Data transmission method, device and equipment of embedded power system and storage medium

By combining symmetric and asymmetric encryption algorithms to encrypt the data of the embedded power system and verify its attribute information at the sensor nodes, the problem of low security in data transmission of embedded power system is solved, and more efficient and secure data transmission is achieved, improving the stability and security of the system.

CN120378174APending Publication Date: 2025-07-25CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510557548.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The data transmission security of embedded power systems is low and vulnerable to attacks, affecting the safe operation of the system and data integrity.

Method used

The combination of symmetric encryption algorithm and asymmetric encryption algorithm is used to encrypt the initial power data, and the attribute information of the sensor node is verified through a distributed soft bus controller to ensure the security of data transmission.

Benefits of technology

It improves the security of data transmission and system reliability, protects the normal operation of the power system and data security, and enhances the ability to resist attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378174A_ABST
    Figure CN120378174A_ABST
Patent Text Reader

Abstract

The invention discloses a data transmission method and device of an embedded power system, equipment and a storage medium. The method comprises the following steps: acquiring initial power data acquired by a sensor node of an embedded power system, and encrypting the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data; and verifying the node attribute information of the sensor node, and transmitting the encrypted power data to a terminal under the condition that the node attribute information is successfully verified. And the data transmission security of the embedded power system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and in particular to a data transmission method, device, equipment and storage medium for an embedded power system. Background Art

[0002] With the rapid development of smart power systems, especially in distributed power monitoring, smart sensor networks and data acquisition, more and more embedded devices are widely used in all aspects of power systems. These devices collect real-time power data through sensor nodes and transmit them to achieve comprehensive monitoring and intelligent scheduling of power systems. However, as the scale of smart power systems continues to expand, security and reliability issues have gradually become one of their core challenges.

[0003] Embedded power systems usually rely on wireless sensor networks or other similar distributed network structures. These networks involve a large number of sensor nodes, which collect and transmit a large amount of sensitive power data, including key information such as voltage, current, and load. Once this data is leaked, it may have a serious impact on the safe operation of the power system. For example, attackers can obtain real-time data from the power system to infer the operating status, load conditions, and potential fault locations of the equipment, thereby maliciously attacking or manipulating the system. Therefore, how to ensure the confidentiality, integrity, and availability of data in various links such as data collection, transmission, and storage has become a core technical problem that needs to be solved in the current power system. Summary of the invention

[0004] The present invention provides a data transmission method, device, equipment and storage medium of an embedded power system to solve the problem of low data transmission security of the embedded power system.

[0005] According to one aspect of the present invention, a data transmission method for an embedded power system is provided, the method comprising:

[0006] Acquire initial power data collected by sensor nodes of the embedded power system, and encrypt the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data;

[0007] The node attribute information of the sensor node is verified, and when the node attribute information is successfully verified, the encrypted power data is transmitted to the terminal.

[0008] According to another aspect of the present invention, there is provided a data transmission device for an embedded power system, the device comprising:

[0009] A data acquisition module, configured to acquire initial power data collected by sensor nodes of an embedded power system, and encrypt the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data;

[0010] A data transmission module, configured to verify the node attribute information of the sensor nodes, and transmit the encrypted power data to a terminal when the verification of the node attribute information is successful.

[0011] According to another aspect of the present invention, there is provided an electronic device, including:

[0012] At least one processor; and

[0013] A memory communicatively connected to the at least one processor; wherein,

[0014] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data transmission method of the embedded power system according to any embodiment of the present invention.

[0015] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the data transmission method of the embedded power system according to any embodiment of the present invention when executed.

[0016] The technical solution of the embodiment of the present invention encrypts the initial power data collected by the sensor nodes of the embedded power system based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data; combines the symmetric encryption algorithm and the asymmetric encryption algorithm to efficiently encrypt the power data, which not only ensures the security of data transmission but also improves the efficiency of encryption and decryption. Then, the node attribute information of the sensor nodes is verified, and when the verification of the node attribute information is successful, the encrypted power data is transmitted to the terminal, enhancing the security of the entire power system, protecting the normal operation of the power system and the security of data, solving the problem of low data transmission security of the embedded power system, and achieving the beneficial effects of improving the data transmission security of the embedded power system, and improving the reliability and stability of the power system.

[0017] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings

[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0019] Figure 1 It is a flowchart of a data transmission method for an embedded power system according to Embodiment 1 of the present invention;

[0020] Figure 2 It is a flowchart of a data transmission method for an embedded power system according to Embodiment 2 of the present invention;

[0021] Figure 3 It is a schematic structural diagram of a data transmission device for an embedded power system according to Embodiment 3 of the present invention;

[0022] Figure 4 It is a schematic structural diagram of an electronic device for implementing the data transmission method of the embedded power system in the embodiments of the present invention. Detailed Embodiments

[0023] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0024] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0025] Embodiment 1

[0026] Figure 1The following is a flowchart of a data transmission method for an embedded power system provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of data transmission in an embedded power system. This method can be executed by a data transmission device of the embedded power system. The data transmission device of the embedded power system can be implemented in the form of hardware and / or software, and the data transmission device of the embedded power system can be configured in an electronic device. As Figure 1 shown, the method includes:

[0027] S110. Obtain the initial power data collected by the sensor nodes of the embedded power system, and encrypt the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data.

[0028] Among them, the embedded power system can be understood as a system based on applying embedded technology to the power system. The sensor node can be understood as a micro-embedded device. The initial power data can be understood as the original power data collected by the sensor nodes in the power system. The encrypted power data can be understood as the data obtained by encrypting the initial power data.

[0029] Specifically, obtain the initial power data collected by the sensor nodes. Among them, the initial power data can include power data such as current, voltage, and power factor. Combine and encrypt the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data.

[0030] Optionally, encrypting the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data includes: generating a first key corresponding to the initial power data through the symmetric encryption algorithm, encrypting the initial power data based on the first key to obtain the encrypted initial power data; encrypting the first key based on the public key of the receiving end through the asymmetric encryption algorithm to obtain the encrypted first key; determining the encrypted power data based on the encrypted initial power data and the encrypted first key.

[0031] Among them, the first key can be understood as the key of the symmetric encryption algorithm.

[0032] Specifically, randomly generate a first key corresponding to the initial power data through the symmetric encryption algorithm, and encrypt the initial power data using the generated first key and the symmetric encryption algorithm. Generate a pair of public and private keys of the receiving end through the asymmetric encryption algorithm, and encrypt the first key based on the public key of the receiving end to obtain the encrypted first key. Combine the encrypted initial power data and the encrypted first key to obtain the encrypted power data.

[0033] Optionally, encrypt the initial power data based on the first key to obtain the encrypted initial power data, which is expressed by the formula as follows:

[0034] C′2 = AES Enerypt (C2, K AES );

[0035] where C′2 represents the encrypted initial power data, C2 represents the compressed initial power data, and K AES represents the first key.

[0036] Optionally, encrypt the first key based on the public key of the terminal through an asymmetric encryption algorithm to obtain the encrypted first key, which is expressed by the formula as follows:

[0037]

[0038] where K′ AES represents the encrypted first key, K AES represents the first key, represents the public key of the receiving end.

[0039] Optionally, before encrypting the initial power data based on the symmetric encryption algorithm and the asymmetric encryption algorithm, it further includes:

[0040] Determine the data type corresponding to the initial power data. In the case where the data type is time series data, perform differential coding processing on the initial power data, and update the initial power data based on the data after the coding processing.

[0041] Among them, time series data can be understood as data arranged in chronological order, such as power parameters such as current and voltage that change over time.

[0042] Specifically, determine the data type corresponding to the initial power data. By checking the structure and content of the data, determine whether it is time series data. If it is determined that the data type is time series data, perform differential coding processing. Select the first data point as the initial value, and starting from the second data point, calculate the difference between the current data point and the previous data point in turn, and use the calculated difference sequence as the data sequence after differential coding. Exemplarily, calculate the difference between adjacent data points through the following formula:

[0043] Δd i = d i - d i-1 , i = 2, 3,..., n;

[0044] where Δd i represents the difference of the i-th data point, and d iThe i-th data point in the data sequence representing the initial power data; d i-1 The (i - 1)-th data point in the data sequence representing the initial power data;

[0045] Convert the initial power data into a differentially encoded data sequence:

[0046] D’ = d1, Δd2, Δd3, …, Δd n ;

[0047] where D’ represents the differentially encoded data sequence.

[0048] Optionally, after obtaining the initial power data collected by at least one sensor node of the embedded power system, it further includes: performing denoising processing and / or compression processing on the initial power data, and updating the initial power data based on the processed data.

[0049] Specifically, a data vector is generated by collecting data through the sensor node, the data vector is denoised, and the denoised data vector is compressed using a preset compression algorithm, and the initial power data is updated based on the processed data.

[0050] Exemplarily, the LZ4 compression algorithm and the Zstd (Z standard compression algorithm) are used to compress the preprocessed data to obtain the compressed data.

[0051] Exemplarily, for the differentially encoded data sequence, the LZ4 algorithm is used for preliminary compression:

[0052] C1 = LZ4 Compress D’;

[0053] where C1 represents the data after LZ4 compression, and D’ represents the differentially encoded data sequence. The data after LZ4 compression is compressed using the Zstd compression algorithm:

[0054] C2 = Zstd Compress C1;

[0055] where C2 represents the data obtained after compression using the Zstd compression algorithm, that is, the compressed initial power data.

[0056] S120. Verify the node attribute information of the sensor node, and when the verification of the node attribute information is successful, transmit the encrypted power data to the terminal.

[0057] Among them, node attribute information can be understood as data for identifying the characteristics and status of sensor nodes. The terminal can be a user terminal. The node attribute information may include the unique identifier of the node (such as MAC address, serial number, etc.), the type of the node, location, manufacturer information, firmware version, etc.

[0058] Specifically, necessary attribute information is collected from the sensor nodes. This information may include the unique identifier of the node (such as MAC address, serial number, etc.), the type of the node, location, manufacturer information, firmware version, etc. The node attribute information is verified by the distributed soft bus controller. When the verification of the node attribute information is successful, the encrypted power data is transmitted to the terminal.

[0059] Optionally, after transmitting the encrypted power data to the terminal, it further includes:

[0060] Decrypt the encrypted first key based on the private key of the receiving end to obtain the first key; decrypt the encrypted initial power data based on the first key to obtain the initial power data.

[0061] Specifically, the receiving end first uses the private key of the receiving end to decrypt the encrypted first key to obtain the first key. Use the decrypted first key to decrypt the encrypted initial power data, recover the compressed initial power data, and decompress the compressed initial power data to obtain the initial power data.

[0062] Exemplarily, the receiving end first uses the private key of the receiving end to decrypt the encrypted first key, which is expressed by the formula as follows:

[0063]

[0064] Among them, K′ RSA represents the encrypted first key; K AES represents the decrypted first key;

[0065] Use the decrypted first key to decrypt the encrypted initial power data to recover the compressed initial power data:

[0066] C2 = AES Decrypt (C′2, K AES );

[0067] Among them, C2 represents the initial power data after compression processing. C′2 represents the encrypted initial power data.

[0068] Use Zstd to decompress the compressed initial power data to obtain the LZ4 compressed data, which is expressed by the formula as follows:

[0069] C1 = Zstd Decompress (C2);

[0070] Next, the data C1 compressed by LZ4 is decompressed using LZ4 to restore the initial power data, which is expressed by the formula as follows:

[0071] D = LZ4 Decompress (C1);

[0072] Among them, D represents the initial power data.

[0073] The technical solution of the embodiment of the present invention obtains the initial power data collected by the sensor nodes of the embedded power system, and encrypts the initial power data based on the symmetric encryption algorithm and the asymmetric encryption algorithm to obtain the encrypted power data; combines the symmetric encryption algorithm and the asymmetric encryption algorithm to encrypt the power data efficiently, which not only ensures the security of data transmission but also improves the efficiency of encryption and decryption. Then, the node attribute information of the sensor node is verified. When the verification of the node attribute information is successful, the encrypted power data is transmitted to the terminal, enhancing the security of the entire power system, protecting the normal operation of the power system and the security of data, solving the problem of low data transmission security of the embedded power system, and achieving the beneficial effects of improving the data transmission security of the embedded power system, improving the reliability and stability of the power system.

[0074] Embodiment 2

[0075] Figure 2 FIG. is a flowchart of a data transmission method for an embedded power system provided by Embodiment 2 of the present invention. This embodiment further refines how to verify the node attribute information of the sensor node in the above embodiment. Optionally, the verification of the node attribute information of the sensor node includes: when it is queried that the database stores the corresponding information of the node attribute information corresponding to the sensor node, sending a challenge value to the sensor node through the distributed soft bus controller; encrypting the challenge value by the sensor node and sending the encrypted challenge value to the distributed soft bus controller; decrypting the encrypted challenge value by the distributed soft bus controller, and verifying the node attribute information of the sensor node based on the decrypted challenge value and the challenge value.

[0076] As Figure 2 shown, the method includes:

[0077] S210. Obtain the initial power data collected by the sensor nodes of the embedded power system, and encrypt the initial power data based on the symmetric encryption algorithm and the asymmetric encryption algorithm to obtain the encrypted power data.

[0078] S220. When the corresponding information of the node attribute information corresponding to the sensor node is stored in the database, send a challenge value to the sensor node through the distributed soft bus controller.

[0079] Among them, the distributed soft bus controller can be understood as a component responsible for managing and controlling soft bus communication in a distributed system. The challenge value can be understood as a parameter for verifying or testing the security of the sensor node.

[0080] Specifically, each sensor node has a unique node identifier and key pair. When the sensor node needs to send data, it sends a node authentication request to the distributed soft bus controller C. The request content is expressed by the following formula:

[0081] Requert i =(ID i ,T i );

[0082] Among them, ID i represents the node identifier of the sensor node S i , and T i represents the timestamp.

[0083] When the sensor node sends a node authentication request, it encrypts the request data using the public key encryption algorithm, which is expressed by the following formula:

[0084]

[0085] Among them, represents encrypting the node authentication request using the public key of the sensor node.

[0086] After receiving the node authentication request from the sensor node, the distributed soft bus controller C first decrypts the node authentication request and extracts the node identifier ID i and the timestamp T i of the sensor node; then verifies whether the sensor node S i is legal by querying the database. If it is not legal, it ends; if it is legal, the distributed soft bus controller C generates a dynamic node token as an authentication credential, which is expressed by the following formula:

[0087] T′ i =(ID i ,R C ,T i );

[0088] Among them, R C represents the random number generated by the distributed soft bus controller, and T′ i represents the dynamic node token, IDi Denote the sensor node S i with the node identifier.

[0089] The distributed soft bus controller encrypts the dynamic node token with its private key and sends it to the sensor node S i , where the transmitted data is expressed by the following formula:

[0090]

[0091] Wherein, denotes encryption of the dynamic identity token T′ by the private key of the distributed soft bus controller i .

[0092] After receiving the encrypted identity token EncryptedToken i , the sensor node S i uses its own private key to decrypt the identity token to obtain the dynamic node token.

[0093] The distributed soft bus controller sends a dynamic challenge value Challenge C to the sensor node. The dynamic challenge value can be a randomly generated value, expressed by the following formula:

[0094] Challenge C = Rand(D);

[0095] Wherein, Rand(D) represents a random number generated by the distributed soft bus controller, i.e., the challenge value.

[0096] S230. Encrypt the challenge value through the sensor node and send the encrypted challenge value to the distributed soft bus controller.

[0097] Specifically, the sensor node uses the private key to encrypt the challenge value Challenge C and then sends the encryption result back to the controller, expressed by the following formula:

[0098]

[0099] Wherein, denotes encryption of the challenge value Challenge using the private key C .

[0100] S240. Decrypt the encrypted challenge value through the distributed soft bus controller, verify the node attribute information of the sensor node based on the decrypted challenge value and the challenge value, and transmit the encrypted power data to the terminal when the verification of the node attribute information is successful.

[0101] Specifically, the controller C receives the response Response from the sensor node i and then uses the public key of the sensor node to decrypt the response to obtain the decrypted challenge value Challenge C ′; compare the decrypted challenge value with the original challenge value, and judge whether the node attribute information is verified successfully according to the comparison result.

[0102] Optionally, the verifying the node attribute information of the sensor node based on the decrypted challenge value and the challenge value includes: determining that the verification of the node attribute information of the sensor node is successful when the decrypted challenge value is the same as the challenge value.

[0103] Specifically, when the decrypted challenge value is the same as the challenge value, it indicates successful authentication; when the decrypted challenge value is different from the challenge value, it indicates failed authentication and rejects the data transmission request.

[0104] The technical solution of the embodiment of the present invention sends a challenge value to the sensor node through the distributed soft bus controller when it is queried that there is corresponding information of the node attribute information corresponding to the sensor node in the database; encrypts the challenge value by the sensor node and sends the encrypted challenge value to the distributed soft bus controller; decrypts the encrypted challenge value through the distributed soft bus controller, and verifies the node attribute information of the sensor node based on the decrypted challenge value and the challenge value. It ensures the security of data during transmission. Even if the data is intercepted during transmission, the original challenge value cannot be obtained without the corresponding decryption key, thus protecting the confidentiality of the data. By comparing the decrypted challenge value with the original challenge value, the identity of the sensor node and the authenticity of the node attribute information can be verified. It helps to prevent malicious nodes from impersonating legitimate nodes and improve the security of the system.

[0105] As an optional example of Embodiment 1 of the present invention, the data transmission method of the embedded power system in this embodiment specifically includes the following steps:

[0106] Step 1. Obtain the initial power data collected by the sensor node of the embedded power system, and encrypt the initial power data based on the symmetric encryption algorithm and the asymmetric encryption algorithm to obtain the encrypted power data.

[0107] Specifically, a first key corresponding to the initial power data is generated through the symmetric encryption algorithm, and the initial power data is encrypted based on the first key to obtain the encrypted initial power data; the first key is encrypted based on the public key of the receiving end through the asymmetric encryption algorithm to obtain the encrypted first key; the encrypted power data is determined based on the encrypted initial power data and the encrypted first key. The data type corresponding to the initial power data is determined. When the data type is time series data, differential coding processing is performed on the initial power data, and the initial power data is updated based on the data after the coding processing. Denoising processing and / or compression processing is performed on the initial power data, and the initial power data is updated based on the processed data.

[0108] Exemplarily, after the sensor node collects data and preprocesses it, the distributed soft bus controller performs end-to-end encryption in a manner combining the symmetric encryption algorithm and the asymmetric encryption algorithm. A data vector is generated by collecting data through the sensor node, and the data vector is denoised. If the collected data is time series data, differential coding is required to reduce the redundancy between data, and finally the preprocessed data is obtained. The preprocessed data is compressed using LZ4 and Zstd to obtain the compressed data. End-to-end encryption is performed on the compressed data in a manner combining the symmetric encryption algorithm and the asymmetric encryption algorithm.

[0109] Exemplarily, the steps of the differential coding are expressed by the following formula:

[0110] Δd i =d i -d i-1 , i = 2, 3, …, n;

[0111] where, Δd i represents the difference of the i-th data point, d i represents the i-th data point in the data sequence of the initial power data; d i-1 represents the (i - 1)-th data point in the data sequence of the initial power data;

[0112] The initial power data is converted into a data sequence after differential coding:

[0113] D’ = d1, Δd2, Δd3, …, Δd n ;

[0114] Among them, D’ represents the data sequence after differential encoding. In this embodiment, the application of differential encoding effectively reduces the redundancy of the data sequence. Especially for time-series data or continuous data collected by sensors, it can significantly reduce the data volume and storage requirements. This not only helps to improve the data compression ratio, but also reduces the computational and bandwidth requirements in subsequent encryption, transmission, and decryption processes, enabling the system to process and transmit data more efficiently.

[0115] Exemplarily, the preprocessed data is compressed using the LZ4 compression algorithm and Zstd (Z Standard Compression Algorithm) to obtain the compressed data.

[0116] Exemplarily, the LZ4 algorithm is used for preliminary compression of the differentially encoded data sequence:

[0117] C1 = LZ4 Compress D’;

[0118] Among them, C1 represents the data after LZ4 compression, and D’ represents the differentially encoded data sequence. The data after LZ4 compression is compressed using the Zstd compression algorithm:

[0119] C2 = Zstd Compress C1;

[0120] Among them, C2 represents the data obtained after compression using the Zstd compression algorithm.

[0121] In this embodiment, the efficiency of data compression is further improved through the hybrid compression of LZ4 and Zstd. The LZ4 algorithm is fast and suitable for preliminary compression of data, while Zstd provides a higher compression ratio. The combination of the two not only ensures the efficient compression of data, but also avoids the performance bottleneck that may be brought by relying on a single algorithm. Therefore, this hybrid compression method can effectively reduce the occupancy of network bandwidth and improve the overall performance and real-time performance of the system.

[0122] Exemplarily, the specific steps of the hybrid encryption are as follows:

[0123] Based on the first key, the initial power data is encrypted to obtain the encrypted initial power data, which is expressed by the formula as follows:

[0124] C2 = AES Enerypt (C2, K AES );

[0125] Among them, C′2 represents the encrypted initial power data, C2 represents the compressed initial power data, and K AES represents the first key.

[0126] Optionally, the first key is encrypted based on the public key of the terminal by using an asymmetric encryption algorithm, and the encrypted first key is represented by the following formula:

[0127]

[0128] where K' AES represents the encrypted first key, K AES represents the first key, represents the public key of the receiving end.

[0129] In this embodiment, the hybrid encryption method combines the advantages of symmetric encryption and asymmetric encryption. Symmetric encryption is used to efficiently encrypt the compressed data, while asymmetric encryption is used to encrypt the symmetric encryption key. This design enables the system to reduce the computational burden in the encryption process while ensuring data security, especially avoiding the problem of large computational complexity of traditional symmetric encryption algorithms. Asymmetric encryption is only used to encrypt the symmetric encryption key, while symmetric encryption ensures the efficiency during the transmission of a large amount of data. Such a design not only improves the encryption speed of the system but also ensures the security and flexibility of key management.

[0130] Step 2. Verify the node attribute information of the sensor node.

[0131] Specifically, when it is queried that the database stores corresponding information of the node attribute information corresponding to the sensor node, a challenge value is sent to the sensor node by the distributed soft bus controller; the sensor node encrypts the challenge value and sends the encrypted challenge value to the distributed soft bus controller; the distributed soft bus controller decrypts the encrypted challenge value, and verifies the node attribute information of the sensor node based on the decrypted challenge value and the challenge value.

[0132] Specifically, each sensor node has a unique node identifier and key pair. When the sensor node needs to send data, it sends a node authentication request to the distributed soft bus controller C, and the request content is represented by the following formula:

[0133] Requert i =(ID i ,T i );

[0134] where ID i represents the node identifier of the sensor node S i , and T i represents the timestamp.

[0135] When the sensor node sends a node authentication request, the request data is encrypted by using a public key encryption algorithm, and is represented by the following formula:

[0136]

[0137] Among them, represents using the public key of the sensor node to encrypt the node authentication request.

[0138] After the distributed soft bus controller C receives the node authentication request from the sensor node, it first decrypts the node authentication request and extracts the node identifier ID i and the timestamp T i ; then it verifies whether the sensor node S i is legal by querying the database. If it is not legal, the process ends; if it is legal, the distributed soft bus controller C generates a dynamic node token as the authentication credential, which is expressed by the formula as follows:

[0139] T′ i = (ID i , R C , T i );

[0140] Among them, R C represents a random number generated by the distributed soft bus controller, T′ i represents the dynamic node token, and ID i represents the node identifier of the sensor node S i .

[0141] The distributed soft bus controller encrypts the dynamic node token with its private key and sends it to the sensor node S i , and the transmitted data is expressed by the formula as follows:

[0142]

[0143] Among them, represents encrypting the dynamic identity token T′ with the private key of the distributed soft bus controller i .

[0144] After receiving the encrypted identity token EncrptedToken i , the sensor node S i uses its own private key to decrypt the identity token to obtain the dynamic node token.

[0145] The distributed soft bus controller sends a dynamic challenge value Challenge C to the sensor node. The dynamic challenge value can be a randomly generated value, which is expressed by the formula as follows:

[0146] Challenge C = Rand(D);

[0147] Wherein, Rand(D) represents a random number generated from the distributed soft bus controller, i.e., the challenge value.

[0148] Specifically, the sensor node uses the private key to encrypt the challenge value Challenge C and then sends the encryption result back to the controller, which is expressed by the formula as follows:

[0149]

[0150] Wherein, represents encrypting the challenge value Challenge using the private key C for encryption.

[0151] The distributed soft bus controller decrypts the encrypted challenge value, and verifies the node attribute information of the sensor node based on the decrypted challenge value and the said challenge value. When the verification of the node attribute information is successful, the encrypted power data is transmitted to the terminal.

[0152] Specifically, after the controller C receives the response Response i from the sensor node, it uses the public key of the sensor node to decrypt the response, and obtains the decrypted challenge value Challenge C '; compares the decrypted challenge value with the original challenge value, and determines whether the verification of the node attribute information is successful according to the comparison result.

[0153] Specifically, when the decrypted challenge value is the same as the said challenge value, it indicates that the authentication is successful; when the decrypted challenge value is different from the said challenge value, it indicates that the authentication fails, and the data transmission request is rejected.

[0154] In this embodiment, through the refined identity authentication process, the communication security between the sensor node and the controller is ensured. Each sensor node needs to perform identity authentication through a unique identifier and a timestamp, and uses public key encryption and dynamic node token generation technology to ensure the security of the transmission process. The challenge-response mechanism further enhances the reliability of node authentication and prevents security risks such as man-in-the-middle attacks. This solution effectively improves the anti-attack ability of the system and ensures that only legitimate nodes can participate in data transmission.

[0155] Step 3. When the verification of the node attribute information is successful, transmit the encrypted power data to the terminal.

[0156] Among them, the preset dynamic routing algorithm can adopt one of the Dijkstra algorithm, A* algorithm, Bellman-Ford algorithm or other algorithms, and this embodiment does not limit it.

[0157] Step 4. Decrypt the encrypted first key based on the private key of the receiving end to obtain the first key; decrypt the encrypted initial power data based on the first key to obtain the initial power data.

[0158] Specifically, the receiving end first uses the private key of the receiving end to decrypt the encrypted first key to obtain the first key. Use the decrypted first key to decrypt the encrypted initial power data, restore the compressed initial power data, and decompress the compressed initial power data to obtain the initial power data.

[0159] Exemplarily, the receiving end first uses the private key of the receiving end to decrypt the encrypted first key, which is expressed by the formula as follows:

[0160]

[0161] Among them, K′ RSA represents the encrypted first key; K AES represents the decrypted first key;

[0162] Use the decrypted first key to decrypt the encrypted initial power data to restore the compressed initial power data:

[0163] C2 = AES Decrypt (C′2, K AES );

[0164] Among them, C2 represents the initial power data after compression processing. C′2 represents the encrypted initial power data.

[0165] Use Zstd to decompress the compressed initial power data to obtain the data compressed by LZ4, which is expressed by the formula as follows:

[0166] C1 = Zstd Decompress (C2);

[0167] Then use LZ4 to decompress the data C1 compressed by LZ4 to restore the initial power data, which is expressed by the formula as follows:

[0168] D = LZ4 Decompress (C1);

[0169] Among them, D represents the initial power data.

[0170] The technical solution of the embodiment of the present invention is an end-to-end encryption transmission method for an embedded power system based on a distributed soft bus. By optimizing encryption technology, key management, and data transmission efficiency, it solves the problems of large computational overhead and difficult key management in the prior art. First, by adopting a hybrid encryption method that combines a symmetric encryption algorithm and an asymmetric encryption algorithm, while ensuring data security, it reduces the consumption of computing resources. The symmetric encryption algorithm is used to encrypt data, which has high efficiency, and the asymmetric encryption algorithm is only used to encrypt the key of the symmetric encryption algorithm, reducing the large-scale computational burden of traditional asymmetric encryption. Second, the distributed soft bus controller ensures the security during the data transmission process through node authentication, prevents illegal nodes from accessing, and improves the reliability of the system. At the same time, a dynamic routing algorithm is adopted to optimize the data transmission path, ensuring efficient and reliable communication, and reducing the phenomena of delay and packet loss. By optimizing the encryption and transmission processes, it not only improves the real-time response ability and security of the power system, but also simplifies the key management process, providing an efficient and secure solution for large-scale distributed power systems.

[0171] Embodiment III

[0172] Figure 3 FIG. is a schematic structural diagram of a data transmission device for an embedded power system provided in Embodiment III of the present invention. As Figure 3 shown, the device includes: a data acquisition module 310 and a data transmission module 320.

[0173] Among them, the data acquisition module 310 is used to acquire the initial power data collected by the sensor nodes of the embedded power system, and encrypt the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data; the data transmission module 320 is used to verify the node attribute information of the sensor nodes, and when the verification of the node attribute information is successful, transmit the encrypted power data to the terminal.

[0174] The technical solution of the embodiment of the present invention is to acquire the initial power data collected by the sensor nodes of the embedded power system, encrypt the initial power data based on a symmetric encryption algorithm and an asymmetric encryption algorithm to obtain encrypted power data; combine the symmetric encryption algorithm and the asymmetric encryption algorithm to efficiently encrypt the power data, which not only ensures the security of data transmission but also improves the encryption and decryption efficiency. Then, verify the node attribute information of the sensor nodes, and when the verification of the node attribute information is successful, transmit the encrypted power data to the terminal, enhancing the security of the entire power system, protecting the normal operation of the power system and the security of data, solving the problem of low data transmission security in the embedded power system, and achieving the beneficial effects of improving the data transmission security of the embedded power system, and improving the reliability and stability of the power system.

[0175] Optionally, the data acquisition module includes:

[0176] A first encryption unit, configured to generate a first key corresponding to the initial power data through the symmetric encryption algorithm, and encrypt the initial power data based on the first key to obtain the encrypted initial power data;

[0177] A second encryption unit, configured to encrypt the first key according to the public key of the receiving end through the asymmetric encryption algorithm to obtain the encrypted first key;

[0178] An encrypted data determination unit, configured to determine the encrypted power data based on the encrypted initial power data and the encrypted first key.

[0179] Optionally, the data transmission module includes:

[0180] A challenge value sending unit, configured to send a challenge value to the sensor node through the distributed soft bus controller when it is queried that the node attribute information corresponding to the sensor node is stored in the database;

[0181] A challenge value encryption unit, configured to encrypt the challenge value through the sensor node and send the encrypted challenge value to the distributed soft bus controller;

[0182] A challenge value verification unit, configured to decrypt the encrypted challenge value through the distributed soft bus controller, and verify the node attribute information of the sensor node based on the decrypted challenge value and the challenge value.

[0183] Optionally, the challenge value verification unit is specifically configured to:

[0184] When the decrypted challenge value is the same as the challenge value, it is determined that the verification of the node attribute information of the sensor node is successful.

[0185] Optionally, the device further includes:

[0186] A first decryption module, configured to decrypt the encrypted first key based on the private key of the receiving end after transmitting the encrypted power data to the terminal to obtain the first key;

[0187] A second decryption module, configured to decrypt the encrypted initial power data based on the first key to obtain the initial power data.

[0188] Optionally, the device further includes:

[0189] The first data processing module is configured to determine the data type corresponding to the initial power data before encrypting the initial power data based on the symmetric encryption algorithm and the asymmetric encryption algorithm. When the data type is time series data, perform differential encoding processing on the initial power data, and update the initial power data based on the encoded data.

[0190] Optionally, the device further includes:

[0191] The second data processing module is configured to perform denoising processing and / or compression processing on the initial power data after obtaining the initial power data collected by at least one sensor node of the embedded power system, and update the initial power data based on the processed data.

[0192] The data transmission device of the embedded power system provided by the embodiments of the present invention can execute the data transmission method of the embedded power system provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0193] Embodiment 4

[0194] Figure 4 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0195] As Figure 4 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0196] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0197] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data transmission of the method-embedded power system.

[0198] In some embodiments, the data transmission of the method-embedded power system can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data transmission of the method-embedded power system described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data transmission of the method-embedded power system by any other suitable means (e.g., by means of firmware).

[0199] The various embodiments of the systems and technologies described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs, which can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0200] A computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0201] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0202] In order to provide interaction with a service acquirer, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the service acquirer; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the service acquirer can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the service acquirer; for example, the feedback provided to the service acquirer can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the service acquirer can be received in any form (including acoustic input, speech input, or tactile input).

[0203] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a service acquirer computer having a graphical service acquirer interface or a web browser, through which the service acquirer can interact with the implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected with each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.

[0204] The computing system can include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0205] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.

[0206] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A data transmission method for an embedded power system, characterized in that, Including: Obtain the initial power data collected by the sensor nodes of the embedded power system, and encrypt the initial power data based on symmetric encryption algorithm and asymmetric encryption algorithm to obtain encrypted power data; Verify the node attribute information of the sensor nodes, and transmit the encrypted power data to the terminal when the node attribute information is verified successfully.

2. The method according to claim 1, wherein Encrypt the initial power data based on symmetric encryption algorithm and asymmetric encryption algorithm to obtain encrypted power data, including: Generate a first key corresponding to the initial power data through the symmetric encryption algorithm, and encrypt the initial power data based on the first key to obtain the encrypted initial power data; Encrypt the first key according to the public key of the receiving end through the asymmetric encryption algorithm to obtain the encrypted first key; Determine the encrypted power data based on the encrypted initial power data and the encrypted first key.

3. The method according to claim 1, wherein The verification of the node attribute information of the sensor nodes includes: When it is queried that the database stores the corresponding information of the node attribute information corresponding to the sensor node, send a challenge value to the sensor node through the distributed soft bus controller; Encrypt the challenge value through the sensor node and send the encrypted challenge value to the distributed soft bus controller; Decrypt the encrypted challenge value through the distributed soft bus controller, and verify the node attribute information of the sensor node based on the decrypted challenge value and the challenge value.

4. The method according to claim 3, characterized in that, The verification of the node attribute information of the sensor node based on the decrypted challenge value and the challenge value includes: When the decrypted challenge value is the same as the challenge value, determine that the verification of the node attribute information of the sensor node is successful.

5. The method according to claim 2, wherein After transmitting the encrypted power data to the terminal, it further includes: Decrypt the encrypted first key based on the private key of the receiving end to obtain the first key; Decrypt the encrypted initial power data based on the first key to obtain the initial power data.

6. The method according to claim 1, characterized in that, Before encrypting the initial power data based on symmetric encryption algorithm and asymmetric encryption algorithm, it further includes: Determine the data type corresponding to the initial power data. When the data type is time series data, perform differential coding processing on the initial power data, and update the initial power data based on the encoded data.

7. The method according to claim 1, characterized in that After obtaining the initial power data collected by at least one sensor node of the embedded power system, it further includes: Perform denoising processing and / or compression processing on the initial power data, and update the initial power data based on the processed data.

8. A data transmission device for an embedded power system, characterized in that, Including: A data acquisition module, configured to obtain the initial power data collected by the sensor nodes of the embedded power system, and encrypt the initial power data based on symmetric encryption algorithm and asymmetric encryption algorithm to obtain encrypted power data; A data transmission module, configured to verify the node attribute information of the sensor nodes, and transmit the encrypted power data to the terminal when the node attribute information is verified successfully.

9. An electronic device, characterized in that, Including: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the data transmission method of the embedded power system according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions for implementing the data transmission method of the embedded power system according to any one of claims 1-7 when the computer instructions are executed by a processor.