Hash algorithm-based electric energy metering box data encryption system
Patent Information
- Application Number
- CN202611125229.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-28
- Publication Date
- 2026-09-22
AI Technical Summary
[0002]目前,电力计量场景下传统哈希加密技术仅支持固定密钥与单向哈希运算,未适配电能计量箱多源异构浮点数据特征,密钥更新缺乏时序与空间熵值驱动,哈希认证易被篡改、链路无闭环校验,且无法根据通信算力与带宽自适应调整加密强度,数据传输安全性与传输效率难以兼顾
本发明通过融合电能计量箱多源异构数据与通信硬件工况参数,精准提取传输异常波动特征并构建多维计量融合特征矩阵,结合时序熵值与台区空间关联熵值驱动滚动密钥动态生成,有效提升哈希加密的密钥随机性与抗破解能力,保障计量数据加密过程的稳定性与可靠性。系统采用适配浮点计量数据的优化哈希函数完成二次迭代哈希运算,生成高安全性增强哈希认证码,依托可变传输时间窗口构建双向闭环时序哈希链,实现计量数据传输全程可校验、篡改可追溯,大幅提升数据加密认证的完整性与抗篡改性。
Smart Images

Figure CN122802164A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of key iteration control technology, and in particular to a data encryption system for electricity metering boxes based on a hash algorithm. Background Technology
[0002] Currently, traditional hash encryption technology in power metering scenarios only supports fixed keys and one-way hash operations. It is not adapted to the characteristics of multi-source heterogeneous floating-point data in power metering boxes. Key updates lack time-series and spatial entropy value driving forces. Hash authentication is easily tampered with, the link has no closed-loop verification, and it cannot adaptively adjust the encryption strength according to communication computing power and bandwidth. It is difficult to balance data transmission security and transmission efficiency.
[0003] For example, traditional hash algorithms are prone to precision loss when directly operating on floating-point data of electricity metering, and the generated hash digests have weak collision resistance; the keys are statically configured and cannot be dynamically updated according to the metering time series and the spatial association of the transformer area, so once leaked, the entire life cycle of data is at risk of leakage; hash authentication is only one-way verification, without the chain association of front and back windows, so it is impossible to quickly locate and block data after it has been tampered with; the encryption parameters are set in a fixed way, and in scenarios with insufficient communication bandwidth or limited computing power, data packet delay, packet loss or encryption redundancy problems are likely to occur.
[0004] Therefore, existing data encryption technologies based on hash algorithms cannot meet the encryption requirements of high real-time performance, high security, and high adaptive transmission of data from electricity metering boxes. There is an urgent need for a new encryption system that integrates multi-dimensional features, dynamic entropy encryption generation, bidirectional hash links, and adaptive encryption adjustment to solve the core defects of traditional technologies, such as static keys, weak hash authentication, no closed-loop links, and unadjustable encryption parameters. Summary of the Invention
[0005] To achieve the above objectives, the present invention provides a data encryption system for electricity metering boxes based on a hash algorithm, characterized in that the system includes a feature fusion module, an entropy density generation module, a hash encryption module, a hash link module, and an adaptive packaging module, wherein: The fusion feature module is used to collect multi-source heterogeneous metering raw data from the power metering box, fuse communication hardware operating parameters, and extract a multi-dimensional metering fusion feature matrix containing transmission abnormal fluctuation features. The entropy density generation module is used to determine the time-series entropy value and the spatial correlation entropy value of the transformer area based on the time-series continuity and time-domain distribution characteristics of the metering data, and generate a rolling key sequence that changes with time through a nonlinear update algorithm, in combination with the on-site metering error correction coefficient and the multi-dimensional metering fusion feature matrix. The hash encryption module is used to generate a primary hash message digest using an optimized hash function adapted to floating-point metering data, and combine it with a hash salt value sequence. After a second iterative hash operation controlled by a rolling key sequence, an enhanced hash authentication code is obtained. The hash link module is used to divide the variable transmission time window according to the meter reading cycle of the power industry, establish a bidirectional chain association between the enhanced hash authentication codes of adjacent windows, update the initial value of the rolling key of the next window nonlinearly based on the window number, and construct a closed-loop time-series hash chain. The adaptive packaging module is used to monitor the communication computing power and transmission bandwidth of the metering box in real time, adjust the key iteration number and salt value refresh frequency according to the verification status of the closed-loop time-series hash chain, and generate encrypted metering transmission data packets.
[0006] Preferably, when the fusion feature module performs the following operations: collecting multi-source heterogeneous metering raw data from the power metering box, fusing communication hardware operating parameters, and extracting a multi-dimensional metering fusion feature matrix containing transmission anomaly fluctuation characteristics, it is specifically used for: Collect multi-source heterogeneous metering raw data from the power metering box, including power metering data, event log data, and status data. Synchronously acquire communication hardware operating parameters, including communication hardware operating temperature, communication channel bit error rate, and data transmission retransmission rate; The original multi-source heterogeneous metering data and the communication hardware operating parameters are timestamped and fused to obtain an initial fusion matrix with a unified time reference. The numerical range of each dimension of the data in the initial fusion matrix is adjusted, and the fluctuation amplitude, rate of change and dispersion of each dimension are statistically analyzed to obtain the statistical feature set of each dimension. Based on the statistical feature set, abnormal transmission fluctuation features are identified. These abnormal transmission fluctuation features are then integrated with the adjusted initial fusion matrix as an additional dimension to obtain a multidimensional metrological fusion feature matrix.
[0007] Preferably, when the entropy density generation module determines the temporal entropy value and the spatial correlation entropy value of the transformer area based on the temporal continuity and temporal distribution characteristics of the metering data, it is specifically used for: Extract the collection sequence of measurement data within a continuous time window, statistically analyze the recurrence pattern of different values in the collection sequence, and obtain the time entropy value that characterizes the overall uncertainty of the collection sequence; Obtain the location attribution information corresponding to multiple power metering data in the same area, group the metering data according to the location attribution information, determine the degree of numerical convergence of the data within each group and the degree of numerical dispersion between different groups, so as to obtain spatial distribution characteristic quantities. Based on the spatial distribution characteristics, the statistical dependency between the measurement data and the corresponding transformer area location is evaluated, and the statistical dependency is quantified as the transformer area spatial correlation entropy value.
[0008] Preferably, when the entropy density generation module performs the process of generating a rolling key sequence that varies over time by combining the on-site measurement error correction coefficient and the multi-dimensional measurement fusion feature matrix using a nonlinear update algorithm, it is specifically used for: Obtain the field metering error correction coefficient, which includes the voltage transformer ratio difference correction factor, the current transformer angle difference compensation amount, and the temperature drift suppression coefficient, and combine them to obtain the error correction vector. The error correction vector is coupled with the multidimensional metrological fusion feature matrix for feature concatenation modulation, so that the error correction coefficients are weighted and embedded into each row vector of the feature matrix to obtain the error-corrected fusion feature stream. Obtain the old rolling key state value generated at the end of the previous encryption cycle, perform bit-by-bit nonlinear diffusion permutation of the old rolling key state value and the fused feature stream, and use the feedback mechanism to update the internal state of the key register sequentially to generate the intermediate key state of the current cycle. Based on the intermediate key state, a new key component is generated recursively for each time window using a timestamp-based nonlinear mapping rule. The key components of all time windows are concatenated in the order of generation to obtain a rolling key sequence that dynamically changes with the metering time series.
[0009] Preferably, when the entropy density generation module executes the process of generating new key components by recursively generating them window by window according to the intermediate key state and using a timestamp-based nonlinear mapping rule, and concatenating the key components of all time windows in the generation order to obtain a rolling key sequence that dynamically changes with the metering time series, it is specifically used for: Obtain the intermediate key state of the current time window and the timestamp corresponding to the current window, and split the timestamp into a high-order time period identifier and a low-order time sequence correction identifier. The intermediate key state is cyclically shifted according to the high-order time period identifier to generate a time period adjustment key state; The key state of the time period is adjusted by bit reversing according to the low-order timing correction flag to generate the key component of the current window; The key component of the current window is appended to the end of the generated key component sequence to obtain an updated key component concatenation sequence; The key component of the current window is used as the intermediate key state of the next time window, and the updated key component concatenation sequence is used as the cumulative sequence. The key components of each window are generated recursively window by window and appended to the end of the corresponding cumulative sequence in turn, so as to obtain a rolling key sequence that changes dynamically with the metering time series.
[0010] Preferably, when the hash encryption module generates a primary hash message digest using an optimized hash function adapted to floating-point metering data, combines it with a hash salt value sequence, and performs a secondary iterative hash operation controlled by a rolling key sequence to obtain an enhanced hash authentication code, it is specifically used for: The floating-point measurement data in the multi-dimensional measurement fusion feature matrix is truncated according to the precision threshold, and the effective high-order fields are converted into a normalized byte sequence to obtain a floating-point data byte stream. The floating-point data byte stream is initially mapped using a hash compression function adapted to the distribution characteristics of floating-point values to generate a fixed-length primary hash message digest. The primary hash message digest is then nonlinearly mixed and mapped with the hash salt value sequence to obtain the intermediate state value to be iterated. The intermediate state value is set as the initial chain variable, and the rolling key sequence is used as the round control parameter. The same hash compression function is repeatedly applied to the intermediate state value for a second iteration operation to obtain the target hash value. The target hash value is used as the enhanced hash authentication code.
[0011] Preferably, when the hash link module divides the variable transmission time window according to the meter reading cycle of the power industry and establishes a bidirectional chain association of the enhanced hash authentication codes of adjacent windows, it is specifically used for: The reference time granularity of the meter reading cycle in the power industry is analyzed. Based on the reference time granularity as the basic window span, the start offset and end boundary of the window are adjusted according to the congestion level of the real-time transmission channel and the arrival rate of metering data to generate a non-uniformly divided variable transmission time window sequence. Extract the enhanced hash authentication code of the current window, hash-anchor and bind the enhanced hash authentication code with the enhanced hash authentication code of the previous window, and simultaneously associate it with the enhanced hash authentication code of the subsequent window to establish a bidirectional hash pointer link; The bidirectional hash pointer link is solidified into the hash chain node to obtain a closed-loop chain verification topology in which the front and rear windows verify each other and tampering will lead to breakage.
[0012] Preferably, when the hash link module performs hash anchoring and binding of the enhanced hash authentication code with the enhanced hash authentication code of the forward window, and verification commitment association with the enhanced hash authentication code of the backward window, to construct a bidirectional hash pointer link, it is specifically used for: Extract the hash anchor seed segment from the enhanced hash authentication code of the forward adjacent window, concatenate the enhanced hash authentication code of the current window as the payload to be bound with the hash anchor seed segment, and perform one-way hash compression to generate the forward hash anchor lock value, thus completing the anchor binding with the forward window. Extract the pre-set empty slot of the enhanced hash authentication code of the backward adjacent window, fill the empty slot with the authentication feature substring of the enhanced hash authentication code of the current window, and obtain the backward verification commitment binding value to complete the commitment association with the backward window. The forward hash anchor lock value and the backward verification commitment binding value are merged into a bidirectional hash pointer structure and stored in the extension area of the current window enhanced hash authentication code, thus establishing a bidirectional hash pointer link between the current window and the forward and backward windows.
[0013] Preferably, when the hash link module performs nonlinear iterative updates to the initial value of the next window rolling key based on the window index to construct a closed-loop time-series hash chain, it is specifically used for: Extract the binary bit string corresponding to the window number of the current transmission time window, and perform an XOR operation on the binary bit string and the tail check segment in the enhanced hash authentication code of the current window to expand it and generate a window perturbation vector. Using the window perturbation vector as a rearrangement index, the scroll key bytes of the current window are nonlinearly permuted to obtain the intermediate diffusion key; Obtain the header feature segment from the enhanced hash authentication code in the previous window, and perform bitwise cross-mixing of the header feature segment with the intermediate diffusion key to obtain the closed-loop feedback key; The closed-loop feedback key is used as the initial value of the rolling key for the next transmission time window, and the enhanced hash authentication code of the current window and the enhanced hash authentication code of the next window are linked in a doubly linked manner through a hash pointer to complete the construction of the closed-loop time-series hash chain.
[0014] Preferably, when the adaptive packaging module performs real-time monitoring of the metering box's communication computing power and transmission bandwidth, adjusts the key iteration count and salt refresh frequency according to the verification status of the closed-loop time-series hash chain, and generates encrypted metering transmission data packets, it is specifically used for: The computing load status value and bandwidth occupancy rate of the current communication channel of the metering box are obtained in real time, and the computing load status value and bandwidth occupancy rate are combined into a dynamic sensing vector of communication resources. Read the verification status identifier in the closed-loop time-series hash chain, wherein the verification status identifier includes the integrity verification result of the current window hash chain and the association strength level of adjacent windows; When the verification status indicator indicates that the hash chain integrity is abnormal and the association strength is lower than the preset threshold, the key iteration number and salt value refresh frequency are synchronously increased according to the computing power surplus and bandwidth idleness in the communication resource dynamic sensing vector. When the verification status indicator indicates that the hash chain is complete and the association strength is sufficient, the current key iteration count and salt value refresh frequency remain unchanged; By adjusting the key iteration count and salt value refresh frequency, the current metering data to be transmitted is subjected to a second iteration hash operation and salt value combination to generate an encrypted metering transmission data packet.
[0015] Compared with the prior art, the present invention has the following beneficial effects: This invention integrates multi-source heterogeneous data from electricity metering boxes with communication hardware operating parameters to accurately extract abnormal transmission fluctuation characteristics and construct a multi-dimensional metering fusion feature matrix. It then combines time-series entropy values and transformer area spatial correlation entropy values to drive dynamic generation of rolling keys, effectively improving the randomness and anti-cracking capability of hash encryption keys and ensuring the stability and reliability of the metering data encryption process. The system employs an optimized hash function adapted to floating-point metering data to complete a second-order iterative hash operation, generating a highly secure enhanced hash authentication code. Relying on a variable transmission time window, it constructs a bidirectional closed-loop time-series hash chain, enabling end-to-end verification and traceability of metering data transmission, significantly improving the integrity and tamper resistance of data encryption authentication.
[0016] This invention adaptively adjusts the key iteration count and salt value refresh frequency based on the closed-loop time-series hash chain verification status, optimizing data transmission efficiency while ensuring encryption strength, and adapting to the complex communication environment of power metering scenarios. The system deeply integrates the metering error correction coefficient with the feature matrix to improve the accuracy of metering data before encryption. Through modular collaborative operation, it achieves efficient execution of the encryption process, meeting the high real-time, high security, and high adaptability requirements of encrypted transmission of power metering box data. Attached Figure Description
[0017] Figure 1 This is a system architecture diagram of an energy metering box data encryption system based on a hash algorithm, provided in an embodiment of the present invention. Figure 2 A flowchart illustrating the closed-loop hash chain construction process of a data encryption system for an energy metering box based on a hash algorithm, provided in an embodiment of the present invention. The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments belong to some, but not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “said” and “the” as used in the embodiments of this invention and the appended claims are also intended to include the plural forms, and “multiple” generally includes at least two unless the context clearly indicates otherwise.
[0020] Depending on the context, the word "if" or "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."
[0021] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.
[0022] In practice, the server-side equipment deployed in a hash-based electricity metering box data encryption system may consist of one or more devices. This hash-based electricity metering box data encryption system can be implemented as a business instance, a virtual machine, or hardware devices. For example, it can be implemented as a business instance deployed on one or more devices in a cloud node. Simply put, it can be understood as software deployed on a cloud node, providing a hash-based electricity metering box data encryption system to various user terminals. Alternatively, it can be implemented as a virtual machine deployed on one or more devices in a cloud node, with application software installed to manage various user terminals. Or, it can also be implemented as a server composed of numerous identical or different types of hardware devices, with one or more hardware devices configured to provide a hash-based electricity metering box data encryption system to various user terminals.
[0023] In terms of implementation, the data encryption system for electricity metering boxes based on hash algorithms and the user terminal are mutually compatible. That is, if the data encryption system for electricity metering boxes based on hash algorithms is implemented as an application installed on a cloud service platform, then the user terminal is implemented as a client that establishes a communication connection with the application; or if the data encryption system for electricity metering boxes based on hash algorithms is implemented as a website, then the user terminal is implemented as a webpage; or if the data encryption system for electricity metering boxes based on hash algorithms is implemented as a cloud service platform, then the user terminal is implemented as a mini-program in an instant messaging application.
[0024] like Figure 1 The figure shown is a system architecture diagram of an energy metering box data encryption system based on a hash algorithm provided in an embodiment of the present invention.
[0025] The hash-based data encryption system for electricity metering boxes described in this invention can be installed on a cloud server. In terms of implementation, it can be used as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed into a website. Depending on the functions implemented, the hash-based data encryption system for electricity metering boxes may include a feature fusion module, an entropy encryption generation module, a hash encryption module, a hash link module, and an adaptive packaging module. The modules described in this invention can also be called units, referring to a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.
[0026] In this embodiment of the invention, in a data encryption system for electricity metering boxes based on a hash algorithm, each of the above modules can be implemented independently and can call other modules. This calling can be understood as a module connecting to multiple modules of another type and providing corresponding services to those connected modules. The data encryption system for electricity metering boxes based on a hash algorithm provided by this embodiment of the invention allows for adjustment of the applicability of the system architecture without modifying the program code. This is achieved by adding modules and directly calling them, enabling cluster-based horizontal expansion and flexibly expanding the system. In practical applications, the above modules can be set in the same device or different devices, or in virtual devices, such as service instances in a cloud server.
[0027] The following describes, with reference to specific embodiments, each component and its specific workflow of a data encryption system for electricity metering boxes based on hash algorithms: The fusion feature module is used to collect multi-source heterogeneous metering raw data from the power metering box, fuse communication hardware operating parameters, and extract a multi-dimensional metering fusion feature matrix containing transmission abnormal fluctuation features. In this embodiment of the invention, when the fusion feature module collects multi-source heterogeneous metering raw data from the power metering box, fuses communication hardware operating parameters, and extracts a multi-dimensional metering fusion feature matrix containing transmission anomaly fluctuation characteristics, it is specifically used for: Collect multi-source heterogeneous metering raw data from the power metering box, including power metering data, event log data, and status data. Synchronously acquire communication hardware operating parameters, including communication hardware operating temperature, communication channel bit error rate, and data transmission retransmission rate; The original multi-source heterogeneous metering data and the communication hardware operating parameters are timestamped and fused to obtain an initial fusion matrix with a unified time reference. The numerical range of each dimension of the data in the initial fusion matrix is adjusted, and the fluctuation amplitude, rate of change and dispersion of each dimension are statistically analyzed to obtain the statistical feature set of each dimension. Based on the statistical feature set, abnormal transmission fluctuation features are identified. These abnormal transmission fluctuation features are then integrated with the adjusted initial fusion matrix as an additional dimension to obtain a multidimensional metrological fusion feature matrix.
[0028] The dedicated data acquisition unit in the electricity metering box collects data at a fixed cycle of 1 minute, accurately recording electricity metering data, event log data, and status data. The electricity metering data includes positive active power and real-time voltage and current; the event log data includes details of events such as power outages and parameter modifications; and the status data includes switch on / off status and door opening / closing status. All data is stored in its native format and directly aggregated to form multi-source heterogeneous metering raw data.
[0029] The enclosure has a built-in communication monitoring unit that connects to the communication module in real time to collect data on the communication hardware operating temperature, communication channel bit error rate, and data transmission retransmission rate. The communication hardware operating temperature is the actual measured value of the communication motherboard. The communication channel bit error rate is calculated by dividing the number of erroneous bytes transmitted by the total number of bytes transmitted: for example, if 5 bytes are erroneous in 1000-byte transmission, the bit error rate is 5 / 1000 = 0.005. The data transmission retransmission rate is calculated by dividing the number of retransmissions by the total number of transmissions: for example, if 3 retransmissions occur in 100 transmissions, the retransmission rate is 3 / 100 = 0.03. All parameters are normalized to form the communication hardware operating condition parameters.
[0030] The unified time calibration database is built based on the standard time signal of the power system, storing accurate time nodes for all time periods. Multi-source heterogeneous metering raw data is matched one-to-one with the communication hardware operating parameters to the timestamps of the corresponding acquisition times. These timestamps are arranged according to the principle of consistency, eliminating misaligned data and completing timestamp alignment and fusion. An initial fusion matrix with a unified time reference is generated by arranging the data according to the rule of "time nodes as rows, data types as columns."
[0031] The numerical adaptation rule base is built based on the rated parameters of the electricity metering box and industry standards. The initial fusion matrix data is scaled and calibrated according to the rule base standards to adjust the numerical range. The fluctuation amplitude is calculated as the difference between adjacent time points in the same dimension. The rate of change is calculated as the difference between adjacent data points divided by the data from the previous time period. The dispersion is calculated as the square root of the sum of the squares of the differences between a single set of data and the average value of the corresponding dimension, divided by the total data volume. These three factors are combined to form the statistical feature set for each dimension.
[0032] The abnormal feature comparison model was trained using 100,000 normal transmission samples and 50,000 abnormal transmission samples. The statistical feature set was input into the model, which then compared and filtered according to a preset fixed threshold to identify abnormal transmission fluctuation features. These features were then set as an additional dimension, embedded into the adjusted initial fusion matrix, and the structure was reorganized to finally generate a multi-dimensional econometric fusion feature matrix.
[0033] This step integrates multi-source metering data and communication operating parameters, and through timestamp alignment, numerical normalization, and anomaly feature extraction, constructs a multi-dimensional fusion feature matrix containing transmission fluctuations. This provides accurate feature input for key generation and hash encryption, improves encryption adaptability and anti-interference capabilities, and strengthens the data foundation and security reliability of the overall solution.
[0034] The entropy density generation module is used to determine the time-series entropy value and the spatial correlation entropy value of the transformer area based on the time-series continuity and time-domain distribution characteristics of the metering data, and generate a rolling key sequence that changes with time through a nonlinear update algorithm, in combination with the on-site metering error correction coefficient and the multi-dimensional metering fusion feature matrix. In this embodiment of the invention, when the entropy density generation module determines the temporal entropy value and the spatial correlation entropy value of the transformer area based on the temporal continuity and temporal distribution characteristics of the metering data, it is specifically used for: Extract the collection sequence of measurement data within a continuous time window, statistically analyze the recurrence pattern of different values in the collection sequence, and obtain the time entropy value that characterizes the overall uncertainty of the collection sequence; Obtain the location attribution information corresponding to multiple power metering data in the same area, group the metering data according to the location attribution information, determine the degree of numerical convergence of the data within each group and the degree of numerical dispersion between different groups, so as to obtain spatial distribution characteristic quantities. Based on the spatial distribution characteristics, the statistical dependency between the measurement data and the corresponding transformer area location is evaluated, and the statistical dependency is quantified as the transformer area spatial correlation entropy value.
[0035] When the entropy density generation module generates a rolling key sequence that changes over time by combining the on-site measurement error correction coefficient and the multi-dimensional measurement fusion feature matrix using a nonlinear update algorithm, it is specifically used for: Obtain the field metering error correction coefficient, which includes the voltage transformer ratio difference correction factor, the current transformer angle difference compensation amount, and the temperature drift suppression coefficient, and combine them to obtain the error correction vector. The error correction vector is coupled with the multidimensional metrological fusion feature matrix for feature concatenation modulation, so that the error correction coefficients are weighted and embedded into each row vector of the feature matrix to obtain the error-corrected fusion feature stream. Obtain the old rolling key state value generated at the end of the previous encryption cycle, perform bit-by-bit nonlinear diffusion permutation of the old rolling key state value and the fused feature stream, and use the feedback mechanism to update the internal state of the key register sequentially to generate the intermediate key state of the current cycle. Based on the intermediate key state, a new key component is generated recursively for each time window using a timestamp-based nonlinear mapping rule. The key components of all time windows are concatenated in the order of generation to obtain a rolling key sequence that dynamically changes with the metering time series.
[0036] The entropy density generation module, when executing the process of generating new key components recursively window by window according to the intermediate key state and using a timestamp-based nonlinear mapping rule, and concatenating the key components of all time windows in the generation order to obtain a rolling key sequence that dynamically changes with the metering time series, is specifically used for: Obtain the intermediate key state of the current time window and the timestamp corresponding to the current window, and split the timestamp into a high-order time period identifier and a low-order time sequence correction identifier. The intermediate key state is cyclically shifted according to the high-order time period identifier to generate a time period adjustment key state; The key state of the time period is adjusted by bit reversing according to the low-order timing correction flag to generate the key component of the current window; The key component of the current window is appended to the end of the generated key component sequence to obtain an updated key component concatenation sequence; The key component of the current window is used as the intermediate key state of the next time window, and the updated key component concatenation sequence is used as the cumulative sequence. The key components of each window are generated recursively window by window and appended to the end of the corresponding cumulative sequence in turn, so as to obtain a rolling key sequence that changes dynamically with the metering time series.
[0037] The preset continuous time window is 1 hour and the acquisition interval is 1 minute. All acquired data within this time window are extracted from the measurement data and sorted according to the acquisition time sequence to form an acquisition sequence. The acquisition sequence is traversed one by one, and the frequency of each different value is counted. The proportion of the frequency of each value to the total data volume of the acquisition sequence is calculated. Each proportion is multiplied by its corresponding natural logarithm and summed. The negative of the summation result is the time entropy value, which represents the overall uncertainty of the acquisition sequence.
[0038] Location attribution information is obtained through the transformer area GIS geographic information system. Based on the layout of power lines in the transformer area and the installation coordinates of metering boxes, the system stores the transformer area zone number and installation location information corresponding to each power metering data. Multiple power metering data in the same transformer area are grouped according to the zone number. The average value of each group is calculated. The sum of the squares of the differences between each data in the group and the average value of the group is divided by the total number of data in the group to obtain the degree of convergence of values within the group. The sum of the squares of the differences between the average values of different groups is calculated to obtain the degree of dispersion of values between groups. The degree of convergence within the group and the degree of dispersion between the groups are integrated to form a spatial distribution characteristic quantity.
[0039] Based on spatial distribution characteristics, the statistical dependence between measurement data and corresponding transformer substation locations is assessed by calculating the ratio of intra-group convergence to inter-group dispersion. A larger ratio indicates a stronger statistical dependence between the measurement data and the substation location. The ratio is then substituted into a preset quantization formula: Quantization entropy = ln(ratio × coefficient C + 1), where coefficient C is 0.618. Z-score standardization is then performed to obtain the final spatial correlation entropy value for the transformer substations.
[0040] The error detection unit built into the power metering box collects on-site metering data in real time. Combined with the transformer calibration standards and temperature compensation specifications, the following calculations are made: Voltage transformer ratio error correction factor = (Measured ratio error - Standard ratio error) / Standard ratio error; Current transformer phase angle error compensation = Measured phase angle error - Rated phase angle error; Temperature drift suppression coefficient = 1 / (1 + α × (Current ambient temperature - Standard operating temperature)), where α is 0.0039. These three coefficients are combined in the order of [ratio error correction factor, phase angle error compensation, temperature drift suppression coefficient] to form an error correction vector.
[0041] A fixed weighted coefficient matrix W=[0.4,0.3,0.3] is preset and constructed based on the weights of measurement error influence. The error correction vector and the multidimensional measurement fusion feature matrix are subjected to feature concatenation modulation: each coefficient in the error correction vector is multiplied by the corresponding coefficient in the weighted coefficient matrix, and then the weighted coefficients are embedded one by one into the end of each row vector of the multidimensional measurement fusion feature matrix, so that the error correction coefficients are evenly weighted and embedded into each row vector. After modulation, the error-corrected fused feature stream is obtained.
[0042] The key register has a built-in state storage unit specifically for storing the old rolling key state value generated at the end of the previous encryption cycle. retrieval , and the fused feature flow after error correction Perform bitwise nonlinear diffusion permutation. The specific permutation steps are as follows: First, divide F into two 256-bit halves. and The second step is to calculate the intermediate value. (“ 3" indicates a left circular shift of 3 bits); the third step utilizes the fixed 8×8 S-box pair of the SM4 algorithm. Perform byte substitution to obtain Fourth step, calculation , This is the intermediate key state for the current cycle. A feedback mechanism is used to send the result of each operation back to the key register, updating the internal state of the key register sequentially. After all sequential updates are completed, the intermediate key state for the current cycle is generated.
[0043] The timestamp-based nonlinear mapping rule is constructed based on the encryption period and time window division criteria, with the time window divided into 1-minute units. For each time window, the key components are calculated. ,in, This represents a bit string concatenation operation. This is the 64-bit binary timestamp corresponding to the current window. This is a simplified compression function. The execution method is as follows: input data (256 bits) The key (320 bits total after concatenation with a 64-bit timestamp) is divided into five 64-bit blocks. All blocks are summed and XORed, then modulo 2^64 addition is performed with a fixed constant 0x9E3779B97F4A7C15 to output a single 64-bit key component. These key components generated in all time windows are concatenated in the order of generation to obtain a rolling key sequence that dynamically changes with the metering time series.
[0044] Retrieve the intermediate key state that has been updated, and simultaneously read the standard system timestamp bound to the current runtime window. Following a preset fixed-bit division rule: the complete timestamp data is equally split into two parts, a high-bit 32-bit segment and a low-bit 32-bit segment, directly separating the high-bit segment identifier for distinguishing runtime periods and the low-bit timing correction identifier for calibrating timing order.
[0045] The byte shift execution standard is called in advance based on the time period division standard. This standard is formulated in combination with the operating period interval of the metering business in the distribution area. The high-order time period identifier is read to determine the specific number of shifts and the shift direction. According to the determined shift parameters, the entire intermediate key state is subjected to a directional byte cyclic shift operation. After the shift is completed, the time period adjustment key state is fixed.
[0046] Based on the bit arrangement order stored in the low-order timing correction flag, the flipping order of the bits inside the data is determined. Specifically, the low-order timing correction flag is used as a seed input to a linear feedback shift register to generate a bit mask of the same length as the time period adjustment key state. Then, the time period adjustment key state and the mask are XORed bit by bit to complete the global bit adjustment and stably generate the key component of the current window.
[0047] According to the linear concatenation storage rule of the key sequence, the key component of the current window generated in real time is directly arranged at the end of the key component sequence that has been integrated and arranged. After the data tail append storage operation is completed, a complete and updated key component concatenation sequence is directly formed.
[0048] The key component of the current window obtained from this round of calculation is directly assigned as the intermediate key state required for the calculation of the next adjacent time window. Simultaneously, the concatenated sequence of updated key components is continuously stored as a cumulative sequence in the overall continuous summary record. The same data processing logic is continuously followed to generate and append key components for each remaining time window. After all time window data is processed, it is uniformly integrated to obtain a rolling key sequence that dynamically changes with the metering time series.
[0049] This step, by calculating entropy values in both temporal and spatial dimensions, accurately quantifies the uncertainty and spatial correlation characteristics of metering data, providing a highly random and discriminative entropy base for rolling key generation. This effectively enhances the key's resistance to cracking, solidifies the core foundation of dynamic encryption, and strengthens the overall security and originality of the solution.
[0050] By combining the measurement error correction coefficient with multidimensional fusion characteristics, a dynamic rolling key is generated through nonlinear diffusion permutation and time-series recursion. This allows the key to be updated in real time according to operating conditions and errors, improving key uniqueness and anti-cracking ability. This provides high-security key support for hash encryption and significantly enhances the overall encryption security and originality of the system.
[0051] Based on timestamp splitting, shifting, and bit reversal operations, dynamic key components are generated window by window and recursively concatenated, enabling the rolling key to be updated in real time with the sequence of events. This significantly improves the randomness and anti-cracking ability of the key, providing high-security dynamic key support for hash encryption and significantly enhancing the originality and reliability of the system encryption.
[0052] The hash encryption module is used to generate a primary hash message digest using an optimized hash function adapted to floating-point metering data, and combine it with a hash salt value sequence. After a second iterative hash operation controlled by a rolling key sequence, an enhanced hash authentication code is obtained. In this embodiment of the invention, when the hash encryption module generates a primary hash message digest using an optimized hash function adapted to floating-point metering data, combines it with a hash salt value sequence, and obtains an enhanced hash authentication code through a secondary iterative hash operation controlled by a rolling key sequence, it is specifically used for: The floating-point measurement data in the multi-dimensional measurement fusion feature matrix is truncated according to the precision threshold, and the effective high-order fields are converted into a normalized byte sequence to obtain a floating-point data byte stream. The floating-point data byte stream is initially mapped using a hash compression function adapted to the distribution characteristics of floating-point values to generate a fixed-length primary hash message digest. The primary hash message digest is then nonlinearly mixed and mapped with the hash salt value sequence to obtain the intermediate state value to be iterated. The intermediate state value is set as the initial chain variable, and the rolling key sequence is used as the round control parameter. The same hash compression function is repeatedly applied to the intermediate state value for a second iteration operation to obtain the target hash value. The target hash value is used as the enhanced hash authentication code.
[0053] Based on a preset unified precision threshold, numerical truncation is performed on all floating-point metering data within the multi-dimensional metering fusion feature matrix. Valid high-order data content that meets the metering business judgment standards is retained, while low-order redundant data that exceeds the precision requirements is removed. Then, format conversion is completed according to the unified byte arrangement format in the power metering field. After the format conversion is completed, a standardized and unified floating-point data byte stream is directly generated.
[0054] An improved hash function based on cuckoo hashing is used as a hash compression function adapted to the distribution characteristics of floating-point values. The construction steps are as follows: two basic hash functions are defined. and , It uses the CRC-64 checksum algorithm. For the FNV-1a 64-bit hash algorithm, create a hash bucket array of size 256. Each bucket is initially empty; for floating-point data byte streams The high-order byte segment of each floating-point value Calculate separately and Two hash positions are obtained. and ; Execute the cuckoo insertion strategy: if position p1 is empty, then... Lightweight fingerprint sensor Store the high 8 bits ;if If an element is occupied, it is evicted, and an attempt is made to insert the original element. Repeat this process until all elements have been inserted or the maximum number of evictions (500) has been reached. If any elements fail to be inserted after reaching the maximum number of evictions, a backoff strategy is implemented: the current hash bucket array is... The initial state is used as the initial data. For each element not yet inserted, its hash value is calculated using the standard SHA-256 hash function, and this hash value is appended as an additional data block to the end of the primary hash message digest. Simultaneously, the number and position index of failed elements are recorded to form the extended digest field. The final filled hash bucket array is then used as the initial state. The data is serialized sequentially to form a primary hash message digest of fixed length 256 bytes. If an extended digest field exists, it is appended to the 256 bytes. The final length of the primary hash message digest is 256 bytes plus the length of the extended field. The length of the extended field is determined by the number of failed elements. Each failed element corresponds to a 32-byte hash value and a 4-byte position index. The complete primary hash message digest, i.e., the combination of the 256-byte basic part and the optional extended field, is non-linearly mixed and mapped with a pre-generated 128-bit hash salt value sequence. The complete primary hash message digest is concatenated with the 16-byte salt value and then fed into the standard SHA-256 hash function for one operation. The result (256 bits) is the intermediate state value to be iterated.
[0055] The intermediate state values to be iterated, which have already been prepared, are set as the initial chain variables used throughout the hash iteration operation. The rolling key sequence, which changes dynamically in real time throughout the process, is used as the sole control parameter for the number of iteration rounds and the operation rhythm. Each key component in the rolling key sequence determines the additional input to the compression function in one iteration. Specifically, for the... In the first iteration, the current chain variable is compared with the rolling key sequence. The concatenated components are input into the SHA-256 compression function, and the output serves as the chain variable for the next round. The iteration round is determined according to the length of the rolling key sequence (i.e., the number of key components), and the same hash compression function is repeatedly called to continuously perform iterative compression operations on the initial chain variable. After all specified rounds of operations are completed, the final target hash value is output, and this target hash value is directly used as the enhanced hash authentication code for encryption.
[0056] This step optimizes the hashing process for floating-point measurement data. First, it extracts the valid fields to avoid precision loss. Then, it combines the hash salt value and the rolling key to complete a second iteration of hashing, generating a highly collision-resistant enhanced hash authentication code. This improves data authentication security and provides a reliable foundation for subsequent hash chain construction.
[0057] The hash link module is used to divide the variable transmission time window according to the meter reading cycle of the power industry, establish a bidirectional chain association between the enhanced hash authentication codes of adjacent windows, update the initial value of the rolling key of the next window nonlinearly based on the window number, and construct a closed-loop time-series hash chain. In this embodiment of the invention, when the hash link module divides the variable transmission time window according to the meter reading cycle of the power industry and establishes a bidirectional chain association of the enhanced hash authentication codes of adjacent windows, it is specifically used for: The reference time granularity of the meter reading cycle in the power industry is analyzed. Based on the reference time granularity as the basic window span, the start offset and end boundary of the window are adjusted according to the congestion level of the real-time transmission channel and the arrival rate of metering data to generate a non-uniformly divided variable transmission time window sequence. Extract the enhanced hash authentication code of the current window, hash-anchor and bind the enhanced hash authentication code with the enhanced hash authentication code of the previous window, and simultaneously associate it with the enhanced hash authentication code of the subsequent window to establish a bidirectional hash pointer link; The bidirectional hash pointer link is solidified into the hash chain node to obtain a closed-loop chain verification topology in which the front and rear windows verify each other and tampering will lead to breakage.
[0058] When the hash link module performs hash anchoring and binding of the enhanced hash authentication code with the enhanced hash authentication code of the forward window, and simultaneously associates it with the enhanced hash authentication code of the backward window to construct a bidirectional hash pointer link, it is specifically used for: Extract the hash anchor seed segment from the enhanced hash authentication code of the forward adjacent window, concatenate the enhanced hash authentication code of the current window as the payload to be bound with the hash anchor seed segment, and perform one-way hash compression to generate the forward hash anchor lock value, thus completing the anchor binding with the forward window. Extract the pre-set empty slot of the enhanced hash authentication code of the backward adjacent window, fill the empty slot with the authentication feature substring of the enhanced hash authentication code of the current window, and obtain the backward verification commitment binding value to complete the commitment association with the backward window. The forward hash anchor lock value and the backward verification commitment binding value are merged into a bidirectional hash pointer structure and stored in the extension area of the current window enhanced hash authentication code, thus establishing a bidirectional hash pointer link between the current window and the forward and backward windows.
[0059] When the hash link module performs nonlinear iterative updates to the initial value of the next window rolling key based on the window index to construct a closed-loop time-series hash chain, it is specifically used for: Extract the binary bit string corresponding to the window number of the current transmission time window, and perform an XOR operation on the binary bit string and the tail check segment in the enhanced hash authentication code of the current window to expand it and generate a window perturbation vector. Using the window perturbation vector as a rearrangement index, the scroll key bytes of the current window are nonlinearly permuted to obtain the intermediate diffusion key; Obtain the header feature segment from the enhanced hash authentication code in the previous window, and perform bitwise cross-mixing of the header feature segment with the intermediate diffusion key to obtain the closed-loop feedback key; The closed-loop feedback key is used as the initial value of the rolling key for the next transmission time window, and the enhanced hash authentication code of the current window and the enhanced hash authentication code of the next window are linked in a doubly linked manner through a hash pointer to complete the construction of the closed-loop time-series hash chain.
[0060] The established standard for meter reading cycles in the power industry is analyzed, and a base time granularity of 15 minutes is determined. This serves as the basis for setting the basic window span. Real-time acquisition of channel transmission delay (in milliseconds) and packet loss rate (percentage) is used to determine channel congestion status. The number of metering data uploaded per unit time (1 minute) is counted to determine the data arrival rate (data entries / minute). The window start offset and end boundary are adjusted synchronously according to the following rules: if the transmission delay > 200ms or the packet loss rate > 5%, the window span is extended by 20%; if the data arrival rate > 100 data entries / minute, the window span is shortened by 10%. Through this adjustment, a variable transmission time window sequence with varying spacing is generated.
[0061] All metering data within a single variable transmission time window is collected, and the data content is organized according to time sequence. A fixed hash operation (e.g., SHA-256) is then performed to generate corresponding values, thereby determining the current window's unique enhanced hash authentication code. This authentication code is combined with the enhanced hash authentication code of the preceding adjacent window to complete hash anchoring: calculate the forward lock value = SHA-256(previous window authentication code || current window authentication code). Then, a numerical pairing operation is performed with the enhanced hash authentication code of the following adjacent window to achieve verification commitment association: the middle 64 bits of the current window authentication code are filled into the reserved empty slot of the following window. A complete bidirectional hash pointer link is built based on these two association methods, enabling bidirectional matching of hash information between adjacent windows within the link.
[0062] The complete data of the established bidirectional hash pointer link is uniformly entered into the pre-built hash chain node storage area to complete the data solidification process. The pre-built storage area is divided into independent storage intervals according to the window sequence number and a fixed storage format is defined. Finally, a closed-loop chain verification topology is formed, which enables mutual verification between adjacent windows and the entire associated link to be disconnected and fail if any enhanced hash authentication code is changed.
[0063] The enhanced hash authentication code of the preceding adjacent window is retrieved, and according to the fixed truncation rules set during module initialization based on the power metering encryption specification: bits 1 to 128 of the enhanced hash authentication code of the preceding window (total length 256 bits) are taken as the hash anchor seed segment; bits 129 to 256 of the enhanced hash authentication code of the current window are taken as the payload to be bound; bits 241 to 256 of the enhanced hash authentication code of the current window are taken as the tail check segment; and bits 1 to 128 of the enhanced hash authentication code of the previous window are taken as the header feature segment. These truncation rules are fixed by configuration parameters at system startup and remain unchanged throughout the entire operating cycle. The enhanced hash authentication code of the current window is used as the payload to be bound, concatenated with the seed segment, and then compressed bit by bit using SHA-256 one-way hash operation to output a 256-bit forward hash anchor lock value, completing the anchor binding with the preceding window. For example, if the forward window enhanced hash authentication code is "12345678" (hexadecimal), the first 16 bytes (i.e. 128 bits) are truncated according to the rules as the seed segment, and the current window authentication code "9876..." is used as the payload. After concatenation, the forward hash anchor lock value is obtained by SHA-256 compression.
[0064] The enhanced hash authentication code structure for the backward adjacent window is divided according to the encoding partition format arranged during the module initialization phase. A preset empty slot for verification commitment is extracted at a fixed position. This empty slot is the reserved last 64-bit blank encoding area. An authentication feature substring is extracted from the fixed position (the middle 64 bits) of the current window's enhanced hash authentication code, and completely filled into the aforementioned empty slot. The encoding structure is then integrated to generate the backward verification commitment binding value, completing the commitment association with the backward window. For example, if the last 8 bytes of the backward window authentication code are reserved as empty slots, the middle 8-byte feature substring "5678..." of the current window authentication code is extracted and filled in, forming the backward verification commitment binding value.
[0065] The generated forward hash anchor lock value (256 bits) and backward verification commitment binding value (64 bits) are integrated in a fixed order (forward lock value first, backward commitment value last) to form a bidirectional hash pointer structure with a total length of 320 bits. A dedicated storage space is allocated within the extended area (the 320-bit area appended to the end of the authentication code) synchronously allocated during the generation of the current window enhanced hash authentication code. The entire structure is written into the extended area, establishing a bidirectional hash pointer link between the current window and the forward and backward windows. A specific closed-loop verification method is as follows: at the receiving end, the forward lock value and the backward commitment value are checked simultaneously. If the forward lock value calculated using the current window authentication code does not match the stored forward lock value, or if the feature substring in the backward commitment slot does not match the authentication code of the next window, it can be determined that the hash chain has been broken and the data has been tampered with.
[0066] Extract the window number of the current transmission time window and convert it into a fixed-length 16-bit binary string. Simultaneously, extract the tail check segment from the enhanced hash authentication code of the current window, at a fixed position set during module initialization (the last 16 bits of the authentication code). Perform a bitwise XOR operation between the binary string and the tail check segment: the result is 0 for the same value and 1 for different values. The complete bit string obtained after the operation is the window perturbation vector. For example, if the window number is 3, corresponding to the binary string "0011", and the tail check segment is "1100", the XOR operation will result in the window perturbation vector "1111".
[0067] The generated window perturbation vector is used as the rearrangement index. All bytes of the current window rolling key are non-linearly permuted according to the bit values corresponding to the index: the rolling key bytes are numbered in their original order (0,1,2,...,L-1), and the position of adjacent bytes is determined by the value (0 or 1) of each bit in the window perturbation vector. Specifically, each bit of the perturbation vector is traversed; if a bit is 1, the corresponding byte in the key byte is swapped with the byte in the next position; if it is 0, it remains unchanged. The rearranged key is the intermediate diffusion key. For example, if the current rolling key byte sequence is [0x12,0x34,0x56,0x78] and the window perturbation vector is [1,1,1,1], then the intermediate diffusion key is obtained by swapping the bytes sequentially: [0x34,0x12,0x78,0x56].
[0068] Retrieve the enhanced hash authentication code from the previous window and extract its header feature segment according to a preset fixed rule (taking the first 16 bytes of the authentication code). This preset rule is set during module initialization according to the power metering encryption standard, specifying the number of bits to be extracted and the starting position. Alternately interleave the extracted header feature segment with each bit of the intermediate diffusion key: first take the first byte of the header feature segment, then the first byte of the intermediate diffusion key, then the second byte of the header feature segment, and so on, mixing bit by bit to form a new key string. This key string is the closed-loop feedback key.
[0069] The generated closed-loop feedback key is directly assigned as the initial value of the rolling key for the next transmission time window. Simultaneously, the enhanced hash authentication codes for the current window and the next window are extracted, and a doubly linked association is established between them using hash pointers: the pointer value is calculated as SHA-256(current window authentication code || next window authentication code), and this pointer value is stored in the extension areas of the two windows respectively. That is, the current window hash pointer points to the next window authentication code, and the next window hash pointer points to the current window authentication code, thus completing the construction of the closed-loop time-series hash chain.
[0070] This step generates a variable time window based on the meter reading cycle and real-time communication status. By constructing a closed-loop hash chain through bidirectional hash anchoring and commitment association, the entire data transmission process is verifiable and tamper-proof, which greatly improves the integrity of authentication and resistance to tampering, and provides a stable and reliable chain-like security guarantee for the system.
[0071] By binding forward hash anchoring with backward verification commitment, a bidirectional hash pointer link is constructed, strongly associating the authentication codes of adjacent windows. This ensures that the link breaks upon data tampering, significantly improving tamper resistance and traceability, and perfecting the closed-loop hash verification system.
[0072] A perturbation vector is generated by using the window sequence number and hash verification segment. The initial value of the rolling key is iteratively updated, and a closed-loop time-series hash chain is constructed by combining bidirectional hash pointers to realize dynamic binding of key and hash authentication, thereby improving the link's resistance to tampering.
[0073] The adaptive packaging module is used to monitor the communication computing power and transmission bandwidth of the metering box in real time, adjust the key iteration number and salt value refresh frequency according to the verification status of the closed-loop time-series hash chain, and generate encrypted metering transmission data packets.
[0074] In this embodiment of the invention, when the adaptive packaging module performs real-time monitoring of the metering box's communication computing power and transmission bandwidth, adjusts the key iteration count and salt value refresh frequency according to the verification status of the closed-loop time-series hash chain, and generates encrypted metering transmission data packets, it is specifically used for: The computing load status value and bandwidth occupancy rate of the current communication channel of the metering box are obtained in real time, and the computing load status value and bandwidth occupancy rate are combined into a dynamic sensing vector of communication resources. Read the verification status identifier in the closed-loop time-series hash chain, wherein the verification status identifier includes the integrity verification result of the current window hash chain and the association strength level of adjacent windows; When the verification status indicator indicates that the hash chain integrity is abnormal and the association strength is lower than the preset threshold, the key iteration number and salt value refresh frequency are synchronously increased according to the computing power surplus and bandwidth idleness in the communication resource dynamic sensing vector. When the verification status indicator indicates that the hash chain is complete and the association strength is sufficient, the current key iteration count and salt value refresh frequency remain unchanged; By adjusting the key iteration count and salt value refresh frequency, the current metering data to be transmitted is subjected to a second iteration hash operation and salt value combination to generate an encrypted metering transmission data packet.
[0075] The CPU utilization rate of the communication processing unit of the metering box is collected in real time to obtain the computing power load status value L. The ratio of the occupied bandwidth of the communication channel to the total bandwidth is calculated synchronously to determine the bandwidth utilization rate B. The two are integrated in the vector format [L,B] to generate a dynamic sensing vector of communication resources. For example, if the computing power load status value is 60% and the bandwidth utilization rate is 40%, the integrated vector is [60%,40%].
[0076] Retrieve the state identification field embedded in the closed-loop time-series hash chain. This field is written synchronously when the hash chain is built and contains two items: the integrity verification result of the current window hash chain (value is "complete" or "abnormal"), and the association strength level of adjacent windows (value range 0~1, calculated by the bidirectional pointer matching degree, matching degree = number of matched bits / total number of bits). Together, they constitute the verification state identifier.
[0077] The preset thresholds are pre-entered according to the power metering safety standards: the integrity threshold is "complete", and the association strength threshold is T=0.7. When the verification status indicator shows that the hash chain integrity is "abnormal" and the association strength level is <0.7, the encryption strength adjustment mechanism is triggered. Based on the communication resource dynamic perception vector V=[L,B], the following quantitative adjustment strategy is executed: if L<30% and B<40%, it is determined to be "sufficient resources", and the key iteration count is increased from the default 10 times to 30 times, and the salt value refresh frequency is increased from once every 10 minutes to once every 2 minutes; if 30%≤L≤60% and 40%≤B≤70%, it is determined to be "moderate resources", and the key iteration count is increased to 20 times, and the salt value refresh frequency is increased to once every 5 minutes; in other cases (scarce resources), the key iteration count is increased to 15 times, and the salt value refresh frequency is increased to once every 8 minutes.
[0078] When the verification status indicator shows that the hash chain integrity is "complete" and the association strength level is ≥0.7, the system is determined to be in a safe and stable state. At this time, the current key iteration count (e.g., 10 times) and salt value refresh frequency (e.g., once every 10 minutes) remain unchanged, and no parameter adjustments are made.
[0079] The current metering data to be transmitted is re-hashd using a second iteration based on the adjusted key iteration count. The specific number of second iterations is the adjusted key iteration count. Salt values for the corresponding time period are retrieved from the local salt pool according to the salt value refresh frequency: the salt pool pre-generates 1024 random 128-bit salt values, used in a circular queue; the salt value generation algorithm is as follows: using the system entropy source to call a cryptographically secure pseudo-random number generator, such as the Linux kernel's getrandom system call or Windows' BCryptGenRandom function, to generate 1024 independent 128-bit random numbers, which are sequentially stored in non-volatile memory, and a current index pointer is maintained; each time a salt value is needed, the salt value pointed to by the current index is retrieved, and then the index pointer is cyclically incremented to 1024. The salt value is combined with the data, and a hash operation is performed to encrypt and encapsulate the metering data, ultimately generating an encrypted metering transmission data packet.
[0080] This step involves real-time sensing of communication computing power and bandwidth, adaptively adjusting encryption parameters based on hash chain verification status, strengthening encryption when security is insufficient, maintaining efficiency when the status is stable, balancing security and smooth transmission, and adapting to complex metering communication scenarios.
[0081] like Figure 2 The diagram shows a sub-flowchart of a closed-loop hash chain construction method for an electricity metering box data encryption system based on a hash algorithm, provided in an embodiment of the present invention. The closed-loop hash chain divides variable transmission time windows according to the electricity meter reading cycle. It extracts the enhanced hash authentication code of the current window, performs hash concatenation and compression with the authentication codes of the preceding adjacent windows, generates a forward anchoring lock value to complete the forward binding, and simultaneously fills the feature substring of the current authentication code into the reserved verification commitment slot of the backward window to form a backward binding value. This constructs a bidirectional hash pointer link and solidifies it into a hash chain node. Subsequently, it performs an XOR operation between the current window sequence number and the tail verification segment of the enhanced hash authentication code to obtain a perturbation vector. This perturbation vector is used to perform a nonlinear permutation on the current rolling key, and then cross-mixes it with the head feature segment of the authentication code of the previous window to generate a closed-loop feedback key. This key is used as the initial value of the rolling key for the next window, ultimately realizing bidirectional association of authentication codes between adjacent windows and iterative key updates window by window, forming a self-verifying and tamper-proof closed-loop time-series hash chain.
[0082] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0083] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A data encryption system for an electricity metering box based on a hash algorithm, characterized in that, The system includes a feature fusion module, an entropy density generation module, a hash encryption module, a hash link module, and an adaptive packaging module, wherein: The fusion feature module is used to collect multi-source heterogeneous metering raw data from the power metering box, fuse communication hardware operating parameters, and extract a multi-dimensional metering fusion feature matrix containing transmission abnormal fluctuation features. The entropy density generation module is used to determine the time-series entropy value and the spatial correlation entropy value of the transformer area based on the time-series continuity and time-domain distribution characteristics of the metering data, and generate a rolling key sequence that changes with time through a nonlinear update algorithm, in combination with the on-site metering error correction coefficient and the multi-dimensional metering fusion feature matrix. The hash encryption module is used to generate a primary hash message digest using an optimized hash function adapted to floating-point metering data, and combine it with a hash salt value sequence. After a second iterative hash operation controlled by a rolling key sequence, an enhanced hash authentication code is obtained. The hash link module is used to divide the variable transmission time window according to the meter reading cycle of the power industry, establish a bidirectional chain association between the enhanced hash authentication codes of adjacent windows, update the initial value of the rolling key of the next window nonlinearly based on the window number, and construct a closed-loop time-series hash chain. The adaptive packaging module is used to monitor the communication computing power and transmission bandwidth of the metering box in real time, adjust the key iteration number and salt value refresh frequency according to the verification status of the closed-loop time-series hash chain, and generate encrypted metering transmission data packets.
2. The data encryption system for an energy metering box based on a hash algorithm as described in claim 1, characterized in that, When the fusion feature module collects multi-source heterogeneous raw metering data from the power metering box, fuses communication hardware operating parameters, and extracts a multi-dimensional metering fusion feature matrix containing transmission anomaly fluctuation characteristics, it is specifically used for: Collect multi-source heterogeneous metering raw data from the power metering box, including power metering data, event log data, and status data. Synchronously acquire communication hardware operating parameters, including communication hardware operating temperature, communication channel bit error rate, and data transmission retransmission rate; The original multi-source heterogeneous metering data and the communication hardware operating parameters are timestamped and fused to obtain an initial fusion matrix with a unified time reference. The numerical range of each dimension of the data in the initial fusion matrix is adjusted, and the fluctuation amplitude, rate of change and dispersion of each dimension are statistically analyzed to obtain the statistical feature set of each dimension. Based on the statistical feature set, abnormal transmission fluctuation features are identified. These abnormal transmission fluctuation features are then integrated with the adjusted initial fusion matrix as an additional dimension to obtain a multidimensional metrological fusion feature matrix.
3. The data encryption system for an energy metering box based on a hash algorithm as described in claim 1, characterized in that, The entropy density generation module, when determining the temporal entropy value and the spatial correlation entropy value of the transformer area based on the temporal continuity and temporal distribution characteristics of the metering data, is specifically used for: Extract the collection sequence of measurement data within a continuous time window, statistically analyze the recurrence pattern of different values in the collection sequence, and obtain the time entropy value that characterizes the overall uncertainty of the collection sequence; Obtain the location attribution information corresponding to multiple power metering data in the same area, group the metering data according to the location attribution information, determine the degree of numerical convergence of the data within each group and the degree of numerical dispersion between different groups, so as to obtain spatial distribution characteristic quantities. Based on the spatial distribution characteristics, the statistical dependency between the measurement data and the corresponding transformer area location is evaluated, and the statistical dependency is quantified as the transformer area spatial correlation entropy value.
4. The data encryption system for an energy metering box based on a hash algorithm as described in claim 3, characterized in that, When the entropy density generation module generates a rolling key sequence that changes over time by combining the on-site measurement error correction coefficient and the multi-dimensional measurement fusion feature matrix using a nonlinear update algorithm, it is specifically used for: Obtain the field metering error correction coefficient, which includes the voltage transformer ratio difference correction factor, the current transformer angle difference compensation amount, and the temperature drift suppression coefficient, and combine them to obtain the error correction vector. The error correction vector is coupled with the multidimensional metrological fusion feature matrix for feature concatenation modulation, so that the error correction coefficients are weighted and embedded into each row vector of the feature matrix to obtain the error-corrected fusion feature stream. Obtain the old rolling key state value generated at the end of the previous encryption cycle, perform bit-by-bit nonlinear diffusion permutation of the old rolling key state value and the fused feature stream, and use the feedback mechanism to update the internal state of the key register sequentially to generate the intermediate key state of the current cycle. Based on the intermediate key state, a new key component is generated recursively for each time window using a timestamp-based nonlinear mapping rule. The key components of all time windows are concatenated in the order of generation to obtain a rolling key sequence that dynamically changes with the metering time series.
5. The data encryption system for an energy metering box based on a hash algorithm as described in claim 4, characterized in that, The entropy density generation module, when executing the process of generating new key components recursively window by window according to the intermediate key state and using a timestamp-based nonlinear mapping rule, and concatenating the key components of all time windows in the generation order to obtain a rolling key sequence that dynamically changes with the metering time series, is specifically used for: Obtain the intermediate key state of the current time window and the timestamp corresponding to the current window, and split the timestamp into a high-order time period identifier and a low-order time sequence correction identifier. The intermediate key state is cyclically shifted according to the high-order time period identifier to generate a time period adjustment key state; The key state of the time period is adjusted by bit reversing according to the low-order timing correction flag to generate the key component of the current window; The key component of the current window is appended to the end of the generated key component sequence to obtain an updated key component concatenation sequence; The key component of the current window is used as the intermediate key state of the next time window, and the updated key component concatenation sequence is used as the cumulative sequence. The key components of each window are generated recursively window by window and appended to the end of the corresponding cumulative sequence in turn, so as to obtain a rolling key sequence that changes dynamically with the metering time series.
6. The data encryption system for an energy metering box based on a hash algorithm as described in claim 1, characterized in that, The hash encryption module, when generating a primary hash message digest using an optimized hash function adapted to floating-point quantitative data, combining it with a hash salt value sequence, and obtaining an enhanced hash authentication code through a secondary iterative hash operation controlled by a rolling key sequence, is specifically used for: The floating-point measurement data in the multi-dimensional measurement fusion feature matrix is truncated according to the precision threshold, and the effective high-order fields are converted into a normalized byte sequence to obtain a floating-point data byte stream; The floating-point data byte stream is initially mapped using a hash compression function adapted to the distribution characteristics of floating-point values to generate a fixed-length primary hash message digest. The primary hash message digest is then nonlinearly mixed and mapped with the hash salt value sequence to obtain the intermediate state value to be iterated. The intermediate state value is set as the initial chain variable, and the rolling key sequence is used as the round control parameter. The same hash compression function is repeatedly applied to the intermediate state value for a second iteration operation to obtain the target hash value. The target hash value is used as the enhanced hash authentication code.
7. The data encryption system for an energy metering box based on a hash algorithm as described in claim 1, characterized in that, When the hash link module executes the process of dividing variable transmission time windows according to the power industry's meter reading cycle and establishing a bidirectional chain association between the enhanced hash authentication codes of adjacent windows, it is specifically used for: The reference time granularity of the meter reading cycle in the power industry is analyzed. Based on the reference time granularity as the basic window span, the start offset and end boundary of the window are adjusted according to the congestion level of the real-time transmission channel and the arrival rate of metering data to generate a non-uniformly divided variable transmission time window sequence. Extract the enhanced hash authentication code of the current window, hash-anchor and bind the enhanced hash authentication code with the enhanced hash authentication code of the previous window, and simultaneously associate it with the enhanced hash authentication code of the subsequent window to establish a bidirectional hash pointer link; The bidirectional hash pointer link is solidified into the hash chain node to obtain a closed-loop chain verification topology in which the front and rear windows verify each other and tampering leads to breakage.
8. The data encryption system for an energy metering box based on a hash algorithm as described in claim 7, characterized in that, When the hash link module performs hash anchoring and binding of the enhanced hash authentication code with the enhanced hash authentication code of the forward window, and verification commitment association with the enhanced hash authentication code of the backward window, to construct a bidirectional hash pointer link, it is specifically used for: Extract the hash anchor seed segment from the enhanced hash authentication code of the forward adjacent window, concatenate the enhanced hash authentication code of the current window as the payload to be bound with the hash anchor seed segment, and perform one-way hash compression to generate the forward hash anchor lock value, thus completing the anchor binding with the forward window. Extract the pre-set empty slot of the enhanced hash authentication code of the backward adjacent window, fill the empty slot with the authentication feature substring of the enhanced hash authentication code of the current window, and obtain the backward verification commitment binding value to complete the commitment association with the backward window. The forward hash anchor lock value and the backward verification commitment binding value are merged into a bidirectional hash pointer structure and stored in the extension area of the current window enhanced hash authentication code, thus establishing a bidirectional hash pointer link between the current window and the forward and backward windows.
9. A data encryption system for an energy metering box based on a hash algorithm as described in claim 7, characterized in that, When the hash link module performs nonlinear iterative updates to the initial value of the next window rolling key based on the window index to construct a closed-loop time-series hash chain, it is specifically used for: Extract the binary bit string corresponding to the window number of the current transmission time window, and perform an XOR operation on the binary bit string and the tail check segment in the enhanced hash authentication code of the current window to expand it and generate a window perturbation vector. Using the window perturbation vector as a rearrangement index, the scroll key bytes of the current window are nonlinearly permuted to obtain the intermediate diffusion key; Obtain the header feature segment from the enhanced hash authentication code in the previous window, and perform bitwise cross-mixing of the header feature segment with the intermediate diffusion key to obtain the closed-loop feedback key; The closed-loop feedback key is used as the initial value of the rolling key for the next transmission time window, and the enhanced hash authentication code of the current window and the enhanced hash authentication code of the next window are linked in a doubly linked manner through a hash pointer to complete the construction of the closed-loop time-series hash chain.
10. A data encryption system for an energy metering box based on a hash algorithm as described in claim 1, characterized in that, The adaptive packaging module, when performing real-time monitoring of the metering box's communication computing power and transmission bandwidth, adjusting the key iteration count and salt value refresh frequency based on the verification status of the closed-loop time-series hash chain, and generating encrypted metering transmission data packets, is specifically used for: The computing load status value and bandwidth occupancy rate of the current communication channel of the metering box are obtained in real time, and the computing load status value and bandwidth occupancy rate are combined into a dynamic sensing vector of communication resources. Read the verification status identifier in the closed-loop time-series hash chain, wherein the verification status identifier includes the integrity verification result of the current window hash chain and the association strength level of adjacent windows; When the verification status indicator indicates that the hash chain integrity is abnormal and the association strength is lower than the preset threshold, the key iteration number and salt value refresh frequency are synchronously increased according to the computing power surplus and bandwidth idleness in the communication resource dynamic sensing vector. When the verification status indicator indicates that the hash chain is complete and the association strength is sufficient, the current key iteration count and salt value refresh frequency remain unchanged; By adjusting the key iteration count and salt value refresh frequency, the current metering data to be transmitted is subjected to a second iteration hash operation and salt value combination to generate an encrypted metering transmission data packet.