A power system in-band non-inductive authentication method and system

Through the electromagnetic and thermal characteristics of power equipment, non-sensing authentication is performed. Combined with elliptic curve cryptography and physically unclonable functions, it solves the security and stability problems of traditional power system authentication methods and provides a safer, more convenient and reliable authentication solution.

CN120263535BActive Publication Date: 2025-10-10STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510695138.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-10-10
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

Traditional power system authentication methods lack security, are complex for user operation, lack strong anti-forgeability, and have poor system stability, which can easily lead to system instability in the face of network attacks or hardware failures.

Method used

The inherent electromagnetic and thermal characteristics of power equipment are used for non-sensing authentication, combined with elliptic curve cryptography technology for encryption, and the physical unclonable function (PUF) and fuzzy extractor are used to generate the authentication value, which is registered and verified by a trusted organization.

Benefits of technology

It achieves convenient authentication without user participation, improves the security, stability and reliability of the system, prevents illegal device access, complies with legal and regulatory requirements, and reduces operational complexity and error risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263535B_ABST
    Figure CN120263535B_ABST
Patent Text Reader

Abstract

The application discloses a kind of in-band non-inductive authentication method and system of power system, method includes: the first device dot multiplication, second device dot multiplication and first authentication value are calculated;Power equipment sends first authentication message to monitoring unit;After receiving the first authentication message, monitoring unit obtains second current timestamp, and generates second random number and first XOR value, calculates session key and second authentication value;Monitoring unit sends second authentication message to power equipment;After receiving second authentication message, power equipment obtains third current timestamp, and judges whether to establish, if it is established, then calculate second XOR value, session key, and verify whether second authentication check value is equal to second authentication value, authentication fails and terminates session, and authentication is successful then it is proved that it is legal monitoring unit.By using the inherent characteristics of power equipment for authentication, a more secure, more convenient and more reliable device authentication solution is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power systems, and in particular relates to an in-band sensorless authentication method and system for a power system. Background Art

[0002] Traditional power systems usually rely on user authentication to ensure the safe operation of the system. Common methods include technologies based on passwords, fingerprints, smart cards, etc. These methods have the following problems:

[0003] (1) Insufficient security: Passwords can be easily guessed or illegally obtained, resulting in the device being accessed or tampered with by unauthorized parties.

[0004] (2) Complex user operations: Users are required to perform manual operations each time they authenticate, which increases the user's operational burden and the risk of errors.

[0005] (3) Weak unforgeability: Traditional methods may not be able to effectively distinguish between legitimate and illegal devices and are easily counterfeited or forged.

[0006] (4) System stability issues: Traditional authentication methods may cause system instability and service interruption when facing network attacks or hardware failures. Summary of the Invention

[0007] The present invention provides an in-band sensorless authentication method and system for an electric power system, which is used to solve the technical problem that traditional electric power equipment authentication methods usually rely on users to enter passwords or manually confirm, resulting in insufficient security.

[0008] In a first aspect, the present invention provides an in-band sensorless authentication method for a power system, which is used for mutual authentication between a monitoring unit and power equipment, comprising:

[0009] The power device generates a first random number , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value ,in, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, is the secret parameter key;

[0010] The power device will first authenticate the message Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment;

[0011] After receiving the first authentication message, the monitoring unit obtains the second current timestamp , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ;

[0012] The monitoring unit sends the second authentication message Sent to power equipment;

[0013] The power equipment receives the second authentication message Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it proves that it is a legitimate monitoring unit. Is the exclusive OR operator.

[0014] In a second aspect, the present invention provides an in-band sensorless authentication system for a power system, which is used for mutual authentication between a monitoring unit and power equipment, comprising:

[0015] A generating module configured to generate a first random number for the power device , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value ,in, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, is the secret parameter key;

[0016] The first sending module is configured to send the first authentication message to the power equipment Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment;

[0017] The computing module is configured to obtain a second current timestamp after the monitoring unit receives the first authentication message , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ;

[0018] The second sending module is configured to monitor the second authentication message Sent to power equipment;

[0019] The verification module is configured to receive a second authentication message from the power device. Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it proves that it is a legitimate monitoring unit. Is the exclusive OR operator.

[0020] According to a third aspect, an electronic device is provided, comprising: at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can perform the steps of the in-band senseless authentication method for an electric power system according to any embodiment of the present invention.

[0021] In a fourth aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the program instructions are executed by a processor, the processor executes the steps of the in-band sensorless authentication method for an electric power system according to any embodiment of the present invention.

[0022] The in-band senseless authentication method and system of the power system of the present application provides a safer, more convenient and more reliable equipment authentication solution by utilizing the inherent characteristics of power equipment for authentication, which has significant advantages over traditional password-based authentication methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0024] Figure 1 A flow chart of an in-band sensorless authentication method for a power system provided by one embodiment of the present invention;

[0025] Figure 2 This is a structural block diagram of an in-band sensorless authentication system for a power system provided by one embodiment of the present invention;

[0026] Figure 3 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0028] See also Figure 1 , which shows a flow chart of an in-band sensorless authentication method for a power system of the present application.

[0029] like Figure 1 As shown, the power system in-band non-sensing authentication method specifically includes the following steps:

[0030] Step S101: The power equipment generates a first random number , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value .

[0031] In this step, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, For the secret parameter key, the power device extracts the device registration tuple from memory , set the first challenge value Input the physical unclonable function PUF and obtain the first response value , and then the first response value and the first auxiliary value Obtain the first verification auxiliary key through the regenerator of the fuzzy extractor , determine the first verification auxiliary key Is it equal to the first auxiliary key? If it is equal, it means that the data of the power equipment has not been modified; then, the electromagnetic characteristics of the power equipment are obtained. and thermal characteristics of electrical equipment , and calculate the secret parameter key ,in, is the first key protection value.

[0032] Step S102: The power equipment sends the first authentication message Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment.

[0033] Step S103: After receiving the first authentication message, the monitoring unit obtains the second current timestamp , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ,in, is the second key protection value.

[0034] In this step, the monitoring unit receives the first authentication message Then, get the second current timestamp ,judge Is it established, among which, is the maximum transmission delay;

[0035] If true, then the electromagnetic characteristics of the power equipment are determined and thermal characteristics of electrical equipment Whether it is within the set threshold;

[0036] If not, an alarm is issued or appropriate control measures are triggered;

[0037] If yes, the monitoring unit extracts the unit registration tuple , then monitor the unit's private key Input the physical unclonable function PUF and obtain the second response value , and then the second response value and the second auxiliary value The second auxiliary key is obtained by the regenerator of the fuzzy extractor , and calculate the secret parameter key , second device multiplication , , first authentication check value ;

[0038] Determine the first authentication check value and the first authentication value passed whether they are equal;

[0039] If they are not equal, the session is terminated;

[0040] If they are equal, it means that it is a legal power device, and the monitoring unit generates a second random number and the first XOR value , calculate the session key and the second authentication value .

[0041] Step S104: The monitoring unit sends the second authentication message Sent to power equipment;

[0042] Step S105: The power equipment receives the second authentication message Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it is proved to be a legitimate monitoring unit.

[0043] In a specific embodiment, registering the power device and the monitoring unit specifically includes:

[0044] The monitoring unit sends its real identity to the trusted agency To request registration; the trusted authority calculates the private key of the monitoring unit , It is the private key of the trusted organization, and the public key of the computing monitoring unit , is a base point on a finite field;

[0045] The power device sends a registration request to the trusted institution. When the trusted institution receives the request, it generates a first challenge value. , the secret parameter key K selects a power device pseudo identity , then the trusted institution sends the first registration request message Send back to the power equipment, the second registration request message Send to monitoring unit;

[0046] The power device receives the first registration request message Then, the first challenge value Input the physical unclonable function PUF and obtain the first response value , and then the first response value Get the first auxiliary value through the fuzzy extractor and the first auxiliary key , then calculate the first key protection value ,in, Is the exclusive OR operator, the power device finally stores the device register tuple ;

[0047] The monitoring unit receives the second registration request message After that, the private key Input the physical unclonable function PUF and obtain the second response value , and then the second response value Get the second auxiliary value through the fuzzy extractor and the second auxiliary key , the second key protection value ,Finally, the monitoring unit stores the unit registration tuple .

[0048] In summary, in this embodiment, the authentication method based on electromagnetic and thermal signatures utilizes electromagnetic signatures (such as electromagnetic wave intensity and spectrum characteristics) and thermal signatures (such as temperature distribution and variation patterns) generated by power equipment during operation to authenticate the device. These signatures are inherent to each power device during operation, are unique and stable, and can be used to identify and distinguish different devices.

[0049] Invisible authentication: Users don't need to directly participate in the authentication process. Instead, the power equipment and the monitoring and control unit authenticate each other through signature data. This approach eliminates complex user steps and improves system usability and user experience.

[0050] Application of Cryptography: Elliptic curve cryptography is used to encrypt and protect data transmission and storage during the authentication process. Elliptic curve cryptography is efficient and secure, making it suitable for encryption needs in resource-constrained environments (such as power equipment).

[0051] Registration and verification of trusted agencies: During the registration process, the power equipment and monitoring control units are verified and registered by a trusted third-party agency. This ensures the legitimacy of the identity of all participants in the system and the equipment, preventing illegal device access and data tampering.

[0052] The method of the present application can achieve the following technical effects:

[0053] Non-aware authentication: Traditional device authentication usually requires user participation and password input or manual confirmation. However, the present application uses the inherent electromagnetic and thermal characteristics of the device for authentication, eliminating the need for user direct participation and improving the convenience and user experience of the authentication process.

[0054] High security: Using elliptic curve cryptography technology to encrypt data transmission and storage, it is more efficient and secure than traditional encryption algorithms, effectively preventing data leakage and tampering.

[0055] Uniqueness and stability: The electromagnetic and thermal characteristics of the power equipment are inherent and stable, and each device has unique characteristics, which ensures the accuracy and reliability of the authentication and prevents illegal devices from accessing the system.

[0056] Compliance and legal protection: Designed and implemented in accordance with local laws and regulations and relevant standards, especially data privacy and security management regulations, reducing legal risks and legal liabilities.

[0057] System reliability: The introduction of fault-tolerant mechanisms and emergency recovery solutions ensures the availability and stability of the system in the face of hardware failures, network attacks or other unexpected situations.

[0058] Easy operation: Users do not need complex operation steps, only need to let the device go through the authentication process by itself, reducing the complexity of operation and the possibility of error.

[0059] In summary, the present application provides a more secure, convenient and reliable device authentication solution by using the inherent characteristics of the power equipment for authentication, which has significant advantages compared to traditional password-based authentication methods.

[0060] Please refer to Figure 2 , which shows a structural block diagram of a power system in-band non-aware authentication system of the present application.

[0061] As Figure 2 shown, the power system in-band non-aware authentication system 200 includes a generation module 210, a first sending module 220, a calculation module 230, a second sending module 240 and a verification module 250.

[0062] The generation module 210 is configured to generate a first random number , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value ,in, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, is the secret parameter key;

[0063] The first sending module 220 is configured to send the first authentication message to the power device Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment;

[0064] The calculation module 230 is configured to obtain a second current timestamp after the monitoring unit receives the first authentication message , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ;

[0065] The second sending module 240 is configured to monitor the second authentication message Sent to power equipment;

[0066] Verification module 250, configured to receive the second authentication message from the power device Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it proves that it is a legitimate monitoring unit. Is the exclusive OR operator.

[0067] It should be understood that Figure 2 Modules and references documented in Figure 1 Therefore, the operations and features described above for the method and the corresponding technical effects also apply to Figure 2 The modules in it will not be described in detail here.

[0068] In other embodiments, embodiments of the present invention further provide a computer-readable storage medium having a computer program stored thereon, wherein when the program instructions are executed by a processor, the processor is caused to execute the power system in-band sensorless authentication method in any of the above method embodiments;

[0069] As an embodiment, the computer-readable storage medium of the present invention stores computer-executable instructions, and the computer-executable instructions are configured as follows:

[0070] The power device generates a first random number , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value ,in, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, is the secret parameter key;

[0071] The power device will first authenticate the message Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment;

[0072] After receiving the first authentication message, the monitoring unit obtains the second current timestamp , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ;

[0073] The monitoring unit sends the second authentication message Sent to power equipment;

[0074] The power equipment receives the second authentication message Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it proves that it is a legitimate monitoring unit. Is the exclusive OR operator.

[0075] The computer-readable storage medium may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the in-band senseless authentication system for the power system, etc. In addition, the computer-readable storage medium may include a high-speed random access memory, and may also include a memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the computer-readable storage medium may optionally include a memory remotely located relative to the processor, and these remote memories may be connected to the in-band senseless authentication system for the power system via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0076] Figure 3 Schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Figure 3 As shown, the device includes: a processor 310 and a memory 320. The electronic device may also include: an input device 330 and an output device 340. The processor 310, the memory 320, the input device 330 and the output device 340 may be connected via a bus or other means. Figure 3 The example of the bus connection is taken. The memory 320 is the computer-readable storage medium mentioned above. The processor 310 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions and modules stored in the memory 320, that is, realizes the in-band senseless authentication method of the power system in the above method embodiment. The input device 330 can receive input digital or character information, and generate key signal input related to the user settings and function control of the in-band senseless authentication system of the power system. The output device 340 may include a display device such as a display screen.

[0077] The electronic device can execute the method provided by the embodiment of the present invention, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not fully described in this embodiment, please refer to the method provided by the embodiment of the present invention.

[0078] As an embodiment, the electronic device is applied to an in-band sensorless authentication system for a power system and is used for a client, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:

[0079] The power device generates a first random number , a first current timestamp , according to the first random number and the first current timestamp , calculates a first device dot product , a second device dot product and a first authentication value , wherein, is a concatenation symbol, is a hash function, is a base point on a finite field, is a public key, is a secret parameter key;

[0080] The power device sends a first authentication message to the monitoring unit, wherein, is a power device pseudo-identity, is an electromagnetic feature of the power device, is a thermal feature of the power device;

[0081] After the monitoring unit receives the first authentication message, it obtains a second current timestamp , generates a second random number and a first XOR value , calculates a session key and a second authentication value ;

[0082] The monitoring unit sends a second authentication message to the power device;

[0083] After the power device receives the second authentication message , it obtains a third current timestamp , and judges whether it is true, wherein, is a maximum transmission delay, if it is true, it calculates a second XOR value , a session key , and verifies whether the second authentication check value is equal to the second authentication value , if the verification fails, the session is terminated, if the verification succeeds, it proves to be a legal monitoring unit, wherein, is an XOR operation operator.

[0084] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods of each embodiment or certain portions of the embodiments.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A power system in-band non-sensing authentication method for mutual authentication between a monitoring unit and power equipment, characterized in that: include: The power device generates a first random number , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value ,in, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, is a secret parameter key, wherein a first random number is generated in the power device , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value Previously, registration of power equipment and monitoring units included: The monitoring unit sends its real identity to the trusted agency To request registration; the trusted authority calculates the private key of the monitoring unit , It is the private key of the trusted organization, and the public key of the computing monitoring unit , is a base point on a finite field; The power device sends a registration request to the trusted institution. When the trusted institution receives the request, it generates a first challenge value. , the secret parameter key K selects a power device pseudo identity , then the trusted institution sends the first registration request message Send back to the power equipment, the second registration request message Send to monitoring unit; The power device receives the first registration request message Then, the first challenge value Input the physical unclonable function PUF and obtain the first response value , and then the first response value Get the first auxiliary value through the fuzzy extractor and the first auxiliary key , then calculate the first key protection value ,in, Is the exclusive OR operator, the power device finally stores the device register tuple ; The monitoring unit receives the second registration request message After that, the private key Input the physical unclonable function PUF and obtain the second response value , and then the second response value Get the second auxiliary value through the fuzzy extractor and the second auxiliary key , the second key protection value ,Finally, the monitoring unit stores the unit registration tuple ; The power device will first authenticate the message Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment; After receiving the first authentication message, the monitoring unit obtains the second current timestamp , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ,in, The monitoring unit sends the second authentication message Sent to power equipment; The power equipment receives the second authentication message Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it proves that it is a legitimate monitoring unit. Is the exclusive OR operator.

2. The method for in-band non-sensing authentication of a power system according to claim 1, characterized in that: Generate a first random number in the power device , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value Previously, the method also included: Power device extracts device registration tuple from memory , set the first challenge value Input the physical unclonable function PUF and obtain the first response value , and then the first response value and the first auxiliary value Obtain the first verification auxiliary key through the regenerator of the fuzzy extractor , determine the first verification auxiliary key Is it equal to the first auxiliary key? If it is equal, it means that the data of the power equipment has not been modified; then, the electromagnetic characteristics of the power equipment are obtained. and thermal characteristics of electrical equipment , and calculate the secret parameter key ,in, is the first key protection value.

3. The method for in-band non-sensing authentication of a power system according to claim 1, characterized in that: After receiving the first authentication message, the monitoring unit obtains the second current timestamp , and generate a second random number and the first XOR value , calculate the session key and the second authentication value include: The monitoring unit receives the first authentication message Then, get the second current timestamp ,judge Is it established, among which, is the maximum transmission delay; If true, then the electromagnetic characteristics of the power equipment are determined and thermal characteristics of electrical equipment Whether it is within the set threshold; If not, an alarm is issued or appropriate control measures are triggered; If yes, the monitoring unit extracts the unit registration tuple , then monitor the unit's private key Input the physical unclonable function PUF and obtain the second response value , and then the second response value and the second auxiliary value The second auxiliary key is obtained by the regenerator of the fuzzy extractor , and calculate the secret parameter key , second device multiplication , , first authentication check value ,in, is a second key protection value; Determine the first authentication check value and the first authentication value passed whether they are equal; If they are not equal, the session is terminated; If they are equal, it means that it is a legal power device, and the monitoring unit generates a second random number and the first XOR value , calculate the session key and the second authentication value .

4. An in-band sensorless authentication system for a power system, used for mutual authentication between a monitoring unit and power equipment, characterized in that: include: A generating module configured to generate a first random number for the power device , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value ,in, is the concatenation symbol, is a hash function, is a base point on a finite field, is the public key, is a secret parameter key, wherein a first random number is generated in the power device , first current timestamp , according to the first random number and the first current timestamp , calculate the first device dot product , second device multiplication And the first authentication value Previously, registration of power equipment and monitoring units included: The monitoring unit sends its real identity to the trusted agency To request registration; the trusted authority calculates the private key of the monitoring unit , It is the private key of the trusted organization, and the public key of the computing monitoring unit , is a base point on a finite field; The power device sends a registration request to the trusted institution. When the trusted institution receives the request, it generates a first challenge value. , the secret parameter key K selects a power device pseudo identity , then the trusted institution sends the first registration request message Send back to the power equipment, the second registration request message Send to monitoring unit; The power device receives the first registration request message Then, the first challenge value Input the physical unclonable function PUF and obtain the first response value , and then the first response value Get the first auxiliary value through the fuzzy extractor and the first auxiliary key , then calculate the first key protection value ,in, Is the exclusive OR operator, the power device finally stores the device register tuple ; The monitoring unit receives the second registration request message After that, the private key Input the physical unclonable function PUF and obtain the second response value , and then the second response value Get the second auxiliary value through the fuzzy extractor and the second auxiliary key , the second key protection value ,Finally, the monitoring unit stores the unit registration tuple ; The first sending module is configured to send the first authentication message to the power equipment Sent to the monitoring unit, where Pseudo-identity for power equipment, is the electromagnetic characteristics of the power equipment, Thermal characteristics of electrical equipment; The computing module is configured to obtain a second current timestamp after the monitoring unit receives the first authentication message , and generate a second random number and the first XOR value , calculate the session key and the second authentication value ; The second sending module is configured to monitor the second authentication message Sent to power equipment; The verification module is configured to receive a second authentication message from the power device. Then, get the third current timestamp , and judge Is it established, among which, is the maximum transmission delay. If it is established, calculate the second XOR value , session key , and verify the second authentication check value Is it consistent with the second authentication value If the verification fails, the session is terminated; if the verification succeeds, it proves that it is a legitimate monitoring unit. Is the exclusive OR operator.

5. An electronic device, characterized in that: include: At least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 3.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.

Citation Information

Patent Citations

  • Anonymous authentication method and system based on equipment distance in edge computing environment

    CN117880800A