Certificate-based smart power grid privacy protection multi-dimensional data aggregation method and system
Through certificate-based cryptographic system and elliptic curve encryption technology, a lightweight multi-dimensional data aggregation method is designed, which solves the key management and high cost problems in the smart grid, and realizes efficient and secure multi-dimensional data aggregation, which is suitable for resource-constrained devices such as smart meters.
Patent Information
- Application Number
- CN202510842003.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing smart grid multi-dimensional data aggregation scheme has the complexity of key management and the risks of key custody, and the calculation and communication costs are high, especially under public key infrastructure or identity-based cryptographic systems.
Using a certificate-based cryptographic system, elliptic curve encryption technology and homomorphic encryption algorithms, a lightweight multi-dimensional data aggregation method is designed to ensure the security and verifiability of data transmission through certificate generation, data encryption, signature and verification processes.
It significantly reduces computing and communication costs, supports efficient weighted aggregation of multi-dimensional data, eliminates key hosting issues, provides data non-forgery, integrity and privacy protection, and is suitable for resource-constrained smart meter devices.
Smart Images

Figure CN120358027A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the research field of the intersection of information security technology and smart grid technology, and in particular to a method for certificate-based multidimensional data aggregation for privacy protection in smart grid (Certificate-Based Multidimensional Data Aggregation for Smart Grid) solution. Background Art
[0002] As an important part of a smart city, the smart grid has gradually become an important direction of modern energy management. Through digital and automation technologies, the smart grid tightly connects various links such as power generation, transmission, distribution, power consumption, and energy storage, and can monitor users' power consumption data in real time with high frequency and accuracy, thus providing technical support for power grid load forecasting, dynamic power distribution, and user behavior optimization. However, the frequent collection and transmission of user energy consumption data also bring potential risks of data privacy leakage. Especially when transmitted in an open network environment, it faces serious threats such as data theft, forgery, and tampering. In the process of collecting energy consumption data, how to ensure the integrity of the data and prevent the leakage of user privacy is a key issue.
[0003] Currently, in some special practices, energy service providers may need to statistically analyze multifunctional data such as the mean and variance of users' fine-grained energy consumption data (such as when and for what purpose the consumption occurs). If a privacy-preserving data aggregation protocol that supports single-type data aggregation is applied, it is necessary to separately aggregate and transmit each type of data, which requires a large amount of computing and communication costs. Generally speaking, it is relatively complex to design such a protocol that supports multidimensional data aggregation. Almost all existing works are based on public key infrastructure or identity-based cryptosystems, which have the problems of key management complexity and key escrow risks. In addition, most of the solutions have extremely large performance bottlenecks due to relying on expensive bilinear pairings and exponentiation operations. The present invention aims to design a secure lightweight multidimensional data aggregation method. This method is established under a certificate-based cryptosystem, which solves the problems of key escrow and key management. At the same time, an encryption and signature scheme that does not require exponentiation operations and bilinear pair operations is designed to ensure the efficient verifiability of the transmitted data, so as to meet the actual needs of the multidimensional data aggregation scenario. Summary of the Invention
[0004] The present invention proposes a method for certificate-based multidimensional data aggregation for privacy protection in smart grid, aiming to solve the problems of existing solutions in terms of computational overhead and security. In particular, the present invention can provide a lightweight encryption and signature scheme for resource-constrained devices such as smart meters to achieve privacy protection and authentication for multidimensional data aggregation.
[0005] The technical solution of the present invention is as follows: A multi-dimensional data aggregation method for privacy protection of smart grid based on certificates, comprising the following steps:
[0006] Step 1, given a security factor, the key generation center sets system parameters and each node outputs a key pair, as well as a super-increasing sequence by running an initialization algorithm and a key extraction algorithm;
[0007] Step 2, the key generation center generates certificates for smart meters, base stations, and energy service providers;
[0008] Step 3, combining the system parameters, key pairs, super-increasing sequence, and certificates, the smart meter encrypts the multi-dimensional power consumption data of users, aggregates the multi-dimensional data into a single data, and encrypts the single data into ciphertext;
[0009] Step 4, the smart meter signs the ciphertext;
[0010] Step 5, the base station verifies the validity of the signatures of the ciphertext data from n smart meters;
[0011] Step 6, after ensuring that the signatures of n meters all pass the verification, the base station aggregates the signatures and ciphertexts of these n smart meters;
[0012] Step 7, the energy service provider verifies the signature of the signed ciphertext data sent by the base station and decrypts the ciphertext.
[0013] Further, the specific implementation manner of Step 1 is as follows:
[0014] Step 1.1, the key generation center selects a secure elliptic curve, which is defined over a finite field and its equation form is , ensuring , mod is for taking the remainder; select a base point of order , where, where and are elements defining the elliptic curve, is a prime number, defining the size of the finite field, is another prime number, used to define the order of the subgroup, is the base point, a specific point on the elliptic curve, and , is the generator;
[0015] Step 1.2, publicly disclose the system parameters , where, is the group formed by the base point as the generator, is the main system public key, is a hash function; each node randomly selects an integer from the set of positive integers modulo as the private key , calculates the public key , and makes public as the signature verification public key;
[0016] Step 1.3, initialize the starting value of the sequence . For , is the number of data dimensions, and each is calculated in sequence, satisfying the following conditions:
[0017]
[0018] where represents the aggregated data volume, represents the maximum value of the electricity consumption data, ensuring that the sum of the generated super-increasing sequence satisfies:
[0019]
[0020] The generated super-increasing sequence is made public for subsequent encryption and data signature processes.
[0021] Furthermore, in Step 2, given the system parameters , the main system private key , the identities of each entity node , and the public key , each entity node calculates the certificate in the following way:
[0022] Step 2.1, select a random number , calculate the first component of the certificate , and use the system master key to calculate the second component . Let = be the certificate of the electricity meter . By verifying the following equation, the validity of the smart electricity meter certificate can be checked:
[0023]
[0024] is the main system public key, is a hash function.
[0025] Step 2.2, in the same way, the certificates of the base station and the energy service provider are respectively = , = 。
[0026] Furthermore, in step 3, given the system parameters , the master system private key , the electricity meter private key , and the public key , the certificate , the super-increasing sequence , each electricity meter calculates the ciphertext in the following way:
[0027] Step 3.1, the smart electricity meter collects the user's electricity consumption data, including the electricity consumption in dimensions and the total electricity consumption of each dimension , and calculates:
[0028] =
[0029] Maps the weighted summation result to a point on the elliptic curve ;
[0030] Step 3.2, the smart electricity meter selects a random number , and calculates the corresponding public value:
[0031]
[0032] This corresponding public value is used to blind the data; according to the system parameters and the certificate component of the energy service provider , calculates the auxiliary value:
[0033]
[0034] Calculates , sets the ciphertext component as , and the ciphertext is .
[0035] Furthermore, in step 4, given the system parameters , the master system private key , the electricity meter private key , and the public key , the certificate , the electricity meter identity , the timestamp , each electricity meter calculates the signature in the following way:
[0036] Step 4.1, the smart electricity meter selects a random number , and calculates the random factor:
[0037]
[0038] Use the hash function defined during system initialization , perform a hash operation on the ciphertext component and the random factor, and calculate the hash value:
[0039]
[0040] Step 4.2, use the hash function , combined with the timestamp , calculate another hash value:
[0041]
[0042] According to the certificate component of the electricity meter , the private key , the random factor , calculate the signature component:
[0043]
[0044] The electricity meter defines the signature tuple as ;
[0045] Step 4.3, the smart electricity meter sends the identity identifier the ciphertext component , the signature component , and the timestamp to the base station.
[0046] Furthermore, in step 5, given the system parameters and the tuple The base station performs the following operations to verify the validity of the signatures of the ciphertext data from n smart electricity meters:
[0047] Step 5.1, the base station verifies the freshness of the timestamp , ensures that it has not expired, and uses the hash function defined by the system to recover the following hash value:
[0048]
[0049]
[0050]
[0051] Step 5.2, the base station verifies whether the signature of a single electricity meter satisfies the following equation:
[0052]
[0053] If the above equation holds, accept the ciphertext of the electricity meter and output 1; otherwise, reject the ciphertext and output 0;
[0054] Step 5.3, the base station performs signature verification on electricity meters. The base station randomly selects a set of small integers , where , is a small integer, and calculates the aggregated signature value:
[0055]
[0056] Verify whether the following aggregated signature equation holds:
[0057]
[0058] If the above equation holds, accept the aggregated ciphertext of the electricity meters and output 1; otherwise, reject the ciphertext and output 0.
[0059] Furthermore, in step 6, given the system parameters , the base station private key , the public key , the certificate , the base station identity identifier , the base station performs the following operations for aggregation processing:
[0060] Step 6.1, aggregate the public values calculated by each electricity meter respectively:
[0061] =
[0062] Aggregate the ciphertext components of all electricity meters:
[0063] =
[0064] Step 6.2, the base station selects a random number , and calculates the random factor:
[0065]
[0066] The base station records the current timestamp , and calculates the following hash values:
[0067] Calculate the hash value related to the base station identity:
[0068]
[0069] Calculate the hash value related to the aggregated data:
[0070]
[0071] Calculate the final hash value in combination with the timestamp:
[0072]
[0073] The base station, according to the certificate component , the private key , generates a signature value:
[0074]
[0075] The base station generates a signature component:
[0076]
[0077] The base station sends the identity identifier ciphertext component , signature component , timestamp to the energy service provider.
[0078] Furthermore, for the system parameters , tuple given in step 7, the energy service provider performs the following operations:
[0079] Step 7.1, the energy service provider verifies the freshness of the timestamp to ensure that it has not expired, and uses the hash function defined by the system to recover the following hash value:
[0080]
[0081]
[0082]
[0083] Step 7.2: The energy service provider verifies whether the signature of the base station satisfies the following equation:
[0084]
[0085] If the above equation holds, the signature verification passes and 1 is output; otherwise, the aggregated ciphertext is rejected and 0 is output;
[0086] Furthermore, for the system parameters , base station private key , public key , certificate , base station identity identifier , ciphertext tuple , super-increasing sequence , the energy service provider performs the following operations:
[0087] Step 8.1, the energy service provider calculates the linear combination factor according to its own certificate components , private key , and calculates the linear combination factor:
[0088]
[0089] Using the received ciphertext tuple , calculates the aggregated data:
[0090] Step 8.2, uses the public Pollard’s Lambda algorithm to recover the original data ;
[0091] Step 8.3, according to the super-increasing sequence initialized by the system and the electricity consumption of a single user and its electricity consumption in each dimension and the relationship existing between the data , uses algorithm to solve the total electricity consumption data of all users in each dimension and the total electricity consumption of these users . .
[0092] The present invention also provides a certificate-based multi-dimensional data aggregation system for smart grid privacy protection, including:
[0093] A processor and a memory, the memory is used to store program instructions, and the processor is used to call the stored instructions in the memory to execute a certificate-based multi-dimensional data aggregation method for smart grid privacy protection as described in the above technical solution.
[0094] In existing multi-dimensional data aggregation schemes for privacy protection, there are usually complex key management or key escrow problems. In addition, due to the dependence on bilinear pairing or modular exponentiation operations, these schemes have obvious deficiencies in terms of computational and communication efficiency. In the present invention, based on the certificate-based cryptosystem, a certificate-based multi-dimensional data aggregation method for smart grid privacy protection is proposed. This method does not require the use of bilinear pairing or complex exponentiation operations, significantly improving the computational performance. At the same time, by taking advantage of the certificate-based cryptosystem, the dependence on the complex key management process and the key escrow problem in traditional schemes are eliminated. Compared with the prior art, this method achieves very competitive computational efficiency and communication overhead. The main contributions of this invention are as follows:
[0095] 1. High efficiency: Based on the optimized elliptic curve encryption technology, it avoids the expensive bilinear pairing and exponential operations in traditional solutions, significantly reducing the computational overhead and communication cost of the system.
[0096] 2. Scalability: It supports the efficient weighted aggregation of multi-dimensional data, is applicable to the dynamic data collection and processing in a large-scale smart grid environment, and meets the requirements of future complex application scenarios.
[0097] 3. Security: By using an efficient certificate encryption mechanism, it eliminates the problems of key management and key escrow in traditional solutions. Adopting data encryption and signature technologies, it ensures that users' sensitive data is fully protected during transmission and aggregation, and only the designated recipient can recover the data content. Based on strict cryptographic security assumptions, the solution has features such as unforgeability, data integrity, and privacy, providing a solid security guarantee for smart grid data sharing. Brief Description of the Drawings
[0098] Figure 1 It is the overall framework diagram of a certificate-based multi-dimensional data aggregation method for smart grid privacy protection provided by an embodiment of the present invention;
[0099] Figure 2 It is the schematic diagram of certificate generation provided by an embodiment of the present invention;
[0100] Figure 3 It is the schematic diagram of data encryption provided by an embodiment of the present invention;
[0101] Figure 4 It is the schematic diagram of signing the ciphertext provided by an embodiment of the present invention;
[0102] Figure 5 It is the schematic diagram of signature verification provided by an embodiment of the present invention;
[0103] Figure 6 It is the schematic diagram of ciphertext data aggregation and signature provided by an embodiment of the present invention;
[0104] Figure 7 It is the flow chart of a certificate-based multi-dimensional data aggregation method for smart grid privacy protection provided by an embodiment of the present invention.
[0105] Figure 8 It is the time comparison diagram between the base station side and the energy service provider side in an embodiment of the present invention. Detailed Embodiments
[0106] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0107] The symbols and definitions are described as follows:
[0108] : Security parameter.
[0109] : The elliptic curve itself.
[0110] : Safe prime number, which defines the size of the finite field.
[0111] : Two parameters defining the elliptic curve equation.
[0112] : Safe prime number, used to define the order of the subgroup.
[0113] : Base point, a specific point on the elliptic curve.
[0114] : A special point on the elliptic curve, called the infinite point or zero point.
[0115] : From the base point as the generator to form a group.
[0116] : Modulo of the set of positive integers.
[0117] : Private key of the main system.
[0118] : Public key of the main system.
[0119] : Energy service provider.
[0120] : Base station.
[0121] : Smart meter.
[0122] : Element is randomly selected from the set in.
[0123] : System public parameters.
[0124] : Identity of the entity node of, .
[0125] : The entity node public and private key pairs
[0126] : entity node certificate
[0127] smart meter plaintext message
[0128] ciphertext
[0129] signature
[0130] aggregated ciphertext signature
[0131] : signature generated timestamp
[0132] : hash function
[0133] : total number of users
[0134] : number of data dimensions
[0135] : maximum value of electricity consumption data
[0136] such as Figure 1 shown, it is the overall framework diagram of the certificate-based multi-dimensional data aggregation method for smart grid privacy protection provided by the embodiments of the present invention, which specifically includes the following steps:
[0137] Step 1) System initialization : Given a security factor , the key generation center sets the system parameters by running the initialization algorithm and the key extraction algorithm ;
[0138] each node's key pair , and the super-increasing sequence . Execute the following steps:
[0139] Step 1.1: The key generation center selects a secure elliptic curve, which is defined over a finite field and has an equation form of , ensuring (mod is for taking the remainder). Select a base point of order , where, among them and are the elements defining the elliptic curve. is a prime number that defines the size of the finite field. is another prime number used to define the order of the subgroup. is the base point, a specific point on the elliptic curve. And ( is the generator).
[0140] Step 1.2: Publicize system parameters , each node randomly selects an integer as the private key from the set of positive integers modulo and calculates the public key and publicizes as the signature verification public key. And is publicized as the signature verification public key.
[0141] Step 1.3: Initialize the starting value of the sequence , for , calculate each in turn, subject to the following conditions:
[0142]
[0143] where represents the amount of aggregated data, and represents the maximum value of the electricity consumption data. Ensure that the sum of the generated super-increasing sequence satisfies:
[0144]
[0145] Publicize the generated super-increasing sequence for subsequent encryption and data signature processes.
[0146] Step 2) Certificate generation algorithm : The key generation center generates certificates for smart meters, base stations, and energy service providers , randomly selects a value from and calculates the certificate components and .
[0147] Given the parameters , the master system private key , the identities of each entity node , and the public key , each entity node calculates the certificate in the following manner:
[0148] Step 2.1: Select a random number and calculate the first component of the certificate , using the system master key Calculate the second component . Set = as the certificate of the electricity meter . To check the validity of the smart electricity meter certificate, the equation can be verified:
[0149] .
[0150] Step 2.2: In the same way, the certificates of the base station and the energy service provider are respectively = , = .
[0151] Step 3) Electricity meter encryption algorithm : The smart electricity meter will encrypt the user's multi-dimensional electricity consumption data, aggregate the multi-dimensional data into a single data , and encrypt the data into ciphertext .
[0152] Given parameters , the master system private key , the electricity meter private key , and the public key , certificate , super-increasing sequence , each electricity meter calculates the ciphertext in the following way:
[0153] Step 3.1: The smart electricity meter collects the user's electricity consumption data, including the electricity consumption of dimensions and the total electricity consumption of each dimension
[0154] =
[0155] Map the weighted summation result to a point on the elliptic curve .
[0156] Step 3.2: The smart electricity meter selects a random number , and calculates the corresponding public value:
[0157]
[0158] This corresponding public value is used to blind the data to prevent the data from being leaked during transmission. According to the system parameters and the certificate components of the energy service provider , Calculate auxiliary value:
[0159]
[0160] Calculate , Set the ciphertext component to , The ciphertext is .
[0161] Step 4) Meter signature algorithm : The smart meter signs the ciphertext to obtain the signature .
[0162] Given parameters , the private key of the main system , the private key of the meter , and the public key ,, the certificate , the meter identity , the timestamp , Each meter calculates the signature in the following way:
[0163] Step 4.1: The smart meter Select a random number , Calculate the random factor:
[0164]
[0165] Use the hash function defined in the system initialization , Perform a hash operation on the ciphertext component and the random factor to calculate the hash value:
[0166]
[0167] Step 4.2: Use the hash function , Combine with the timestamp , Calculate another hash value:
[0168]
[0169] According to the certificate component of the meter , the private key , the random factor , Calculate the signature component:
[0170]
[0171] The meter defines the signature tuple as .
[0172] Step 4.3: The smart meter Put the identity identifier the ciphertext component , the signature component , timestamp and send it to the base station.
[0173] Step 5) Base station verification algorithm : The base station verifies the validity of the signatures of the ciphertext data from n smart meters.
[0174] Given parameters , and tuples the base station performs the following operations:
[0175] Step 5.1: The base station verifies the timestamp for freshness to ensure it has not expired. Use the system-defined hash function to recover the following hash values:
[0176]
[0177]
[0178]
[0179] Step 5.2: The base station verifies whether the signature of a single meter satisfies the following equation:
[0180]
[0181] If the above equation holds, at this time the base station verification algorithm outputs 1, indicating that the base station accepts the ciphertext of this meter; if it outputs 0, then the ciphertext is rejected;
[0182] Step 5.3: The base station can also simultaneously verify the signatures of meters. The base station randomly selects a set of small integers , where , is a small integer (for example = 5). Calculate the aggregated signature value:
[0183]
[0184] Verify whether the following aggregated signature equation holds:
[0185]
[0186] If the above equation holds, then accept the aggregated ciphertext of the meters, output 1; otherwise reject the ciphertext, output 0;
[0187] Step 6) Base station aggregated signature algorithm : The base station ensures that After the signatures of all the electricity meters are verified, the ciphertexts of these n smart electricity meters are aggregated, and the aggregated ciphertext is signed to improve the data transmission efficiency.
[0188] Given parameters , base station private key , public key , certificate , base station identity identifier , the base station performs the following operations:
[0189] Step 6.1: Aggregate the public values calculated by each electricity meter :
[0190] =
[0191] Aggregate the ciphertext components of all the electricity meters :
[0192] =
[0193] Step 6.2: The base station selects a random number , and calculates the random factor:
[0194]
[0195] The base station records the current timestamp , and calculates the following hash values:
[0196] Calculate the hash value related to the base station identity:
[0197]
[0198] Calculate the hash value related to the aggregated data:
[0199]
[0200] Calculate the final hash value by combining the timestamp:
[0201]
[0202] The base station generates a signature value according to the certificate component , private key , and generates a signature component:
[0203]
[0204] The base station generates a signature component:
[0205]
[0206] The base station sends the identity identifier ciphertext component , signature component , timestamp to the energy service provider.
[0207] Step 7) Energy provider verification algorithm : The energy service provider verifies the signature of the signed ciphertext data sent by the base station to ensure the integrity, legality, and authenticity of the base station's signature.
[0208] Given parameters , tuples , the energy service provider performs the following operations:
[0209] Step 7.1: The energy service provider verifies the freshness of the timestamp to ensure that it has not expired. Use the system-defined hash function to recover the following hash values:
[0210]
[0211]
[0212]
[0213] Step 7.2: The energy service provider verifies whether the signature of the base station satisfies the following equation:
[0214]
[0215] If the above equation holds, the energy provider verification algorithm outputs 1, indicating that the signature verification is passed; otherwise outputs 0, indicating that the aggregated ciphertext is rejected.
[0216] Step 8) Energy provider verification algorithm : After ensuring that the signature verification of the base station is passed, the energy service provider recovers the original multi-dimensional user electricity consumption data from the aggregated ciphertext data received from the base station.
[0217] Given parameters , base station private key , public key , certificate , base station identity identifier , ciphertext tuple , super-increasing sequence , the energy service provider performs the following operations:
[0218] Step 8.1: The energy service provider according to its own certificate component and private key , calculate the linear combination factor:
[0219]
[0220] Use the received ciphertext tuple , calculate the aggregated data:
[0221] The correctness of this equation is verified by the following derivation process:
[0222]
[0223]
[0224]
[0225]
[0226] .
[0227] Step 8.2: Use the existing public Pollard’s Lambda algorithm to recover the original data .
[0228] Step 8.3: According to the super-increasing sequence initialized by the system and the electricity consumption of a single user and its electricity consumption in each dimension and the relationship existing between the data , use algorithm to solve the total electricity consumption data of all users in each dimension and the total electricity consumption of these users .
[0229] The algorithm steps are as follows:
[0230] The super-increasing sequence
[0231]
[0232]
[0233]
[0234]
[0235] return
[0236] The effects of the present invention will be illustrated by comparative experiments as follows:
[0237] To evaluate the performance of the present invention, we experimentally compared it with the following representative literatures [1]-[4] in recent years in terms of computational cost and communication cost. For the specific literatures, please refer to: [1] O. R. M. Boudia, S. M. Senouci, and M. Feham. Elliptic Curve-Based Secure Multidimensional Aggregation for Smart Grid Communications. IEEE Sens. J., vol. 17, no. 23, pp. 7750–7757, 2017; [2] X. Zuo, L. Li, H. Peng, S. Luo, and Y. Yang. Privacy-Preserving Multidimensional Data Aggregation Scheme Without Trusted Authority in Smart Grid. IEEE Syst. J., vol. 15, no. 1, pp. 395–406, 2021; [3] X. Zhang, C. Huang, Y. Zhang, and S. Cao. Enabling Verifiable Privacy Preserving Multi-Type Data Aggregation in Smart Grids. IEEE Trans. Dependable Secur. Comput., vol. 19, no. 6, pp. 4225–4239, 2022; [4] F. Wu, X. Li, S. Kumari, M. J. Alenazi, and C.-M. Chen. CFDAS: A Customer-Centric and Fault-Tolerant Data Aggregation Scheme for Smart Grid in 6G Networks Keeping Unlinkability Under the Conception Industry 5.0. IEEE Transactions on Consumer Electronics, pp. 1–1, 2024. We first established a benchmark experiment to evaluate the computational cost of these schemes by quantifying the running time of relevant cryptographic operations.To achieve the same security level, we use the built-in Type A curve and Type D curve in the open-source JPBC library to implement the relevant operations of bilinear pairing and elliptic curve cryptography respectively. Then, for a fair comparison, we consider setting the modulus length of Paillier encryption used in [3] to 1024 bits. We use the RaspberryPi 3B+ device to simulate the smart meter and a laptop equipped with an Intel Core i7-10750h CPU @ 2.6 GHz and 16G of memory to simulate the base station and the energy service provider. Meanwhile, we believe that the Pollard lambda public algorithm for solving the 32-bit discrete logarithm problem is sufficient to meet our computational requirements.
[0238] Table 1 Time comparison at the smart meter side (unit: milliseconds)
[0239]
[0240] Table 1 lists the time cost comparison of the proposed invention and the schemes in [1-4] at the smart meter side when the dimensions of the energy consumption data are =5, 10, 15 respectively. The numerical results show that, except for [4], the time cost at the meter side in other schemes increases with the increase of the value. Taking =10 as an example, the time cost of the proposed invention is 163.68 milliseconds, and the time costs of the other schemes are 955.64 milliseconds, 587.56 milliseconds, 758.60 milliseconds, and 239.41 milliseconds respectively. Obviously, the computational cost of the proposed invention is lower than that of other schemes.
[0241] Similarly, when the dimension of the energy consumption data =10, we compare the computational costs of the proposed invention and [1]-[4] at the base station side and the energy service provider side respectively, and the results are shown in Figure 8 . It can be seen from Figure 8 that the proposed invention has a smaller computational overhead at both the base station and the energy service provider sides. Therefore, overall, our scheme has a more competitive computational cost while ensuring security, and is especially suitable for resource-constrained smart meters.
[0242] Meanwhile, based on the experimental parameters used in the above computational cost comparison, we can obtain the parameters related to the communication cost analysis, such as the lengths of the elements in and are 320 bits and 160 bits respectively. At the same time, we assume that the lengths of the identity and the timestamp are both 32 bits. Based on these metrics, we compare the communication costs between the smart meter side and the base station side, and the results are shown in Table 2.
[0243] Table 2 Time Comparison between Smart Meter End and Base Station End (Unit: bit)
[0244]
[0245] As shown in Table 2, there are some similarities in the overall trend between the communication cost of sending data from the smart meter end to the base station end and that of sending data from the base station end to the energy service provider end. Since the smart meter is embedded with storage and computing devices with limited resources, the communication cost of sending data from the meter side to the base station end is one of the key factors affecting the performance and feasibility of deploying relevant data aggregation schemes in the smart grid. Therefore, we will mainly focus on the communication cost at the meter end. It can be seen from the table that the communication cost of the present invention is 1984 bits, slightly higher than that in Reference [4], but lower than other schemes. It seems that our scheme does not achieve the optimal communication cost. However, considering that there are some defects in the existing work in terms of security and privacy (such as the key management problem and the security problem of signature batch verification in Reference [4]), and our work has better guarantees in terms of security and privacy, the communication cost of the present invention still has good competitiveness.
[0246] On the other hand, the embodiment of the present invention also provides a certificate-based multi-dimensional data aggregation system for smart grid privacy protection, including:
[0247] A processor and a memory, the memory is used to store program instructions, and the processor is used to call the stored instructions in the memory to execute a certificate-based multi-dimensional data aggregation method for smart grid privacy protection as described in the above technical solution.
[0248] The specific embodiments described in this article are only examples to illustrate the spirit of the present invention. Those skilled in the art of the present invention can make various modifications or supplements to the described specific embodiments or use similar ways to replace them, but will not deviate from the spirit of the present invention or exceed the scope defined by the appended claims.
Claims
1. A certificate-based multi-dimensional data aggregation method for privacy protection in smart grid, characterized in that It includes the following steps: Step 1: Given a safety factor, the key generation center sets system parameters, outputs key pairs for each node, and a super-increasing sequence by running an initialization algorithm and a key extraction algorithm; Step 2: The key generation center generates certificates for smart meters, base stations, and energy service providers; Step 3: Combining the system parameters, key pairs, super-increasing sequence, and certificates, the smart meter encrypts the multi-dimensional power consumption data of users, aggregates the multi-dimensional data into a single data, and encrypts the single data into ciphertext; Step 4: The smart meter signs the ciphertext; Step 5: The base station verifies the validity of the signatures of the ciphertext data from n smart meters; Step 6: After ensuring that the signatures of the n meters all pass the verification, the base station aggregates the ciphertexts of these n smart meters and signs the aggregated ciphertext; Step 7: The energy service provider verifies the signature of the signed ciphertext data sent by the base station and decrypts the ciphertext.
2. The multi-dimensional data aggregation method for smart grid privacy protection based on certificates according to claim 1, characterized in that: The specific implementation method of Step 1 is as follows: Step 1.1, the key generation center generates and selects a secure elliptic curve, which is defined over a finite field and has an equation of the form , ensuring , where mod is the remainder operation; select a -order base point , where and are elements defining the elliptic curve, is a prime number that defines the size of the finite field, is another prime number used to define the order of the subgroup, is the base point, a specific point on the elliptic curve, and , is the generator; Step 1.2: Public system parameters ,in, By base point As a group of generators, is the main system public key, is a hash function; each node in the model The set of positive integers Randomly select an integer as the private key , calculate the public key , and Public as a signature verification public key; Step 1.3, initialize the starting value of the sequence , for , which is the number of data dimensions, calculate each successively, satisfying the following conditions: ; Among them represents the aggregated data volume represents the maximum value of the electricity consumption data, ensuring that the sum of the generated super-increasing sequence satisfies: ; The generated super-increasing sequence is disclosed for subsequent encryption and data signature processes.
3. The multi-dimensional data aggregation method for smart grid privacy protection based on certificates according to claim 1, characterized in that: The system parameters given in step 2 , the private key of the main system , the identities of each entity node , and the public key , each entity node calculates the certificate in the following way: Step 2.1, select a random number , calculate the first component of the certificate , and use the system master key to calculate the second component , and set = as the certificate of the electricity meter ; by verifying the following equation, the validity of the smart meter certificate can be checked: ; is the public key of the main system, is a hash function; Step 2.2, in the same way, the base station and the energy service provider certificates are respectively = , = .
4. The multi-dimensional data aggregation method for smart grid privacy protection based on certificates according to claim 1, characterized in that: In step 3, given system parameters , the private key of the main system , the private key of the electricity meter , and the public key , the certificate , the super-increasing sequence , each electricity meter calculates the ciphertext in the following way: Step 3.1, smart meter Collects the electricity consumption data of users, including the electricity consumption in each dimension and the total electricity consumption in each dimension , and calculates: = ; Map the weighted summation result to a point on the elliptic curve ; Step 3.2, the smart meter selects a random number , and calculates the corresponding public value: ; The corresponding public value is used to blind the data; Based on the system parameters and the certificate components of the energy service provider , calculate the auxiliary value: ; Calculation , set the ciphertext component as , the ciphertext is .
5. A multi-dimensional data aggregation method for intelligent grid privacy protection based on certificates as claimed in claim 1, characterized in that: In step 4, given system parameters , the private key of the main system , the private key of the electricity meter , and the public key , certificate , the identity of the electricity meter , timestamp , each electricity meter calculates the signature in the following way: Step 4.1, smart meter Select a random number , and calculate the random factor: ; Use the hash function defined by system initialization , perform a hash operation on the ciphertext component and the random factor to calculate the hash value: ; Step 4.2, use a hash function , combined with the timestamp , to calculate another hash value: ; According to the certificate component of the electricity meter , the private key , the random factor , calculate the signature component: ; The electricity meter defines the signature tuple as ; Step 4.3, smart electricity meter Send the identity identifier ciphertext component , signature component , timestamp to the base station.
6. The multi-dimensional data aggregation method for intelligent grid privacy protection based on a certificate according to claim 1, wherein: The system parameters given in step 5 , tuple The base station performs the following operations to verify the validity of the signatures of the ciphertext data from n smart meters: Step 5.1, the base station verifies the freshness of the time stamp to ensure that it has not expired, and uses a system-defined hash function to recover the following hash value: ; ; ; Step 5.2: The base station verifies whether the signature of a single meter satisfies the following equation: ; If the above equation holds, output 1 to indicate acceptance of the ciphertext of the meter; otherwise, output 0 to indicate rejection of the ciphertext; Step 5.3, the base station can also perform signature verification on the electricity meters. The base station randomly selects a set of small integers , where , is a small integer, and calculates the aggregated signature value: ; Verify whether the following aggregated signature equation holds: ; If the above equation holds, output 1 to indicate acceptance of the ciphertext of the meter; otherwise, output 0 to indicate rejection of the ciphertext.
7. The multi-dimensional data aggregation method for smart grid privacy protection based on certificates according to claim 1, characterized in that: In step 6, given system parameters , the base station private key , the public key , the certificate , the base station identity identifier , the base station performs the following operations for aggregation processing: Step 6.1, aggregate the public values calculated by each individual electricity meter : = ; Aggregate the ciphertext components of all electricity meters : = ; Step 6.2, the base station selects a random number , and calculates the random factor: ; The base station records the current timestamp , and calculates the following hash value: Calculate the hash value related to the base station identity: ; Calculate the hash value related to the aggregated data: ; Calculate the final hash value in combination with the timestamp: ; The base station generates an aggregated signature value according to the certificate component , the private key , as follows: ; The base station generates an aggregated signature component: ; The base station sends the identity identifier ciphertext component , signature component , timestamp to the energy service provider.
8. The multi-dimensional data aggregation method for smart grid privacy protection based on certificates according to claim 1, wherein: The system parameters given in step 7 , tuple , the energy service provider performs the following operations: Step 7.1, the energy service provider verifies the freshness of the time stamp to ensure that it has not expired, and uses a system-defined hash function to recover the following hash value: ; ; ; Step 7.2: The energy service provider verifies whether the signature of the base station satisfies the following equation: ; If the above equation holds, output 1 to indicate that the signature verification passes and accept the aggregated ciphertext; otherwise, output 0 to indicate that the signature verification fails and reject the aggregated ciphertext.
9. The multi-dimensional data aggregation method for intelligent grid privacy protection based on certificates according to claim 1, characterized in that: The system parameters given in step 8 , the private key of the base station , the public key , the certificate , the identity identifier of the base station , the ciphertext tuple , the super-increasing sequence , the energy service provider performs the following operations: Step 8.1, the energy service provider calculates according to its own certificate components , private key , calculate: ; Use the received ciphertext tuple , and calculate the aggregated data: ; Step 8.2, use the publicly available Pollard’s Lambda algorithm to recover the original data ; Step 8.3, according to the super-increasing sequence initialized by the system and the electricity consumption of a single user and its electricity consumption in each dimension and the data the relationship existing between , use the algorithm to solve the total electricity consumption data of all users in each dimension and the total electricity consumption of these users .
10. A certificate-based multi-dimensional data aggregation system for privacy protection in smart grid, characterized in that, It includes: A processor and a memory. The memory is used to store program instructions, and the processor is used to call the stored instructions in the memory to execute a multi-dimensional data aggregation method for certificate-based smart grid privacy protection as described in any one of claims 1-9.
Citation Information
Patent Citations
Multi-period data fusion method and system for wireless sensor network
CN114745689A
Industrial Internet of Things multi-dimensional privacy protection data aggregation method based on homomorphic proxy re-encryption
CN119675879A
Fog-based multi-dimensional multi-angle electricity consumption data aggregating system
WO2022001535A1