Intelligent electric meter security encryption method and system
Through the smart meter security encryption method of multiple hash verification, digital signature and hardware security module generation key generation, the integrity and security of smart meter data transmission are solved, and data reliability and system security are realized.
Patent Information
- Application Number
- CN202510611379.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-07-18
AI Technical Summary
Smart electric surfaces are facing the hidden dangers of frequent network security vulnerabilities and data security leakage, and the existing technology is difficult to effectively ensure the integrity and security of data transmission.
Multiple hash checksum digital signature technology is adopted, combined with hardware security modules to generate keys, establish key backup and recovery mechanisms, implement two-way identity authentication, and trigger alarm mechanisms during data transmission to ensure data integrity and communication security.
Through multiple hash checksum digital signature technology, we ensure the integrity and reliability of the data transmission process, improve the security of the key and the fault tolerance of the system, prevent illegal equipment from being accessed, and protect user privacy and data security.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of smart meters, and in particular to a smart meter security encryption method and system. Background Art
[0002] A smart meter is one of the important data acquisition devices of the power grid, and needs to complete the tasks of data acquisition, power consumption recording, and data transmission of electric energy. It is an important foundation for realizing the integration of power grid information devices, data analysis, metering optimization, and grid intelligence. In addition to the basic power consumption metering function of traditional electric energy meters, smart meters are connected to the Internet and have multi-directional user terminal control functions and various data transmission capabilities.
[0003] However, due to this characteristic, smart meters are also facing an increasing frequency of network security vulnerabilities, as well as information risks and economic losses that may be brought about by data security leaks and security vulnerabilities. Summary of the Invention
[0004] (1) Technical Problems to be Solved
[0005] In view of the deficiencies of the prior art, the present invention provides a smart meter security encryption method and system, which solves the problems raised in the above background art.
[0006] (2) Technical Solutions
[0007] To achieve the above object, the present invention is realized through the following technical solutions: A smart meter security encryption method and system, including the following steps:
[0008] S1. After the smart meter terminal performs a one-time hash processing on the encrypted data, multiple hash validations are performed at different stages of the data. For example, before data collection and encryption, the original data is first subjected to a SHA-256 hash calculation to obtain an initial hash value, which is stored in the local secure storage area of the meter. Then, during the transmission of the encrypted data, another hash processing is performed to obtain a transmission hash value. After receiving the data, the background control terminal first recalculates the hash value of the decrypted data and compares it with the initial hash value of the meter terminal. If they are the same, it is further compared with the transmission hash value to further ensure the integrity of the data during transmission;
[0009] S2. Perform a digital signature on the generated hash value, encrypt the hash value using the private key of the meter to generate signature information, and send the signed hash value and the encrypted data to the background control terminal. The background control terminal decrypts the signature using the public key of the meter to obtain the original hash value, and then compares it with the hash value calculated by itself to verify the integrity and reliability of the data source;
[0010] S3. Use a hardware security module or a trusted platform module to generate and store the keys required for the chaotic encryption algorithm, ensuring that the key generation process has sufficient randomness and unpredictability;
[0011] S4. Establish a key backup and recovery mechanism. Encrypt the keys and store them in a secure backup server or device, and at the same time back up the encrypted data to a cloud server. Establish a multi-level data backup and recovery system. When needed, backup data can be retrieved from the cloud for recovery, further improving the security and reliability of the data;
[0012] S5. Before the smart meter communicates with the background control terminal, both parties perform identity authentication first;
[0013] S6. When abnormal situations such as data tampering, key leakage, and illegal access are detected, the smart meter and the background control terminal should immediately trigger an alarm mechanism and send an alarm notification to the operation and maintenance personnel of the power company, so that timely measures can be taken for handling to prevent further damage or abuse of the data.
[0014] Preferably, in step S4, a data backup function can also be set locally on the smart meter to regularly back up and store important power consumption data and related parameters. When abnormalities occur or data is lost during data transmission, data can be restored from the local backup to ensure the integrity and continuity of the data.
[0015] Preferably, in step S3, the secret key is updated regularly, and a secure key distribution mechanism is used, such as the Diffie-Hellman key exchange protocol, to ensure the security of the key during the update and distribution process.
[0016] Preferably, in step S4, in the case of a smart meter failure or key loss, through a secure recovery process, the backup key can be used to perform data encryption and decryption operations again to ensure the continuity and availability of the data.
[0017] Preferably, in step S5, the identity authentication method is that the smart meter uses a digital certificate to prove its identity, and the background control terminal confirms its legitimacy by verifying the meter's certificate; the background control terminal sends an authentication request to the meter, and the meter ensures that the server communicating with it is trustworthy by verifying the background certificate, which can prevent illegal devices from accessing the system and data from being tampered with or forged.
[0018] Preferably, for operations that require user participation, such as remotely querying power consumption information and performing remote recharge, a user identity authentication mechanism is established. The user performs identity authentication by entering a username and password, using a dynamic password, or a digital certificate, etc., to ensure that only legitimate users can access and operate the data of the smart meter.
[0019] Preferably, during data transmission, in case of data loss, interruption or timeout, etc., the smart meter and the back-end control terminal should have corresponding processing mechanisms. For example, the smart meter can automatically retransmit the data, and the back-end control terminal can send a data request instruction to require the meter to retransmit the data to ensure the integrity and continuity of the data.
[0020] A smart meter security encryption system is applied to the above-mentioned smart meter security encryption method, and is characterized by including:
[0021] Smart meter hardware, equipped with a microcontroller for running encryption algorithms and processing data, a metering chip for accurately collecting data such as voltage and current, a secure storage module for securely storing keys and sensitive information, and a communication module supporting multiple communication methods to achieve data transmission with the back-end control terminal;
[0022] Back-end control terminal hardware, including a server for processing and storing a large amount of smart meter data, a secure network device for ensuring the security and stability of network communication, and a data storage device;
[0023] Smart meter software, installed with a secure operating system for managing the operation and resources of the meter and data processing and analysis software for preprocessing and analyzing the collected power consumption data;
[0024] Back-end control terminal software, installed with data receiving and decrypting software for receiving the encrypted data sent by the smart meter and decrypting it with the corresponding key, and a data management and analysis system for storing, managing and deeply analyzing the decrypted data;
[0025] Communication system, a power line carrier communication (PLC) network adopting a secure and reliable communication protocol;
[0026] Security system, including an identity authentication system, a data encryption and decryption system, and a key management system;
[0027] Data backup and recovery system, establishing a data backup mechanism on the local smart meter and the cloud server, regularly backing up important power consumption data and related parameters, so as to be able to recover the data in time in case of data loss or abnormality, and ensuring the integrity and continuity of the data.
[0028] Data integrity verification system, respectively setting data integrity verification modules on the smart meter and the back-end control terminal, and verifying the integrity of the data during transmission and storage through methods such as hash check and digital signature to prevent the data from being tampered with;
[0029] User identity authentication module: For operations that require user participation, such as remotely querying electricity consumption information and performing remote recharges, a user identity authentication mechanism is established. Users can authenticate their identities by entering a username and password, using a dynamic password, or a digital certificate, etc., to ensure that only legitimate users can access and operate the data of the smart meter.
[0030] User interface: Provide a user-friendly and easy-to-use interface to facilitate users to perform various operations, such as viewing electricity consumption information, setting parameters, receiving alarm notifications, etc.
[0031] Preferably, the identity authentication system establishes a complete two-way identity authentication mechanism, and the smart meter and the background control terminal authenticate their identities with each other through technologies such as digital certificates; the data encryption and decryption system deploys data encryption and decryption modules at the smart meter end and the background control terminal respectively, supports multiple encryption algorithms, and encrypts the transmitted data; the key management system constructs a secure key management system, which is responsible for operations such as key generation, storage, update, distribution, and backup.
[0032] (III) Beneficial effects
[0033] The present invention provides a smart meter security encryption method and system, which has the following beneficial effects:
[0034] 1. Through multiple hash checksums and digital signature technologies, ensure the integrity and reliability of data during transmission, effectively prevent data from being tampered with, and verify the integrity of data and the reliability of the source.
[0035] 2. Use a hardware security module to generate and store keys, improve the security and reliability of keys, enhance the anti-attack ability of encryption algorithms, and at the same time establish a key backup and recovery mechanism and a multi-level data backup system to improve the fault tolerance of the system and the persistent availability of data.
[0036] 3. The two-way identity authentication mechanism ensures the communication security between the smart meter and the background control terminal, prevents illegal devices from accessing and data forgery, guarantees the overall security of the system, and at the same time the user identity authentication mechanism ensures that only legitimate users can access and operate the data of the smart meter, further protecting user privacy and data security. Specific implementation manners
[0037] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0038] Embodiment 1:
[0039] An intelligent electricity meter security encryption method includes the following steps:
[0040] S1. The intelligent electricity meter collects data such as voltage and current, processes it through a microcontroller, uses a metering chip to accurately measure the collected data, and stores the measured data in a secure storage module.
[0041] S2. Use a communication module to transmit the data to the background control terminal. Before data transmission, encrypt the data. Perform a one-time hash processing on the encrypted data at the intelligent electricity meter end, and perform a SHA-256 hash calculation on the original data after data collection and before encryption to obtain the initial hash value and store it.
[0042] S3. During the transmission process of the encrypted data, perform another hash processing to obtain the transmission hash value. After the background control terminal receives the data, first recalculate the hash value of the decrypted data and compare it with the initial hash value at the electricity meter end. If they are consistent, then compare it with the transmission hash value to ensure the integrity of data transmission.
[0043] S4. Perform a digital signature on the generated hash value. The intelligent electricity meter uses its private key to encrypt the hash value to generate signature information, and sends the signed hash value and the encrypted data to the background control terminal together.
[0044] S5. The background control terminal uses the public key of the intelligent electricity meter to decrypt the signature to obtain the original hash value, and then compares it with the hash value calculated by itself to verify the integrity of the data and the reliability of the source.
[0045] S6. Adopt a Hardware Security Module (HSM) or a Trusted Platform Module (TPM) to generate and store the keys required for the chaotic encryption algorithm to ensure that the key generation process has sufficient randomness and unpredictability.
[0046] S7. Establish a key backup and recovery mechanism, encrypt the keys and store them in a secure backup server or device, and simultaneously back up the encrypted data to a cloud server to build a multi-level data backup and recovery system to improve the security and reliability of the data.
[0047] S8. Before the intelligent electricity meter and the background control terminal communicate, both parties first perform identity authentication. The intelligent electricity meter uses a digital certificate to prove its identity, and the background control terminal verifies the certificate to confirm its legality. At the same time, the background control terminal sends an authentication request to the electricity meter, and the electricity meter verifies the background certificate to ensure the trustworthiness of the communication server, preventing illegal device access and data tampering and forgery.
[0048] S9. When abnormal situations such as data tampering, key leakage, and illegal access are detected, the smart meter and the background control terminal immediately trigger an alarm mechanism to send an alarm notification to the operation and maintenance personnel of the power company for timely handling to prevent further damage or abuse of the data. Example 2:
[0049] The difference between this embodiment and the first embodiment lies in that:
[0050] In step 2, a data backup function can also be set locally on the smart meter to regularly back up and store important electricity consumption data and related parameters. When an abnormality occurs during data transmission or data is lost, the data can be restored from the local backup to ensure the integrity and continuity of the data;
[0051] In step 1, the key is updated regularly, and a secure key distribution mechanism, such as the Diffie-Hellman key exchange protocol, is used to ensure the security of the key during the update and distribution process;
[0052] In step 2, in the case of a smart meter failure or key loss, through a secure recovery process, the backup key can be used to re-perform data encryption and decryption operations to ensure the continuity and availability of the data;
[0053] For operations that require user participation, such as remotely querying electricity consumption information and performing remote recharge, a user identity authentication mechanism is established. The user authenticates their identity by entering a username and password, using a dynamic password, or a digital certificate, etc., to ensure that only legitimate users can access and operate the data of the smart meter;
[0054] During data transmission, if situations such as data loss, interruption, or timeout occur, the smart meter and the background control terminal should have corresponding processing mechanisms. For example, the smart meter can automatically re-send the data, and the background control terminal can send a data request instruction to require the meter to re-transmit the data to ensure the integrity and continuity of the data.
[0055] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An intelligent electricity meter security encryption method, characterized in that, It includes the following steps: S1. After the smart meter performs a one-time hashing process on the encrypted data, multiple hashing validations are carried out at different stages of the data; S2. The smart meter encrypts the hash value with the private key to generate a signature, and sends it together with the encrypted data to the background. The background decrypts the signature with the public key to obtain the original hash value, and then compares it with the hash value calculated by itself; S3. A security module is used to generate and store the keys required for the chaotic encryption algorithm, ensuring that the key generation process has sufficient randomness and unpredictability; S4. A key backup and recovery mechanism is established. The key is encrypted and stored in a secure backup server or device, and the encrypted data is simultaneously backed up to the cloud server to establish a multi-level data backup and recovery system; S5. Before the smart meter communicates with the background control terminal, both parties perform identity authentication first; S6. When abnormal situations such as data tampering, key leakage, and illegal access are detected, the smart meter and the background control terminal should immediately trigger an alarm mechanism and send an alarm notification to the operation and maintenance personnel of the power company so that timely measures can be taken for processing to prevent further damage or abuse of the data.
2. The intelligent electric meter security encryption method according to claim 1, wherein: In step S4, a data backup function can also be set locally on the smart meter to regularly back up and store important electricity consumption data and related parameters.
3. The security encryption method for an intelligent electric meter according to claim 1, wherein: In step S3, the secret key is updated regularly and a secure key distribution mechanism is used.
4. The security encryption method for an intelligent electric meter according to claim 1, characterized in that: In step S4, in the case of a smart meter failure or key loss, through a secure recovery process, the backup key can be used to re-perform data encryption and decryption operations.
5. A security encryption method for an intelligent electricity meter according to claim 1, characterized in that: In step S5, the identity authentication method is that the smart meter uses a digital certificate to prove its identity, and the background control terminal confirms its legitimacy by verifying the meter's certificate; The background control terminal sends an authentication request to the meter.
6. The intelligent electricity meter security encryption method according to claim 1, characterized in that It also includes: For operations that require user participation, such as remotely querying electricity consumption information and performing remote recharge, a user identity authentication mechanism is established. The user performs identity authentication by entering a username and password, using a dynamic password, or a digital certificate, etc.
7. An intelligent electricity meter security encryption system, applied to an intelligent electricity meter security encryption method as described in claims 1-6, characterized in that, It includes: Smart meter hardware, equipped with a microcontroller, a metering chip, a secure storage module, and a communication module, for data processing, metering, key storage, and data transmission; Background control terminal hardware, including a server, secure network devices, and data storage devices, for processing, storing data, and ensuring the security and stability of network communication; Smart meter software, installing a secure operating system and data processing and analysis software, managing the operation of the meter, resources, and preprocessing and analyzing electricity consumption data; Background control terminal software, installing data receiving and decrypting software and a data management and analysis system, for receiving, decrypting data, and storing, managing, and analyzing data; Communication system, adopting a secure and reliable power line carrier communication network to ensure the security and stability of data transmission; Security system, including identity authentication, data encryption and decryption, key management, etc. systems, to ensure the security and integrity of data; Data backup and recovery system, establishing a data backup mechanism on the local smart meter and the cloud server, regularly backing up important data to ensure timely recovery in case of data loss or abnormality; Data integrity verification system, which sets up data integrity verification modules at the smart meter and the back-end control terminal, verifies the integrity of data through methods such as hash verification and digital signatures, and prevents data from being tampered with; User identity authentication module, for operations that require user participation, establishes a user identity authentication mechanism to ensure that only legitimate users can access and operate the data of the smart meter; User interface, which provides a friendly and easy-to-use interface to facilitate users to perform various operations, such as viewing electricity consumption information, setting parameters, and receiving alarm notifications.
8. A security encryption method and system for an intelligent electric meter according to claim 1, characterized in that: The identity authentication system mutually authenticates the identities of the smart meter and the back-end control terminal through technologies such as digital certificates by establishing a complete two-way identity authentication mechanism; the data encryption and decryption system deploys data encryption and decryption modules at the smart meter end and the back-end control terminal respectively, supports multiple encryption algorithms, and encrypts the transmitted data; the key management system constructs a secure key management system, which is responsible for operations such as key generation, storage, update, distribution, and backup.