password control system includes a plurality of distributed power supplies; the distributed power supply is configured with a security authentication device; the security authentication device is configured with a first private key for representing a private key of the distributed power supply and a first public key for representing a public key of the distributed power supply;
[0005] The distributed power supply password control method comprises:
[0006] Obtaining a symmetric encryption key, a second private key representing the cloud private key, a second public key representing the cloud public key, and the first public key;
[0007] Digitally signing the symmetric encryption key according to the second private key to obtain a target key signature;
[0008] Encrypting the symmetric encryption key according to the first public key to generate a target key ciphertext;
[0009] Transmitting the target key signature and the target key ciphertext to the security authentication device, so that the security authentication device decrypts the target key signature and the target key ciphertext according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key;
[0010] Encrypt the communication message according to the symmetric encryption key to obtain a message ciphertext;
[0011] The message ciphertext is transmitted to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain the decrypted message to be communicated.
[0012] Furthermore, the obtaining of the second public key includes:
[0013] Randomly generate numbers according to the preset length to obtain a number of random numbers;
[0014] Using the random number as a second private key for representing a cloud private key;
[0015] Calculation is performed based on the second private key to obtain a second public key used to represent the cloud public key.
[0016] Further, digitally signing the symmetric encryption key according to the second private key to obtain a target key signature includes:
[0017] Calculate the symmetric encryption key according to a preset hash function to obtain a message digest;
[0018] Encrypting the message digest according to the second private key to obtain an encrypted message digest;
[0019] The encrypted message digest is used as the target key signature to obtain the target key signature corresponding to the symmetric encryption key.
[0020] Furthermore, it also includes:
[0021] Calculate the corresponding hash value according to the message to be communicated;
[0022] Encrypt the corresponding hash value according to the symmetric encryption key to obtain a message verification string;
[0023] Transmitting the message check string to the security authentication device, so that the security authentication device decrypts the message check string according to the message check string and the decrypted symmetric encryption key to obtain a target hash value, and transmits the target hash value to the cloud;
[0024] Determine whether the target hash value and the hash value corresponding to the message to be communicated are the same;
[0025] If so, the message ciphertext remains unchanged during transmission;
[0026] If not, the message ciphertext has been changed during transmission.
[0027] Furthermore, the security authentication device is used to perform decryption according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key;
[0028] Decrypting according to the first private key, the second public key, the target key signature, and the target key ciphertext to obtain a decrypted symmetric encryption key includes:
[0029] Verify the target key signature according to the second public key to determine whether the target key signature is valid;
[0030] If so, decrypt the target key ciphertext according to the first private key to obtain a decrypted symmetric encryption key;
[0031] If not, an error prompt message is generated so that the user can take corresponding safety measures according to the error prompt message.
[0032] Furthermore, it also includes:
[0033] Obtaining a decryption response time of the security authentication device for decryption;
[0034] Calculate an average value according to the decryption response time to obtain an average response time;
[0035] Compare the decryption response time with the average response time to determine the target number of times the decryption response time is greater than the average response time;
[0036] When the target number of times is greater than the preset number of times, a device alarm message is generated, so that the user can check the corresponding security authentication device according to the device alarm message.
[0037] Furthermore, it also includes:
[0038] generating a key pair update instruction within a preset time interval;
[0039] Updating the second private key and the second public key according to the key pair update instruction;
[0040] The device replacement information is generated within a preset time interval, so that the user can replace the security authentication device according to the device replacement information.
[0041] As an improvement of the above solution, another embodiment of the present invention provides a distributed power supply password control system, including: a cloud and a plurality of distributed power supplies; the distributed power supplies are configured with a security authentication device; the security authentication device is configured with a first private key for representing a private key of the distributed power supply and a first public key for representing a public key of the distributed power supply;
[0042] The cloud is used to obtain a symmetric encryption key, a second private key for representing a cloud private key, a second public key for representing a cloud public key, and a first public key; digitally sign the symmetric encryption key according to the second private key to obtain a target key signature; encrypt the symmetric encryption key according to the first public key to generate a target key ciphertext; transmit the target key signature and the target key ciphertext to the security authentication device, so that the security authentication device decrypts the target key signature and the target key ciphertext according to the first private key, the second public key, the target key signature, and the target key ciphertext to obtain a decrypted symmetric encryption key; encrypt a message to be communicated according to the symmetric encryption key to obtain a message ciphertext; transmit the message ciphertext to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated;
[0043] The security authentication device shown is used to decrypt according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; decrypt the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated.
[0044] Another embodiment of the present invention provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, a distributed power supply password control method as described in the above embodiment is implemented.
[0045] Another embodiment of the present invention provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a distributed power supply password control method described in the above embodiment.
[0046] By implementing the present invention, at least the following beneficial effects are achieved:
[0047] The present invention provides a distributed power supply password control method, system, terminal device and storage medium, wherein the method is applicable to the cloud of a distributed power supply password control system; the distributed power supply password control system comprises a plurality of distributed power supplies; the distributed power supply is configured with a security authentication device; the security authentication device is configured with a first private key for representing a distributed power supply private key and a first public key for representing a distributed power supply public key; the distributed power supply password control method comprises: obtaining a symmetric encryption key, a second private key for representing a cloud private key, a second public key for representing a cloud public key and the first public key; digitally signing the symmetric encryption key according to the second private key to obtain Target key signature; encrypt the symmetric encryption key according to the first public key to generate a target key ciphertext; transmit the target key signature and the target key ciphertext to the security authentication device, so that the security authentication device decrypts according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain the decrypted symmetric encryption key; encrypt the message to be communicated according to the symmetric encryption key to obtain the message ciphertext; transmit the message ciphertext to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain the decrypted message to be communicated. By digitally signing and encrypting the symmetric encryption key and configuring a security authentication device for decryption and authentication, the security and integrity of the symmetric encryption key transmission are ensured. When a large number of messages to be communicated are transmitted, the symmetric encryption key is used for encryption and decryption operations to avoid using too many computing resources for message encryption and decryption operations. At the same time, the symmetric encryption key is encrypted and decrypted according to the first public key and the second private key, which not only ensures that the required symmetric encryption key is completely transmitted to the security authentication device of the distributed power supply, but also ensures the security of the symmetric encryption key during the transmission process to prevent the key from being tampered with. In addition, the symmetric encryption key is much smaller than the data volume of the message to be communicated, so the use of key pairs for transmission of the symmetric encryption key does not require too high computing power, thereby reducing system costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a flow chart of a distributed power supply password control method provided by an embodiment of the present invention;
[0049] Figure 2 It is a structural schematic diagram of a distributed power supply password control system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0050] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0051] See also Figure 1 , is a flow chart of a distributed power supply password control method provided by an embodiment of the present invention, which is applicable to the cloud of a distributed power supply password control system; the distributed power supply password control system includes a plurality of distributed power supplies; the distributed power supply is configured with a security authentication device; the security authentication device is configured with a first private key for representing a distributed power supply private key and a first public key for representing a distributed power supply public key;
[0052] Specifically, the distributed power supply reserves a device interface, and the security authentication device is inserted into the distributed power supply through the reserved device interface; the first private key represents a private key representing the distributed power supply stored in the security authentication device; the first public key represents a public key representing the distributed power supply stored in the security authentication device.
[0053] In a preferred embodiment of the present invention, the security authentication device is a USB shield. The USB shield must have a nationally certified security level, be able to securely store key pairs, support encryption operations, and have a hardware protection mechanism to prevent physical and logical attacks. Since the USB shield can store multiple different keys, several first private keys and first public keys can be configured.
[0054] The distributed power supply password control method includes:
[0055] S1, obtaining a symmetric encryption key, a second private key used to represent a cloud private key, a second public key used to represent a cloud public key, and a first public key;
[0056] Specifically, the symmetric encryption key is an SM4 key, and a 128-bit random number can be generated as an SM4 key using CSPRNG. The second private key represents the private key stored on the cloud; the second public key represents the public key stored on the cloud. When the cloud acts as the sender, the second private key is a confidential key that only the cloud knows and is used to digitally sign the message to ensure the integrity of the message and the authenticity of the source. The second private key cannot be made public, otherwise any participant can forge the signature of the cloud. The second public key is a public key that can be obtained by any end and is used to verify the digital signature created by the cloud using the private key. It can be made public safely because the second public key cannot be used to decrypt data encrypted using the second private key. At this time, the distributed power source acts as the receiver, and its first private key is a confidential key that is only known by the current end device as the receiver. It is used to decrypt the received ciphertext and obtain the original message. The first private key cannot be made public, otherwise any end can decrypt the message sent from the cloud to the current end. The first public key is a public key that can be obtained by any end. The cloud acts as the sender and uses the first public key of the receiver to encrypt the message, ensuring that only the receiver with the corresponding private key can decrypt the message. Data encrypted by a public key can only be decrypted with the corresponding private key, and data signed by a private key can only be verified with the corresponding public key.
[0057] Preferably, the acquisition of the second public key includes:
[0058] Randomly generate numbers according to the preset length to obtain a number of random numbers;
[0059] Using the random number as a second private key for representing a cloud private key;
[0060] Calculation is performed based on the second private key to obtain a second public key used to represent the cloud public key.
[0061] In a preferred embodiment of the present invention, the cloud acts as the sender and uses its own second private key to digitally sign the symmetric encryption key A to obtain the target key signature S; encrypts the symmetric encryption key A according to the first public key to generate the target key ciphertext C; encrypts the communication message M according to the symmetric encryption key A to obtain the message ciphertext D, and sends the target key signature S, the target key ciphertext C and the message ciphertext D to the security authentication device.
[0062] S2. Digitally sign the symmetric encryption key according to the second private key to obtain a target key signature;
[0063] Specifically, digitally signing the symmetric encryption key according to the second private key to obtain a target key signature includes:
[0064] Calculate the symmetric encryption key according to a preset hash function to obtain a message digest;
[0065] Encrypting the message digest according to the second private key to obtain an encrypted message digest;
[0066] The encrypted message digest is used as the target key signature to obtain the target key signature corresponding to the symmetric encryption key.
[0067] In a preferred embodiment of the present invention, the symmetric encryption key A is operated according to a preset hash function to obtain a message digest, and then the message digest is encrypted according to the second private key to obtain an encrypted message digest, and finally the encrypted message digest is used as a target key signature to obtain a target key signature corresponding to the symmetric encryption key.
[0068] Preferably, a corresponding hash value is calculated according to the message to be communicated;
[0069] Encrypt the corresponding hash value according to the symmetric encryption key to obtain a message verification string;
[0070] Transmitting the message check string to the security authentication device, so that the security authentication device decrypts the message check string according to the message check string and the decrypted symmetric encryption key to obtain a target hash value, and transmits the target hash value to the cloud;
[0071] Determine whether the target hash value and the hash value corresponding to the message to be communicated are the same;
[0072] If so, the message ciphertext remains unchanged during transmission;
[0073] If not, the message ciphertext has been changed during transmission.
[0074] In a preferred embodiment of the present invention, first, a hash calculation is performed on the communication message (original message) to obtain a hash value. The hash function can map data of any length to a fixed-length hash value, and the generated hash values should be very different for different inputs. The hash value obtained by the above calculation is encrypted using a symmetric encryption key, and the encrypted hash value is called a message check string. The encrypted message check string is transmitted to the security authentication device, and the security authentication device uses the same symmetric encryption key (decrypted symmetric encryption key) to decrypt the received message check string to obtain the original hash value (target hash value); then, the security authentication device transmits this target hash value to the cloud, and the cloud simultaneously receives the target hash value transmitted from the security authentication device. Then, the cloud compares the hash value calculated by itself with the target hash value transmitted from the security authentication device. If the two hash values are the same, it means that the message to be communicated has not changed during the transmission process and maintains integrity; if the two hash values are different, it means that the message to be communicated may have changed during the transmission process, or there is an error in the encryption / decryption process.
[0075] S3. Encrypt the symmetric encryption key according to the first public key to generate a target key ciphertext;
[0076] In a preferred embodiment of the present invention, the symmetric encryption key is encrypted according to the first public key, and an encryption algorithm in a public key cryptosystem may be used, such as RSA, ECC, etc. The result of the encryption is to generate a target key ciphertext, which is an encrypted text from which the symmetric encryption key cannot be directly read.
[0077] S4, transmitting the target key signature and the target key ciphertext to the security authentication device, so that the security authentication device decrypts according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key;
[0078] Specifically, the security authentication device is used to decrypt according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key;
[0079] Decrypting according to the first private key, the second public key, the target key signature, and the target key ciphertext to obtain a decrypted symmetric encryption key includes:
[0080] Verify the target key signature according to the second public key to determine whether the target key signature is valid;
[0081] If so, decrypt the target key ciphertext according to the first private key to obtain a decrypted symmetric encryption key;
[0082] If not, an error prompt message is generated so that the user can take corresponding safety measures according to the error prompt message.
[0083] In a preferred embodiment of the present invention, the security authentication device receives the second public key, the target key signature and the target key ciphertext, and uses the second public key to verify the target key signature, ensuring that the target key signature is generated by a legitimate party holding the corresponding private key, thereby verifying its authenticity. If the signature is valid, it means that the source of the target key ciphertext is credible, and the next decryption operation can be continued, that is, the target key ciphertext is decrypted according to the first private key to obtain the decrypted symmetric encryption key. After the decryption is successful, the decrypted symmetric encryption key is obtained for subsequent data encryption or decryption operations. If the signature is invalid, the device will generate an error prompt message to prompt the user of possible security risks and recommend taking corresponding security measures. At this time, the device will not continue to perform the decryption operation, but will generate an error prompt message to prevent potential security risks, such as man-in-the-middle attacks or data tampering. After receiving the error prompt message, the user should take appropriate security measures according to the prompt, such as re-acquiring the key, checking the security of the communication channel, etc.
[0084] S5. Encrypt the communication message according to the symmetric encryption key to obtain a message ciphertext;
[0085] In a preferred embodiment of the present invention, the message to be communicated may be text, data, instructions, etc. Before encryption, the message exists in plain text. The message ciphertext is the encrypted message to be communicated, which can maintain the confidentiality of the information during the transmission process, and its content cannot be directly read even if it is intercepted. The encrypted message ciphertext is usually transmitted to the recipient together with the target key signature (used to verify the authenticity of the source of the message) and the target key ciphertext (the encrypted symmetric encryption key, used by the recipient to decrypt the message). The recipient first uses his own private key to decrypt the target key ciphertext to obtain the symmetric encryption key, and then uses this key to decrypt the message ciphertext to obtain the original message. Before or after decryption, the recipient will also verify the hash value of the message to ensure its integrity.
[0086] S6. Transmit the message ciphertext to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain the decrypted message to be communicated.
[0087] Specifically, in the security authentication device, the decrypted symmetric encryption key has been obtained through private key decryption. This key was previously transmitted and securely stored through public key encryption. The security authentication device uses the decrypted symmetric encryption key to decrypt the received message ciphertext, using the same symmetric encryption algorithm as used for encryption, but in the opposite direction. After successful decryption, the security authentication device obtains the decrypted message to be communicated. This message is the same as the original plaintext message sent, but because it has undergone the encryption and decryption process, its confidentiality during transmission is ensured. Through the encryption and decryption process, it is ensured that the message will not be read by unauthorized third parties during transmission. The decryption operation enables the recipient to restore the original message content for subsequent processing or response. The entire encryption, transmission and decryption process is an important part of ensuring the secure transmission of information in the distributed power supply cryptographic control system.
[0088] Specifically, it also includes:
[0089] Obtaining a decryption response time of the security authentication device for decryption;
[0090] Calculate an average value according to the decryption response time to obtain an average response time;
[0091] Compare the decryption response time with the average response time to determine the target number of times the decryption response time is greater than the average response time;
[0092] When the target number of times is greater than the preset number of times, a device alarm message is generated, so that the user can check the corresponding security authentication device according to the device alarm message.
[0093] In a preferred embodiment of the present invention, when the security authentication device receives the message ciphertext and starts the decryption operation, the system will record the time required from the start of decryption to the completion of decryption, that is, the decryption response time. Collect multiple samples of decryption response time within a period of time, and calculate the average value of these samples to obtain the average response time. This average value reflects the average time consumed by the security authentication device for decryption operation under normal circumstances. Compare each decryption response time with the average response time, and record the number of times the decryption response time is greater than the average response time, that is, the target number of times. If the target number of times is greater than the preset number of times, the system will consider that there may be problems with the decryption performance of the security authentication device, and generate a device alarm message, which will include the specific situation and possible reasons for the abnormal decryption response time. After receiving the device alarm message, the user (such as a system administrator or maintenance personnel) will check and maintain the corresponding security authentication device according to the prompts in the message, including checking the hardware status, software version, network connection, etc. of the device, and performing necessary troubleshooting and repair.
[0094] In another preferred embodiment of the present invention, for a security authentication device such as a USB shield, 1) visual inspection can also be performed: check whether the USB shield has obvious physical damage, such as cracks, deformation, burn marks or damage to the connection port; check the connection port: confirm that the USB port is free of dirt, dust or damage to ensure normal connection. 2) Connection test: insert the USB shield into the USB port of a computer or other device; check whether the computer can recognize the USB shield. If the system cannot recognize it, it may be that the USB shield is damaged or has a connection problem. 3) Driver check: confirm that the driver of the USB shield has been correctly installed and updated to the latest version; check the status of the USB shield through the USB shield management software, including key status, storage space usage, etc. 4) Authentication test: try to use the USB shield for identity authentication, such as logging into the system or conducting transactions; encryption / decryption test: perform encryption or decryption operations to check whether the USB shield can process data normally. 5) System log analysis: check the logs of the operating system and the USB shield management software to find any errors or warnings related to the USB shield; if the USB shield supports logging, analyze the USB shield log to identify abnormal behavior. 6) LED indicator check: Observe whether the LED indicator on the USB shield works as expected; Circuit test (professional operation): If you suspect that the internal circuit of the USB shield is damaged, you may need professional equipment to perform circuit testing.
[0095] Preferably, it also includes:
[0096] generating a key pair update instruction within a preset time interval;
[0097] Updating the second private key and the second public key according to the key pair update instruction;
[0098] The device replacement information is generated within a preset time interval, so that the user can replace the security authentication device according to the device replacement information.
[0099] In a preferred embodiment of the present invention, the parties involved in the encrypted communication negotiate to determine a common synchronization time to ensure that the key is replaced within the specified time. The system will automatically generate a key pair update instruction according to a preset time interval (such as daily, weekly or monthly), and this instruction is a signal to trigger the key pair update operation. When the system receives the key pair update instruction, it will generate a new private key and public key pair and replace the second private key and the second public key currently in use. The updated private key and public key pair will take effect immediately and be used for subsequent encryption and decryption operations. At the same time, the old private key and public key pair will be securely stored or destroyed to ensure that it will not be obtained by unauthorized third parties. In addition to key pair updates, the system will also generate device replacement information according to a preset time interval. The device replacement information includes the specific time of replacing the device and the recommended replacement reason (such as device aging, performance degradation, etc.). After receiving the device replacement information, the user (such as a system administrator or maintenance personnel) will replace the security authentication device according to the prompts in the information. The replacement process may include removing the old device, installing the new device, and configuring the necessary parameters of the new device. Regularly updating key pairs can effectively reduce the risk of key cracking or leakage. Even if a key pair is leaked at a certain point in time, the leaked key will soon become invalid due to the regular replacement of key pairs. By regularly replacing equipment, problems such as equipment aging or performance degradation can be discovered and handled in a timely manner, thereby extending the service life of the entire system. Regular updates of key pairs and equipment help keep the system up to date and reduce system downtime caused by equipment failure or key leakage.
[0100] In a preferred embodiment of the present invention, a public key is used to encrypt a message and a private key is used to decrypt a message, which is used to securely exchange symmetric encryption keys and perform digital signatures. The SM4 key is used to encrypt and decrypt the communication message, which is used to encrypt a large amount of data, because symmetric encryption is generally more efficient than asymmetric encryption. That is, asymmetric encryption is used to securely exchange the SM4 key. The SM4 key is used to encrypt the actual transmitted data (the communication message), which is more efficient when processing a large amount of data.
[0101] By implementing this embodiment, a symmetric encryption key, a second private key used to represent a cloud private key, a second public key used to represent a cloud public key, and a first public key are obtained; the symmetric encryption key is digitally signed according to the second private key to obtain a target key signature; the symmetric encryption key is encrypted according to the first public key to generate a target key ciphertext; the target key signature and the target key ciphertext are transmitted to the security authentication device, so that the security authentication device decrypts them according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; the message to be communicated is encrypted according to the symmetric encryption key to obtain a message ciphertext; the message ciphertext is transmitted to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated. By digitally signing and encrypting the symmetric encryption key and configuring a security authentication device for decryption and authentication, the security and integrity of the symmetric encryption key transmission are ensured. When a large number of messages to be communicated are transmitted, the symmetric encryption key is used for encryption and decryption operations to avoid using too many computing resources for message encryption and decryption operations. At the same time, the symmetric encryption key is encrypted and decrypted according to the first public key and the second private key, which not only ensures that the required symmetric encryption key is completely transmitted to the security authentication device of the distributed power supply, but also ensures the security of the symmetric encryption key during the transmission process to prevent the key from being tampered with. In addition, the symmetric encryption key is much smaller than the data volume of the message to be communicated, so the use of key pairs for transmission of the symmetric encryption key does not require too high computing power, thereby reducing system costs.
[0102] See also Figure 2 , is a schematic diagram of a distributed power supply cryptographic control system provided by an embodiment of the present invention, including a cloud and a plurality of distributed power supplies; the distributed power supplies are configured with a security authentication device; the security authentication device is configured with a first private key for representing a private key of the distributed power supply and a first public key for representing a public key of the distributed power supply;
[0103] The cloud is used to obtain a symmetric encryption key, a second private key for representing a cloud private key, a second public key for representing a cloud public key, and a first public key; digitally sign the symmetric encryption key according to the second private key to obtain a target key signature; encrypt the symmetric encryption key according to the first public key to generate a target key ciphertext; transmit the target key signature and the target key ciphertext to the security authentication device, so that the security authentication device decrypts the target key signature and the target key ciphertext according to the first private key, the second public key, the target key signature, and the target key ciphertext to obtain a decrypted symmetric encryption key; encrypt a message to be communicated according to the symmetric encryption key to obtain a message ciphertext; transmit the message ciphertext to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated;
[0104] The security authentication device shown is used to decrypt according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; decrypt the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated.
[0105] The present invention provides a distributed power supply cryptographic control system, comprising a cloud and a plurality of distributed power supplies; the distributed power supplies are configured with a security authentication device; the security authentication device is configured with a first private key for representing a private key of the distributed power supply and a first public key for representing a public key of the distributed power supply; according to the cloud, a symmetric encryption key, a second private key for representing a cloud private key, a second public key for representing a cloud public key, and the first public key are obtained; the symmetric encryption key is digitally signed according to the second private key to obtain a target key signature; the symmetric encryption key is encrypted according to the first public key to generate a target key ciphertext; the target key signature and the target key ciphertext are transmitted to the security authentication device so that the security authentication The security authentication device decrypts according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; encrypts the message to be communicated according to the symmetric encryption key to obtain a message ciphertext; transmits the message ciphertext to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated; through the security authentication device, decrypts according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated. By digitally signing and encrypting the symmetric encryption key and configuring a security authentication device for decryption and authentication, the security and integrity of the symmetric encryption key transmission are ensured. When a large number of messages to be communicated are transmitted, the symmetric encryption key is used for encryption and decryption operations to avoid using too many computing resources for message encryption and decryption operations. At the same time, the symmetric encryption key is encrypted and decrypted according to the first public key and the second private key, which not only ensures that the required symmetric encryption key is completely transmitted to the security authentication device of the distributed power supply, but also ensures the security of the symmetric encryption key during the transmission process to prevent the key from being tampered with. In addition, the symmetric encryption key is much smaller than the data volume of the message to be communicated, so the use of key pairs for transmission of the symmetric encryption key does not require too high computing power, thereby reducing system costs.
[0106] It should be noted that the system embodiment described above is merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, in the drawings of the system embodiment provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art may understand and implement it without paying any creative effort.
[0107] Those skilled in the art can clearly understand that, for the sake of convenience and brevity, the specific working process of the system described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0108] Another embodiment of the present invention further provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements a distributed power supply password control method as described in the above embodiment when executing the computer program. The terminal device may be a computing device such as a desktop computer, a notebook, a PDA, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.
[0109] The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, and uses various interfaces and lines to connect various parts of the entire terminal device.
[0110] The memory can be used to store the computer program, and the processor realizes various functions of the terminal device by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc.; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Med ia Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device or other volatile solid-state storage device.
[0111] Another embodiment of the present invention provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a distributed power supply password control method described in the above embodiment.
[0112] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by the processor, the steps of each of the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or system that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium.
[0113] The above is a preferred embodiment of the present invention. It should be pointed out that a person skilled in the art can make several improvements and modifications without departing from the principle of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A distributed power supply password control method, characterized in that: Applicable to the cloud of a distributed power supply cryptographic control system; the distributed power supply cryptographic control system includes a plurality of distributed power supplies; the distributed power supply is configured with a security authentication device; the security authentication device is configured with a first private key for representing a private key of the distributed power supply and a first public key for representing a public key of the distributed power supply; The distributed power supply password control method comprises: Obtaining a symmetric encryption key, a second private key representing the cloud private key, a second public key representing the cloud public key, and the first public key; Digitally signing the symmetric encryption key according to the second private key to obtain a target key signature; Encrypting the symmetric encryption key according to the first public key to generate a target key ciphertext; Transmitting the target key signature and the target key ciphertext to the security authentication device, so that the security authentication device decrypts the target key signature and the target key ciphertext according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; Encrypt the communication message according to the symmetric encryption key to obtain a message ciphertext; The message ciphertext is transmitted to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain the decrypted message to be communicated.
2. A distributed power supply password control method as claimed in claim 1, characterized in that: The obtaining of the second public key includes: Randomly generate numbers according to the preset length to obtain a number of random numbers; Using the random number as a second private key for representing a cloud private key; Calculation is performed based on the second private key to obtain a second public key used to represent the cloud public key.
3. A distributed power supply password control method as claimed in claim 1, characterized in that: Digitally signing the symmetric encryption key according to the second private key to obtain a target key signature includes: Calculate the symmetric encryption key according to a preset hash function to obtain a message digest; Encrypting the message digest according to the second private key to obtain an encrypted message digest; The encrypted message digest is used as the target key signature to obtain the target key signature corresponding to the symmetric encryption key.
4. A distributed power supply password control method as claimed in claim 1, characterized in that: Also includes: Calculate the corresponding hash value according to the message to be communicated; Encrypt the corresponding hash value according to the symmetric encryption key to obtain a message verification string; Transmitting the message check string to the security authentication device, so that the security authentication device decrypts the message check string according to the message check string and the decrypted symmetric encryption key to obtain a target hash value, and transmits the target hash value to the cloud; Determine whether the target hash value and the hash value corresponding to the message to be communicated are the same; If so, the message ciphertext remains unchanged during transmission; If not, the message ciphertext has been changed during transmission.
5. A distributed power supply password control method as claimed in claim 1, characterized in that: The security authentication device is used to decrypt according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; Decrypting according to the first private key, the second public key, the target key signature, and the target key ciphertext to obtain a decrypted symmetric encryption key includes: Verify the target key signature according to the second public key to determine whether the target key signature is valid; If so, decrypt the target key ciphertext according to the first private key to obtain a decrypted symmetric encryption key; If not, an error prompt message is generated so that the user can take corresponding safety measures according to the error prompt message.
6. A distributed power supply password control method as claimed in claim 1, characterized in that: Also includes: Obtaining a decryption response time of the security authentication device for decryption; Calculate an average value according to the decryption response time to obtain an average response time; Compare the decryption response time with the average response time to determine the target number of times the decryption response time is greater than the average response time; When the target number of times is greater than the preset number of times, a device alarm message is generated, so that the user can check the corresponding security authentication device according to the device alarm message.
7. A distributed power supply password control method as claimed in claim 1, characterized in that: Also includes: generating a key pair update instruction within a preset time interval; Updating the second private key and the second public key according to the key pair update instruction; The device replacement information is generated within a preset time interval, so that the user can replace the security authentication device according to the device replacement information.
8. A distributed power supply password control system, characterized in that: It includes a cloud and several distributed power sources; the distributed power sources are configured with a security authentication device; the security authentication device is configured with a first private key for representing a private key of the distributed power source and a first public key for representing a public key of the distributed power source; The cloud is used to obtain a symmetric encryption key, a second private key representing a cloud private key, a second public key representing a cloud public key, and the first public key; Digitally signing the symmetric encryption key according to the second private key to obtain a target key signature; encrypting the symmetric encryption key according to the first public key to generate a target key ciphertext; The target key signature and the target key ciphertext are transmitted to the security authentication device, so that the security authentication device decrypts the target key signature and the target key ciphertext according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain the decrypted symmetric encryption key; the message to be communicated is encrypted according to the symmetric encryption key to obtain the message ciphertext; the message ciphertext is transmitted to the security authentication device, so that the security authentication device decrypts the message ciphertext according to the decrypted symmetric encryption key to obtain the decrypted message to be communicated; The security authentication device shown is used to decrypt according to the first private key, the second public key, the target key signature and the target key ciphertext to obtain a decrypted symmetric encryption key; decrypt the message ciphertext according to the decrypted symmetric encryption key to obtain a decrypted message to be communicated.
9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, a distributed power supply password control method as claimed in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute a distributed power supply cryptographic control method as described in any one of claims 1 to 7.
Citation Information
Cited By
License authentication control method and system, computer equipment and medium
CN120979721A