Smart power grid anonymous authentication method and device for wireless sensor network
By designing an anonymous authentication and key negotiation mechanism in a wireless sensor network smart grid, the problem of insufficient node anonymity is solved, achieving anonymity and forward security of sensor nodes, and improving the continuous security and adaptability of the smart grid.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Chinese People's Liberation Army Cyberspace Force Information Engineering University
- Filing Date
- 2025-12-24
- Publication Date
- 2026-05-01
AI Technical Summary
Existing anonymous authentication methods for smart grids using wireless sensor networks lack node anonymity, resulting in deficiencies in security, efficiency, and adaptability, and failing to meet continuous security requirements.
An anonymous authentication and key negotiation mechanism is designed. Through mutual authentication and session key generation between sensor nodes, gateway nodes and control center, the anonymity of sensor nodes is ensured. Elliptic curve cryptography is used to achieve forward security and resist long-term private key and temporary key leakage attacks.
It achieves anonymity and forward security for sensor nodes, improves the continuous security of smart grids, resists common security threats, and meets the requirements of high reliability and high security.
Smart Images

Figure CN121968083A_ABST
Abstract
Description
Technical Field
[0001] The embodiments disclosed herein relate to the field of computer technology, and more specifically to a method and apparatus for anonymous authentication of smart grids for wireless sensor networks. Background Technology
[0002] Wireless Sensor Networks (WSNs) are networks composed of a large number of sensor nodes distributed across a specific area. Smart grids based on WSNs enable real-time monitoring, data transmission, and intelligent control of data such as current, voltage, and load in the power grid. Currently, anonymous authentication key negotiation mechanisms are commonly used to ensure the confidentiality and integrity of data during communication in smart grids via WSNs. However, existing authentication key negotiation methods generally lack node anonymity and exhibit varying degrees of deficiencies in security, efficiency, and adaptability. Summary of the Invention
[0003] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.
[0004] Some embodiments of this disclosure propose a method and apparatus for anonymous authentication of smart grids for wireless sensor networks, in order to solve the technical problems mentioned in the background section above.
[0005] In a first aspect, some embodiments of this disclosure provide an anonymous authentication method for a smart grid oriented towards wireless sensor networks. The method includes: a sensor node generating a first authentication message based on a received long-term private key of a sensor, sensor encrypted authentication information, and a long-term public key of a control center, and sending the first authentication message to a gateway node; the gateway node, in response to receiving the first authentication message, generating a second authentication message and sending the second authentication message to a control center node, wherein the second authentication message includes the first authentication message; the control center node, in response to receiving the second authentication message, generating a third authentication message based on the second authentication message, and sending the third authentication message to the gateway node; the gateway node, in response to receiving the third authentication message, generating a fourth authentication message based on a gateway node identity identifier and a received first long-term private key of the gateway, and sending the fourth authentication message to the sensor node; the sensor node, in response to receiving the fourth authentication message, sequentially generating sensor encrypted information and a sensor session key; and the sensor node, based on the generated sensor session key, completing session key negotiation with the gateway node and the control center node in response to determining successful verification of the fourth authentication message.
[0006] Secondly, some embodiments of this disclosure provide an anonymous authentication device for a smart grid oriented to a wireless sensor network. The device includes: a first generation unit configured to have a sensor node generate a first authentication message based on a received long-term private key of a sensor, sensor encrypted authentication information, and a long-term public key of a control center, and send the first authentication message to a gateway node; a second generation unit configured to have the gateway node generate a second authentication message in response to receiving the first authentication message, and send the second authentication message to a control center node, wherein the second authentication message includes the first authentication message; and a third generation unit configured to have the control center node, in response to receiving the second authentication message, generate a second authentication message based on the received first authentication message. The system comprises: a second authentication message, a third authentication message, and a third authentication message sent to the gateway node; a fourth generation unit configured to, in response to receiving the third authentication message, generate a fourth authentication message based on the gateway node's identity identifier and the received first gateway long-term private key, and send the fourth authentication message to the sensor node; a fifth generation unit configured to, in response to receiving the fourth authentication message, sequentially generate sensor encryption information and a sensor session key; and a verification unit configured to, based on the generated sensor session key, determine that the fourth authentication message has been successfully verified and complete session key negotiation with the gateway node and the control center node.
[0007] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.
[0008] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.
[0009] The various embodiments of this disclosure have the following beneficial effects: the anonymity authentication method for smart grids based on wireless sensor networks, as described in some embodiments of this disclosure, satisfies the anonymity of sensor nodes and possesses forward security, thereby improving the continuous security of the power grid. Specifically, the reason for the reduced continuous security of the power grid is that existing authentication key negotiation methods generally lack node anonymity and have varying degrees of defects in security, efficiency, and adaptability. Based on this, the anonymity authentication method for smart grids based on wireless sensor networks, as described in some embodiments of this disclosure, designs an anonymous authentication and key negotiation mechanism to address the resource constraints and communication security requirements of smart grids. This mechanism consists of a system administrator, sensor nodes, gateway nodes, and a control center. Sensor nodes, gateway nodes, and the control center share sensitive information, and the mutual authentication and session key generation among these entities ensure the security of subsequent communication. It is worth noting that this mechanism can satisfy the anonymity of sensor nodes and possess forward security, while also resisting temporary key leakage attacks. Even if a long-term private key or temporary key of a communicating party is accidentally leaked, an attacker cannot calculate the session key from that key, thereby ensuring the continuous security of the system. Furthermore, considering the communication characteristics between sensor nodes, gateway nodes, and the control center in a wireless sensor network smart grid, the anonymous authentication and key negotiation mechanism of this application possesses multiple security features: First, by anonymizing the sensor node's identity, it ensures that user electricity consumption behavior and sensitive equipment information will not be illegally stolen or traced during data interaction, thus meeting the anonymity requirements of sensor nodes; second, the generation of the session key includes multiple parameters, so even if the temporary key of this session is leaked, attackers cannot deduce the corresponding session key, thus resisting temporary key leakage attacks; third, by utilizing key negotiation technology in elliptic curve cryptography, forward security is achieved, ensuring that the session key remains confidential even if the long-term private key of a participant is accidentally leaked. Simultaneously, this mechanism can also resist common security threats in wireless sensor network smart grids, such as long-term private key leakage spoofing attacks and temporary key leakage spoofing attacks. In summary, the aforementioned anonymous authentication and key negotiation mechanism can guarantee the anonymity of sensor nodes in a wireless sensor network smart grid while meeting the core requirements of high reliability and high security for smart grids, providing continuous security in the large-scale deployment and safe operation of smart grids. Attached Figure Description
[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.
[0011] Figure 1 This is a flowchart of some embodiments of an anonymous authentication method for smart grids with wireless sensor networks according to the present disclosure;
[0012] Figure 2 This is a schematic diagram of the authentication and key negotiation mechanism of the anonymous authentication method for smart grids with wireless sensor networks according to this disclosure;
[0013] Figure 3 This is a schematic diagram of the registration phase process of the anonymous authentication method for smart grids with wireless sensor networks according to this disclosure;
[0014] Figure 4 This is a schematic diagram of the identity verification and key negotiation phases of the anonymous authentication method for smart grids with wireless sensor networks according to this disclosure;
[0015] Figure 5 This is a schematic diagram of the dynamic node update phase of the anonymous authentication method for smart grids with wireless sensor networks according to this disclosure.
[0016] Figure 6 This is a schematic diagram of the structure of some embodiments of an anonymous authentication device for smart grids with wireless sensor networks according to the present disclosure;
[0017] Figure 7 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation
[0018] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0019] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.
[0020] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0021] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0022] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0023] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.
[0024] Figure 1 A flow 100 of some embodiments of a smart grid anonymity authentication method for wireless sensor networks according to the present disclosure is shown. This smart grid anonymity authentication method for wireless sensor networks includes the following steps:
[0025] Step 101: The sensor node generates a first authentication message based on the received long-term private key of the sensor, the sensor encrypted authentication information and the long-term public key of the control center, and sends the first authentication message to the gateway node.
[0026] In some embodiments, in the smart grid anonymous authentication method for wireless sensor networks, the sensor node can generate a first authentication message based on the received long-term private key of the sensor, the sensor encrypted authentication information, and the long-term public key of the control center, and send the first authentication message to the gateway node.
[0027] A smart grid based on wireless sensor networks typically consists of a System Administrator (SA), a Control Center (CC), Gateway Nodes (GN), and numerous Sensor Nodes (SN). The System Administrator ensures the normal operation of network devices and services by being responsible for system initialization and the registration and maintenance of each node. Each sensor node typically possesses sensing, data processing, and communication capabilities, and can wirelessly transmit the collected data to the Gateway Node. The Gateway Node acts as a bridge between the sensor nodes and the Control Center, responsible for collecting and integrating the power data gathered by all sensor nodes, and then transmitting this power data to the Control Center for processing and storage. The Control Center typically consists of servers with high computing, communication, and storage capabilities to support the collection, processing, and analysis of large amounts of power grid data.
[0028] It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future wireless connection methods.
[0029] It should be noted that, as Figure 2 As shown, the smart grid anonymity authentication method for wireless sensor networks in this application includes a system initialization phase, a registration phase, an authentication and key negotiation phase, and a dynamic node update phase. The registration phase refers to the process where sensor nodes (SN), gateway nodes (GN), and control centers (CC) register with the system administrator (SA) in a secure communication environment and generate long-term private key pairs for subsequent communication. The specific process is as follows: Figure 3 As shown in Figure 4. The authentication and key negotiation stages described above are steps 101 to 106, and the specific process is shown in Figure 4.
[0030] During the system initialization phase, the system administrator (i.e., the system management node SA) can operate within a limited domain. Construct elliptic curves ,in , It is a constant. Represents an elliptic curve The previous one with prime order cyclic subgroups yes The generator is then randomly selected by SA using a secure one-way hash function. , , , , , and broadcast system parameters The above. It is a one-way hash function.
[0031] In some optional implementations of certain embodiments, the sensor node can generate a first authentication message based on the received long-term private key of the sensor, the sensor encrypted authentication information, and the long-term public key of the control center, and send the first authentication message to the gateway node through the following steps:
[0032] The first step is to generate a temporary public / private key and a first timestamp for the sensor. In practice, the sensor node SN mentioned above is randomly selected. As a temporary private key for the sensor, it is used to generate session keys and ensure forward security of the protocol, and through... The expression generates a temporary public key for the sensor corresponding to the sensor's temporary private key. And the timestamp of the current time is used as the first timestamp. .
[0033] The second step involves generating sensor privacy information based on the received long-term private key and sensor node identity. In practice, the aforementioned sensor node SN can generate sensor privacy information using the following expression. For subsequent verification:
[0034] .
[0035] Among them, the above It can be the identification identifier of the aforementioned sensor nodes. It is a long-term private key for sensors, providing long-term, stable identity authentication and data integrity assurance.
[0036] The third step involves generating the first authentication parameter and the second authentication parameter based on the received sensor encryption authentication information, the control center's long-term public key, the aforementioned sensor private information, and the aforementioned sensor temporary public key. In practice, the aforementioned sensor node SN can generate the first authentication parameter using the following expression. Second certification parameters :
[0037] ;
[0038] .
[0039] in, It is the received encrypted authentication information from the sensor. It is the long-term public key corresponding to the control center and its long-term private key.
[0040] The fourth step involves using the generated first authentication parameters, second authentication parameters, the aforementioned sensor temporary public key, and the aforementioned first timestamp as the first authentication message (i.e., ...). The information is sent to the gateway node.
[0041] Optionally, before the sensor node generates the first authentication message based on the received sensor long-term private key, sensor encrypted authentication information, and control center long-term public key, the above method may further include the following steps (i.e., the above registration phase):
[0042] The first step involves the system administrator node, upon receiving the gateway node's identity identifier and the sensor node's identity identifier, generating the sensor's long-term public / private key, sensor's private information, sensor's encrypted authentication information, the gateway's long-term private key, and the control center's long-term public / private key. The gateway's long-term private key includes a first gateway long-term private key and a second gateway long-term private key. In practice, the system administrator node receives the sensor node's identity identifier... and gateway node identity identifier Then, first generate randomly. The long-term private key of the sensor node (i.e., the long-term private key of the sensor), and the two long-term private keys of the gateway node GN. (i.e., the long-term private key of the first gateway) Second gateway long-term private key ) and the long-term private key of the control center CC (i.e., the long-term private key of the control center) ), and through expressions , , , Generate long-term public keys for the sensors respectively long-term public key of the control center Sensor privacy information and sensor encryption authentication information .in Indicates Using the key, a symmetric encryption operation is performed using the AES-128 algorithm.
[0043] It should be noted that the sensor node SN is selected as a true identity composed of a combination of the power grid area and the device number. As a sensor node identifier, a similar gateway node (GN) selects a real identity composed of a combination of network layer and device number. As the identity identifier of the gateway node, it is sent to the system administrator (SA) to request registration.
[0044] The second step involves the system administrator node packaging the generated long-term private key for the sensors, the sensor encryption authentication information, and the long-term private key for the first gateway (i.e., ...). Send to the sensor node.
[0045] The third step is for the system administrator node to transfer the aforementioned gateway's long-term private key (i.e., Send to the gateway node.
[0046] The fourth step involves the system administrator node packaging the generated long-term private key of the control center with the long-term private key of the second gateway (i.e., ...). Send to the control center node.
[0047] Fifth, the system administrator node publishes the sensor's long-term public key to all nodes. Long-term public key with control center .
[0048] Step 102: Upon receiving the first authentication message, the gateway node generates a second authentication message and sends the second authentication message to the control center node.
[0049] In some embodiments, the gateway node may generate a second authentication message in response to receiving the first authentication message, and send the second authentication message to the control center node, wherein the second authentication message includes the first authentication message.
[0050] In some optional implementations of certain embodiments, the gateway node may respond to receiving a first authentication message by generating a second authentication message and sending it to the control center node through the following steps:
[0051] The first step is to generate the current timestamp as the second timestamp. In practice, the aforementioned gateway node receives the first authentication message. Then, first check the first timestamp. To ensure freshness, a timestamp of the current time is then generated as a second timestamp. .
[0052] The second step involves generating the third authentication parameter based on the second timestamp and the received second gateway long-term private key. In practice, the gateway node can generate the third authentication parameter using the following expression. :
[0053] .
[0054] The third step is to use the aforementioned first authentication parameter, second authentication parameter, third authentication parameter, sensor temporary public key, first timestamp, and second timestamp as the second authentication message (i.e., Send to the control center node.
[0055] Step 103: Upon receiving the second authentication message, the control center node generates a third authentication message based on the second authentication message and sends the third authentication message to the aforementioned gateway node.
[0056] In some embodiments, the control center node may, in response to receiving a second authentication message, generate a third authentication message based on the second authentication message, and send the third authentication message to the gateway node.
[0057] In some optional implementations of certain embodiments, the control center node may generate a third authentication message based on the second authentication message and send the third authentication message to the gateway node through the following steps:
[0058] The first step is to verify the third authentication parameter based on the second authentication message to obtain the first verification result. In practice, after receiving the second authentication message, the control center node first checks the timestamp. The freshness, and verify the equation. Whether it holds true or not, we obtain the first verification result.
[0059] The second step involves generating encrypted sensor authentication information based on the first authentication message, in response to the confirmation that the first verification result indicates successful verification. In practice, the control center node can use the sensor's temporary public key included in the first authentication message. Generate sensor encryption authentication information using the following expression. :
[0060] .
[0061] It should be noted that if the first verification result indicates that the verification has failed, the control center node will stop the session with the gateway node and the sensor node.
[0062] The third step is to verify the second authentication parameters based on the first authentication message mentioned above, and obtain the second verification result. In practice, the control center node can verify the second authentication parameters using the information included in the first authentication message, i.e. The second verification result was obtained. Specifically, for... Part of it can be done through To be confirmed. Indicates Using the AES-128 algorithm as the key, a symmetric decryption operation is performed.
[0063] The fourth step, in response to the confirmation that the second verification result indicates successful verification, generates a temporary private key for the control center, a temporary public key for the control center, and a third timestamp. In practice, the aforementioned control center node is randomly selected. As its temporary key (i.e., the control center's temporary private key) through the expression Generate a temporary public key for the control center And the timestamp of the current time as a third timestamp. .
[0064] It should be noted that if the second verification result indicates that the verification has failed, the control center node will stop the session with the gateway node and the sensor node.
[0065] The fifth step involves generating encrypted control center information based on the received long-term private key of the control center, long-term public key of the sensors, temporary public key of the sensors, and the temporary private key of the control center. In practice, the control center node can use the received long-term private key of the control center... Temporary private key for control center Sensor long-term public key Sensor temporary public key and expression Generate encrypted information for the control center .
[0066] Step six: Based on the aforementioned control center encrypted information and sensor encrypted authentication information, generate the control center session key, the fourth authentication parameter, and the fifth authentication parameter. In practice, the aforementioned control center node can... , , Generate control center session keys respectively Fourth certification parameter and the fifth certification parameters .
[0067] Step 7: Use the fourth authentication parameter, the fifth authentication parameter, the control center's temporary public key, and the third timestamp as the third authentication message (i.e., Send to the aforementioned gateway node.
[0068] Step 104: Upon receiving the third authentication message, the gateway node generates a fourth authentication message based on its identity identifier and the received first long-term private key of the gateway, and sends the fourth authentication message to the sensor node.
[0069] In some embodiments, in response to receiving a third authentication message, the gateway node may generate a fourth authentication message based on the gateway node's identity identifier and the received first gateway long-term private key, and send the fourth authentication message to the sensor node.
[0070] In some optional implementations of certain embodiments, the gateway node can generate a fourth authentication message based on the gateway node's identity identifier and the received first long-term private key of the gateway, and send the fourth authentication message to the sensor node through the following steps:
[0071] The first step is to verify the fourth authentication parameters included in the third authentication message based on the received long-term private key of the second gateway, thereby obtaining the third verification result. In practice, the gateway node GN receives the third authentication message. Then, first check the included third timestamp. The freshness, and through gateway node identity identification. Second gateway long-term private key Verify the equation Whether it holds true or not, we obtain the third verification result.
[0072] The second step, in response to the determination that the third verification result indicates that the verification has passed, is to generate a timestamp of the current time as the fourth timestamp. .
[0073] It should be noted that if the third verification result indicates that the verification has failed, the control center node will stop the session with the gateway node and the sensor node.
[0074] The third step involves generating the sixth authentication parameter based on the aforementioned gateway node identity identifier, the aforementioned first gateway long-term private key, and the aforementioned fourth timestamp. In practice, the aforementioned gateway node GN uses the aforementioned gateway node identity identifier... The aforementioned first gateway's long-term private key The aforementioned fourth timestamp and expression Generate the sixth authentication parameter .
[0075] The fourth step involves using the fifth authentication parameter, the sixth authentication parameter, the control center's temporary public key, the third timestamp, and the fourth timestamp as the fourth authentication message. Send to the aforementioned sensor nodes.
[0076] Step 105: Upon receiving the fourth authentication message, the sensor node sequentially generates sensor encryption information and a sensor session key.
[0077] In some embodiments, the sensor node may, in response to receiving a fourth authentication message, sequentially generate sensor encryption information and a sensor session key. In practice, the sensor node receives the fourth authentication message from the gateway node GN. Then, first check the included fourth timestamp. The freshness, and verify the equation. The verification process checks if the connection is valid. If verification fails, the session with the control center node and gateway node is terminated. If verification succeeds, the aforementioned sensor node SN transmits the sensor's long-term public key. Temporary private key for sensors long-term public key of the control center Temporary public key for control center and expression Generate encrypted sensor information Then, through sensor node identification. Sensor privacy information Sensor encryption information, third-party timestamps and expression Separately with sensor session keys .
[0078] Step 106: Based on the generated sensor session key, the sensor node responds to the confirmation that the fourth authentication message has been successfully verified, and the session key negotiation with the gateway node and the control center node is completed.
[0079] In some embodiments, the sensor node can, based on the generated sensor session key, complete session key negotiation with the gateway node and control center node in response to successful verification of the fourth authentication message. In practice, the sensor node can verify the equation... The verification process is as follows: If verification fails, the session with the control center node and gateway node is terminated. If verification succeeds, it indicates that the aforementioned sensor node SN has successfully negotiated the session key with the control center CC through the gateway node GN.
[0080] It should be noted that, in order to further improve the adaptability of the mechanism to the dynamic operation scenarios of wireless sensor smart grids, this application supports the dynamic addition of new sensor nodes (SNs) to sense data (i.e., the aforementioned dynamic node update phase, the specific process of which is as follows). Figure 5 (As shown). When it is necessary to connect a new sensor node SN to the existing communication environment, such as... Figure 5 As shown, the system management node (SA) will perform the following access process. First, the new sensor node (SN) selects its identity. The sensor node identifier for the new sensor is sent to the system administrator (SA) to request registration. Upon receiving the registration message, the system management node (SA) first randomly generates... (i.e., the corresponding long-term private key of the sensor and the long-term private key of the gateway), and calculate (Corresponding long-term public key for the sensor) (Corresponding sensor privacy information) (Corresponding sensor encryption authentication information). The message will then be sent. Send the message to the new sensor node SN storage. The key is sent to the gateway node GN for storage. Finally, the system management section SA exposes the long-term public key of the new sensor node SN. .
[0081] The various embodiments of this disclosure have the following beneficial effects: the anonymity authentication method for smart grids based on wireless sensor networks, as described in some embodiments of this disclosure, satisfies the anonymity of sensor nodes and possesses forward security, thereby improving the continuous security of the power grid. Specifically, the reason for the reduced continuous security of the power grid is that existing authentication key negotiation methods generally lack node anonymity and have varying degrees of defects in security, efficiency, and adaptability. Based on this, the anonymity authentication method for smart grids based on wireless sensor networks, as described in some embodiments of this disclosure, designs an anonymous authentication and key negotiation mechanism to address the resource constraints and communication security requirements of smart grids. This mechanism consists of a system administrator, sensor nodes, gateway nodes, and a control center. Sensor nodes, gateway nodes, and the control center share sensitive information, and the mutual authentication and session key generation among these entities ensure the security of subsequent communication. It is worth noting that this mechanism can satisfy the anonymity of sensor nodes and possess forward security, while also resisting temporary key leakage attacks. Even if a long-term private key or temporary key of a communicating party is accidentally leaked, an attacker cannot calculate the session key from that key, thereby ensuring the continuous security of the system. Furthermore, considering the communication characteristics between sensor nodes, gateway nodes, and the control center in a wireless sensor network smart grid, the anonymous authentication and key negotiation mechanism of this application possesses multiple security features: First, by anonymizing the sensor node's identity, it ensures that user electricity consumption behavior and sensitive equipment information will not be illegally stolen or traced during data interaction, thus meeting the anonymity requirements of sensor nodes; second, the generation of the session key includes multiple parameters, so even if the temporary key of this session is leaked, attackers cannot deduce the corresponding session key, thus resisting temporary key leakage attacks; third, by utilizing key negotiation technology in elliptic curve cryptography, forward security is achieved, ensuring that the session key remains confidential even if the long-term private key of a participant is accidentally leaked. Simultaneously, this mechanism can also resist common security threats in wireless sensor network smart grids, such as long-term private key leakage spoofing attacks and temporary key leakage spoofing attacks. In summary, the aforementioned anonymous authentication and key negotiation mechanism can guarantee the anonymity of sensor nodes in a wireless sensor network smart grid while meeting the core requirements of high reliability and high security for smart grids, providing continuous security in the large-scale deployment and safe operation of smart grids.
[0082] Further reference Figure 6 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an anonymous authentication device for smart grids in wireless sensor networks. These device embodiments are similar to... Figure 1 Corresponding to the method embodiments shown, this smart grid anonymity authentication device for wireless sensor networks can be specifically applied to various electronic devices.
[0083] like Figure 6 As shown, a smart grid anonymity authentication device 600 for wireless sensor networks in some embodiments includes: a first generation unit 601, a second generation unit 602, a third generation unit 603, a fourth generation unit 604, a fifth generation unit 605, and a verification unit 606. The first generation unit 601 is configured to have a sensor node generate a first authentication message based on a received sensor long-term private key, sensor encrypted authentication information, and a control center long-term public key, and send the first authentication message to a gateway node. The second generation unit 602 is configured to have the gateway node generate a second authentication message in response to receiving the first authentication message, and send the second authentication message to a control center node, wherein the second authentication message includes the first authentication message. The third generation unit 603 is configured to have the control center node generate a third authentication message in response to receiving the second authentication message, and send the third authentication message to a control center node. The third authentication message is sent to the aforementioned gateway node; the fourth generation unit 604 is configured so that, in response to receiving the third authentication message, the gateway node generates a fourth authentication message based on the gateway node's identity identifier and the received first gateway long-term private key, and sends the fourth authentication message to the sensor node; the fifth generation unit 605 is configured so that, in response to receiving the fourth authentication message, the sensor node sequentially generates sensor encryption information and a sensor session key; the verification unit 606 is configured so that, based on the generated sensor session key, the sensor node determines that the fourth authentication message has been successfully verified and completes session key negotiation with the aforementioned gateway node and control center node.
[0084] It is understandable that the units described in the smart grid anonymity authentication device 600 for wireless sensor networks are similar to the reference units. Figure 1 The steps in the described method correspond accordingly. Therefore, the operations, features, and beneficial effects described above for the method are also applicable to the smart grid anonymous authentication device 600 for wireless sensor networks and the units contained therein, and will not be repeated here.
[0085] The following is for reference. Figure 7 It shows a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality or scope of the embodiments of this disclosure. Figure 7As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The memory may include a non-volatile storage medium and internal memory. The non-volatile storage medium may store an operating system and a computer program. The computer program includes program instructions that, when executed, cause the processor to perform any of the methods described above. The processor provides computational and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the execution of the computer program in the non-volatile storage medium; when executed by the processor, the computer program causes the processor to perform any of the methods described above. The network interface is used for network communication, such as sending assigned tasks. Those skilled in the art will understand that... Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present disclosure and does not constitute a limitation on the computer device to which the present disclosure is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0086] It should be understood that the processor can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among these, a general-purpose processor can be a microprocessor or any conventional processor.
[0087] In one embodiment, the processor is configured to run a computer program stored in a memory to perform the following steps: A sensor node generates a first authentication message based on a received long-term private key for the sensor, sensor encryption authentication information, and a long-term public key for the control center, and sends the first authentication message to a gateway node; the gateway node, in response to receiving the first authentication message, generates a second authentication message and sends the second authentication message to the control center node, wherein the second authentication message includes the first authentication message; the control center node, in response to receiving the second authentication message, generates a third authentication message based on the second authentication message and sends the third authentication message to the gateway node; the gateway node, in response to receiving the third authentication message, generates a fourth authentication message based on its identity identifier and a received first long-term private key for the gateway, and sends the fourth authentication message to the sensor node; the sensor node, in response to receiving the fourth authentication message, sequentially generates sensor encryption information and a sensor session key; and the sensor node, based on the generated sensor session key, completes session key negotiation with the gateway node and the control center node after confirming successful verification of the fourth authentication message.
[0088] This disclosure also provides a computer-readable storage medium storing a computer program, the computer program including program instructions, and the method implemented when the program instructions are executed can be referred to the various embodiments of the methods described above.
[0089] The aforementioned computer-readable storage medium may be an internal storage unit of the computer device described in the foregoing embodiments, such as the hard disk or memory of the computer device. Alternatively, the aforementioned computer-readable storage medium may be an external storage device of the computer device, such as a plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the computer device.
[0090] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.
[0091] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.
Claims
1. A method for anonymous authentication of smart grids in wireless sensor networks, characterized in that, include: The sensor node generates a first authentication message based on the received long-term private key of the sensor, the sensor encrypted authentication information, and the long-term public key of the control center, and sends the first authentication message to the gateway node. In response to receiving the first authentication message, the gateway node generates a second authentication message and sends the second authentication message to the control center node, wherein the second authentication message includes the first authentication message; Upon receiving the second authentication message, the control center node generates a third authentication message based on the second authentication message and sends the third authentication message to the gateway node. In response to receiving the third authentication message, the gateway node generates a fourth authentication message based on the gateway node's identity identifier and the received first gateway long-term private key, and sends the fourth authentication message to the sensor node. Upon receiving the fourth authentication message, the sensor node sequentially generates sensor encryption information and a sensor session key. Based on the generated sensor session key, the sensor node, in response to confirming successful verification of the fourth authentication message, completes the session key negotiation with the gateway node and the control center node.
2. The method according to claim 1, characterized in that, Before the sensor node generates the first authentication message based on the received sensor long-term private key, sensor encryption authentication information, and control center long-term public key, the method further includes: Upon receiving the gateway node identity identifier and the sensor node identity identifier, the system administrator node generates the sensor long-term public and private key, sensor private information, sensor encrypted authentication information, gateway long-term private key, and control center long-term public and private key. The gateway long-term private key includes the first gateway long-term private key and the second gateway long-term private key. The system administrator node packages and sends the generated long-term private key of the sensor, the sensor encryption authentication information, and the long-term private key of the first gateway to the sensor node; The system administrator node sends the gateway's long-term private key to the gateway node; The system administrator node packages the generated long-term private key of the control center and the long-term private key of the second gateway and sends them to the control center node; The system administrator node exposes the long-term public keys of the sensors and the long-term public key of the control center to all nodes.
3. The method according to claim 2, characterized in that, The step of generating a first authentication message based on the received sensor long-term private key, sensor encrypted authentication information, and control center long-term public key, and sending the first authentication message to the gateway node, includes: Generate temporary public and private keys and a first timestamp for the sensor; Based on the received long-term private key of the sensor and the identity identifier of the sensor node, generate the sensor's private information; Based on the received sensor encryption authentication information, the control center's long-term public key, the sensor's private information, and the sensor's temporary public key, a first authentication parameter and a second authentication parameter are generated. The generated first authentication parameter, second authentication parameter, sensor temporary public key, and first timestamp are sent as the first authentication message to the gateway node.
4. The method according to claim 3, characterized in that, The response to receiving the first authentication message, generating the second authentication message, and sending it to the control center node includes: Generate the current timestamp as the second timestamp; Generate a third authentication parameter based on the second timestamp and the received second gateway long-term private key; The first authentication parameter, the second authentication parameter, the third authentication parameter, the sensor temporary public key, the first timestamp, and the second timestamp are sent as a second authentication message to the control center node.
5. The method according to claim 4, characterized in that, The step of generating a third authentication message based on the second authentication message and sending the third authentication message to the gateway node includes: Based on the second authentication message, the third authentication parameter is verified to obtain the first verification result; In response to determining that the first verification result indicates successful verification, sensor encrypted authentication information is generated based on the first authentication message; Based on the first authentication message, the second authentication parameters are verified to obtain the second verification result; In response to the determination that the second verification result indicates successful verification, a temporary private key for the control center, a temporary public key for the control center, and a third timestamp are generated. Based on the received long-term private key of the control center, long-term public key of the sensor, temporary public key of the sensor and temporary private key of the control center, generate encrypted information of the control center; Based on the control center encryption information and sensor encryption authentication information, a control center session key, a fourth authentication parameter, and a fifth authentication parameter are generated. The fourth authentication parameter, the fifth authentication parameter, the control center temporary public key, and the third timestamp are sent as the third authentication message to the gateway node.
6. The method according to claim 5, characterized in that, The step of generating a fourth authentication message based on the gateway node's identity identifier and the received first gateway long-term private key, and sending the fourth authentication message to the sensor node, includes: Based on the received second gateway long-term private key, the fourth authentication parameters included in the third authentication message are verified to obtain the third verification result; In response to determining that the third verification result indicates that the verification has passed, the current timestamp is generated as the fourth timestamp; The sixth authentication parameter is generated based on the gateway node identity identifier, the first gateway long-term private key, and the fourth timestamp; The fifth authentication parameter, the sixth authentication parameter, the control center temporary public key, the third timestamp, and the fourth timestamp are sent to the sensor node as the fourth authentication message.
7. A smart grid anonymity authentication device for wireless sensor networks, characterized in that, include: The first generation unit is configured to have the sensor node generate a first authentication message based on the received sensor long-term private key, sensor encrypted authentication information and control center long-term public key, and send the first authentication message to the gateway node. The second generation unit is configured such that, in response to receiving the first authentication message, the gateway node generates a second authentication message and sends the second authentication message to the control center node, wherein the second authentication message includes the first authentication message; The third generation unit is configured to, in response to receiving the second authentication message, generate a third authentication message based on the second authentication message, and send the third authentication message to the gateway node; The fourth generation unit is configured such that, in response to receiving the third authentication message, the gateway node generates a fourth authentication message based on the gateway node's identity identifier and the received first gateway long-term private key, and sends the fourth authentication message to the sensor node. The fifth generation unit is configured so that, in response to receiving the fourth authentication message, the sensor node sequentially generates sensor encryption information and a sensor session key; The verification unit is configured such that, in response to the sensor node determining that the fourth authentication message has been successfully verified, the session key negotiation with the gateway node and the control center node is completed.
8. An electronic device, characterized in that, include: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1 to 6.
9. A computer-readable medium, characterized in that, It stores a computer program thereon, wherein the computer program, when executed by a processor, implements the method as described in any one of claims 1 to 6.