A power distribution side power data security protection method

CN122601326APending Publication Date: 2026-08-18NORTH CHINA BRANCH OF STATE GRID CORPORATION OF CHINA +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610861288.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-15
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

[0003]现有配电侧电力数据的安全保护方案存在诸多突出缺陷:(1)配电终端普遍存在算力受限、存储资源匮乏、能耗约束严格等硬件瓶颈,传统国密组合方案计算开销较大,通用关联数据认证加密(Authenticated Encryption with Associated Data,AEAD)算法无法直接适配电力终端应用场景;(2)传统的密钥生成与完整性校验易遭受“合法格式篡改”攻击,即数据格式符合规范但数值违背电力物理约束条件;(3)传统公钥基础设施(PublicKeyInfrastructure,PKI)证书体系存在证书生成、更新、吊销流程复杂、运维成本高昂等问题,难以适配百万级终端的规模化接入需求

Benefits of technology

在本申请实施例所提供的配电侧电力数据的安全保护方法中,配电终端首先按照数据敏感等级对获取的配电侧电力数据进行分级,得到不同级别的电力数据;然后基于配电终端的根密钥和设备唯一标识,以及当前电力特征向量,生成动态会话密钥;再基于动态会话密钥,对不同级别的电力数据采用对应级别的安全策略进行分级保护处理,得到安全数据,并基于安全数据中包含的密文数据的哈希值、设备唯一标识、时间戳以及会话序号,生成第一完整性校验值;最后将安全数据按规约报文结构进行重组,并将第一完整性校验值嵌入至对应扩展位置,得到安全报文,以及将安全报文发送至配电主站,以使配电主站在确定安全报文的完整性校验和电力物理约束校验通过后,进行数据存储。这样,通过对不同级别的电力数据采用对应级别的安全策略进行分级保护处理,避免了“一刀切”式加密带来的巨大计算与通信开销,适配了配电终端算力、存储资源受限的客观条件,在保证安全强度的同时降低终端计算与存储开销;并且采用结合根密钥和设备唯一标识与实时电力特征向量生成的“动态会话密钥”,避免了固定密钥带来的仿冒与破解风险,有效抵御了因固定密钥泄露导致的长期安全风险和重放攻击;另外,将安全报文发送至配电主站,以使配电主站在确定安全报文的完整性校验和电力物理约束校验通过后,进行数据存储,配电主站不仅进行密码学层面的完整性验签,还创新性地引入电力物理约束校验,使得配电主站能够识别出那些即使通信格式正确、密码学校验通过,但数值违背电网基本物理规律的“合法格式非法数值”高级隐蔽攻击。综上实现了在配电终端侧对电力数据从产生到送出的安全防护,在降低硬件资源开销的同时,抵御数据篡改、窃听、重放及隐蔽攻击,提升了配电系统安全稳定运行水平。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122601326A_ABST
    Figure CN122601326A_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of power distribution side electric power data security protection method, it is related to power system security protection technical field, to reduce hardware resource overhead while, resist attack.Power distribution terminal is classified to the power distribution side electric power data obtained according to data sensitivity level, and the electric power data of different levels is obtained;Based on the root key and the equipment unique identification of power distribution terminal, and current power feature vector, generate dynamic session key;Based on dynamic session key, the security policy of corresponding level is used to the classified protection processing of different level electric power data, and security data is obtained, and based on the hash value of ciphertext data, equipment unique identification, time stamp and session serial number, generate first integrity check value;Based on security data and first integrity check value, generate security message, and send security message to power distribution master station, so that power distribution master station carries out data storage after determining that the integrity check of security message and power physical constraint check pass.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power system security protection technology, and in particular to a method for the security protection of power data on the distribution side. Background Technology

[0002] With the continuous advancement of new power system construction, the distribution Internet of Things (IoT) has entered a stage of large-scale deployment. The number of distribution terminals, such as smart meters and various field sensing sensors, is experiencing explosive growth, and the flexible and diverse access methods of these devices are leading to a dynamic and ever-changing structure and boundary of the distribution network, significantly increasing data security risks. Distribution-side power data serves as the core basis for power system dispatching decisions, equipment operation and maintenance management, and electricity billing settlement. The leakage of its confidentiality or the breach of its integrity directly threatens the stable operation of the power grid. Therefore, data security protection has become a critical requirement for the construction of new power systems.

[0003] The existing power data security protection schemes on the distribution side have many prominent defects: (1) Distribution terminals generally have hardware bottlenecks such as limited computing power, scarce storage resources, and strict energy consumption constraints. The traditional national cryptographic combination scheme has a large computational overhead, and the general Authenticated Encryption with Associated Data (AEAD) algorithm cannot be directly adapted to the power terminal application scenario; (2) Traditional key generation and integrity verification are easily subjected to "legitimate format tampering" attacks, that is, the data format conforms to the standard but the value violates the power physical constraints; (3) The traditional Public Key Infrastructure (PKI) certificate system has problems such as complex certificate generation, update and revocation processes and high operation and maintenance costs, which are difficult to adapt to the large-scale access needs of millions of terminals. Summary of the Invention

[0004] This application provides a method for protecting the security of power data on the distribution side, which reduces hardware resource consumption while resisting data tampering, eavesdropping, replay and covert attacks, thereby improving the safe and stable operation of the power distribution system.

[0005] In a first aspect, embodiments of this application provide a method for the security protection of power data on the distribution side, applied to a distribution terminal, the method comprising: The acquired power distribution data is classified according to its sensitivity level to obtain different levels of power data. A dynamic session key is generated based on the root key and unique identifier of the distribution terminal, as well as the current power feature vector. The current power feature vector is obtained based on the operation data of the distribution equipment in the power distribution side data. Based on dynamic session keys, different levels of power data are protected by corresponding security policies to obtain secure data. Based on the hash value of the encrypted data, the unique device identifier, the timestamp, and the session sequence number contained in the secure data, a first integrity verification value is generated. Among the various security policies, the most complex security policy is the lightweight SM4 algorithm. The security data is reassembled according to the protocol message structure, and the first integrity check value is embedded into the corresponding extension position to obtain the security message. The security message is then sent to the distribution master station so that the distribution master station can store the data after confirming that the integrity check and power physical constraint check of the security message have passed.

[0006] Secondly, embodiments of this application provide a method for the security protection of power data on the distribution side, applied to a distribution master station, the method comprising: The system receives security messages sent by the power distribution terminal. These security messages are generated by the power distribution terminal reassembling security data according to the protocol message structure and embedding the first integrity check value into the corresponding extension location. The security data is obtained by the power distribution terminal using a dynamic session key and applying corresponding security strategies to classify and protect different levels of power data. The most complex security strategy among these strategies is the lightweight SM4 algorithm. Different levels of power data are obtained by the power distribution terminal classifying the acquired power distribution data according to its data sensitivity level. The first integrity check value is generated by the power distribution terminal based on the hash value of the encrypted data contained in the security data, the unique identifier of the terminal device, the timestamp, and the session sequence number. The dynamic session key is generated by the power distribution terminal based on its root key, the unique identifier of the device, and the current power feature vector. The current power feature vector is obtained by the power distribution terminal based on the power distribution equipment operation data in the power distribution data. Based on the encrypted data, unique device identifier, timestamp, session sequence number, and dynamic session key in the security message, a second integrity check value is generated, and the first integrity check value and the second integrity check value are compared to determine the integrity check result. When the integrity verification result passes, based on the dynamic session key, the power data of different levels is decrypted in a hierarchical manner using the corresponding decryption strategy to obtain plaintext data. Then, based on the preset power physical constraint verification rules, the plaintext data is verified for power physical constraints to obtain the power physical constraint verification result. When the power physical constraint verification result is passed, the plaintext data is stored.

[0007] Thirdly, this application also provides a security protection device for power distribution side data, applied to a power distribution terminal, the device comprising: The processing module is used to classify the acquired power distribution data according to the data sensitivity level to obtain power data of different levels; The first generation module is used to generate a dynamic session key based on the root key and unique identifier of the power distribution terminal, as well as the current power feature vector. The current power feature vector is obtained based on the power distribution equipment operation data in the power distribution side power data. The second generation module is used to perform hierarchical protection processing on power data of different levels based on dynamic session keys and corresponding security policies to obtain secure data. Based on the hash value of the encrypted data, the unique device identifier, the timestamp, and the session sequence number contained in the secure data, the first integrity verification value is generated. Among the various security policies, the most complex security policy is the lightweight SM4 algorithm. The sending module is used to reassemble the security data according to the protocol message structure, embed the first integrity check value into the corresponding extension position to obtain the security message, and send the security message to the distribution master station so that the distribution master station can store the data after confirming that the integrity check and power physical constraint check of the security message have passed.

[0008] In an optional embodiment, when the acquired power distribution data is classified according to its data sensitivity level to obtain power data of different levels, the processing module is further configured to: Based on the control attribute score, impact range score, and real-time score of each power data contained in the power distribution side power data, the data sensitivity level of each power data is determined. Among them, the control attribute score is used to characterize whether the corresponding power data contains control attributes of the grid operation status, the impact range score is used to characterize the grid range affected by the leakage or tampering of the corresponding power data, and the real-time score is used to characterize the timeliness requirements of the corresponding power data. According to their respective data sensitivity levels, the power data are classified into different levels, including Level 1, Level 2, and Level 3 power data. The sensitivity level of Level 1 power data is higher than that of Level 2 power data, and the sensitivity level of Level 2 power data is higher than that of Level 3 power data.

[0009] In an optional embodiment, the first generation module is further configured to: When a key update condition is triggered, the dynamic session key is updated, wherein the key update condition includes at least one of the following: The dynamic session key has not been updated for a preset duration threshold; The dynamic session key has been used up to a preset threshold number of times. The rate of change of the current power feature vector is greater than or equal to the preset feature change rate threshold.

[0010] In an optional embodiment, based on a dynamic session key, different levels of power data are subjected to graded protection processing using corresponding security strategies. When obtaining secure data, the second generation module is further configured to: The first lightweight SM4 algorithm is used to encrypt the first level power data to obtain the first ciphertext data. The first lightweight SM4 algorithm replaces the 8×8 lookup table S box with a 4×4 lightweight S box constructed based on the composite field GF(((2²)²)²), and adds a bit-level permutation layer to the output of the 4×4 lightweight S box. The second-level power data is encrypted using the second lightweight SM4 algorithm to obtain the second ciphertext data, and / or the second-level power data is hashed using the SM3 algorithm to obtain the second-level power data with hash tags. The number of iterations of the second lightweight SM4 algorithm is less than the number of iterations of the first lightweight SM4 algorithm. The first encrypted data, the second encrypted data, or the second-level power data and the third-level power data with hash tags are used as secure data.

[0011] In an optional embodiment, the second generation module is further configured to: The first-level power data, or the set of first-level power data and second-level power data, are grouped to obtain data groups; For each data group, perform the following operations in sequence: use the corresponding lightweight SM4 algorithm to encrypt the current data group to obtain the current ciphertext group, and based on the previous intermediate state value, use the SM3 algorithm to compress the current ciphertext group to obtain the current intermediate state value. Each ciphertext group will be used as the ciphertext data contained in the secure data, and the final intermediate state value corresponding to the last data group will be used as the hash value of the ciphertext data.

[0012] In an optional embodiment, when sending a security message to the distribution master station, the sending module is further configured to: The first short check value is obtained by truncating the first integrity check value to the first N bits, where N is an integer greater than 1; The device's unique identifier, core abbreviation, and first short check value are combined to form lightweight pre-verification information, which is then sent to the power distribution master station. The core abbreviation is obtained by feature extraction from the first-level power data. Upon receiving the first confirmation message from the distribution master station, a security message is sent to the distribution master station. The first confirmation message indicates that the distribution master station allows the sending of the security message.

[0013] Fourthly, embodiments of this application also provide a security protection device for power distribution side data, applied to a power distribution terminal, the device comprising: The receiving module is used to receive security messages sent by the power distribution terminal. The security message is obtained by the power distribution terminal reassembling security data according to the protocol message structure and embedding the first integrity check value into the corresponding extension position. The security data is obtained by the power distribution terminal using a dynamic session key to perform hierarchical protection processing on power data of different levels using corresponding security policies. The most complex security policy among all security policies is the lightweight SM4 algorithm. The power data of different levels is obtained by the power distribution terminal classifying the acquired power data of the power distribution side according to the data sensitivity level. The first integrity check value is generated by the power distribution terminal based on the hash value of the ciphertext data contained in the security data, the unique identifier of the terminal device, the timestamp, and the session sequence number. The dynamic session key is generated by the power distribution terminal based on its root key, the unique identifier of the device, and the current power feature vector. The current power feature vector is obtained by the power distribution terminal based on the power distribution equipment operation data in the power distribution side data. The first verification module is used to generate a second integrity verification value based on the encrypted data, device unique identifier, timestamp, session sequence number, and dynamic session key in the security message, and compare the first integrity verification value and the second integrity verification value to determine the integrity verification result. The second verification module is used to perform hierarchical decryption processing on power data of different levels based on the dynamic session key when the integrity verification result passes, using the corresponding level decryption strategy to obtain plaintext data, and to perform power physical constraint verification on the plaintext data based on the preset power physical constraint verification rules to obtain the power physical constraint verification result. The storage module is used to store plaintext data when the power physical constraint verification result passes.

[0014] In an optional embodiment, the device further includes a lightweight pre-verification module, which is used for: Receive lightweight pre-verification information sent by the power distribution terminal. The lightweight pre-verification information includes: unique device identifier and core abbreviation. When it is determined that the device's unique identifier belongs to the device whitelist and the core abbreviation meets the rationality conditions, a first confirmation message is generated and sent to the power distribution terminal. The first confirmation message indicates that the power distribution terminal is allowed to send a security message.

[0015] In an optional embodiment, the lightweight pre-verification information further includes: a first short check value. Before generating the second integrity check value based on the ciphertext data, device unique identifier, timestamp, session sequence number, and dynamic session key in the secure message, the lightweight pre-verification module is further configured to: Extract the first integrity check value contained in the security message, and truncate the first integrity check value to the first N bits to obtain the second short check value, where N is an integer greater than 1; Compare the first shortest check value and the second shortest check value to determine the shortest check value verification result.

[0016] In an optional embodiment, when performing electrical physical constraint verification on plaintext data and obtaining the electrical physical constraint verification result, the second verification module is further configured to: If it is determined that the load change rate contained in the plaintext data is less than the preset load change rate threshold, and the physical relationship between the voltage and current contained in the plaintext data and the theoretical power value is within the error range, then the power physical constraint verification result is determined to be passed.

[0017] Fifthly, embodiments of this application also provide an electronic device, including: Processor; and Stored program memory, The program includes instructions that, when executed by a processor, cause the processor to perform the steps of the method for secure protection of power data on the distribution side as described in either the first or second aspect.

[0018] In a sixth aspect, embodiments of this application also provide a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to perform the steps of the security protection method for power distribution side data as described in either the first or second aspect.

[0019] In a seventh aspect, this application provides a computer program product that, when invoked by a computer, causes the computer to perform the steps of the power distribution side power data security protection method as described in either the first or second aspect.

[0020] The beneficial effects of this application are as follows: In the power distribution data security protection method provided in this application embodiment, the power distribution terminal first classifies the acquired power distribution data according to the data sensitivity level to obtain power data of different levels; then, based on the root key and unique device identifier of the power distribution terminal, and the current power feature vector, a dynamic session key is generated; then, based on the dynamic session key, the power data of different levels is subjected to hierarchical protection processing using the corresponding level of security strategy to obtain secure data, and a first integrity verification value is generated based on the hash value of the encrypted data, the unique device identifier, the timestamp, and the session sequence number contained in the secure data; finally, the secure data is reassembled according to the protocol message structure, and the first integrity verification value is embedded into the corresponding extension position to obtain a secure message, and the secure message is sent to the power distribution master station so that the power distribution master station stores the data after confirming that the integrity verification and power physical constraint verification of the secure message have passed. In this way, by adopting corresponding security strategies for different levels of power data for hierarchical protection, the huge computational and communication overhead caused by "one-size-fits-all" encryption is avoided. This approach adapts to the objective conditions of limited computing power and storage resources in distribution terminals, reducing terminal computing and storage overhead while ensuring security strength. Furthermore, the use of a "dynamic session key" generated by combining the root key, the device's unique identifier, and real-time power feature vectors avoids the risks of impersonation and cracking associated with fixed keys, effectively resisting long-term security risks and replay attacks caused by fixed key leaks. In addition, security messages are sent to the distribution master station, which then stores the data after verifying the integrity and power physical constraint of the security messages. The distribution master station not only performs cryptographic integrity verification but also innovatively introduces power physical constraint verification, enabling it to identify advanced covert attacks that use "legitimate format but illegal values" even if the communication format is correct and the cryptographic verification passes, but the values ​​violate the basic physical laws of the power grid. In summary, this achieves security protection for power data from generation to transmission at the power distribution terminal, reducing hardware resource consumption while resisting data tampering, eavesdropping, replay and covert attacks, thus improving the safe and stable operation level of the power distribution system.

[0021] Furthermore, other features and advantages of this application will be set forth in the following description and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described herein are used to provide a further understanding of this application, constitute a part of this application, and do not constitute an improper limitation of this application. In the accompanying drawings: Figure 1 This is a schematic diagram of an optional system architecture applicable to the embodiments of this application.

[0023] Figure 2 This is a schematic diagram illustrating the implementation process of a method for secure protection of power data on the distribution side, provided in an embodiment of this application.

[0024] Figure 3 This is a schematic diagram of another implementation process of a method for the security protection of power data on the distribution side provided in this application.

[0025] Figure 4 This is a signaling interaction diagram of a method for secure protection of power data on the distribution side provided in an embodiment of this application.

[0026] Figure 5 This is a schematic diagram of the structure of a power distribution side power data security protection device provided in an embodiment of this application.

[0027] Figure 6 This is another structural schematic diagram of a power distribution side power data security protection device provided in an embodiment of this application.

[0028] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0029] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.

[0030] It should be understood that the steps described in the method embodiments of this application may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this application is not limited in this respect.

[0031] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc., mentioned in this application are used only to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.

[0032] It should be noted that the terms "a" and "a plurality of" used in this application are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0033] The names of the messages or information exchanged between multiple devices in the embodiments of this application are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0034] The design concept of the embodiments of this application is briefly introduced below: With the continuous advancement of new power system construction, the distribution Internet of Things (IoT) has entered a stage of large-scale deployment. The number of distribution terminals, such as smart meters and various field sensing sensors, is experiencing explosive growth, and the flexible and diverse access methods of these devices are leading to a dynamic and ever-changing structure and boundary of the distribution network, significantly increasing data security risks. Distribution-side power data serves as the core basis for power system dispatching decisions, equipment operation and maintenance management, and electricity billing settlement. The leakage of its confidentiality or the breach of its integrity directly threatens the stable operation of the power grid. Therefore, data security protection has become a critical requirement for the construction of new power systems.

[0035] The existing power data security protection schemes on the distribution side have many prominent defects: (1) They lack integrated analysis of multi-dimensional information such as the operating status of power distribution equipment, communication interaction process, and physical environment parameters, making it difficult to resist highly concealed data tampering attacks; (2) Power distribution terminals generally have hardware bottlenecks such as limited computing power, scarce storage resources, and strict energy consumption constraints. The traditional national cryptographic combination scheme has a large computational overhead, and the general AEAD algorithm cannot be directly adapted to the power terminal application scenario; (3) Traditional key generation and integrity verification are easily subjected to "legitimate format tampering" attacks, that is, the data format conforms to the standard but the value violates the physical constraints of the power; (4) The traditional PKI certificate system has problems such as complex certificate generation, update, and revocation processes and high operation and maintenance costs, making it difficult to adapt to the large-scale access needs of millions of terminals.

[0036] In view of this, this application provides a method for secure protection of power distribution data. The power distribution terminal first classifies the acquired power distribution data according to its data sensitivity level, obtaining power data of different levels. Then, based on the root key and unique device identifier of the power distribution terminal, and the current power feature vector, a dynamic session key is generated, wherein the current power feature vector is obtained based on the power distribution equipment operation data in the power distribution data. Next, based on the dynamic session key, corresponding security strategies are applied to the different levels of power data for graded protection processing, resulting in secure data. A first integrity verification value is generated based on the hash value of the encrypted data, the unique device identifier, the timestamp, and the session sequence number contained in the secure data. The most complex security strategy among all security strategies is the lightweight SM4 algorithm. Finally, the secure data is reassembled according to the protocol message structure, and the first integrity verification value is embedded into the protocol message structure. At the corresponding extended location, a security message is obtained and sent to the distribution master station. The distribution master station stores the data after confirming that the security message's integrity and power physical constraint verifications have passed. Then, the distribution master station receives the security message from the distribution terminal. First, based on the encrypted data, unique device identifier, timestamp, session sequence number, and dynamic session key in the security message, it generates a second integrity verification value and compares the first and second integrity verification values ​​to determine the integrity verification result. Then, when the integrity verification result passes, based on the dynamic session key, it performs hierarchical decryption processing on different levels of power data using corresponding decryption strategies to obtain plaintext data. Based on preset power physical constraint verification rules, it performs power physical constraint verification on the plaintext data to obtain the power physical constraint verification result. Finally, when the power physical constraint verification result passes, the plaintext data is stored. In this way, a complete process from data classification, key management, security processing, message encapsulation and transmission, and data storage is constructed, realizing the security protection of power data from generation to transmission on the distribution terminal side, and the security protection of power data reception, verification and storage on the distribution master station side. While reducing hardware resource consumption, it resists data tampering, eavesdropping, replay and covert attacks, and improves the safe and stable operation level of the distribution system. Specifically, the following beneficial effects are included: (1) By adopting corresponding security strategies for graded protection processing of power data of different levels, the huge computing and communication overhead caused by "one-size-fits-all" encryption is avoided, which is adapted to the objective conditions of limited computing power and storage resources of distribution terminals, and reduces terminal computing and storage overhead while ensuring security strength. (2) The use of "dynamic session key" generated by combining root key and device unique identifier with real-time power feature vector avoids the imitation and cracking risks caused by fixed key, and effectively resists long-term security risks and replay attacks caused by fixed key leakage.(3) The first integrity verification value is generated by using the hash value of the encrypted data, the unique identifier of the device, the timestamp, and the session sequence number. This verification value is bound to the security message to effectively prevent the verification value from being tampered with, forged, or replaced, and to ensure the integrity, authenticity, and anti-attack capability of the data. (4) The security data is "reassembled according to the protocol message structure" to ensure that the original message frame structure is not destroyed while ensuring data security, and to achieve multi-protocol compatibility. This allows the application to be seamlessly embedded into the existing power distribution system, making it easy to deploy and compatible. (5) The power distribution master station not only performs cryptographic integrity verification, but also innovatively introduces power physical constraint verification, which enables the power distribution master station to identify advanced covert attacks that are "legal format but illegal value" even if the communication format is correct and the cryptographic verification passes, but the value violates the basic physical laws of the power grid (such as power imbalance). Furthermore, integrity verification is performed before decryption to avoid invalid decryption operations from the source, save the master station's computing power resources, and resist computing power exhaustion type DoS attacks.

[0037] In particular, the preferred embodiments of this application will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments of this application and the features in the embodiments can be combined with each other without conflict.

[0038] See Figure 1 As shown, it is a schematic diagram of an optional system architecture applicable to the embodiments of this application. The system architecture may include: power distribution terminal 101, power distribution master station 102 and power distribution equipment 103.

[0039] This application embodiment does not impose any limitation on the number of communication devices involved in the above system architecture. For example, the above system architecture may include more communication devices, or it may include fewer communication devices, or it may also include other network devices. Figure 1 As shown, only the power distribution terminal 101, power distribution master station 102 and power distribution equipment 103 are described as examples. The following is a brief introduction to the above communication equipment and their respective functions.

[0040] For example, the distribution terminal 101 is an intelligent data acquisition or control unit installed next to or integrated into the power distribution equipment 103. Distribution terminals include: data transfer units (DTUs), feeder terminal units (FTUs), and transformer terminal units (TTUs), etc. One distribution terminal typically collects and manages data from one or more power distribution equipment 103s within the distribution area. For example, the distribution terminal 101 is installed at key nodes in the distribution area, such as high-voltage lines, distribution transformers, intelligent switches, and data acquisition terminals.

[0041] Distribution master station 102 is a distribution automation master station system or distribution Internet of Things platform, deployed in the dispatch center or data center, used to receive, parse and verify terminal messages.

[0042] Power distribution equipment 103 includes primary equipment such as transformers, switches, circuit breakers, and instrument transformers.

[0043] The following describes the method for protecting power distribution data on the distribution side provided by the exemplary embodiments of this application, in conjunction with the above-described system architecture and with reference to the accompanying drawings. It should be noted that the above-described system architecture is only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.

[0044] See Figure 2 The diagram shown illustrates the implementation flow of a power distribution side power data security protection method provided in this application embodiment. The method is described here using power distribution equipment as the implementing entity. The specific implementation flow of this method is as follows: S20: Classify the acquired power distribution data according to the data sensitivity level to obtain power data of different levels.

[0045] In this embodiment of the application, before classifying the acquired power distribution data according to the data sensitivity level to obtain power data of different levels, multi-source power distribution data acquisition and preprocessing are performed to provide reliable data support for subsequent encryption protection.

[0046] Optionally, in this embodiment of the application, a possible implementation method for collecting and preprocessing multi-source power distribution side data is provided, specifically including the following operations: SA1: Collects power distribution equipment operation data, terminal communication data, and transformer area environmental data to obtain power distribution side data.

[0047] In this embodiment of the application, the power distribution side data includes three types of data: power distribution equipment operation data, terminal communication data, and transformer area environmental data.

[0048] Among them, the power distribution equipment operation data refers to the inherent operating status parameters of the monitored power distribution equipment, including but not limited to: line load, voltage, current, equipment temperature, and switch on / off status; the terminal communication data refers to the communication behavior data generated by the power distribution terminal itself when interacting with the power distribution master station or other equipment, including but not limited to: communication protocol type, data transmission timing, link connection status, and port information; the transformer area environmental data refers to the environmental parameters of the external transformer area where the power distribution equipment and the power distribution terminal are located, including but not limited to: transformer area temperature and humidity, equipment vibration parameters, and environmental interference intensity.

[0049] Optionally, in this embodiment of the application, when collecting power data from the distribution side, the corresponding power data is collected according to the frequency collection mode corresponding to the data sensitivity level, and stored in the terminal temporary buffer according to the type. For example, the first-level power data (core sensitive data) adopts the high-frequency collection mode, the second-level power data (general sensitive data) adopts the medium-frequency collection mode, and the third-level power data (non-sensitive data) adopts the low-frequency collection mode.

[0050] SA2: Cleans and denoises the power data on the distribution side.

[0051] In this embodiment, an outlier detection algorithm is used to identify and remove noise points and erroneous values ​​in the power distribution data in batches, eliminating invalid data caused by equipment failure and communication interference. Furthermore, for sensor data with large fluctuations such as voltage, current, and equipment temperature, the Median filtering algorithm is used for smoothing to achieve data noise reduction and improve data stability.

[0052] If the filter window size is set to 5, the expression for the filtered data value is as follows:

[0053] Among them, x i This is the currently collected data value. x i-1 The data value collected at the previous moment. x i-2 The data value collected at the previous time step. x i+1 This will be the data value collected at the next moment. x i-2 This represents the data value collected at the next next time step.

[0054] Optionally, in this embodiment of the application, a possible implementation method is provided for classifying the acquired power distribution data according to the data sensitivity level to obtain power data of different levels, specifically including the following operations: S200: Based on the control attribute score, impact range score, and real-time score of each power data included in the distribution side power data, determine the data sensitivity level of each power data.

[0055] Among them, the control attribute score is used to characterize whether the corresponding power data contains control attributes of the power grid operation status. For example, control attributes such as Automatic Generation Control (AGC) control commands, remote control opening and closing commands, and protection setting sheets have high scores, while control attributes such as environmental temperature and humidity monitoring and daily power consumption statistics have low scores. The impact range score is used to characterize the power grid range affected by the leakage or tampering of the corresponding power data. For example, the impact range score of the main transformer fault alarm in the distribution area and the main transformer side data of the substation (affecting the safety of the entire distribution area or multiple lines) has high scores, while the impact range score of data from a single smart meter terminal collection point has low scores. The real-time score is used to characterize the timeliness requirements of the corresponding power data (i.e., the allowable delay time from generation to completion of processing). For example, the real-time score of relay protection action information and sudden fault alarm (requiring millisecond-level response) has high scores, while the real-time score of historical load curves and equipment asset ledger updates (allowing minute-level or hour-level delays) has low scores.

[0056] In this embodiment of the application, the control attribute score, influence range score and real-time score of each power data are weighted and summed to obtain the sensitivity comprehensive score of each power data, and the data sensitivity level of each power data is determined based on the score range to which the sensitivity comprehensive score of each power data belongs.

[0057] Optionally, in this embodiment of the application, the expression for the sensitivity comprehensive score is as follows:

[0058] in, C To control attribute scores, I To determine the range of influence scores, T For real-time scores, ω 1. ω 2 and ω 3 is the weighting coefficient. ω 1+ ω 2+ ω 2 = 1.

[0059] In this way, a quantifiable scoring model is defined, transforming the determination of data sensitivity levels from a subjective and empirical judgment to an objective and automated calculation process. This improves the accuracy and consistency of data sensitivity level determination. Furthermore, the three scoring dimensions (control attributes, scope of influence, and real-time performance) directly correspond to the core safety concerns of power production. This scoring rule ensures that the highest level of security measures (such as strong encryption) are automatically applied to the key data that has the greatest impact on the stable operation of the power grid and has the highest real-time requirements, thus achieving precise allocation of security resources.

[0060] Optionally, in this embodiment of the application, for power data with a fixed data sensitivity level (such as control commands, protocol frame headers, etc.), the data sensitivity level of such power data with a fixed data sensitivity level is determined during system initialization, so that the data sensitivity level of such power data with a fixed data sensitivity level does not need to be repeatedly confirmed in the future; for power data with a non-fixed data sensitivity level (such as load, voltage, etc.), the data sensitivity level of such power data with a non-fixed data sensitivity level is determined in real time after each data acquisition, so as to achieve dynamic and accurate adaptive sensitivity level marking.

[0061] S201: According to the data sensitivity level of each power data, classify each power data into different levels of power data.

[0062] The different levels of power data include: Level 1 power data, Level 2 power data, and Level 3 power data. The sensitivity level of Level 1 power data is higher than that of Level 2 power data, and the sensitivity level of Level 2 power data is higher than that of Level 3 power data.

[0063] In this application embodiment, the data sensitivity level is divided into a first sensitivity level, a second sensitivity level and a third sensitivity level. The first sensitivity level is the core sensitivity level, the second sensitivity level is the general sensitivity level, and the third sensitivity level is the non-sensitive level. The first sensitivity level is higher than the second sensitivity level, and the second sensitivity level is higher than the third sensitivity level.

[0064] For example, power data of the first sensitivity level includes: equipment control commands, load peak data, fault alarm information, etc.; power data of the second sensitivity level includes: equipment normal operating parameters, average load data of the transformer area, etc.; and power data of the third sensitivity level includes: communication protocol header, equipment fixed identifier, message frame sequence number, etc.

[0065] Furthermore, in this embodiment, after obtaining power data at different levels, the first-level power data is processed. The processed data retains its data characteristics, improving the consistency and adaptability of subsequent algorithm processing, and providing standardized, high-quality input for subsequent lightweight SM4 encryption and integrity verification. Specifically, for continuous numerical data (such as load peak, voltage, current, etc.) in the first-level power data, min-max normalization is used to map it to the [0,1] interval to improve the consistency of subsequent encryption algorithms; for discrete enumeration data (such as control commands, fault alarm codes, etc.) in the first-level power data, its original encoding is retained or integerization is performed using ordered mapping (such as 0,1,2,…).

[0066] Optionally, in this embodiment of the application, the expression for the normalized data value is as follows:

[0067] in, x The original value, x min The minimum value of this type of data. x max This represents the maximum value of this type of data.

[0068] S21: Generate a dynamic session key based on the root key and unique identifier of the distribution terminal, as well as the current power feature vector.

[0069] The current power feature vector is derived from the operating data of power distribution equipment in the power distribution side data. The current power feature vector includes voltage fluctuations, load change rate, current phase, etc., providing information on operational unpredictability.

[0070] In this embodiment, an HMAC key derivation function based on SM3 is used to nonlinearly fuse the root key and unique device identifier of the distribution terminal with the current power feature vector to obtain a dynamic session key. Specifically, the logical expression for generating the dynamic session key is as follows:

[0071] in, KDF SM3 This is an HMAC key derivation function based on SM3; MK The root key is stored securely in the hardware to ensure the legitimate identity of the device; ID A unique identifier for the power distribution terminal equipment; RTS ( t ) represents the current business feature vector.

[0072] Optionally, in this embodiment of the application, when the power distribution terminal leaves the factory, the unique root key of the SM4 algorithm is written into the terminal's built-in security chip through hardware burning. The root key can only be called inside the security chip and does not support external reading or export, thus ensuring the security of the root key at the hardware level. The security chip also records the root key's generation time, unique device identifier, and other related information to achieve the binding of the root key with the device.

[0073] Optionally, in this embodiment of the application, when the key update condition is triggered, the dynamic session key is updated to improve the key dynamism and security. The key update condition includes at least one of the following: (1) the unupdated duration of the dynamic session key reaches a preset duration threshold; (2) the number of times the dynamic session key is used reaches a preset number of times threshold; (3) the rate of change of the power feature corresponding to the current power feature vector is greater than or equal to a preset feature change rate threshold.

[0074] In this embodiment of the application, the relative rate of change of each feature value in the current power feature vector compared to each feature value in the previous power feature vector is calculated. The highest relative rate of change among all relative rates of change is taken as the power feature change rate corresponding to the current power feature vector, or the average or weighted average of all relative rates of change is taken as the power feature change rate corresponding to the current power feature vector.

[0075] The formula for calculating the relative rate of change of each eigenvalue is as follows:

[0076] in, F t This represents a one-dimensional business feature value in the current power feature vector. F t-1 This represents the corresponding one-dimensional business feature value in the power feature vector at the previous time step.

[0077] In this way, by triggering session key updates under multiple conditions, the effective lifespan of the session key is ensured to be short and unpredictable. Even if a session key is cracked in a short period, its impact is limited to the data transmitted within the validity period of that session key, greatly limiting the attack window and improving the forward security of the system. In particular, using the rate of change of power characteristics as the trigger condition links the session key update to the actual physical operating state of the power grid (e.g., load surges), enhancing the unpredictability of the session key update. This is because attackers find it difficult to accurately simulate or predict the real dynamics of the power grid, thus more effectively defending against replay or prediction attacks based on session key derivation.

[0078] S22: Based on the dynamic session key, the power data of different levels is subjected to hierarchical protection processing using the corresponding security policy to obtain secure data. Based on the hash value of the encrypted data, the unique device identifier, the timestamp, and the session sequence number contained in the secure data, the first integrity verification value is generated.

[0079] Among all security strategies, the most complex is the lightweight SM4 algorithm. The security strategies include: the first lightweight SM4 algorithm, the second lightweight SM4 algorithm, the SM3 algorithm, and the plaintext preservation strategy. The first lightweight SM4 algorithm has the highest complexity.

[0080] Optionally, in this embodiment of the application, a possible implementation method is provided for hierarchical protection processing of power data at different levels based on dynamic session keys and corresponding security strategies to obtain secure data, specifically including the following operations: S210: The first lightweight SM4 algorithm is used to encrypt the first-level power data to obtain the first ciphertext data.

[0081] Among them, the first lightweight SM4 algorithm replaces the 8×8 lookup table S-box with a 4×4 lightweight S-box constructed based on the composite field GF(((2²)²)²), and adds a bit-level permutation layer on the output of the 4×4 lightweight S-box.

[0082] In this embodiment, the first lightweight SM4 algorithm is based on the national standard SM4 algorithm, maintaining the 32-round standard security iteration framework, 128-bit key, and block length to ensure that the basic security capability is not reduced. Then, the traditional 8×8 lookup table S-box is replaced by a lightweight nested network composed of multiple 4×4 S-boxes using the composite field GF(((2²)²)²) construction method. Finite field operations are used to replace the lookup table operation, significantly reducing hardware resource consumption and computational latency. In order to compensate for the diffusion loss caused by the lightweight S-box, a bit-level permutation layer based on the GIFT idea is inserted on the output of the 4×4 lightweight S-box. This allows the single-bit change to spread quickly to the entire 128-bit block without increasing hardware resource overhead and latency, improving the algorithm's nonlinearity and resistance to differential / linear attacks, and ensuring that the first lightweight SM4 algorithm still maintains the national standard security strength.

[0083] S211: The second-level power data is encrypted using the second lightweight SM4 algorithm to obtain the second ciphertext data, and / or the second-level power data is hashed using the SM3 algorithm to obtain the hashed second-level power data.

[0084] The second lightweight SM4 algorithm has fewer iterations than the first lightweight SM4 algorithm.

[0085] In this embodiment of the application, the first lightweight SM4 algorithm has 32 iteration rounds, and the second lightweight SM4 algorithm is obtained by reducing the number of rounds based on the first lightweight SM4 algorithm, with 24 iteration rounds.

[0086] Optionally, in this embodiment, the security strategy for the second-level power data is determined based on the current business scenario. Specifically, when the business scenario is a critical control instruction scenario, the second lightweight SM4 algorithm is used to encrypt the second-level power data to obtain second ciphertext data; when the business scenario is a message transmission scenario, SM3 is used to hash the second-level power data to obtain hash-tagged second-level power data.

[0087] S212: Use the first ciphertext data, the second ciphertext data, or the second-level power data and the third-level power data with hash tags as secure data.

[0088] In this embodiment, a plaintext preservation strategy is adopted for the third-level power data, meaning that the third-level power data is not encrypted and is stored directly in plaintext. The first ciphertext data, the second ciphertext data, or the second-level power data with hash tags, and the third-level power data are then aggregated to obtain secure data.

[0089] In this way, differentiated security strategies are provided for data with different sensitivity levels, ranging from "high-strength encryption" to "integrity protection" and then to "no processing." This tiered approach ensures the absolute security of core sensitive data while minimizing the processing overhead for general sensitive and non-sensitive data, optimizing the overall resource utilization of the terminal, avoiding the main station's parsing failure caused by full-message encryption, and reducing encryption computation overhead. Furthermore, even though the "second lightweight SM4 algorithm" used for "general sensitive data" reduces the number of iterations, it is still based on a lightweight improved SM4 framework (such as using a 4×4 lightweight S-box and a bit-level permutation layer), providing confidentiality protection far exceeding that of plaintext transmission under resource-constrained conditions.

[0090] Furthermore, in this embodiment, a ciphertext-driven digest update mechanism is adopted to achieve integrated execution of encryption and integrity verification, thereby obtaining ciphertext data (the ciphertext data is: first ciphertext data, or a set of first ciphertext data and second ciphertext data) and the hash value of the ciphertext data.

[0091] Optionally, in this embodiment of the application, a possible implementation for generating ciphertext data and the hash value of the ciphertext data is provided, specifically including the following operations: S213: Group the first-level power data, or the set of first-level power data and second-level power data, to obtain each data group.

[0092] In this embodiment of the application, the first-level power data, or the set of the first-level power data and the second power data, are grouped according to a group length of 128 bits to obtain each data group.

[0093] S214: For each data group, perform the following operations in sequence: use the corresponding lightweight SM4 algorithm to encrypt the current data group to obtain the current ciphertext group, and based on the previous intermediate state value, use the SM3 algorithm to compress the current ciphertext group to obtain the current intermediate state value.

[0094] In this embodiment, the corresponding lightweight SM4 algorithm is used to encrypt the current data group to obtain the current ciphertext group. If the current data group belongs to the first level of power data, the first lightweight SM4 algorithm is used to encrypt the current data group to obtain the current ciphertext group; if the current data group belongs to the second level of power data, the second lightweight SM4 algorithm is used to encrypt the current data group to obtain the current ciphertext group. When the current data group is the first data group, the previous intermediate state value is the initial vector IV.

[0095] For example, the detailed steps of encrypting the current data group using the first lightweight SM4 algorithm to obtain the current ciphertext group include: generating 32 round keys from the dynamic session key using the SM4 key expansion algorithm, performing 32 rounds of iteration on the current data group, and finally reversing the order of the four final 32-bit words obtained after 32 rounds of iteration to obtain the current ciphertext group. The iteration operation in each round is as follows: Each 8-bit byte is mathematically mapped to the composite field GF(((2^2)^2)^2), and through a series of lightweight operations such as squaring, multiplication, and affine transformation on this field, the equivalent effect of a 4×4 S-box network is achieved, resulting in 32-bit intermediate output data. A fixed bit position rearrangement operation is applied to the 32-bit intermediate data (i.e., the positions of the 32 bits are shuffled according to the pre-designed mapping) to obtain 32-bit data after bit-level permutation. Then, the SM4 standard linear transformation is performed on the 32-bit data after bit-level permutation to obtain the linear transformation result. Finally, the result of the linear transformation is XORed with the wheel key of the current round to obtain the output data of the current round.

[0096] In this way, each ciphertext group output by the SM4 algorithm flows directly into the SM3 compression function in real time through the feedback loop to participate in iterative calculations, without buffering. The ciphertext groups generated by the SM4 algorithm drive the real-time update of intermediate values ​​in SM3, completely eliminating the physical boundary and ciphertext buffering latency between the encryption engine and the hash engine in traditional architectures, truly achieving encryption as authentication. This eliminates the intermediate buffering and latency caused by two sequential operations required in traditional schemes that "encrypt all data first, then calculate the overall hash," and the integrated engine design enables hardware-level resource sharing, further reducing overall computational overhead and energy consumption.

[0097] S215: The obtained ciphertext groups are used as ciphertext data contained in the secure data, and the final intermediate state value corresponding to the last obtained data group is used as the hash value of the ciphertext data.

[0098] In this embodiment of the application, each ciphertext group is obtained as ciphertext data contained in the security data, and the final intermediate state value corresponding to the last data group is used as the hash value of the ciphertext data.

[0099] In this embodiment of the application, when generating the first integrity verification value based on the hash value, device unique identifier, timestamp, and session sequence number of the encrypted data contained in the security data, the hash value, device unique identifier, timestamp, and session sequence number of the encrypted data are concatenated. The concatenated dataset is then input into the SM3 compression function again, and finally a fixed-length hash value is output, which is the first integrity verification value.

[0100] S23: Reassemble the security data according to the protocol message structure, embed the first integrity check value into the corresponding extension position to obtain the security message, and send the security message to the distribution master station so that the distribution master station can store the data after confirming that the integrity check and power physical constraint check of the security message have passed.

[0101] The protocol message structure is one of the mainstream communication protocols such as Power 104, 61850, and DL / T645. The first integrity check value is embedded in the integrated check field within the custom extended field.

[0102] In this embodiment, the first encrypted data, the second encrypted data, or the second-level power data and the third-level power data with hash tags are reassembled according to the protocol message structure, and the first integrity check value is embedded into the corresponding extension position of the message to obtain the encapsulated secure message. The encapsulated secure message is transmitted according to the transmission rules of the original communication protocol. The distribution master station can identify the integrated check field and parse the message through the standardized interface without destroying the standard protocol frame structure.

[0103] Optionally, in this embodiment of the application, before sending the security message to the distribution master station, lightweight pre-verification information can be sent first, so that the distribution master station can perform lightweight pre-verification, improve data verification efficiency, and quickly filter illegal data.

[0104] Optionally, in this embodiment of the application, a possible implementation method for sending security messages to the distribution master station is provided, which specifically includes the following operations: S230: Truncate the first N bits of the first integrity check value to obtain the first short check value.

[0105] Where N is an integer greater than 1.

[0106] For example, N is 32, that is, the first 32 bits of the first integrity check value are truncated to obtain the first short check value.

[0107] S231: The device's unique identifier, core abbreviation, and first short check value are combined to form lightweight pre-verification information, which is then sent to the power distribution master station.

[0108] The core short code is obtained by feature extraction from the first-level power data. It is a short identification information extracted or encoded from the first-level power data according to preset rules. It is used by the main station to quickly verify the rationality and basic legality of the data type without the need for complete decryption or complex hash calculation.

[0109] Optionally, in this embodiment of the application, different encoding methods are used for different types of data in the first-level power data when generating the core abbreviation. Specifically, for continuous data such as voltage, current, and load, they are mapped to interval numbers (such as 0, 1, 2, etc.) according to a preset step size (such as voltage in 10V increments and current in 5A increments) to form a short integer code; for discrete data such as switch status and protection action signals, their original state values ​​(such as 0 / 1, True / False) are directly taken as the abbreviation.

[0110] In this embodiment, a lightweight pre-verification information is composed of a unique device identifier, a core abbreviation, and a first short checksum. This lightweight pre-verification information is then sent to the power distribution master station. After receiving the lightweight pre-verification information, the power distribution master station determines whether the unique device identifier belongs to the device whitelist and whether the core abbreviation meets the rationality conditions. When the power distribution master station determines that the unique device identifier belongs to the device whitelist and the core abbreviation meets the rationality conditions, it generates first confirmation information and sends the first confirmation information to the power distribution terminal.

[0111] S232: When the first confirmation message is received from the distribution master station, a safety message is sent to the distribution master station.

[0112] The first confirmation message indicates that the power distribution master station is authorized to send a security message.

[0113] In this embodiment of the application, when the power distribution terminal receives the first confirmation information returned from the power distribution master station, it sends a security message to the power distribution master station.

[0114] See Figure 3 The diagram shown illustrates another implementation flow of a method for secure protection of power data on the distribution side provided in this application. The implementation process is illustrated below, using the distribution master station as the executing entity. S30: Receives security messages sent by the power distribution terminal.

[0115] In this process, the security message is obtained by the distribution terminal reassembling the security data according to the protocol message structure and embedding the first integrity check value into the corresponding extension position. The security data is obtained by the distribution terminal using a dynamic session key to perform hierarchical protection processing on power data of different levels using corresponding security policies. Among the various security policies, the most complex security policy is the lightweight SM4 algorithm. The different levels of power data are obtained by the distribution terminal classifying the acquired power data from the distribution side according to the data sensitivity level. The first integrity check value is generated by the distribution terminal based on the hash value of the encrypted data contained in the security data, the unique identifier of the terminal device, the timestamp, and the session sequence number. The dynamic session key is generated by the distribution terminal based on its root key, the unique identifier of the device, and the current power feature vector. The current power feature vector is obtained by the distribution terminal based on the power equipment operation data in the power data from the distribution side. The specific acquisition method of the security message is described in S20~S23 above, and will not be repeated here in this embodiment.

[0116] Optionally, in this embodiment of the application, a first lightweight pre-verification is performed before receiving the security message sent by the power distribution terminal to improve data verification efficiency and quickly filter illegal data.

[0117] Optionally, in this embodiment of the application, a possible implementation method for the first lightweight pre-verification is provided, specifically including the following operations: SB1: Receives lightweight pre-verification information sent by the power distribution terminal.

[0118] The lightweight pre-verification information includes: a unique device identifier and a core abbreviation. The core abbreviation is obtained by the power distribution terminal through feature extraction of the first-level power data. It is a short identification information extracted or encoded from the first-level power data according to preset rules.

[0119] SB2: When the device's unique identifier belongs to the device whitelist and the core abbreviation meets the rationality conditions, generate the first confirmation information and send the first confirmation information to the power distribution terminal.

[0120] The first confirmation information indicates that the power distribution terminal is allowed to send a security message.

[0121] In this embodiment, the device's unique identifier is first determined to belong to the device whitelist. If so, the core abbreviation is then checked to see if it meets the validity criteria. Otherwise, the verification process ends, and no first confirmation information is sent to the power distribution terminal. Next, the core abbreviation is determined to meet the validity criteria. If so, a first confirmation information is generated and sent to the power distribution terminal; otherwise, no first confirmation information is sent to the power distribution terminal.

[0122] In this way, before establishing a complete communication session or processing large data security messages, access attempts from illegal or unauthorized terminals can be quickly rejected by verifying the "device whitelist." Combined with the rationality judgment of the "core simplified code," obviously abnormal or forged data reporting requests can be intercepted in advance, reducing the risk of attacks on the power distribution master station from the source. The entire first pre-verification process is completed in milliseconds, improving data verification efficiency.

[0123] Optionally, in this embodiment of the application, the lightweight pre-verification information further includes: a first short check value, then after receiving the security message, the power distribution master station first uses the first short check value to perform the second lightweight pre-verification.

[0124] Optionally, in this embodiment of the application, a possible implementation method for the second lightweight pre-verification is provided, specifically including the following operations: SB3: Extract the first integrity check value contained in the security message, and truncate the first N bits of the first integrity check value to obtain the second short check value.

[0125] Where N is an integer greater than 1.

[0126] For example, N is 32, that is, the first 32 bits of the first integrity check value are truncated to obtain the second short check value.

[0127] SB4: Compare the first short check value and the second short check value to determine the short check value verification result.

[0128] In this embodiment, it is determined whether the first short checksum and the second short checksum are the same. If they are, the short checksum verification result is determined to be passed; otherwise, the short checksum verification result is determined to be failed. When the short checksum verification result is passed, a second integrity checksum is generated based on the ciphertext data, device unique identifier, timestamp, session sequence number, and dynamic session key in the security message. The first integrity checksum and the second integrity checksum are then compared to determine the integrity verification result.

[0129] In this way, after the first lightweight pre-verification passes and the complete security message arrives, a fast short hash comparison is immediately performed. This can quickly verify the basic integrity of the data, filter out invalid data that has been forged or tampered with, and the computational cost of this check is much lower than that of the complete SM3 signature verification. If the short check value verification result fails, the security message can be discarded directly without any subsequent deep verification steps, saving valuable computing resources for the distribution master station and making the entire hierarchical verification mechanism more efficient.

[0130] S31: Based on the encrypted data, device unique identifier, timestamp, session sequence number, and dynamic session key in the security message, generate a second integrity check value, and compare the first integrity check value and the second integrity check value to determine the integrity check result.

[0131] In this embodiment, the power distribution master station parses the security message, extracts the device unique identifier, timestamp, session sequence number and first integrity check value from the security message extension field, extracts ciphertext data from the message data field, then retrieves the dynamic session key corresponding to the device unique identifier from the local security storage based on the extracted device unique identifier, and then calculates the second integrity check value based on the device unique identifier, timestamp, ciphertext data, session sequence number and retrieved dynamic session key.

[0132] In this embodiment of the application, the logical expression for calculating the second integrity check value is as follows:

[0133] in, H cale Calculate the hash value for the power distribution master station. ID As a unique identifier for the device, TS For timestamps, Cipher For encrypted data in security messages, Seq For the session sequence number, SK This is a dynamic session key.

[0134] In this embodiment, it is determined whether the first integrity check value and the second integrity check value are the same. If they are, the integrity check result is determined to be passed; otherwise, the integrity check result is determined to be failed, and it is identified as a data tampering attack, triggering a level one warning. At the same time, the data is isolated and the tampering characteristics are recorded. The level one warning information is synchronously recorded in the security log, including information such as the verification failure type, data source, and timestamp, providing a basis for subsequent attack tracing.

[0135] In this way, integrity verification is performed before decryption, which can quickly identify and discard tampered packets, replay packets and illegal attack packets before decryption, thus avoiding invalid decryption operations from the source, saving power distribution station computing resources, and resisting computing power exhaustion-type DoS attacks.

[0136] S32: When the integrity verification result passes, based on the dynamic session key, the power data of different levels is decrypted in a hierarchical manner using the corresponding decryption strategy to obtain plaintext data. Based on the preset power physical constraint verification rules, the plaintext data is verified for power physical constraints to obtain the power physical constraint verification result.

[0137] In this embodiment of the application, the encrypted data in the security message is decrypted in a hierarchical manner using a corresponding level of decryption strategy. For example, the first encrypted data in the encrypted data is decrypted using the decryption strategy corresponding to the first lightweight SM4 algorithm to obtain the first level of power data, and the second encrypted data in the encrypted data is decrypted using the decryption strategy corresponding to the second lightweight SM4 algorithm to obtain the second level of power data.

[0138] In this embodiment of the application, based on the preset power physical constraint verification rules, the power distribution equipment operation data contained in the plaintext data is subjected to power physical constraint verification to obtain the power physical constraint verification result.

[0139] Optionally, in this embodiment, if the load change rate contained in the plaintext data is determined to be less than a preset load change rate threshold, and the physical relationship between the voltage and current contained in the plaintext data and the theoretical power value is determined to be within the error range, then the power physical constraint verification result is determined to be passed; otherwise, the power physical constraint verification result is determined to be failed, and it is judged as a covert attack of illegal values ​​in a legal format, triggering a secondary warning, marking abnormal data, and tracing the data source. The secondary warning information is synchronously recorded in the security log, including information such as the verification failure type, data source, and timestamp, providing a basis for subsequent attack tracing.

[0140] In this embodiment of the application, the determination expression for power physical constraint verification is as follows:

[0141] in, ΔP For the load change rate, P th The load change rate threshold, U For voltage, I For current, P This is the theoretical power value. ε This represents the allowable error range.

[0142] In this way, the classical physical laws and engineering experience of power system operation are encoded into specific mathematical judgment formulas, enabling the distribution master station to possess deep security detection capabilities based on business semantics. This allows for the effective detection of advanced and covert data injection attacks aimed at slowly disrupting grid stability or simulating normal fluctuations to bypass monitoring. In addition to cryptographic integrity verification, it innovatively introduces "power physical constraint verification," enabling the distribution master station to identify advanced covert attacks—"legitimate format, illegal value" attacks—where the communication format is correct and cryptographic verification passes, but the values ​​violate the basic physical laws of the power grid (such as power imbalance). This is a capability that traditional pure cryptographic schemes cannot achieve.

[0143] S33: When the power physical constraint verification result is passed, the plaintext data is stored.

[0144] In this embodiment of the application, when the power physical constraint verification result is passed, the plaintext data is stored. Optionally, in this embodiment of the application, a possible implementation method for storing plaintext data is provided, specifically including the following operations: S330: Employs the SM4 algorithm to perform field-level encryption on the first-level power data contained in the plaintext data, obtaining encrypted data, and associates and stores the corresponding dynamic session key version number, device unique identifier, and timestamp with the encrypted data.

[0145] In this embodiment of the application, the first-level power data contained in the plaintext data is encrypted at the field level using SM4 encryption. A dynamic initialization vector (IV) is introduced to ensure that the same plaintext corresponds to different ciphertexts, thereby obtaining encrypted data. The encrypted data is associated with and stored with the corresponding dynamic session key version number, device unique identifier, and timestamp.

[0146] S331: Generate plaintext service scope label for first-level power data.

[0147] Among them, the plaintext business scope label is the interval code obtained by mapping the first-level power data according to a preset step size, and is used to support interval retrieval of encrypted data.

[0148] In this embodiment, the plaintext service range labels for generating first-level power data are generated by setting a preset step size for voltage, current, and load, and are used for interval retrieval without decryption. Specifically, voltage, current, load, and other values ​​are mapped to interval codes according to the preset step size and stored in plaintext form to support direct querying by plaintext service range labels without decryption.

[0149] For example, for voltage values, a preset step size of 10V can be used as a range. A voltage value of 237V would be mapped to the range "230-240V" and stored in plaintext using a service range label (such as "VT23"). In this way, when querying "records with voltage between 230-240V", it is not necessary to decrypt all the data; only the plaintext service range label "VT23" needs to be matched.

[0150] In this way, by generating "plaintext business scope tags," the system can perform efficient range queries and statistical analysis on encrypted data without decrypting it, perfectly balancing the confidentiality and availability of data storage and solving a major pain point in secure storage. Furthermore, by associating encrypted data with "dynamic session key version numbers," "unique device identifiers," and "timestamps," a robust data traceability chain is established. In the event of a security incident, the key used for data encryption, the source terminal, and the time of generation can be accurately traced, greatly enhancing security auditing and accountability capabilities.

[0151] Optionally, in this embodiment, a security audit chain is constructed to ensure its immutability and authenticity. Specifically, all operation information (including operation time, operation subject, operation type, and data change content) of power distribution data from acquisition, encryption, transmission, verification to storage and access is recorded to generate corresponding audit chain logs. Then, a hash value is generated for each record in the audit chain log using the SM3 algorithm, and the hash value of the subsequent record is generated based on the hash value of the previous record, thus forming a security audit chain.

[0152] In this embodiment of the application, the expression for calculating the hash value of the nth log entry is:

[0153] in, H n-1 The hash value of the (n-1)th log entry. Log n This is the content of the nth log entry.

[0154] Record the entire process of data operation logs from receipt and verification to storage; The content of each operation log is concatenated with the hash value of the previous log to calculate a new hash value, forming an interlocking hash chain audit log constructed using the SM3 hash algorithm.

[0155] Optionally, in this embodiment of the application, hierarchical access control is implemented based on role permissions when accessing stored encrypted data.

[0156] Optionally, in this embodiment of the application, when encrypted data needs to be shared, the power distribution master station first verifies the role and permission of the visitor, and then performs a secondary verification based on the password, certificate or biometrics. After the verification is passed, the data key used to encrypt the encrypted data is encrypted and encapsulated using a dynamic session key and then transmitted. The visitor then uses the session key to decrypt and obtain the data key, and then decrypts and accesses the encrypted data.

[0157] Based on the above embodiments, see Figure 4 The diagram shown is a signaling interaction diagram of a power distribution side power data security protection method provided in this application embodiment, which specifically includes the following steps: S40: The power distribution terminal classifies the acquired power distribution data according to the data sensitivity level to obtain power data of different levels.

[0158] S41: Generate a dynamic session key based on the root key and unique identifier of the distribution terminal, as well as the current power feature vector.

[0159] S42: Based on the dynamic session key, the power data of different levels is subjected to hierarchical protection processing using the corresponding security policy to obtain secure data. Based on the hash value of the encrypted data, the unique device identifier, the timestamp, and the session sequence number contained in the secure data, the first integrity verification value is generated.

[0160] S43: Reassemble the security data according to the protocol message structure and embed the first integrity check value into the corresponding extension position to obtain the security message.

[0161] S44: Combining the device's unique identifier, core abbreviation, and first short check value into lightweight pre-check information.

[0162] The first short check value is obtained by truncating the first N bits of the first integrity check value. The core abbreviation is obtained by feature extraction from the first-level power data.

[0163] S45: Send lightweight pre-verification information to the distribution master station.

[0164] S46: When the power distribution master station determines that the unique identifier of the equipment belongs to the equipment whitelist and the core abbreviation meets the rationality conditions, it generates the first confirmation information.

[0165] S47: The power distribution master station sends the first confirmation information to the power distribution terminal.

[0166] The first confirmation information indicates that the power distribution terminal is allowed to send a security message.

[0167] S48: The distribution terminal sends a security message to the distribution master station.

[0168] S49: The power distribution master station extracts the first integrity check value contained in the security message, and truncates the first N bits of the first integrity check value to obtain the second short check value. It then compares the first short check value and the second short check value in the received lightweight pre-check information to determine the short check value check result.

[0169] S410: When the short check value verification result is passed, a second integrity check value is generated based on the ciphertext data, device unique identifier, timestamp, session sequence number, and dynamic session key in the security message, and the first integrity check value and the second integrity check value are compared to determine the integrity check result.

[0170] S411: When the integrity verification result passes, based on the dynamic session key, the power data of different levels is decrypted in a hierarchical manner using the corresponding decryption strategy to obtain plaintext data. Based on the preset power physical constraint verification rules, the plaintext data is verified for power physical constraints to obtain the power physical constraint verification result.

[0171] S412: When the power physical constraint verification result is passed, the plaintext data is stored.

[0172] Furthermore, based on the same technical concept, embodiments of this application provide a security protection device for power data on the distribution side. For example, see [link to relevant documentation]. Figure 5 As shown in the figure, a power distribution data security protection device 500 is provided in an embodiment of this application and is applied to a power distribution terminal. The power distribution data security protection device 500 may include: a processing module 501, a first generation module 502, a second generation module 503, and a sending module 504, wherein: The processing module 501 is used to classify the acquired power distribution side data according to the data sensitivity level to obtain power data of different levels; The first generation module 502 is used to generate a dynamic session key based on the root key and unique identifier of the power distribution terminal and the current power feature vector, wherein the current power feature vector is obtained based on the power distribution equipment operation data in the power distribution side power data; The second generation module 503 is used to perform hierarchical protection processing on power data of different levels based on dynamic session keys and corresponding security policies to obtain secure data. Based on the hash value of the encrypted data, the unique identifier of the device, the timestamp, and the session sequence number contained in the secure data, a first integrity verification value is generated. Among the various security policies, the most complex security policy is the lightweight SM4 algorithm. The sending module 504 is used to reassemble the security data according to the protocol message structure, embed the first integrity check value into the corresponding extension position to obtain the security message, and send the security message to the distribution master station so that the distribution master station can store the data after determining that the integrity check and power physical constraint check of the security message have passed.

[0173] In an optional embodiment, when the acquired power distribution data is classified according to its data sensitivity level to obtain power data of different levels, the processing module 501 is further configured to: Based on the control attribute score, impact range score, and real-time score of each power data contained in the power distribution side power data, the data sensitivity level of each power data is determined. Among them, the control attribute score is used to characterize whether the corresponding power data contains control attributes of the grid operation status, the impact range score is used to characterize the grid range affected by the leakage or tampering of the corresponding power data, and the real-time score is used to characterize the timeliness requirements of the corresponding power data. According to their respective data sensitivity levels, the power data are classified into different levels, including Level 1, Level 2, and Level 3 power data. The sensitivity level of Level 1 power data is higher than that of Level 2 power data, and the sensitivity level of Level 2 power data is higher than that of Level 3 power data.

[0174] In an optional embodiment, the first generation module 502 is further configured to: When a key update condition is triggered, the dynamic session key is updated, wherein the key update condition includes at least one of the following: The dynamic session key has not been updated for a preset duration threshold; The dynamic session key has been used up to a preset threshold number of times. The rate of change of the current power feature vector is greater than or equal to the preset feature change rate threshold.

[0175] In an optional embodiment, based on the dynamic session key, different levels of power data are subjected to hierarchical protection processing using corresponding security strategies. When secure data is obtained, the second generation module 503 is further configured to: The first lightweight SM4 algorithm is used to encrypt the first level power data to obtain the first ciphertext data. The first lightweight SM4 algorithm replaces the 8×8 lookup table S box with a 4×4 lightweight S box constructed based on the composite field GF(((2²)²)²), and adds a bit-level permutation layer to the output of the 4×4 lightweight S box. The second-level power data is encrypted using the second lightweight SM4 algorithm to obtain the second ciphertext data, and / or the second-level power data is hashed using the SM3 algorithm to obtain the second-level power data with hash tags. The number of iterations of the second lightweight SM4 algorithm is less than the number of iterations of the first lightweight SM4 algorithm. The first encrypted data, the second encrypted data, or the second-level power data and the third-level power data with hash tags are used as secure data.

[0176] In an optional embodiment, the second generation module 503 is further configured to: The first-level power data, or the set of first-level power data and second-level power data, are grouped to obtain data groups; For each data group, perform the following operations in sequence: use the corresponding lightweight SM4 algorithm to encrypt the current data group to obtain the current ciphertext group, and based on the previous intermediate state value, use the SM3 algorithm to compress the current ciphertext group to obtain the current intermediate state value. Each ciphertext group will be used as the ciphertext data contained in the secure data, and the final intermediate state value corresponding to the last data group will be used as the hash value of the ciphertext data.

[0177] In an optional embodiment, when sending a security message to the distribution master station, the sending module 504 is further configured to: The first short check value is obtained by truncating the first integrity check value to the first N bits, where N is an integer greater than 1; The device's unique identifier, core abbreviation, and first short check value are combined to form lightweight pre-verification information, which is then sent to the power distribution master station. The core abbreviation is obtained by feature extraction from the first-level power data. Upon receiving the first confirmation message from the distribution master station, a security message is sent to the distribution master station. The first confirmation message indicates that the distribution master station allows the sending of the security message.

[0178] Based on the same technical concept, embodiments of this application provide a security protection device for power distribution side power data. For example, see [link to relevant documentation]. Figure 6 As shown, this application provides a power distribution data security protection device 600, which is used in a power distribution master station. The power distribution data security protection device 600 may include: a receiving module 601, a first verification module 602, a second verification module 603, a storage module 604, and a lightweight pre-verification module 605, wherein: The receiving module 601 is used to receive security messages sent by the power distribution terminal. The security message is obtained by the power distribution terminal reassembling security data according to the protocol message structure and embedding the first integrity check value into the corresponding extension position. The security data is obtained by the power distribution terminal using a dynamic session key to perform hierarchical protection processing on power data of different levels using corresponding security policies. The most complex security policy among the various security policies is the lightweight SM4 algorithm. The different levels of power data are obtained by the power distribution terminal classifying the acquired power distribution side data according to the data sensitivity level. The first integrity check value is generated by the power distribution terminal based on the hash value of the ciphertext data contained in the security data, the unique identifier of the terminal device, the timestamp, and the session sequence number. The dynamic session key is generated by the power distribution terminal based on its root key, the unique identifier of the device, and the current power feature vector. The current power feature vector is obtained by the power distribution terminal based on the power distribution equipment operation data in the power distribution side data. The first verification module 602 is used to generate a second integrity verification value based on the ciphertext data, device unique identifier, timestamp, session sequence number, and dynamic session key in the security message, and compare the first integrity verification value and the second integrity verification value to determine the integrity verification result. The second verification module 603 is used to perform hierarchical decryption processing on power data of different levels based on the dynamic session key and the corresponding level decryption strategy to obtain plaintext data when the integrity verification result passes, and to perform power physical constraint verification on the plaintext data based on the preset power physical constraint verification rules to obtain the power physical constraint verification result. Storage module 604 is used to store plaintext data when the power physical constraint verification result passes.

[0179] In an optional embodiment, the lightweight pre-verification module 605 is used to: Receive lightweight pre-verification information sent by the power distribution terminal. The lightweight pre-verification information includes: unique device identifier and core abbreviation. When it is determined that the device's unique identifier belongs to the device whitelist and the core abbreviation meets the rationality conditions, a first confirmation message is generated and sent to the power distribution terminal. The first confirmation message indicates that the power distribution terminal is allowed to send a security message.

[0180] In an optional embodiment, the lightweight pre-verification information further includes: a first short check value. Before generating the second integrity check value based on the ciphertext data, device unique identifier, timestamp, session sequence number, and dynamic session key in the secure message, the lightweight pre-verification module 605 is further configured to: Extract the first integrity check value contained in the security message, and truncate the first integrity check value to the first N bits to obtain the second short check value, where N is an integer greater than 1; Compare the first shortest check value and the second shortest check value to determine the shortest check value verification result.

[0181] In an optional embodiment, when performing electrical physical constraint verification on plaintext data and obtaining the electrical physical constraint verification result, the second verification module 603 is further configured to: If it is determined that the load change rate contained in the plaintext data is less than the preset load change rate threshold, and the physical relationship between the voltage and current contained in the plaintext data and the theoretical power value is within the error range, then the power physical constraint verification result is determined to be passed.

[0182] Based on the description of the method and apparatus embodiments above, an exemplary embodiment of the present invention also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, which, when executed by the at least one processor, causes the electronic device to perform the method according to an embodiment of the present invention.

[0183] This application also provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a computer's processor, is used to cause the computer to perform a method according to an embodiment of this application.

[0184] This application also provides a computer program product, including a computer program, wherein the computer program, when executed by a computer's processor, is used to cause the computer to perform a method according to an embodiment of this application.

[0185] See Figure 7 The diagram shown below illustrates the structure of an electronic device 700 that can serve as a server or client in this application, and is an example of a hardware device that can be applied to various aspects of this application. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.

[0186] like Figure 7As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. The RAM 703 may also store various programs and data required for the operation of the device 700. The computing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0187] Multiple components in electronic device 700 are connected to I / O interface 705, including: input unit 706, output unit 707, storage unit 708, and communication unit 709. Input unit 706 can be any type of device capable of inputting information to electronic device 700. Input unit 706 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of electronic device. Output unit 707 can be any type of device capable of presenting information and may include, but is not limited to, a display, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 708 may include, but is not limited to, disk and optical disk. Communication unit 709 allows electronic device 700 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers and / or chipsets, such as Bluetooth devices, WiFi devices, worldwide interoperability for microwave access (WiMax) devices, cellular communication devices, and / or the like.

[0188] The computing unit 701 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above. For example, in some embodiments, the above-described security protection method based on power distribution side data can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 700 via ROM 702 and / or communication unit 709. In some embodiments, the computing unit 701 can be configured to perform the above-described security protection method for power distribution side data by any other suitable means (e.g., by means of firmware).

[0189] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0190] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, erasable programmable read-only memory (EPROM) or flash memory, optical fibers, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0191] As used in this application, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device, PLD) used to provide machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0192] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0193] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0194] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other.

[0195] Furthermore, it should be understood that the above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of the invention. Therefore, any equivalent variations made in accordance with the claims of this invention are still within the scope of this application.

Claims

1. A method for secure protection of power data on the distribution side, characterized in that, Applied to power distribution terminals, including: The acquired power distribution data is classified according to its sensitivity level to obtain different levels of power data. A dynamic session key is generated based on the root key and unique device identifier of the power distribution terminal, as well as the current power feature vector, wherein the current power feature vector is obtained based on the power distribution equipment operation data in the power distribution side power data; Based on the dynamic session key, the power data of different levels are subjected to hierarchical protection processing using corresponding security strategies to obtain secure data. Based on the hash value of the encrypted data contained in the secure data, the unique identifier of the device, the timestamp, and the session sequence number, a first integrity verification value is generated. Among the various security strategies, the most complex security strategy is the lightweight SM4 algorithm. The security data is reassembled according to the protocol message structure, and the first integrity check value is embedded into the corresponding extension position to obtain a security message. The security message is then sent to the distribution master station so that the distribution master station can store the data after confirming that the integrity check and power physical constraint check of the security message have passed.

2. The method as described in claim 1, characterized in that, The acquired power distribution data is classified according to its data sensitivity level to obtain different levels of power data, including: Based on the control attribute score, impact range score, and real-time score of each power data included in the power distribution side power data, the data sensitivity level of each power data is determined. The control attribute score is used to characterize whether the corresponding power data contains control attributes of the power grid operating status, the impact range score is used to characterize the power grid range affected by the leakage or tampering of the corresponding power data, and the real-time score is used to characterize the timeliness requirements of the corresponding power data. According to the data sensitivity level of each power data, the power data is classified into different levels, including: first-level power data, second-level power data, and third-level power data. The first-level power data has a higher sensitivity level than the second-level power data, and the second-level power data has a higher sensitivity level than the third-level power data.

3. The method as described in claim 1, characterized in that, The method further includes: When a key update condition is triggered, the dynamic session key is updated, wherein the key update condition includes at least one of the following: The dynamic session key has not been updated for a preset duration threshold; The number of times the dynamic session key is used reaches a preset threshold. The rate of change of the power feature corresponding to the current power feature vector is greater than or equal to a preset feature change rate threshold.

4. The method as described in claim 2, characterized in that, Based on the dynamic session key, the power data at different levels is subjected to hierarchical protection processing using corresponding security strategies to obtain secure data, including: The first lightweight SM4 algorithm is used to encrypt the first-level power data to obtain the first ciphertext data. The first lightweight SM4 algorithm replaces the 8×8 lookup table S-box with a 4×4 lightweight S-box constructed based on the composite field GF(((2²)²)²), and adds a bit-level permutation layer to the output of the 4×4 lightweight S-box. The second-level power data is encrypted using the second lightweight SM4 algorithm to obtain second ciphertext data, and / or the second-level power data is hashed using the SM3 algorithm to obtain second-level power data with hash tags, wherein the number of iterations of the second lightweight SM4 algorithm is less than the number of iterations of the first lightweight SM4 algorithm; The first encrypted data, the second encrypted data, or the second-level power data with hash tags, and the third-level power data are used as the secure data.

5. The method as described in claim 4, characterized in that, The method further includes: The first-level power data, or the set of the first-level power data and the second-level power data, are grouped to obtain data groups; For each data group, perform the following operations in sequence: use the corresponding lightweight SM4 algorithm to encrypt the current data group to obtain the current ciphertext group, and based on the previous intermediate state value, use the SM3 algorithm to compress the current ciphertext group to obtain the current intermediate state value. Each ciphertext group is obtained as ciphertext data contained in the secure data, and the final intermediate state value corresponding to the last data group is used as the hash value of the ciphertext data.

6. The method as described in claim 2, characterized in that, Sending the security message to the power distribution master station includes: The first short check value is obtained by truncating the first N bits of the first integrity check value, where N is an integer greater than 1; The device's unique identifier, core abbreviation, and the first short check value are combined to form lightweight pre-verification information, which is then sent to the power distribution master station. The core abbreviation is obtained by feature extraction from the first-level power data. When the first confirmation information is received from the power distribution master station, the security message is sent to the power distribution master station, wherein the first confirmation information indicates that the power distribution master station allows the sending of the security message.

7. A method for secure protection of power data on the distribution side, characterized in that, Applied to power distribution master stations, including: The system receives a security message sent by a power distribution terminal. The security message is obtained by the power distribution terminal reassembling security data according to a protocol message structure and embedding a first integrity check value into the corresponding extension position. The security data is obtained by the power distribution terminal using a dynamic session key and applying corresponding security strategies to classify and protect different levels of power data. The most complex security strategy among these strategies is the lightweight SM4 algorithm. The different levels of power data are obtained by the power distribution terminal classifying the acquired power distribution-side data according to its data sensitivity level. The first integrity check value is generated by the power distribution terminal based on the hash value of the encrypted data contained in the security data, the unique identifier of the terminal device, the timestamp, and the session sequence number. The dynamic session key is generated by the power distribution terminal based on its root key, the unique identifier of the device, and the current power feature vector. The current power feature vector is obtained by the power distribution terminal based on the power distribution equipment operation data in the power distribution-side data. Based on the encrypted data in the security message, the device's unique identifier, the timestamp, the session sequence number, and the dynamic session key, a second integrity verification value is generated, and the first integrity verification value and the second integrity verification value are compared to determine the integrity verification result. When the integrity verification result passes, based on the dynamic session key, the power data at different levels is decrypted in a hierarchical manner using the corresponding level decryption strategy to obtain plaintext data. Then, based on the preset power physical constraint verification rules, the plaintext data is subjected to power physical constraint verification to obtain the power physical constraint verification result. When the power physical constraint verification result is passed, the plaintext data is stored.

8. The method as described in claim 7, characterized in that, Before receiving the security message sent by the power distribution terminal, the method further includes: The device receives lightweight pre-verification information sent by the power distribution terminal, the lightweight pre-verification information including: the device's unique identifier and core abbreviation; When it is determined that the unique identifier of the device belongs to the device whitelist and the core abbreviation meets the rationality condition, a first confirmation message is generated and sent to the power distribution terminal, wherein the first confirmation message indicates that the power distribution terminal is allowed to send the security message.

9. The method as described in claim 8, characterized in that, The lightweight pre-verification information further includes: a first short verification value. Before generating the second integrity verification value based on the ciphertext data in the security message, the device unique identifier, the timestamp, the session sequence number, and the dynamic session key, the following is also included: Extract the first integrity check value contained in the security message, and truncate the first N bits of the first integrity check value to obtain the second short check value, where N is an integer greater than 1; Compare the first short check value and the second short check value to determine the short check value verification result.

10. The method as described in claim 7, characterized in that, The step of performing power physical constraint verification on the plaintext data to obtain the power physical constraint verification result includes: If it is determined that the load change rate contained in the plaintext data is less than the preset load change rate threshold, and the physical relationship between the voltage and current contained in the plaintext data and the theoretical power value is within the error range, then the power physical constraint verification result is determined to be passed.