Smart power grid authentication and key agreement method based on NTRU grid
By adopting NTRU-based authentication and key negotiation methods in the smart grid, combined with physical non-clone function and fuzzy extractor technology, the security and efficiency of identity authentication and key negotiation in the smart grid are solved, and efficient and secure identity authentication and key negotiation are achieved.
Patent Information
- Application Number
- CN202510530434.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-06-20
AI Technical Summary
The existing identity authentication and key negotiation methods in smart grids have problems such as low communication efficiency, high energy consumption, poor security and difficulty in adapting to practical applications.
Using the NTRU grid-based smart grid authentication and key negotiation methods, through system initialization, smart meter registration, service provider registration and authentication and key negotiation stages, NTRU encryption algorithm, physical non-clone function and fuzzy extractor technology are used to achieve safe and efficient identity authentication and key negotiation.
It significantly improves the security and feasibility of grid identity authentication and key negotiation, reduces computing overhead, improves communication efficiency, reduces energy consumption, and has the characteristics of resisting quantum attacks and anti-machine learning attacks.
Smart Images

Figure CN120185809A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of smart grid security, and particularly to a smart grid authentication and key negotiation method based on NTRU lattice. Background Art
[0002] Traditional power systems can neither detect users' electricity consumption in real time nor adjust power distribution in a timely manner in the face of emergencies such as increased demand and damaged infrastructure, so power supply instability often occurs. Moreover, since most traditional power system structures are centralized, it is difficult to manage large-scale renewable energy and respond to emergencies. To solve these problems, existing smart grids have significantly improved the response speed, stability, and user experience of power systems by integrating advanced encryption communication, algorithms, and data analysis technologies. At the same time, they support the development of sustainable energy and promote the energy industry to develop in a more intelligent and sustainable direction. With the increasingly perfect deployment of smart grids, mobile terminals are also continuously put into use, applying more complex and diverse communication technologies and dynamic topological structures. At the same time, they are more dependent on a large number of physical devices, which involve sensitive information of many consumers. Once an adversary obtains this information, they can speculate on users' home life patterns and thus carry out malicious behaviors such as precise fraud, which poses a new challenge to the security protection of smart grids. To ensure the safe and reliable operation of smart grids, secure and reliable identity authentication is essential.
[0003] Currently, there are still the following disadvantages in power grid identity authentication and key negotiation:
[0004] 1) Existing authentication schemes are vulnerable to various security threats. Especially with the development of quantum computers, encryption algorithms based on large prime number factorization, discrete logarithm problems, and elliptic curve cryptography are difficult to resist quantum attacks, resulting in poor security of power grid identity authentication and key negotiation.
[0005] 2) The existing identity authentication registration process is usually carried out in a hypothetically secure channel environment. However, there is no absolutely secure channel in real life. Therefore, the current identity authentication registration method has poor scalability and is difficult to adapt to complex and changeable actual application environments.
[0006] 3) Smart meters are usually placed in unattended locations, making them vulnerable to physical attacks and malware attacks. After the smart meter completes the registration process, most existing methods cannot effectively process the secret information in it, easily causing information leakage and tampering, thus affecting the authentication and key negotiation process.
[0007] 4) Traditional communication protocols usually involve mutual authentication between the smart meter and the control center, between the control center and the service provider, and between the smart meter and the service provider. There is no direct way to extend it to three parties. Mostly, after establishing secure communication between the smart meter and the control center, the control center then establishes secure communication with the service provider, which increases the number of communication rounds and communication latency. Therefore, the communication efficiency is low and the energy consumption is high. Summary of the Invention
[0008] The object of the present invention is to solve the problems of low communication efficiency, high energy consumption, poor security, and difficulty in adapting to practical applications existing in the existing identity authentication and key negotiation methods in the smart grid environment, and to propose a smart grid authentication and key negotiation method based on the NTRU lattice.
[0009] A smart grid authentication and key negotiation method based on the NTRU lattice includes the following steps:
[0010] System initialization phase: The control center performs system initialization, determines system parameters, generates the public key of the control center, and selects and stores the corresponding identity information for each smart meter and service provider. It sends the system parameters, the public key of the control center, and the smart meter identity information obtained from system initialization to the smart meter; it sends the system parameters, the public key of the control center, and the service provider identity information obtained from system initialization to the service provider;
[0011] Smart meter registration phase: The smart meter uses the smart meter identity information ID SM , the public key PK of the control center CC , and the system parameters to perform smart meter registration on the public channel;
[0012] Service provider registration phase: The service provider uses the service provider identity information ID sp , the public key PK of the control center CC , and the system parameters to perform service provider registration on the public channel;
[0013] Authentication and key negotiation phase: Complete the authentication of the control center to the smart meter, the service provider to the control center, the control center to the service provider, and the smart meter to the control center in sequence, and negotiate a consistent session key among the smart meter, the control center, and the service provider.
[0014] Further, in the system initialization phase, the specific process is as follows:
[0015] A1. The control center determines system parameters and generates the public and private keys of the control center:
[0016] First, the control center initializes and generates system parameters;
[0017] The system parameters include: the hash function h(·), the prime number q that determines the modulus of the polynomial ring, the control parameter prime number p that adjusts the number of noises, and the prime number N that is the number of polynomial rings;
[0018] Then, define three polynomial rings according to q, p, and N:
[0019]
[0020] where X is the variable of the polynomial, Z represents the set of integers, and Z[X] is the polynomial ring over integers;
[0021] Then, select four sets of polynomials with integer coefficients in the polynomial ring (L f , L g , L r , L m ), and add them to the system parameter set;
[0022] Then, select r f in the set of polynomials with integer coefficients L CC , select g g in L CC , and then obtain the private key of the control center according to r CC Use r CC and g CC to obtain the public key PK CC of the control center:
[0023]
[0024] where g CC and r CC are relatively prime, is r CC modulo q, is r CC modulo p;
[0025] A2. The control center selects and stores the identity information for each smart meter and the server. At the same time, it sends the control center public key PK CC , the system parameters q, p, N, L f , L g , L r , L m , the hash function h(·), and the identity information ID SM of the smart meter to the smart meter; it sends the control center public key PK CC , the system parameters q, p, N, L f , L g , L r , L m , the hash function h(·), and the identity information ID of the serversp Send to the service provider.
[0026] Furthermore, in the smart meter registration phase, the specific process is as follows:
[0027] B1. The smart meter selects an initial challenge value c 1i , and uses c 1i to generate the private key of the smart meter Specifically:
[0028] B1.1. The smart meter selects an initial challenge value c 1i , and uses the physically unclonable function to generate the corresponding response f 1i . Specifically:
[0029] f 1i = PUF(c 1i )
[0030] where PUF() is the physically unclonable function;
[0031] B1.2. Use the fuzzy extractor to process the response f 1i to generate a random number r' 1i and auxiliary data p 1i :
[0032] (r' 1i , p 1i ) = Gen(f 1i )
[0033] where Gen() is the generation algorithm of the fuzzy extractor;
[0034] B1.3. Convert the random number r' 1i to a random polynomial r 1i , and construct the private key of the smart meter based on the random polynomial r 1i Specifically:
[0035] where r 1i ∈ L f , is r modulo p 1i ;
[0036] B2. Use the private key of the smart meter to generate the public key PK of the smart meter SM . Specifically:
[0037]
[0038] where g 1i ∈ L g , is r modulo q1i , g 1i is relatively prime to r 1i ;
[0039] B3. Generate random polynomials l i and l2. Use l1, the public key PK of the control center CC and the prime number q that determines the modulus of the polynomial ring to encrypt the identity ID SM of the smart meter and the random polynomial l2 respectively, and obtain the encryption results R1 and R2. Specifically:
[0040] R1 = l1 * PK CC + ID SM (mod q)
[0041] R2 = l1 * PK CC + l2 (mod q)
[0042] where l1 ∈ L r , l2 ∈ L m ;
[0043] B4. Generate a timestamp T. Use ID SM , R2, PK SM and T to obtain the variable M1. The smart meter transmits M1, R1, R2, PK SM and T to the control center through the public channel;
[0044] The variable M1 is specifically:
[0045] M1 = h(ID SM ||R2||PK SM ||T)
[0046] B5. After receiving the data of M1, R1, R2, PK SM and T, the control center generates a timestamp T1. The control center uses the timestamp T1 to check whether the timestamp T is within a reasonable range. If it is within a reasonable range, it decrypts the identity information ID′ SM of the smart meter and the random polynomial l′2 using the private key of the control center, and then executes B6; otherwise, it directly ends the service;
[0047] The control center uses the timestamp T1 to check whether the timestamp T is within a reasonable range. Specifically: If T1 - T < ΔT, it means that the timestamp T is within a reasonable range; otherwise, it means that the timestamp T is not within a reasonable range;
[0048] where ΔT is a preset timestamp interval threshold;
[0049] The decrypting the identity information ID′ SM of the smart meter and the random polynomial l′2 using the private key of the control center is specifically:
[0050]
[0051] a1 = r CC R1 (mod q)
[0052] a2 = r CC R2 (mod q)
[0053] Wherein, a1 and a2 are intermediate variables;
[0054] B6. Compare whether the identity information ID selected for the smart meter during the system initialization stage SM is the same as ID′ SM If they are the same, then use ID SM , R2, PK SM and T to generate the variable M1′. If they are not the same, directly end the service; then compare M1 with M1′. If M1 is the same as M1′, execute B7; if they are not the same, directly terminate the service;
[0055] Use ID SM , R2, PK SM and T to generate the variable M1′. Specifically:
[0056] M1′ = h(ID SM ||R2||PK SM ||T)
[0057] B7. Generate a random polynomial l4. The control center uses the public key PK of the smart meter SM to encrypt the random polynomial l4 to obtain R3, and then use ID SM , l′2, R3 and T1 to generate M2, use ID SM , l′2 and l4 to generate A1, and transmit the timestamp T1, R3 and M2 to the smart meter on the public channel;
[0058] R3, M2, A1 are obtained through the following formulas:
[0059] R3 = l3 * PK SM + l4 (mod q)
[0060] M2 = h(ID SM ||l′2||R3||T1)
[0061] A1 = h(ID SM ||l′2||l4)
[0062] Wherein, l4 ∈ L m , l3 is a random polynomial, l3 ∈ L r ;
[0063] After receiving T1, R3, and m2, the smart meter generates a timestamp T2 and uses the timestamp T2 to check whether the timestamp T1 is within a reasonable range. If it is not within the reasonable range, the service is directly terminated; if it is within the reasonable range, then use ID SM , l2, R3, and T1 to generate m′2;
[0064] The process of using the timestamp T2 to check whether the timestamp T1 is within a reasonable range is specifically as follows: If T2 - T1 < ΔT, it means that the timestamp T1 is within the reasonable range; otherwise, it means that the timestamp T1 is not within the reasonable range;
[0065] The process of using ID SM , l2, R3, and T1 to generate M′2 is specifically as follows:
[0066] M′2 = h(ID SM ||l2||R3||T1)
[0067] B9. Compare M′2 with the received M2. If M′2 is consistent with M2, store the received R3, and then clear the private key of the smart meter Response value f 1i , M1, and M2′; if M′2 is inconsistent with M2, directly terminate the service.
[0068] Furthermore, the specific process of the service provider registration phase is as follows:
[0069] C1. The service provider selects an initial challenge value c 2i , and uses the initial challenge value c 2i to generate a random number r′ 2i and auxiliary data p 2i , specifically as follows:
[0070] C1.1. The service provider selects an initial challenge value c 2i , and uses c 2i to generate a response value f 2i , specifically as follows:
[0071] f 2i = PUF(c 2i )
[0072] C1.2. Use the fuzzy extractor to process the response f 2i to generate a random number r′ 2i and auxiliary data p 2i :
[0073] (r′ 2i , p 2i ) = Gen(f 2i )
[0074] C2. Store the random number r′2i Convert to a random polynomial r 2i , based on r 2i Construct the service provider's private key Then use the constructed service provider's private key to generate the service provider's public key PK SP :
[0075]
[0076] Among them, r 2i ∈L f , g 2i ∈L g , g 2i is relatively prime to r 2i , is r modulo q 2i , is r modulo p 2i ;
[0077] C3. Generate a random polynomial l6, and use the control center's public key PK CC to encrypt the service provider's ID SP and the random polynomial l6 respectively, to obtain the encrypted service provider identity information R4 and the encrypted random polynomial R5:
[0078] R4 = l5 * PK CC + ID SP (mod q)
[0079] R5 = l5 * PK CC + l6 (mod q)
[0080] Among them, l6 ∈ L m , l5 ∈ L r , l5 is a random polynomial;
[0081] C4. Generate a timestamp T3, and use ID SP , R5, PK SP and T3 the service provider obtains the variable M3, and transmits M3, R4, R5, PK SP and T3 to the control center through the public channel;
[0082] The said using ID SP , R5, PK SP and T3 the service provider obtains the variable M3, specifically:
[0083] M3 = h(ID SP ||R5||PK SP ||T3)
[0084] C5. The control center receives M3, R4, R5, PKSP After generating the timestamp T4 with the T3 data, the control center uses the timestamp T4 to check whether the timestamp T3 is within a reasonable range. If it is within the reasonable range, the control center decrypts the service provider's identity information ID' using the control center's private key SP and the random polynomial l'6, and then executes C6; otherwise, directly end the service;
[0085] The control center uses the timestamp T4 to check whether the timestamp T3 is within a reasonable range, specifically:
[0086] If T4 - T3 < ΔT, it means that the timestamp T3 is within the reasonable range; otherwise, it means that the timestamp T3 is not within the reasonable range;
[0087] The decryption of the service provider's identity information ID' using the control center's private key SP and the random polynomial l'6, specifically:
[0088]
[0089] a3 = r CC R4(mod q)
[0090] a4 = r CC R5(mod q)
[0091] C6. According to the decrypted service provider's ID' SP Compare with the identity information ID selected by the control center for the service provider SP If they are the same, use ID SP 、R5、PK SP and T3 to calculate the variable M3'; otherwise, directly end the service; Compare M3' with M3. If they are the same, execute C7; otherwise, directly end the service;
[0092] The calculation of the variable M3' using ID SP 、R5、PK SP and T3, specifically:
[0093] M3' = h(ID SP ||R5||PK SP ||T3)
[0094] C7. The control center uses the service provider's public key PK SP to encrypt l4 to obtain R6, and then uses ID SP 、l'6、R6 and T4 to generate M4, uses ID SP 、l'6 and l4 to generate A2, and transmits the timestamp T4, R6 and M4 to the service provider on the public channel;
[0095] R6, M4, and A2 are obtained in the following manner:
[0096] R6 = l3 * PK SP + l4 (mod q)
[0097] M4 = h(ID SP || l′6 || R6 || T4)
[0098] A2 = h(ID SP || l′6 || l4)
[0099] After the service provider receives the T4, R6, and M4 data, it generates a timestamp T5, and uses the timestamp T5 to check whether the timestamp T4 is within a reasonable range. If it is within the reasonable range, it uses ID SP , T4, R6, and l6 to generate M4′, and then executes C9; otherwise, it directly ends the service.
[0100] The process of using the timestamp T5 to check whether the timestamp T4 is within a reasonable range is specifically as follows:
[0101] If T5 - T4 < ΔT, it means that the timestamp T4 is within the reasonable range; otherwise, it means that the timestamp T4 is not within the reasonable range.
[0102] The process of using ID SP , T4, R6, and l6 to generate M4′ is specifically as follows:
[0103] M4′ = h(ID SP || l6 || R6 || T4)
[0104] In C9, compare whether M4′ is the same as M4. If they are the same, store R6, and then clear the private key response value f 2i , M3, and M4; otherwise, directly end the service.
[0105] Furthermore, the specific process of the authentication and key negotiation phase is as follows:
[0106] D. The smart meter restores the private key of the smart meter, decrypts the random polynomial l′4 using the private key of the smart meter, and then obtains the authentication key K1 with the control center using l′4. The smart meter transmits K1 and the current timestamp T6 to the control center over the public channel.
[0107] E. The control center generates a timestamp T7. The control center uses T7 to determine whether the timestamp T6 is within a reasonable range. If it is not within the reasonable range, it directly ends the service; if it is within the reasonable range, it generates the authentication key K1′ with the smart meter, then completes the authentication of the smart meter by the control center through K1′ and K1, and then generates the smart meter pseudonym PID SMand the authentication key K2 with the service provider, and finally send K2, PID SM and T7 to the service provider;
[0108] F. The service provider uses K2, PID SM and the timestamp T7 to complete the authentication of the service provider to the control center, then encrypts the random polynomial l7 to obtain R7, generates the authentication key K3 with the control center, and sends K3, R7 and the current timestamp T8 to the control center through the public channel;
[0109] G. The control center decrypts R7 using the control center private key to obtain the random polynomial l’7, uses l’7 and T8 to obtain the authentication key K3′ with the service provider, and uses K3′ and K3 to complete the authentication of the control center to the service provider; then encrypts l’7 to obtain R8, and further generates the authentication key K4 with the smart meter and the service provider pseudonym PID SP and sends K4, R8, PID SP and the current timestamp T9 to the smart meter;
[0110] H. The smart meter uses K4, T9, PID SP and R8 to complete the authentication of the smart meter to the control center, and generates the common session key SK′ of the smart meter, the control center and the service provider.
[0111] Furthermore, the smart meter in D restores the smart meter private key, decrypts the random polynomial l′4 using the smart meter private key, and then uses l′4 to obtain the authentication key K1 with the control center. The smart meter transmits K1 and the current timestamp T6 to the control center through the public channel, specifically:
[0112] D1. The smart meter uses the initial challenge value c 1i to restore the smart meter private key and then uses the private key of the smart meter to decrypt R3 to obtain the random polynomial l′4:
[0113] D1.1. The smart meter uses the initial challenge value c 1i to restore the smart meter private key
[0114] First, use the initial challenge value c 1i to generate the response f 1i :
[0115] f 1i = PUF(c 1i )
[0116] Then, use the fuzzy extractor to process the response f 1i to generate the random number r′1i and auxiliary data p 1i :
[0117] (r′ 1i ) = Rep(f 1i , p 1i )
[0118] Finally, convert the random number r′ 1i to a random polynomial r 1i , so as to use the random polynomial r 1i to construct the private key of the smart meter
[0119] where r 1i ∈ L f , is r modulo p 1i ;
[0120] D1.2. Use the private key of the smart meter to decrypt R3 and obtain the random polynomial l′4:
[0121]
[0122] a5 = r 1i R3 (mod q)
[0123] where a5 is an intermediate variable;
[0124] D2. Use the random polynomials ID SM , l2 and l′4 to obtain the variable A′1:
[0125] A′1 = h(ID SM ||l2||l′4)
[0126] D3. Generate a new timestamp T6, and generate the authentication key K1 with the control center based on A′1, ID SM , l2, l′4 and T6. Then the smart meter transmits K1 and T6 to the control center on the public channel;
[0127] The authentication key K1 with the control center is specifically:
[0128] K1 = h(A1′||ID SM ||l2||l′4||T6||l x )
[0129] where l x is the smart meter location identifier.
[0130] Further, for the generation timestamp T7 in E, the control center uses T7 to determine whether the timestamp T6 is within a reasonable range. If it is not within the reasonable range, the service is directly terminated; if it is within the reasonable range, an authentication key K1' for the smart meter is generated, and then the control center authenticates the smart meter by comparing K1' and K1, and then generates the smart meter pseudonym PID SM and the authentication key K2 for the service provider. Finally, K2, PID SM and T7 are sent to the service provider. Specifically:
[0131] E1. After receiving K1 and T6 transmitted from the smart meter, the control center generates the timestamp T7, and uses the timestamp T7 to determine whether the timestamp T6 is within a reasonable range. If it is within the reasonable range, an authentication key K1' for the smart meter is generated, and then E2 is executed; otherwise, the service is directly terminated;
[0132] The determination of whether the timestamp T6 is within a reasonable range using the timestamp T7 is specifically: if T7 - T6 < ΔT, it means that the timestamp T6 is within the reasonable range; otherwise, it means that T6 is not within the reasonable range;
[0133] The authentication key K1' for the smart meter is specifically:
[0134] K′1 = h(A1||ID SM ||l′2||l4||T6||l′ x )
[0135] where l′ x is the location identifier of the smart meter stored in the control center;
[0136] E2. Compare the authentication key K1' for the smart meter generated in E1 with the authentication key K1 received from the smart meter. If K1' and K1 are the same, the authentication of the smart meter by the control center is completed, and then E3 is executed; if they are not the same, the authentication is terminated;
[0137] E3. Generate the authentication key K2 between the control center and the service provider and the smart meter pseudonym PID SM , and then send K2, PID SM and the timestamp T7 to the service provider;
[0138] The authentication key K2 between the control center and the service provider is as follows:
[0139] K2 = h(A2||ID SP ||l′6||l4||T7||PID SM )
[0140] The smart meter pseudonym PID SM is as follows:
[0141] PID SM = ID SM ⊕ A2.
[0142] Furthermore, the service provider in F uses K2, PID SM and timestamp T7 to complete the authentication of the service provider to the control center, then encrypts the random polynomial l7 to obtain R7, generates an authentication key K3 with the control center, and sends K3, R7, and the current timestamp T8 to the control center through a public channel, specifically:
[0143] F1. The service provider receives PID SM , K2, and T7, generates timestamp T8, and uses timestamp T8 to check whether timestamp T7 is within a reasonable range. If it is within the reasonable range, then execute F2; otherwise, directly end the service;
[0144] F2. The service provider uses the challenge value c 2i to recover the service provider's private key Then, uses the service provider's private key to decrypt R6 to obtain l″4, specifically:
[0145] F2.1. The service provider uses the challenge value c 2i to recover the service provider's private key Specifically:
[0146] First, uses the challenge value c 2i to generate a response value f 2i , specifically:
[0147] f 2i = PUF(c 2i )
[0148] Then, uses the fuzzy extractor to process the response f 2i to generate a random number r′ 2i and auxiliary data p 2i :
[0149] (r′ 2i ) = Rep(f 2i , p 2i )
[0150] Finally, converts the random number r′ 2i to a random polynomial r 2i , uses r 2i to construct the service provider's private key
[0151] where r 2i ∈ L f , is r modulo p 2i ;
[0152] F2.2. Use the service provider's private key to decrypt R6 to obtain l″4:
[0153]
[0154] a6 = r 2i R6 (mod q)
[0155] where a6 is an intermediate variable;
[0156] F3. Use the service provider's identity information ID SP , l6 and l″4 to generate A2′, then use A2′ to obtain the authentication key K2′ with the control center, compare K2′ with the received K2 by the service provider. If K2′ is consistent with K2, the service provider's authentication of the control center is completed, and F4 is executed; otherwise, the authentication process ends;
[0157] The use of the service provider's identity information ID SP and l6 to generate A2′ is specifically:
[0158] A2′ = h(ID SP ||l6||l″4)
[0159] Using A2′ to obtain the authentication key K2′ with the control center is specifically:
[0160] K2′ = h(A2′||ID 7P ||l6||l″4||T7||PID SM )
[0161] F4. Generate a new random polynomial l7, encrypt l7 to obtain the encryption result R7:
[0162] R7 = l5*PK CC +l7 (mod q)
[0163] where l7 ∈ L m ;
[0164] F5. Use A2′ to obtain the service provider's authentication key K3 with the control center, and send K3, timestamp T8 and R7 to the control center on the public channel; the service provider's authentication key K3 with the control center is as follows:
[0165] K3 = h(A2′||SK||l6||T8||l y )
[0166] SK = h(ID SM||ID SP ||l″4||l7)
[0167] ID SM = PID SM ⊕A2′
[0168] Wherein, SK is the common session key of the smart meter, the control center, and the service provider, and l y is the location identifier of the service provider.
[0169] Furthermore, the control center in G decrypts R7 using the control center private key to obtain the random polynomial l’7, obtains the authentication key K3′ with the service provider using l’7 and T8, and completes the authentication of the control center to the service provider using K3′ and K3; then encrypts l’7 to obtain R8, and generates the authentication key K4 with the smart meter and the service provider pseudonym PID SP , and sends K4, R8, PID SP and the current timestamp T9 to the smart meter, specifically:
[0170] G1. After receiving K3, T3, and R7, the control center generates the timestamp T9, and uses the timestamp T9 to check whether the timestamp T8 is within a reasonable range. If it is within the reasonable range, then execute G2; otherwise, directly end the authentication;
[0171] The step of using the timestamp T9 to check whether the timestamp T8 is within a reasonable range is specifically: if T9 - T8 ≤ ΔT, it means that the timestamp T8 is within the reasonable range; otherwise, it means that the timestamp T8 is not within the reasonable range;
[0172] G2. The control center decrypts R7 using the control center private key to obtain the random polynomial l’7, obtains the common session key SK′ of the smart meter, the control center, and the service provider using l’7, and then obtains the authentication key K3′ with the service provider using SK′:
[0173] K3′ = h(A2||SK′||l’6||T8||l y ′)
[0174] SK′ = h(ID SM ||ID SP ||l4||l′7)
[0175]
[0176] a7 = r CC R7(mod q)
[0177] Wherein, l y ′ is the location identifier of the service provider stored in the control center;
[0178] G3. Compare whether the authentication key K3' of the service provider obtained at G2 is the same as the authentication key K3 obtained by the control center at G1. If they are the same, the authentication of the service provider by the control center is completed, and G4 is executed; otherwise, the authentication process ends.
[0179] G4. Encrypt l'7 to obtain the encryption result R8, and then use SK' to generate the authentication key K4 with the smart meter:
[0180] R8 = l3 * PK sm + l'7 (mod q)
[0181] K4 = h(A1 || SK' || l'2 || T9)
[0182] G5. Use the identity information ID of the service provider SP and A1 to generate the service provider pseudonym PID SP , and then send K4, timestamp T9, and PID SP and R8 to the smart meter;
[0183] The use of the identity information ID of the service provider SP and A1 to generate the service provider pseudonym PID SP , specifically:
[0184] PID SP = ID SP ⊕ A1.
[0185] Furthermore, in the H, the smart meter uses K4, T9, PID SP and R8 to complete the authentication of the smart meter to the control center, and generate the common session key SK' of the smart meter, the control center, and the service provider, specifically:
[0186] H1. After the smart meter receives K4, T9, PID SP and R8, it generates a timestamp T 10 , and uses the timestamp T 10 to check whether the timestamp T9 is within a reasonable range. If it is within the reasonable range, H2 is executed; otherwise, the service is directly ended;
[0187] The use of the timestamp T 10 to check whether the timestamp T9 is within a reasonable range, specifically:
[0188] If T 10 - T9 ≤ ΔT, it means that the timestamp T9 is within the reasonable range; otherwise, it means that the timestamp T9 is not within the reasonable range;
[0189] H2. Use the smart meter private key Decrypt the random polynomial l″7 in R8, and then solve for the identity information ID of the service provider SP :
[0190]
[0191] a8 = r 1i R8 (mod q)
[0192] ID SP = PID SP ⊕ A1
[0193] H3. Use ID SM 、ID SP 、l′4 and l″7 to obtain the common session key SK″ of the smart meter, control center, and service provider, and then use A′1, SK″, l2, and T9 to obtain the authentication key K4′ of the smart meter for the control center:
[0194] K4′ = h(A1′ || SK″ || l2 || T9)
[0195] SK″ = h(ID SM || ID SP || l′4 || l″7)
[0196] H4. Compare whether K4′ is the same as K4. If they are the same, the authentication of the smart meter for the control center is completed; otherwise, the authentication process is directly terminated.
[0197] The beneficial effects of the present invention are as follows:
[0198] 1). As a lattice-based public key cryptosystem, NTRU builds its security on the NP-hard shortest vector problem (SVP), ensuring a strong resistance to quantum attacks at the theoretical level. Therefore, the present invention adopts the NTRU encryption algorithm, which significantly reduces the computational overhead while resisting quantum attacks, thereby enhancing the security and feasibility of power grid identity authentication and key negotiation.
[0199] 2). The registration process of the present invention is carried out in an open channel. In the registration stage, the physical unclonable function and fuzzy extractor technology are combined. Before the registration is about to be completed, the smart meter and the service provider will clear the private key information and responses, thereby ensuring that the device can effectively resist physical attacks in the outdoor environment. At the same time, by hiding the relationship between the incentive and the private key, the defense ability of the system against machine learning attacks is further enhanced, avoiding the leakage and tampering of the stored secret information.
[0200] 3) By combining NTRU encryption technology, physical unclonable functions, and fuzzy extractor technology, the present invention extends traditional two-party authentication to three parties, reduces the number of communication rounds and interactions, realizes the authentication and establishment of session keys among smart meters, control centers, and service provider entities, reduces communication latency, thereby improving communication efficiency and reducing energy consumption.
[0201] 4) The present invention can also resist other common threats such as DOS attacks, replay attacks, privileged insider attacks, impersonation attacks, and long-term key leakage attacks, and has anonymity and forward security. BRIEF DESCRIPTION OF THE DRAWINGS
[0202] Figure 1 It is a system model diagram composed of a smart meter, a control center, and a service provider. DETAILED DESCRIPTION OF THE INVENTION
[0203] As Figure 1 shown, the system model in the present invention includes three entities: a smart meter (SM), a control center (CC), and a service provider (SP).
[0204] (1) Smart meter (SM): Regularly collects user power consumption data, real-time monitors parameters such as the voltage and frequency of the power, grasps the state of the power grid, transmits the data to the control center through a communication network, and can also make adjustments according to the control orders of the control center to meet the power supply requirements.
[0205] (2) Control center (CC): It is the core management node of the smart grid system, responsible for monitoring and controlling the operation state and power distribution of the entire power grid, and can realize optimized power distribution, fault management and recovery, and real-time monitoring and adjustment to issue control orders.
[0206] (3) Service provider (SP): The service provider needs to adjust operations such as energy production, transmission, and distribution according to the instructions and scheduling arrangements of the control center.
[0207] Next, the present invention will be described in conjunction with the specific embodiments.
[0208] Specific Embodiment 1: The present invention is a smart grid authentication and key negotiation method based on NTRU lattices. The specific process is as follows:
[0209] System initialization stage: The control center performs system initialization, determines system parameters, generates the public key of the control center, selects and stores the corresponding identity information for each smart meter and service provider, and sends the system parameters, the public key of the control center, and the smart meter identity information obtained from the system initialization to the smart meter; sends the system parameters, the public key of the control center, and the service provider identity information obtained from the system initialization to the service provider. Specifically:
[0210] A1. The control center determines relevant system parameters and the public and private keys of the control center:
[0211] First, the control center obtains the system parameters:
[0212] The system parameters include: a secure hash function h(·) and the system parameters required for the NTRU algorithm.
[0213] Specifically, the secure hash function is SHA-256; the system parameters required for the NTRU algorithm include the prime number q = 2048 that determines the polynomial ring modulus, the prime number p = 3 that adjusts the noise number, and the prime number N = 1499 that is the number of polynomial rings;
[0214] Then, according to the selected prime number q, prime number p, and prime number N, three polynomial rings are defined:
[0215]
[0216] Among them, X is the variable of the polynomial, Z represents the set of integers, and Z[X] is the polynomial ring over integers; in this step, taking modulo X N -1 can ensure that the degrees of all polynomials do not exceed N - 1 and make the polynomials have cyclic properties;
[0217] Then, four sets of polynomials with integer coefficients are selected in the polynomial ring (L f , L g , L r , L m );
[0218] Among them, L f , L g are used for the generation of public and private keys;
[0219] Then, according to the sets of polynomials with integer coefficients, r CC ∈ L f and g CC ∈ L g are selected, and then the private key of the control center is obtained according to r CC The public key PK of the control center is obtained by using r CC and g CC : CC :
[0220]
[0221] Among them, g CC and r CC are relatively prime, is r CC modulo q, is r modulo pCC ;
[0222] A2. The control center selects and stores the identity information for each smart meter and the server, and at the same time, it sends the public key PK of the control center CC , system parameters q, p, N, L f , L g , L r , L m , hash function h(·), and the identity information ID of the smart meter SM to the smart meter; it sends the public key PK of the control center CC , system parameters, p, N, L f , L g , L r , L m , hash function h(·), and the identity information ID of the server sp to the service provider;
[0223] Smart meter registration phase: The smart meter uses the identity information ID of the smart meter obtained by A2 SM , the public key PK of the control center CC , and the system parameters to perform smart meter registration on the public channel. Specifically:
[0224] B1. In the registration process, each smart meter with an internally integrated physical unclonable function selects an initial challenge value c 1i when registering, and uses c 1i to generate the private key of the smart meter Specifically:
[0225] B1.1. The smart meter selects an initial challenge value c 1i , and uses the physical unclonable function to generate the corresponding response f 1i . Specifically:
[0226] f 1i = PUF(c 1i )
[0227] where PUF is the physical unclonable function, and the physical unclonable function is a unique physical device that can generate a unique response corresponding to the challenge value using a unique built-in chip;
[0228] B1.2. Use the fuzzy extractor to process the response f 1i to generate a random number r′ 1i and auxiliary data p 1i :
[0229] (r′ 1i , p 1i ) = Gen(f 1i )
[0230] Among them, Gen() is the generation algorithm of the fuzzy extractor;
[0231] (r, p) ← Gen(ω) is the generation algorithm of the fuzzy extractor. The input binary sequence ω can generate a stable key r and auxiliary information p for subsequent recovery through Grn. The fuzzy extractor is a technology that uses cryptography to make the output of the PUF response that is unstable or mixed with noise tend to be stable, ensuring that the responses generated by the same challenge value through the same PUF are consistent at different times and in different scenarios, and can also prevent an adversary from directly deducing the key from the response value. The fuzzy extractor also has a corresponding recovery algorithm: Input the binary sequence or a sequence that is close enough to the binary sequence and the auxiliary information p can recover the key r;
[0232] B1.3. Convert the random number r' 1i to a random polynomial r 1i , and construct the private key of the smart meter based on the random polynomial r 1i
[0233] Among them, r 1i ∈ L f , is r modulo p 1i ;
[0234] B2. Then, with the help of the constructed private key of the smart meter generate the public key of the smart meter
[0235] Among them, g 1i ∈ L g , is r modulo q 1i , g 1i is relatively prime to r 1i r ;
[0236] B3. Generate random polynomials l1 ∈ L m and l2 ∈ L , and use l1, the public key PK of the control center CC and the prime number q that determines the modulus of the polynomial ring to encrypt the smart meter identity ID SM and the random polynomial l2 to obtain the encryption results R1 and R2, specifically:
[0237] R1 = l1 * PK CC + ID SM (mod q)
[0238] R2 = l1 * PK CC + l2 (mod q)
[0239] Among them, R1 is the encrypted identity of the smart meter, and R2 is the encrypted polynomial l2;
[0240] B4. Generate a timestamp T, and use ID SM , R2, PK SM and T to obtain the variable M1. The smart meter transmits M1, R1, R2, PK SM and T to the control center through the public channel;
[0241] M1 = h(ID SM ||R2||PK SM ||T)
[0242] B5. To resist replay attacks, after the control center receives the data of M1, R1, R2, PK SM and T, the control center generates a timestamp T1. The control center uses the timestamp T1 to check whether the timestamp T is within a reasonable range. If it is within a reasonable range, the control center decrypts the identity information ID' SM of the smart meter and the random polynomial l'2 with the private key of the control center, and then executes B6; otherwise, directly end the service;
[0243] The control center uses the timestamp T1 to check whether the timestamp T is within a reasonable range, specifically:
[0244] If T1 - T < ΔT, it means that the timestamp T is within a reasonable range; otherwise, it means that the timestamp T is not within a reasonable range;
[0245] Among them, ΔT is a preset timestamp interval threshold;
[0246] Decrypt the ID' SM of the smart meter and the random polynomial l'2 with the private key of the control center, specifically:
[0247] a1 = r CC R1 (mod q)
[0248]
[0249] a2 = r CC R2 (mod q)
[0250]
[0251] Among them, a1 and a2 are intermediate variables;
[0252] B6. Compare whether ID' SM is the same as the ID SM selected by the control center for the smart meter during the system initialization phase. If they are the same, then use ID SM , R2, PKSM Generate variable M1' using ID, R2, PK, and T. If they are not the same, directly end the service; then compare M1 with M1'. If M1 is the same as M1', execute step B7; if not, directly terminate the service.
[0253] Utilize ID SM , R2, PK SM and T to generate variable M1', specifically:
[0254] M1' = h(ID SM ||R2||PK SM ||T)
[0255] B7. The control center uses the public key PK of the smart meter SM to encrypt the newly generated random polynomial l4 ∈ L m to obtain R3, and then uses ID SM , l′2, R3, and T1 to generate M2, uses ID SM , l′2, and l4 to generate A1, and transmits the timestamp T1, R3, and M2 to the smart meter on the public channel:
[0256] R3 = l3 * PK SM + l4 (mod q)
[0257] M2 = h(ID SM ||l′2||R3||T1)
[0258] A1 = h(ID SM ||l′2||l4)
[0259] where l3 is a random polynomial, l3 ∈ L r ;
[0260] B8. After receiving T1, R3, and M2, the smart meter generates timestamp T2, and uses timestamp T2 to check whether timestamp T1 is within a reasonable range. If it is not within a reasonable range, directly end the service; if it is within a reasonable range, use ID SM , l2, R3, and T1 to generate M′2:
[0261] M′2 = h(ID SM ||l2||R3||T1)
[0262] The smart meter uses timestamp T2 to check whether timestamp T1 is within a reasonable range, specifically:
[0263] If T2 - T1 < ΔT, it means that timestamp T1 is within a reasonable range; otherwise, it means that timestamp T1 is not within a reasonable range.
[0264] B9. Compare M'2 with the received M2. If M'2 is identical to M2, store the received R3 and then clear the private key of the smart meter. Response value f 1i , M1 and M2'; if M'2 is not identical to M2, directly end the service;
[0265] The schematic table of the smart meter registration phase is shown in Table 1;
[0266] Table 1
[0267]
[0268] Service provider registration phase: The service provider uses the service provider identity information ID sp , the public key PK of the control center CC , and the system parameters to perform service provider registration on the public channel. Specifically:
[0269] C1. Each service provider integrated with a physical unclonable function selects an initial challenge value c 2i during registration, and uses the initial challenge value c 2i to generate a random number r' 2i and auxiliary data p 2i . Specifically:
[0270] C1.1. Before each service provider joins the system, select an initial challenge value c 2i , and use the physical unclonable function to generate a response value f 2i . Specifically:
[0271] f 2i = PUF(c 2i )
[0272] C1.2. Process the response f using the fuzzy extractor 2i to generate a random number r' 2i and auxiliary data p 2i :
[0273] (r' 2i , p 2i ) = Gen(f 2i )
[0274] where Gen is the fuzzy extractor;
[0275] C2. Convert the random number r' 2i to a random polynomial r 2i , and construct the service provider's private key based on r 2i and then generate the public key of the service provider with the constructed private key:
[0276]
[0277] Among them, r 2i ∈L f , g 2i ∈L g , g 2i is relatively prime to r 2i , is r under modulo q 2i , is r under modulo p 2i ;
[0278] C3. Use the public key PK of the control center CC to encrypt the ID of the service provider SP and the newly generated random polynomial l6 ∈ L m to obtain the encrypted service provider identity information R4 and the encrypted random polynomial R5:
[0279] R4 = l5 * PK CC + ID SP (mod q)
[0280] R5 = l5 * PK CC + l6 (mod q)
[0281] Among them, l5 ∈ L r , and l5 is a random polynomial;
[0282] C4. Generate a timestamp T3, and use ID SP , R5, PK SP and T3 for the service provider to obtain the variable M3, and transmit M3, R4, R5, PK SP and T3 to the control center through a public channel;
[0283] M3 = h(ID SP ||R5||PK SP ||T3)
[0284] C5. To resist replay attacks, after the control center receives the data of M3, R4, R5, PK SP and T3, the control center generates a timestamp T4. The control center uses the timestamp T4 to check whether the timestamp T3 is within a reasonable range. If it is within the reasonable range, it decrypts the service provider identity information ID′ SP and the random polynomial l′6 using the private key of the control center, and then executes C6; otherwise, directly end the service;
[0285] The control center uses the timestamp T4 to check whether the timestamp T3 is within a reasonable range, specifically:
[0286] If T4 - T3 < ΔT, it means that the timestamp T3 is within a reasonable range; otherwise, it means that the timestamp T3 is not within a reasonable range.
[0287] The service provider identity information ID′ is decrypted using the control center private key SP and the random polynomial l′6, specifically:
[0288] a3 = r CC R4 (mod q)
[0289]
[0290] a4 = r CC R5 (mod q)
[0291]
[0292] C6. According to the decrypted ID′ of the service provider SP compare with the identity information ID selected by the control center for the service provider SP If they are the same, use ID SP , R5, PK SP and T3 to calculate the variable M3′; otherwise, directly end the service; compare whether M3′ is the same as M3. If they are the same, execute C7; otherwise, directly end the service.
[0293] The calculation of the variable M3′ using ID SP , R5, PK SP and T3 is specifically:
[0294] M3′ = h(ID SP ||R5||PK SP ||T3)
[0295] C7. The control center encrypts l4 using the public key PK of the service provider SP to obtain R6, and then uses ID SP , l′6, R6 and T4 to generate M4, uses ID SP , l′6 and l4 to generate A2, and transmits the timestamp T4, R6, M4 on the public channel to the service provider.
[0296] R6, M4, A2 are obtained through the following methods:
[0297] R6 = l3 * PK SP + l4 (mod q)
[0298] M4 = h(ID SP ||l′6||R6||T4)
[0299] A2 = h(ID SP||l′6||l4)
[0300] C8. After receiving the T4, R6, and M4 data, the service provider generates a timestamp T5, and uses the timestamp T5 to check whether the timestamp T4 is within a reasonable range. If it is within the reasonable range, then use ID SP , T4, R6, and l6 to generate M4′, and then execute C9; otherwise, directly end the service;
[0301] M4′ = h(ID SP ||l6||R6||T4)
[0302] The smart meter uses the timestamp T5 to check whether the timestamp T4 is within a reasonable range, specifically:
[0303] If T5 - T4 < ΔT, it means that the timestamp T4 is within the reasonable range; otherwise, it means that the timestamp T4 is not within the reasonable range;
[0304] C9. Compare whether M4′ is the same as M4. If they are the same, then store R6, and then clear the private key of the service provider and, the response value f 2i , M3, and M4; otherwise, directly end the service.
[0305] The service provider registration phase is shown in Table 2;
[0306] Table 2
[0307]
[0308]
[0309] Authentication and key negotiation phase: As shown in Table 3, the authentication of the smart meter by the control center, the service provider by the control center, the control center by the service provider, and the smart meter by the control center are completed in sequence, and a consistent session key among the smart meter, the control center, and the service provider is negotiated. Specifically:
[0310] D. The smart meter recovers the smart meter private key, and uses the smart meter private key to decrypt the random polynomial l′4, and then uses l′4 to obtain the authentication key K1 with the control center. The smart meter transmits K1 and T6 to the control center on the public channel, specifically:
[0311] D1. The smart meter uses the initial challenge value c 1i to recover the smart meter private key Then use the private key of the smart meter to decrypt R3 to obtain the random polynomial l′4:
[0312] D1.1. The smart meter uses the initial challenge value c 1iRestore the private key of the smart meter
[0313] First, use the initial challenge value c 1i to generate the response f 1i :
[0314] f 1i = PUF(c 1i )
[0315] where PUF is a physically unclonable function;
[0316] Then, use the fuzzy extractor to process the response f 1i to generate the random number r' 1i and the auxiliary data p 1i :
[0317] (r' 1i ) = Rep(f 1i , p 1i )
[0318] where Rep() is the recovery algorithm of the fuzzy extractor;
[0319] is the recovery algorithm of the fuzzy extractor. Inputting a binary sequence or a sequence close enough to a binary sequence and the auxiliary information p can recover the key r.;
[0320] Finally, convert the random number r' 1i to the random polynomial r 1i , and thus use the random polynomial r 1i to construct the private key of the smart meter
[0321] where r 1i ∈ L f , is r modulo p 1i ;
[0322] D1.2. Use the private key of the smart meter to decrypt R3 and obtain the random polynomial l'4:
[0323] a5 = r 1i R3 (mod q)
[0324]
[0325] where a5 is an intermediate variable;
[0326] D2. Use the random polynomials ID SM , l2 and l'4 to obtain the variable A'1:
[0327] A′1 = h(ID SM ||l2||l′4)
[0328] D3. Generate a new timestamp T6, and generate an authentication key K1 with the control center based on A′1, ID SM , l2, l′4, T6 and l x Then the smart meter transmits K1 and T6 to the control center over the public channel:
[0329] K1 = h(A1′||ID SM ||l2||l′4||T6||l x )
[0330] where l x is the location identifier of the smart meter, aiming to prevent the smart meter from obtaining price difference benefits by falsely reporting location information.
[0331] E. The control center generates a timestamp T7. The control center uses T7 to determine whether the timestamp T6 is within a reasonable range. If it is not within the reasonable range, the service is directly terminated; if it is within the reasonable range, an authentication key K1′ with the smart meter is generated, and then the control center authenticates the smart meter by comparing K1′ and K1, and generates a smart meter pseudonym PID SM and an authentication key K2 with the service provider. Finally, K2, PID SM and T7 are sent to the service provider, specifically:
[0332] E1. After receiving K1 and T6 transmitted by the smart meter, to resist replay attacks, the control center generates a timestamp T7, uses the timestamp T7 to determine whether the timestamp T6 is within a reasonable range. If it is within the reasonable range, an authentication key K1′ for the smart meter is generated, and then E2 is executed; otherwise, the service is directly terminated;
[0333] To determine whether the timestamp T6 is within a reasonable range, specifically:
[0334] If T7 - T6 < ΔT, it means that the timestamp T6 is within the reasonable range; otherwise, T6 is not within the reasonable range;
[0335] The generation of the authentication key K1′ with the smart meter is specifically:
[0336] K′1 = h(A1||ID SM ||l′2||l4||T6||l′ x )
[0337] where l' 'x is the location identifier of the smart meter stored in the control center;
[0338] E2. Compare the authentication key K1' of the smart meter generated by E1 with the authentication key K1 received from the smart meter. If K1' and K1 are the same, the authentication of the smart meter by the control center is completed, and then execute E3; if they are different, end the authentication.
[0339] E3. Generate the authentication key K2 between the control center and the service provider and the smart meter pseudonym PID SM , and then send K2, PID SM and the timestamp T7 to the service provider;
[0340] The authentication key K2 between the control center and the service provider is as follows:
[0341] K2 = h(A2||ID SP ||l′6||l4||T7||PID SM )
[0342] where h(·) is a hash function;
[0343] To achieve the anonymity of the smart meter, the real identity of the smart meter is hidden using the pseudonym of the smart meter. The smart meter pseudonym PID SM is as follows:
[0344] PID SM = ID SM ⊕A2
[0345] F. The service provider uses K2, PID SM and the timestamp T7 to complete the authentication of the service provider to the control center, then encrypts the random polynomial l7 to obtain R7, generates the session key K3 with the control center, and sends K3, the timestamp T8 and R7 to the control center through the public channel, specifically:
[0346] F1. After the service provider receives PID SM , K2 and T7, it generates the timestamp T8, and uses the timestamp T8 to check whether the timestamp T7 is within a reasonable range. If it is within a reasonable range, execute step F2; otherwise, directly end the service;
[0347] Checking whether the timestamp T7 is within a reasonable range is specifically: if T8 - T7 ≤ ΔT, it means that the timestamp T7 is within a reasonable range;
[0348] F2. The service provider uses the initial challenge value c 2i to recover the service provider's private key and then uses the service provider's private key to decrypt R6 to obtain l″4:
[0349] F2.1. The service provider uses the initial challenge value c2i Restore Service Provider Private Key Specifically:
[0350] First, use the initial challenge value c 2i to generate the response value f 2i , specifically:
[0351] f 2i = PUF(c 2i )
[0352] Then, use the fuzzy extractor to process the response f 2i to generate the random number r' 2i and the auxiliary data p 2i :
[0353] (r' 2i ) = Rep(f 2i , p 2i )
[0354] where is the recovery algorithm of the fuzzy extractor. Inputting the binary sequence or a sequence close enough to the binary sequence and the auxiliary information p can recover the key r;
[0355] Then, convert the random number r' 2i to the random polynomial r 2i ∈ L f , and use r 2i to construct the service provider private key
[0356] where is r modulo p 2i ;
[0357] F2.2. Use the service provider private key to decrypt R6 to obtain l''4:
[0358] a6 = r 2i R6 (mod q)
[0359]
[0360] where a6 is an intermediate variable;
[0361] F3. Use the service provider identity information ID sP , l6 and l''4 to generate A2', and then use A2' to obtain the authentication key K2' with the control center. Compare the authentication key K2' with the control center with the received K2 by the service provider. If K2' is consistent with K2, the authentication of the service provider to the control center is completed, and F4 is executed; otherwise, the authentication process ends;
[0362] A2′ and K2′ are obtained as follows:
[0363] A2′ = h(ID SP ||l6||l″4)
[0364] K2′ = h(A2′||ID SP ||l6||l″4||T7||PID SM )
[0365] F4. Generate a new random polynomial l7 ∈ L m , encrypt l7 to obtain the encryption result R7:
[0366] R7 = l5*PK CC +l7 (mod q)
[0367] F5. XOR the pseudonym PID of the smart meter SM with A2′ to restore the identity information ID of the smart meter SM , and further obtain the common session key SK of the smart meter, control center, and service provider and the authentication key K3 with the control center. Send K3, timestamp T8, and R7 to the control center on the public channel;
[0368] The identity information ID of the smart meter SM Specifically:
[0369] ID SM = PID SM ⊕A2′
[0370] The common session key SK of the smart meter, control center, and service provider is specifically:
[0371] SK = h(ID SM ||ID SP ||l″4||l7)
[0372] The authentication key K3 between the service provider and the control center is specifically:
[0373] K3 = h(A2′||SK||l6||T8||l y )
[0374] where l y is the location identifier of the service provider;
[0375] G. The control center decrypts R7 using the control center private key to obtain the random polynomial l’7, obtains the authentication key K3′ between the control center and the service provider using l’7 and T8, and completes the authentication of the control center to the service provider using K3′ and K3; then encrypts l’7 to obtain R8, and generates the authentication key K4 with the smart meter and the service provider pseudonym PID SP , and sends K4, R8, PID SP and the current timestamp T9 to the smart meter, specifically:
[0376] G1. After receiving K3, T3, and R7, the control center generates a timestamp T9, uses the timestamp T9 to check whether the timestamp T8 is within a reasonable range. If it is within the reasonable range, then execute G2; otherwise, directly end the authentication;
[0377] Specifically, checking whether the timestamp T8 is within a reasonable range is as follows: If T9 - T8 ≤ ΔT, it means that the timestamp T8 is within the reasonable range; otherwise, it means that the timestamp T8 is not within the reasonable range;
[0378] G2. The control center uses the control center private key to decrypt R7 to obtain the random polynomial l’7, and further obtains the common session key SK′ of the smart meter, the control center, and the service provider and the authentication key K3′ with the service provider:
[0379] a7 = r CC R7 (mod q)
[0380]
[0381] SK′ = h(ID SM ||ID SP ||l4||l′7)
[0382] K3′ = h(A2||SK′||l’6||T8||l y ′)
[0383] where l y ′ is the location identifier of the service provider stored in the control center;
[0384] G3. Compare the authentication key K3′ with the service provider obtained in G2 with the K3 obtained by the control center in G1. If they are the same, the authentication of the control center to the service provider is completed, and execute G4; otherwise, the authentication process ends;
[0385] G4. Encrypt l′7 to obtain the encryption result R8, and then generate the authentication key K4 with the smart meter:
[0386] R8 = l3*PK SM +l′7 (mod q)
[0387] K4 = h(A1 || SK′ || l′2 || T9)
[0388] G5. To achieve anonymity, the ID of the service provider SP is XORed with A1 to generate the service provider pseudonym PID SP , and K4, timestamp T9, and PID SP and R8 are sent to the smart meter;
[0389] The service provider pseudonym PID SP is as follows:
[0390] PID SP = ID SP ⊕ A1
[0391] H. The smart meter uses K4, T9, PID SP and R8 to complete the authentication of the smart meter to the control center, and generates the common session key SK′ of the smart meter, control center, and service provider, specifically:
[0392] H1. After receiving K4, T9, PID SP and R8, the smart meter generates a timestamp T 10 , and uses the timestamp T 10 to check whether the timestamp T9 is within a reasonable range. If it is within the reasonable range, then execute H2; otherwise, directly end the service;
[0393] Using the timestamp T 10 to check whether the timestamp T9 is within a reasonable range, specifically:
[0394] If T 10 - T9 ≤ ΔT, it means that the timestamp T9 is within a reasonable range; otherwise, it means that the timestamp T9 is not within a reasonable range;
[0395] H2. Use the private key of the smart meter to decrypt the random polynomial l″7 in R8, and then solve for the identity information ID of the service provider SP :
[0396] a8 = r 1i R8 (mod q)
[0397]
[0398] ID SP = PID SP ⊕ A1
[0399] H3. Use ID SM 、ID SP, l′4 and l″7 obtain the common session key SK″ of the smart meter, control center, and service provider, and then use A′1, SK″, l2, and T9 for the authentication key K4′ between the smart meter and the control center:
[0400] SK″ = h(ID SM ||ID SP ||l′4||l″7)
[0401] K4′ = h(A1′||SK″||l2||T9)
[0402] H4 compares the key K4′ with the key K4. If they are the same, the authentication of the smart meter for the control center is completed; otherwise, the authentication process is directly terminated.
[0403] The schematic table of the identity authentication and key negotiation phase is shown in Table 3.
[0404] Table 3
[0405]
[0406]
[0407] In this embodiment, each time authentication is performed, the system updates the challenge value parameters of the smart meter and the service provider, so that the response value and subsequent random numbers change, and then updates the private keys of the smart meter and the service provider. At the same time, the random polynomials l2, l4, l6, and l7 are also updated to enhance the untraceability and forward security of the system.
[0408] The present invention combines physical unclonable functions, fuzzy extractors, and NTRU technologies, and provides an efficient and secure authentication, data protection, and communication mechanism through the uniqueness guarantee at the hardware level and advanced cryptographic technologies. The PUF uses physical randomness or microscopic manufacturing differences to generate unique identifiers; the fuzzy extractor stabilizes the output, hides the relationship between the stimuli and responses, and can recover the private key later; NTRU not only has a small computational overhead but also has the characteristics of resisting quantum computing, and can effectively resist the threats brought by quantum computers to traditional public key encryption algorithms. Combining the advantages of the three, the present invention can provide strong security while ensuring efficiency. The present invention not only saves communication resources, realizes registration in the public channel, and does not store private key information. It has been experimentally proven that the present invention can achieve the expected experimental results in terms of security:
[0409] Mutual Authentication: In the present invention, two-way authentication among the control center, smart meter, and service provider is completed according to K′1 = K1, K′2 = K2, K′3 = K3, and K′4 = K4. During the authentication and key negotiation process of the present invention, due to the Ring-SIS and Ring-LWE hard problems of NTRU, the adversary cannot obtain the ID of the smart meter SM , and can only be cracked by r li , r 2i to obtain l4 that can only be cracked by r CC to obtain l2 that can only be cracked by r SP . Therefore, the information of K1 cannot be forged; similarly, the adversary cannot crack l4, l2, and the ID of the service provider CC and cannot forge the information of K2; in addition, the adversary cannot obtain l7 that can only be cracked by r li and r
[0410] to forge the information of K3 and K4. SM , the ID of the service provider SP , and can only be cracked by r 1i , r 2i to obtain l4 that can only be cracked by r CC , r 1i to obtain l7 that can only be cracked by r
[0411] Impersonation Attack: The adversary obtains all the information transmitted on the public channel to achieve the purpose of impersonating the smart meter, control center, and service provider. In the present invention, if the adversary attempts to impersonate the smart meter, since it cannot obtain the ID SM , l2, and l4 at the same time, it cannot generate K1 and A1, so it cannot pass the identity authentication. Similarly, the adversary cannot obtain the ID SP , l6, and l4 at the same time or cannot obtain the ID SM , l2, l4, and l7 at the same time, so it cannot impersonate the control center; the adversary cannot obtain the ID SP , l6, l4, and l7 at the same time, so it cannot impersonate the service provider.
[0412] Forward Secrecy: In the present invention, even if the adversary obtains the previous authentication key and session key, since l2, l4, l6, and l7 are dynamically updated, c 1i and c 2i will also be dynamically updated, so the private keys of the smart meter and service provider will also be dynamically updated. Therefore, each authentication is different, and the adversary cannot obtain the current authentication key and session key.
[0413] Anonymity: In the present invention, the smart meter and the control center encrypt the ID with the public key of the control center respectively. SM and the ID SP . The control center generates the pseudonym PID of the smart meter SM = ID SM ⊕ A2, and the pseudonym PID of the service provider SP = ID SP ⊕ A1. When the adversary intercepts the information PID Sm and PID SP on the public channel, due to the inability to obtain the private key of the control center and the ID constituting A2 SP , l6 and l4, the adversary cannot obtain the real information of the smart meter; similarly, the adversary cannot obtain the ID constituting A1 SM , l2 and l4, so the adversary cannot obtain the real information of the service provider.
[0414] Resistance to DoS attack: The DoS attack actually means that the attacker makes the target system difficult to bear the current storage, bandwidth, etc. by sending a large amount of information, resulting in the system being slow or even crashing. In the present invention, SM, SP, and CC will check whether the timestamp is within a reasonable range every time they receive new transmission information. If not, they will immediately terminate the authentication and key negotiation process. If K'1!= K1, K'2!= K2, K'3!= K3, K'4!= K4, they will immediately terminate the authentication and key negotiation process to prevent potential DoS attacks.
[0415] Resistance to quantum attack: In the present invention, l2, l4, l6, and l7 all use the NTRU public key encryption method for encryption, and its security is based on the short integer solution problem Ring-SIS on the ring. Currently, there is no known efficient solution for these problems in classical computers and quantum computers.
[0416] Replay attack: A replay attack means that the attacker intercepts and re-sends a previous valid message to deceive the system into authenticating it. In the present invention, the system time is synchronized, and a timestamp is randomly generated every time information is received. By detecting whether the timestamp is within a reasonable range, the attacker is prevented from launching a replay attack.
[0417] Resistance to machine learning attack: If the attacker can obtain a certain number of CRP pairs, a model can be established to infer the corresponding response when a new stimulus is obtained. In the present invention, no stimulus and response are leaked during the transmission process. Coupled with the application of the fuzzy extractor, the relationship between the stimulus and the response is made more secret, so there is no machine learning attack against CRP.
[0418] Anti-cloning and physical attacks: Anti-cloning and physical attacks refer to the functions of an attacker copying or attacking a device to obtain or tamper with sensitive information. The present invention utilizes a physically unclonable function, whose output varies due to tiny differences. Moreover, during the registration phase, the service provider and the smart meter clear the private key and the response value. Additionally, the tampering behavior of the attacker will change the output of the PUF. Therefore, anti-cloning and physical attacks can be achieved.
[0419] Anti-privileged insider attacks: These are attack behaviors targeting internal users with privileged permissions, and the adversary can obtain the channel information during the registration phase. Since only encrypted information and public keys exist in the channel during the registration process in this design, and the l2, l4, l6, and l7 required for subsequent authentication and key negotiation cannot be cracked, anti-privileged insider attacks can be achieved.
Claims
1. A smart grid authentication and key agreement method based on NTRU grid, characterized by: The specific process of the method is: System initialization stage: The control center performs system initialization, determines system parameters, generates the public key of the control center, selects and stores corresponding identity information for each smart meter and service provider, sends the system parameters obtained by system initialization, the public key of the control center and the identity information of the smart meter to the smart meter; sends the system parameters obtained by system initialization, the public key of the control center and the identity information of the service provider to the service provider; Smart meter registration phase: The smart meter uses the smart meter identity information ID obtained after initialization SM , control center public key PK CC , system parameters are registered in the public channel for smart meter; Service provider registration phase: The service provider uses the service provider identity information ID obtained after initialization sp , control center public key PK CC , system parameters are registered with the service provider in the public channel; Authentication and key negotiation phase: The control center authenticates the smart meter, the service provider authenticates the control center, the control center authenticates the service provider, and the smart meter authenticates the control center in sequence, and a consistent session key is negotiated between the smart meter, the control center, and the service provider.
2. According to claim 1, a smart grid authentication and key agreement method based on NTRU grid is characterized in that: The specific process of the system initialization stage is as follows: A1. The control center determines the system parameters and generates the control center public and private keys: First, the control center initializes and generates system parameters; The system parameters include: a hash function h(·), a prime number q that determines the modulus of the polynomial ring, a control parameter prime number p that adjusts the noise number, and a prime number N that is the number of the polynomial ring; Then, three polynomial rings are defined in terms of q, p and N: Where X is the variable of the polynomial, Z represents the set of integers, and Z[X] is the polynomial ring over integers; Then, four sets of polynomials with integer coefficients are selected in the polynomial ring (L f , L g , L r , L m ) and will be added to the system parameter set; Then, in the set of integer coefficient polynomials L f Select r CC , in L g Select g CC , and then according to r CC Get the control center private key Using r CC and g CC Get the control center public key PK CC : Among them, g CC With r CC Mutually prime, It is r of model q CC , is r under the modulus p CC ; A2. The control center selects and stores identity information for each smart meter and server, and stores the control center public key PK CC , system parameters q, p, N, L f , L g , L r , L m , hash function h(·) and the identity information ID of the smart meter SM Send to smart meter; send the control center public key PK CC , system parameters q, p, N, L f , L g , L r , L m , hash function h(·) and the server's identity information ID sp Sent to the service provider.
3. The method for smart grid authentication and key agreement based on NTRU grid according to claim 2, characterized in that: The specific process of the smart meter registration stage is as follows: B1. Smart meter selects initial challenge value c 1i , using c 1i Generate smart meter private key Specifically: B1.
1. The smart meter selects an initial challenge value c 1i , and use the physical unclonable function to generate the corresponding response f 1i , specifically: f 1i =PUF(c 1i ) Among them, PUF() is a physically unclonable function; B1.
2. Processing response f using fuzzy extractor 1i Generate a random number r′ 1i and auxiliary data p 1i : (r′ 1i ,p 1i )=Gen(f 1i ) Among them, Gen() is the generation algorithm of the fuzzy extractor; B1.
3. The random number r′ 1i Convert to random polynomial r 1i , based on the random polynomial r 1i Constructing a smart meter private key Among them, r 1i ∈L f , is r under the modulus p 1i ; B2. Using the private key of smart meter Generate smart meter public key PK SM , specifically: Among them, g 1i ∈L g , is r under the module q 1i , g 1i With r 1i mutually prime; B3, generate random polynomials l1 and l2, use l1 and control center public key PK CC The prime number q that determines the modulus of the polynomial ring is related to the smart meter ID SM and random polynomial l2, respectively, to obtain encryption results R1 and R2, specifically: R1=l1*PK CC +ID SM (mod q) R2=l1*PK CC +l2(mod q) Among them, l1∈L r , l2∈L m ; B4. Generate timestamp T, using ID SM , R2, PK SM and T to obtain the variable M1, and the smart meter converts M1, R1, R2, PK SM and T are transmitted to the control center through an open channel; The variable M1 is specifically: M1=h(ID SM ||R2||PK SM ||T) B5, the control center receives M1, R1, R2, PK SM The control center uses the timestamp T1 to check whether the timestamp T is within a reasonable range. If it is within a reasonable range, the control center uses the private key to decrypt the identity information ID′ of the smart meter. SM and random polynomial l′2, then execute B6; otherwise, terminate the service directly; The control center uses the timestamp T1 to check whether the timestamp T is within a reasonable range. Specifically, if T1-T<ΔT, it means that the timestamp T is within a reasonable range, otherwise it means that the timestamp T is not within a reasonable range. Wherein, ΔT is the preset timestamp interval threshold; The control center private key is used to decrypt the identity information ID′ of the smart meter SM and the random polynomial l′2, specifically: a1=r CC R1(mod q) a2=r CC R2(mod q) Among them, a1 and a2 are intermediate variables; B6. Compare the identity information ID selected for the smart meter during the system initialization phase SM With ID′ SM Are they the same? If they are the same, use the ID SM , R2, PK SM Generate variable M1′ with T. If they are not the same, terminate the service directly. Then compare M1 with M1′. If M1 and M1′ are the same, execute B7. If they are not the same, terminate the service directly. Utilization ID SM , R2, PK SM and T generate the variable M1′, specifically: M1′=h(ID SM ||R2||PK SM ||T) B7, generate random polynomial l4, the control center uses the public key PK of the smart meter SM Encrypt the random polynomial l4 to obtain R3, and then use ID SM , l′2, R3 and T1 generate M2, using ID SM ,l′2 and l4 generate A1, and transmit the timestamps T1, R3 and ,M2 to the smart meter in the open channel; R3, M2, A1 are obtained by the following formula: <h2 style=";text-align:left;direction:ltr">R3 = l3 * PK<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> +l4(mod q) <h2 style=";text-align:left;direction:ltr">M2 = h(ID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ||l′2||R3||T1) A1=h(ID SM ||l′2||l4) Among them, l4∈L m , l3 is a random polynomial, l3∈L r ; B8. After receiving T1, R3 and m2, the smart meter generates a timestamp T2 and uses the timestamp T2 to check whether the timestamp T1 is within a reasonable range. If not, the service is terminated directly. If within a reasonable range, the ID SM , l2, R3 and T1 generate m′2; The use of timestamp T2 to check whether timestamp T1 is within a reasonable range is specifically: if T2-T1<ΔT, it means that timestamp T1 is within a reasonable range, otherwise it means that timestamp T1 is not within a reasonable range; The Utilization ID SM , l2, R3 and T1 generate M′2, specifically: <h2 style=";text-align:left;direction:ltr">M′2 = h(ID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ||l2||R3||T1) B9, compare M′2 with the received M2, if M′2 is consistent with M2, store the received R3, and then clear the private key of the smart meter Response value f 1i , M1 and M2′; if M′2 is inconsistent with M2, the service is terminated directly.
4. The method for smart grid authentication and key agreement based on NTRU grid according to claim 3 is characterized in that: The specific process of the service provider registration stage is as follows: C1. The service provider selects the initial challenge value c 2i , using the initial challenge value c 2i Generate a random number r′ 2i and auxiliary data p 2i , specifically: C1.
1. The service provider selects the initial challenge value c 2i , using c 2i Generate response value f 2i , specifically: f 2i =PUF(c 2i ) C1.
2. Processing response f using fuzzy extractor 2i Generate a random number r′ 2i and auxiliary data p 2i : (r′ 2i ,p 2i )=Gen(f 2i ) C2, the random number r' 2i Convert to random polynomial r 2i , based on r 2i Constructing a Service Provider Private Key Then use the constructed service provider private key to generate the service provider public key Pk SP : Among them, r 2i ∈L f , g 2i ∈L g , g 2i With r 2i Mutually prime, is r under the module q 2i , is r under the modulus p 2i ; C3, generate random polynomial l6, using the control center public key PK CC The service provider ID SP and random polynomial l6 respectively, to obtain the encrypted service provider identity information R4 and the encrypted random polynomial R5: R4=l5*PK CC +ID SP (mod q) R5=l5*PK CC +l6(mod q) Among them, l6∈L m , l5∈L r , l5 is a random polynomial; C4, generate timestamp T3, use ID SP , R5, PK SP and T3 service provider to obtain variable M3, and M3, R4, R5, PK SP and T3 are transmitted to the control center through an open channel; The Utilization ID SP , R5, PK SP and the T3 service provider obtains the variable M3, specifically: <h2 style=";text-align:left;direction:ltr">M3 = h(ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||R5||PK<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||T3) C5, control center receives M3, R4, R5, PK SP The control center uses the timestamp T4 to check whether the timestamp T3 is within a reasonable range. If it is within a reasonable range, the control center uses the private key to decrypt the service provider identity information ID′ SP and random polynomial l′6, then execute C6; otherwise, terminate the service directly; The control center uses the timestamp T4 to check whether the timestamp T3 is within a reasonable range, specifically: If T4-T3<ΔT, it means that the timestamp T3 is within a reasonable range, otherwise it means that the timestamp T3 is not within a reasonable range; The control center private key is used to decrypt the service provider identity information ID' SP and the random polynomial l′6, specifically: a3=r CC R4(mod q) a4=r CC R5(mod q) C6. Based on the decrypted service provider ID′ SP The identity information ID selected by the control center for the service provider SP Compare, if the same, use ID SP , R5, PK SP Calculate variable M3′ with T3; otherwise, terminate the service directly; compare M3′ with M3 to see if they are the same, if they are the same, execute C7; otherwise, terminate the service directly; The Utilization ID SP , R5, PK SP and T3 to calculate the variable M3′, specifically: <h2 style=";text-align:left;direction:ltr">M3′ = h(ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||R5||PK<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||T3) C7, the control center uses the service provider's public key PK SP Encrypt l4 to obtain R6, and then use ID SP , l′6, R6 and T4 generate M4, using ID SP , l′6 and l4 generate A2, and transmit timestamps T4, R6 and M4 to the service provider in a public channel; R6, M4, A2 are obtained by: <h2 style=";text-align:left;direction:ltr">R6 = l3 * PK<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> +l4(mod q) M4=h(ID SP ||l′6||R6||T4) <h2 style=";text-align:left;direction:ltr">A2 = h(ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||l′6||l4) C8. After receiving T4, R6 and M4 data, the service provider generates a timestamp T5 and uses the timestamp T5 to check whether the timestamp T4 is within a reasonable range. If it is within a reasonable range, the service provider uses the ID SP , T4, R6 and l6 generate M4′, and then execute C9; otherwise, the service ends directly; The use of timestamp T5 to check whether timestamp T4 is within a reasonable range is specifically as follows: If T5-T4<ΔT, it means that the timestamp T4 is within a reasonable range, otherwise it means that the timestamp T4 is not within a reasonable range; The Utilization ID SP , T4, R6 and l6 generate M4′, specifically: M4′=h(ID SP ||l6||R6||T4) C9, compare M4′ with M4 to see if they are consistent. If they are consistent, store R6 and then clear the service provider’s private key. Response value f 2i , M3 and M4; otherwise, terminate the service directly.
5. The method for smart grid authentication and key agreement based on NTRU grid according to claim 4, characterized in that: The specific process of the authentication and key agreement phase is as follows: D. The smart meter recovers the private key of the smart meter and uses the private key to decrypt the random polynomial l′4. Then, l′4 is used to obtain the authentication key K1 with the control center. The smart meter transmits K1 and the current timestamp T6 to the control center in the public channel. E. The control center generates a timestamp T7. The control center uses T7 to determine whether the timestamp T6 is within a reasonable range. If not, the service is terminated directly. If it is within a reasonable range, the authentication key K1′ with the smart meter is generated. Then, the control center completes the authentication of the smart meter through K1′ and K1, and then generates the smart meter pseudonym PID. SM and the authentication key K2 with the service provider, and finally K2, PID SM and T7 to the service provider; F. Service providers use K2 and PID SM The service provider completes the authentication of the control center with the timestamp T7, then encrypts the random polynomial l7 to obtain R7, generates the authentication key K3 between the service provider and the control center, and sends K3, R7 and the current timestamp t8 to the control center through a public channel; G. The control center uses the control center private key to decrypt R7 to obtain the random polynomial l'7, uses l'7 and T8 to obtain the authentication key K3' with the service provider, and uses K3' and K3 to complete the control center's authentication of the service provider; then encrypts l'7 to obtain R8, and then generates the authentication key K4 with the smart meter and the service provider pseudonym PID SP , set K4, R8, PID SP And the current timestamp T9 is sent to the smart meter; H. Smart meter using K4, T9, PID SP The smart meter and R8 complete the authentication of the control center and generate a common session key SK′ for the smart meter, the control center and the service provider.
6. The method for smart grid authentication and key agreement based on NTRU grid according to claim 5, characterized in that: The smart meter in D recovers the private key of the smart meter and uses the private key of the smart meter to decrypt the random polynomial l′4. Then, l′4 is used to obtain the authentication key K1 with the control center. The smart meter transmits K1 and the current timestamp T6 to the control center in the public channel. Specifically: D1, smart meter uses initial challenge value c 1i Recovering the Smart Meter Private Key Then use the private key of the smart meter Decrypt R3 and obtain the random polynomial l′4: D1.
1. Smart meter uses initial challenge value c 1i Recovering the Smart Meter Private Key First, using the initial challenge value c 1u Generate response f 1i : f 1i =PUF(c 1i ) Then, the response f is processed using the fuzzy extractor 1i Generate a random number r′ 1i and auxiliary data p 1i : (r′ 1i )=Rep(f 1i ,p 1i ) Finally, the random number r′ 1i Convert to random polynomial r 1i , thus using the random polynomial r 1i Constructing a smart meter private key Among them, r 1i ∈L f , is r under the modulus p 1i ; D1.
2. Using the private key of the smart meter Decrypt R3 and obtain the random polynomial l′4: a5=r 1i R3(mod q) Among them, a5 is an intermediate variable; D2. Using random polynomial ID SM , l2 and l′4 to obtain the variable A′1: A′1=h(ID SM ||l2||l′4) D3, generate a new timestamp T6, based on A′1, ID SM , l2, l′4 and T6 generate the authentication key K1 with the control center, and then the smart meter transmits K1 and T6 to the control center in the open channel; The authentication key K1 with the control center is: <h2 style=";text-align:left;direction:ltr">K1 = h(A1′||ID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ||l2||l′4||T6||l<h2 style=";text-align:left;direction:ltr"> x <h2 style=";text-align:left;direction:ltr"> ) Among them, l x is the smart meter location identifier.
7. The method for smart grid authentication and key agreement based on NTRU grid according to claim 6, characterized in that: The control center uses T7 to determine whether the timestamp T6 is within a reasonable range. If not, the service is terminated directly. If it is within a reasonable range, the authentication key K1′ with the smart meter is generated, and the authentication of the smart meter by the control center is completed by comparing K1′ with K1, and then the pseudonym PID of the smart meter is generated. SM and the authentication key K2 with the service provider, and finally K2, PID SM and T7 to the service provider, specifically: E1. After receiving K1 and T6 from the smart meter, the control center generates a timestamp T7 and uses the timestamp T7 to determine whether the timestamp T6 is within a reasonable range. If it is within a reasonable range, the smart meter authentication key K1′ is generated and then E2 is executed; otherwise, the service is terminated directly. The use of timestamp T7 to determine whether timestamp T6 is within a reasonable range is specifically: if T7-T6<ΔT, it means that timestamp T6 is within a reasonable range, otherwise it means that T6 is not within a reasonable range; The authentication key K1′ with the smart meter is specifically: <h2 style=";text-align:left;direction:ltr">K′1 = h(A1||ID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ||l′2||l4||T6||l′<h2 style=";text-align:left;direction:ltr"> x <h2 style=";text-align:left;direction:ltr"> ) Among them, l′ x is the location identifier of the smart meter stored in the control center; E2, compare the smart meter authentication key K1′ generated by E1 with the authentication key K1 received from the smart meter. If K1′ and K1 are the same, the control center completes the authentication of the smart meter and then executes E3; if they are not the same, the authentication ends; E3, generate the authentication key K2 between the control center and the service provider and the smart meter pseudonym PID SM , then K2, PID SM and timestamp T7 is sent to the service provider; The authentication key K2 between the control center and the service provider is as follows: <h2 style=";text-align:left;direction:ltr">K2 = h(S2||ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||l′6||l4||T7||PID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ) The smart meter pseudonym PID SM as follows:
8. The method for smart grid authentication and key agreement based on NTRU grid according to claim 7, characterized in that: The service provider in F uses K2 and PID SM The service provider completes the authentication of the control center with the timestamp T7, then encrypts the random polynomial l7 to obtain R7, generates the authentication key K3 between the service provider and the control center, and sends K3, R7 and the current timestamp T8 to the control center through the public channel, specifically: F1. The service provider receives PID SM After K2 and T7, generate timestamp T8, use timestamp T8 to check whether timestamp T7 is within a reasonable range, if it is within a reasonable range, execute F2; otherwise, end the service directly; F2, the service provider uses the challenge value c 2i Recovering the Service Provider Private Key Then use the service provider private key Decrypt R6 to obtain l″4, specifically: F2.
1. Service providers use challenge value c 2i Recovering the Service Provider Private Key Specifically: First, using the challenge value c 2i The response value f 2i , specifically: f 2i =PUF(c 2i ) Then, the response f is processed using the fuzzy extractor 2i Generate a random number r′ 2i and auxiliary data p 2i : (r′ 2i )=Rep(f 2i ,p 2i ) Finally, the random number r′ 2i Convert to random polynomial r 2i , using r 2i Constructing a Service Provider Private Key Among them, r 2i ∈L f , is r under the modulus p 2i ; F2.
2. Using the Service Provider Private Key Decrypt R6 to obtain l″4: a6=r 2i R6(mod q) Among them, a6 is an intermediate variable; F3. Using the service provider identity information ID SP , l6 and l″4 generate A2′, then use A2′ to obtain the authentication key K2′ with the control center, and compare K2′ with K2 received by the service provider. If K2′ is consistent with K2, the service provider completes the authentication of the control center and executes F4; otherwise, the authentication process ends; The use of service provider identity information ID SP and l6 to generate A2′, specifically: <h2 style=";text-align:left;direction:ltr">A2′ = h(ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||l6||l″4) Use A2′ to obtain the authentication key K2′ with the control center, specifically: <h2 style=";text-align:left;direction:ltr">K2′ = h(A2′||ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||l6||l″4||T7||PID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ) F4. Generate a new random polynomial l7, encrypt l7, and obtain the encryption result R7: <h2 style=";text-align:left;direction:ltr">R7 = l5*PK<h2 style=";text-align:left;direction:ltr"> CC <h2 style=";text-align:left;direction:ltr"> +l7(mod q) Among them, l7∈L m ; F5, use A2' to obtain the authentication key K3 between the service provider and the control center, and send K3, timestamp T8 and R7 to the control center in the public channel; the authentication key K3 between the service provider and the control center is as follows: <h2 style=";text-align:left;direction:ltr">K3 = h(A2′||SK||l6||T8||l<h2 style=";text-align:left;direction:ltr"> y <h2 style=";text-align:left;direction:ltr"> ) <h2 style=";text-align:left;direction:ltr">SK = h(ID<h2 style=";text-align:left;direction:ltr"> SM <h2 style=";text-align:left;direction:ltr"> ||ID<h2 style=";text-align:left;direction:ltr"> SP <h2 style=";text-align:left;direction:ltr"> ||l″4||l7) Among them, SK is the common session key of the smart meter, control center, and service provider. y is the location identifier of the service provider.
9. The method for smart grid authentication and key agreement based on NTRU grid according to claim 8, characterized in that: The control center in G uses the control center private key to decrypt R7 to obtain the random polynomial l'7, uses l'7 and T8 to obtain the authentication key K3' with the service provider, and uses K3' and K3 to complete the control center's authentication of the service provider; then encrypts l'7 to obtain R8, and then generates the authentication key K4 with the smart meter and the service provider pseudonym PID SP , set K4, R8, PID SP And the current timestamp T9 is sent to the smart meter, specifically: G1. After receiving K3, T3 and R7, the control center generates timestamp T9 and uses timestamp T9 to check whether timestamp T8 is within a reasonable range. If it is within a reasonable range, G2 is executed; otherwise, authentication is terminated directly. The use of timestamp T9 to check whether timestamp T8 is within a reasonable range is specifically: if T9-T8≤ΔT, it means that timestamp T8 is within a reasonable range, otherwise, it means that timestamp T8 is not within a reasonable range; G2, the control center uses the control center private key Decrypt R7 to obtain the random polynomial l'7, use l'7 to obtain the common session key SK' of the smart meter, control center, and service provider, and then use SK' to obtain the authentication key K3' with the service provider: <h2 style=";text-align:left;direction:ltr">K3′ = h(A2||SK′||l'6||T8||l<h2 style=";text-align:left;direction:ltr"> y <h2 style=";text-align:left;direction:ltr"> ′) SK′=h(ID SM ||ID SP ||l4||l′7) <h2 style=";text-align:left;direction:ltr">a7=r<h2 style=";text-align:left;direction:ltr"> CC <h2 style=";text-align:left;direction:ltr"> R7(mod q) Among them, l y ′ is the location identifier of the service provider stored in the control center; G3, compare the authentication key K3′ obtained with the service provider at G2 with the authentication key K3 obtained by the control center at G1 to see if they are consistent. If they are consistent, the control center completes the authentication of the service provider and executes G4; otherwise, the authentication process ends; G4, encrypt l′7 to obtain the encryption result R8, and then use SK′ to generate the authentication key K4 with the smart meter: R8=l3*PK SM +l′7(mod q) K4=h(A1||SK′||l′2||T9) G5. Use the identity information ID of the service provider SP and A1 generates the service provider pseudonym PID SP , then K4, timestamp T9, and PID SP and R8 to the smart meter; The identity information ID of the service provider is used SP and A1 generates the service provider pseudonym PID SP , specifically:
10. The method for smart grid authentication and key agreement based on NTRU grid according to claim 9, characterized in that: The smart meter in H uses K4, T9, PID SP The smart meter and R8 complete the authentication of the control center and generate the common session key SK′ of the smart meter, the control center and the service provider, which is: H1, smart meter receives K4, T9, PID SP After R8, the timestamp T is generated. 10 , using the timestamp T 10 Check whether the timestamp T9 is within a reasonable range. If so, execute H2; otherwise, terminate the service directly. The time stamp T 10 Check whether the timestamp T9 is within a reasonable range, specifically: If T 10 -T9≤ΔT, it means that the timestamp T9 is within a reasonable range; otherwise, it means that the timestamp T9 is not within a reasonable range; H2. Using the private key of smart meter Decrypt the random polynomial l″7 in R8, and then solve for the service provider’s identity information ID SP : a8=r 1i R8(modq) H3. Utilization ID SM 、ID SP , l′4 and l″7 obtain the common session key SK″ of the smart meter, control center and service provider, and then use A′1, SK″, l2 and T9 to obtain the smart meter’s authentication key K4′ for the control center: K4′=h(A1′||SK″||l2||T9) SK″=h(ID SM ||ID SP ||l′4||l″7) H4. Compare K4′ and K4 to see if they are consistent. If they are consistent, the smart meter completes the authentication of the control center; otherwise, the authentication process ends directly.
Citation Information
Cited By
Smart grid authentication and key negotiation method and system considering dynamic identity matching table
CN120768613A