A power data security transmission method and system for a smart meter
By generating a dynamic session key through hardware fingerprint and timestamp dual-factor key negotiation mapping, the smart meter's energy data is symmetrically encrypted. Combined with channel noise characteristics, a dynamic padding sequence is generated, realizing secure transmission of smart meter energy data throughout the entire process. This solves the problems of easy cracking of fixed keys and failure to remove sensitive information, and improves the security and anti-attack capability of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- JIANGYIN CHANGYI GRP CO LTD
- Filing Date
- 2026-05-21
- Publication Date
- 2026-07-31
AI Technical Summary
In the transmission of electricity data in smart meters, fixed keys are easily cracked, dynamic encryption and channel scrambling mechanisms are lacking, sensitive information is not cleared in time, data is easily eavesdropped and tampered with, and the ability to resist attacks is insufficient, which cannot meet the requirements of smart grids for high reliability and high security transmission.
A dynamic session key is generated by hardware fingerprint and timestamp dual-factor key negotiation mapping. The plaintext data packet is symmetrically encrypted. A dynamic padding sequence is generated by combining the channel environment noise characteristics and homomorphically encrypted with the random confusion sequence. The sensitive information is then transmitted and cleared through the power line carrier communication interface.
It enhances encryption strength and resistance to attacks, ensuring high reliability and security of data transmission and meeting the high-security transmission requirements of smart grids.
Smart Images

Figure CN122268676B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power communication. In particular, it relates to a method and system for secure transmission of electrical data in smart meters. Background Technology
[0002] As the terminal data acquisition device of the smart grid, smart meters rely on power line carrier communication for power data transmission. Current mainstream transmission security solutions generally use fixed keys for encryption protection. Since the keys remain unchanged for a long time, they are easily reverse engineered and cracked. Data is vulnerable to eavesdropping, tampering, and forgery attacks in the transmission link, and cannot resist dynamic network threats. The confidentiality and integrity of data transmission cannot be effectively guaranteed.
[0003] Existing technologies do not integrate hardware fingerprints, time factors, and channel environment characteristics into the encryption system. They only employ a single symmetric encryption method and lack dynamic key negotiation, data scrambling, and homomorphic encryption fusion mechanisms, resulting in insufficient encryption strength and resistance to attacks. Furthermore, sensitive information such as temporary keys and padding sequences are not promptly removed after transmission, posing a risk of key leakage and data breaches. Overall, the security protection effect cannot meet the requirements of smart grids for highly reliable and secure transmission of electrical data. Summary of the Invention
[0004] This invention provides a method and system for secure transmission of electrical energy data in smart meters. It addresses the technical problems of easy cracking of fixed keys for electrical energy data transmission in smart meters, lack of dynamic encryption and channel scrambling mechanisms, failure to promptly remove sensitive information, susceptibility to eavesdropping and tampering, and insufficient resistance to attacks. The aim is to improve the encryption strength and resistance to attacks of electrical energy data transmission, ensure high reliability and security of data transmission, and meet the high-security transmission requirements of smart grids.
[0005] In a first aspect, a method for secure transmission of electrical energy data for a smart meter includes: S1. Obtain the current electricity metering data of the smart meter, and encapsulate the electricity metering data in a structured manner to obtain the plaintext data packet to be transmitted from the smart meter. S2. Based on the preset key derivation rules, perform two-factor key negotiation mapping on the current hardware fingerprint features and timestamp information of the smart meter to obtain the dynamic session key of the smart meter. S3. Based on the dynamic session key, perform symmetric encryption on the plaintext data packet to be transmitted to obtain the primary ciphertext data of the smart meter; S4. Based on the current channel environment noise characteristics of the smart meter, generate a dynamic filling sequence for the smart meter, and fill the dynamic filling sequence into the protocol reserved bits of the primary ciphertext data to generate the scrambled ciphertext data of the smart meter. S5. Homomorphic encryption is performed on the random obfuscation sequence between the smart meter and the data concentrator and the scrambled ciphertext data to obtain the target transmission ciphertext of the smart meter. S6. The target transmission ciphertext is sent to the data concentrator through the power line carrier communication interface of the smart meter, and the dynamic session key, the dynamic padding sequence and the random obfuscation sequence are cleared after the transmission is completed.
[0006] Preferably, the step of acquiring the current electricity metering data of the smart meter and performing structured encapsulation of the electricity metering data to obtain the plaintext data packet to be transmitted from the smart meter includes: In response to the timing sampling interrupt signal inside the smart meter, the analog voltage signal and analog current signal of the current power grid circuit are sampled synchronously. Instantaneous power integration is performed on the analog voltage signal and the analog current signal to obtain the current energy metering data of the smart meter; The current system running time of the smart meter is used as the collection timestamp, and the collection timestamp and the electricity metering data are protocol-encapsulated to obtain the original load information of the smart meter. A data frame synchronization word is added to the header of the original load information, and an integrity check code is appended to the tail of the original load information to generate the plaintext data packet to be transmitted for the smart meter.
[0007] Preferably, the step of performing a two-factor key negotiation mapping on the current hardware fingerprint features and timestamp information of the smart meter based on a preset key derivation rule to obtain the dynamic session key of the smart meter includes: The unique serial number and media access control address of the smart meter are concatenated and combined to obtain the hardware fingerprint feature of the smart meter. The current timestamp information is obtained from the real-time clock circuit of the smart meter, and the timestamp information is granularized to obtain the discretized time factor of the timestamp information. The hardware fingerprint feature is used as the first negotiation factor and the discretization time factor is used as the second negotiation factor, which are respectively input to the first input terminal and the second input terminal defined by the preset key derivation rule; Within the key derivation rule, the first negotiation factor and the second negotiation factor are XORed, and then concatenated with the root key stored in the smart meter to obtain the intermediate derivation value of the smart meter. The intermediate derived value is iteratively remapped to obtain the dynamic session key of the smart meter.
[0008] Preferably, the iterative remapping of the intermediate derived values to obtain the dynamic session key of the smart meter includes: The intermediate derived value is split into a high half-zone byte sequence and a low half-zone byte sequence by bytes, and the high half-zone byte sequence and the low half-zone byte sequence are swapped end to end to obtain the first mapping value of the smart meter. Each byte in the first mapping value is cyclically shifted and added to the corresponding byte of the fixed offset built into the smart meter to obtain the second mapping value of the smart meter; Using the second mapping value as the current round input, the splitting and swapping and the cyclic shifting and adding are repeatedly executed until the number of iteration rounds reaches the preset round number threshold in the smart meter; After the last iteration, the current remapping value is extracted by prefix fixed-length truncation to obtain the dynamic session key of the smart meter.
[0009] Preferably, the step of performing symmetric encryption on the plaintext data packet to be transmitted based on the dynamic session key to obtain the primary ciphertext data of the smart meter includes: The plaintext data packet to be transmitted is subjected to cryptographic block chain verification to obtain the message authentication code of the plaintext data packet to be transmitted; The message authentication code is appended to the end of the plaintext data packet to be transmitted to generate the extended plaintext data of the smart meter; Based on a preset group length, the extended plaintext data is divided into plaintext group data sequences; Based on the dynamic session key, the first plaintext block in the plaintext block data sequence is subjected to keyed encryption transformation to obtain the target ciphertext block data corresponding to the first plaintext block data; Using the target ciphertext block data as feedback input, chain encryption is performed on subsequent plaintext block data in the plaintext block data sequence to obtain the primary ciphertext data of the smart meter.
[0010] Preferably, the step of generating a dynamic padding sequence for the smart meter based on the current channel environment noise characteristics of the smart meter, and filling the protocol reserved bits of the primary ciphertext data with the dynamic padding sequence to generate the scrambled ciphertext data of the smart meter, includes: The background noise of the current communication link in the smart meter is sampled in real time, and the time-frequency characteristic parameters reflecting the channel environment interference intensity are extracted from the background noise. The time-frequency characteristic parameters are normalized and mapped to obtain the feature fingerprint of the smart meter; The feature fingerprint is loaded as an input parameter into the key stream generator of the smart meter for pseudo-random expansion to obtain the dynamic filling sequence of the smart meter. Read the protocol header information of the primary ciphertext data, locate the logical storage area of the protocol reserved bits in the protocol header information, and match and verify the dynamic padding sequence with the logical storage area; When the verification passes, the dynamic filling sequence is injected into the logical storage area for bit interleaving and mixing to obtain the scrambled ciphertext data of the smart meter.
[0011] Preferably, the step of loading the feature fingerprint as an input parameter into the keystream generator of the smart meter for pseudo-random expansion to obtain the dynamic filling sequence of the smart meter includes: The feature fingerprint is written into the input buffer of the key stream generator in byte order, and the initial state vector of the key stream generator is set according to the binary length of the feature fingerprint. Perform bit-level permutations on the bytes in the initial state vector to obtain the permuted state bytes; All the permuted state bytes are concatenated into an intermediate extended sequence, and the intermediate extended sequence is cyclically fed back into the feedback register of the key stream generator; The feedback register is triggered to perform a preset number of state updates, and the output bits of the feedback register are extracted during each state update. The output bits are concatenated sequentially until the length of the concatenated sequence is equal to the length of the protocol reserved bits of the primary ciphertext data. Then, the state update is stopped and the dynamic filling sequence of the smart meter is output.
[0012] Preferably, the step of homomorphically encrypting and fusing the random obfuscation sequence between the smart meter and the data concentrator with the scrambled ciphertext data to obtain the target transmission ciphertext of the smart meter includes: Read the random obfuscation sequence agreed upon with the data concentrator from the local secure storage area of the smart meter; The scrambled ciphertext data is decomposed into multiple data blocks by bytes, and the random obfuscation sequence is divided into sequence segments of the same length as the number of data blocks. The data block and the corresponding sequence segment are XORed and fused bitwise to obtain the fused sub-block of the data block; The fusion sub-blocks are sequentially reassembled and concatenated to obtain the intermediate fusion ciphertext of the smart meter; The intermediate fused ciphertext is byte-rearranged and encapsulated to obtain the target transmission ciphertext of the smart meter.
[0013] Preferably, the step of sending the target transmission ciphertext to the data concentrator via the power line carrier communication interface of the smart meter, and clearing the dynamic session key, the dynamic padding sequence, and the random obfuscation sequence after transmission, includes: According to the communication protocol of the power line carrier communication interface of the smart meter, the target transmission ciphertext is adapted and encapsulated to obtain the data frame to be sent by the smart meter. Based on the physical layer communication parameters of the power line carrier communication interface, the data frame to be transmitted is subjected to orthogonal frequency division multiplexing modulation to obtain the modulation carrier signal of the smart meter. The modulated carrier signal is sent to the data concentrator via the power line carrier communication interface; After receiving the transmission confirmation response returned by the data concentrator, the smart meter's secure storage area erase command is triggered to overwrite and clear the dynamic session key, the dynamic padding sequence, and the random obfuscation sequence.
[0014] In a second aspect, a secure power data transmission system for smart meters includes a processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, a secure power data transmission method for smart meters as described in any one of the claims is implemented.
[0015] Compared with the prior art, the present invention has the following beneficial effects: This invention generates dynamic session keys through a two-factor key negotiation mapping of hardware fingerprint features and timestamp information. This enables dynamic key generation and ensures single-transmission validity, significantly improving the security level of encryption keys and making encryption protection more timely and unique. By relying on the dynamic session key to complete symmetric encryption of plaintext data packets, coupled with a data integrity verification mechanism, the integrity of electricity metering data can be firmly guaranteed, preventing data loss or tampering during encryption processing. Based on channel environmental noise characteristics, a dynamic padding sequence is generated and filled into protocol reserved bits, enabling precise scrambling of ciphertext data, enhancing its anti-decryption capabilities, while not disrupting the original communication protocol structure, ensuring data transmission compatibility with existing protocol systems.
[0016] This invention fuses random obfuscation sequences with scrambled ciphertext using homomorphic encryption, establishing a multi-layered ciphertext protection architecture to further enhance data transmission security and effectively resist various security threats during transmission. The target ciphertext is transmitted via a power line carrier communication interface, coupled with a dedicated modulation method, ensuring security while improving data transmission stability and efficiency. Upon completion of transmission, the dynamic session key, dynamic padding sequence, and random obfuscation sequence are immediately cleared, completely eliminating the risk of residual sensitive information and preventing key and scrambling information leakage from the process. This solution achieves secure management of the entire process of smart meter energy data collection, encapsulation, encryption, and transmission, comprehensively improving the confidentiality, integrity, and reliability of energy data transmission, meeting the core requirements of smart grids for high-security and high-stability energy data transmission.
[0017] The above and other objects, advantages and features of the present invention will become more apparent to those skilled in the art from the following detailed description of specific embodiments of the invention in conjunction with the accompanying drawings. Attached Figure Description
[0018] The following sections will describe some specific embodiments of the invention in a detailed manner by way of example and not limitation, with reference to the accompanying drawings. The same reference numerals in the drawings denote the same or similar parts or portions. Those skilled in the art should understand that these drawings are not necessarily drawn to scale. In the drawings: Figure 1 This is a schematic flowchart of a method for secure transmission of electrical energy data for a smart meter according to an embodiment of the present invention; Figure 2 This is a schematic diagram of a secure power data transmission system for smart meters according to an embodiment of the present invention. Detailed Implementation
[0019] The following reference Figures 1 to 2 This application describes a method and system for secure transmission of electrical data in a smart meter. In this description, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" or "second" may explicitly or implicitly include at least one of that feature, that is, include one or more of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified. When a feature "includes or contains" one or more of the features it encompasses, unless otherwise specifically described, this indicates that other features are not excluded and may be further included.
[0020] In the description of this embodiment, the terms "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0021] This embodiment provides a method for secure transmission of electrical energy data in smart meters. This method enables dynamic security protection throughout the entire process of electrical energy data acquisition, encryption, and transmission, while preserving the original hardware architecture of the smart meter and being compatible with existing power line carrier communication standard protocols. This effectively improves the confidentiality, integrity, and anti-attack capabilities of data transmission.
[0022] Please see Figure 1 , Figure 1 This is a schematic flowchart of a method for secure transmission of electrical data in a smart meter according to an embodiment of the present invention. The method generally includes: S1. Obtain the current electricity metering data of the smart meter, and encapsulate the electricity metering data in a structured manner to obtain the plaintext data packet to be transmitted from the smart meter. S2. Based on the preset key derivation rules, perform two-factor key negotiation mapping on the current hardware fingerprint features and timestamp information of the smart meter to obtain the dynamic session key of the smart meter. S3. Based on the dynamic session key, perform symmetric encryption on the plaintext data packet to be transmitted to obtain the primary ciphertext data of the smart meter; S4. Based on the current channel environment noise characteristics of the smart meter, generate a dynamic filling sequence for the smart meter, and fill the dynamic filling sequence into the protocol reserved bits of the primary ciphertext data to generate the scrambled ciphertext data of the smart meter. S5. Homomorphic encryption is performed on the random obfuscation sequence between the smart meter and the data concentrator and the scrambled ciphertext data to obtain the target transmission ciphertext of the smart meter. S6. The target transmission ciphertext is sent to the data concentrator through the power line carrier communication interface of the smart meter, and the dynamic session key, the dynamic padding sequence and the random obfuscation sequence are cleared after the transmission is completed.
[0023] In step S1 above, when the smart meter receives an internal timed sampling interrupt signal, it synchronously collects analog voltage and analog current signals in the power grid circuit, performs instantaneous power integration processing on the collected signals, obtains the current power metering data, sets the smart meter's own system running time as the collection timestamp, encapsulates the collection timestamp and power metering data according to the communication protocol standard to form the original load information, adds a data frame synchronization word to the header of the original load information, and appends an integrity check code to the tail of the original load information, finally generating the plaintext data packet to be transmitted by the smart meter.
[0024] In step S2 above, the unique serial number inside the smart meter is sequentially concatenated with the media access control address to form the hardware fingerprint of the smart meter. The current timestamp information is obtained from the real-time clock circuit of the smart meter, and processed according to a preset time regularization granularity to obtain a discretized time factor. The hardware fingerprint and the discretized time factor are input as two negotiation factors into a preset key derivation process. After bitwise XOR processing of the two negotiation factors, they are concatenated with the root key built into the smart meter to obtain intermediate derivation data. The intermediate derivation data is split equally according to the total number of bytes. When the total number of bytes is even, it is divided into two equal parts; when it is odd, the higher half of the byte sequence has one more byte than the lower half. The first half consists of a high half of the byte sequence and the second half consists of a low half of the byte sequence. The first half of the two byte sequences are swapped to obtain the first mapping data. The cyclic shift and addition process first performs a cyclic left shift operation of each single byte of the first mapping data by 3 bits, and then adds it arithmetically with the corresponding byte at a fixed offset. The result is modulo 256 to avoid data overflow, and the second mapping data is obtained. The splitting, swapping and cyclic shifting and addition operations are repeated until the number of operations reaches the preset number of iterations. The prefix fixed-length truncation process starts from the first byte of the final remapped data and continuously truncates data segments without offset or omission according to the 128-bit (16-byte) fixed key length specified in the smart grid power communication security standard to generate the dynamic session key of the smart meter.
[0025] In step S3 above, a cryptographic block chain verification operation is performed on the plaintext data packet to be transmitted to generate a message authentication code corresponding to the plaintext data packet to be transmitted. The message authentication code is appended to the end of the message of the plaintext data packet to be transmitted to form the extended plaintext data of the smart meter. The extended plaintext data is divided into multiple plaintext data packets according to the preset packet length. The first plaintext data packet is encrypted using a dynamic session key to obtain the ciphertext data corresponding to the first plaintext data packet. The ciphertext data packet is used as the feedback basis to sequentially perform chain encryption on the subsequent plaintext data packets. All the encrypted data packets are combined to form the primary ciphertext data of the smart meter.
[0026] In step S4 above, background noise signals in the current communication link of the smart meter are collected in real time. Time-frequency characteristic parameters that reflect the interference intensity of the channel environment are extracted from the background noise signals. The preset normalization standard is the linear normalization standard of power line carrier communication channel characteristics. First, the amplitude parameter and frequency distribution parameter in the time-frequency characteristic parameters are mapped to the closed interval [0,1] respectively. The numerical conversion is completed by the linear normalization formula (measured parameter value − minimum parameter value) / (maximum parameter value − minimum parameter value). Then, the normalized amplitude and frequency parameters are concatenated into a fixed-length binary feature sequence in high-order to low-order order to obtain the feature fingerprint of the smart meter. The feature fingerprint is written into the input buffer of the key stream generator, and the initial state of the key stream generator is set according to the binary length of the feature fingerprint. The vector is used to perform bit-level permutation on each byte of the initial state vector to obtain the permuted state byte. All permuted state bytes are concatenated into an intermediate extended sequence. The intermediate extended sequence is cyclically fed back to the feedback register of the key stream generator. The feedback register is triggered to perform state updates according to the preset update round number. During each state update, the output bit of the feedback register is extracted and continuously concatenated until the sequence length is completely consistent with the protocol reserved bit length of the primary ciphertext data, thus obtaining the dynamic filling sequence of the smart meter. The protocol header information of the primary ciphertext data is read, the logical storage area corresponding to the protocol reserved bit is located, and the compatibility between the dynamic filling sequence and the logical storage area is verified. After the verification is passed, the dynamic filling sequence is injected into the logical storage area and bit-interleaving mixing is performed to generate the scrambled ciphertext data of the smart meter.
[0027] In step S5 above, the random obfuscation sequence pre-negotiated with the data concentrator is read from the local secure storage area of the smart meter. The obfuscated ciphertext data is decomposed into multiple independent data blocks by bytes. The random obfuscation sequence is divided into a corresponding number of sequence segments of the same length according to the number and length of the data blocks. Each data block and its corresponding sequence segment are XORed and fused to obtain a fused sub-block corresponding to each data block. All fused sub-blocks are reassembled and concatenated according to their original arrangement to form the intermediate fused ciphertext of the smart meter. The intermediate fused ciphertext is then subjected to byte rearrangement and encapsulation processing to generate the target transmission ciphertext of the smart meter.
[0028] In step S6 above, the target transmitted ciphertext is adapted and encapsulated according to the communication protocol standard of the power line carrier communication interface of the smart meter to generate a data frame to be sent by the smart meter. Based on the physical layer communication parameters of the power line carrier communication interface, the data frame to be sent is subjected to orthogonal frequency division multiplexing modulation processing to generate the modulation carrier signal of the smart meter. The modulation carrier signal is sent to the data concentrator through the power line carrier communication interface. After receiving the transmission confirmation response returned by the data concentrator, the smart meter's secure storage area erase command is triggered to perform overwrite and clearing processing on the dynamic session key, dynamic padding sequence and random obfuscation sequence.
[0029] The beneficial effects include generating dynamic session keys through a combination of hardware fingerprints and timestamps, ensuring the uniqueness and timeliness of the keys; generating dynamic padding sequences based on channel noise characteristics and combining them with random obfuscation sequences to achieve homomorphic encryption fusion, thus constructing a multi-layered ciphertext protection structure, effectively improving the anti-attack capability of power data transmission; and immediately overwriting and clearing sensitive information after transmission, completely eliminating the security risks caused by information residue. It is fully compatible with the power line carrier communication protocol, ensuring data transmission efficiency while realizing full-process security control of power data from acquisition, encapsulation, encryption to transmission, comprehensively ensuring the confidentiality and integrity of power data transmission.
[0030] In step S1 above, the method of obtaining the current electricity metering data of the smart meter and encapsulating the electricity metering data in a structured manner to obtain the plaintext data packet to be transmitted of the smart meter includes the following steps; Step S101: In response to the timing sampling interrupt signal inside the smart meter, the analog voltage signal and analog current signal of the current power grid circuit are sampled synchronously. Step S102: Perform instantaneous power integration on the analog voltage signal and the analog current signal to obtain the current power metering data of the smart meter; Step S103: Use the current system running time of the smart meter as the collection timestamp, and encapsulate the collection timestamp and the electricity metering data using a protocol to obtain the original load information of the smart meter; Step S104: Add a data frame synchronization word to the header of the original load information and append an integrity check code to the tail of the original load information to generate the plaintext data packet to be transmitted for the smart meter.
[0031] In step S101 above, the internal timing sampling circuit of the smart meter generates an interrupt signal stably according to the preset standard time period for power acquisition. After receiving the interrupt signal, the analog signal acquisition unit of the meter performs signal acquisition operations on the voltage transmission line and current transmission line of the power grid circuit without time deviation through independent voltage acquisition channel and current acquisition channel, and synchronously acquires the analog voltage signal and analog current signal of the current power grid circuit.
[0032] In step S102 above, the metering processing unit inside the smart meter first converts the collected analog voltage signal and analog current signal into digital signals, and then performs instantaneous power integration processing on the converted digital signals. Using the preset metering integration period as the time reference, the power value is continuously accumulated and integrated to eliminate the deviation caused by the instantaneous fluctuation of the signal, and obtain the current power metering data of the smart meter.
[0033] In step S103 above, the real-time clock unit inside the smart meter keeps a continuous and accurate time, reads the current stable operating system time that is accurate to the second, and directly determines the system time as the collection timestamp. The protocol encapsulation unit inside the meter fills the collection timestamp into the protocol fixed time field and fills the power metering data into the protocol core payload field according to the standard frame structure protocol of power line carrier communication. After completing the ordered combination and encapsulation, the original payload information of the smart meter is obtained.
[0034] In step S104 above, the data frame construction unit inside the smart meter selects the fixed data frame synchronization word specified by the power line carrier communication protocol and adds it to the beginning position of the original load information for the receiver to quickly identify the start of the data frame. It generates an integrity check code using a fixed verification rule and appends it to the end position of the original load information for the receiver to verify the integrity of the data transmission. After completing all data combination operations, it generates the plaintext data packet to be transmitted by the smart meter.
[0035] The beneficial effects are as follows: synchronous acquisition is triggered by a standard periodic interrupt, ensuring the synchronization and stability of analog voltage and current signal acquisition; analog-to-digital conversion combined with precise power integration processing improves the accuracy of power metering data; standardized frame structure protocol encapsulation ensures the compliance of the original load information format; the addition of data frame synchronization words and integrity check codes enables the identification and verification of data frames; and the final generated plaintext data packets to be transmitted have a unified format, accurate data, and strong transmission adaptability, providing a stable and reliable basic data carrier for subsequent data encryption and secure transmission.
[0036] In step S2 above, the method of obtaining the dynamic session key of the smart meter by performing two-factor key negotiation mapping on the current hardware fingerprint features and timestamp information of the smart meter based on the preset key derivation rules includes the following steps. Step S201: Concatenate and combine the unique serial number and media access control address of the smart meter to obtain the hardware fingerprint feature of the smart meter. Step S202: Obtain the current timestamp information from the real-time clock circuit of the smart meter, and perform granular normalization on the timestamp information to obtain the discretized time factor of the timestamp information; Step S203: The hardware fingerprint feature is used as the first negotiation factor and the discretization time factor is used as the second negotiation factor, and they are respectively input to the first input terminal and the second input terminal defined by the preset key derivation rule; Step S204: Within the key derivation rule, the first negotiation factor and the second negotiation factor are XORed, and then concatenated with the root key stored in the smart meter to obtain the intermediate derivation value of the smart meter. Step S205: Iteratively remap the intermediate derived value to obtain the dynamic session key of the smart meter.
[0037] In step S201 above, the internal secure storage unit of the smart meter is a dedicated data storage module configured by the manufacturer at the time of manufacture. It is used to permanently store the device's unique identification information. The unique serial number, which is permanently fixed and cannot be modified at the time of manufacture, is read from this module. This serial number is the unique identification code corresponding to each smart meter. At the same time, the globally unique media access control address built into the communication chip is read. This address is the fixed physical identifier of the meter's communication hardware. According to the manufacturer's preset fixed connection order of first the unique serial number and then the media access control address, the two sets of character data are sequentially and continuously concatenated bit by bit. The combined data sequence maintains the fixed length specified by the protocol and has no missing data, thus obtaining the hardware fingerprint feature of the smart meter.
[0038] In step S202 above, the real-time clock circuit of the smart meter is a factory-configured high-precision hardware timing module that continuously outputs stable and time-deviation-free standard time data. The current complete timestamp information, accurate to the minute level, is read from this circuit. This timestamp information includes complete time data of year, month, day, hour, and minute. The preset fixed time granularity standard comes from the explicit provisions of the smart meter power communication security protocol. The minute level is used as the sole normalization benchmark. The timestamp information is normalized according to this standard, and all time precision data at the second level and below are removed. Only the minute-level time data that meets the protocol requirements is retained to obtain the discrete time factor corresponding to the timestamp information.
[0039] In step S203 above, the smart meter formally sets the generated hardware fingerprint feature as the first negotiation factor for key negotiation and the generated discretized time factor as the second negotiation factor for key negotiation. The key derivation module is a hardware security processing unit built into the smart meter. Its first data input terminal and second data input terminal are fixed data input ports predefined by the communication security protocol. The first negotiation factor is transmitted to the first data input terminal and the second negotiation factor is transmitted to the second data input terminal to ensure that the two sets of negotiation factors are input without overlap, loss, or delay.
[0040] In step S204 above, the formula for calculating the intermediate derived value is as follows: ; In the formula, This is the intermediate derived value. The first negotiation factor, The second negotiation factor, This is a fixed offset built into the smart meter. For the root key, For bitwise XOR operation, This is a bitwise operation for left shifting by three bits; The key derivation module is a dedicated encryption processing unit built into the smart meter. Internally, it runs a fixed logic processing flow preset by the communication security protocol. The first negotiation factor is derived from the hardware fingerprint feature generated by concatenating the smart meter's factory-fixed unique serial number and the communication chip's media access control address in a fixed manufacturer order. This is the core factor of the meter's unique hardware identity. The second negotiation factor is derived from the real-time clock circuit's timestamp, a discrete time factor normalized to a minute-level benchmark according to the power communication security protocol, possessing dynamic timeliness attributes. The root key is the core foundation key that the manufacturer has fixed in a secure storage unit according to power grid transmission security standards and key specifications. It has undergone security testing and verification and is tamper-proof and readable. The fixed offset is the result of multiple tests and verifications by the encryption team, considering the meter's hardware capabilities, channel characteristics, and protection requirements. The factory-preset fixed values are permanently stored in the encryption processing unit. The bitwise XOR operation processes the data by comparing the binary bits one by one. The same bit is output as 0 and different bits are output as 1, which is adapted to the processing efficiency of the meter hardware. The left shift three bits operation moves the binary data three bits to the high bits and fills the low bits with 0, which can improve the data obfuscation. The module first performs XOR logic processing on the first negotiation factor and the second negotiation factor bit by bit, and then combines the root key and the fixed offset to achieve two-factor fusion through logical operations and bit operations. Finally, it generates an intermediate derived value that connects the two-factor key negotiation and the subsequent iterative remapping stage. This operation process is adapted to the processing capability of the meter hardware. The generated intermediate derived value has high complexity and device uniqueness, providing basic data that meets security standards for the subsequent generation of dynamic session keys.
[0041] In step S205 above, the preset fixed number of iterations comes from the security test verification results of the smart meter security encryption protocol. To ensure the standard value set for key complexity, the smart meter strictly performs iterative remapping operations on the intermediate derived values according to this fixed number of iterations. The specific implementation of the iterative remapping operation is as follows: In each iteration, the currently processed data sequence is first divided into a high half-zone byte sequence and a low half-zone byte sequence according to the total number of bytes. The first and last positions of the two sets of byte sequences are swapped to obtain a rearranged data sequence. Then, each byte in the rearranged data sequence is cyclically shifted left by 3 bits to the corresponding byte with the fixed offset built into the smart meter, and then arithmetically added. The addition result is modulo 256 to ensure that the byte value is within the valid range, thus completing the data rearrangement and conversion of a single round of iteration. In each iteration, the data sequence is processed by byte position swapping and fixed character conversion according to the preset rules of the protocol. The rules and processes of each iteration are completely consistent. After completing all iterations, the processed data sequence is extracted according to the key standard length specified in the protocol. The extracted data sequence fully meets the requirements for symmetric encryption, thus obtaining the dynamic session key of the smart meter.
[0042] The beneficial effects are as follows: relying on the unique serial number fixed at the factory and the physical address of the communication chip to generate hardware fingerprint features, making the key generation device-specific and uncopyable; based on the time granularity specified by the protocol to form a discrete time factor, the key has dynamic timeliness characteristics; the two-factor input according to the protocol port direction ensures the standardization of the key derivation process; the root key is the core key fixed at the factory; XOR processing and concatenation combination improve the security of intermediate derived values; and the remapping operation is performed according to the number of iterations verified by the protocol to further enhance the complexity and security level of the dynamic session key. The final generated dynamic session key has device uniqueness, time dynamics and high resistance to cracking, providing compliant and secure key support for subsequent data encryption.
[0043] In step S3 above, the method of performing symmetric encryption on the plaintext data packet to be transmitted based on the dynamic session key to obtain the primary ciphertext data of the smart meter includes the following steps; Step S301: Perform cryptographic block chain verification on the plaintext data packet to be transmitted to obtain the message authentication code of the plaintext data packet to be transmitted. Step S302: Append the message authentication code to the end of the plaintext data packet to be transmitted to generate the extended plaintext data of the smart meter. Step S303: Based on the preset group length, the extended plaintext data is divided into plaintext group data sequences; Step S304: Based on the dynamic session key, perform keyed encryption transformation on the first plaintext block data in the plaintext block data sequence to obtain the target ciphertext block data corresponding to the first plaintext block data; Step S305: Using the target ciphertext block data as feedback input, chain encryption processing is performed on subsequent plaintext block data in the plaintext block data sequence to obtain the primary ciphertext data of the smart meter.
[0044] In step S301 above, the encryption verification unit built into the smart meter is a hardware-level security processing module. It follows the cryptographic blockchain verification execution standard that is plaintext stipulated in the national smart grid power communication security protocol and has passed industry security certification. It performs bit-by-bit integrity verification on each bit of the plaintext data packet to be transmitted. The verification process takes the complete data packet as the sole benchmark, with no data bits skipped or omitted throughout the process. After the verification is completed, a message authentication code that is uniquely bound to the plaintext data packet to be transmitted and cannot be tampered with is generated.
[0045] In step S302 above, the data splicing unit inside the smart meter is a dedicated data combination hardware module. According to the message structure additional specifications clearly specified in the national power line carrier communication general protocol and adapted to all smart meters, the generated message authentication code is accurately added to the last bit of the plaintext data packet to be transmitted. Throughout the process, the internal structure, data order and data length of the original data packet remain unchanged. After the splicing operation is completed, the extended plaintext data of the smart meter is generated.
[0046] In step S303 above, the preset group length is derived from the mandatory provisions of the national smart grid power line carrier communication standard protocol. This value has been verified through multi-dimensional adaptation tests of smart meter hardware computing power, data transmission frame structure, and encryption processing efficiency. It is a fixed and universal standard value. The data segmentation unit of the smart meter is a dedicated data segmentation hardware module. According to the fixed group length, it is uniformly segmented from the starting data bit of the extended plaintext data. The length of each data segment is completely consistent with the preset group length. There is no data overlap or data loss between segments. After the segmentation is completed, a continuous, complete, and fixed sequence of plaintext group data is formed.
[0047] In step S304 above, the encryption transformation unit of the smart meter is a hardware-level symmetric encryption processing module. It calls the dynamic session key generated in the early stage through two-factor key negotiation, and performs a complete key-based encryption transformation on the first plaintext block data in the plaintext block data sequence according to the processing rules of the national power communication symmetric encryption standard that is completely matched with the key logic. The transformation process strictly follows the one-to-one correspondence processing logic between the key and the block data, with no data misalignment and no logical deviation, and generates the target ciphertext block data corresponding to the first plaintext block data.
[0048] In step S305 above, the chain encryption unit of the smart meter is a dedicated cascade encryption hardware module. The target ciphertext block data is used as the fixed feedback input for the encryption of all subsequent block data. The encryption processing rules and execution process are completely consistent with the first plaintext block data. According to the original arrangement order of the plaintext block data sequence, the encryption processing is performed on all block data after the first block in sequence. After all blocks are encrypted, they are seamlessly combined in the original order. The combined data format conforms to the power communication encryption standard, and the primary ciphertext data of the smart meter is obtained.
[0049] The beneficial effects include generating a uniquely bound message authentication code through industry-certified cryptographic block chain verification, ensuring the integrity and verifiability of the plaintext data packets to be transmitted from the source; completing message splicing according to the general communication protocol to make the extended plaintext data adaptable to all smart meter transmission scenarios; cutting data according to the national protocol standard group length to fully match the processing capabilities of the meter hardware; dynamic session key encryption of the first group to ensure the uniqueness of the initial encryption; chain-feedback encryption to ensure that the encryption logic of all groups is consistent and the format is standardized; and finally generating high-security and highly compatible primary ciphertext data, providing stable and reliable encrypted data support for subsequent data scrambling.
[0050] In step S4 above, the method of generating a dynamic filling sequence for the smart meter based on the current channel environment noise characteristics of the smart meter, and filling the dynamic filling sequence into the protocol reserved bits of the primary ciphertext data to generate scrambled ciphertext data of the smart meter includes the following steps; Step S401: Sample the background noise of the current communication link in the smart meter in real time, and extract the time-frequency characteristic parameters of the background noise that reflect the intensity of interference in the channel environment; Step S402: Normalize and map the time-frequency characteristic parameters to obtain the feature fingerprint of the smart meter; Step S403: The feature fingerprint is loaded as an input parameter into the key stream generator of the smart meter for pseudo-random expansion to obtain the dynamic filling sequence of the smart meter. Step S404: Read the protocol header information of the primary ciphertext data, locate the logical storage area of the protocol reserved bits in the protocol header information, and match and verify the dynamic padding sequence with the logical storage area; Step S405: When the verification passes, the dynamic filling sequence is injected into the logical storage area for bit interleaving and mixing to obtain the scrambled ciphertext data of the smart meter.
[0051] In step S401 above, the channel noise sampling hardware unit built into the smart meter performs uninterrupted sampling of the background noise that continuously exists in the current power line communication link according to the real-time sampling frequency specified in the national power line carrier communication standard. The sampling process covers the entire communication frequency band. Then, according to the smart grid channel environment detection specification, the amplitude characteristics and frequency distribution characteristics that can directly reflect the channel interference intensity are extracted from the sampled background noise data and combined to form time-frequency characteristic parameters.
[0052] In step S402 above, the data mapping processing unit inside the smart meter adopts a normalized mapping rule predefined in the smart meter encryption security protocol and verified by security testing. This normalized mapping rule is a standardized processing rule that converts the amplitude, frequency distribution, and other time-frequency characteristic parameters extracted from the channel background noise into a uniform-length discrete digital sequence by performing linear scaling, discrete quantization, and fixed-width normalization according to a preset standard value range. The protocol on which the conversion is based is the National Smart Grid Power Communication Security Protocol and the Power Line Carrier Communication Standard Protocol, which are official industry standards that smart meter encrypted transmission must follow. The conversion process strictly follows the numerical correspondence relationship specified in the protocol. Specifically, the amplitude value of the time-frequency characteristic parameter is linearly mapped to the high 4 bits of the binary sequence, and the frequency distribution value is linearly mapped to the low 4 bits of the binary sequence. The actual value of the parameter and the binary bit value are proportionally positively correlated according to the fixed coefficient of the protocol. Finally, the converted fixed-length standardized data sequence is used as the feature fingerprint of the smart meter.
[0053] In step S403 above, the smart meter uses the generated feature fingerprint as the core input parameter and loads it completely into the key stream generator built into the meter and conforming to the power communication security standard. The key stream generator performs bit-by-bit expansion processing on the feature fingerprint according to the pseudo-random expansion process preset by the protocol. The expansion process continues until the generated data meets the requirements for subsequent filling, and finally the dynamic filling sequence of the smart meter is obtained.
[0054] In step S404 above, the protocol parsing hardware unit inside the smart meter reads the protocol header information in the primary encrypted data that follows the power line carrier communication standard protocol format, locates the logical storage area corresponding to the protocol reserved bit in the protocol header information according to the address field defined by the protocol, and then compares the length of the dynamic filling sequence with the fixed bit width of the logical storage area one by one to complete the matching verification between the dynamic filling sequence and the logical storage area.
[0055] In step S405 above, when the length comparison result of the dynamic filling sequence and the logical storage area is completely consistent, the data mixing unit inside the smart meter accurately injects the dynamic filling sequence into the logical storage area of the protocol reserved bit, and performs orderly mixing processing on the data according to the bit interleaving rules preset by the power communication protocol. The mixing process does not change the core structure and effective content of the primary ciphertext data, and finally obtains the scrambled ciphertext data of the smart meter.
[0056] The beneficial effects are that the channel background noise is obtained by standard sampling frequency and the standard time-frequency characteristic parameters are extracted to ensure that the feature source is truly consistent with the current communication environment. Based on the normalized mapping and pseudo-random expansion preset by the protocol, a dynamic filling sequence is generated to ensure the randomness and environmental adaptability of the sequence. The protocol reserved bits are accurately located and the length is checked. Bit interleaving and mixing improve the anti-decryption capability of the ciphertext without destroying the data structure. The finally generated scrambled ciphertext data has both environmental adaptability and high security, providing a stable scrambled data foundation for subsequent homomorphic encryption fusion.
[0057] In step S5 above, the method of homomorphically encrypting and fusing the random obfuscation sequence between the smart meter and the data concentrator with the scrambled ciphertext data to obtain the target transmission ciphertext of the smart meter includes the following steps; Step S501: Read the random obfuscation sequence agreed upon with the data concentrator from the local secure storage area of the smart meter; Step S502: Decompose the scrambled ciphertext data into multiple data blocks by bytes, and divide the random obfuscation sequence into sequence segments of the same length as the number of data blocks; Step S503: Perform bitwise XOR fusion on the data block and the corresponding sequence segment to obtain the fused sub-block of the data block; Step S504: Sequentially reassemble and concatenate the fusion sub-blocks to obtain the intermediate fusion ciphertext of the smart meter; Step S505: The intermediate fused ciphertext is byte-rearranged and encapsulated to obtain the target transmission ciphertext of the smart meter.
[0058] In step S501 above, the local secure storage area of the smart meter is a dedicated hardware encrypted storage module integrated by the manufacturer during the equipment manufacturing stage. This module has hardware security features such as anti-reading, anti-tampering, and anti-erasure, and fully complies with the national smart grid power terminal security storage specifications. The random obfuscation sequence is exclusive obfuscated data that is confirmed through a dedicated key negotiation channel after the smart meter and data concentrator complete identity verification according to the two-way identity authentication standard of the national smart grid power communication security protocol during the initial networking pairing stage. After confirmation, it is permanently stored in the local secure storage area. The smart meter can directly read the random obfuscation sequence from the secure storage area through the hardware secure reading channel. The reading process is controlled by the hardware encryption unit throughout, with no risk of data loss, tampering, or leakage.
[0059] In step S502 above, the National Smart Grid Power Line Carrier Communication Standard Protocol clearly defines the byte as the smallest standard unit for data transmission and hardware processing. This standard has been verified through massive terminal adaptation tests in the industry and is applicable to all communication processing scenarios of smart meters and data concentrators. The data decomposition hardware unit inside the smart meter uses a single byte as a fixed reference unit and continuously decomposes the data starting from the beginning byte of the scrambled ciphertext. The byte lengths of the multiple data blocks formed by the decomposition are completely consistent, with no data truncation or overlap. At the same time, the data partitioning hardware unit divides the random scrambling sequence evenly from the starting position according to the fixed byte length of each data block. The number of sequence fragments after partitioning is exactly the same as the number of data blocks, and the byte length of each sequence fragment is completely consistent with the corresponding data block, with no length difference or quantity deviation.
[0060] In step S503 above, bitwise XOR fusion is a general hardware-level logic processing method that has been certified for security in the field of power communication encryption. It is widely used in power terminal data encryption scenarios. The hardware encryption processing unit inside the smart meter performs bitwise comparison processing on each bit of binary data of each data block and the corresponding sequence segment. The same binary bit outputs a fixed value, and different binary bits output the corresponding value. All data bits are completely processed without any omissions. After processing, a fused sub-block that uniquely corresponds to the data block is generated. Each fused sub-block retains the core features of the original data and has high obfuscation characteristics.
[0061] In step S504 above, the data concatenation hardware unit inside the smart meter strictly follows the original byte arrangement order before the scrambled ciphertext data is decomposed, and seamlessly concatenates all the fused sub-blocks from the first to the last. During the concatenation process, the position of each fused sub-block corresponds completely to the position of the data block before decomposition, with no data misalignment, missing, repetition or reversed order. After the concatenation is completed, a continuous and complete intermediate fused ciphertext with a format that conforms to the power communication encryption standard is formed.
[0062] In step S505 above, the byte rearrangement encapsulation is performed according to the transmission frame encapsulation rules specified in the national smart grid power line carrier communication standard protocol. These rules are adapted to the transmission characteristics of the power line carrier physical layer. The frame encapsulation hardware unit inside the smart meter adjusts the byte order of the intermediate fused ciphertext in an orderly manner according to the fixed rearrangement rules of the protocol. After the adjustment is completed, a frame header identifier and a frame tail check bit are added according to the structural requirements of the standard transmission frame to complete the overall encapsulation process. The encapsulated data fully meets the physical layer transmission specifications and data format requirements of power line carrier communication, thus obtaining the target transmission ciphertext of the smart meter.
[0063] The beneficial effects are as follows: relying on the hardware encryption storage area that complies with the State Grid security specifications and the random obfuscation sequence generated through negotiation with the protocol standard, the exclusive security and immutability of the obfuscated information are guaranteed from the data source. Data is decomposed and divided into units based on the industry-unified standard byte, ensuring data processing accuracy and device compatibility. The use of certified and universal hardware-level XOR fusion processing significantly improves the obfuscation level and anti-decryption capability of the encrypted data. The fusion sub-blocks are strictly concatenated in the original order to completely preserve the core information and structural integrity of the data. Byte rearrangement and encapsulation are performed according to the power line carrier transmission protocol, so that the target transmitted encrypted data can simultaneously meet the dual requirements of high security protection and stable transmission. The resulting encrypted data has outstanding anti-attack capability and strong transmission adaptability, providing a safe, stable, compliant and reliable transmission carrier for subsequent data transmission links.
[0064] In step S6 above, the method of sending the target transmission ciphertext to the data concentrator through the power line carrier communication interface of the smart meter, and clearing the dynamic session key, the dynamic padding sequence and the random obfuscation sequence after the transmission is completed includes the following steps; Step S601: According to the communication protocol of the power line carrier communication interface of the smart meter, the target transmission ciphertext is adapted and encapsulated to obtain the data frame to be sent by the smart meter. Step S602: Based on the physical layer communication parameters of the power line carrier communication interface, orthogonal frequency division multiplexing modulation is performed on the data frame to be transmitted to obtain the modulation carrier signal of the smart meter; Step S603: The modulated carrier signal is sent to the data concentrator through the power line carrier communication interface; Step S604: After receiving the transmission confirmation response returned by the data concentrator, the secure storage area erase command of the smart meter is triggered to overwrite and clear the dynamic session key, the dynamic padding sequence, and the random obfuscation sequence.
[0065] In step S601 above, the power line carrier communication interface of the smart meter strictly follows the general standard protocol for power line carrier communication issued by the national smart grid. This protocol has been tested and verified by authoritative industry institutions and is uniformly applicable to the communication interaction scenario between the smart meter and the data concentrator. The frame encapsulation hardware unit inside the smart meter adds a frame header synchronization identifier specified by the protocol to the front end of the target transmitted ciphertext according to the fixed data frame structure specified by the protocol, and adds a frame tail end identifier and transmission verification information specified by the protocol to the back end, completing the full-dimensional adaptation encapsulation process. The encapsulated data format fully matches the transmission requirements of power line carrier communication, and the data frame to be sent by the smart meter is obtained.
[0066] In step S602 above, the physical layer communication parameters of the power line carrier communication interface are clearly defined by the national smart grid power line carrier communication physical layer standard, including fixed configuration parameters such as carrier transmission frequency, signal bandwidth, and symbol rate. All parameters have been adapted and verified for complex power transmission environments to ensure stable signal transmission. The modulation hardware unit inside the smart meter performs orthogonal frequency division multiplexing modulation processing on the data frame to be transmitted based on this set of fixed physical layer communication parameters, converting the digital data frame to be transmitted into an analog carrier signal that conforms to the characteristics of power line transmission. The conversion process follows the power communication physical layer modulation standard throughout, resulting in the modulated carrier signal of the smart meter.
[0067] In step S603 above, the power line carrier communication interface of the smart meter is a dedicated hardware communication port that directly connects to the power grid power line. This interface uses the power line as the only data transmission medium and stably sends the generated modulated carrier signal to the corresponding data concentrator through the preset power line transmission channel. The transmission process strictly follows the physical layer transmission timing of power line carrier communication, without signal interruption, data loss or timing deviation.
[0068] In step S604 above, after the data concentrator fully receives the modulated carrier signal and completes signal parsing, data verification and integrity verification, it will return a transmission confirmation response in a fixed format specified by the power line carrier communication protocol. After the smart meter's communication receiving unit accurately receives the transmission confirmation response, it immediately triggers a hardware-level erase command for the local secure storage area. This erase command is a fixed execution command preset by the smart meter security protection specification. By writing fixed overwrite data to the storage unit, it performs a complete overwrite and clearing operation on the dynamic session key, dynamic padding sequence and random obfuscation sequence. After clearing, the relevant sensitive data cannot be recovered and read in any way.
[0069] The beneficial effects are as follows: the data frame to be transmitted is encapsulated in accordance with the national power line carrier communication standard protocol, ensuring that the data format is highly compatible with the transmission scenario; orthogonal frequency division multiplexing modulation is performed in accordance with the physical layer standard parameters to ensure that the signal is compatible with the power line transmission characteristics; signal transmission is completed by relying on the power line dedicated medium to ensure transmission stability; after the transmission is completed, all sensitive data is cleared by hardware overwriting, completely eliminating the risk of key and obfuscated information leakage, and realizing the full-process security closed-loop management of power data from encryption and transmission to the destruction of sensitive information.
[0070] The flowchart provided in this embodiment is not intended to indicate that the operations of the method will be performed in any particular order, or that all operations of the method are included in every case. Furthermore, the method may include additional operations. Within the scope of the technical concept provided by the method in this embodiment, additional variations can be made to the above method.
[0071] It should be understood that in some embodiments, the components may be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods may be implemented using software or firmware stored in memory and executed by a suitable instruction execution system.
[0072] This embodiment also provides a secure power data transmission system for smart meters, such as... Figure 2 As shown, it includes a memory 20, a processor 10, and a computer program 21 stored in the memory 20 and running on the processor 10. When the computer program 21 is executed by the processor 10, it implements the steps of a method for secure transmission of electrical energy data for a smart meter according to any of the above embodiments.
[0073] The computer program 21 used to perform the operations of this invention may be assembly instructions, Instruction Set Architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, integrated circuit configuration data, or source code or object code written in one or more programming languages and any combination of procedural programming languages. The computer program 21 may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including a Local Area Network (LAN) or Wide Area Network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, to perform aspects of this invention, electronic circuits, including, for example, programmable logic circuits, Field-Programmable Gate Arrays (FPGAs), or Programmable Logic Arrays (PLAs), may execute computer-readable program instructions to personalize the electronic circuits by utilizing status information of the computer-readable program instructions.
[0074] Therefore, those skilled in the art should recognize that although numerous exemplary embodiments of the present invention have been shown and described in detail herein, many other variations or modifications conforming to the principles of the present invention can be directly determined or derived from the disclosure of the present invention without departing from the spirit and scope of the invention. Thus, the scope of the present invention should be understood and construed as covering all such other variations or modifications.
Claims
1. A method for secure transmission of electrical energy data in smart meters, characterized in that, include: S1. Obtain the current electricity metering data of the smart meter, and encapsulate the electricity metering data in a structured manner to obtain the plaintext data packet to be transmitted from the smart meter. S2. Based on the preset key derivation rules, perform two-factor key negotiation mapping on the current hardware fingerprint features and timestamp information of the smart meter to obtain the dynamic session key of the smart meter. S3. Based on the dynamic session key, perform symmetric encryption on the plaintext data packet to be transmitted to obtain the primary ciphertext data of the smart meter; S4. Based on the current channel environment noise characteristics of the smart meter, generate a dynamic padding sequence for the smart meter, and fill the protocol reserved bits of the primary ciphertext data with the dynamic padding sequence to generate the scrambled ciphertext data of the smart meter, including... The background noise of the current communication link in the smart meter is sampled in real time, and the time-frequency characteristic parameters reflecting the channel environment interference intensity are extracted from the background noise. The time-frequency characteristic parameters are normalized and mapped to obtain the feature fingerprint of the smart meter; The feature fingerprint is loaded as an input parameter into the key stream generator of the smart meter for pseudo-random expansion to obtain the dynamic filling sequence of the smart meter. Read the protocol header information of the primary ciphertext data, locate the logical storage area of the protocol reserved bits in the protocol header information, and match and verify the dynamic padding sequence with the logical storage area; When the verification passes, the dynamic filling sequence is injected into the logical storage area for bit interleaving and mixing to obtain the scrambled ciphertext data of the smart meter; S5. Homomorphic encryption is performed on the random obfuscation sequence between the smart meter and the data concentrator and the scrambled ciphertext data to obtain the target transmission ciphertext of the smart meter. S6. The target transmission ciphertext is sent to the data concentrator through the power line carrier communication interface of the smart meter, and the dynamic session key, the dynamic padding sequence and the random obfuscation sequence are cleared after the transmission is completed.
2. The method for secure transmission of electrical data in a smart meter according to claim 1, characterized in that, The process of acquiring the current electricity metering data of the smart meter and encapsulating the electricity metering data in a structured manner to obtain the plaintext data packet to be transmitted from the smart meter includes: In response to the timing sampling interrupt signal inside the smart meter, it synchronously samples the analog voltage signal and analog current signal of the current power grid circuit; Instantaneous power integration is performed on the analog voltage signal and the analog current signal to obtain the current energy metering data of the smart meter; The current system running time of the smart meter is used as the collection timestamp, and the collection timestamp and the electricity metering data are protocol-encapsulated to obtain the original load information of the smart meter. A data frame synchronization word is added to the header of the original load information, and an integrity check code is appended to the tail of the original load information to generate the plaintext data packet to be transmitted for the smart meter.
3. The method for secure transmission of electrical energy data in a smart meter according to claim 1, characterized in that, The method, based on a preset key derivation rule, performs a two-factor key negotiation mapping between the current hardware fingerprint features and timestamp information of the smart meter to obtain the dynamic session key of the smart meter, including: The unique serial number and media access control address of the smart meter are concatenated and combined to obtain the hardware fingerprint feature of the smart meter. The current timestamp information is obtained from the real-time clock circuit of the smart meter, and the timestamp information is granularized to obtain the discretized time factor of the timestamp information. The hardware fingerprint feature is used as the first negotiation factor and the discretization time factor is used as the second negotiation factor, which are respectively input to the first input terminal and the second input terminal defined by the preset key derivation rule; Within the key derivation rule, the first negotiation factor and the second negotiation factor are XORed, and then concatenated with the root key stored in the smart meter to obtain the intermediate derivation value of the smart meter. The intermediate derived value is iteratively remapped to obtain the dynamic session key of the smart meter.
4. The method for secure transmission of electrical data in a smart meter according to claim 3, characterized in that, The iterative remapping of the intermediate derived values to obtain the dynamic session key of the smart meter includes: The intermediate derived value is split into a high half-zone byte sequence and a low half-zone byte sequence by bytes, and the high half-zone byte sequence and the low half-zone byte sequence are swapped end to end to obtain the first mapping value of the smart meter. Each byte in the first mapping value is cyclically shifted and added to the corresponding byte of the fixed offset built into the smart meter to obtain the second mapping value of the smart meter; Using the second mapping value as the current round input, the splitting and swapping and the cyclic shifting and adding are repeatedly executed until the number of iteration rounds reaches the preset round number threshold in the smart meter; After the last iteration, the current remapping value is extracted by prefix fixed-length truncation to obtain the dynamic session key of the smart meter.
5. A method for secure transmission of electrical energy data in a smart meter according to claim 1, characterized in that, The step of performing symmetric encryption on the plaintext data packet to be transmitted based on the dynamic session key to obtain the primary ciphertext data of the smart meter includes: The plaintext data packet to be transmitted is subjected to cryptographic block chain verification to obtain the message authentication code of the plaintext data packet to be transmitted; The message authentication code is appended to the end of the plaintext data packet to be transmitted to generate the extended plaintext data of the smart meter; Based on a preset group length, the extended plaintext data is divided into plaintext group data sequences; Based on the dynamic session key, the first plaintext block in the plaintext block data sequence is subjected to keyed encryption transformation to obtain the target ciphertext block data corresponding to the first plaintext block data; Using the target ciphertext block data as feedback input, chain encryption processing is performed on subsequent plaintext block data in the plaintext block data sequence to obtain the primary ciphertext data of the smart meter.
6. A method for secure transmission of electrical energy data in a smart meter according to claim 1, characterized in that, The step of loading the characteristic fingerprint as an input parameter into the keystream generator of the smart meter for pseudo-random expansion to obtain the dynamic filling sequence of the smart meter includes: The feature fingerprint is written into the input buffer of the key stream generator in byte order, and the initial state vector of the key stream generator is set according to the binary length of the feature fingerprint. Perform bit-level permutations on the bytes in the initial state vector to obtain the permuted state bytes; All the permuted state bytes are concatenated into an intermediate extended sequence, and the intermediate extended sequence is cyclically fed back into the feedback register of the key stream generator; The feedback register is triggered to perform a preset number of state updates, and the output bits of the feedback register are extracted during each state update. The output bits are concatenated sequentially until the length of the concatenated sequence is equal to the length of the protocol reserved bits of the primary ciphertext data. Then, the state update is stopped and the dynamic filling sequence of the smart meter is output.
7. A method for secure transmission of electrical energy data in a smart meter according to claim 1, characterized in that, The step of homomorphically encrypting and fusing the random obfuscation sequence between the smart meter and the data concentrator with the scrambled ciphertext data to obtain the target transmission ciphertext of the smart meter includes: Read the random obfuscation sequence agreed upon with the data concentrator from the local secure storage area of the smart meter; The scrambled ciphertext data is decomposed into multiple data blocks by bytes, and the random obfuscation sequence is divided into sequence segments of the same length as the number of data blocks. The data block and the corresponding sequence segment are XORed and fused bitwise to obtain the fused sub-block of the data block; The fusion sub-blocks are sequentially reassembled and concatenated to obtain the intermediate fusion ciphertext of the smart meter; The intermediate fused ciphertext is byte-rearranged and encapsulated to obtain the target transmission ciphertext of the smart meter.
8. A method for secure transmission of electrical data in a smart meter according to claim 1, characterized in that, The step of sending the target transmission ciphertext to the data concentrator via the power line carrier communication interface of the smart meter, and clearing the dynamic session key, the dynamic padding sequence, and the random obfuscation sequence after transmission, includes: According to the communication protocol of the power line carrier communication interface of the smart meter, the target transmission ciphertext is adapted and encapsulated to obtain the data frame to be sent by the smart meter. Based on the physical layer communication parameters of the power line carrier communication interface, the data frame to be transmitted is subjected to orthogonal frequency division multiplexing modulation to obtain the modulation carrier signal of the smart meter. The modulated carrier signal is sent to the data concentrator via the power line carrier communication interface; After receiving the transmission confirmation response returned by the data concentrator, the smart meter's secure storage area erase command is triggered to overwrite and clear the dynamic session key, the dynamic padding sequence, and the random obfuscation sequence.
9. A secure power data transmission system for smart meters, characterized in that, include: A processor and a memory, the memory storing computer program instructions that, when executed by the processor, implement the steps of a method for secure transmission of electrical energy data for a smart meter according to any one of claims 1-8.