Cross-domain authentication method and device for instantaneous data of power grid, electronic equipment and storage medium

By generating the user's digital identity and key, combining the SM2 signature algorithm and alliance blockchain technology, cross-domain authentication of grid instantaneous data is realized, solving the problem that the existing technology cannot achieve cross-domain authentication of grid instantaneous data, ensuring data security and adapting to the needs of new power systems.

CN120110754APending Publication Date: 2025-06-06POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510267869.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art cannot realize cross-domain authentication of instantaneous data in the power grid, and cannot guarantee the data security of cross-domain scheduling of a large number of devices in a transient.

Method used

By generating the user's digital identity, public key, private key, temporary private key and temporary public key, combined with SM2 signature algorithm and alliance blockchain technology, the user's cross-domain authentication and the generation and verification of block credentials are realized.

Benefits of technology

It realizes cross-domain authentication of instantaneous data in the power grid, ensures the security of cross-domain scheduling data, reduces the workload of authentication work, and adapts to the needs of large-scale cross-domain scheduling in a short time in the new power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110754A_ABST
    Figure CN120110754A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-domain authentication method and device for instantaneous data of a power grid, electronic equipment and a storage medium, and the method comprises the steps: when a registration request of a user is received, carrying out the analysis according to the registration request, obtaining an identity identifier of the user, and carrying out the registration of the user according to the identity identifier; when a cross-domain authentication request of a user is received, generating a first identifier signature of the user for the digital identity identifier in a power system production non-control region, judging whether the first identifier signature is a legal signature, and if so, determining a corresponding block certificate of the user in the domain; and when a cross-domain request of a user is received, querying whether the user is a legal user on the chain, if so, sending the cross-domain request to the authentication server of the different domain so as to enable the authentication server of the different domain to perform signature verification operation on the user, and if the signature verification is successful, generating a corresponding block certificate of the user in the different domain. Through the method, cross-domain authentication of the instantaneous data of the power grid can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure communication technology, and in particular to a cross-domain authentication method, device, electronic device and storage medium for instantaneous data of a power grid. Background Art

[0002] With the emergence of a variety of new power generation methods, my country's new power system has developed rapidly, from traditional thermal power, hydropower and other power generation methods as the core to photovoltaic power generation, wind power generation and other renewable energy power generation as the main supply. The new power generation method has the advantages of clean, good environmental benefits, renewable, and short infrastructure cycle. In the new power system with new energy as the main body, a large number of distributed power sources constrained by the characteristics of new energy power generation are obviously unable to adapt to the basic requirements of "source follows load", and in some cases, light and wind power generation also have anti-peak characteristics. Therefore, compared with the traditional power system, the transformation from "source follows load" to "source-load interaction" will become one of the main features of the new power system. Based on this feature, the new power system is bound to face a large number of cross-domain dispatching operations in a short period of time: power exchange and dispatch between different regions or power systems, and power systems in different regions can exchange power across domains through aggregation layer nodes to achieve resource optimization and supply and demand coordination. However, in the case of instantaneous cross-domain dispatching of a large number of devices in a distributed power network environment, identity authentication in the new power system faces huge challenges. The existing technology cannot realize cross-domain authentication of instantaneous data of the power grid, and cannot guarantee the data security of instantaneous cross-domain dispatching of a large number of devices. Summary of the invention

[0003] The present invention provides a method, device, electronic device and storage medium for cross-domain authentication of instantaneous data of a power grid, so as to solve the technical problem that the prior art cannot realize cross-domain authentication of instantaneous data of a power grid.

[0004] In order to solve the above technical problems, an embodiment of the present invention provides a cross-domain authentication method for instantaneous data of a power grid, comprising:

[0005] When receiving a registration request from a user, obtaining an identity identifier of the user according to the registration request, then generating a digital identity identifier of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then registering the user according to the digital identity identifier, the public key, the private key, the temporary public key and the temporary private key;

[0006] When receiving a cross-domain authentication request from a user, generate a first identification signature of the user for the digital identity in the non-control area of ​​the power system production, and determine whether the first identification signature is a legal signature. If so, issue a corresponding legal factor to the user, and generate a corresponding block certificate for the user in this domain;

[0007] When receiving a cross-domain request from a user, the chain is queried to see if the user is a legitimate user. If so, the cross-domain request is sent to the authentication server in the foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the domain on the chain based on the user's digital identity, and performs a signature verification operation on the user based on the block certificate. If the signature verification is successful, a block certificate corresponding to the user in the foreign domain is generated.

[0008] As a preferred solution, it also includes:

[0009] Obtain corresponding elliptic curve equation parameters according to preset security parameters, and then determine the coordinates of the base point according to the elliptic curve equation;

[0010] A random integer is generated as the private key of the system, and the public key corresponding to the system is generated according to the private key and the base point. Then the public key, the coordinates of the base point, and the parameters of the elliptic curve equation are written into the blockchain as public parameters.

[0011] As a preferred solution, the digital identity of the user, the public key, private key, temporary private key and temporary public key of the user in the production non-control area of ​​the power system are generated according to the identity identifier, and then the user is registered according to the digital identity, public key, private key, temporary public key and temporary private key, including:

[0012] Generate a digital identity corresponding to the user according to the identity identifier, and determine whether the user has completed registration according to the digital identity, if the registration has been completed, exit the current operation, if the registration has not been completed, perform the user registration operation;

[0013] The user registration operation includes:

[0014] Generate a random number as a private key of the user in the production non-control area of ​​the power system, generate a public key corresponding to the user in the production non-control area according to the private key and the base point, and send the private key and public key of the user in the production non-control area to the user;

[0015] Generate a temporary private key and a temporary public key of the user in the generated non-control area, and then generate a hash value corresponding to the digital identity according to the temporary public key, the identity identifier of the user and the digital identity corresponding to the user.

[0016] As a preferred solution, the generating user signs the first identification of the digital identity in the non-control area of ​​the power system production, and determines whether the first identification signature is a legal signature, and if so, issues a corresponding legal factor to the user, including:

[0017] When receiving a cross-domain authentication request from a user, generating a corresponding first identifier and a second identifier according to a preset SM2 cryptographic algorithm, and combining the first identifier and the second identifier to generate a first identifier signature of the user for the digital identity identifier in the production non-control area;

[0018] Generate a corresponding verification message according to the timestamp when the first identification signature is generated, the user's identity identifier, the digital identity corresponding to the user, and the first identification signature, and send the verification message to the authentication service center, so that the authentication service center determines whether the user identity is within the preset validity period according to the verification message, and if not, terminates the current operation; if so, calculates the second identification signature of the authentication service center for the digital identity according to the digital identity corresponding to the user;

[0019] The first identification signature is compared with the second identification signature. If the first identification signature is consistent with the second identification signature, the first identification signature is determined to be a legal signature and a legal factor is issued to the user. If the first identification signature is inconsistent with the second identification signature, the first identification signature is determined to be an illegal signature and a legal factor is not issued to the user.

[0020] As a preferred solution, the generation of the block certificate corresponding to the user in the domain includes:

[0021] When the user's cross-domain authentication is successful, a block certificate corresponding to the user is generated, the block certificate is written into the transaction, and then the transaction is broadcast to the blockchain network.

[0022] As a preferred solution, the block certificate corresponding to the user in the local domain is queried on the chain according to the user's digital identity, and the user's signature is verified according to the block certificate. If the signature verification is successful, the block certificate corresponding to the user in the foreign domain is generated, including:

[0023] According to the user's digital identity, the corresponding block certificate of the user in the domain is queried on the chain, and the identification signature of the user's digital identity by the authentication service center in the foreign domain and the hash value of the identification signature are calculated according to the identity;

[0024] The user's signature is verified based on the block certificate, digital identity, the identification signature of the user's digital identity by the foreign authentication service center and the hash value of the identification signature. If the verification is successful, the corresponding block certificate of the user in the foreign domain is generated.

[0025] Based on the above embodiment, another embodiment of the present invention provides a cross-domain authentication device for instantaneous data of a power grid, comprising: a user registration module, a cross-domain authentication module and a cross-domain request module;

[0026] The user registration module is used to, when receiving a registration request from a user, parse the registration request to obtain an identity identifier of the user, then generate a digital identity identifier of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then register the user according to the digital identity identifier, the public key, the private key, the temporary public key and the temporary private key;

[0027] The cross-domain authentication module is used to generate a first identification signature of the user for the digital identity in the non-control area of ​​the power system production when receiving a cross-domain authentication request from the user, and determine whether the first identification signature is a legal signature. If so, issue a corresponding legal factor to the user and generate a corresponding block certificate for the user in the domain;

[0028] The cross-domain request module is used to query whether the user is a legitimate user on the chain when receiving the user's cross-domain request. If so, the cross-domain request is sent to the authentication server in the foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the domain on the chain according to the user's digital identity, and performs a signature verification operation on the user according to the block certificate. If the signature verification is successful, the block certificate corresponding to the user in the foreign domain is generated.

[0029] As a preferred solution, it also includes: a public parameter generation module;

[0030] The public parameter generation module is used to obtain the corresponding elliptic curve equation parameters according to the preset security parameters, and then determine the coordinates of the base point according to the elliptic curve equation; randomly generate an integer as the private key of the system, generate the public key corresponding to the system according to the private key and the base point, and then write the public key, the coordinates of the base point, and the elliptic curve equation parameters as public parameters into the blockchain.

[0031] Based on the above embodiments, another embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, the cross-domain authentication method of power grid instantaneous data described in the above invention embodiments is implemented.

[0032] Based on the above embodiments, another embodiment of the present invention provides a storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the cross-domain authentication method of power grid instantaneous data described in the above invention embodiment.

[0033] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0034] The present invention provides a cross-domain authentication method for instantaneous data of a power grid. When a registration request from a user is received, an identity identifier of the user is obtained by parsing the registration request, and then a digital identity identifier of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​a power system are generated according to the identity identifier, and then the user is registered according to the digital identity identifier, the public key, the private key, the temporary public key and the temporary private key; when a cross-domain authentication request from the user is received, a first identification signature of the user for the digital identity identifier in the production non-control area of ​​the power system is generated, and it is judged whether the first identification signature is a legal signature, if so, a corresponding legal factor is issued to the user, and a block certificate corresponding to the user in the local domain is generated; when a cross-domain request from the user is received, whether the user is a legal user is queried on a chain, and if so, the cross-domain request is sent to an authentication server in a foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the local domain on a chain according to the digital identity identifier of the user, and performs a signature verification operation on the user according to the block certificate, and if the signature verification is successful, a block certificate corresponding to the user in the foreign domain is generated. The present invention can realize cross-domain authentication of instantaneous data of power grid. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is a flow chart of a cross-domain authentication method for instantaneous data of a power grid provided by an embodiment of the present invention;

[0036] Figure 2 It is the overall cross-domain authentication framework diagram of the present invention;

[0037] Figure 3 This is a schematic diagram of the structure of a cross-domain authentication device for instantaneous data of a power grid provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0038] In order to make the purpose, technical solutions and advantages of this application clearer, the technical solutions in this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0039] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by technicians in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" in the specification and claims of this application and the above-mentioned figure descriptions and any variations thereof are intended to cover non-exclusive inclusions.

[0040] In the description of the embodiments of the present application, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "multiple" is more than two, unless otherwise clearly and specifically defined.

[0041] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0042] In the description of the embodiments of the present application, the term "and / or" is only a description of the association relationship of the associated objects, indicating that there may be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0043] In the description of the embodiments of the present application, the term "multiple" refers to more than two (including two). Similarly, "multiple groups" refers to more than two groups (including two groups), and "multiple pieces" refers to more than two pieces (including two pieces).

[0044] In the description of the embodiments of the present application, unless otherwise clearly specified and limited, technical terms such as "installed", "connected", "connected", "fixed" and the like should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the internal connection of two elements or the interaction relationship between two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to the specific circumstances.

[0045] Embodiment 1

[0046] Please refer to Figure 1 , is a flow chart of a cross-domain authentication method for instantaneous data of a power grid provided by an embodiment of the present invention, comprising the following specific steps:

[0047] S1. When receiving a registration request from a user, obtain the user's identity identifier according to the registration request, then generate the user's digital identity, the user's public key, private key, temporary private key and temporary public key in the production non-control area of ​​the power system according to the identity identifier, and then register the user according to the digital identity, public key, private key, temporary public key and temporary private key;

[0048] Preferably, it also includes: obtaining corresponding elliptic curve equation parameters according to preset security parameters, and then determining the coordinates of the base point according to the elliptic curve equation; randomly generating an integer as a private key of the system, generating a public key corresponding to the system according to the private key and the base point, and then writing the public key, the coordinates of the base point, and the elliptic curve equation parameters as public parameters into the blockchain.

[0049] Specifically, the present invention provides a power grid identity authentication method based on the SM2 signature algorithm and the alliance blockchain, which adopts cryptographic technologies such as hash functions and digital signatures to realize safe and reliable identity authentication of users in different domains, and effectively solves the above-mentioned problems mentioned in the background technology.

[0050] The important terms and constraints of the present invention are as follows:

[0051] Alliance chain: Alliance chain is a blockchain jointly managed by multiple institutions. Each organization or institution manages one or more nodes. Its data is only allowed to be read and written by institutions within the system. Only authorized entities can join or exit the network. Its main features are weak centralization, strong controllability, and fast transaction speed.

[0052] Hash function: also known as hash function, is to compress messages or data of any length into a summary, making the data volume smaller and the format fixed. Hash function has the characteristics of one-way and collision resistance, and can be used for message authentication to ensure the integrity of the message.

[0053] Digital signature: It can be regarded as a digitized form of a traditional handwritten signature. It exists in data information or as an attachment or logically related data. It is unforgeable and is used to identify the identity of the data signer and verify the content of the signed message. It mainly includes signature algorithms and signature verification algorithms.

[0054] Please refer to Figure 2 ,for Figure 2 This is the overall cross-domain authentication framework diagram of the present invention. The specific steps of the instantaneous large amount of cross-domain authentication method for power grid data of the present invention are as follows:

[0055] 1. System initialization: The system selects appropriate elliptic curve parameters based on the security parameter λ and transmits some parameters to the proxy layer node through a secure channel:

[0056] S1-1. The power system selects appropriate elliptic curve parameters according to the security parameter λ. Usually, a specific elliptic curve equation is selected. According to the requirements of the present invention, the elliptic curve parameters corresponding to the 128-bit security parameter (λ=128) are selected. The elliptic curve parameters are calculated using a 256-bit finite field F p , where p is a large prime number. The elliptic curve form is:

[0057] y 2 ≡x 3 +ax+b(mod p);

[0058] The parameters a and b satisfy the non-singularity condition. Then, the coordinates of the base point G (X G ,Y G ).

[0059] S1-2. Without loss of generality, the identity identifiers of the production non-control area aggregation node user, the production non-control area authentication service center, and the production control area authentication center are respectively (hereinafter, domain A is used to refer to the production non-control area sink, and domain B is used to refer to the production control area):

[0060] {ID A , ID ASa , ID ASb};

[0061] The production control area is the core area of ​​the power system, which is mainly used for real-time control and monitoring of the power production process. It is responsible for the operation of the power data acquisition and monitoring system, energy management system, wide-area phasor measurement system, etc., to ensure real-time monitoring and scheduling of power production. The production non-control area is used for non-real-time production management and auxiliary systems to support related businesses of power production. Deployment such as fault recording information management system, wind power prediction system, etc., to collect, process and analyze data to provide support for production control. The aggregation node collects data from each sensor and transmits it to the central processing system or cloud platform to support the monitoring and control of the power system. The authentication service center is the key node responsible for user identity authentication and data interaction legitimacy verification.

[0062] S1-3. The system randomly generates an integer as the private key d of the system, which usually ranges from 1 to the order n of the elliptic curve. The public key Q is the multiple of the base point G corresponding to the private key d, that is, Q = d·G. A The relevant parameters received are the public key Q, the coordinates of the base point G (X G ,Y G ), elliptic curve equation parameters a and b.

[0063] S1-4, the system initializes all common parameters param = {X G, Y G , a, b, Q} will be transmitted to the aggregation node proxy layer node through a secure channel; the proxy layer node BAS A The public parameters are written into the blockchain and are publicly visible to users in different grid domains.

[0064] Preferably, the method of generating a digital identity of a user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then registering the user according to the digital identity, public key, private key, temporary public key and temporary private key, comprises: generating a digital identity corresponding to the user according to the identity identifier, and judging whether the user has completed registration according to the digital identity, if the registration has been completed, exiting the current operation, and if the registration has not been completed, executing the user registration operation; wherein the user registration operation comprises: generating a random number as a private key of the user in a production non-control area of ​​the power system, and generating a public key corresponding to the user in the production non-control area according to the private key and the base point, and sending the private key and public key of the user in the production non-control area to the user; generating a temporary private key and a temporary public key of the user in the production non-control area, and then generating a hash value corresponding to the digital identity according to the temporary public key, the identity identifier of the user and the digital identity corresponding to the user.

[0065] 2. User registration, KGC in this domain A Generate the user's digital identity, public key and private key, temporary private key and temporary public key based on the identity identifier provided by the user:

[0066] S2-1, the user at the aggregation node in the production non-control area sends the identity identifier ID through a secure channel A Send to the authentication service center AS A .

[0067] S2-2, Certification Service Center AS A After receiving the user registration message, perform the following operations:

[0068] (1) Based on the user's ID A , T A =SM3(ID A ), T A Used to check whether the user has registered. If so, exit the registration process. Otherwise, enter process (2).

[0069] (2) Key Generation Center KGC A Generate key pair: KGC A Generate a random number d IDA As user U′ AThe private key in the trust domain A has a value range from 1 to the order n of the elliptic curve. Then the user's public key P is generated IDA =d IDA G. Send the public key and private key of the requesting user in trust domain A to the registered user through an encrypted channel;

[0070] (3) Key Generation Center KGC A T A With P IDA The two pieces of information are sent to the proxy layer node in the local domain through a secure channel. The proxy layer node in the local domain maintains a json file that stores the two pieces of information in key-value format.

[0071] In the present invention, the key generation center KGC A With the certification service center AS A The same server is divided into two modules just to facilitate the description of corresponding functions.

[0072] S2-3. Generate the user's temporary private key and temporary public key: SK U =SM3((d IDA ×Q)||T),PK U =SK U ×G;

[0073] S2-4. Generate a hash value A of the digital identity U : Based on the user's temporary public key p IDA , Identifier ID A Generate a digital identity A U =SM3(ID A ||Ω u ||a||b||X G ||Y G ||X U ||Y U );

[0074] S2-5. Generate T A The hash value, e 1 =SM3(T A ||A U ), where e 1 Represents the hash value of the user's digital identity, T A A digital identity for a user.

[0075] S2. When receiving a cross-domain authentication request from a user, generate a first identification signature of the user for the digital identity in the non-control area of ​​the power system production, and determine whether the first identification signature is a legal signature. If so, issue a corresponding legal factor to the user, and generate a corresponding block certificate for the user in this domain;

[0076] Preferably, the method generates a first identification signature of the digital identity identifier of the user in the non-control area of ​​power system production, and determines whether the first identification signature is a legal signature. If so, a corresponding legal factor is issued to the user, including / ; when a cross-domain authentication request from the user is received, a corresponding first identification and a second identification are generated according to a preset SM2 cryptographic algorithm, and the first identification and the second identification are combined to generate a first identification signature of the digital identity identifier of the user in the non-control area of ​​production; according to the timestamp when the first identification signature is generated, the identity identifier of the user, the digital identity identifier corresponding to the user, and the first identification signature, a corresponding verification message is generated and The verification message is sent to the authentication service center, so that the authentication service center determines whether the user identity is within the preset validity period according to the verification message. If not, the current operation is terminated. If yes, the authentication service center calculates the second identification signature of the digital identity according to the digital identity corresponding to the user; the first identification signature is compared with the second identification signature. If the first identification signature is consistent with the second identification signature, the first identification signature is determined to be a legal signature and a legal factor is issued to the user. If the first identification signature is inconsistent with the second identification signature, the first identification signature is determined to be an illegal signature, and the legal factor is not issued to the user.

[0077] Preferably, the generating of the block certificate corresponding to the user in the domain includes: when the user cross-domain authentication is successful, generating the block certificate corresponding to the user, writing the block certificate into the transaction, and then broadcasting the transaction to the blockchain network.

[0078] 3. Intra-domain authentication: The user of this domain initiates an authentication request to the authentication service center of this domain. After receiving the request, the authentication service center of this domain first verifies the validity and legality of the message. If the verification is successful, it means that both parties in communication are legal. The authentication service center of this domain issues a legal factor to the user of this domain, and the two parties subsequently conduct encrypted communication:

[0079] S3-1. User U′ A Use the SM2 cryptographic algorithm to calculate the signature of the user's own identity: Calculate part of the user's identity signature according to the following formula:

[0080] r 1 =(e 1 +x 1 )mod n;

[0081] The second part of the signature of the requesting user's tag in domain A is calculated according to the following formula:

[0082] φ 1 =(1+SK U ) -1(kr 1 ×SK U )mod n;

[0083] The first part of the signature is combined with the second part of the signature to form the signature S of the user identity sending the request in domain A. a The first part of the signature ensures that the signature is bound to the message content and the random number, providing a security basis for the signature. The second part of the signature binds the user's identity and the random number k to ensure the identity authentication capability of the signature. The combination method selects binary encoding: 1 and φ 1 Convert them into binary streams and encode them together.

[0084] S3-2, User U′ A The timestamp T when the user signs the tag 1 , User Identifier ID A 、Digital identity T A , digital identity signature S a Generate message M 1 = <T 1 , ID A , T A , S a >Send to the authentication service center AS A .

[0085] S3-3, local authentication service center AS A Receive verification message M 1 After that, first parse the message and select the current timestamp T 2 , if |T 2 -T temp |<ΔT, it is established, which means that the identity continues to proceed to the next step within the validity period. Otherwise, the session is terminated or not accepted. 1 -T 2 |<ΔT, if true, then the information M 1 is fresh, otherwise the session is terminated or not accepted; where ΔT is the difference between the timestamp attached to the message and the current timestamp when the message is received;

[0086] S3-4, Authentication Service Center AS A Verify the signature of the user ID in the domain authentication request:

[0087] Certification Service Center AS A According to the digital identity T A , obtain the public key of the user applying for cross-domain authentication. A According to the digital identity T A If the corresponding user public key cannot be obtained, the authentication service center AS AReject cross-domain requests from users in domain A. Otherwise, calculate the corresponding temporary private key and public key;

[0088] Calculate temporary private key and public key: T ASa =SM3(ID ASa ), SK ASa =SM3((p IDA ×d)||T ASa ),PK ASa =SK ASa ×G;

[0089] S3-5. Follow the same detailed steps in S2 and S3 to obtain the authentication service center AS A Signature of the identification (the previous steps S2 and S3);

[0090] The signature of the authentication request user in this domain who meets the authentication conditions is sent to the authentication service center AS A The signature of the identifier is compared. If the two are the same, it is a legal signature. Otherwise, the signature of the identifier made by the cross-domain requesting user in domain A is considered illegal. The f factor is used to indicate whether the signature is legal. When the identifier signature is legal, the value is 1, otherwise, the value is 0.

[0091] S3-6, Authentication Service Center AS A Sign the userid for cross-domain requests:

[0092] Calculate and verify the signature of the user identity of the cross-domain request in domain A and then authenticate the service center AS A The hash value of the identity information: M ASa =SM3(ID ASa ||Ω ASa ||a||b||X G ||Y G ||X ASa ||Y ASa );

[0093] Calculate the hash value of the signed identity of the user identity of the cross-domain request in domain A:

[0094] e 2 =SM3(T A ||M ASa ||f);

[0095] Using the SM2 cryptographic algorithm, the authentication service center verifies the signature of the authentication request user identity in the domain and then calculates the signature of the identity: the authentication service center AS A Verify the first part of the signature of the identity after sending the request user identity in domain A: r 2 =(e 2 +x 1) mod n, where r 2 Indicates the authentication service center AS A Verify the first part of the signature of the identity after the signature of the requesting user identity sent in domain A;

[0096] Computing Certification Service Center AS A Verify the second part of the signature of the identity after sending the signature of the requesting user identity in domain A: φ 2 =(1+d) -1 (kr 2 ×d)mod n, where φ 2 Indicates the authentication service center AS A Verify the second part of the signature of the identity after the signature of the requesting user identity sent in domain A;

[0097] The first part of the signature and the second part of the signature are combined into the authentication service center AS A Verify the signature of the cross-domain request user ID and then sign the ID S ASa .

[0098] 4. Integration on the chain: When the local authentication service center AS A With the domain user U′ A After the domain authentication is successful, the domain authentication service center AS A According to the authentication results, the relevant information is sent to the aggregation node proxy layer node BAS through a secure channel. A , aggregation node proxy layer node BAS A Generate block certificate:

[0099] S4-1, when the domain authentication service center AS A With the domain user U′ A After the domain authentication is successful, the domain authentication service center AS A According to the authentication results, the relevant information is sent to the aggregation node proxy layer node BAS through a secure channel. A , aggregation node proxy layer node BAS A Generate block certificate:

[0100]

[0101] Then write the credentials into the transaction:

[0102]

[0103] S4-2, TX content is stored on the chain in the form of key-value. With T A Spliced ​​into key part, SM3 (BCert A ), T2 , S ASa For the value part;

[0104] S4-3, local aggregation node proxy layer node BAS A Broadcast the transaction to the blockchain network.

[0105] S3. When receiving a cross-domain request from a user, query whether the user is a legitimate user on the chain. If so, send the cross-domain request to the authentication server in the foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the domain on the chain according to the user's digital identity, and performs a signature verification operation on the user according to the block certificate. If the signature verification is successful, a block certificate corresponding to the user in the foreign domain is generated.

[0106] Preferably, the block certificate corresponding to the user in the local domain is queried on the chain according to the digital identity of the user, and a signature verification operation is performed on the user according to the block certificate. If the signature verification is successful, a block certificate corresponding to the user in the foreign domain is generated, including: querying the block certificate corresponding to the user in the local domain on the chain according to the digital identity of the user, and calculating the identification signature of the digital identity of the user by the authentication service center in the foreign domain and the hash value of the identification signature according to the identity; performing a signature verification operation on the user according to the block certificate, the digital identity, the identification signature of the digital identity of the user by the authentication service center in the foreign domain and the hash value of the identification signature. If the signature verification is successful, a block certificate corresponding to the user in the foreign domain is generated.

[0107] 5. Cross-domain authentication, local domain user U′ A AS A Initiate a cross-domain request, the domain authentication service center AS A First, check on the chain whether the user is a legitimate user. If it is legitimate, send the cross-domain request to the foreign authentication server AS B ; When the foreign authentication server AS B After receiving the cross-domain request, first check the freshness of the cross-domain message. If it is legal, query the chain based on the digital identity of the authentication server in this domain and the digital identity of the cross-domain request user. A ) Query the block certificate content stored in the proxy layer node of this domain. After that, the foreign domain server performs the signature verification operation. If successful, it will conduct subsequent encrypted communication with the user of this domain.

[0108] S5-1, local authentication service center AS A In the local proxy layer node BAS A Check whether there is a generated block certificate BCert A If yes, check BCert AThe exp value in the query is used to verify whether the user's temporary identity has expired. If it has expired, the S2 step is repeated. Otherwise, the cross-domain request is made. Sent to the foreign aggregation node proxy layer node BAS B , where T 3 Timestamp for cross-domain requests;

[0109] S5-2, Foreign aggregation node proxy layer node BAS B After receiving the cross-domain request, first parse the message and select the current timestamp T 4 , if |T 3 -T 4 |<ΔT, if true, then the information M 2 is fresh, otherwise terminate the session or refuse to agree;

[0110] S5-3, Foreign aggregation node proxy layer node BAS B According to the news T ASA With T A Perform an on-chain query, and then transmit the queried information to the foreign authentication server through an encrypted channel to S ASa Perform signature verification operation;

[0111] Foreign Authentication Service Center AS B According to the same calculation method in step S3-6, the authentication service center AS is obtained. B The hash value of the user's signature e 3 ;

[0112] Calculate the coordinates of the verification point on the elliptic curve: Where (x 2 ,y 2 ) represents the coordinates of the verification point on the elliptic curve;

[0113] Certification Service Center AS B Determine whether the signature refers to satisfying r at the same time 2 ∈[1,n-1], r 2 =(e 3 +x 2 )mod n, If it meets the requirements, go to step 1, otherwise go to step 3;

[0114] Step 1: Determine whether the value of factor f is 1. If so, proceed to step 2; otherwise, proceed to step 3.

[0115] Step 2: Foreign authentication service center AS B Agree to cross-domain user U′ A request, and for user U′ A Start the service;

[0116] Step 3: Foreign authentication service center AS B Reject cross-domain user U′ A Requests;

[0117] S5-4, foreign authentication server AS B After verifying the identity of the user in this domain, the basic information is transmitted to the foreign domain proxy layer node BAS through a secure channel B , foreign proxy layer node BAS B Generate a foreign blockchain certificate for the user, namely:

[0118]

[0119] The certificate is then written into the transaction, and then the transaction is written into the blockchain. The transaction content is as follows:

[0120]

[0121] It can be seen that the present invention provides a cross-domain authentication method for instantaneous data of a power grid, and the present invention can achieve the following beneficial effects:

[0122] (1) The present invention introduces blockchain technology and does not rely on third-party credit endorsement to achieve cross-domain authentication. It utilizes the distributed storage function and tamper-proof, data interoperability, and traceability characteristics of the alliance chain to effectively protect cross-domain scheduling information in the power grid.

[0123] (2) The present invention proposes a temporary identity method, which provides a temporary identity for each user and authentication service center in the domain, and provides a guarantee for the security of the keys of the users and authentication service center in the domain. The temporary identity is combined with the authentication method to solve the problem of a large number of repeated authentications in a short period of time.

[0124] (3) The present invention also aims at the storage limitation of blockchain, and sets a proxy layer node for each domain to process the stored data in the domain. After the proxy layer node processes the data, it is stored on the chain in the form of Key-Value, so as to achieve the effect of reducing storage and improving query speed. It is foreseeable that a large amount of data will be generated in the power grid aggregation node layer domain in a short period of time, and storing a large amount of data in the blockchain will inevitably lead to excessive transaction delays that are unacceptable, so it is chosen to store the data in the form of Key-Value on the chain to reduce the query speed.

[0125] (4) In order to prevent a large number of cross-domain requests from flooding into the authentication service center in a short period of time and placing a heavy burden on the authentication service center, the present invention adds a proxy layer between the aggregation node entity layer and the blockchain layer to alleviate the burden on the authentication service center;

[0126] (5) The results of local domain authentication are applied to cross-domain authentication, which reduces the workload of authentication work and copes with the scenario where a large number of users perform cross-domain authentication in a short period of time.

[0127] Embodiment 2

[0128] Please refer to Figure 3 , is a schematic diagram of the structure of a cross-domain authentication device for instantaneous data of a power grid provided by an embodiment of the present invention, the device comprising: a user registration module, a cross-domain authentication module and a cross-domain request module;

[0129] The user registration module is used to, when receiving a registration request from a user, parse the registration request to obtain an identity identifier of the user, then generate a digital identity identifier of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then register the user according to the digital identity identifier, the public key, the private key, the temporary public key and the temporary private key;

[0130] The cross-domain authentication module is used to generate a first identification signature of the user for the digital identity in the non-control area of ​​the power system production when receiving a cross-domain authentication request from the user, and determine whether the first identification signature is a legal signature. If so, issue a corresponding legal factor to the user and generate a corresponding block certificate for the user in the domain;

[0131] The cross-domain request module is used to query whether the user is a legitimate user on the chain when receiving the user's cross-domain request. If so, the cross-domain request is sent to the authentication server in the foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the domain on the chain according to the user's digital identity, and performs a signature verification operation on the user according to the block certificate. If the signature verification is successful, the block certificate corresponding to the user in the foreign domain is generated.

[0132] Preferably, it also includes: a public parameter generation module; the public parameter generation module is used to obtain the corresponding elliptic curve equation parameters according to the preset security parameters, and then determine the coordinates of the base point according to the elliptic curve equation; randomly generate an integer as the private key of the system, generate the public key corresponding to the system according to the private key and the base point, and then write the public key, the coordinates of the base point, and the elliptic curve equation parameters as public parameters into the blockchain.

[0133] It should be noted that the device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, in the accompanying drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art may understand and implement it without paying any creative effort.

[0134] Those skilled in the art can clearly understand that for the sake of convenience and brevity, the specific working process of the device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0135] Embodiment 3

[0136] Accordingly, an embodiment of the present invention provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the cross-domain authentication method for instantaneous data of a power grid as described in the above-mentioned embodiment of the invention is implemented.

[0137] The electronic device may be a computing device such as a desktop computer, a notebook, a palm computer, a cloud server, etc. The device may include, but is not limited to, a processor and a memory.

[0138] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the device, and various interfaces and lines are used to connect various parts of the entire device.

[0139] Embodiment 4

[0140] Accordingly, an embodiment of the present invention provides a storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the cross-domain authentication method for power grid instantaneous data described in the above-mentioned embodiment of the invention.

[0141] The memory can be used to store the computer program, and the processor realizes various functions of the device by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc.; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (FlashCard), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0142] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by the processor, the steps of each method embodiment described above can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0143] The above is a preferred embodiment of the present invention. It should be pointed out that a person skilled in the art can make several improvements and modifications without departing from the principle of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A cross-domain authentication method for instantaneous data of a power grid, characterized in that: include: When receiving a registration request from a user, obtaining an identity identifier of the user according to the registration request, then generating a digital identity identifier of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then registering the user according to the digital identity identifier, the public key, the private key, the temporary public key and the temporary private key; When receiving a cross-domain authentication request from a user, generate a first identification signature of the user for the digital identity in the non-control area of ​​the power system production, and determine whether the first identification signature is a legal signature. If so, issue a corresponding legal factor to the user, and generate a corresponding block certificate for the user in this domain; When receiving a cross-domain request from a user, the chain is queried to see if the user is a legitimate user. If so, the cross-domain request is sent to the authentication server in the foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the domain on the chain based on the user's digital identity, and performs a signature verification operation on the user based on the block certificate. If the signature verification is successful, the block certificate corresponding to the user in the foreign domain is generated.

2. The cross-domain authentication method for instantaneous data of a power grid according to claim 1, characterized in that: Also includes; Obtain corresponding elliptic curve equation parameters according to preset security parameters, and then determine the coordinates of the base point according to the elliptic curve equation; A random integer is generated as the private key of the system, and the public key corresponding to the system is generated according to the private key and the base point. Then the public key, the coordinates of the base point, and the parameters of the elliptic curve equation are written into the blockchain as public parameters.

3. The cross-domain authentication method for instantaneous data of a power grid as claimed in claim 2, characterized in that: The step of generating a digital identity of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then registering the user according to the digital identity, the public key, the private key, the temporary public key and the temporary private key includes: Generate a digital identity corresponding to the user according to the identity identifier, and determine whether the user has completed registration according to the digital identity, if the registration has been completed, exit the current operation, if the registration has not been completed, perform the user registration operation; The user registration operation includes: Generate a random number as a private key of the user in the production non-control area of ​​the power system, generate a public key corresponding to the user in the production non-control area according to the private key and the base point, and send the private key and public key of the user in the production non-control area to the user; Generate a temporary private key and a temporary public key of the user in the generated non-control area, and then generate a hash value corresponding to the digital identity according to the temporary public key, the identity identifier of the user and the digital identity corresponding to the user.

4. The cross-domain authentication method for instantaneous data of a power grid as claimed in claim 3, characterized in that: The generating of the first identification signature of the digital identity by the user in the non-control area of ​​the power system production, and judging whether the first identification signature is a legal signature, and if so, issuing a corresponding legal factor to the user, includes: When receiving a cross-domain authentication request from a user, generating a corresponding first identifier and a second identifier according to a preset SM2 cryptographic algorithm, and combining the first identifier and the second identifier to generate a first identifier signature of the user for the digital identity identifier in the production non-control area; Generate a corresponding verification message according to the timestamp when the first identification signature is generated, the user's identity identifier, the digital identity corresponding to the user, and the first identification signature, and send the verification message to the authentication service center, so that the authentication service center determines whether the user identity is within the preset validity period according to the verification message, and if not, terminates the current operation; if so, calculates the second identification signature of the authentication service center for the digital identity according to the digital identity corresponding to the user; The first identification signature is compared with the second identification signature. If the first identification signature is consistent with the second identification signature, the first identification signature is determined to be a legal signature and a legal factor is issued to the user. If the first identification signature is inconsistent with the second identification signature, the first identification signature is determined to be an illegal signature and a legal factor is not issued to the user.

5. The cross-domain authentication method for instantaneous data of a power grid as claimed in claim 4, characterized in that: The generating of the block certificate corresponding to the user in the domain includes: When the user's cross-domain authentication is successful, a block certificate corresponding to the user is generated, the block certificate is written into the transaction, and then the transaction is broadcast to the blockchain network.

6. The cross-domain authentication method for instantaneous data of a power grid as claimed in claim 5, characterized in that: The block certificate corresponding to the user in the local domain is queried on the chain according to the user's digital identity, and the user's signature is verified according to the block certificate. If the signature verification is successful, the block certificate corresponding to the user in the foreign domain is generated, including: According to the user's digital identity, the corresponding block certificate of the user in the domain is queried on the chain, and the identification signature of the user's digital identity by the authentication service center in the foreign domain and the hash value of the identification signature are calculated according to the identity; The user's signature is verified based on the block certificate, digital identity, the identification signature of the user's digital identity by the foreign authentication service center and the hash value of the identification signature. If the verification is successful, the corresponding block certificate of the user in the foreign domain is generated.

7. A cross-domain authentication device for instantaneous data of a power grid, characterized in that: include: User registration module, cross-domain authentication module and cross-domain request module; The user registration module is used to, when receiving a registration request from a user, parse the registration request to obtain an identity identifier of the user, then generate a digital identity identifier of the user, a public key, a private key, a temporary private key and a temporary public key of the user in a production non-control area of ​​the power system according to the identity identifier, and then register the user according to the digital identity identifier, the public key, the private key, the temporary public key and the temporary private key; The cross-domain authentication module is used to generate a first identification signature of the user for the digital identity in the non-control area of ​​the power system production when receiving a cross-domain authentication request from the user, and determine whether the first identification signature is a legal signature. If so, issue a corresponding legal factor to the user and generate a corresponding block certificate for the user in the domain; The cross-domain request module is used to query whether the user is a legitimate user on the chain when receiving the user's cross-domain request. If so, the cross-domain request is sent to the authentication server in the foreign domain, so that the authentication server in the foreign domain queries the block certificate corresponding to the user in the domain on the chain according to the user's digital identity, and performs a signature verification operation on the user according to the block certificate. If the signature verification is successful, the block certificate corresponding to the user in the foreign domain is generated.

8. The cross-domain authentication device for instantaneous data of a power grid according to claim 7, characterized in that: It also includes: a common parameter generation module; The public parameter generation module is used to obtain the corresponding elliptic curve equation parameters according to the preset security parameters, and then determine the coordinates of the base point according to the elliptic curve equation; randomly generate an integer as the private key of the system, generate the public key corresponding to the system according to the private key and the base point, and then write the public key, the coordinates of the base point, and the elliptic curve equation parameters as public parameters into the blockchain.

9. An electronic device, characterized in that: The invention comprises a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the cross-domain authentication method for instantaneous data of a power grid as claimed in any one of claims 1 to 6 is implemented.

10. A storage medium, characterized in that: The storage medium includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the cross-domain authentication method for instantaneous data of a power grid as described in any one of claims 1 to 6.