A multi-level encryption method for power grid privacy data hiding classification algorithm

CN122783262APending Publication Date: 2026-09-18STATE GRID LIAONING ELECTRIC POWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511781848.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-29
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

这些数据在传输过程中面临被窃取、篡改或分析的风险,传统加密方法虽能保障数据机密性,但难以对抗基于流量分析与行为推断的隐私攻击

Benefits of technology

[0058] This invention constructs a highly diverse control flow structure and path diversity measurement through the synergistic effect of two-state non-transparent predicates and branch confusion algorithms. This system effectively resists reverse engineering attacks based on static analysis; it employs an improved k-means clustering algorithm to achieve automatic and accurate classification of power data and user data, with a classification accuracy consistently above 90%, meeting the precision requirements of power grid data management; it adopts a hierarchical encryption strategy to address the sensitivity differences of different data types: a high-strength RC6 algorithm is used for power data, while a lightweight Fiestel structure is used for user data, optimizing system performance while ensuring security; through optimized algorithm implementation and parallel processing technology, the overall solution's response time is controlled within 5 seconds, meeting the stringent requirements of real-time data processing in smart grids; and a complete key management system is established to ensure that the RC6 round key and Fiestel subkey are independent of each other, providing forward security and effectively preventing the decryption of historical data due to key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_35
    Figure SMS_35
  • Figure SMS_52
    Figure SMS_52
  • Figure SMS_53
    Figure SMS_53
Patent Text Reader

Abstract

The application discloses a power grid privacy data multilevel encryption method of a hidden classification algorithm, and comprises the following steps: S1: based on the hidden classification algorithm, the transmission path form of power grid privacy data is changed by using a two-state non-transparent predicate to obtain information of each path; S2: a branch confusion algorithm is used to hide each path after confusion processing; S3: the k-means algorithm is used to classify the privacy data on different transmission paths into power data and user data; and S4: the RC6 algorithm and the Fiestel algorithm are used to respectively encrypt the power data and the user data. The application realizes efficient classification and multilevel encryption of power grid privacy data in the transmission process, and has the characteristics of short response time, high classification accuracy and strong anti-analysis capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security and privacy protection technology, specifically to a multi-level encryption method for power grid privacy data using a hidden classification algorithm. Background Technology

[0002] With the rapid development of smart grids, the power grid system generates and transmits a large amount of data containing sensitive information such as user electricity consumption behavior and grid operation status. This data faces the risk of being stolen, tampered with, or analyzed during transmission. While traditional encryption methods can ensure data confidentiality, they are insufficient to combat privacy attacks based on flow analysis and behavioral inference. Existing encryption technologies primarily focus on data content protection, lacking covert design for data categories, transmission paths, and control flow structures. Attackers can infer data categories and even reconstruct some sensitive information by analyzing data flow patterns, path characteristics, and control flow structures. Therefore, there is an urgent need for a privacy protection method that integrates data classification and multi-layered encryption, and possesses path hiding and anti-analysis capabilities. Summary of the Invention

[0003] The purpose of this invention is to provide a multi-level encryption method for power grid privacy data based on a hidden classification algorithm, which achieves efficient classification, path hiding and hierarchical encryption of data during transmission, and meets the dual requirements of response time and classification accuracy.

[0004] The technical solution of the present invention to solve the above-mentioned technical problems is as follows:

[0005] S1: Based on the hidden classification algorithm, the form of the power grid privacy data transmission path is changed by using a two-state non-transparent predicate to obtain information about each path;

[0006] S2: Use a branch obfuscation algorithm to hide each path after obfuscation;

[0007] S3: Use the k-means algorithm to classify privacy data on different transmission paths into power data and user data;

[0008] S4: The RC6 algorithm and the Fiestel algorithm are used to encrypt the power data and user data respectively.

[0009] Preferably, the specific method for obtaining path information in step S1 is as follows:

[0010] Path tagging and predicate generation functions:

[0011] Suppose there are n initial transmission paths to be processed, forming a set of privacy data transmission paths to be protected. ,in Indicates the first There are several transmission paths; based on the hidden classification algorithm, each path is assigned a specific value. Generate the corresponding bistate non-transparent predicate function:

[0012] (1)

[0013] in, These are secret constants determined at compile time. For runtime input parameters, For constructor, ensure (x) has a deterministic and hidden Boolean output at runtime;

[0014] Control flow reconstruction function:

[0015] Using the aforementioned two-state non-transparent predicates to analyze the original control flow graph Perform a refactoring, inserting code at critical branch points. (x) Controlled non-statically inferable path branches form a confused control flow graph. ,in , and These are the equivalent code blocks for the corresponding true / false outputs. This is the reconstructed set of edges;

[0016] Path selection and diversity measurement functions:

[0017] Path selection function Dynamically guide the execution flow and define path diversity metrics:

[0018] (2)

[0019] in, The total number of paths, It is a path similarity function based on the longest common subsequence or node sequence matching, with values ​​between [0,1]. When the value approaches 1, it indicates that the greater the difference in the path set, the stronger the resistance to analysis.

[0020] Further optimization involves employing a branch obfuscation algorithm in step S2 to hide the obfuscated path, specifically including:

[0021] Based on the confused control flow graph obtained in step S1 A branch obfuscation algorithm is used for deep hiding.

[0022] Control flow graph Implement control flow flattening transformation, converting the original nested branch structure into an equivalent switch-case scheduling pattern, and define scheduling variables:

[0023]

[0024] in, The current execution state is... For runtime input parameters, This is the state transition function;

[0025] Insert into the flattened control flow A pseudo-branch node forms an enhanced control flow graph. ,in:

[0026]

[0027]

[0028] in, For the inserted first A pseudo-branch node For the corresponding pseudo-branch edge;

[0029] Define a function to measure the complexity of confusion:

[0030]

[0031] in, These are structural weighting coefficients used to balance the contributions of increasing edges and nodes to complexity. , These represent the number of nodes before and after the confusion, respectively. , These represent the number of edges before and after confusion, respectively;

[0032] when When the system reaches the preset path concealment strength requirement, it can effectively resist reverse engineering attacks based on control flow analysis.

[0033] Further optimization involves using the k-means algorithm in step S3 to separate privacy data along different transmission paths into power data and user data, specifically including:

[0034] Collect a sample set of power grid privacy data:

[0035]

[0036] in, Indicates the first Data The feature vector has dimensions including packet length, transmission frequency, protocol type, and source / destination address features.

[0037] Initialize the k-means clustering algorithm: Set the number of clusters These correspond to different power data clusters. and user data clusters Two initial cluster centers were randomly selected. Perform an iterative optimization process, at the... In each iteration, each data sample Assign to the nearest cluster; the assignment function is:

[0038]

[0039] Recalculate the cluster centers for each cluster:

[0040]

[0041] Define the clustering objective function (within-cluster sum of squares error):

[0042]

[0043] When the difference of the objective function between two adjacent iterations Or reach the maximum number of iterations Optimization stops when the time is right, where This is the convergence threshold;

[0044] Final output classification result: Power data cluster and user data clusters And ensure classification accuracy. ,in , , , These represent the sample sizes of true positives, true negatives, false positives, and false negatives, respectively.

[0045] Further preferred, in step S4, the power data includes: a power data encryption unit, a user data encryption unit, and a key expansion module.

[0046] Further optimization, in step S4, the encryption processing of power data and user data using the RC6 algorithm and the Fiestel algorithm specifically includes:

[0047] Classified power data clusters The RC6 algorithm is used for encryption, and the number of encryption rounds is set. Key length The core round function of the RC6 algorithm is defined as follows:

[0048]

[0049] in, It is a 32-bit register status variable. This indicates a bitwise XOR operation. This indicates a circular left shift operation, which is performed on a 128-bit data block during encryption. Round-based iterative processing, each round consisting of three stages: forward transformation, round loop, and backward transformation, where the round key... Generated from the master key using a key expansion algorithm;

[0050] Classified user data clusters A custom encryption algorithm based on the Fiestel structure is used, and the number of iteration rounds is set. The single-round encryption process of the Fiestel structure is defined as follows:

[0051]

[0052]

[0053] in , The first The left and right 32-bit data blocks of the wheel. For the first Wheel key, wheel function Employing a nonlinear transformation structure:

[0054]

[0055] in, For linear diffusion layers, bit confusion is achieved using the maximum distance separable matrix multiplication method; It is a non-linear substitution layer, using a custom design. S-boxes enable byte substitution;

[0056] Based on master key The RC6 algorithm round key sequences are generated using a key expansion algorithm. and Fiestel algorithm subkey sequence This ensures that the key materials for the two encryption algorithms are independent of each other and meet the forward security requirements.

[0057] The present invention has the following beneficial effects:

[0058] This invention constructs a highly diverse control flow structure and path diversity measurement through the synergistic effect of two-state non-transparent predicates and branch confusion algorithms. This system effectively resists reverse engineering attacks based on static analysis; it employs an improved k-means clustering algorithm to achieve automatic and accurate classification of power data and user data, with a classification accuracy consistently above 90%, meeting the precision requirements of power grid data management; it adopts a hierarchical encryption strategy to address the sensitivity differences of different data types: a high-strength RC6 algorithm is used for power data, while a lightweight Fiestel structure is used for user data, optimizing system performance while ensuring security; through optimized algorithm implementation and parallel processing technology, the overall solution's response time is controlled within 5 seconds, meeting the stringent requirements of real-time data processing in smart grids; and a complete key management system is established to ensure that the RC6 round key and Fiestel subkey are independent of each other, providing forward security and effectively preventing the decryption of historical data due to key leakage. Detailed Implementation

[0059] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0060] Example

[0061] This invention relates to a multi-level encryption method for power grid privacy data using a hidden classification algorithm, comprising the following steps:

[0062] S1: Based on the hidden classification algorithm, the form of the power grid privacy data transmission path is changed by using a two-state non-transparent predicate to obtain information about each path;

[0063] In a power grid data transmission environment, there are multiple initial transmission paths, forming a set of privacy data transmission paths that need to be protected. ,in Indicates the first There are several transmission paths; based on the hidden classification algorithm, each path is assigned a specific value. Generate the corresponding bistate non-transparent predicate function:

[0064]

[0065] in, These are secret constants determined at compile time. For runtime input parameters, For constructor, ensure (x) has a deterministic and hidden Boolean output at runtime;

[0066] Using the aforementioned two-state non-transparent predicates to analyze the original control flow graph Perform a refactoring, inserting code at critical branch points. (x) Controlled non-statically inferable path branches form a confused control flow graph. ,in , and These are the equivalent code blocks for the corresponding true / false outputs. This is the reconstructed set of edges;

[0067] Path selection function Dynamically guide the execution flow and define path diversity metrics:

[0068]

[0069] in, The total number of paths, It is a path similarity function based on the longest common subsequence or node sequence matching, with values ​​between [0,1]. When the value approaches 1, it indicates that the greater the difference in the path set, the stronger the resistance to analysis.

[0070] S2: Use a branch obfuscation algorithm to hide each path after obfuscation;

[0071] Based on the confused control flow graph obtained in step S1 A branch obfuscation algorithm is used for deep hiding.

[0072] Control flow graph Implement control flow flattening transformation, converting the original nested branch structure into an equivalent switch-case scheduling pattern, and define scheduling variables:

[0073]

[0074] in, The current execution state is... For runtime input parameters, This is the state transition function;

[0075] Insert into the flattened control flow A pseudo-branch node forms an enhanced control flow graph. ,in:

[0076]

[0077]

[0078] in, For the inserted first A pseudo-branch node For the corresponding pseudo-branch edge;

[0079] Define a function to measure the complexity of confusion:

[0080]

[0081] in, These are structural weighting coefficients used to balance the contributions of increasing edges and nodes to complexity. , These represent the number of nodes before and after the confusion, respectively. , These represent the number of edges before and after confusion, respectively;

[0082] when When the system reaches the preset path concealment strength requirement, it can effectively resist reverse engineering attacks based on control flow analysis.

[0083] S3: Use the k-means algorithm to classify privacy data on different transmission paths into power data and user data;

[0084] Collect a sample set of power grid privacy data:

[0085]

[0086] in, Indicates the first Data The feature vector has dimensions including packet length, transmission frequency, protocol type, and source / destination address features.

[0087] Initialize the k-means clustering algorithm and set the number of clusters. These correspond to different power data clusters. and user data clusters Two initial cluster centers were randomly selected. Perform the iterative optimization process, at the... In each iteration, each data sample Assign to the nearest cluster; the assignment function is:

[0088]

[0089] Recalculate the cluster centers for each cluster:

[0090]

[0091] Define the clustering objective function (within-cluster sum of squares error):

[0092]

[0093] When the difference of the objective function between two adjacent iterations Or reach the maximum number of iterations Optimization stops when the time is right, where This is the convergence threshold;

[0094] Final output classification result: Power data cluster and user data clusters And ensure classification accuracy. ,in , , , These represent the sample sizes of true positives, true negatives, false positives, and false negatives, respectively.

[0095] S4: The RC6 algorithm and the Fiestel algorithm are used to encrypt the power data and user data respectively;

[0096] Classified power data clusters The RC6 algorithm is used for encryption, and the number of encryption rounds is set. Key length The core round function of the RC6 algorithm is defined as follows:

[0097]

[0098] in, It is a 32-bit register status variable. This indicates a bitwise XOR operation. This indicates a circular left shift operation, which is performed on a 128-bit data block during encryption. Round-based iterative processing, each round consisting of three stages: forward transformation, round loop, and backward transformation, where the round key... Generated from the master key using a key expansion algorithm;

[0099] Classified user data clusters A custom encryption algorithm based on the Fiestel structure is used, and the number of iteration rounds is set. The single-round encryption process of the Fiestel structure is defined as follows:

[0100]

[0101]

[0102] in , The first The left and right 32-bit data blocks of the wheel. For the first Wheel key. Wheel function. Employing a nonlinear transformation structure:

[0103]

[0104] in, For linear diffusion layers, bit confusion is achieved using the maximum distance separable matrix multiplication method; It is a non-linear substitution layer, using a custom design. S-boxes enable byte substitution;

[0105] Based on master key The RC6 algorithm round key sequences are generated using a key expansion algorithm. and Fiestel algorithm subkey sequence This ensures that the key materials for the two encryption algorithms are independent of each other and meet the forward security requirements.

[0106] This invention proposes a multi-level encryption method for power grid privacy data using a hidden classification algorithm. By constructing a control flow obfuscation mechanism based on bi-state non-transparent predicates and a branch hiding algorithm, it transforms and masquerades the transmission path of power grid privacy data, achieving diversity and resistance to analysis, thus providing a fundamental guarantee for the covert transmission of privacy data. Based on this, an automatic data classification module based on the k-means clustering algorithm is designed. Through multi-dimensional feature extraction and iterative optimization, it achieves accurate differentiation between power data and user data, with a classification accuracy consistently above 90%. Furthermore, this invention combines the differences in data categories and security requirements to construct a hierarchical encryption strategy. A high-strength RC6 algorithm is used for power data, while a lightweight Fiestel structure encryption is used for user data, optimizing system performance while ensuring security. This method significantly improves the anti-analysis capability and confidentiality of power grid privacy data during transmission through key technologies such as path diversity measurement, confusion complexity assessment, clustering target optimization, and key independent expansion. It reduces the risk of control flow reversal and data theft, and ensures the security and efficiency of the system in real-time transmission, heterogeneous terminals, and multi-link scenarios. It provides complete technical support for data privacy protection and hierarchical management in the smart grid environment.

[0107] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A multi-level encryption method for power grid privacy data using a hidden classification algorithm, characterized in that, Includes the following steps: S1: Based on the hidden classification algorithm, the form of the power grid privacy data transmission path is changed by using a two-state non-transparent predicate to obtain information about each path; S2: Use a branch obfuscation algorithm to hide each path after obfuscation; S3: Use the k-means algorithm to classify privacy data on different transmission paths into power data and user data; S4: The RC6 algorithm and the Fiestel algorithm are used to encrypt the power data and user data respectively.

2. The method for multi-level encryption of power grid privacy data using a hidden classification algorithm according to claim 2, characterized in that, The specific method for S1 to obtain path information is as follows: Path tagging and predicate generation functions: Suppose there are n initial transmission paths to be processed, forming a set of privacy data transmission paths to be protected. ,in Indicates the first There are several transmission paths; based on the hidden classification algorithm, each path is assigned a specific value. Generate the corresponding bistate non-transparent predicate function: (1) in, These are secret constants determined at compile time. For runtime input parameters, For constructor, ensure (x) has a deterministic and hidden Boolean output at runtime; Control flow reconstruction function: Using the aforementioned two-state non-transparent predicates to analyze the original control flow graph Perform a refactoring, inserting code at critical branch points. (x) Controlled non-statically inferable path branches form a confused control flow graph. ,in , and These are the equivalent code blocks for the corresponding true / false outputs. This is the reconstructed set of edges; Path selection and diversity measurement functions: Path selection function Dynamically guide the execution flow and define path diversity metrics: (2) in, The total number of paths, It is a path similarity function based on the longest common subsequence or node sequence matching, with values ​​between [0,1]. When the value approaches 1, it indicates that the greater the difference in the path set, the stronger the resistance to analysis.

3. The method for multi-level encryption of power grid privacy data using a hidden classification algorithm according to claim 1, characterized in that, In step S2, a branch obfuscation algorithm is used to hide the obfuscated path, specifically including: Based on the confused control flow graph obtained in step S1 A branch obfuscation algorithm is used for deep hiding. Control flow graph Implement control flow flattening transformation, converting the original nested branch structure into an equivalent switch-case scheduling pattern, and define scheduling variables: in, The current execution state is... For runtime input parameters, This is the state transition function. Insert into the flattened control flow A pseudo-branch node forms an enhanced control flow graph. ,in: in, For the inserted first A pseudo-branch node For the corresponding pseudo-branch edge; Define a function to measure the complexity of confusion: in, These are structural weighting coefficients used to balance the contributions of increasing edges and nodes to complexity. , These represent the number of nodes before and after the confusion, respectively. , These represent the number of edges before and after confusion, respectively; when When the system reaches the preset path concealment strength requirement, it can effectively resist reverse engineering attacks based on control flow analysis.

4. The multi-level encryption method for power grid privacy data using a hidden classification algorithm according to claim 1, characterized in that, In step S3, the k-means algorithm is used to divide the privacy data on different transmission paths into power data and user data, specifically including: Collect a sample set of power grid privacy data: in, Indicates the first Data The feature vector has dimensions including packet length, transmission frequency, protocol type, and source / destination address features. Initialize the k-means clustering algorithm and set the number of clusters. These correspond to different power data clusters. and user data clusters Two initial cluster centers were randomly selected. Perform the iterative optimization process, at the... In each iteration, each data sample Assign to the nearest cluster; the assignment function is: Recalculate the cluster centers for each cluster: Define the clustering objective function (within-cluster sum of squares error): When the difference of the objective function between two adjacent iterations Or reach the maximum number of iterations Optimization stops when the time is right, where This is the convergence threshold; Final output classification result: Power data cluster and user data clusters And ensure classification accuracy. ,in , , , These represent the sample sizes of true positives, true negatives, false positives, and false negatives, respectively.

5. A multi-level encryption method for power grid privacy data using a hidden classification algorithm according to claim 1, characterized in that, In step S4, the power data includes: a power data encryption unit, a user data encryption unit, and a key expansion module.

6. A multi-level encryption method for power grid privacy data using a hidden classification algorithm according to claim 6, characterized in that, In step S4, the encryption processing of power data and user data using the RC6 algorithm and the Fiestel algorithm specifically includes: Classified power data clusters The RC6 algorithm is used for encryption, and the number of encryption rounds is set. Key length The core round function of the RC6 algorithm is defined as follows: in, It is a 32-bit register status variable. This indicates a bitwise XOR operation. This indicates a circular left shift operation, which is performed on a 128-bit data block during encryption. Round-based iterative processing, each round consisting of three stages: forward transformation, round loop, and backward transformation, where the round key... Generated from the master key using a key expansion algorithm; Classified user data clusters A custom encryption algorithm based on the Fiestel structure is used, and the number of iteration rounds is set. The single-round encryption process of the Fiestel structure is defined as follows: in , The first The left and right 32-bit data blocks of the wheel. For the first Wheel key, wheel function Employing a nonlinear transformation structure: in, For linear diffusion layers, bit confusion is achieved using the maximum distance separable matrix multiplication method; It is a non-linear substitution layer, using a custom design. S-boxes enable byte substitution; Based on master key The RC6 algorithm round key sequences are generated using a key expansion algorithm. and Fiestel algorithm subkey sequence This ensures that the key materials for the two encryption algorithms are independent of each other and meet the forward security requirements.