Digital signature system and method

By generating target keys for different services in the power system and digitally signing, the problem of low security in data transmission in the power system is solved, and more efficient data security transmission and system security improvement are achieved.

CN120378117APending Publication Date: 2025-07-25CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510557278.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the data encryption technology of the power system is single, resulting in low security in encrypted data transmission, making it difficult to adapt to the complex and changing security needs and environment of embedded power systems.

Method used

A digital signature system is provided, including a key management module, a data sending end and a data receiving end. Through the key generation submodule, a target service security level is determined based on the historical service data of the power system, a target key corresponding to each target service is generated, and a digital signature module is used to sign the summary data to ensure the security of data transmission.

Benefits of technology

By providing different levels of encryption keys for different services, the security of data transmission is improved, unnecessary encryption consumption is avoided, and the integrity and security of data during transmission is ensured through real-time and periodic key update mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378117A_ABST
    Figure CN120378117A_ABST
Patent Text Reader

Abstract

The invention discloses a digital signature system which comprises a secret key management module, a data sending end and a data receiving end. The key management module comprises a key generation sub-module which is used for generating a target key corresponding to each target service according to the security level of each target service of the power system; the data sending end is used for determining a target key corresponding to a service session request of a target service in response to the service session request of the target service; signing abstract data corresponding to the target service through the target key to obtain target signature data corresponding to the service session request; service data corresponding to the target service, the target signature data and the target service identifier are sent to a data receiving end; and the data receiving end comprises a digital signature verification module which is used for performing security verification on the data sending end according to the service data corresponding to the target service sent by the data sending module, the target signature data and the target service identifier. The security of power system data transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power system communication, and in particular, to a digital signature system and method. Background Art

[0002] With the development of power technology, it has become a relatively common technology to manage various power equipment through the power system. The embedded power system in the power system is an intelligent power system integrating various high-tech means such as microprocessor technology, communication technology, and power electronics technology, and is widely used in industrial automation, transportation, energy management, smart home and other fields. The embedded power system faces many security threats during operation, such as data tampering, illegal access, device hijacking, etc. These threats may lead to system failures, data leakage, or even the collapse of the entire power system.

[0003] In order to ensure the safe operation of the embedded power system, the existing technologies generally ensure the safe operation of the power system by means of encryption technology or setting up a firewall.

[0004] However, traditional security measures usually only protect a certain specific layer or link, and the operation process of the power system is relatively complex. The simple protection in the existing technology is difficult to meet the complex and changeable security requirements and environment of the embedded power system, and the security of the power system is relatively low. Summary of the Invention

[0005] The present invention provides a digital signature system and method to solve the problem of single data encryption technology and low security of encrypted data transmission in the existing technology.

[0006] According to one aspect of the present invention, a digital signature system is provided, including a key management module, a data sending end, and a data receiving end. It is characterized in that the key management module includes a key generation sub-module, the data sending end includes a key determination module, a digital signature module, and a data sending module, and the data receiving end includes a digital signature verification module; wherein,

[0007] The key generation sub-module is used to determine multiple target services of the power system according to the historical business data of the power system, as well as the security level of each target service, and generate a target key corresponding to each target service according to the security level of each target service;

[0008] The target key determination module is used to determine a target key corresponding to the service session request of the target service in response to the service session request for the target service;

[0009] The digital signature module is used to sign the digest data corresponding to the target service with the target key to obtain target signature data corresponding to the service session request;

[0010] The data sending module is used to send the service data corresponding to the target service, the target signature data and the target service identifier to the data receiving end;

[0011] The digital signature verification module is used to perform security verification on the data sending end according to the service data corresponding to the target service, the target signature data and the target service identifier sent by the data sending module.

[0012] According to another aspect of the present invention, a digital signature method is provided, which is applied to a digital signature system. The method includes:

[0013] The key generation sub-module determines multiple target services of the power system and the security level of each target service according to the historical service data of the power system, and generates a target key corresponding to each target service according to the security level of each target service;

[0014] The target key determination module determines a target key corresponding to the service session request of the target service according to the service session request for the target service;

[0015] The digital signature module signs the digest data corresponding to the target service with the target key to obtain target signature data corresponding to the service session request;

[0016] The data sending module sends the service data corresponding to the target service, the target signature data and the target service identifier to the data receiving end;

[0017] The digital signature verification module verifies the identity of the data sending end according to the service data corresponding to the target service, the target signature data and the target service identifier sent by the data sending module.

[0018] The technical solution of the embodiment of the present invention is as follows: The key generation sub-module determines multiple target services of the power system and the security level of each target service according to the historical service data of the power system, and generates a target key corresponding to each target service according to the security level of each target service. It can provide encryption keys of different levels for different services in the power system, improve the security of data transmission, and avoid the consumption caused by unnecessary encryption. The target key determination module determines the target key corresponding to the service session request of the target service in response to the service session request for the target service, and uses the digital signature module to sign the digest data corresponding to the target service with the target key to obtain the target signature data corresponding to the service session request. Finally, the data sending module sends the service data, target signature data, and target service identifier corresponding to the target service to the data receiving end, which can further ensure the secure transmission of data. The digital signature verification module is used to verify the security of the data sending end according to the service data, target signature data, and target service identifier corresponding to the target service sent by the data sending module, which can avoid data tampering during transmission and improve the security of data transmission.

[0019] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0021] Figure 1 FIG. 1 is a schematic structural diagram of a digital signature system according to Embodiment 1 of the present invention;

[0022] Figure 2 FIG. 2 is a schematic structural diagram of another digital signature system according to Embodiment 2 of the present invention;

[0023] Figure 3 FIG. 3 is a flowchart of a digital signature method according to Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0026] Embodiment 1

[0027] Figure 1 A structural schematic diagram of a digital signature system is provided for Embodiment 1 of the present invention. This embodiment is applicable to the situation of signing data that needs to be transmitted in a target service. The system can be implemented in the form of hardware and / or software. As Figure 1 shown, the digital signature system includes: a key management module 110, a data sender 120, and a data receiver 130; the key management module 110 includes a key generation sub-module 111, the data sender includes a key determination module 121, a digital signature module 122, and a data sending module 123, and the data receiver 130 includes a digital signature verification module 131.

[0028] The key generation sub-module 111 can be used to determine multiple target services of the power system and the security level of each target service according to the historical service data of the power system, and generate target keys corresponding to each target service according to the security level of each target service.

[0029] Among them, the power system can be a system composed of multiple ports such as power plants, transmission lines, substations, distribution systems, and end-user equipment in the power grid, and can be responsible for operations such as power generation, transmission, distribution, and use in the power grid system. Different business scenarios in the power system (such as power dispatching or equipment monitoring and other power services) have different requirements for data security. The power system can include an embedded power system, which includes at least one data sender and at least one data receiver. The data sender can be a device terminal that sends data, and the data receiver can be a device terminal that receives data. It should be noted that the same terminal can be a data sender or a data receiver when processing different services.

[0030] Among them, the historical business data can be the business data records generated during the business process of the power system in the processing system. The target business can be a business in the power system with data security transmission requirements. The specific scope of the target business of the present invention is not specifically limited, and can be determined according to the power system scope and business scope specified by the user, or the target business in the power system can be determined by other means. The security level can be the security level corresponding to each target business determined after analyzing the historical business data recording the execution process of the target business in the power system. The target key can be generated by a corresponding digital signature generation algorithm according to the security level corresponding to each target business, and is the key corresponding to each target business. The target key can be used to sign and verify the business data corresponding to the target business.

[0031] The key generation sub-module can include a system service determination unit 1111, a service risk value calculation unit 1112, and a key generation unit 1113. The system service determination unit 1111 can be used to obtain the historical business data of the power grid system, and determine multiple target services of the power grid system and the service risk probability and service risk impact value of each target service according to the historical business data.

[0032] Among them, the service risk probability can be the probability of risks such as data tampering, illegal access, and equipment hijacking occurring during the execution of the target service. The service risk probability can be determined according to the number of times of service risks occurring for each target service after analyzing the historical business data, or can be determined by other means. The service risk impact value can be the impact on the power system after a service risk occurs during the execution of the target service. The service risk impact value can be determined according to the impact on the hardware equipment or other resources in the power system after the target service has a service risk in the historical data, or can be determined according to the service data corresponding to each target service or other means. The embodiments of the present invention do not specifically limit the determination methods of the service risk probability and the service risk impact value.

[0033] The business risk value calculation unit 1112 is configured to determine the business risk value corresponding to each target business according to the business risk probability and the business risk impact value corresponding to each target business.

[0034] Among them, the business risk value can be determined according to the business risk probability and the business risk impact value corresponding to each target business. For example, the business risk value can be determined according to the product of the business risk probability and the business risk impact value, or can be determined according to the preset weights corresponding to the business risk probability and the business risk impact value. The embodiments of the present invention do not specifically limit the method for determining the business risk value.

[0035] The key generation unit 1113 is configured to determine the security level corresponding to each target business according to the business risk value corresponding to each target business, and generate a target key corresponding to each target business according to the security level of each target business.

[0036] Among them, the security level can be determined according to the business risk value corresponding to the target business, and the security level corresponding to each target business. The security level can include multiple levels such as system level, device level, and user level, and different security levels correspond to different key generation algorithms and different key generation parameters.

[0037] Specifically, the key generation unit 1113 is configured to: determine the key generation algorithm and the key generation parameters corresponding to each target business according to the security level of each target business, where the key generation parameters include the key valid time and the key length; and generate a target key corresponding to each target business according to the key generation parameters corresponding to each target business through the key generation algorithm.

[0038] Among them, the key generation algorithm can be an algorithm for generating a target key corresponding to a target service. For example, key generation algorithms such as the RSA cryptographic algorithm (a type of asymmetric encryption algorithm. Different from symmetric encryption algorithms, the RSA algorithm has two different keys, one is the public key and the other is the private key) and ECC (Elliptic Curve Cryptography). The key generation parameters can be the parameter information of the key when generating the key through the key generation algorithm. The key generation parameters can include parameters such as the key validity period and the key length. The key validity period can be the maximum time that the key can be used after it is generated. For example, during the key usage period, if there is no business risk or the number of business risks is small for the service corresponding to the key, the key can be used all the time until the key usage time is reached. If there is one or more business risks for the service corresponding to the key, the key can be directly replaced and updated when the business risk occurs before the key usage time is reached. The key length can be determined according to the different security levels corresponding to different target services, which is the length of the key. The key length can be 2048 bits or a higher number of bits, or it can also be 1024 bits or 512 bits. The specific key length corresponding to different services can be determined according to user requirements and the security levels of different services, or it can be determined by other means. The embodiments of the present invention do not specifically limit the determination method of the key length.

[0039] Optionally, the key management module 110 may further include a key storage sub-module 112 and a key distribution sub-module 113. The key storage sub-module 112 can be used to store the target key generated by the key generation sub-module. The key distribution sub-module 113 can be used to determine multiple data senders and multiple data receivers corresponding to each target service, and distribute the target key corresponding to each target service to the multiple data senders and multiple data receivers corresponding to the target service. The key management module can also be used to back up the target key for quickly restoring the key when the target key is lost or damaged. It should be noted that when distributing the target key, if the same terminal can be used to execute multiple target services, the target keys corresponding to all services that the terminal can execute are distributed to the terminal. For example, when terminal A is the data sender of the target service data when executing service a, and terminal B is the data receiver of the target service data when executing service a, the private key of the key corresponding to service a is distributed to terminal A, and terminal A signs the data with the private key of the key corresponding to service a. The public key of the key corresponding to service a is distributed to terminal B, and terminal B verifies the signed data with the public key of the key corresponding to service a.

[0040] The target key determination module 121 is configured to determine a target key corresponding to the service session request of the target service in response to the service session request for the target service.

[0041] Among them, the service session request can be a service request sent by the data sending end to the data receiving end. For example, the service session request can be a service request such as device A sending a request to modify the configuration parameters of device B or obtain the data collected by device B.

[0042] The digital signature module 122 is used to sign the digest data corresponding to the target service with the target key to obtain the target signature data corresponding to the service session request.

[0043] Among them, the digest data can be a fixed-length data representation obtained by processing the data to be signed through a preset hash algorithm. The hash algorithm is a one-way function that can convert an input of any length into an output of a fixed length. The generated digest data is much shorter than the original data to be signed, but contains enough information to verify the integrity of the data. The target signature data can be the signature data obtained by signing the digest data with the private key corresponding to the target service.

[0044] Specifically, the digital signature module 122 can be used to: obtain the service data corresponding to the target service, and convert the data to be signed in the service data into digest data of a preset length through a preset hash algorithm.

[0045] Among them, the data to be signed can be the service data corresponding to the target service that needs to be digitally signed. The preset hash algorithm can be a preset hash algorithm, such as the SHA-256 algorithm (Secure Hash Algorithm 256-bit, a cryptographic hash function belonging to the SHA-2 series of algorithms), the SHA-3 algorithm (Secure Hash Algorithm 3, the third-generation secure hash algorithm), and other hash algorithms.

[0046] The data sending end 120 is further used to determine the target key corresponding to the target service from the target keys issued by the key distribution sub-module, and sign the digest data with the private key of the target key to obtain the target signature data corresponding to the service session request.

[0047] Specifically, after determining the target service to be executed by the target sending end, the target key corresponding to the target service can be determined from the multiple target keys issued according to the identification information of the target service corresponding to the service session request, and then the digest data is signed with the private key of the target key corresponding to the target service, thereby obtaining the target signature data corresponding to the service session request.

[0048] The data sending module 123 is used to send the service data corresponding to the target service, the target signature data, and the target service identifier to the data receiving end.

[0049] Among them, the service data can be data directly related to the target service. For example, the service data is necessary for executing the target service, or is data generated and used during the service process. The target service identifier can be an identifier used to uniquely identify and distinguish different services. The target service identifier can be used to represent the currently executed or requested target service. By setting different target service identifiers for different target services, the corresponding target key can be determined according to the target service identifier of each target service, and the data can be signed with the private key of the target key. Furthermore, on the basis of ensuring the secure transmission of data, the risk of data being tampered with is reduced.

[0050] The digital signature verification module 131 can be used to verify the security of the data sender according to the service data, target signature data, and target service identifier corresponding to the target service sent by the data sending module.

[0051] Specifically, the digital signature verification module 131 can be used to: perform a hash calculation on the data to be signed in the service data through a preset hash algorithm to obtain recalculated digest data corresponding to the service data; and determine the target key corresponding to the target service from the target keys issued by the key distribution sub-module according to the target service identifier, and verify the identity of the data sender according to the public key of the target key, the recalculated digest data, and the target signature data.

[0052] Exemplarily, after receiving the data packet containing the service data, target signature data, and target service identifier corresponding to the target service transmitted by the data sending module, the digital signature verification module can perform a hash process on the part of the service data to be signed by using a preset hash algorithm to generate a recalculated digest data. According to the target service identifier, select the public key corresponding to the target key that matches the target service from one or more target keys provided by the key distribution sub-module. The verification module verifies the digital signature according to the public key corresponding to the target key, the recalculated digest data, and the target signature data. If the data obtained by decrypting or verifying through the public key is consistent with the recalculated digest data, it is determined that the identity of the data sender is valid and the data has not been tampered with, and the signature verification is passed; if the data does not match, it is determined that the identity of the data sender is in doubt or the data has been tampered with during transmission, and the verification fails. By signing and verifying the data with the target key, the security of data transmission can be improved, and the integrity of the data can be further ensured.

[0053] The technical solution of the embodiment of the present invention can determine multiple target services of the power system and the security level of each target service according to the historical service data of the power system through the key generation sub-module, and generate target keys corresponding to each target service according to the security level of each target service. It can provide different levels of encryption keys for different services in the power system, improve the security of data transmission of higher-level target services, and avoid the consumption caused by encryption during the signature verification of lower-level target keys. By the target key determination module, in response to a service session request for a target service, it determines the target key corresponding to the service session request for the target service, and uses the digital signature module to sign the digest data corresponding to the target service through the target key to obtain the target signature data corresponding to the service session request. Finally, through the data sending module, it sends the service data corresponding to the target service, the target signature data, and the target service identifier to the data receiving end, which can further ensure the secure transmission of data. The digital signature verification module is used to perform security verification on the data sending end according to the service data, the target signature data, and the target service identifier corresponding to the target service sent by the data sending module, which can avoid data tampering during transmission and improve the security of data transmission.

[0054] Embodiment 2

[0055] Figure 2 It is a schematic structural diagram of a digital signature system provided by Embodiment 2 of the present invention. As Figure 2 shown, the digital signature system further includes: an anomaly monitoring module 140 and an anomaly handling module 150; the key management module further includes a first key update sub-module 114 and a second key update sub-module 115.

[0056] The anomaly monitoring module 140 is used to perform anomaly detection on the service execution data of all target services in the power system, and when it monitors that the service execution data in the power system meets the preset anomaly conditions, it sends the anomaly execution data, the anomaly service identifier corresponding to the anomaly execution data, and the service anomaly data to the anomaly handling module.

[0057] Among them, anomaly detection can be an operation of detecting devices, networks, and other associated objects involved in the execution of a target service during the execution of the target service in a power system. For example, by deploying a network traffic monitoring tool to analyze network traffic in real time to detect whether there is abnormal traffic; or monitoring the device status, including sudden changes in sensor readings or abnormal behavior of the controller, and determining whether the device has been hijacked or damaged by analyzing the abnormal behavior. The preset anomaly condition can be a set of rules or thresholds preset for judging whether the service execution data during the execution of the target service is abnormal. For example, conditions such as data deviation exceeding a certain range, the occurrence of a specific error code, or network fluctuations. The detection scheme of anomaly detection in the embodiments of the present invention is not specifically limited, and the setting range of the preset anomaly condition is also not specifically limited. Those skilled in the art can determine the detection scheme of anomaly detection and the setting range of the preset anomaly condition according to actual anomaly detection requirements.

[0058] Among them, the abnormal execution data can be the abnormal execution data corresponding to the target service in the power system when the service execution data meets the preset anomaly condition during the execution of the target service. The abnormal service identifier can be data or a label used to uniquely identify the service with an anomaly. The service anomaly data can be data related to the abnormal execution data and used for further analysis or processing. For example, data such as error logs or abnormal status information.

[0059] The anomaly handling module 150 is configured to determine the abnormal target service according to the abnormal service identifier and determine the anomaly response strategy for the abnormal target service according to the service anomaly data.

[0060] Among them, the anomaly response strategy can be formulated for the abnormal target service and is used to restore the normal operation of the service or mitigate the impact of the anomaly. For example, if the digital signature verification of the device executing the target service fails, the affected device can be isolated, the operation permissions of relevant users can be suspended, or a backup system can be started, and the affected device can be repaired, the key can be updated, and the data can be restored.

[0061] The first key update sub-module 114 can be used to update the target key corresponding to the abnormal target service in real time.

[0062] Specifically, after the anomaly monitoring module of the power system detects that the target service meets the preset update conditions, the specific target service is located according to the service identifier of the target service, and the service identifier of the target service is sent to the key management module. After receiving the abnormal service identifier, the key module forwards it to the key management subsystem. After receiving the abnormal service identifier, the key management subsystem can identify the target key associated with the target service according to the abnormal service identifier, generate a new key through the key generation unit to replace the original target key, and update the old key corresponding to the target service stored in the key storage unit with the newly generated key.

[0063] The second key update sub-module 115 is used to periodically obtain the service logs of the power system according to the preset update period, determine the security level information corresponding to each target service in the power system according to the service logs; and periodically update the target keys corresponding to the target services in the power system according to the security level information of each target service.

[0064] Among them, the preset update period can be preset and is used to define the time interval of the key update frequency. The embodiment of the present invention does not specifically limit the cycle duration of the preset update period, and those skilled in the art can set the cycle duration of the preset update period according to the update requirements. The service log can be a log used to record information such as the operation status and security events of the target service in the power system. The security level information can be the level or score for evaluating the security of the target service analyzed from the service log.

[0065] Specifically, periodically obtaining the service logs of the power system according to the preset update period, determining the security level information corresponding to each target service in the power system according to the service logs, and updating the target keys corresponding to the target services in the power system can collect the service logs generated during the preset period from each service system of the power system after reaching the end time of the preset period, and determine the security level information corresponding to each target service in the power system by analyzing the service logs. The key management module generates new keys according to the security level information corresponding to each target service in the power system and updates the target keys corresponding to each target service. Exemplarily, the key generation sub-module generates a new key according to the latest security requirements, and then the key storage sub-module replaces the original target key with the newly generated key, so as to ensure that the target services in the power system maintain the latest security status at the key level. It can further improve the security and operation and maintenance efficiency of the power system.

[0066] In the technical solution of the embodiment of the present invention, the key generation sub-module generates a target key corresponding to each target service according to the security level of each target service, which can provide different levels of encryption keys for different services in the power system, improve the security of data transmission, and avoid the consumption caused by unnecessary encryption. The digital signature module signs the digest data corresponding to the target service through the target key to obtain the target signature data corresponding to the service session request, and the digital signature verification module verifies the security of the data sender according to the service data, target signature data and target service identifier corresponding to the target service sent by the data sending module, which can avoid data tampering during transmission and improve the security of data transmission. By setting the first update sub-module to update the target key corresponding to the abnormal target service in real time, it can respond to the abnormality in real time and update the key to quickly cope with potential security threats; by setting the second update sub-module to periodically obtain the service logs of the power system according to the preset update period, determine the security level information corresponding to each target service in the power system; and update the target key corresponding to the target service in the power system periodically according to the security level information of each target service, which can update the key periodically to ensure that the key always meets the latest security requirements. Through the settings of the first update sub-module and the second update sub-module, the security and reliability of the power system can be further improved.

[0067] Embodiment III

[0068] Figure 3 It is a flowchart of a real-time data processing method for the transmission edge side based on a multi-level deployment architecture provided by Embodiment III of the present invention. As Figure 3 shown, the method includes:

[0069] S310. Determine multiple target services of the power system and the security level of each target service according to the historical service data of the power system through the key generation sub-module, and generate a target key corresponding to each target service according to the security level of each target service.

[0070] S320. Determine the target key corresponding to the service session request of the target service through the target key determination module according to the service session request for the target service.

[0071] S330. Sign the digest data corresponding to the target service through the digital signature module according to the target key to obtain the target signature data corresponding to the service session request.

[0072] S340. Send the service data, target signature data and target service identifier corresponding to the target service to the data receiving end through the data sending module.

[0073] S350. The digital signature verification module verifies the identity of the data sender according to the service data corresponding to the target service, the target signature data, and the target service identifier sent by the data sending module.

[0074] In the technical solution of the embodiment of the present invention, the key generation sub-module determines multiple target services of the power system and the security level of each target service according to the historical service data of the power system, and generates a target key corresponding to each target service according to the security level of each target service, which can provide different levels of encryption keys for different services in the power system. While improving the security of data transmission, it avoids the consumption caused by unnecessary encryption. The target key determination module determines the target key corresponding to the service session request of the target service in response to the service session request for the target service, and uses the digital signature module to sign the digest data corresponding to the target service with the target key to obtain the target signature data corresponding to the service session request. Finally, through the data sending module, the service data corresponding to the target service, the target signature data, and the target service identifier are sent to the data receiving end, which can further ensure the secure transmission of data. The digital signature verification module verifies the security of the data sender according to the service data corresponding to the target service, the target signature data, and the target service identifier sent by the data sending module, which can avoid data tampering during transmission and improve the security of data transmission.

[0075] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitations are imposed herein.

[0076] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A digital signature system, characterized in that, It includes a key management module, a data sender, and a data receiver. The key management module includes a key generation sub-module. The data sender includes a key determination module, a digital signature module, and a data sending module. The data receiver includes a digital signature verification module. Among them, The key generation sub-module is used to determine multiple target services of the power system and the security level of each target service according to the historical business data of the power system, and generate a target key corresponding to each target service according to the security level of each target service; The target key determination module is used to determine a target key corresponding to the service session request of the target service in response to the service session request for the target service; The digital signature module is used to sign the digest data corresponding to the target service through the target key to obtain target signature data corresponding to the service session request; The data sending module is used to send the service data corresponding to the target service, the target signature data, and the target service identifier to the data receiver; The digital signature verification module is used to perform security verification on the data sender according to the service data corresponding to the target service, the target signature data, and the target service identifier sent by the data sending module.

2. The digital signature system according to claim 1, characterized in that, The key generation sub-module includes a system service determination unit, a service risk value calculation unit, and a key generation unit. Among them, The system service determination unit is used to obtain the historical business data of the power grid system, and determine multiple target services of the power grid system and the service risk probability and service risk impact value of each target service according to the historical business data; The service risk value calculation unit is used to determine the service risk value corresponding to each target service according to the service risk probability and service risk impact value corresponding to each target service; The key generation unit is used to determine the security level of each target service according to the service risk value corresponding to each target service, and generate a target key corresponding to each target service according to the security level of each target service.

3. The digital signature system according to claim 2, characterized in that, Specifically, the key generation unit is used to determine the key generation algorithm and key generation parameters corresponding to each target service according to the security level of each target service, where the key generation parameters include the key validity period and the key length; and generate a target key corresponding to each target service through the key generation algorithm according to the key generation parameters corresponding to each target service.

4. The digital signature system according to claim 1, characterized in that, The key management module further includes a key storage sub-module and a key distribution sub-module. Among them, The key storage sub-module is used to store the target keys generated by the key generation sub-module; The key distribution sub-module is used to determine multiple data senders and multiple data receivers corresponding to each target service, and distribute the target key corresponding to each target service to the multiple data senders and multiple data receivers corresponding to the target service.

5. The digital signature system according to claim 4, characterized in that, The digital signature module is specifically configured to: obtain service data corresponding to the target service, and convert the data to be signed in the service data into digest data of a preset length through a preset hashing algorithm; The data sender is further configured to determine a target key corresponding to the target service from the target keys issued by the key distribution sub-module, and sign the digest data with the private key of the target key to obtain target signature data corresponding to the service session request.

6. The digital signature system according to claim 4, characterized in that, The digital signature verification module is specifically configured to: perform hashing calculation on the data to be signed in the service data through a preset hashing algorithm to obtain recalculated digest data corresponding to the service data; and determine a target key corresponding to the target service from the target keys issued by the key distribution sub-module according to the target service identifier, and verify the identity of the data sender according to the recalculated digest data and the target signature data with the public key of the target key.

7. The digital signature system according to claim 1, characterized in that, The digital signature system further includes an anomaly monitoring module and an anomaly handling module; wherein, The anomaly monitoring module is configured to perform anomaly detection on the service execution data of all target services in the power system, and when it is detected that the service execution data in the power system meets a preset anomaly condition, send the abnormal execution data, the abnormal service identifier corresponding to the abnormal execution data, and service anomaly data to the anomaly handling module; The anomaly handling module is configured to determine the abnormal target service according to the abnormal service identifier, and determine an abnormal response strategy for the abnormal target service according to the service anomaly data; The key management module further includes a first key update sub-module, and the first key update sub-module is configured to update the target key corresponding to the abnormal target service in real time.

8. The digital signature system according to claim 1, characterized in that, The key management module further includes a second key update sub-module; wherein, the second key update sub-module is configured to periodically obtain the service logs of the power system according to a preset update period, determine the security level information corresponding to each target service in the power system according to the service logs; and periodically update the target keys corresponding to the target services in the power system according to the security level information of each target service.

9. The digital signature system according to claim 1, characterized in that The power system includes an embedded power system, and the embedded power system includes at least one data sender and at least one data receiver.

10. A digital signature method, characterized in that, Applied to the digital signature system according to any one of claims 1-9, the method includes: Determining multiple target services of the power system and the security level of each target service according to the historical service data of the power system by the key generation sub-module, and generating a target key corresponding to each target service according to the security level of each target service; Determining a target key corresponding to the service session request of the target service according to the service session request for the target service by the target key determination module; The digital signature module signs the digest data corresponding to the target service according to the target key to obtain target signature data corresponding to the service session request; The data sending module sends the service data corresponding to the target service, the target signature data, and the target service identifier to the data receiving end; The digital signature verification module verifies the identity of the data sending end according to the service data corresponding to the target service, the target signature data, and the target service identifier sent by the data sending module.

Citation Information

Cited By

  • A software security upgrade method and system based on a trusted node of a power monitoring system

    CN122593811A