Efficient user information integrity protection method based on message authentication code in smart power grid
By adopting Whips and HMAC solutions in the smart grid, negotiating symmetric encryption primitives and generating verification tags, the problem of high computational complexity of user information integrity protection in smart meters is solved, and efficient and secure user information integrity protection is achieved.
Patent Information
- Application Number
- CN202510924675.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-08-12
AI Technical Summary
The prior art has high computational complexity in the protection of user information integrity in smart grids, and it is difficult to effectively implement in resource-constrained smart meters.
Using the progressive message authentication code scheme Whips and the traditional message authentication code scheme HMAC, the integrity of user information is ensured by negotiating symmetric encryption primitives between smart meter and power company, derive symmetric encryption keys, and generating and verifying tags in each cycle.
It realizes efficient and secure protection of user information integrity in resource-constrained smart meters, reduces storage and computing overhead, and is suitable for resource-constrained environments.
Smart Images

Figure CN120474827A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of smart grid technology, specifically to a method for protecting user information integrity in smart grids using message authentication codes (MACs). By using the progressive MAC scheme Whips and the traditional MAC scheme HMAC in user information exchanges between smart meters, power companies, and data users, efficient user information integrity protection is achieved. Background Art
[0002] To overcome the limitations of traditional power grids, such as a single energy structure and one-way information flow, and to meet the growing needs of modern society, the world is actively promoting the construction of smart grids. The core changes of smart grids are: (1) integrating multiple energy sources and building a two-way power flow: by integrating green energy such as wind and solar energy into the traditional power system, the user role is transformed from a simple consumer to a potential energy supplier ("prosumer"); (2) integrating a two-way communication network and building a two-way information flow: by integrating an advanced metering infrastructure (AMI) on the power layer and using advanced communication and sensing technologies, a two-way interaction between users and power companies is achieved. AMI includes user-side smart meters (SM), data concentrators (DC), and power companies (PC). Smart meters automatically measure user information (user identity, smart meter number, smart meter readings, real-time bills, lifestyle patterns, and grid operation logs) at fixed intervals (such as 15 minutes or 30 minutes) and aggregate the information to the power company via wired / wireless networks in the AMI. The continuous accumulation of this high-frequency, periodically collected data has generated a massive amount of user information big data. This data profoundly reflects user behavior and socioeconomic activities, and is of great significance to the development of the power system and society. Power companies can conduct data analysis and decision-making based on this real-time, comprehensive user information big data, either on their own or in conjunction with relevant departments. 1) Power companies can use this user information big data to drive efficient smart grid operation, such as: a) accurately monitoring grid status: real-time perception of system operating conditions; b) optimizing energy dispatch and distribution: dynamically matching supply and demand, improving the efficiency of renewable energy consumption; c) formulating scientific pricing strategies: supporting demand response and refined electricity pricing mechanisms; d) improving system resilience and reliability: predicting risks and rapidly responding to failures. 2) Given the close connection between user information big data and economic and social development, power companies can assist relevant departments in generating socioeconomic insights based on this data, such as: a) analyzing macroeconomic trends: assessing regional economic vitality through changes in electricity consumption; b) assisting in social governance decisions: assessing housing vacancy rates, population mobility, and industrial development; and c) providing refined public services: supporting urban planning and emergency management.
[0003] Because user information big data holds immense value, its integrity is crucial. Once its integrity is compromised or data is maliciously tampered with, a series of serious consequences can occur, impacting the normal operation of the entire power system. For example, if an attacker tampers with a residential smart meter reading, relevant departments may misjudge housing vacancy rates, thereby impacting key decisions such as real estate. In critical processes such as grid planning, equipment maintenance, pricing, and fault diagnosis at power companies, erroneous data can lead to inappropriate decisions. This not only disrupts grid operations, reduces reliability and stability, and increases operating costs, but also seriously compromises grid security and power supply quality, ultimately damaging user experience and satisfaction. Therefore, implementing effective user data integrity protection measures to ensure the authenticity and integrity of user information is a solid foundation for the secure, stable operation and sustainable development of smart grids.
[0004] Researchers have achieved certain results in protecting the integrity of user information, primarily based on blockchain technology and digital signature technology. The blockchain's immutability and distributed ledger characteristics can effectively ensure the trustworthiness of data from measurement to transmission; digital signatures, through asymmetric encryption mechanisms, provide strong identity authentication and integrity verification for the data source. While these technologies have advantages in ensuring data immutability and identity authentication, they are based on public key cryptography and have high computational complexity, leading to performance bottlenecks in resource-constrained smart meters. In contrast, message authentication code (MAC) schemes derived from symmetric cryptography are more lightweight and exhibit significant advantages in efficiency and memory usage. MAC schemes generate and verify authentication codes through shared keys, enabling rapid data integrity verification while significantly reducing storage and computational overhead, making them suitable for resource-constrained smart meters.
[0005] In summary, how to enable power companies to verify the integrity of user information in smart grids based on a lightweight MAC algorithm is the key to solving the above problems. Summary of the Invention
[0006] In order to overcome the problems existing in the above technologies, the present invention proposes a user information integrity protection method based on message authentication code for smart grid.
[0007] To achieve the above object, the technical solution adopted by the present invention is:
[0008] An efficient user information integrity protection method based on message authentication code for smart grid includes the following steps:
[0009] (1) Pre-set key and initial state:
[0010] Power companies deploy smart meters at user terminals Previously, in all smart meters Two pseudo-random functions are preset in and , and in smart meters Preset MAC key in ,in for exist The key in for exist The key in Indicates the number of the smart meter, which satisfies , Indicates the number of smart meters; then in the smart meter Prefabricate initial internal state As shown in formula (1):
[0011] , (1)
[0012] in, represents the initial sub-state, The definition is as shown in formula (2):
[0013] ; (2)
[0014] The power company then backs up the pseudo-random function, key, and initial state, and Deploy to the user end;
[0015] (2) Negotiate symmetric encryption primitives and derive symmetric encryption keys:
[0016] (2-1) Negotiate symmetric encryption primitives:
[0017] Smart meter at user end First, the symmetric encryption scheme and hash function supported by the power company are sent, and a message authentication code is added to the message sent. The specific process is as follows:
[0018] ① Smart meter The name of the symmetric encryption scheme and hash function it supports are packaged into a data packet, recorded as , then smart meters According to the current status counter reading , initial substate as well as Generate a new sub-state as shown in formula (3):
[0019] ; (3)
[0020] Then define the next state according to the new sub-state as shown in formula (4):
[0021] ; (4)
[0022] In formula (4) The definition is as shown in formula (5):
[0023] ; (5)
[0024] After that, smart meters Generate based on new state The verification label is shown in formula (6):
[0025] ; (6)
[0026] The last smart meter The generated verification tag and The package is sent to the power company, which then uses equations (3), (4) and (6) to calculate Generate verification tags and with In contrast, if Then it means The data packet has not been tampered with. If it is different, the received data packet is discarded and the data is requested to be retransmitted;
[0027] ② Power company from Select the symmetric encryption scheme it supports and hash functions , then the power company will read the current status counter , initial substate as well as and Generate a new sub-state as shown in formula (7):
[0028] ; (7)
[0029] Then define the next state according to the new sub-state as shown in formula (8):
[0030] ; (8)
[0031] The power company then generates The verification label is shown in formula (9):
[0032] ; (9)
[0033] Finally, the power company will With the generated verification tag Package and send to smart meter , smart meters The verification tag is regenerated by formula (7), (8) and (9) and compared with the received verification tag. If they are the same, it means that it has not been tampered with, and the smart meter is confirmed to be The encryption primitive for communication with the power company is , the hash function used to derive the key is ; If the integrity is violated, the data is discarded and required to be retransmitted;
[0034] (2-2) Derive the symmetric encryption key:
[0035] After determining the symmetric encryption scheme and hash function, the power company and the smart meter In the same way, use the preset Whips key The key for the symmetric encryption scheme is derived using the HKDF key derivation algorithm. The specific process is as follows:
[0036] ① Assumption The output length is ,like ( Represents the key length), then Then fill it with 0 to make its length equal to , recorded as ,like ,but ;
[0037] ② Regulations for A bit sequence of 0s, for A cyclic bit sequence of length "00110100", for The length of the "01011100" cyclic bit sequence will be and XOR, the result is recorded as ;
[0038] ③ Will Splicing in Before, the calculation is performed according to formula (10), and the calculation result is recorded as :
[0039] ; (10)
[0040] ④ Will and XOR, the result is recorded as , and then Splicing in Before, the calculation is performed as shown in formula (11), and the result is recorded as :
[0041] ; (11)
[0042] ⑤ Initialize an empty output key , initialize a counter ,initialization , and loop as follows until Until the length reaches the negotiated symmetric encryption scheme length:
[0043] First, calculate according to formula (12) :
[0044] , (12)
[0045] Then the counter is incremented by one. Calculate according to formula (13):
[0046] , (13)
[0047] In the formula Indicates the HMAC message authentication code algorithm, Indicates splicing; the final length will meet the requirements Record ;
[0048] (3) Data measurement:
[0049] In each cycle Each user-side smart meter Measure user information within this period As shown in formula (14):
[0050] ; (14)
[0051] in Indicates the real-time meter reading for the current cycle, Indicates the fault count of the current cycle, Indicates the smart meter number, Represents the weather data of the current period, Indicates the real-time bill for the current period. Indicates user information. Indicates residential power operation log, etc.;
[0052] (4) Generate verification tag and send data:
[0053] (4-1) Data encryption:
[0054] In each cycle Each user-side smart meter Through the negotiated symmetric encryption scheme using the derived key User information Encrypted into ciphertext , as shown in formula (15):
[0055] , (15)
[0056] in Represents the symmetric encryption algorithm between the smart meter and the power company;
[0057] (4-2) Update internal status:
[0058] Smart Meters Read the counter , initial substate , and the ciphertext As The input and output of the next sub-state are shown in formula (16):
[0059] ; (16)
[0060] Then define the next state ,in, The definition is shown in formula (17):
[0061] ; (17)
[0062] (4-3) Generate verification tags:
[0063] Smart Meters Read the counter , initial substate as well as As Input and output ciphertext Verification tag As shown in formula (18):
[0064] ; (18)
[0065] (4-4) Data transmission:
[0066] Smart Meters The ciphertext And the generated tags Packaged as and will After being forwarded by other smart meters and data concentrators, it is sent to the power company;
[0067] (5) Data reception and storage:
[0068] (5-1) Data reception:
[0069] Power companies receive smart meters Sent ;
[0070] (5-2) Data Verification:
[0071] The power company receives in And the backed up The internal state is recalculated according to formulas (16) and (18) to obtain its verification label , and and received in Make a comparison;
[0072] (5-3) Data decryption and storage:
[0073] If the final calculated label satisfy , then decrypt as shown in formula (19) :
[0074] , (19)
[0075] In formula (19) Represents the symmetric decryption algorithm between the smart meter and the power company. The power company will decrypt the Storage; if the final calculated label , then abandon And request data retransmission;
[0076] (6) Data Request:
[0077] Data users Submit data requests to the power company when user information is needed for data analysis or decision-making;
[0078] (7) Negotiate encryption primitives, verify identities, and exchange keys:
[0079] Data users The following steps are performed to negotiate cryptographic primitives, verify identities, and exchange keys with the power company:
[0080] ① Data users First, package the symmetric encryption scheme, hash function, and key material it supports ,in is a prime number, is the group generator, The shared value for the Diffie-Hellen key exchange protocol satisfies , then sign the above data and send the data together with the signature and its digital certificate to the power company; the hash function is used to construct the message authentication code algorithm HMAC and the key derivation algorithm HKDF;
[0081] ② The power company receives the data from the user. After the data packet is received, the data user is first verified through the certificate If the identity is incorrect, the subsequent steps will not be carried out. If the identity is correct, the integrity of the received data packet will be verified by signature. If the integrity is damaged, the data user will be notified. Make a data retransmission request. If the data integrity has not been tampered with, the power company selects the symmetric encryption scheme and hash function it supports as , and select from the key material , and then generate it autonomously (in satisfy ), after which the power company will and Pack and sign, and finally the power company sends the packaged data packet and signature together with its digital certificate to the data user ;
[0082] ③ Data users After receiving the data packet from the power company, the identity is first verified through the certificate, and then the integrity is verified through the signature (the process is the same as the power company verification process ②). calculate ;
[0083] ④ Calculation by power company The final calculated The power company and the data user The master key used for communication between ;
[0084] ⑤ Power companies and data users In the same way, using the key The keys for the symmetric encryption algorithm and HMAC are derived using the HKDF key derivation algorithm. The specific process is as follows:
[0085] 1) Assumptions The output length is ,like ( Represents the key length), then in Then fill it with 0 to make its length equal to , recorded as ,like ,but ;
[0086] 2) Regulations for A bit sequence of 0s, for A cyclic bit sequence of length "00110100", for The length of the "01011100" cyclic bit sequence will be and XOR, the result is recorded as ;
[0087] 3) Splicing in Before, the calculation is performed according to formula (20), and the calculation result is recorded as :
[0088] ; (20)
[0089] 4) and XOR, the result is recorded as , and then Splicing in Before, the calculation is performed as shown in formula (21), and the result is recorded as :
[0090] ; (twenty one)
[0091] 5) The key of the symmetric encryption scheme generated subsequently is recorded as , the HMAC key is recorded as , initialize an empty output key , initialize a counter ,initialization , and loop as follows until Length reaches So far, among them Indicates length:
[0092] First, calculate according to formula (22) :
[0093] , (twenty two)
[0094] Then the counter is incremented by one. Calculate according to formula (23):
[0095] , (twenty three)
[0096] In the formula Indicates the HMAC message authentication code algorithm, Indicates splicing;
[0097] The length requirement will eventually be met Center front Part of it is used as the key for the symmetric encryption scheme, and the rest is used as the HMAC key;
[0098] (8) Download user information and use:
[0099] (8-1) Download user information:
[0100] Power companies will provide data users with Required user information data Encrypted into ciphertext using the negotiated symmetric encryption algorithm As shown in formula (24):
[0101] , (twenty four)
[0102] in Indicates the symmetric encryption algorithm negotiated by the power company and the data user; the power company then uses the ciphertext Based on the derived key The verification tag is generated by HMAC as shown in formula (25):
[0103] ; (25)
[0104] The power company will then send the encrypted and verification tags Packaged as , data users Download from the power company ;
[0105] (8-2) Data Usage:
[0106] Data users Download to Then, the verification label is regenerated by formula (25) in Compare, if they are consistent, it means the ciphertext Not tampered with, data user decrypts As shown in formula (26):
[0107] , (26)
[0108] After that, the data user will use the decrypted Perform data analysis and decision making; if the regenerated verification labels are in If they are inconsistent, re-download.
[0109] Step (1) of the invented method is executed once by the power company; steps (2) to (5) are interaction steps between the smart meter and the power company, based on the progressive message authentication code scheme Whips, and are executed once in each cycle; steps (6) to (8) are interaction steps between the data user and the power company, based on the traditional message authentication code scheme HMAC, and are executed by the data user when he needs to use the user information. Compared with the blockchain technology and digital signature technology derived from the public key cryptography system, the label length of the Whips and HMAC schemes is shorter, and the time to verify the label is also shorter. Among them, Whips is a progressive message authentication code scheme. The smart meter generates the verification label of the user information, and the power company verifies it after receiving it. It is particularly suitable for resource-constrained smart meters because it has the following three advantages: ① A shorter output label length can be achieved through a pseudo-random function, reducing the storage overhead of the smart meter; ② It allows the resynchronization of data packets, avoiding the potential risk of data packet loss on subsequent data analysis; ③ The integrity of the current data packet is determined by the label generated by the current data packet and the subsequent The tags are jointly protected to achieve short verification tags while taking high security into consideration.
[0110] Therefore, the present invention has the following advantages:
[0111] In terms of lightweightness, Whips has a shorter verification tag while ensuring high security, making it suitable for resource-constrained smart meters.
[0112] In terms of integrity verification, the integrity of user information is ensured by the progressive message authentication code Whips when it is uploaded from the smart meter to the power company, and by the traditional message authentication code scheme HMAC between the data user and the power company, achieving full process integrity verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0113] Figure 1 This is a flow chart of a method for protecting user information integrity based on message authentication codes in smart grids;
[0114] Figure 2 It is a graph of the average generation time of verification tags generated by smart meters based on Whips;
[0115] Figure 3 This is a graph of the average generation time of HMAC-based verification tags generated by power companies;
[0116] Figure 4 This is a comparison chart of the verification tag generation time of Whips, HMAC and other integrity verification schemes;
[0117] Figure 5 This is a comparison chart of the verification tag lengths generated by Whips, HMAC, and other integrity verification schemes under different hash functions; DETAILED DESCRIPTION
[0118] The present invention is described in further detail below with reference to the accompanying drawings:
[0119] like Figure 1 As shown, the user information integrity protection method based on message authentication code in the smart grid described in this embodiment has the following specific steps:
[0120] (1) Pre-set key and initial state:
[0121] Power companies deploy smart meters at user terminals Previously, in all smart meters Two pseudo-random functions are preset in and , and in smart meters Preset MAC key in ,in for exist The key in for exist The key in Indicates the number of the smart meter, which satisfies , Indicates the number of smart meters; then in the smart meter Prefabricate initial internal state As shown in formula (1):
[0122] , (1)
[0123] in, represents the initial sub-state, The definition is as shown in formula (2):
[0124] ; (2)
[0125] The power company then backs up the pseudo-random function, key, and initial state, and Deploy to the user end;
[0126] (2) Negotiate symmetric encryption primitives and derive symmetric encryption keys:
[0127] (2-1) Negotiate symmetric encryption primitives:
[0128] Smart meter at user end First, the symmetric encryption scheme and hash function supported by the power company are sent, and a message authentication code is added to the message sent. The specific process is as follows:
[0129] ① Smart meter The name of the symmetric encryption scheme and hash function it supports are packaged into a data packet, recorded as , then smart meters According to the current status counter reading , initial substate as well as Generate a new sub-state as shown in formula (3):
[0130] ; (3)
[0131] Then define the next state according to the new sub-state as shown in formula (4):
[0132] ; (4)
[0133] In formula (4) The definition is as shown in formula (5):
[0134] ; (5)
[0135] After that, smart meters Generate based on new state The verification label is shown in formula (6):
[0136] ; (6)
[0137] The last smart meter The generated verification tag and The package is sent to the power company, which then uses equations (3), (4) and (6) to calculate Generate verification tags and with In contrast, if Then it means The data packet has not been tampered with. If it is different, the received data packet is discarded and the data is requested to be retransmitted;
[0138] ② Power company from Select the symmetric encryption scheme it supports and hash functions , then the power company will read the current status counter , initial substate as well as and Generate a new sub-state as shown in formula (7):
[0139] ; (7)
[0140] Then define the next state according to the new sub-state as shown in formula (8):
[0141] ; (8)
[0142] The power company then generates The verification label is shown in formula (9):
[0143] ; (9)
[0144] Finally, the power company will With the generated verification tag Package and send to smart meter , smart meters The verification tag is regenerated by formula (7), (8) and (9) and compared with the received verification tag. If they are the same, it means that it has not been tampered with, and the smart meter is confirmed to be The encryption primitive for communication with the power company is , the hash function used to derive the key is ; If the integrity is violated, the data is discarded and required to be retransmitted;
[0145] (2-2) Derive the symmetric encryption key:
[0146] After determining the symmetric encryption scheme and hash function, the power company and the smart meter In the same way, use the preset Whips key The key for the symmetric encryption scheme is derived using the HKDF key derivation algorithm. The specific process is as follows:
[0147] ① Assumption The output length is ,like ( Represents the key length), then Then fill it with 0 to make its length equal to , recorded as ,like ,but ;
[0148] ② Regulations for A bit sequence of 0s, for A cyclic bit sequence of length "00110100", for The length of the "01011100" cyclic bit sequence will be and XOR, the result is recorded as ;
[0149] ③ Will Splicing in Before, the calculation is performed according to formula (10), and the calculation result is recorded as :
[0150] ; (10)
[0151] ④ Will and XOR, the result is recorded as , and then Splicing in Before, the calculation is performed as shown in formula (11), and the result is recorded as :
[0152] ; (11)
[0153] ⑤ Initialize an empty output key , initialize a counter ,initialization , and loop as follows until Until the length reaches the negotiated symmetric encryption scheme length:
[0154] First, calculate according to formula (12) :
[0155] , (12)
[0156] Then the counter is incremented by one. Calculate according to formula (13):
[0157] , (13)
[0158] In the formula Indicates the HMAC message authentication code algorithm, Indicates splicing; the final length will meet the requirements Record ;
[0159] (3) Data measurement:
[0160] In each cycle Each user-side smart meter Measure user information within this period As shown in formula (14):
[0161] ; (14)
[0162] in Indicates the real-time meter reading for the current cycle, Indicates the fault count of the current cycle, Indicates the smart meter number, Indicates the weather data of the current period, Indicates the real-time bill for the current period. Indicates user information. Indicates residential power operation log, etc.;
[0163] (4) Generate verification tag and send data:
[0164] (4-1) Data encryption:
[0165] In each cycle Each user-side smart meter Through the negotiated symmetric encryption scheme using the derived key User information Encrypted into ciphertext , as shown in formula (15):
[0166] , (15)
[0167] in Represents the symmetric encryption algorithm between the smart meter and the power company;
[0168] (4-2) Update internal status:
[0169] Smart Meters Read the counter , initial substate , and the ciphertext As The input and output of the next sub-state are shown in formula (16):
[0170] ; (16)
[0171] Then define the next state ,in, The definition is shown in formula (17):
[0172] ; (17)
[0173] (4-3) Generate verification tags:
[0174] Smart Meters Read the counter , initial substate as well as As Input and output ciphertext Verification tag As shown in formula (18):
[0175] ; (18)
[0176] (4-4) Data transmission:
[0177] Smart Meters The ciphertext And the generated tags Packaged as and will After being forwarded by other smart meters and data concentrators, it is sent to the power company;
[0178] (5) Data reception and storage:
[0179] (5-1) Data reception:
[0180] Power companies receive smart meters Sent ;
[0181] (5-2) Data Verification:
[0182] The power company receives in And the backed up The internal state is recalculated according to formulas (16) and (18) to obtain its verification label , and and received in Make a comparison;
[0183] (5-3) Data decryption and storage:
[0184] If the final calculated label satisfy , then decrypt as shown in formula (19) :
[0185] , (19)
[0186] In formula (19) Represents the symmetric decryption algorithm between the smart meter and the power company. The power company will decrypt the Storage; if the final calculated label , then abandon And request data retransmission;
[0187] (6) Data Request:
[0188] Data users Submit data requests to the power company when user information is needed for data analysis or decision-making;
[0189] (7) Negotiate encryption primitives, verify identities, and exchange keys:
[0190] Data users The following steps are performed to negotiate cryptographic primitives, verify identities, and exchange keys with the power company:
[0191] ① Data users First, package the symmetric encryption scheme, hash function, and key material it supports ,in is a prime number, is the group generator, The shared value for the Diffie-Hellen key exchange protocol satisfies , then sign the above data and send the data together with the signature and its digital certificate to the power company; the hash function is used to construct the message authentication code algorithm HMAC and the key derivation algorithm HKDF;
[0192] ② The power company receives the data from the user. After the data packet is received, the data user is first verified through the certificate If the identity is incorrect, the subsequent steps will not be carried out. If the identity is correct, the integrity of the received data packet will be verified by signature. If the integrity is damaged, the data user will be notified. Make a data retransmission request. If the data integrity has not been tampered with, the power company selects the symmetric encryption scheme and hash function it supports as , and select from the key material , and then generate it autonomously (in satisfy ), after which the power company will and Pack and sign, and finally the power company sends the packaged data packet and signature together with its digital certificate to the data user ;
[0193] ③ Data users After receiving the data packet from the power company, the identity is first verified through the certificate, and then the integrity is verified through the signature (the process is the same as the power company verification process ②). calculate ;
[0194] ④ Calculation by power company The final calculated The power company and the data user The master key used for communication between ;
[0195] ⑤ Power companies and data users In the same way, using the key The keys for the symmetric encryption algorithm and HMAC are derived using the HKDF key derivation algorithm. The specific process is as follows:
[0196] 1) Assumptions The output length is ,like ( Represents the key length), then in Then fill it with 0 to make its length equal to , recorded as ,like ,but ;
[0197] 2) Regulations for A bit sequence of 0s, for A cyclic bit sequence of length "00110100", for The length of the "01011100" cyclic bit sequence will be and XOR, the result is recorded as ;
[0198] 3) Splicing in Before, the calculation is performed according to formula (20), and the calculation result is recorded as :
[0199] ; (20)
[0200] 4) and XOR, the result is recorded as , and then Splicing in Before, the calculation is performed as shown in formula (21), and the result is recorded as :
[0201] ; (twenty one)
[0202] 5) The key of the symmetric encryption scheme generated subsequently is recorded as , the HMAC key is recorded as , initialize an empty output key , initialize a counter ,initialization , and loop as follows until Length reaches So far, among them Indicates length:
[0203] First, calculate according to formula (22) :
[0204] , (twenty two)
[0205] Then the counter is incremented by one. Calculate according to formula (23):
[0206] , (twenty three)
[0207] In the formula Indicates the HMAC message authentication code algorithm, Indicates splicing;
[0208] The length requirement will eventually be met Center front Part of it is used as the key for the symmetric encryption scheme, and the rest is used as the HMAC key;
[0209] (8) Download user information and use:
[0210] (8-1) Download user information:
[0211] Power companies will provide data users with Required user information data Encrypted into ciphertext using the negotiated symmetric encryption algorithm As shown in formula (24):
[0212] , (twenty four)
[0213] in Indicates the symmetric encryption algorithm negotiated by the power company and the data user; the power company then uses the ciphertext Based on the derived key The verification tag is generated by HMAC as shown in formula (25):
[0214] ; (25)
[0215] The power company will then send the encrypted and verification tags Packaged as , data users Download from the power company ;
[0216] (8-2) Data Usage:
[0217] Data users Download to Then, the verification label is regenerated by formula (25) in Compare, if they are consistent, it means the ciphertext Not tampered with, data user decrypts As shown in formula (26):
[0218] , (26)
[0219] After that, the data user will use the decrypted Perform data analysis and decision making; if the regenerated verification labels are in If they are inconsistent, re-download.
[0220] The present invention verifies and designs experiments for two aspects: (1) verification of the effectiveness of the invention method and (2) verification of the efficiency of the invention method.
[0221] Regarding “(1) Verification of the effectiveness of the invention method”, 500 groups of random experiments were conducted to verify whether the invention method can operate normally and in a short time. First, each group of experiments was set up as follows: AES was selected as the symmetric encryption scheme between the smart meter and the power company and between the power company and the data user; the hash function SHA-256 was used as a pseudo-random function; the number of user-side smart meters and data users was random (i.e. Random values, The user-side smart meter randomly selects an element as plaintext to encrypt. The average time it takes for the smart meter to generate the Whips verification tag in each experiment is used as the Whips verification tag generation time (in milliseconds) for that experiment. The average time it takes for the power company to generate the HMAC verification tag in each experiment is used as the HMAC verification tag generation time (in milliseconds) for that experiment.
[0222] Two different sets of experiments were conducted for "(2) Verification of the efficiency of the invention method". In the first set of experiments, 500 sets of random experiments were conducted, with the average verification tag generation time (ms) (the average verification tag generation time of each smart meter) as the comparison standard. Under the same experimental settings as experiment (1), 500 random experiments were conducted on the Whips, HMAC and RSA, ECDSA, and EDDSA digital signature schemes used in the present invention. In the second set of experiments, the signature scheme used the key length in the actual scenario, that is, the RSA key length was set to 256 bytes, and the ECDSA and EDDSA key lengths were set to 32 bytes. The other experimental settings were the same as the third set of experiments. The hash functions used were SHA-224, SHA-256 and SHA-384 respectively for the experiments. Each hash function was subjected to 500 experiments to compare the tag lengths under different hash functions.
[0223] For all 500 random experiments in Experiment (1), Figure 2 The average time it takes to generate verification labels for Whips in 500 random experiments is shown. Figure 3 The average generation and verification tag time of HMAC in 500 random experiments is shown. Figure 2 It can be seen from the figure that the integrity verification between the smart meter and the power company can be performed normally and the execution time is short. Figure 2 It can be seen that the average time for generating verification labels in each group of experiments does not exceed 0.6ms. Among them, the time for generating verification labels in group 31 is the longest, which is 0.51ms. Figure 3 The average generation and verification tag time of HMAC in 500 random experiments is shown. Figure 3 It can be seen from the above that the integrity verification between the power company and the data user can be performed normally and the execution time is short. Figure 3 It can be seen that the average time for generating verification labels in each group of experiments does not exceed 0.45ms, among which the time for generating verification labels in group 124 is the longest, which is 0.41ms.
[0224] Figure 4 The comparison of the verification tag generation time of Whips and HMAC used in 500 random experiments in Experiment (2) with other integrity verification schemes shows that Whips and HMAC have more advantages in generating verification tags than other integrity verification schemes. Figure 4In the 150th experiment, the time for Whips to generate a verification tag was 0.06ms, and the time for HMAC to generate a verification tag was 0.05ms. Under the same conditions, the time for RSA signature scheme to generate a verification tag was 0.89ms, the time for ECDSA signature scheme to generate a verification tag was 0.18ms, and the time for EDDSA signature scheme to generate a verification tag was 0.13ms. These experiments verify that the computational overhead of Whips used in the method of the present invention is relatively small.
[0225] Figure 5 This figure compares the length of verification tags generated by Whips and HMAC, used in the present invention's method in Experiment (2), with other integrity verification schemes under different hash functions. It can be seen that Whips has an advantage in generating verification tag length compared to other integrity verification schemes. As shown in the figure, the tag length generated by Whips is shorter than that of the RSA signature scheme, the ECDSA signature scheme, and the EDDSA signature scheme, indicating that Whips has an advantage in terms of communication overhead.
Claims
1. An efficient user information integrity protection method based on message authentication code in smart grid, characterized in that: The following steps are involved: (1) Pre-set key and initial state: Power companies deploy smart meters at user terminals Previously, in all smart meters Two pseudo-random functions are preset in and , and in smart meters Preset MAC key in ,in for exist The key in for exist The key in Indicates the number of the smart meter, which satisfies , Indicates the number of smart meters; then in the smart meter Prefabricate initial internal state As shown in formula (1): , (1) in, represents the initial sub-state, The definition is as shown in formula (2): ; (2) The power company then backs up the pseudo-random function, key, and initial state, and Deploy to the user end; (2) Negotiate symmetric encryption primitives and derive symmetric encryption keys: (2-1) Negotiate symmetric encryption primitives: Smart meter at user end First, the symmetric encryption scheme and hash function supported by the power company are sent, and a message authentication code is added to the message sent. The specific process is as follows: ① Smart meter The name of the symmetric encryption scheme and hash function it supports are packaged into a data packet, recorded as , then smart meters According to the current status counter reading , initial substate as well as Generate a new sub-state as shown in formula (3): ; (3) Then define the next state according to the new sub-state as shown in formula (4): ; (4) In formula (4) The definition is as shown in formula (5): ; (5) After that, smart meters Generate based on new state The verification label is shown in formula (6): ; (6) The last smart meter The generated verification tag and The package is sent to the power company, which then uses equations (3), (4) and (6) to calculate Generate verification tags and with In contrast, if Then it means The data packet has not been tampered with. If it is different, the received data packet is discarded and the data is requested to be retransmitted; ② Power company from Select the symmetric encryption scheme it supports and hash functions , then the power company will read the current status counter , initial substate as well as and Generate a new sub-state as shown in formula (7): ; (7) Then define the next state according to the new sub-state as shown in formula (8): ; (8) The power company then generates The verification label is shown in formula (9): ; (9) Finally, the power company will With the generated verification tag Package and send to smart meter , smart meters The verification tag is regenerated by formula (7), (8) and (9) and compared with the received verification tag. If they are the same, it means that it has not been tampered with, and the smart meter is confirmed to be The encryption primitive for communication with the power company is , the hash function used to derive the key is ; If the integrity is violated, the data is discarded and required to be retransmitted; (2-2) Derive the symmetric encryption key: After determining the symmetric encryption scheme and hash function, the power company and the smart meter In the same way, use the preset Whips key The key for the symmetric encryption scheme is derived using the HKDF key derivation algorithm. The specific process is as follows: ① Assumption The output length is ,like ( Represents the key length), then Then fill it with 0 to make its length equal to , recorded as ,like ,but ; ② Regulations for A bit sequence of 0s, for A cyclic bit sequence of length "00110100", for The length of the "01011100" cyclic bit sequence will be and XOR, the result is recorded as ; ③ Will Splicing in Before, the calculation is performed according to formula (10), and the calculation result is recorded as : ; (10) ④ Will and XOR, the result is recorded as , and then Splicing in Before, the calculation is performed as shown in formula (11), and the result is recorded as : ; (11) ⑤ Initialize an empty output key , initialize a counter ,initialization , and loop as follows until Until the length reaches the negotiated symmetric encryption scheme length: First, calculate according to formula (12) : , (12) Then the counter is incremented by one. Calculate according to formula (13): , (13) In the formula Indicates the HMAC message authentication code algorithm, Indicates splicing; the final length will meet the requirements Record ; (3) Data measurement: In each cycle Each user-side smart meter Measure user information within this period As shown in formula (14): ; (14) in Indicates the real-time meter reading for the current cycle, Indicates the fault count of the current cycle, Indicates the smart meter number, Represents the weather data of the current period, Indicates the real-time bill for the current period. Indicates user information. Indicates residential power operation log, etc.; (4) Generate verification tag and send data: (4-1) Data encryption: In each cycle Each user-side smart meter Through the negotiated symmetric encryption scheme using the derived key User information Encrypted into ciphertext , as shown in formula (15): , (15) in Represents the symmetric encryption algorithm between smart meters and power companies; (4-2) Update internal status: Smart Meters Read the counter , initial substate , and the ciphertext As The input and output of the next sub-state are shown in formula (16): ; (16) Then define the next state ,in, The definition is shown in formula (17): ; (17) (4-3) Generate verification tags: Smart Meters Read the counter , initial substate as well as As Input and output ciphertext Verification tag As shown in formula (18): ; (18) (4-4) Data transmission: Smart Meters The ciphertext And the generated tags Packaged as and will After being forwarded by other smart meters and data concentrators, it is sent to the power company; (5) Data reception and storage: (5-1) Data reception: Power companies receive smart meters Sent ; (5-2) Data Verification: The power company receives in And the backed up The internal state is recalculated according to formulas (16) and (18) to obtain its verification label , and and received in Make a comparison; (5-3) Data decryption and storage: If the final calculated label satisfy , then decrypt as shown in formula (19) : , (19) In formula (19) Represents the symmetric decryption algorithm between the smart meter and the power company. The power company will decrypt the Storage; if the final calculated label , then abandon And request data retransmission; (6) Data Request: Data users Submit data requests to the power company when user information is needed for data analysis or decision-making; (7) Negotiate encryption primitives, verify identities, and exchange keys: Data users The following steps are performed to negotiate cryptographic primitives, verify identities, and exchange keys with the power company: ① Data users First, package the symmetric encryption scheme, hash function, and key material it supports ,in is a prime number, is the group generator, The shared value for the Diffie-Hellen key exchange protocol satisfies , then sign the above data and send the data together with the signature and its digital certificate to the power company; the hash function is used to construct the message authentication code algorithm HMAC and the key derivation algorithm HKDF; ② The power company receives the data from the user. After the data packet is received, the data user is first verified through the certificate If the identity is incorrect, the subsequent steps will not be carried out. If the identity is correct, the integrity of the received data packet will be verified by signature. If the integrity is damaged, the data user will be notified. Make a data retransmission request. If the data integrity has not been tampered with, the power company selects the symmetric encryption scheme and hash function it supports as , and select from the key material , and then generate it autonomously (in satisfy ), after which the power company will and Pack and sign, and finally the power company sends the packaged data packet and signature together with its digital certificate to the data user ; ③ Data users After receiving the data packet from the power company, the identity is first verified through the certificate, and then the integrity is verified through the signature (the process is the same as the power company verification process ②). calculate ; ④ Calculation by power company The final calculated The power company and the data user The master key used for communication between ; ⑤ Power companies and data users In the same way, using the key The keys for the symmetric encryption algorithm and HMAC are derived using the HKDF key derivation algorithm. The specific process is as follows: 1) Assumptions The output length is ,like ( Represents the key length), then in Then fill it with 0 to make its length equal to , recorded as ,like ,but ; 2) Regulations for A bit sequence of 0s, for A cyclic bit sequence of length "00110100", for The length of the "01011100" cyclic bit sequence will be and XOR, the result is recorded as ; 3) Splicing in Before, the calculation is performed according to formula (20), and the calculation result is recorded as : ; (20) 4) and XOR, the result is recorded as , and then Splicing in Before, the calculation is performed as shown in formula (21), and the result is recorded as : ; (21) 5) The key of the symmetric encryption scheme generated subsequently is recorded as , the HMAC key is recorded as , initialize an empty output key , initialize a counter ,initialization , and loop as follows until Length reaches So far, among them Indicates length: First, calculate according to formula (22) : , (22) Then the counter is incremented by one. Calculate according to formula (23): , (23) In the formula Indicates the HMAC message authentication code algorithm, Indicates splicing; The length requirement will eventually be met Center front Part of it is used as the key for the symmetric encryption scheme, and the rest is used as the HMAC key; (8) Download user information and use: (8-1) Download user information: Power companies will provide data users with Required user information data Encrypted into ciphertext using the negotiated symmetric encryption algorithm As shown in formula (24): , (24) in Indicates the symmetric encryption algorithm negotiated by the power company and the data user; the power company then uses the ciphertext Based on the derived key The verification tag is generated by HMAC as shown in formula (25): ; (25) The power company will then send the encrypted and verification tags Packaged as , data users Download from the power company ; (8-2) Data Usage: Data users Download to Then, the verification label is regenerated by formula (25) in Compare, if they are consistent, it means the ciphertext Not tampered with, data user decrypts As shown in formula (26): , (26) After that, the data user will use the decrypted Perform data analysis and decision making; if the regenerated verification labels are in If they are inconsistent, re-download.