Power data security convergence communication method based on attack and defense integration
Through the integrated offensive and defense power data security aggregation communication method, quantum fingerprint authentication and dynamic key obfuscation technology are used, combined with space-time attention model and federated learning, the problem that traditional passive defense is difficult to deal with complex attacks is solved, and the efficient, secure transmission and stable operation of power data is achieved.
Patent Information
- Application Number
- CN202510687808.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-05-27
AI Technical Summary
Traditional network security protection mainly focuses on passive defense, and it is difficult to deal with increasingly complex attack methods, resulting in challenges in the safe transmission of power data and the stable operation of the power grid.
The power data security aggregation communication method based on the integrated attack and defense is adopted, and real-time behavior checksum and dynamic encryption is achieved through the edge terminal access authentication of quantum fingerprint anchoring, the tamper-resistant data preprocessing of dynamic key obfuscation, the quantum communication technology generates initial keys, virtual nodes simulate attacks and collects intelligence, and data-driven automatic optimization defense strategy. Combined with the space-time attention model and federated learning technology, real-time behavior checksum dynamic encryption is achieved.
It realizes efficient and secure communication of power data, reduces computing resource consumption, adapts to changes in equipment operating status, covers cloning attacks and abnormal behaviors, provides active defense and real-time intelligence support, and improves the security and stability of the power system.
Smart Images

Figure CN120415718A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power data aggregation communication, and particularly to a power data security aggregation communication method based on offense and defense integration. Background Art
[0002] With the evolution of power grid intelligence, digitization, and informatization, the power Internet of Things has developed rapidly. A large number of intelligent devices and sensors have been connected to the power system, generating a huge amount of data. An efficient and secure aggregation communication method is required to support data transmission and processing. Generally speaking, the power grid can be regarded as a cyber-physical system, and the communication network is its nerve center. In recent years, malicious attacks on the power grid have gradually changed from traditional physical damage to cyber attacks, posing a huge challenge to the secure transmission of power data and the stable operation of the power grid.
[0003] Traditional network security protection mainly focuses on passive defense and is difficult to cope with increasingly complex attack means. The concept of offense and defense integration emphasizes combining attack and defense. By actively understanding the means and strategies of attackers, defensive planning and optimization are carried out in advance, and at the same time, it has the capabilities of attack traceability and rapid response to improve the overall security protection level. In this context, a power data security aggregation communication method based on offense and defense integration has emerged, aiming to design a more efficient and secure data aggregation communication scheme by comprehensively considering attack and defense factors to ensure the secure and stable operation of the power system. Summary of the Invention
[0004] The purpose of the present invention is to propose a power data security aggregation communication method based on offense and defense integration to solve the problem that traditional network security protection mainly focuses on passive defense and is difficult to cope with increasingly complex attack means.
[0005] The purpose of the present invention can be achieved through the following technical solutions: A power data security aggregation communication method based on offense and defense integration includes the following steps:
[0006] A01: Edge terminal access authentication based on quantum fingerprint anchoring. The noise signal generated by the internal quantum tunneling effect of the device is used as a unique identifier after SHA-3 hash encoding, and a three-dimensional authentication vector is constructed in combination with dynamic biometric features. Through a spatio-temporal attention model, real-time behavior verification of access requests is realized.
[0007] A02: Tamper-resistant data preprocessing with dynamic key confusion.
[0008] A03: Confidence dynamic filtering based on tamper-resistant data preprocessing.
[0009] A04: Generate the initial key using quantum communication technology, generate random parameters every 15 seconds using the chaos algorithm, change the encryption rules, define the security controller to globally manage the encryption policy, and synchronize the key and parameters to all devices in real time to ensure consistent encryption collaboration;
[0010] A05: Use virtual nodes to simulate real devices, lure attacks and collect intelligence, record attack behaviors and extract malicious code features, update the threat database, and provide real-time intelligence for defense;
[0011] A06: Automatically optimize the defense strategy through data-driven to adapt to new attacks, use the contrast learning algorithm to automatically label unknown attack samples from massive data, utilize self-supervised learning technology, dynamically adjust the edge detection parameters, and inject the optimized strategy back into each defense link.
[0012] Furthermore: The method of constructing the three-dimensional authentication vector by combining dynamic biometrics is to construct the three-dimensional authentication vector by fusing quantum noise fingerprints, hardware operation biometric entropy values, and harmonic energy distribution entropy. The specific algorithm is as follows:
[0013] Generate the first dimension Q of the quantum noise fingerprint. Use the internal quantum tunneling device of the device to collect the thermal noise signal n(t), and generate the quantum fingerprint through 256-bit SHA-3 hash encoding
[0014] Where: represents the exclusive OR operation, UUID is the globally unique identifier of the device; t1 and t0 represent the start and end times of the time interval, used to limit the time range for analyzing or processing data, SHA-3 256 That is, the secure hash algorithm, n(t) is a function of time t, representing the data characteristics at time t. By integrating it over the time period from t0 to t1, the cumulative value of the relevant data characteristics in this time period is obtained. represents the integral operation of the function n(t) over the time interval [t0, t1] to obtain the cumulative result of the data in this time period;
[0015] Calculate the second dimension E of the hardware operation biometric entropy value. Perform a fast Fourier transform on the voltage signal v(t) during the operation of the device, and extract the first 10 harmonic components, A k = |FFT(v(t)) k |, A k represents the amplitude of the kth frequency component obtained after calculation, FFT is the fast Fourier transform algorithm, and v(t) represents the original time-domain signal that changes with time t;
[0016] Calculate the harmonic energy distribution entropy E represents the harmonic energy distribution entropy, which is used to measure the degree of uniformity of the harmonic energy distribution among different frequency components. Both k and i are harmonic orders, and their value ranges from 1 to 10, representing the analysis of the first 10 harmonics. A k represents the amplitude of the k-th harmonic, and A i represents the amplitude of the i-th harmonic. The contribution degree of each harmonic to the total energy is quantified by the ratio of the square of the amplitude of each harmonic to the sum of the squares of the amplitudes of all harmonics;
[0017] The hardware ID hash encoding generates the third dimension H, and a two-factor hash processing is performed on the device hardware ID. In the formula, HMAC-SHA-512 is the hash message authentication code algorithm, and ID is the hardware identifier of the device. refers to 8 bytes of the quantum key prefix, which is exclusive-OR operated with the hardware identifier. K represents the key owned by the device and is used as the key input for the HMAC-SHA-512 algorithm;
[0018] Three-dimensional authentication vector construction and normalization. The features of the three dimensions are concatenated and normalized to form the final authentication vector. Among them, Q represents the power load data vector in the power data, E represents the device operating status data vector in the power data, H represents the power grid topology structure data vector in the power data, \|\| represents the norm of the vector, which is used to normalize the vector to make the vector length 1, and V is a new vector composed of the vectors obtained by normalizing Q, E, and H, which is used for subsequent data security aggregation and communication processing;
[0019] Real-time verification algorithm for access requests. Define the real-time acquisition vector V t and the registration vector V r The cosine similarity is expressed by the formula S represents the similarity metric value between the two vectors, V t represents the target vector, and V r represents the reference vector, and V t ·V r represents the dot product operation of the vector V t and V r to measure the consistency of the two vectors in direction. \|\| represents the Euclidean norm of the vector, which is used to normalize the vector to eliminate the influence of the vector length on the similarity calculation. When S≥θ, the authentication is passed; otherwise, the secondary verification is triggered. θ is the preset threshold.
[0020] Furthermore, the content of realizing the real-time behavior verification of the access request through the spatio-temporal attention model is as follows:
[0021] Based on the first dimension Q, the second dimension E, and the third dimension H, a matrix is formed by sampling according to the time series. Its shape is 3×T, and each column in the matrix represents a feature vector at a time step t;
[0022] Spatio-temporal feature extraction: Use Bi-LSTM to extract temporal features in the time series, and combine with GCN to mine the spatial relationship between features. The two cooperate to process the three-dimensional authentication vector matrix, and convert the original data into an intermediate feature representation containing spatio-temporal information;
[0023] Based on the extracted spatio-temporal features, information is screened by dynamically focusing on key time steps and feature dimensions, and the final feature z is fused; final , and the depthwise separable convolution technology is used to reduce the computational amount;
[0024] Calculate z final The Mahalanobis distance D from the historical normal features M By comparing with the set threshold, it is judged whether the current access request conforms to the normal behavior pattern, and the real-time verification decision is completed.
[0025] Furthermore, the anti-tampering data preprocessing process of the dynamic key confusion is to obtain the real-time longitude and latitude coordinates through the built-in GPS / Beidou module, calculate the geographical location entropy after quantization processing, and the formula reflecting the uncertainty of the device's spatial position is:
[0026] H geo represents the geographical information entropy, which is used to measure the uncertainty or chaos degree of the geographical space data distribution. n is the total number of categories of the geographical space data classification, and p i represents the probability that the i-th type of geographical space data appears in the overall population,
[0027] According to the geographical location entropy H geo Generate a 32×32-dimensional dynamic offset matrix O(t), which is updated every 5 seconds, and the formula is expressed as
[0028] where, ChaosMap is a chaotic mapping function to perform complex non-linear transformation on the input data, timestamp is the time stamp, is the bitwise logical operation on H geo and timestamp, and mod256 is the modulo operation, which takes the remainder of the output result of the ChaosMap function by 256, and maps the numerical value to the 0-255 interval to adapt to the representation range of byte data;
[0029] Generate the master key K0 = DKCA_KDF, where KDF includes the geographical location entropy, the first dimension Q value of the device quantum fingerprint, and a random number, and DKCA_KDF is a key derived based on the key derivation function according to multiple parameter combinations;
[0030] Generate 32 rounds of dynamic round keys based on K0 through the SM4_KeyExpansion standard function in combination with the dynamic offset matrix O(t). rk i represents the round key of the i-th round, and rk i-1 represents the round key of the (i - 1)-th round. SM4_KeyExpansion is a key expansion function based on the national cryptographic algorithm SM4, which is used to generate the current round key from the previous round key;
[0031] Geographical location pre-obfuscation, perform XOR preprocessing on the data packet P using the hash value of the current grid number and the MAC address. The formula is (g cur the MAC address of the device). Among them, P is the original data, P = [p0, p1, p2, p3], p0 represents the original data of the power data acquisition node, p1 represents the ciphertext data after data encryption processing, p3 is the data after decryption and verification at the receiving end, and g cur represents the current grid number, and perform XOR preprocessing on the original data using the current grid number and the MAC address hash value,
[0032] Dynamic key encryption, C = SM4_Encrypt(P′, rk0, rk1,..., rk 31 ), SM4_Encrypt represents the SM4 encryption algorithm, P′ is the parameter obtained by geographical location pre-obfuscation, and rk0, rk1,..., rk 31 are the round encryption round keys used by the SM4 encryption algorithm, which are used to perform multiple rounds of transformation on the plaintext data during the encryption process to achieve data encryption;
[0033] Chain hash verification construction, XOR the ciphertext C i , the timestamp t i and the quantum fingerprint Q with the previous round hash value h i-1 and then calculate the hash value.
[0034] Furthermore, the anti-tampering data preprocessing also includes constructing an edge node federated learning detection model, training a malicious payload detection feature library in real time, converting network traffic into a 224×224 grayscale image, and performing feature extraction. The formula is f t = LSTM(CNN(x t ), f t-1 );
[0035] Among them, f tThe output feature at time step t, representing the processed feature vector of power data, which integrates the information of the current time step and the historical information of the previous time step, and is used for subsequent security analysis. LSTM is a long short-term memory network, which is used to capture the long-term dependencies of data in the time dimension when processing sequence data. CNN is a convolutional neural network, which is used to extract features from the input data x t For feature extraction, key features of power data in the spatial dimension are extracted through convolution and pooling operations on x t The power data at time step t, which includes voltage, current, and power, is denoted as f t-1 The output feature at time step t - 1, which is used as the input of the LSTM network to transfer the information of the previous time step to the current time step. The formula extracts spatial features through CNN, and LSTM captures time series dependencies;
[0036] Based on f t The gradient of the model parameters is updated θ i According to It is updated, and combined with the federated learning aggregation formula Let the global model learn the characteristics of malicious payloads in the entire power data network. In the formula, θ * Represents the finally calculated aggregated value, m represents the number of data groups or categories, and N i Represents the weight of the i-th group of data, and θ i Represents the parameter value corresponding to the i-th group of data;
[0037] The feature vector f t Is input into the federated learning model, and the confidence is generated through the formula C conf = FLM(f t ), where FLM is the federated learning model.
[0038] Furthermore, the confidence dynamic filtering method is as follows:
[0039]
[0040] When the confidence is lower than the threshold T1, it is determined that the data has a high risk, and deep detection is immediately triggered and the transmission is blocked; when the confidence is between T1 and T2, the data enters the sandbox environment for behavior analysis, and when the confidence is higher than T2, the data is considered safe and allowed to pass directly.
[0041] Compared with the prior art, the beneficial effects of the present invention are:
[0042] 1. A hardware fingerprint generation technology based on quantum physical characteristics is proposed. The noise signal hash code generated by the internal quantum tunneling effect of the device is used as a unique identifier, and a three-dimensional authentication vector is constructed by combining dynamic biometric characteristics. The real-time behavior verification of access requests is realized through a lightweight spatio-temporal attention model, which reduces the computing power consumption compared with traditional models. The cross-domain fusion authentication of quantum noise fingerprints and the operating characteristics of power equipment breaks through the single authentication mode of traditional digital certificates or hardware IDs.
[0043] 2. A two-factor dynamic key confusion algorithm is designed. Based on SM4 encryption, a dynamic offset based on the geographical location entropy value of the device is introduced, and a malicious payload detection feature library is trained in real time through an edge node federated learning model. Combining with the data integrity hash chain technology, a chained hash value containing a timestamp and device fingerprint is generated for each data packet to realize pre-screening of attack characteristics and data anti-tampering before transmission. The dynamic key confusion mechanism driven by geographical location entropy is different from traditional fixed-parameter encryption or single federated learning detection schemes.
[0044] 3. A hybrid encryption system with periodic parameter perturbation is designed. The quantum channel generates the initial session key, and the classical channel dynamically switches the encryption mode every 15 seconds to generate a key confusion factor. The dynamic synchronization of encryption parameters across the network is realized by defining a security controller, and the quantum key and chaotic dynamic encryption mechanism are integrated and applied in the scheme.
[0045] 4. Through the spatio-temporal attention model, the real-time behavior verification of access requests is realized. The verification is multi-dimensional anomaly capture, covering cloning attacks, parameter tampering, and abnormal behaviors. The feature weights are adjusted in real time to adapt to changes in the device operating state. The depthwise separable convolution technology is used to reduce the amount of calculation. Without losing too much accuracy, the computational complexity of the model is reduced, making the model easier to run quickly on resource-constrained edge devices, meeting the goal of lightweight design and reducing computational resource consumption. Based on the extracted spatio-temporal features, information is screened by dynamically focusing on key time steps and feature dimensions. In the time dimension, key time steps are dynamically focused to avoid performing equally complex calculations on all time steps and reduce unnecessary operations. In the space dimension, key feature dimensions are screened, and only important feature dimensions are processed subsequently, reducing the amount of data processing and computational overhead, achieving lightweight from the computational process. The lightweight detection and authentication design meets the computing power limitations of edge devices such as smart meters and sensors and adapts to the power Internet of Things scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the accompanying drawings.
[0047] Figure 1 It is a flowchart of a power data security aggregation communication method based on the integration of offense and defense of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0048] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative work belong to the scope of protection of the present invention.
[0049] Please refer to Figure 1 As shown, a power data security aggregation communication method based on offense and defense integration includes the following steps:
[0050] A power data security aggregation communication method based on offense and defense integration includes the following steps:
[0051] A01: Edge terminal access authentication based on quantum fingerprint anchoring. The noise signal generated by the internal quantum tunneling effect of the device is used as a unique identifier through SHA-3 hash encoding, and a three-dimensional authentication vector is constructed in combination with dynamic biometric features. Through the spatio-temporal attention model, real-time behavior verification of access requests is realized;
[0052] A02: Anti-tampering data preprocessing with dynamic key confusion;
[0053] A03: Confidence dynamic filtering based on anti-tampering data preprocessing;
[0054] A04: Use quantum communication technology to generate the initial key, generate random parameters every 15 seconds using the chaos algorithm, change the encryption rules, define the global management encryption strategy of the security controller, and synchronize the key and parameters to all devices in real time to ensure consistent encryption cooperation;
[0055] A05: Use virtual nodes to simulate real devices, lure attacks and collect intelligence, record attack behaviors and extract malicious code features, update the threat database, and provide real-time intelligence for defense;
[0056] A06: Automatically optimize the defense strategy through data-driven to adapt to new attacks. Use the contrastive learning algorithm to automatically label unknown attack samples from massive data, use self-supervised learning technology to dynamically adjust the edge detection parameters, and inject the optimized strategy into each defense link in reverse;
[0057] This solution uses trusted access authentication to ensure the legality and compliance of access devices from the source, safeguards the security and integrity of data before transmission through data preprocessing to prevent data from being maliciously tampered with or injected with malicious content, uses dynamic encryption communication to achieve the dynamization and coordination of the encryption process, enhances the confidentiality during data transmission, has active defense and intelligence collection functions, transforms passive defense into active defense, provides real-time and effective information support for subsequent defense, and has an intelligent defense optimization function to achieve the self-evolution and dynamic adaptation of the defense system to cope with constantly changing attack methods;
[0058] In this solution, the method of constructing a three-dimensional authentication vector by combining dynamic biometrics is to construct a three-dimensional authentication vector by fusing quantum noise fingerprints, the biometric entropy value of hardware operation, and the harmonic energy distribution entropy. The specific algorithm is as follows: The quantum noise fingerprint generates the first dimension Q. The thermal noise signal n(t) is collected by using the internal quantum tunneling device of the device and is encoded by 256-bit SHA-3 hashing to generate the quantum fingerprint Q = SHA-
[0059]
[0060] Where: represents the exclusive OR operation, UUID is the globally unique identifier of the device; t1 and t0 represent the start and end times of the time interval, which are used to limit the time range for analyzing or processing data. SHA-3 256 That is, the secure hash algorithm. n(t) is a function of time t, representing the data characteristics at time t. By integrating it within the time period from t0 to t1, the cumulative value of the relevant data characteristics within this time period is obtained. represents the integral operation of the function n(t) over the time interval [t0, t1] to obtain the cumulative result of the data within this time period;
[0061] The biometric entropy value of hardware operation calculates the second dimension E. For the voltage signal v(t) during device operation, a fast Fourier transform is performed to extract the first 10 harmonic components. A k = |FFT(v(t)) k |, A k represents the amplitude of the k-th frequency component obtained after calculation. FFT is the fast Fourier transform algorithm, and v(t) represents the original time-domain signal that changes with time t;
[0062] Calculate the harmonic energy distribution entropy E represents the harmonic energy distribution entropy, which is used to measure the distribution uniformity of harmonic energy among different frequency components. Both k and i are harmonic orders, and their value ranges from 1 to 10, representing the analysis of the first 10 harmonics. A k represents the amplitude of the k-th harmonic, A iDenote the amplitude of the \(i\)-th harmonic. The contribution degree of each harmonic to the total energy is quantified by the ratio of the square of the amplitude of each harmonic to the sum of the squares of the amplitudes of all harmonics.
[0063] The hardware ID hash encoding generates the third dimension \(H\), which performs a two-factor hash processing on the device hardware ID. In the formula, HMAC-SHA-512 is the hash message authentication code algorithm, and ID is the hardware identifier of the device. It refers to 8 bytes of the quantum key prefix, which performs an exclusive OR operation with the hardware identifier. \(K\) represents the key owned by the device and is used as the key input for the HMAC-SHA-512 algorithm.
[0064] The three-dimensional authentication vector is constructed and normalized. The features of the three dimensions are concatenated and normalized to form the final authentication vector \(V\). Among them, \(Q\) represents the power load data vector in the power data, \(E\) represents the device operation status data vector in the power data, \(H\) represents the power grid topology structure data vector in the power data, \(\|\|\) represents the norm of the vector, which is used to normalize the vector so that the vector length is 1. \(V\) is a new vector composed of the vectors obtained by normalizing \(Q\), \(E\), and \(H\), and is used for subsequent data security aggregation and communication processing.
[0065] Access request real-time verification algorithm. Define the real-time acquisition vector \(V\) t and the registration vector \(V\) r The cosine similarity is expressed by the formula \(S\) represents the similarity metric value between the two vectors. \(V\) t represents the target vector, and \(V\) r represents the reference vector, and \(V\) t ·\(V\) r represents the dot product operation of the vector \(V\) t and \(V\) r to measure the consistency of the two vectors in direction. \(\|\|\) represents the Euclidean norm of the vector, which is used to normalize the vector to eliminate the influence of the vector length on the similarity calculation. When \(S\geq\theta\), the authentication is passed; otherwise, the secondary verification is triggered. \(\theta\) is the preset threshold. The following is the comparison table between the traditional access authentication and the quantum fingerprint three-dimensional authentication:
[0066]
[0067] The above authentication scheme constructs the digital DNA of the power edge terminal through the cross-domain fusion of quantum physical characteristics and device operation dynamic characteristics, cuts off the attack path of illegal devices from the access source, provides a trusted trust anchor for subsequent data encryption, transmission protection, and aggregation security, is the primary barrier for realizing the integrated power data security of offense and defense, blocks the access of illegal devices from the source, and establishes a trust root for the full-link security.
[0068] In this solution, the content of realizing real-time behavior verification of access requests through the spatio-temporal attention model is as follows: Based on the first dimension Q, the second dimension E, and the third dimension H, sampling is performed in time series to form a matrix whose shape is 3×T, and each column in the matrix represents a feature vector at a time step t;
[0069] Spatio-temporal feature extraction: Use Bi-LSTM to extract temporal features in the time series, and combine GCN to mine the spatial relationships between features. The two cooperate to process the three-dimensional authentication vector matrix, and convert the original data into an intermediate feature representation containing spatio-temporal information;
[0070] Based on the extracted spatio-temporal features, information is screened by dynamically focusing on key time steps and feature dimensions, and the final feature z is fused final , and the depthwise separable convolution technology is used to reduce the computational amount;
[0071] Calculate z final and the Mahalanobis distance D from the historical normal features M By comparing with the set threshold, it is judged whether the current access request conforms to the normal behavior pattern, and the real-time verification decision is completed;
[0072] Multi-dimensional anomaly capture: Analyze the spatio-temporal correlations of Q, E, and H simultaneously, covering cloning attacks, parameter tampering, and abnormal behaviors. The feature weights are adjusted in real time to adapt to changes in the device operation state. The lightweight detection and authentication design meet the computing power limitations of edge devices such as smart meters and sensors, and are adapted to the power Internet of Things scenario;
[0073] In this solution, the anti-tampering data preprocessing process of dynamic key confusion is to obtain real-time longitude and latitude coordinates through the built-in GPS / Beidou module, calculate the geographical location entropy after quantization processing, and the formula reflecting the uncertainty of the device's spatial position is:
[0074] H geo represents the geographical information entropy, which is used to measure the uncertainty or chaos degree of the geographical space data distribution. n is the total number of categories of geographical space data classification, and p i represents the probability that the i-th category of geographical space data appears in the overall population,
[0075] According to the geographical location entropy H geo generate a 32×32-dimensional dynamic offset matrix O(t), which is updated every 5 seconds, and the formula is expressed as
[0076] where, ChaosMap is a chaotic mapping function to perform complex non-linear transformation on the input data, timestamp is the time stamp, is for H geoPerform bitwise logical operations with the timestamp. Mod 256 is a modulo operation. Take the remainder of the output result of the ChaosMap function modulo 256, map the value to the range of 0 - 255, and adapt to the representation range of byte data;
[0077] Generate the master key K0 = DKCA_KDF, where KDF includes geographical location entropy, the first dimension Q value of the device quantum fingerprint, and a random number. DKCA_KDF is derived based on a key derivation function according to a combination of multiple parameters;
[0078] Based on K0, use the SM4_KeyExpansion standard function in combination with the dynamic offset matrix O(t) to generate 32 rounds of dynamic round keys rk i Represents the round key of the i-th round, rk i-1 Represents the round key of the (i - 1)-th round. SM4_KeyExpansion is a key expansion function based on the national cryptographic algorithm SM4, used to generate the current round key from the previous round key;
[0079] Geographical location pre - confusion. Perform XOR pre - processing on the data packet P using the hash value of the current grid number and the MAC address. The formula is (g cur Device MAC address), where P is the original data, P = [p0, p1, p2, p3], p0 represents the original data of the power data acquisition node, p1 represents the ciphertext data after data encryption processing, p3 is the data after decryption and verification at the receiving end, g cur Represents the current grid number. Perform XOR pre - processing on the original data using the current grid number and the MAC address hash value,
[0080] Dynamic key encryption, C = SM4_Encrypt(P′, rk0, rk1,..., rk 31 ), SM4_Encrypt represents the SM4 encryption algorithm, P′ is the parameter obtained from geographical location pre - confusion, rk0, rk1,..., rk 31 Are the round encryption round keys used by the SM4 encryption algorithm, used to perform multiple rounds of transformation on the plaintext data during the encryption process to achieve data encryption;
[0081] Chain - type hash verification construction, Perform XOR on the ciphertext C i , the timestamp t i And the quantum fingerprint Q with the previous round hash value h i-1 And then calculate the hash value;
[0082] In this solution, the anti-tampering data preprocessing further includes constructing an edge node federated learning detection model, training a malicious payload detection feature library in real time, converting network traffic into grayscale images of 224×224, and performing feature extraction. The formula is f t = LSTM(CNN(x t ), f t-1 );
[0083] where f t is the output feature at time step t, representing the feature vector of the processed power data, which integrates the information of the current time step and the historical information of the previous time step, and is used for subsequent security analysis. LSTM is a long short-term memory network, which is used to capture the long-term dependencies of data in the time dimension when processing sequence data. CNN is a convolutional neural network used to extract features from the input data x t , and extracts the key features of the power data in the spatial dimension through convolution and pooling operations. x t is the power data at time step t, including voltage, current, and power. f t-1 is the output feature at time step t-1, which is used as the input of the LSTM network to transfer the information of the previous time step to the current time step. The formula extracts spatial features through CNN, and LSTM captures time series dependencies;
[0084] Based on the model parameters obtained from f t , the gradient θ i is updated according to , and combined with the federated learning aggregation formula to enable the global model to learn the features of malicious payloads in the entire power data network. In the formula, θ * represents the finally calculated aggregation value, m represents the number of data groups or categories, N i represents the weight of the i-th group of data, and θ i represents the parameter value corresponding to the i-th group of data;
[0085] The feature vector f t is input into the federated learning model, and the confidence is generated through the formula C conf = FLM(f t ). FLM is the federated learning model;
[0086] The confidence dynamic filtering method is as follows:
[0087]
[0088] When the confidence level is lower than the threshold T1, it is determined that the data has a high risk, and deep detection is immediately triggered and the transmission is blocked; when the confidence level is between T1 and T2, the data enters the sandbox environment for behavior analysis, and when the confidence level is higher than T2, the data is considered safe and allowed to pass directly;
[0089] The confidence level dynamic filtering mechanism combines federated learning to achieve distributed detection of cross-node malicious code, provides a basis for judgment for dynamic filtering, and forms a complement to the data grouping and obfuscation processing process. The former focuses on the real-time detection and interception of traffic, and the latter resists attacks from the aspects of data encryption and integrity verification through dynamic key obfuscation and hash chain integrity verification. The two jointly ensure the security of power data during the aggregation and communication process, and effectively prevent risks such as data tampering and malicious attacks.
[0090] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A power data security aggregation communication method based on integrated offense and defense, characterized in that, It includes the following steps: A01: Edge terminal access authentication based on quantum fingerprint anchoring. The noise signal generated by the internal quantum tunneling effect of the device is used as a unique identifier after SHA-3 hash encoding, and a three-dimensional authentication vector is constructed by combining dynamic biometric features. Through a spatio-temporal attention model, real-time behavior verification of access requests is achieved; A02: Tamper-resistant data preprocessing with dynamic key confusion; A03: Confidence dynamic filtering based on tamper-resistant data preprocessing; A04: Use quantum communication technology to generate an initial key. Generate random parameters every 15 seconds using a chaotic algorithm to change the encryption rule. Define a global management encryption policy for the security controller, and synchronize the key and parameters to all devices in real time to ensure consistent encryption coordination; A05: Use virtual nodes to simulate real devices, lure attacks and collect intelligence, record attack behaviors and extract malicious code features, update the threat database, and provide real-time intelligence for defense; A06: Automatically optimize the defense strategy through data-driven to adapt to new attacks. Use contrastive learning algorithms to automatically label unknown attack samples from massive data, and use self-supervised learning techniques to dynamically adjust edge detection parameters. The optimized strategy is injected back into each defense link.
2. The power data security aggregation communication method based on offense and defense integration according to claim 1, wherein, The method of constructing the three-dimensional authentication vector by combining dynamic biometric features is to construct a three-dimensional authentication vector by fusing quantum noise fingerprints, biometric entropy values of hardware operation, and harmonic energy distribution entropy. The specific algorithm is as follows: Generate the first dimension Q of the quantum noise fingerprint. Use the internal quantum tunneling device of the device to collect the thermal noise signal n(t), and generate the quantum fingerprint through 256-bit SHA-3 hash encoding Wherein: represents an exclusive OR operation, UUID is the globally unique identifier of the device; t1 and t0 represent the start and end times of the time interval, which are used to limit the time range for data analysis or processing, SHA-3 256 i.e., the Secure Hash Algorithm, n(t) is a function of time t, representing the data feature at time t. By integrating it over the time period from t0 to t1, the cumulative value of the relevant data features in this time period is obtained. represents the integration operation of the function n(t) over the time interval [t0, t1] to obtain the cumulative result of the data in this time period; The hardware calculates the second dimension E of the biometric entropy value, performs a fast Fourier transform on the voltage signal v(t) during device operation, and extracts the first 10 harmonic components, A k = |FFT(v(t)) k |, A k represents the amplitude of the k-th frequency component obtained after calculation, FFT is the fast Fourier transform algorithm, and v(t) represents the original time-domain signal that changes with time t; Calculating the Entropy of Harmonic Energy Distribution Let \(E\) represent the entropy of harmonic energy distribution, which is used to measure the degree of uniformity of the distribution of harmonic energy among different frequency components. Both \(k\) and \(i\) are harmonic orders, with a value range from 1 to 10, representing the analysis of the first 10 harmonics. \(A\) k represents the amplitude of the \(k\) -th harmonic, and \(A\) i represents the amplitude of the \(i\) -th harmonic. By the ratio of the square of the amplitude of each harmonic to the sum of the squares of the amplitudes of all harmonics, the contribution of each harmonic to the total energy is quantified; The hardware ID hash encoding generates the third dimension H, and performs a two-factor hashing process on the device hardware ID. In the formula, HMAC-SHA-512 is the hash message authentication code algorithm, and ID is the hardware identifier of the device. It refers to 8 bytes of the quantum key prefix, which performs an exclusive OR operation with the hardware identifier. K represents the key owned by the device and is used as the key input for the HMAC-SHA-512 algorithm. Three-dimensional authentication vector construction and normalization, concatenating and normalizing the three-dimensional features to form the final authentication vector V. Among them, Q represents the power load data vector in power data, E represents the device operation status data vector in power data, H represents the power grid topology structure data vector in power data, || represents the norm of the vector, which is used for the normalization operation of the vector to make the vector length 1. V is a new vector composed of the vectors obtained by normalizing Q, E, and H, and is used for subsequent data security aggregation and communication processing. Real-time verification algorithm for access requests, defining the real-time acquisition vector V t and the registration vector V r The cosine similarity of is expressed by the formula S represents the similarity metric value between the two vectors, V t represents the target vector, V r represents the reference vector, V t ·V r represents the dot product operation of the vector V t and V r is used to measure the consistency of the two vectors in direction. \|\| represents the Euclidean norm of the vector, which is used to normalize the vector to eliminate the influence of the vector length on the similarity calculation. When S≥θ, the authentication is passed; otherwise, the secondary verification is triggered. θ is the preset threshold.
3. The method for secure aggregation communication of power data based on integrated offense and defense according to claim 2, wherein, The content of realizing real-time behavior verification of access requests through the spatio-temporal attention model is: Sampling is performed based on the first dimension Q, the second dimension E, and the third dimension H to form a matrix in a time series Its shape is 3×T, and each column in the matrix represents a feature vector at a time step t; Spatio-temporal feature extraction. Use Bi-LSTM to extract temporal features in the time series, and combine GCN to mine the spatial relationship between features. The two cooperate to process the three-dimensional authentication vector matrix, and convert the original data into an intermediate feature representation containing spatio-temporal information; Based on the extracted spatio-temporal features, information is screened by dynamically focusing on key time steps and feature dimensions, and the final feature z is obtained through fusion. final , the depthwise separable convolution technology is adopted to reduce the computational amount. Calculate z final Mahalanobis distance D from historical normal features M By comparing with the set threshold, determine whether the current access request conforms to the normal behavior pattern and complete the real-time verification decision.
4. A power data security aggregation communication method based on integrated offense and defense as claimed in claim 1, wherein, The process of tamper-resistant data preprocessing with dynamic key confusion is to obtain real-time longitude and latitude coordinates through the built-in GPS / Beidou module, calculate the geographical location entropy after quantization processing, and the formula reflecting the uncertainty of the device's spatial position is: H geo represents the geographical information entropy, which is used to measure the uncertainty or degree of chaos in the distribution of geospatial data. n is the total number of categories for the classification of geospatial data, and p i represents the probability of the i-th type of geospatial data occurring in the overall population. According to the geographical location entropy H geo Generate a 32×32 dimensional dynamic offset matrix O(t), which is updated every 5 seconds. The formula is expressed as Among them, ChaosMap is a chaotic mapping function that performs complex non-linear transformations on the input data, and timestamp is a timestamp. is to perform bitwise logical operations on H geo and timestamp. mod256 is a modulo operation that takes the remainder of the output result of the ChaosMap function modulo 256, maps the value to the range of 0-255, and adapts to the representation range of byte data. Generate the master key K0 = DKCA_KDF, where KDF includes the geographical location entropy, the first dimension Q value of the device's quantum fingerprint, and a random number, and DKCA_KDF is a key derived based on a key derivation function according to the combination of multiple parameters; Based on K0, through the SM4_KeyExpansion standard function combined with the dynamic offset matrix O(t), generate 32 rounds of dynamic round keys rk i represents the round key of the i-th round, rk i-1 represents the round key of the (i - 1)-th round. SM4_KeyExpansion is a key expansion function based on the national cryptographic algorithm SM4, which is used to generate the current round key from the previous round key; Geographical location pre - obfuscation, perform XOR pre - processing on data group P using the hash value of the current grid number and the MAC address. The formula is where P is the original data, P = [p0, p1, p2, p3], p0 represents the original data of the power data acquisition node, p1 represents the ciphertext data after data encryption processing, p3 is the data after decryption and verification at the receiving end, and g cur represents the current grid number. Use the current grid number and the MAC address hash value to perform XOR pre - processing on the original data Dynamic key encryption, C = SM4_Encrypt(P′, rk0, rk1,..., rk 31 ), where SM4_Encrypt represents the SM4 encryption algorithm, P′ is the parameter obtained by pre-confusing the geographical location, and rk0, rk1,..., rk 31 are the round encryption keys used in the SM4 encryption algorithm, which are used to perform multiple rounds of transformation on the plaintext data during the encryption process to achieve data encryption; Chain hash verification construction Ciphertext C i , timestamp t i and quantum fingerprint Q are XORed with the previous round hash value h i-1 to calculate the hash value.
5. A power data security aggregation communication method based on integrated offense and defense according to claim 4, characterized in that The anti-tampering-based data preprocessing further includes constructing an edge node federated learning detection model, training a malicious payload detection feature library in real time, converting network traffic into grayscale images of 224×224, and performing feature extraction. The formula is f t = LSTM(CNN(x t ), f t-1 ); where, f t is the output feature at time step t, representing the feature vector of the processed power data, which integrates the information of the current time step and the historical information of the previous time step, and is used for subsequent safety analysis. LSTM is a long short-term memory network, which is used to capture the long-term dependencies of data in the time dimension when processing sequence data. CNN is a convolutional neural network used to extract features from the input data x t by performing convolution and pooling operations to extract the key features of the power data in the spatial dimension. x t is the power data at time step t, including voltage, current, and power. f t-1 is the output feature at time step t-1, which serves as the input to the LSTM network, passing the information of the previous time step to the current time step. The formula extracts spatial features through CNN and captures time series dependencies through LSTM; Based on f t The updated gradient of the model parameters obtained θ i According to Update, combined with the federated learning aggregation formula Let the global model learn the characteristics of malicious payloads in the entire power data network. In the formula, θ * Represents the finally calculated aggregated value, m represents the number of data groups or categories, N i Represents the weight of the i-th group of data, θ i Represents the parameter value corresponding to the i-th group of data; Input the feature vector f t into the federated learning model, and generate a confidence level through the formula C conf = FLM(f t ), where FLM is the federated learning model.
6. The method for secure aggregation communication of power data based on integrated offense and defense according to claim 5, wherein The confidence dynamic filtering method is: When the confidence level is lower than the threshold T1, it is determined that the data has a high risk, and deep detection is immediately triggered and the transmission is blocked; when the confidence level is between T1 and T2, the data enters the sandbox environment for behavior analysis. When the confidence level is higher than T2, the data is considered safe and allowed to pass directly.
Citation Information
Patent Citations
Archive data protection method based on block chain
CN118228312A
A remote measurement data transmission method and system based on quantum key encryption
CN119743248A
Identity authentication system based on biometric fingerprint identification technology
CN119808054A
Cross-domain mutual trust identification authentication platform for power terminal and multi-service system
CN119853948A
Electronic signature generation and anti-counterfeiting system based on multi-source information fusion
CN119885294A