Power system data secure transmission method and system based on national cryptographic algorithm

By employing layered encryption transmission and dynamic key management based on the SM2/SM3/SM4 national cryptographic algorithms, the security and efficiency issues of traditional encryption algorithms in the power Internet of Things (IoT) are resolved, enabling efficient and secure transmission of power system data. This technology is suitable for smart grid IoT systems.

CN121098513APending Publication Date: 2025-12-09GUODIAN NANJING AUTOMATION SOFTWARE ENG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511284011.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing technologies struggle to balance resource constraints, real-time requirements, and security strength in the power Internet of Things. Traditional encryption algorithms are easily cracked in quantum computing environments, key management is complex, and data integrity verification mechanisms are weak. National cryptographic algorithms are inefficient and lack collaborative design in power scenarios, making it difficult to balance security and availability.

Method used

Employing the SM2/SM3/SM4 national cryptographic algorithms, and through a layered encryption transmission strategy and dynamic key management, the terminal device and the master station system perform two-way identity authentication to generate an initial session key. Then, through SM4 symmetric encryption, SM3 digest verification and lightweight encapsulation protocol, combined with a timestamp and event-driven key update strategy, an end-to-end secure link is constructed.

Benefits of technology

It achieves improved encryption efficiency, resists quantum computing threats, prevents replay attacks, and ensures data confidentiality and integrity while being compatible with existing power communication protocols, making it suitable for power systems with high real-time and security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098513A_ABST
    Figure CN121098513A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric power information security, in particular to an electric power system data security transmission method and system based on a national cryptographic algorithm, and the method comprises the steps: a terminal device and a master station system respectively generate an SM2 key pair, write a public key into a digital certificate signed and issued by a CA, and securely store a private key and a certificate chain locally; the terminal equipment establishes connection with the master station system and performs bidirectional identity authentication; after the bidirectional identity authentication succeeds, the terminal equipment and the master station system derive a session key of an initial version through an SM2 key exchange protocol; data transmission is carried out between the terminal equipment and the master station system through a layered encryption transmission strategy; and in a data transmission process, generating a dynamically updated session key based on a key updating strategy, and performing data transmission between the terminal equipment and the master station system by adopting the session key of the latest version. According to the invention, multiple national secret algorithms are fused, end-to-end confidentiality, integrity and real-time identity authentication are realized in a closed loop, and the security of power data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power information security, in particular to a power system data security transmission method and system based on a national encryption algorithm. BACKGROUND

[0002] With the deep integration of smart grid and Internet of Things technology, the power system is gradually building an Internet of Things system covering the whole link of generation, transmission, distribution and use. This change realizes the real-time perception of the power grid state and the efficient interaction of data through a large number of intelligent terminal devices (such as smart meters, distribution network automation terminals, distributed energy controllers, etc.), which provides key support for power grid operation optimization, user behavior analysis and new energy consumption. However, the security of power system data transmission under the Internet of Things architecture faces multiple challenges, and the core contradiction is concentrated in the following aspects: Limitations of traditional encryption algorithms: The current international mainstream encryption algorithms such as RSA and AES widely used in power communication networks have inherent defects. RSA algorithm relies on the difficulty of large integer factorization and faces the risk of being cracked by Shor algorithm in the quantum computing environment; AES algorithm has high efficiency, but its static key mode is difficult to adapt to the scene demand of dynamic access of Internet of Things terminals. In addition, the key management of traditional algorithms relies on a centralized certificate system, which is prone to single point failure in a distributed Internet of Things environment, and the key update mechanism is complex, which is difficult to meet the scalability requirements after large-scale deployment of power terminals.

[0003] Conflict between power terminal device resource constraints and encryption efficiency: Power Internet of Things terminals (such as low-power sensors and edge computing nodes) generally have limited computing power, small storage space, and short battery life. Traditional encryption algorithms (such as AES-256) require high computing resources, resulting in increased data encryption / decryption delay, especially in scenarios such as distribution network differential protection and distributed energy regulation that require high-frequency data interaction, which may affect the real-time requirements of the power system. Although some solutions improve efficiency through hardware acceleration, they increase the cost of terminals, which is contrary to the construction goal of low cost and wide coverage of the power Internet of Things.

[0004] Weak data integrity verification mechanism: Existing power communication protocols (such as IEC 60870-5-104 and DL / T634.5104) mostly use lightweight verification methods such as CRC, which can only detect random errors and cannot resist malicious tampering attacks. Attackers can tamper with control instructions or fake measurement data through man-in-the-middle attacks, which may cause serious consequences such as relay protection misoperation and new energy off-grid. Although the integrity protection scheme based on hash function (such as HMAC) can improve security, it requires additional computational overhead, which is difficult to implement in resource-constrained terminals.

[0005] Lack of application adaptability of national cryptographic algorithms: Although the self-designed SM2, SM3, SM4 and other national cryptographic algorithms have advantages in compliance, there are still technical bottlenecks in the power scene. The SM4 block encryption algorithm needs to be iterated multiple times when encrypting long data, which is less efficient than the stream encryption mode. Although the SM2 elliptic curve public key algorithm has quantum resistance, its key agreement process relies on fixed parameters, making it difficult to support temporary session key generation in the dynamic networking scenario of terminals. Existing researches mainly focus on the transplantation application of single national cryptographic algorithm, lack of collaborative design for multiple business needs of power Internet of Things (such as control instruction encryption, measurement data integrity verification, and device identity authentication), resulting in the difficulty in balancing the three goals of confidentiality, integrity and availability.

[0006] Defects in the comprehensive performance of existing solutions: Some existing technical researches try to improve the performance through lightweight improvement (such as SM4 truncated encryption), but there are the following problems: first, relying on a single encryption mechanism, not building a layered security system, which cannot meet the needs of high-strength encryption of control instructions and low-overhead transmission of state data at the same time; second, not designing an adaptive encryption strategy according to the computing power characteristics of power terminals, such as dynamically adjusting the encryption strength according to the device type (edge gateway / sensor); third, lacking an end-to-end security collaboration framework, resulting in fragmentation of key agreement, data encryption, and integrity verification, increasing the complexity of protocol interaction.

[0007] In summary, existing technologies cannot balance the resource constraints, real-time requirements and security strength of power Internet of Things, and there is an urgent need for a new data transmission protection mechanism that integrates lightweight encryption, dynamic key agreement and multi-dimensional security verification to support the reliable operation of the smart grid Internet of Things system. SUMMARY

[0008] The purpose of the present application is to provide a power system data security transmission method and system based on national cryptographic algorithms to solve at least one of the above technical problems.

[0009] The present application achieves the above-mentioned purposes through the following technical solutions: A power system data security transmission method based on national cryptographic algorithms, comprising: The terminal device and the master station system generate SM2 key pairs respectively and write the public key into the digital certificate issued by CA, and store the private key and certificate chain locally; The terminal device and the master station system establish a connection and perform bidirectional identity authentication; After successful bidirectional identity authentication, the terminal device and the master station system derive an initial version of the session key through the SM2 key exchange protocol; The terminal device and the master station system perform data transmission through a layered encryption transmission strategy; In the data transmission process, a dynamic updated session key is generated based on a key update strategy, and the terminal device and the master station system use the latest version of the session key for data transmission.

[0010] Further, the layered encryption transmission strategy comprises: The core data layer performs symmetric encryption on the power critical data through an SM4 algorithm; The verification layer generates a data digest through an SM3 algorithm and binds the data digest with the encrypted data; The transmission layer encapsulates the encrypted data and the verification information into a target message format adapted to the power communication protocol through a lightweight encapsulation protocol.

[0011] Further, the power critical data comprises electric energy and control instructions.

[0012] Further, the target message format is [Header][SM4 encrypted data][SM3 digest][timestamp][signature].

[0013] Further, the key update strategy comprises a timestamp triggered update strategy and an event driven update strategy. The timestamp triggered update strategy is that the session key is automatically updated once every preset time interval. The event driven update strategy is that when the security gateway detects abnormal traffic or attack behavior, the key is immediately reset, and the terminal device and the master station system rollback the session key to the previous version.

[0014] Further, the timestamp triggered update strategy comprises the following process: The master station system is responsible for timing, and when the time interval from the last key update reaches the preset time, the key is reset; the master station system carries a key update instruction through the next downlink message; After receiving the key update instruction, the terminal device verifies the signature and updates the session key; The communication parties perform data transmission through the latest version of the session key.

[0015] Further, the event driven update strategy comprises the following process: The security gateway detects abnormal traffic in real time, and immediately sends alarm information to the master station system after discovering an attack; The master station system verifies the alarm information, and after verification, the master station system broadcasts a key reset instruction to all related terminal devices; the security gateway synchronously discards all old sessions using the old key; The terminal device and the master station system perform data transmission through the reset session key.

[0016] Further, the terminal device and the master station system use the latest version of the session key for data transmission, comprising: when any party fails to correctly decrypt or verify the signature for a preset number of times in succession, the two parties return to the two-way identity authentication stage to rehandshake.

[0017] A power system data security transmission system based on a national cryptographic algorithm adopts the power system data security transmission method based on the national cryptographic algorithm as claimed in any one of the above, and the transmission system comprises a terminal device, an encryption module and a master station system. The terminal device is used for collecting power key data, storing and running a local SM2 key pair and a digital certificate, completing two-way identity authentication with the master station system, receiving and executing a key update instruction, performing SM4 encryption, SM3 digest calculation and message packaging on the power key data according to a dynamic session key, and then sending the power key data. The encryption module is embedded in the terminal device and / or the master station system, and is used for performing SM2 signature and verification, SM2 key exchange, SM4 symmetric encryption / decryption, SM3 digest generation and session key derivation, and providing a hardware acceleration interface. The master station system is used for storing and running a local SM2 key pair and a digital certificate, completing two-way identity authentication with the terminal device, maintaining a session key version number, generating and distributing a key update instruction according to a key update strategy, and performing SM4 decryption, SM3 integrity verification and source authentication on received data according to a dynamic session key.

[0018] Further, the transmission system further comprises a security gateway. The security gateway is deployed on a communication link between the terminal device and the master station system, and is used for mirroring and detecting network traffic in real time, sending alarm information to the master station system when abnormal traffic or attack behavior is found, triggering key resetting by the master station system after verification of the alarm, and synchronously discarding old key session data by the security gateway.

[0019] The present application has the following advantages: The present application adopts a national cryptographic algorithm deep fusion architecture, solves the message expansion problem of traditional encryption schemes in IEC 60870-5-104 and other protocols through the adaptability modification of SM2 / SM3 / SM4 algorithms and power communication protocols, and adopts a lightweight packaging protocol to reduce encryption overhead and improve encryption efficiency.

[0020] The present application adopts a dynamic key management mechanism, improves data transmission security through a dual-mode key update strategy, adopts a periodic rotation mechanism in the time dimension, and constructs a security gateway linkage triggering system in the event dimension.

[0021] The layered defense system is constructed through a three-level protection architecture of a core data layer, a verification layer and a transmission layer, SM4 encryption guarantees data confidentiality, SM3 hash ensures data integrity, a time stamp + digital signature double anti-replay mechanism can resist replay attacks, man-in-the-middle attacks and other threats, and meets the real-time encryption needs of millisecond-level control instructions of the smart grid.

[0022] The present application adds a security expansion unit through a message format reconstruction technology, while being compatible with existing power communication protocols, improves the interconnection rate of equipment, and is suitable for distributed photovoltaic grid-connected, differential protection and other scenes with double requirements of real-time and security. BRIEF DESCRIPTION OF DRAWINGS

[0023] Figure 1 A flowchart of a power system data security transmission method based on a national secret algorithm according to an embodiment of the present application is shown in FIG. 1. Figure 2 A layered encryption transmission strategy diagram according to an embodiment of the present application is shown in FIG. 2. Figure 3 A key update strategy diagram according to an embodiment of the present application is shown in FIG. 3. Figure 4 A structure diagram of a power system data security transmission system based on a national secret algorithm according to an embodiment of the present application is shown in FIG. 4. DETAILED DESCRIPTION

[0024] The content of the present application will now be discussed with reference to exemplary embodiments. It should be understood that the discussed embodiments are only for better understanding and thus implementing the content of the present application by those of ordinary skill in the art, rather than implying any limitation to the scope of the present application.

[0025] As used herein, the term “comprising” and variations thereof are to be construed as meaning “including but not limited to”. The term “based on” is to be construed as “based at least in part on”. The terms “one embodiment” and “an embodiment” are to be construed as “at least one embodiment”.

[0026] Embodiment one Figure 1 A flowchart of a power system data security transmission method based on a national secret algorithm according to an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, according to an embodiment of the present application, a power system data security transmission method based on a national secret algorithm includes the following steps: Figure 1 Step S102, the terminal device and the master station system generate SM2 key pairs respectively and write the public key into a digital certificate issued by CA, and store the private key and the certificate chain locally; Step S104, the terminal device and the master station system establish a connection and perform bidirectional identity authentication; ​Step S106, after the successful bidirectional identity authentication, the terminal device and the master station system derive an initial version of a session key through an SM2 key exchange protocol; Step S108, the terminal device and the master station system perform data transmission through a layered encryption transmission strategy; Step S110, in the data transmission process, a dynamically updated session key is generated based on a key update strategy, and the terminal device and the master station system perform data transmission by using the latest version of the session key.

[0027] In the embodiment, a power system data security transmission method based on a national secret algorithm is proposed, and an end-to-end data security link of “handshake first, then encryption, and then rotation” is adopted: the terminal device and the master station system each generate an SM2 key pair first, complete bidirectional identity authentication after the CA issues a certificate, and then in the one-time handshake process of the SM2 key exchange protocol, the local private key and the opposite public key are used to derive an initial session key in combination with a random number, and the key only resides in the encryption module and is never landed to the file system. All power core data (such as power, control instructions, etc.) are cut into 16B SM4 blocks on the terminal side, and then encrypted in parallel, and then a 256bit digest is generated by SM3, together with a timestamp, a key version number N, and a terminal signature, to encapsulate a message adapted to a power communication protocol (such as IEC 60870-5-104). After receiving, the master station system indexes the local key library by N, and then decrypts, verifies, and verifies the MAC, and any step failure triggers the “key version out of step” counter; when the counter reaches a preset number of times (such as 3 times), it automatically falls back to step S104 to rehandshake. The key life cycle is uniformly maintained by the master station: the timer is set to increase N every preset time (such as 1 hour) and broadcast KeyUpdate with signature, and the security gateway performs DPI anomaly detection on the link and sends Security_Alert to the master station immediately when replay, traffic mutation, or certificate anomaly is found, and the master station broadcasts Emergency_KeyUpdate after verification, and the gateway synchronously discards the old key session to realize second-level isolation. The encryption module uses the SM4-SM3 coprocessor built-in ARM Cortex-M, and the block + pipeline + DMA makes the single-frame encryption and decryption delay <2ms at 48MHz main frequency, and the RAM peak is <1.5kB, which meets the power consumption constraints of concentrator-level and meter-level devices.

[0028] The application realizes end-to-end confidentiality, integrity, and real-time identity authentication through the “handshake-encryption-rotation” closed loop while keeping the existing power protocol compatible, taking the “national secret three-piece set” as the core, and at the same time, with the help of hardware acceleration and layered key management, the calculation and storage overhead is minimized, and it can be widely deployed in smart meters, distributed energy terminals, power monitoring systems, and other high real-time and low power consumption scenarios.

[0029] Figure 2 A schematic diagram of the layered encryption transmission strategy of an embodiment of the present application is shown in FIG. 1. As shown, according to an embodiment of the present application, the layered encryption transmission strategy in step S108 includes: Figure 2 The core data layer performs symmetric encryption on the power critical data through the SM4 algorithm; The verification layer generates a data digest through the SM3 algorithm and binds the data digest with the encrypted data; The transmission layer encapsulates the encrypted data and the verification information into a target message format adapted to the power communication protocol through a lightweight encapsulation protocol.

[0030] Preferably, the target message format is: [Header][SM4 encrypted data][SM3 digest][timestamp][signature].

[0031] In the layered encryption transmission strategy of step S108 in this embodiment, the data is encapsulated layer by layer from “core→verification→transmission”: first, the encryption co-processor on the terminal device side uses a 128-bit SM4-CTR key derived from the current session key to perform 16 Byte block parallel encryption on the critical load data such as power energy and control instructions, to ensure confidentiality; then in the verification layer, an SM3 hash is performed on the whole “SM4 ciphertext+timestamp+message header” to generate a 256-bit digest and bind it with the ciphertext, and any bit-level tampering will cause the digest to be mismatched; finally, in the transmission layer, the lightweight encapsulator packs the above fields together with the SM2 signature of the terminal in the fixed format of “[Header][SM4 encrypted data][SM3 digest][timestamp][signature]”, and 1 Byte key version number is reserved in the Header, which can be directly inserted into the ASDU user data area of IEC 60870-5-104 without modifying the existing protocol parser logic. The receiving end processes in reverse order: first, the signature is verified to confirm the source, then the version number is used to index the local key library for decryption, and finally the SM3 digest is compared to complete the integrity verification; if the verification fails, the data is discarded immediately and an exception count is triggered to avoid incorrect data entering the SCADA system. Through the triple protection mechanism of SM4 layered encryption, SM3 integrity verification and SM2 identity authentication, combined with dynamic key version management and lightweight protocol adaptation technology, the present application ensures the confidentiality, integrity and source authenticity of power data, realizes seamless compatibility with existing communication protocols, effectively resists tampering attacks and reduces the terminal computing load, and ensures high security, high real-time and high reliability of smart grid data transmission.

[0032] Figure 3 A schematic diagram of the key update strategy of an embodiment of the present application is shown in FIG. 2. As shown, Figure 3 ​As shown, according to an embodiment of the application, in step S110, the key update strategy includes a timestamp trigger update strategy and an event-driven update strategy. The timestamp trigger update strategy is that the session key is automatically updated once every preset time. The event-driven update strategy is that when the security gateway detects abnormal traffic or attack behavior, the key is immediately reset, and the terminal device and the host system rollback the session key to the previous version.

[0033] Preferably, the timestamp trigger update strategy includes the following process: The host system is responsible for timing, and when the time from the last key update reaches the preset time, the key is reset; the host system carries the key update instruction through the next downlink message; The terminal device verifies the signature and updates the session key after receiving the key update instruction; The communication parties transmit data through the latest version of the session key.

[0034] Preferably, the event-driven update strategy includes the following process: The security gateway detects abnormal traffic in real time, and immediately sends alarm information to the host system after discovering an attack; The host system verifies the alarm information, and after verification, the host system broadcasts the key reset instruction to all related terminal devices at the same time; the security gateway synchronously discards all old sessions using old keys; The terminal device and the host system transmit data through the reset session key.

[0035] In this embodiment, in step S110, the session key adopts a “double engine” life cycle management, and the key update strategy includes a timestamp trigger update strategy and an event-driven update strategy. The timestamp trigger update strategy adopts timestamp triggering, and the host system internally maintains a monotonically increasing counter N and a 32-bit UTC timer; every preset time (configurable), N is incremented, and “KeyUpdate(N)‖signature” is broadcasted with the next downlink 104 protocol message; after receiving, the terminal device verifies the signature with the old key, and if the verification is passed, a new SM4 / SM3 key is derived using the same KDF, and the old key is immediately erased. The event-driven update strategy is driven by events; the security gateway performs stateless DPI on the network side, and matches the frame rate, key version number, and certificate chain in real time; once the rule is triggered, the security gateway immediately sends Security_Alert to the host through an out-of-band channel. After the host completes secondary verification, “Emergency_Reset(N+1)” is broadcasted; the security gateway synchronously discards all old version frames to prevent replay.

[0036] The application realizes dynamic adaptive management of the key life cycle, resists quantum computing threats through periodic updates, and blocks attack sessions in real time through event triggering, in combination with the old session discarding strategy of the security gateway, to effectively prevent replay attacks after key leakage, ensure the real-time performance and attack resistance of the smart grid communication system.

[0037] According to an embodiment of the application, in step S110, the terminal device and the master station system use the latest version of the session key for data transmission, including: when either party fails to correctly decrypt or verify the signature for a preset number of times in succession, the two parties fall back to the two-way identity authentication stage to rehandshake.

[0038] In the embodiment, in step S110, the master station system and the terminal device each maintain a step-out counter CNT (the default threshold is 3). When communicating, if the received message has any of the following situations: SM4 decryption fails, SM3 digest check fails, or SM2 signature verification fails, the receiving party immediately increments CNT and silently discards the frame; when CNT reaches the threshold, a hard fallback is triggered, and the two parties fall back to the two-way identity authentication stage to rehandshake. For example, the receiving party actively sends a “RENEGOTIATE_REQ” message and carries the local latest key version number N; after receiving, the opposite party immediately clears CNT and falls back to step S104, regardless of whether the CNT of the opposite party is over the limit; the two parties complete two-way identity authentication again using SM2 certificates, derive a new session key K', and continue communication using the new key version number N'=N+1. The application triggers two-way identity authentication rehandshake when consecutive decryption / verification fails through the step-out counter and hard fallback mechanism, effectively isolates abnormal sessions, prevents attackers from exhausting resources through garbage messages, ensures that legitimate devices can quickly recover secure communication in abnormal states, and improves the attack resistance and business continuity of smart grid data transmission.

[0039] Embodiment two According to an embodiment of the application, a power system data security transmission method based on a national secret algorithm includes the following steps: Step S201, identity authentication and key pre-negotiation; An asymmetric key pair of the terminal device and the master station system is generated using an SM2 elliptic curve algorithm, and two-way identity authentication is completed. Based on the SM2 key exchange protocol, a dynamic session key seed (Seed Key) is pre-generated.

[0040] The terminal device and the master station system complete bidirectional identity authentication through an SM2 algorithm, and generate a dynamic session key seed based on an SM2 key exchange protocol; Step S202, layered encryption transmission; The core data layer: the SM4 algorithm is used for symmetric encryption of power key data (such as electric energy and control instructions), and the key is derived from a dynamically generated session key.

[0041] The verification layer: a data digest is generated through the SM3 algorithm, and is bound with the encrypted data to ensure data integrity.

[0042] The transmission layer: a lightweight encapsulation protocol is used to encapsulate the encrypted data and the verification information into a fixed format packet, and adapt to a power communication protocol (such as IEC 60870-5-104).

[0043] The SM4 algorithm is used for symmetric encryption of power core data, and the SM3 algorithm is used to generate an integrity digest of the encrypted data; the encrypted data, the integrity digest, a timestamp and a terminal signature are encapsulated into a packet format conforming to the power communication protocol; Step S203, the dynamic key update mechanism is used to update the key; Based on the periodic characteristics of power data transmission (such as reporting data every 5 minutes), a timestamp triggering and event-driven key update strategy is designed, including: Timestamp triggering: the session key is automatically updated every hour; Event-driven: when abnormal traffic or attack behavior is detected, the key is immediately reset.

[0044] The dynamic key update mechanism of timestamp triggering and event-driven is designed, and the session key is reset periodically or by an abnormal event.

[0045] Step S204, resource optimization design; The SM4 algorithm is optimized for hardware acceleration, and is adapted to a low-power power terminal chip (such as an ARM Cortex-M series).

[0046] The block encryption and parallel computing technology are used to reduce memory occupation and improve processing efficiency.

[0047] In this embodiment, a power system data security transmission method based on a national secret algorithm is provided, bidirectional identity authentication and dynamic key negotiation of a terminal device and a master station system are realized based on an SM2 algorithm, the SM4 algorithm is used for lightweight symmetric encryption of power core data, and a data digest is generated through the SM3 algorithm to guarantee integrity, a dynamic key update strategy of timestamp triggering and event-driven is designed, the key is automatically reset in combination with a power business cycle, and resource occupation is optimized through hardware acceleration and block encryption technology, and the method is adapted to a low-power terminal device.

[0048] The application solves the efficient integration problem of the national secret algorithm in the power scene, ensures the end-to-end security, is compatible with the existing power communication protocol (such as IEC 60870-5-104), improves the encryption efficiency, can resist replay attacks, man-in-the-middle attacks and other threats, and is suitable for the power scene with high real-time and high security requirements such as smart meters and distributed energy monitoring.

[0049] Embodiment three Figure 4 The structure diagram of the power system data security transmission system based on the national secret algorithm according to an embodiment of the application is shown in the figure. Figure 4 As shown in the figure, according to an embodiment of the application, a power system data security transmission system based on the national secret algorithm adopts any power system data security transmission method based on the national secret algorithm of the application, and the transmission system includes a terminal device, an encryption module and a master station system. The terminal device is used for collecting power key data, storing and running a local SM2 key pair and a digital certificate, completing bidirectional identity authentication with the master station system, receiving and executing a key update instruction, performing SM4 encryption, SM3 digest calculation and message packaging on the power key data according to a dynamic session key, and then sending the data. The encryption module is embedded in the terminal device and / or the master station system, and is used for performing SM2 signature and verification, SM2 key exchange, SM4 symmetric encryption / decryption, SM3 digest generation and session key derivation, and providing a hardware acceleration interface. The master station system is used for storing and running a local SM2 key pair and a digital certificate, completing bidirectional identity authentication with the terminal device, maintaining a session key version number, generating and distributing a key update instruction according to a key update strategy, and performing SM4 decryption, SM3 integrity verification and source authentication on the received data according to a dynamic session key.

[0050] In the embodiment, a power system data security transmission system based on national cryptographic algorithm is provided, a terminal device is integrated with a low-power ARM-Cortex-M encryption coprocessor, after key data such as power and control instructions are collected on site, a local SM2 private key is called to complete signature, a 256-bit session key is negotiated with a master station system through SM2 key exchange, and SM4-CTR encryption keys and SM3-HMAC integrity keys are derived by KDF. The encryption module is symmetrically deployed on both sides of the terminal device and the master station system, and supports hardware pipeline + DMA block encryption. The master station system maintains a global key version number N, a timer triggers KeyUpdate once every preset time (such as 1H), or performs Emergency_Reset when receiving a security gateway Security_Alert, and broadcasts an update instruction with SM2 signature; the terminal device verifies the signature and atomically replaces the key, and automatically falls back to re-handshake when a step counter exceeds the limit, to prevent half-connection attacks. All business data are encapsulated according to the format of “[Header][SM4 ciphertext][SM3 digest][timestamp][signature]”, and can be directly embedded into an IEC 60870-5-104 frame without modifying the existing SCADA analysis logic.

[0051] The present application fuses multiple national cryptographic algorithms, realizes end-to-end confidentiality, integrity and source authentication in real-time services through hardware acceleration and versioned key management, and is compatible with low power consumption, protocol and automatic fault tolerance, and can be widely deployed in high-security scenarios such as smart meters and distributed energy terminals.

[0052] According to an embodiment of the present application, the transmission system further comprises a security gateway; The security gateway is deployed on a communication link between the terminal device and the master station system, and is used for mirroring and detecting network traffic in real time, sending alarm information to the master station system when abnormal traffic or attack behavior is found; the master station system triggers key reset after verifying the alarm, and the security gateway synchronously discards old key session data.

[0053] In this embodiment, the security gateway is deployed as a "network boundary sentinel" between the terminal device and the host system: it captures all uplink / downlink traffic in real time through port mirroring or TEE bypass, uses the DPI engine to perform stateless matching on frame rate, key version number, certificate chain length, SM3 digest repetition, etc. Once the abnormal threshold is triggered, the Security_Alert carrying the event type, quintuple and forensic hash is sent to the host system through out-of-band syslog / SNMP Trap. After the host system completes the secondary authentication, it immediately broadcasts the Emergency_KeyUpdate(N+1) instruction, and the security gateway synchronously discards all old version sessions on the data plane and records the audit log, thereby blocking potential replay or man-in-the-middle attacks. To repair the "gateway false alarm" risk, the security gateway has a built-in whitelist self-learning module that can converge the normal business model within 30s and dynamically adjust the threshold, ensuring that the alarm false alarm rate is <1%.

[0054] The present application significantly reduces the attack window and improves the self-healing ability of the entire network by setting a security gateway without touching the key plaintext.

[0055] Embodiment four A power system data security transmission system based on a national secret algorithm, comprising: a terminal device, an encryption module, a host system, and a security gateway. The terminal device (such as a smart meter or a distributed energy device) is responsible for collecting power data (such as electric energy, voltage, current, etc.); the terminal device is built-in with an SM2 / SM3 / SM4 algorithm module for completing data encryption and signature; the terminal device is pre-installed with an SM2 public key certificate and completes bidirectional authentication with the host system; the data is encrypted using a dynamically generated SM4 key, an SM3 digest is generated, and the data is packaged into a message format: [Header][SM4 encrypted data][SM3 digest][timestamp][signature]; The encryption module is used for dynamic key generation, data encryption (SM4), data digest generation (SM3), and identity authentication (SM2); at the same time, the encryption module supports hardware acceleration and is suitable for low-power terminal devices.

[0056] The host system receives the encrypted data sent by the terminal device; the terminal identity is verified using the SM2 public key, the data is decrypted using the SM4 key, and the data integrity is checked through the SM3 digest.

[0057] The security gateway is deployed between the terminal device and the host system, realizes protocol conversion and abnormal traffic monitoring, and triggers key reset.

[0058] In the embodiment, the terminal device and the master station system complete bidirectional identity authentication through the SM2 algorithm, and based on the asymmetric encryption characteristics of the SM2 algorithm, the identity authenticity and communication security of both sides are ensured. The terminal device is internally provided with a hardware acceleration module for performing SM4 encryption and SM3 digest generation, and the hardware acceleration module is realized based on an ARM Cortex-M series chip. The message format encapsulated by the terminal device is compatible with the power communication protocol IEC 60870-5-104 or DL / T 634.5104, and the message header contains an encryption algorithm identifier and a key version number. In the communication process between the terminal device and the master station system, a dynamic key update mechanism is adopted, including: time stamp triggering and event-driven triggering. Time stamp triggering: the session key is automatically updated once an hour; event-driven triggering: through a security gateway deployed between the terminal device and the master station system, protocol conversion and abnormal traffic monitoring are realized, and when a network attack or data traffic anomaly is detected, the key is immediately reset.

[0059] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the transmission system described above can refer to the corresponding process in the foregoing transmission method embodiments, which will not be repeated here.

[0060] The above description is only the preferred embodiment of the present application and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the application involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the above features are replaced with the technical features disclosed in the present application (but not limited to) having similar functions to form technical solutions.

[0061] It should be understood that the size of the serial number of the steps in the summary of the application and the embodiments does not absolutely mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

Claims

1. A method for secure data transmission in a power system based on national cryptographic algorithms, characterized in that, include: The terminal device and the main station system each generate an SM2 key pair and write the public key into a digital certificate issued by a CA, and securely store the private key and certificate chain locally. The terminal device establishes a connection with the main station system and performs two-way identity authentication; After successful two-way authentication, the terminal device and the main station system derive an initial version of the session key through the SM2 key exchange protocol; The terminal device and the main station system transmit data using a layered encryption transmission strategy. During data transmission, a dynamically updated session key is generated based on a key update strategy, and the terminal device and the master station system use the latest version of the session key for data transmission.

2. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 1, characterized in that, The layered encrypted transmission strategy includes: The core data layer uses the SM4 algorithm to symmetrically encrypt key power data; The verification layer generates a data digest using the SM3 algorithm and binds the data digest to the encrypted data. The transport layer encapsulates encrypted data and verification information into a target message format that is compatible with power communication protocols through a lightweight encapsulation protocol.

3. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 2, characterized in that: The key power data includes: electrical energy and control commands.

4. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 2, characterized in that, The target message format is: [Header][SM4 encrypted data][SM3 digest][timestamp][signature].

5. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 1, characterized in that, The key update strategies include: timestamp-triggered update strategy and event-driven update strategy; The timestamp-triggered update strategy is as follows: the session key is automatically updated once at a preset interval; The event-driven update strategy is as follows: when the security gateway detects abnormal traffic or attack behavior, it immediately triggers a key reset, and the terminal device and the main station system roll back the session key to the previous version.

6. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 5, characterized in that, The timestamp-triggered update strategy includes the following process: The master station system is responsible for timing. When the time since the last key update reaches a preset time, it triggers a key reset. The master station system carries the key update instruction in the next downlink message. Upon receiving the key update instruction, the terminal device verifies the signature and updates the session key. The two communicating parties use the latest version of the session key to transmit data.

7. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 5, characterized in that, The event-driven update strategy Includes the following processes: The security gateway detects abnormal traffic in real time and immediately sends alarm information to the main station system upon detecting an attack. The master station system verifies the alarm information. After successful verification, the master station system simultaneously broadcasts a key reset command to all relevant terminal devices; the security gateway synchronously discards all old sessions using the old key. The terminal device and the main station system transmit data using the reset session key.

8. The method for secure data transmission in power systems based on national cryptographic algorithms according to claim 1, characterized in that, The terminal device and the main station system use the latest version of the session key for data transmission, including: when either party fails to correctly decrypt or verify the signature for a preset number of consecutive times, both parties fall back to the two-way authentication stage and re-handshake.

9. A power system data security transmission system based on national cryptographic algorithms, employing the power system data security transmission method based on national cryptographic algorithms as described in any one of claims 1-8, characterized in that, The transmission system includes: terminal equipment, encryption module, and master station system; The terminal device is used to collect key power data, store and run the local SM2 key pair and digital certificate, complete two-way identity authentication with the master station system, receive and execute key update instructions, and send the key power data after SM4 encryption, SM3 digest calculation and message encapsulation based on the dynamic session key. The encryption module is embedded in the terminal device and / or the main station system, and is used to perform SM2 signature and verification, SM2 key exchange, SM4 symmetric encryption / decryption, SM3 digest generation and session key derivation, and provides a hardware acceleration interface; The master station system is used to store and run the local SM2 key pair and digital certificate, complete two-way identity authentication with the terminal device, maintain the session key version number, generate and distribute key update instructions according to the key update policy, and perform SM4 decryption, SM3 integrity verification and source authentication on the received data based on the dynamic session key pair.

10. The power system data security transmission system based on national cryptographic algorithms according to claim 9, characterized in that, The transmission system further includes: a security gateway; The security gateway is deployed on the communication link between the terminal device and the master station system. It is used to mirror and detect network traffic in real time, and send alarm information to the master station system when abnormal traffic or attack behavior is detected. After the master station system verifies the alarm, it triggers a key reset, and the security gateway discards the old key session data simultaneously.