Batch anonymous access authentication method and system for power edge computing terminals

Through the batch signature verification algorithm combined with the linear homomorphic properties of elliptic curves and hash functions, efficient anonymous access authentication of devices in power Internet of Things systems is achieved, computing and communication overhead problems during large-scale device access is solved, and device identity privacy and data integrity are ensured.

CN120281483APending Publication Date: 2025-07-08CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +4
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510370877.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In existing power Internet of Things systems, there is too much computing and communication overhead when accessing equipment, which is difficult to support batch access of large-scale devices, resulting in delayed responses, and the device anonymous identity information needs to be sent in advance, resulting in security risks.

Method used

The batch signature verification algorithm is used to combine the bilinear mapping of the elliptic curve and the linear homomorphic properties of the hash function to realize batch authentication of anonymous identity information of multiple devices, generate side signature information and integrate authentication requests, reducing the computing load of side devices.

Benefits of technology

Improve device access efficiency, ensure confidentiality and calculation accuracy during data interaction, protect the anonymous identity of the device, and reduce the computing and communication overhead of the side devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281483A_ABST
    Figure CN120281483A_ABST
Patent Text Reader

Abstract

The invention provides a batch anonymous access authentication method and system for an electric power edge computing terminal, and the method comprises the steps: receiving authentication request information transmitted by all end-side equipment which requests to access the electric power Internet of Things at the same moment through edge-side equipment which accesses the electric power Internet of Things; based on the authentication request information sent by each end-side device, performing batch authentication on the anonymous identity information of each end-side device by using a batch signature verification algorithm to obtain a batch authentication result; when the batch authentication result is passed, generating side signature information according to the timestamp of the side equipment; based on the side signature information, integrating the side authentication request and sending the integrated side authentication request to each end side device; according to the batch signature verification algorithm, the validity of each signature and the integrity of data can be ensured by utilizing the bilinear mapping of the elliptic curve and the linear homomorphic property of the hash function, and a plurality of signatures can be verified in one operation, so that the calculation load and the processing time of side equipment are greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to a method and system for batch anonymous access authentication of power edge computing terminals. Background Art

[0002] In recent years, all parties have attached great importance to the intelligent management and monitoring of power equipment to ensure the stable operation of the power system and the optimal allocation of resources, and to accelerate the construction of a new type of power Internet of Things system that is secure, controllable, flexible, efficient, open and interactive. Edge computing, due to its characteristics such as low latency and location awareness, has become an important technical support for power system solutions. By extending computing power to the network edge, edge computing can make full use of the computing resources of edge devices and save network transmission bandwidth, and can provide low-latency and high-stability services, effectively improving the service quality of the power system. Currently, with the increasing development of the power Internet of Things system and the access of a large number of devices, the complexity of the power grid edge environment is increasing day by day, and the data interaction and collaborative operations among multiple entities on the edge side are becoming more and more frequent. Ensuring the privacy of sensitive data during the interaction and sharing process has also become an urgent problem to be solved in the current power Internet of Things.

[0003] In the new type of power Internet of Things system, the types and scales of power terminals are increasing day by day, and it is necessary to ensure the full trust of devices in the power system. In existing solutions, before an intelligent terminal device accesses the power Internet of Things system, it will send its own device information to the edge device. However, in the power Internet of Things, users often do not want others to know their identity information to prevent attackers from inferring users' living behavior habits by maliciously eavesdropping on data and analyzing users' electricity consumption. In addition, the existing framework construction solutions still adopt traditional authentication mechanisms, which have excessive computing and communication overheads and are difficult to support the growing device requirements in the edge computing environment. When a large number of devices access simultaneously, it will cause the edge device to respond with delays due to overloading, affecting the access efficiency of the devices and making it difficult to meet the requirements of batch access authentication of devices. Summary of the Invention

[0004] To solve the problem that the existing data authentication method cannot achieve batch verification of signatures when verifying the integrity of data, resulting in the situation that when a large number of devices access the edge device simultaneously, the edge device will respond with delays due to overloading, thus affecting the access efficiency of the devices, the present invention proposes a method for batch anonymous access authentication of power edge computing terminals, including:

[0005] Using the edge device accessing the power Internet of Things to receive the authentication request information sent by each end-side device requesting to access the power Internet of Things at the same moment;

[0006] Based on the authentication request information sent by each edge device, use the batch signature verification algorithm to batch authenticate the anonymous identity information of each edge device to obtain a batch authentication result;

[0007] When the batch authentication result is passed, generate edge signature information according to the time stamp of the edge device configured in advance;

[0008] Based on the edge signature information, integrate the edge authentication request and send it to each edge device;

[0009] Among them, the batch signature verification algorithm is carried out by combining the bilinear mapping of the elliptic curve and the linear homomorphism property of the hash function.

[0010] Optionally, the step of using the batch signature verification algorithm to batch authenticate the anonymous identity information of each edge device based on the authentication request information sent by each edge device to obtain a batch authentication result includes:

[0011] Perform a product operation according to the authentication request information of each edge device and a preset base point to obtain an aggregated verification information value of each edge device;

[0012] Perform a summation operation according to the signature authentication information of each edge device to obtain a signature verification information value of each edge device;

[0013] Use the batch signature verification algorithm to batch authenticate the anonymous identity information of each edge device based on the aggregated verification information value and the signature verification information value to obtain a batch authentication result.

[0014] Optionally, the expression corresponding to the batch signature verification algorithm is as follows:

[0015]

[0016] In the formula,

[0017]

[0018] Among them, Sig i represents the signature authentication information of the i-th edge device; i = 1...n; n represents the total number of edge devices accessing the power Internet of Things; P represents a preset base point on the elliptic curve; L i represents the aggregated verification information value of the i-th edge device; K i represents the first signature public key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; U i represents the second signature public key of the i-th edge device; represents the second encrypted data hash function value of the i-th edge device; h2i denote the data type hash function value of the i-th edge device; PK denotes the system public key; R i denote the third signature public key of the i-th edge device.

[0019] Based on the same inventive concept, the present invention also provides a batch anonymous access authentication system for a power edge computing terminal, including:

[0020] A request information receiving module, configured to use the edge devices accessing the power Internet of Things to receive the authentication request information sent by each edge device requesting to access the power Internet of Things at the same moment;

[0021] A batch identity authentication module, configured to perform batch authentication on the anonymous identity information of each edge device by using a batch signature verification algorithm based on the authentication request information sent by each edge device, to obtain a batch authentication result;

[0022] A signature information generation module, configured to generate edge signature information according to the time stamp of the edge device pre-configured when the batch authentication result is passed;

[0023] A data integration module, configured to integrate the edge authentication requests and send them to each edge device based on the edge signature information;

[0024] Wherein, the batch signature verification algorithm is performed by combining the bilinear mapping of the elliptic curve and the linear homomorphism property of the hash function.

[0025] Optionally, the batch identity authentication module includes:

[0026] An aggregation verification sub-module, configured to perform a product operation according to the authentication request information of each edge device and a pre-set base point to obtain the aggregation verification information value of each edge device;

[0027] A signature verification sub-module, configured to perform a summation operation according to the signature authentication information of each edge device to obtain the signature verification information value of each edge device;

[0028] A batch authentication sub-module, configured to perform batch authentication on the anonymous identity information of each edge device by using a batch signature verification algorithm according to the aggregation verification information value and the signature verification information value, to obtain a batch authentication result.

[0029] Optionally, the expression corresponding to the batch signature verification algorithm is as follows:

[0030]

[0031] In the formula,

[0032]

[0033] Among them, Sig i represents the signature authentication information of the i-th edge device; i = 1…n; n represents the total number of edge devices accessing the power Internet of Things; P represents the base point on the preset elliptic curve; L i represents the aggregated verification information value of the i-th edge device; K i represents the first signature public key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; U i represents the second signature public key of the i-th edge device; represents the second encrypted data hash function value of the i-th edge device; h 2i represents the data type hash function value of the i-th edge device; PK represents the system public key; R i represents the third signature public key of the i-th edge device.

[0034] Based on the same inventive concept, the present invention also provides a method for batch anonymous access authentication of a power edge computing terminal, including:

[0035] Using each edge device that requests to access the same power Internet of Things at the same time to obtain their respective anonymous identity information;

[0036] Through each of the edge devices, calculate their respective signature authentication information based on the pre-configured signature private key;

[0037] Based on the anonymous identity information and signature authentication information of each of the edge devices, integrate the authentication request information of each of the edge devices, and send the authentication request information to the edge device accessing the power Internet of Things;

[0038] Through each of the edge devices, receive the edge authentication request sent by the edge device, and authenticate the identity of the edge device according to the edge authentication request;

[0039] Among them, the edge authentication request is obtained after batch authentication using the batch signature verification algorithm described above. Optionally, the step of calculating, through each of the edge devices, their respective signature authentication information based on the pre-configured signature private key includes:

[0040] Through each of the edge devices, sign their respective anonymous identity information according to the pre-configured signature private key, the obtained private key of each edge device, and the hash function value, to obtain the signature authentication information corresponding to each of the edge devices.

[0041] Optionally, the calculation formula for the signature authentication information corresponding to the edge device is as follows:

[0042]

[0043] Among them, Sig i represents the signature authentication information of the i-th edge device; k i represents the first private key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; sk i represents the signature private key pre-configured for the i-th edge device; r i represents the second private key of the i-th edge device; represents the second encrypted data hash function value of the i-th edge device.

[0044] Optionally, the edge-side authentication request includes one or more of the following: edge-side signature information, signature public key, cloud public key, and timestamp.

[0045] Optionally, authenticating the edge device according to the edge-side authentication request includes:

[0046] Performing a multiplication operation on the edge-side signature information and a pre-set base point to obtain the encrypted signature value of the edge device;

[0047] Performing a multiplication operation on the cloud public key and the pre-calculated encrypted data hash function value of the edge device to obtain the random verification value of the edge device;

[0048] Performing a multiplication operation according to the pre-obtained system public key, timestamp hash function value, and the encrypted data hash function value to obtain the identity verification value of the edge device;

[0049] Performing a summation process on the random verification value, the identity verification value, and the signature public key to obtain the comprehensive verification value of the edge device;

[0050] Authenticating the edge device according to the encrypted signature value and the comprehensive verification value.

[0051] Optionally, the expression corresponding to authenticating the edge device is as follows:

[0052] ESig j P = W j ·h j + PK·h1(EID j , W j )·h j + D j ;

[0053] Among them, ESig j represents the edge-side signature information of edge device j; P represents the base point on the preset elliptic curve; W jRepresents the cloud public key of edge device j; h j Represents the encrypted data hash function value of edge device j; PK represents the system public key; j1(EID j ,W j ) represents the timestamp hash function value regarding the identity identifier EID of edge device j j and cloud public key W j ; D j Represents the signature public key of edge device j.

[0054] Based on the same inventive concept, the present invention also provides a power edge computing terminal batch anonymous access authentication system, including:

[0055] An anonymous identity generation module, configured to use each edge device that requests to access the same power Internet of Things at the same moment to obtain its respective anonymous identity information;

[0056] A signature authentication calculation module, configured to calculate respective signature authentication information by each of the edge devices based on a pre-configured signature private key;

[0057] An authentication request integration module, configured to integrate the authentication request information of each of the edge devices based on the anonymous identity information and signature authentication information of each of the edge devices, and send the authentication request information to the edge device accessing the power Internet of Things;

[0058] A two-way authentication module, configured to receive an edge authentication request sent by the edge device by each of the edge devices, and authenticate the identity of the edge device according to the edge authentication request.

[0059] Optionally, the signature authentication calculation module is specifically configured to:

[0060] Sign the respective anonymous identity information by each of the edge devices according to the pre-configured signature private key, the obtained private key of each edge device, and the hash function value, to obtain the signature authentication information corresponding to each of the edge devices.

[0061] Optionally, the calculation formula for the signature authentication information corresponding to the edge device is as follows:

[0062]

[0063] Wherein, Sig i represents the signature authentication information of the i-th edge device; k i represents the first private key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; sk i represents the pre-configured signature private key of the i-th edge device; r iRepresents the second private key of the i-th edge device; Represents the second encrypted data hash function value of the i-th edge device.

[0064] Optionally, the edge-side authentication request includes one or more of the following: edge-side signature information, signature public key, cloud public key, and timestamp.

[0065] Optionally, the mutual authentication module includes:

[0066] An encryption signature calculation sub-module, configured to perform a multiplication operation based on the edge-side signature information and a preset base point to obtain the encryption signature value of the edge device;

[0067] A random verification calculation sub-module, configured to perform a multiplication operation on the cloud public key and the pre-calculated encrypted data hash function value of the edge device to obtain the random verification value of the edge device;

[0068] An identity authentication calculation sub-module, configured to perform a multiplication operation based on a pre-obtained system public key, a timestamp hash function value, and the encrypted data hash function value to obtain the identity authentication value of the edge device;

[0069] A comprehensive verification calculation sub-module, configured to perform a summation process on the random verification value, the identity authentication value, and the signature public key to obtain the comprehensive verification value of the edge device;

[0070] A reverse authentication sub-module, configured to authenticate the identity of the edge device based on the encryption signature value and the comprehensive verification value.

[0071] Optionally, the expression corresponding to authenticating the identity of the edge device is as follows:

[0072] ESig j P = W j ·g j + PK · h1(EID j , W j ) · h j + D j ;

[0073] Wherein, ESig j represents the edge-side signature information of edge device j; P represents a preset base point on the elliptic curve; Wj j represents the cloud public key of edge device j; h j represents the encrypted data hash function value of edge device j; PK represents the system public key; h1(EID j , Wj j ) represents the identity identifier EID of edge device j j and the cloud public key Wj jThe timestamp hash function value of D j Represents the signature public key of the edge device j.

[0074] Based on the same inventive concept, the present invention also provides a power edge computing terminal batch anonymous access authentication system, including: end-side devices and edge-side devices accessing the same power Internet of Things;

[0075] The edge-side device is used to implement a power edge computing terminal batch anonymous access authentication method as described above;

[0076] The end-side device is used to implement a power edge computing terminal batch anonymous access authentication method as described above.

[0077] On the other hand, the present invention also provides an electronic device, including: at least one processor and a memory; the memory and the processor are connected by a bus;

[0078] The memory is used to store one or more programs;

[0079] When the one or more programs are executed by the at least one processor, a power edge computing terminal batch anonymous access authentication method as described above is implemented.

[0080] On the other hand, the present invention also provides a computer device-readable storage medium, on which an execution program is stored, and when the execution program is executed, a power edge computing terminal batch anonymous access authentication method as described above is implemented.

[0081] Compared with the prior art, the beneficial effects of the present invention are:

[0082] The present invention provides a power edge computing terminal batch anonymous access authentication method and system, including: the edge-side device receives the authentication request information sent by each end-side device accessing the same power Internet of Things; based on the authentication request information of each end-side device, the batch signature verification algorithm is used to batch authenticate the anonymous identity information of each end-side device to obtain a batch authentication result; when the batch authentication result is passed, the edge-side signature information is generated according to the pre-configured timestamp of the edge-side device; based on the edge-side signature information, the edge-side authentication request is integrated and sent to each end-side device; wherein, the batch signature verification algorithm is implemented based on the bilinear mapping of the elliptic curve and the linear homomorphic property of the hash function; the batch signature verification algorithm used in this application can ensure the validity of each signature and the integrity of the data by using the bilinear mapping of the elliptic curve and the linear homomorphic property of the hash function, and can verify multiple signatures in one operation, greatly reducing the computing load and processing time of the edge-side device. Description of the Drawings

[0083] Figure 1Schematic diagram of the framework process of a method for batch anonymous access authentication of power edge computing terminals at the edge device side provided by the present invention;

[0084] Figure 2 Overall flowchart for anonymous identity verification of a method for batch anonymous access authentication of power edge computing terminals provided by the present invention;

[0085] Figure 3 Schematic diagram of the structural composition of a system for batch anonymous access authentication of power edge computing terminals at the edge device side provided by the present invention;

[0086] Figure 4 Schematic diagram of the process of a method for batch anonymous access authentication of power edge computing terminals at the terminal device side provided by the present invention;

[0087] Figure 5 Schematic diagram of the structural composition of a system for batch anonymous access authentication of power edge computing terminals at the terminal device side provided by the present invention;

[0088] Figure 6 Schematic diagram of the structural composition of a system for batch anonymous access authentication of power edge computing terminals including terminal devices and edge devices provided by the present invention;

[0089] Figure 7 Schematic diagram of the structure of an electronic device provided by the present invention. Detailed implementation manners

[0090] The present invention proposes a method, system, device and medium for batch anonymous access authentication of power edge computing terminals. The following further elaborates on the detailed implementation manners of the present invention with reference to the accompanying drawings.

[0091] Example 1:

[0092] The present invention provides a method for batch anonymous access authentication of power edge computing terminals. The flowchart is as Figure 1 shown and includes:

[0093] Step 1: Use the edge devices accessing the power Internet of Things to receive the authentication request information sent by each terminal device requesting to access the power Internet of Things at the same moment;

[0094] Step 2: Based on the authentication request information sent by each terminal device, use a batch signature verification algorithm to batch authenticate the anonymous identity information of each terminal device to obtain a batch authentication result;

[0095] Step 3: When the batch authentication result is passed, generate edge signature information according to the time stamp of the edge device configured in advance;

[0096] Step 4: Integrate the edge - side authentication request based on the edge - side signature information and send it to each edge - side device;

[0097] Among them, the batch signature verification algorithm is carried out by combining the bilinear mapping of the elliptic curve and the linear homomorphic property of the hash function.

[0098] Generally, before the formal power Internet of Things, edge - side devices or end - side devices need to send device registration requests to the cloud server according to the protocol requirements. When the cloud server allows device registration, it will send corresponding parameter configuration information to the device requesting registration, such as identity information, public - private key pairs, and public parameters. Only devices that have successfully registered can be allowed to access the power Internet of Things system through access authentication and participate in data and service interaction activities in the power Internet of Things. During the data interaction process, data integrity and the correctness of calculation results are ensured by signing and verifying the data. Before verifying the registration request, the cloud server first needs to complete initialization. Specifically, the initialization process of the cloud server can include:

[0099] The cloud initializes public parameters G, q, P, e, PK, h0, h1, h2, h3, h4, h5, C pk , where G represents the elliptic curve base point, q represents the order of the base point G; P ∈ G q represents a base point on the elliptic curve G q ; e is a computable bilinear mapping (that is, it maps points on two elliptic curves to an element in a target group G T ), and can be expressed as e: G×G → G T . h0, h1, h2, h3, h4, h5 are 6 one - way hash functions: h0: G×{0,1} * →{0,1} * , h1: h2: h3: h4:{0,1} * →G, h5: Among them, h5 is a hash function with linear homomorphic properties; represents the multiplicative group of order q; PK = s·P is the system public key, where s ∈ Z q is the private key of the cloud server, and Z q represents the integers of order q. In addition, the cloud server has a public - private key pair for encrypting and decrypting information. Among them, the public key can be expressed as C sk , and the private key can be expressed as C pk , and the cloud server sets the system public parameters as G, q, P, e, PK, h0, h1, h2, h3, h4, h5, C pkAnd broadcast. The above cloud server can construct an efficient, secure, and scalable anonymous authentication and data protection framework by initializing a series of public parameters. For example, by selecting the elliptic curve base point G and its order q and combining with the bilinear mapping e, advanced cryptographic operations (such as aggregate signature verification) can be achieved to ensure the credibility and integrity of the data source. Secondly, multiple one-way hash functions (such as h0, h1, h2, h3, h4, h5) are introduced, especially h5 with linear homomorphic properties, which support batch verification and efficient aggregation of encrypted data, can reduce the computational and communication overheads. The system public key PK is generated by the cloud server private key s and the base point P, which can ensure the security and uniqueness of the key. At the same time, through the anonymous identity generation mechanism of the edge device, the user identity privacy is protected. In addition, the cloud server has an independent encryption public and private key pair C sk and C pk , which are used to protect sensitive information during device registration and communication processes. Therefore, initializing the cloud server before the registration request can ensure the confidentiality, integrity, and correctness of the data during transmission and calculation, which is especially suitable for scenarios such as large-scale device access and data interaction in the power Internet of Things.

[0100] After the cloud server initialization is completed, it can accept the registration request of the edge device. The registration request information sent by the edge device to the cloud server through the secure channel can include: the serial number of the edge device and the pre-configured security credentials. The cloud server verifies the identity of the edge device through the request information. After successful verification, the cloud server records the registration information of the edge device. The registration information usually includes the hardware specifications, software version, geographical location, etc. of the edge device to realize the management of the edge device. The cloud server randomly selects an integer to calculate the corresponding scalar multiplication public key: W j =w j ·P. This scalar multiplication public key represents the public key generated by the scalar multiplication of w j on the base point P of the elliptic curve G, which is equivalent to the public elliptic curve point and is used in the identity authentication process. Among them, represents the multiplicative group of order q; the edge device generates private key information: Esk j =w j +s·h1(EID j ,W j ); where s represents the cloud server private key; h1 represents the hash function, which can be expressed as h1: EID j represents the unique device identification code of edge device j. The cloud server sends {Esk j ,W j} to edge device j through the secure channel; after the edge device registration is successful, it sets its private key to Esk j, the public key is W j , establish a continuous communication channel with the cloud server to access the power Internet of Things system. During this process, by effectively verifying the identity of the edge devices by the cloud server, the cloud server can accurately identify and verify the identity of each device, preventing unauthorized or malicious devices from accessing the system. This identity verification mechanism helps to enhance the security of the system, avoid potential security risks, and the cloud server adopts a public key generation and private key distribution mechanism based on elliptic curves during the verification process, ensuring the security and uniqueness of the keys. By randomly selecting an integer w j and calculating the scalar multiplication public key W j , the dynamic generation of the public key is realized. This mechanism not only enhances the security of the key but also reduces the risk of the key being attacked and cracked, establishing a secure channel for communication between devices; after the edge device is registered, its own private key Esk j and public key W j are successfully generated, providing a continuous and reliable communication channel for accessing the power Internet of Things system. Through the key exchange and communication establishment with the cloud server, the edge device can securely transmit data, receive instructions, and participate in the entire power Internet of Things ecosystem, realizing real-time monitoring and management, which improves the response ability and flexibility of the system.

[0101] Through the above steps, the edge device is successfully registered and accessed to the power Internet of Things. Subsequently, it is necessary to perform efficient anonymous identity authentication on a large number of end devices. And in order to cope with the computing and communication overhead brought by the large-scale access of end devices, an authentication mechanism based on a batch signature verification algorithm can be considered. By aggregating the authentication request information and signature authentication information of each end device and utilizing the characteristics of elliptic curve cryptography, the batch verification of the anonymous identities of multiple end devices is realized. Specifically:

[0102] In one implementation, the process of batch authenticating the anonymous identity information of each end device by using the batch signature verification algorithm based on the authentication request information sent by each end device in step 2 above may include:

[0103] Perform a product operation according to the authentication request information of each end device and a pre-set base point to obtain the aggregated verification information value of each end device;

[0104] Perform a summation operation according to the signature authentication information of each end device to obtain the signature verification information value of each end device;

[0105] According to the aggregated verification information value and the signature verification information value, use the batch signature verification algorithm to batch authenticate the anonymous identity information of each end device to obtain a batch authentication result;

[0106] In this implementation, batch authentication of the anonymous identity information of end-side devices is performed through a batch signature verification algorithm, which can significantly improve the authentication efficiency and reduce the computational and communication overheads, especially suitable for scenarios with large-scale device access such as the power Internet of Things. First, in this implementation, an aggregated verification information value is generated through a product operation, which can integrate the authentication information of multiple devices into a unified verification point, reducing the number of verifications. Second, a signature verification information value is obtained through a summation operation, which can further simplify the verification process. Finally, the batch signature verification algorithm is used to compare the aggregated verification information value and the signature verification information value, which can ensure the accuracy and reliability of the authentication result. This mechanism not only improves the authentication efficiency but also protects the privacy of end-side devices through anonymous identities, enhancing the security of the system. In this implementation, although elliptic curve cryptography, hash functions, and batch signature verification algorithms themselves are existing technologies, the combined application of these technologies in batch anonymous authentication in the power Internet of Things scenario can solve the efficiency and security problems brought by large-scale device access, realizing efficient and privacy-protected authentication. Second, in this implementation, by introducing linear homomorphic hash functions and bilinear mappings, batch verification and efficient aggregation of encrypted data are supported, and this design is not widely applied in existing technologies. Therefore, efficient and secure batch authentication can be achieved through this implementation.

[0107] For example, the corresponding expression of the above batch signature verification algorithm can be as follows:

[0108]

[0109] In the formula,

[0110]

[0111] Among them, Sig i represents the signature authentication information of the i-th end-side device; i = 1…n; n represents the total number of end-side devices accessing the power Internet of Things; P represents the base point on a preset elliptic curve; L i represents the aggregated verification information value of the i-th end-side device; K i represents the first signature public key of the i-th end-side device; represents the first encrypted data hash function value of the i-th end-side device; U i represents the second signature public key of the i-th end-side device; represents the second encrypted data hash function value of the i-th end-side device; h 2i represents the data type hash function value of the i-th end-side device; PK represents the system public key; R iIt represents the third signature public key of the i-th edge device. If this formula holds, it means that the n devices requesting access are all legitimate, and the access requests of these n devices are allowed. If the formula does not hold, it indicates that there are illegal devices among these n devices. At this time, the edge device needs to verify the edge devices one by one, and only allow the access requests of the edge devices that pass the verification. For all edge devices that pass the authentication, the edge device increases their reputation values. For devices that fail the anonymous access authentication, the edge device reduces their reputation values and updates their reputation attributes. In this example, by introducing multiple hash functions and a dynamic reputation mechanism, the security and flexibility in the authentication process can be enhanced, the real-time monitoring and evaluation of device behaviors can be achieved, and malicious devices can be effectively identified and isolated.

[0112] After the access authentication is successful, the edge device regularly checks the security status information of the edge devices, including security patches, locations, etc. Continuously monitor and record the relevant information requested by the edge devices, including the identity authentication of the edge devices, the network traffic requested, etc., and analyze this information to detect and evaluate the access requests of the edge devices in real time. If any abnormality is found, disconnect the access to the edge device, reduce the reputation value of the edge device, and update its reputation attribute to ensure that each access of the edge device complies with the system security policy, promptly prevent the occurrence of malicious behaviors, and adapt to the changing network environment in the power Internet of Things system.

[0113] In summary, aiming at the problems faced by identity authentication in the power IoT edge fusion environment, such as the high overhead of existing authentication schemes and the problem that the anonymous identity information of edge devices needs to be sent to the edge device in advance, the present invention proposes a method for batch anonymous access authentication of power edge computing terminals. Driven by the business scenarios of the power Internet of Things, this method takes into account the requirements of data fusion computing and privacy protection, and can achieve efficient batch anonymous authentication of edge devices, ensuring the confidentiality, source credibility, and computational correctness during the data interaction process, and is applicable to the data fusion computing scenario on the edge side of the power Internet of Things. The present invention realizes efficient and batch anonymous access authentication by making full use of the cloud private key information to construct the signature private keys of edge devices and edge devices and combining elliptic curve cryptography. In addition, by constructing a bilinear mapping signature scheme and using a linear homomorphic hash function, the verification of the source, integrity, and computational correctness of the cloud-edge-edge interaction data is further realized. Therefore, the method proposed by the present invention can not only solve the deficiencies of existing authentication schemes in terms of high overhead, privacy leakage, and low verification efficiency, but also improve the security and operation efficiency of the power Internet of Things through anonymous identity protection, batch authentication mechanism, and efficient verification means.

[0114] Embodiment 2:

[0115] Based on the same inventive concept, the present invention also provides a batch anonymous access authentication system for power edge computing terminals. The schematic structural composition is as shown in Figure 3 and includes:

[0116] A request information receiving module, which is used to utilize edge devices accessing the power Internet of Things to receive authentication request information sent by each end-side device requesting to access the power Internet of Things at the same moment;

[0117] A batch identity authentication module, which is used to batch authenticate the anonymous identity information of each end-side device based on the authentication request information sent by each end-side device by using a batch signature verification algorithm to obtain a batch authentication result;

[0118] A signature information generation module, which is used to generate edge signature information according to the time stamp of the edge device pre-configured when the batch authentication result is passed;

[0119] A data integration module, which is used to integrate edge authentication requests and send them to each end-side device based on the edge signature information;

[0120] Among them, the batch signature verification algorithm is carried out by combining the bilinear mapping of the elliptic curve and the linear homomorphic property of the hash function.

[0121] In one implementation manner, the above batch identity authentication module may include:

[0122] An aggregation verification sub-module, which is used to perform a product operation according to the authentication request information of each end-side device and a pre-set base point to obtain an aggregation verification information value of each end-side device;

[0123] A signature verification sub-module, which is used to perform a summation operation according to the signature authentication information of each end-side device to obtain a signature verification information value of each end-side device;

[0124] A batch authentication sub-module, which is used to batch authenticate the anonymous identity information of each end-side device according to the aggregation verification information value and the signature verification information value by using a batch signature verification algorithm to obtain a batch authentication result.

[0125] Exemplarily, the expression corresponding to the above batch signature verification algorithm may be as follows:

[0126]

[0127] In the formula,

[0128]

[0129] Among them, Sig iDenote the signature authentication information of the i-th edge device; i = 1…n; n represents the total number of edge devices accessing the power Internet of Things; P represents the base point on the preset elliptic curve; L i Denote the aggregated verification information value of the i-th edge device; K i Denote the first signature public key of the i-th edge device; Denote the first encrypted data hash function value of the i-th edge device; U i Denote the second signature public key of the i-th edge device; Denote the second encrypted data hash function value of the i-th edge device; h 2i Denote the data type hash function value of the i-th edge device; PK represents the system public key; R i Denote the third signature public key of the i-th edge device.

[0130] Embodiment 3:

[0131] Based on the same inventive concept, the present invention also provides a method for batch anonymous access authentication of a power edge computing terminal. The process schematic diagram is as Figure 4 shown, including:

[0132] Step S1: Use each edge device that requests to access the same power Internet of Things at the same moment to obtain its respective anonymous identity information;

[0133] Step S2: Through each of the edge devices, calculate their respective signature authentication information based on the pre-configured signature private key;

[0134] Step S3: Based on the anonymous identity information and signature authentication information of each of the edge devices, integrate the authentication request information of each of the edge devices, and send the authentication request information to the edge device accessing the power Internet of Things;

[0135] Step S4: Through each of the edge devices, receive the edge authentication request sent by the edge device, and perform identity authentication on the edge device according to the edge authentication request;

[0136] Among them, the edge authentication request is obtained after batch authentication using the batch signature verification algorithm as described above.

[0137] Generally, in order to protect their own identity privacy, before device registration in the above-mentioned step S1, each edge device first needs to generate anonymous identity information using its own private key and the cloud public key, and send a registration request to the cloud server using the anonymous identity information. After successful registration, the edge device sends an access request to the edge device using its own anonymous identity information and signature information. The edge device uses the received anonymous identity information and signature information to perform batch anonymous access authentication on the edge device requesting access, alleviating the computational overhead generated during the access of a large number of terminals. Through this method, the edge device generates its own anonymous identity information, and the edge uses anonymous identities throughout the communication process, solving the security threats brought by the edge device using its real identity for registration in the existing solution, ensuring that only the cloud server can obtain the real identity information of the edge device during the entire registration and access process, and introducing a timestamp parameter in the generation of anonymous identity information (for example, it can be represented by T i ), effectively preventing attackers from intercepting the anonymous identity of an edge device during a registration request and using this anonymous identity to request device registration from the cloud.

[0138] After the edge device registration is successful, the edge device needs to accept the registration authentication of the cloud server. Specifically, the registration process of the edge device can include:

[0139] The edge device has pre-configured public key information SM sk (for decryption and signature) and private key information SM pk (for encryption and verification). The edge device i randomly selects an integer: is the multiplicative group of order q of the elliptic curve, and calculates the corresponding scalar multiplication public key: K i = k i ·P, where this scalar multiplication public key K i represents the public key generated by performing scalar multiplication on the base point P on the elliptic curve with k i ; k i is used as its own partial private key, and K i is used as its own partial public key. Using its own real identity information ID i ∈{0,1} * calculate the anonymous identity information: represents the exclusive OR operation; PK represents the system public key; T i represents the timestamp of the edge device i; h0 represents G×{0,1} * →{0,1} * ; G represents the base point of the elliptic curve. The edge device i encrypts the request information using the cloud's encryption public key C pk , including the anonymous identity information FID of the edge device ii , K i , T i , SM pk , and the pre-configured security credentials, send the encrypted request information to the edge device, which forwards it to the cloud server. The cloud server uses the private key C sk to decrypt the request information, and then restores the true identity of the end device i s represents the private key of the cloud server. Then, according to the pre-configured security credentials, judge whether the device is legal. After passing the verification, record the registration information of the end device, and randomly select an integer represents the multiplicative group of order q of the base point G, and calculate the corresponding scalar multiplication public key: U i = u i · P, and use the cloud server private key s to generate the partial private key for signing for the end device: sk i = u i + s · h2(FID i , U i , K i ), h2 represents the hash function {0,1} * × G × The cloud server records the true identity, anonymous identity, hardware specifications, software version, geographical location, etc. of the end device. The cloud server uses SM pk to encrypt {sk i , U i}, and send the encrypted result to the edge device, which forwards it to the end device i. After the end device obtains the response information sent by the cloud server, it first uses SM sk to decrypt to obtain {sk i , U i}. The end device i sets its signature private key as (k i , sk i ), and the signature public key as (K i , U i ); In this process, the anonymous identity information FID i is generated at the end side. The true identity information of the end device is effectively protected during the transmission process, avoiding the risk of identity information leakage and enhancing the privacy of the system. Secondly, use the cloud private key s and elliptic curve cryptography technology to generate the partial private key sk of the end device i, which can ensure the security and uniqueness of the secret key and prevent the secret key from being forged or tampered with. In addition, by verifying and recording the registration information of the edge devices through the cloud, the credibility and legality of the device identity are ensured, providing a reliable data basis for subsequent batch anonymous authentication. This process not only realizes the anonymous registration of edge devices but also protects the security of data transmission through encryption and signature mechanisms, providing strong support for large-scale device access and efficient authentication in the power Internet of Things system; in the above-mentioned edge device registration process, although the XOR operation and hash function are existing technologies, their combined application in generating the anonymous identity of edge devices, especially in combination with the cloud public key PK and timestamp T i , realizes the anonymization and dynamicization of the edge device identity, and this design has no clear application in the existing technology; and the partial private key sk of the edge device is generated through the cloud private key s and hash function h2 i , which can ensure the security and uniqueness of the secret key. This secret key generation mechanism combines the joint participation of the cloud and the device side, avoids single-point failures, protects the security of data transmission during the registration process, and at the same time ensures the credibility of the device identity through effective verification of the device identity by the cloud, which can further enhance the security of the power Internet of Things system.

[0140] After the edge devices successfully register and obtain anonymous identity information, it is necessary to further authenticate the identities of these devices efficiently and securely. To achieve this goal, the edge devices can generate their respective signature authentication information based on the pre-configured signature private key, combined with the hash function value and private key information. Specifically:

[0141] In one implementation, the process of calculating the respective signature authentication information by the above-mentioned each edge device based on the pre-configured signature private key in step S2 may include:

[0142] Each of the edge devices signs its anonymous identity information according to the pre-configured signature private key, the obtained private key of each edge device, and the hash function value, to obtain the signature authentication information corresponding to each edge device.

[0143] Exemplarily, the calculation formula corresponding to the signature authentication information of the above-mentioned edge device may be as follows:

[0144]

[0145] Among them, Sig i represents the signature authentication information of the i-th edge device; k i represents the first private key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; sk i represents the pre-configured signature private key of the i-th edge device; ri Denote the second private key of the i-th edge device; Denote the second encrypted data hash function value of the i-th edge device; In this example, by calculating the signature authentication information of the edge device through the above calculation formula, it can ensure that the identity information of each edge device is protected during the transmission and authentication process, preventing identity forgery and data tampering. At the same time, the generation process of the signature authentication information combines the characteristics of elliptic curve cryptography and hash functions, enhancing the uniqueness and security of the signature. It can not only improve the authentication efficiency, but also protect the privacy of the edge device through anonymous identity, ensuring the integrity and credibility during the data interaction process; and by combining anonymous identity information and hash function and it can achieve efficient and secure signature generation, effectively preventing replay attacks and signature forgery.

[0146] Through the above implementation method, signature authentication information can be generated, and these signature information can be further verified efficiently and securely to ensure the identity legality of the edge device and the integrity of the data. To achieve this goal, the edge device can batch verify the identity of the edge device based on the received signature authentication information, signature public key, and hash function value. Specifically:

[0147] In one implementation, the process of integrating the authentication request information of each edge device based on the anonymous identity information and signature authentication information of each edge device in step S3 above and sending the authentication request information to the edge device accessing the power Internet of Things (that is, the edge device requests to access the edge device) may include:

[0148] The edge device i sets its signature private key as (k i , sk i ), and the signature public key as (K i , U i ). Randomly select an integer is the multiplicative group of the q-order of the elliptic curve; Calculate the corresponding scalar multiplication public key: R i =r i ·P, generate the timestamp T i and calculate and where P represents the base point on the elliptic curve G; Denote the calculation result of the hash function h3 with respect to (FID i , R i , K i , T i ), FID i represents the identity identification information of the edge device i, R i represents the integer r iThe corresponding scalar multiplication public key, K i represents the partial public key of the edge device i, and h3 represents a hash function satisfying h3: represents the calculation result of the hash function h3 with respect to (FID i , R i , U i , T i ). Then the edge device calculates the signature authentication information and sends {R i , U i , K i , Sig i , FID i , T i} to the edge device. The edge device receives the access request information {R i , U i , K i , Sig i , FID i , T i} sent by the edge device. First, the edge device checks the stored edge device list according to the identity information FID of the edge device i i . If the edge device does not exist in the list, the edge device stores the anonymous identity and public key (K i , U i ) of the edge device, and initializes its reputation attribute and reputation value to implement a zero-trust-based authentication mechanism. The reputation attribute is related to the set threshold. When the reputation value is greater than the threshold, the reputation attribute is set to "trusted", otherwise it is "untrusted". The edge device performs reputation assessment based on each request information and interaction activity with the edge device. As the number of interactions between the edge device and the edge device increases, the reputation attribute and reputation value of the device are continuously updated. If the edge device exists in the edge device list, the edge device checks its reputation attribute and reputation value according to the anonymous identity information of the requesting device. If the reputation attribute of the device is "untrusted", the edge device directly rejects the access of the device, reducing the computing resources required for anonymous access authentication. If the reputation attribute of the device is "trusted", anonymous access authentication is performed. If the reputation attribute of the edge device is "trusted" or the edge device does not exist in the device list, the edge device performs anonymous access authentication on it. First, it checks the timestamp to verify whether the request has expired. If the request has expired, the edge device rejects the access request of the edge device. After the timestamp check passes, the edge device calculates h 2i = h2(FID i , U i , K i ), and The edge device judges the equation Whether it holds to achieve anonymous access authentication for the end - side device. After successful authentication, the edge - side device stores the FID i and the corresponding public key (K i ,U i ). In addition, the edge - side device can determine whether the equation holds to achieve batch anonymous access authentication for n end - side devices requesting access at the same time; where h2 represents the hash function h2: Since the cloud generates anonymous identities and signature private keys for end - side devices, it uses the private key of the cloud server. By using the point - multiplication operation of the elliptic curve, the cloud private key is converted into the system public key, so that before anonymous access authentication, the edge - side device does not need to pre - store the anonymous identity information of registered end - side devices, reducing the communication overhead required for anonymous access authentication and improving the authentication efficiency. After the edge - side device passes the authentication, the edge - side device randomly selects an integer: Calculate the corresponding scalar - multiplication public key: D j = d j ·P, generate a timestamp T j , calculate h j = h3(EID j ,D j ,W j ,T j ), where EID j represents the identity - identification information of edge - side device j; W j represents the scalar - multiplication public key corresponding to w j ; then generate the signature information: ESig j = Esk j ·h j + d j , and the edge - side device sends {D j ,W j ,ESig j ,EID j ,T j} as the authentication request information to end - side device i. The end - side device determines whether the formula ESig j P = W j ·h j + PK·h1(EID j ,Wj j )·h j + D j holds to achieve authentication of the edge - side device, where h1 represents the hash function h1: The overall process of end - side device registration and anonymous access is as Figure 2As shown, after the authentication notice, the terminal device will interact with the edge device in the next step; otherwise, the terminal device will terminate the interaction with the edge device.

[0149] In this implementation, the terminal device generates the signature authentication information Sig j , and by combining the timestamp and the hash function value, the uniqueness and dynamic security of the signature information can be ensured. The edge device judges the legitimacy of the terminal device by verifying the signature authentication information and the timestamp, and can achieve efficient batch authentication of multiple terminal devices through the batch verification formula; in addition, a zero-trust mechanism based on the reputation value is introduced in this implementation. By dynamically updating the device reputation attributes and reputation values, malicious devices can be effectively identified and isolated, enhancing the security and credibility of the system.

[0150] In one implementation, the process of authenticating the edge device according to the edge authentication request in step S4 above may include:

[0151] Perform a multiplication operation based on the edge signature information and a preset base point to obtain the encrypted signature value of the edge device;

[0152] Perform a multiplication operation on the cloud public key and the pre-calculated encrypted data hash function value of the edge device to obtain the random verification value of the edge device;

[0153] Perform a multiplication operation based on the pre-obtained system public key, timestamp hash function value, and the encrypted data hash function value to obtain the identity verification value of the edge device;

[0154] Sum up the random verification value, the identity verification value, and the signature public key to obtain the comprehensive verification value of the edge device;

[0155] Authenticate the edge device according to the encrypted signature value and the comprehensive verification value.

[0156] Exemplarily, the above edge authentication request may include one or more of the following: edge signature information, signature public key, cloud public key, and timestamp;

[0157] Exemplarily, the expression corresponding to authenticating the edge device may be as follows:

[0158] ESig j P = W j ·h j + PK·h1(EID j , W j )·h j + D j ;

[0159] Among them, ESig j represents the edge-side signature information of edge-side device j; P represents the base point on a preset elliptic curve; W j represents the cloud public key of edge-side device j; h j represents the encrypted data hash function value of edge-side device j; PK represents the system public key; h1(EID j , W j ) represents the timestamp hash function value with respect to the identity identifier EID j of edge-side device j and the cloud public key W j ; D j represents the signature public key of edge-side device j; in this example, based on the signature information, system public key, cloud public key, and hash function of the edge-side device, the edge-side device is authenticated. This process can ensure the identity legality of the edge-side device, enhance the dynamic security of identity authentication, effectively prevent replay attacks and identity forgery. In addition, through the characteristics of elliptic curve cryptography, efficient identity authentication is achieved, reducing the computational and communication overhead. This mechanism provides reliable security guarantees for device access in the power Internet of Things, ensures the integrity and credibility in the data interaction process, and improves the overall performance of the system through an efficient authentication process.

[0160] Therefore, when the present invention performs batch anonymous access authentication on the end-side device, that is, before the end-side device registers, it first generates anonymous identity information using its own private key and the cloud public key, and sends a registration request to the cloud server using the anonymous information, so that the real identity of the end-side device is not transmitted in the network, solving the security threats brought by the end-side device using its real identity for registration in the existing solution. By using batch anonymous access authentication, the computational overhead generated during the access of a large number of terminals is alleviated. Through this method, the end-side generates its own anonymous identity, and the end uses the anonymous identity throughout the communication process, solving the security threats brought by the end-side device using its real identity for registration in the existing solution, ensuring that only the cloud side can obtain the real identity information of the end-side during the entire registration access process, and introducing a timestamp parameter in the generation of anonymous identity, effectively preventing an attacker from intercepting the anonymous identity when a certain end-side device requests registration and using this anonymous identity to request device registration from the cloud.

[0161] In addition, fault diagnosis is an important service in the power Internet of Things system. This application can also, through the edge computing capabilities of the fusion terminal, perform real-time perception and monitoring of the key parameter information of various devices, timely detect fault problems existing in the power grid, quickly locate the fault location, and analyze and evaluate the fault cause, fault impact, severity, etc. Alarm information is generated according to the evaluation results, enabling operation and maintenance personnel to promptly grasp the fault conditions of the power equipment in the substation area, carry out maintenance work, and ensure the normal operation of the power Internet of Things system. For example, the main process of using the framework proposed in the present invention for fault diagnosis services is as follows:

[0162] When the end-side devices and edge-side devices are connected to the power Internet of Things system, the cloud server will authenticate the access of the edge-side devices to ensure the credibility of the edge-side devices connected to the system, and the edge-side devices that have already been connected to the system will perform anonymous access authentication on the end-side devices to ensure that all the end-side devices connected to the system are credible. Through the access authentication of various devices, it is ensured that the identities of all participating devices are credible throughout the process during fault diagnosis, preventing malicious participants from disguising as false end-side devices or edge-side devices and sending malicious data, and ensuring the normal progress of the fault diagnosis service.

[0163] On the end side, various devices such as sensors, smart meters, and programmable logic controllers in the power system collect the operation data of the power grid in real time, including key parameters such as voltage, current, power, frequency, and temperature. The end-side devices perform local preprocessing on these key parameters collected, determine the type of the collected parameters, perform data normalization processing according to the parameter type, perform local homomorphic encryption on the preprocessed data, and sign the encrypted result. The homomorphic encryption result and the signature result are sent to the edge-side devices through data transmission devices such as optical fibers and cables.

[0164] On the edge side, when the edge-side server receives the encrypted collected data sent by the end-side devices, it first verifies the signature information to ensure the integrity of the data and the credibility of the source, and ensures that the data has not been tampered with by malicious attackers during the transmission process.

[0165] Embodiment 4:

[0166] Based on the same inventive concept, the present invention also provides a power edge computing terminal batch anonymous access authentication system. The schematic structural composition diagram is as Figure 5 shown, including:

[0167] An anonymous identity generation module, which is used to utilize each end-side device that requests to access the same power Internet of Things at the same moment to obtain their respective anonymous identity information;

[0168] A signature authentication calculation module, which is used to calculate their respective signature authentication information by each of the end-side devices based on the pre-configured signature private key;

[0169] An authentication request integration module, configured to integrate the authentication request information of each end - side device based on the anonymous identity information and signature authentication information of each end - side device, and send the authentication request information to the edge - side device accessing the power Internet of Things;

[0170] A two - way authentication module, configured to receive the edge - side authentication request sent by the edge - side device through each end - side device, and perform identity authentication on the edge - side device according to the edge - side authentication request.

[0171] In one implementation, the above - mentioned signature authentication calculation module may specifically be used for:

[0172] Each end - side device signs its own anonymous identity information according to the pre - configured signature private key, the obtained private key of each end - side device, and the hash function value, to obtain the signature authentication information corresponding to each end - side device.

[0173] Exemplarily, the calculation formula for the signature authentication information corresponding to the above - mentioned end - side device may be as follows:

[0174]

[0175] where Sig i represents the signature authentication information of the i - th end - side device; k i represents the first private key of the i - th end - side device; represents the first encrypted data hash function value of the i - th end - side device; sk i represents the pre - configured signature private key of the i - th end - side device; r i represents the second private key of the i - th end - side device; represents the second encrypted data hash function value of the i - th end - side device.

[0176] Exemplarily, the above - mentioned edge - side authentication request may include one or more of the following: edge - side signature information, signature public key, cloud public key, and timestamp.

[0177] In one implementation, the above - mentioned two - way authentication module may include:

[0178] An encrypted signature calculation sub - module, configured to perform a multiplication operation according to the edge - side signature information and a pre - set base point to obtain the encrypted signature value of the edge - side device;

[0179] A random verification calculation sub - module, configured to perform a multiplication operation on the cloud public key and the pre - calculated encrypted data hash function value of the edge - side device to obtain the random verification value of the edge - side device;

[0180] An authentication calculation sub-module for performing a product operation based on a pre-acquired system public key, a timestamp hash function value, and the encrypted data hash function value to obtain an authentication value of the edge device;

[0181] An integrated verification calculation sub-module for performing a summation process on the random verification value, the authentication value, and the signature public key to obtain an integrated verification value of the edge device;

[0182] A reverse authentication sub-module for authenticating the identity of the edge device according to the encrypted signature value and the integrated verification value.

[0183] Exemplarily, the expression corresponding to the authentication of the edge device can be as follows:

[0184] ESig j P = W j ·h j + PK·h1(EID j , W j )·h j + D j ;

[0185] Wherein, ESig j represents the edge signature information of edge device j; P represents the base point on a preset elliptic curve; W j represents the cloud public key of edge device j; h j represents the encrypted data hash function value of edge device j; PK represents the system public key; h1(EID j , W j ) represents the timestamp hash function value with respect to the identity identifier EID j of edge device j and the cloud public key W j ; D j represents the signature public key of edge device j.

[0186] Embodiment 5:

[0187] Based on the same inventive concept, the present invention also provides a power edge computing terminal batch anonymous access authentication system, the structural schematic diagram of which is as shown in Figure 6 and includes: end-side devices and edge devices accessing the same power Internet of Things;

[0188] The edge device is used to implement a power edge computing terminal batch anonymous access authentication method as described above;

[0189] The end-side device is used to implement a power edge computing terminal batch anonymous access authentication method as described above.

[0190] Embodiment 6:

[0191] As Figure 7 shown, the present invention also provides an electronic device, which may be a computer device, a single-chip microcomputer device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, the processor, and the transceiver component are connected through a bus; the memory can be used to store an execution program, and an exemplary execution program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, and the data can be called and / or modified when the instructions are executed.

[0192] The processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of a method for batch anonymous access authentication of a power edge computing terminal in the above embodiment.

[0193] Embodiment 7:

[0194] Based on the same inventive concept, the present invention also provides a readable storage medium, specifically an electronic device-readable storage medium (Memory). The electronic device-readable storage medium is a memory device in the electronic device and is used to store programs and data. It can be understood that the storage medium here can include both the built-in storage medium in the electronic device and, of course, the extended storage medium supported by the electronic device. The storage medium provides a storage space, and the operating system of the terminal is stored in this storage space. And, one or more instructions suitable for being loaded and executed by the processor are also stored in this storage space. These instructions can be one or more execution programs (including program codes). It should be noted that the storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. By loading and executing one or more instructions stored in the storage medium by the processor, the steps of a method for batch anonymous access authentication of a power edge computing terminal in the above embodiment can be implemented.

[0195] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0196] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0197] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0198] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0199] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit the scope of its protection. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that after reading the present invention, various changes, modifications, or equivalent replacements can still be made to the specific implementation manners of the application. However, these changes, modifications, or equivalent replacements are all within the scope of the protection of the claims pending for approval of the application.

Claims

1. A method for batch anonymous access authentication of power edge computing terminals, characterized in that, including: using edge devices connected to the power Internet of Things to receive authentication request information sent by each end device requesting to access the power Internet of Things at the same moment; based on the authentication request information sent by each end device, using a batch signature verification algorithm to batch authenticate the anonymous identity information of each end device to obtain a batch authentication result; when the batch authentication result is passed, generating edge signature information according to the timestamp of the edge device preconfigured; integrating the edge authentication request based on the edge signature information and sending it to each end device; wherein, the batch signature verification algorithm is carried out by combining the bilinear mapping of the elliptic curve and the linear homomorphism property of the hash function.

2. The method according to claim 1, characterized in that, The step of using a batch signature verification algorithm to batch authenticate the anonymous identity information of each end device based on the authentication request information sent by each end device to obtain a batch authentication result includes: performing a product operation according to the authentication request information of each end device and a pre-set base point to obtain an aggregated verification information value of each end device; performing a summation operation according to the signature authentication information of each end device to obtain a signature verification information value of each end device; using the batch signature verification algorithm to batch authenticate the anonymous identity information of each end device according to the aggregated verification information value and the signature verification information value to obtain a batch authentication result.

3. The method according to claim 2, wherein The corresponding expression of the batch signature verification algorithm is as follows: wherein, Among them, Sig i represents the signature authentication information of the i-th edge device; i = 1…n; n represents the total number of edge devices accessing the power Internet of Things; P represents the base point on the preset elliptic curve; L i represents the aggregated verification information value of the i-th edge device; K i represents the first signature public key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; U i represents the second signature public key of the i-th edge device; represents the second encrypted data hash function value of the i-th edge device; h 2i represents the data type hash function value of the i-th edge device; PK represents the system public key; R i represents the third signature public key of the i-th edge device.

4. A batch anonymous access authentication system for power edge computing terminals, characterized in that, including: a request information receiving module, configured to use edge devices connected to the power Internet of Things to receive authentication request information sent by each end device requesting to access the power Internet of Things at the same moment; a batch identity authentication module, configured to use a batch signature verification algorithm to batch authenticate the anonymous identity information of each end device based on the authentication request information sent by each end device to obtain a batch authentication result; a signature information generating module, configured to generate edge signature information according to the timestamp of the edge device preconfigured when the batch authentication result is passed; a data integration module, configured to integrate the edge authentication request based on the edge signature information and send it to each end device; wherein, the batch signature verification algorithm is carried out by combining the bilinear mapping of the elliptic curve and the linear homomorphism property of the hash function.

5. The system according to claim 4, wherein The batch identity authentication module includes: an aggregated verification sub-module, configured to perform a product operation according to the authentication request information of each end device and a pre-set base point to obtain an aggregated verification information value of each end device; a signature verification sub-module, configured to perform a summation operation according to the signature authentication information of each end device to obtain a signature verification information value of each end device; a batch authentication sub-module, configured to use the batch signature verification algorithm to batch authenticate the anonymous identity information of each end device according to the aggregated verification information value and the signature verification information value to obtain a batch authentication result.

6. The system according to claim 5, wherein The corresponding expression of the batch signature verification algorithm is as follows: wherein, Among them, Sig i represents the signature authentication information of the i-th edge device; i = 1…n; n represents the total number of edge devices accessing the power Internet of Things; P i represents the aggregated verification information value of the i-th edge device; K i represents the first signature public key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; U i represents the second signature public key of the i-th edge device; represents the second encrypted data hash function value of the i-th edge device; h 2i represents the data type hash function value of the i-th edge device; PK represents the system public key; R i represents the third signature public key of the i-th edge device.

7. A method for batch anonymous access authentication of power edge computing terminals, characterized in that, including: using each end device that requests to access the same power Internet of Things at the same moment to obtain its own anonymous identity information; Each of the edge devices calculates its own signature authentication information based on a pre-configured signature private key; Based on the anonymous identity information and signature authentication information of each of the edge devices, the authentication request information of each of the edge devices is integrated, and the authentication request information is sent to the edge device accessing the power Internet of Things; Each of the edge devices receives the edge authentication request sent by the edge device, and authenticates the identity of the edge device according to the edge authentication request; Among them, the edge authentication request is obtained after batch authentication using the batch signature verification algorithm in claim 1.

8. The method according to claim 7, wherein The step of each of the edge devices calculating its own signature authentication information based on a pre-configured signature private key includes: Each of the edge devices signs its own anonymous identity information according to the pre-configured signature private key, the obtained private key of each edge device, and the hash function value, to obtain the signature authentication information corresponding to each edge device.

9. The method according to claim 7 or 8, characterized in that, The calculation formula corresponding to the signature authentication information of the edge device is as follows: Among them, Sig i represents the signature authentication information of the i-th edge device; k i represents the first private key of the i-th edge device; represents the first encrypted data hash function value of the i-th edge device; sk i represents the signature private key pre-configured for the i-th edge device; r i represents the second private key of the i-th edge device; represents the second encrypted data hash function value of the i-th edge device.

10. The method according to claim 7, characterized in that, The edge authentication request includes one or more of the following: edge signature information, signature public key, cloud public key, and timestamp.

11. The method according to claim 10, wherein The step of authenticating the identity of the edge device according to the edge authentication request includes: Performing a product operation on the edge signature information and a pre-set base point to obtain the encrypted signature value of the edge device; Performing a product operation on the cloud public key and the pre-calculated encrypted data hash function value of the edge device to obtain the random verification value of the edge device; Performing a product operation according to the pre-obtained system public key, timestamp hash function value, and the encrypted data hash function value to obtain the identity verification value of the edge device; Performing a summation process on the random verification value, the identity verification value, and the signature public key to obtain the comprehensive verification value of the edge device; Authenticating the identity of the edge device according to the encrypted signature value and the comprehensive verification value.

12. The method according to claim 11, wherein The expression corresponding to authenticating the identity of the edge device is as follows: ESig j P = W j ·h j + PK·h1(EID j ,W j )·h j + D j ; Among them, ESig j represents the edge-side signature information of edge-side device j; P represents the base point on the preset elliptic curve; W j represents the cloud public key of edge-side device j; h j represents the encrypted data hash function value of edge-side device j; PK represents the system public key; h1(EID j , W j ) represents the timestamp hash function value regarding the identity identifier EID j of edge-side device j and the cloud public key W j ; D j represents the signature public key of edge-side device j.

13. A batch anonymous access authentication system for power edge computing terminals, characterized in that, Including: An anonymous identity generation module, which is used to use each of the edge devices that request to access the same power Internet of Things at the same time to obtain their respective anonymous identity information; A signature authentication calculation module, which is used to calculate the signature authentication information of each of the edge devices based on a pre-configured signature private key through each of the edge devices; An authentication request integration module, which is used to integrate the authentication request information of each of the edge devices based on the anonymous identity information and signature authentication information of each of the edge devices, and send the authentication request information to the edge device accessing the power Internet of Things; A two-way authentication module, which is used to receive the edge authentication request sent by the edge device through each of the edge devices, and authenticate the identity of the edge device according to the edge authentication request.

14. The system according to claim 13, wherein The signature authentication calculation module is specifically used for: Each of the edge devices signs its own anonymous identity information according to the pre-configured signature private key, the obtained private key of each edge device, and the hash function value, to obtain the signature authentication information corresponding to each edge device.

15. The system according to claim 13, wherein The edge - side authentication request includes one or more of the following: edge - side signature information, signature public key, cloud public key, and timestamp.

16. The system according to claim 15, wherein The two - way authentication module includes: An encrypted signature calculation sub - module, configured to perform a multiplication operation based on the edge - side signature information and a preset base point to obtain the encrypted signature value of the edge - side device; A random verification calculation sub - module, configured to perform a multiplication operation on the cloud public key and the pre - calculated encrypted data hash function value of the edge - side device to obtain the random verification value of the edge - side device; An identity authentication calculation sub - module, configured to perform a multiplication operation based on the pre - obtained system public key, timestamp hash function value, and the encrypted data hash function value to obtain the identity authentication value of the edge - side device; A comprehensive verification calculation sub - module, configured to perform a summation process on the random verification value, the identity authentication value, and the signature public key to obtain the comprehensive verification value of the edge - side device; A reverse authentication sub - module, configured to authenticate the identity of the edge - side device based on the encrypted signature value and the comprehensive verification value.

17. The system according to claim 16, wherein, The expression corresponding to authenticating the identity of the edge - side device is as follows: ESig j P = W j ·h j + PK·h1(EID j ,W j )·h j + D j ; Among them, ESig j represents the edge signature information of edge device j; P represents the base point on the preset elliptic curve; W j represents the cloud public key of edge device j; h j represents the encrypted data hash function value of edge device j; PK represents the system public key; h1(EID j , W j ) represents the timestamp hash function value regarding the identity identifier EID j of edge device j and the cloud public key W j ; S j represents the signature public key of edge device j.

18. A batch anonymous access authentication system for power edge computing terminals, characterized in that, Including: The end - side device and the edge - side device accessing the same power Internet of Things; The edge - side device is used to implement a method for batch anonymous access authentication of a power edge - computing terminal as described in any one of claims 1 - 3; The end - side device is used to implement a method for batch anonymous access authentication of a power edge - computing terminal as described in any one of claims 7 - 12.

19. An electronic device, characterized in that, Including: At least one processor and a memory; The memory and the processor are connected by a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, a method for batch anonymous access authentication of a power edge - computing terminal as described in any one of claims 1 - 3 or any one of claims 7 - 12 is implemented.

20. A computer-readable storage medium, characterized in that, There is an execution program stored thereon, and when the execution program is executed, a method for batch anonymous access authentication of a power edge - computing terminal as described in any one of claims 1 - 3 or any one of claims 7 - 12 is implemented.

Citation Information

Cited By

  • Privacy-protected cloud side-end layered batch data integrity verification method

    CN121217473A