METHOD FOR VALIDATION OF A MULTIPLE FLOW FOR ALLOCATION OF ENERGY OR ENERGY MATERIAL
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- VOLTERRES
- Filing Date
- 2020-03-13
- Publication Date
- 2026-05-06
Description
[0001] The present invention relates to methods for validating a multi-flow allocation of energy or energetic matter.
[0002] In the following, the term "actor network" refers to a set of N actors, also called nodes, capable of producing, consuming, or storing energy, and targeted by the multi-flow allocation. These actors are assumed to be connected to each other by a physical energy transport and / or distribution network.
[0003] "Energy allocation data" refers to a virtual value representing a quantity of energy received, produced or stored by one of the network actors.
[0004] The term "multiflow" refers to a multiflow within a time graph, that is, a formal representation of the virtual flows of energy or energetic matter of potentially different natures between nodes in the network of actors. This multiflow includes coefficients that can be presented, for example, in the form of tables, weighted graphs, or weighted path lists.
[0005] "Green energy" refers to energy that has been produced from renewable energy sources such as hydroelectric, wind, solar, geothermal, wave or tidal power, or from biomass.
[0006] "Green energy material" refers to materials derived from biomass.
[0007] The term “green energy supplier” refers to an actor supplying energy or energy materials that provides its customers with energy or energy materials, at least part of which is green energy or energy materials. technical field
[0008] More and more consumers want to increase the share of green energy in their energy consumption. To meet this need, they are purchasing energy from suppliers who present themselves as green energy providers.
[0009] This phenomenon is also observed for energy sources, such as gas. Consumers are seeking to increase the share of energy derived from biomass.
[0010] For a consumer to determine whether a green energy supplier is meeting its promised service quality, they need to know the proportion of green energy or energy source in the total energy or energy source received. They may also want to know certain characteristics of the energy sources used by that supplier, in order to favor, for example, local production or a specific type of production.
[0011] Conversely, some green energy producers need to verify the destination of their production. This is the case, for example, for producers who primarily want to supply consumers located in a nearby geographical area. The role of an energy or energy material supplier is to purchase all or part of the energy or energy material production from producers and then resell it to consumers. A portion of the energy or energy material delivered to the consumer may be green energy or energy material. However, in some countries, the proportion of green energy or energy material is not the majority of total energy or energy material production. Green energy or energy material suppliers therefore need to certify that the energy they have supplied to consumers is indeed green. Previous techniques
[0012] Guarantees of Origin (GOs), established by European Directive 2009 / 28 / EC and defined by Article R. 314-53 of the French Energy Code, are electronic documents used solely to prove to the end customer that a specific share or quantity of energy has been produced from renewable sources or through cogeneration. GOs are managed through a centralized registry maintained by a company and do not easily guarantee that production occurred simultaneously with consumption or that production is local.
[0013] Application WO 2017 / 199053 concerns a system that allows an end consumer to verify that the energy they have purchased is indeed green. To achieve this, energy units are linked to energy tokens produced by a blockchain. Such a system is relatively restrictive and difficult to implement on a large scale, with a large number of different producers. Description of the invention
[0014] The invention aims to provide a method which allows a supplier of green energy or energy material to have the actors of a network validated, without necessarily involving a trusted third party, that the quality of service is indeed that promised, and in particular allows to certify, over a large number of short time steps, that a supplier of green energy or energy material has not sold more green energy or energy material than it has bought. Summary of the invention
[0015] The invention achieves this goal through a method for validating a multiflow allocation of energy or energetic matter (F), this multiflow comprising coefficients corresponding to a quantity of energy or energetic matter of nature Q q allocated to a virtual flow between nodes N i and N j of the network of actors at different times, this quantity of energy or energetic matter having been produced, stored, released from storage and / or consumed within the network of actors, this method comprising the steps, for a given node N i: of encrypting at least the coefficients of the multiflow involving this node to obtain encrypted data, of publishing, via a computer network, the encrypted data so as to allow each node N i to send back a validation message certifying compliance with a predefined condition between the data of the multiflow F and an actual value of production, stock level or consumption observed at the level of node N i, recording, in a database, the validation messages sent by the nodes of the network of actors so as to allow the validation of the coefficients of the multiflow.
[0016] The invention allows network participants to validate that the quality of service is indeed that promised by the energy supplier. Not all nodes necessarily need to send a validation message for the multiflow to be validated. The advantage of this process is that it is easily implemented on a large scale because it does not require the installation of dedicated equipment at network participants' premises, and it is implemented on a blockchain. blockchain ) existing public blockchain and that it requires only a limited number of transactions in that blockchain (for example, one per day or one per month) regardless of the quantities of energy or energy-producing materials exchanged. Furthermore, it ensures the confidentiality of production, consumption, storage, and / or destocking data for network participants.
[0017] Thus, for example, a given producer or consumer will not know what another producer or consumer has produced, consumed, stored, or destocked, and vice versa. The publication of encrypted data can be done by posting it on a server without access restrictions, so that this encrypted data is accessible, for example, via the internet, from anywhere in the world to anyone who connects to the server.
[0018] Publication can be done on a distributed ledger, in particular a blockchain-based ledger.
[0019] The step of publishing on a distributed ledger ensures the integrity and authenticity of the {F} file, which groups the encrypted data of the multi-flow of energy or energy material allocation, which has been validated.
[0020] Access to published encrypted data may be subject to access restrictions, for example, the entry of a username and password and / or IP address recognition.
[0021] Alternatively, publication is carried out by automatically sending encrypted data to a predefined address given by the actor wishing to receive this information, by a PUSH type notification or by email.
[0022] The encryption step may be preceded by a step of calculating the multiflow of energy or energetic matter allocation F, this calculation may be carried out by a mathematical optimization method, in particular by application of a flow optimization algorithm in graphs or, more generally, by a linear or quadratic programming algorithm, in integers or not, or by approximate, heuristic or metaheuristic algorithms.
[0023] The calculation of the multiflow of energy or energy material allocation makes it possible to assign a value to each of the energy exchanges between the different nodes, in the general case where the energy flows in the physical networks are not precisely known.
[0024] This multi-flow model is calculated to meet the service quality requirements of various stakeholders. The flows listed in the multi-flow model are not necessarily actual flows on the electrical grid, but rather virtual flows intended to demonstrate that the desired service quality is achieved. However, they must be consistent with any observations of actual flows.
[0025] In cases where a technology allows for the measurement of all actual flows in the network, the multiflow (F) can be established from these measurements without the use of algorithms. The invention makes it possible to validate that the values appearing in this multiflow F do not contradict those observed in reality, in particular the measurements of energy consumed or produced by the different nodes at each instant.
[0026] The encryption of data in the multi-stream allocation of energy or energy material is preferably carried out using an asymmetric encryption method.
[0027] The asymmetric data encryption step ensures data confidentiality. It also ensures the uniqueness of the data source because it is fully visible, but in encrypted form, to all nodes of the network.
[0028] Each node in the network preferably possesses a private key and a public key. Advantageously, all coefficients of the multiflow F are encrypted during the encryption step.
[0029] Encrypting all the coefficients of the multiflow ensures the confidentiality of consumption, production, and / or storage data for the nodes in the network of actors, with each node Ni having access only to the coefficients relevant to it. In addition to the coefficients of the multiflow F, the encrypted data may include information about the type of energy stored and / or the location of production or consumption.
[0030] Adding numerical information fields allows for greater precision regarding the energy allocated to the consumer or producer. With this additional information, a consumer can, for example, verify that they are receiving a specific type of energy, such as wind power, or check the location where that energy is produced.
[0031] The encrypted data can be contained in a computer file {F}.
[0032] The file {F} is, for example, a file in CSV, JSON or XML format.
[0033] This file {F} is encrypted using the public keys of the network nodes in such a way that the network nodes of actors who hold a private key associated with a public key can decrypt it.
[0034] This file {F} contains one or more pieces of information, each piece of information relating to a partial description of the multiflow, including, for example, at least one coefficient of the multiflow. Each piece of information is encrypted in such a way that the node(s) concerned by the information can decrypt the encrypted piece of information, but other actors cannot.
[0035] The information contained in the {F} file can take the form of a list or a set of fields, some encrypted and others not. It can be structured, for example, as a list, a set, a hash table, a JSON object, or an XML object.
[0036] In particular, an information element can be a triplet, contain three fields, and should only be accessible to the two actors N i and N j.
[0037] The first contains a secret symmetric key k encrypted using the public key of node N i of the actor network, the second contains the same symmetric key k encrypted using the public key of node N j of the actor network, and the third field is encrypted by the symmetric key k and contains a partial description of the multiflow F, such as a coefficient of this multiflow.
[0038] This third field can contain other information. For example, it can contain information relating to the nature of the energy transmitted from node N i to node N j.
[0039] Alternatively, each piece of information can contain more than 3 fields.
[0040] Alternatively, each piece of information can contain one or two fields.
[0041] The computer file {F} can contain a number of information elements equal to the number of coefficients in the multiflow F.
[0042] The computer file {F} can contain a number of information elements less than the number of coefficients of the multiflow F, said information elements corresponding to the non-zero coefficients of the multiflow F.
[0043] The computer file {F} can contain a number of information elements less than the number of coefficients of the multiflow F, said information elements corresponding to the non-zero coefficients of the multiflow F plus at least one information element corresponding to a zero coefficient of the multiflow F.
[0044] This variant reduces the file size by either hiding or revealing the exact number of non-zero coefficients in the multiflow F. It also prevents the number of actors involved in the validation process from being disclosed.
[0045] The received validation messages can be recorded on a computer storage device. A database management system can be used for this purpose.
[0046] The step of recording a validation message can be followed by a step of publishing this validation message on a distributed ledger, in particular a blockchain-based ledger.
[0047] Publishing the validation on a distributed ledger ensures its integrity and authenticity. It also maintains a history of validations and ensures traceability.
[0048] Advantageously, all nodes send a validation message.
[0049] In these cases, the proof of the validity of the multiflow is total since all the nodes have verified that the coefficients of the multiflow satisfy a predefined condition.
[0050] If not all nodes in the actor network send a validation message, then the multiflow validation is said to be partial. Partial validation may be sufficient. Advantageously, each node Ni in the actor network has the option to send its validation message at any time after publication.
[0051] In particular, even if a new multi-flow of energy or energy material allocation has been published, it is still possible to validate a previously published multi-flow.
[0052] This characteristic may discourage the actor responsible for publishing the multiflow from publishing an invalid one, since the verification of the predefined condition can be done at any time by the nodes of the network of actors.
[0053] The invention also relates to a method for validating data on the allocation of energy or an energetic material in connection with a node N i of a network of actors, comprising the steps of: retrieval and decryption of an encrypted version of data from a multiflow of energy or energy material allocation between this node N i and the other node(s) of the network of actors, sending a validation message to a predefined recipient if a predefined condition is met between this data and at least one production, stock level or consumption value observed or measured by this node.
[0054] This process is preferably implemented by each of the network nodes, and allows them to confidentially receive the coefficients of the multiflow of energy or energy material allocation and to verify their validity.
[0055] The nodes of the network of actors can observe production, stock level or consumption values, for example through electricity meters.
[0056] If the multiflow is a four-dimensional table i, j, q, and t, the process can include calculating the quantities V iqt of a product Q q virtually stored by node N i at time t from the equation: V iq t − 1 + ∑ j = 0 N F jiqt − ∑ j = 0 N F ijqt = V iqt , Fijqt denoting the coefficient of the multiflow F representing the quantity of energy or energetic matter of the product Qq transferred from node Ni to node Nj between times t-1 and t, said predefined condition corresponding to compliance with the following equations: ∑ q F 0 iqt ≤ P it ∑ q F i 0 qt ≤ C it ∑ q w iq V iqt ≤ K it where F 0iqt is the quantity of product Q q virtually produced by node N i between times t-1 and t according to the multiflow assignment F, F i0qt is the quantity of product Q q virtually consumed by node N i between times t-1 and t according to the multiflow assignment F, P it and C it are the actual observed production and consumption values, ∑ q w iq V iqt is the overall energy stock level and K it is the storage capacity of node N i between times t-1 and t.
[0057] The checks by the different nodes ensure the validity of the values of the coefficients of the multiflow of energy or energetic matter allocation F.
[0058] Verification that the predefined condition between the received data and the actual production, stock level, or consumption observed by this node can be performed automatically by a software tool. Using a software tool to verify compliance with the aforementioned condition is preferable, as it simplifies and automates the task of verifying the network nodes.
[0059] The verification can be done each time the {F} file is published, for example. This publication can take place regularly, on an annual, monthly, weekly, daily, or other basis.
[0060] The verification can be done manually. However, it is preferable to perform it automatically. When automated, the verification can be performed at a higher frequency, for example hourly, if the {F} file is published at that same frequency and if the observed data is accessible.
[0061] The software tool can be implemented by any type of computer or specialized circuit, for example integrated into an electrical cabinet or production or consumption monitoring system.
[0062] The software tool can interface with the equipment that allows nodes to retrieve actual observed consumption or production data. The software tool can also interface with the IT system of a third-party entity responsible for measuring consumption, production, or storage levels at network nodes. Combining the software tool with the data source(s) that enable nodes to retrieve observed consumption or production data simplifies data validation for network nodes.
[0063] The retrieval of an encrypted version of the coefficients of a multiflow energy or energy-material allocation between this node Ni and the other node(s) in the network of actors linked to this node is followed by a verification of the authenticity of this encrypted version. This verification ensures that the retrieved file corresponds to the one in the blockchain.
[0064] In the case where the nodes of the actor network do not store energy or energy material, the sending of the validation message can be systematic for the energy production nodes only.
[0065] In the case where the nodes of the actor network do not store energy or energy material, the sending of the validation message can be systematic for the energy consumption nodes only.
[0066] In the absence of storage, it is possible to partially validate the multi-flow energy or energy-material allocation even if not all nodes have sent a validation message. For example, only the consumer nodes or only the producer nodes might send a validation message. The energy supplier can therefore validate a multi-flow energy or energy-material allocation more easily. Advantageously, energy is physically transported between the nodes (Ni) of the network of actors in the form of electricity.
[0067] Advantageously, the energy source is gas. Brief description of the drawings
[0068] The invention will be better understood upon reading the detailed description that follows, the non-limiting examples of its implementation, and upon examination of the attached drawing, on which: [ Fig 1 ] There figure 1represents an example of interactions between network actors during the validation process of a multi-flow allocation of energy or energy resources between the different production, consumption, storage and / or release nodes of the network, [ Fig 2 ] There figure 2 represents an example of interactions between network actors during the validation process of a multi-flow allocation of energy or energy resources between the different production and / or consumption nodes of the network, [ Fig 3 ] There figure 3 represents steps in the validation process as they can be carried out by an actor with access to production, consumption, storage and / or destocking data from network nodes, and [ Fig 4 ] There figure 4 is an example of a software tool interface that can be used for the validation operation. Detailed description
[0069] There figure 1illustrates steps in an example of implementation of a process according to the invention by an actor A having access to production, consumption, storage or destocking data of the nodes of a network of actors.
[0070] This actor A is, for example, an energy supplier, particularly of electricity and more specifically a supplier of green electricity.
[0071] This actor A may also be a supplier of green energy materials.
[0072] The network is composed of a number N of nodes N i . Each node N i can produce, consume, store and / or release a product Q q . The term "product" refers to the nature of the electricity or energy that is produced.
[0073] For example, the product Qq could be wind, hydroelectric, or nuclear electricity. The nature of the electricity produced can also include the geographical location of energy production.
[0074] Q q can also be gas derived from biomass.
[0075] Nodes capable of producing energy include, for example, energy producers with wind turbines, solar panels, hydroelectric dams, or nuclear power plants.
[0076] Nodes capable of consuming energy or energy resources include, for example, individual or industrial consumers who use the electricity or gas they receive for domestic or industrial purposes. They can also include public entities such as municipal infrastructure.
[0077] Nodes capable of storing energy or energy-bearing materials can consist of any system capable of storing and releasing energy, such as rechargeable battery-based systems, electrolyzer and fuel cell systems, pumped-storage hydroelectricity systems, gas compression storage systems, etc. Nodes Ni have computing resources, such as a computer, and a means of communicating with actor A, for example, via the internet or any other communication network.
[0078] Since time has been previously discretized into instants t, the time interval Δt below extends between instants t-1 and t. The duration of this time interval Δt is, for example, half an hour. Not all intervals necessarily have the same duration.
[0079] Several numerical values can be attached to each node N i, including: a production P iqt of product Q q during the interval Δ t, this production can be zero a global production P it during the interval Δ t, this production can be zero a consumption C iqt of product Q q during the interval Δ t, this consumption can be zero a global consumption C it during the interval Δ t, this consumption can be zero a storage capacity K it during the interval Δ t, this storage capacity can be zero if there is no possible storage or even infinite if storage is not limited a quantity V iqt of product Q q stored during the interval Δ t, this quantity can be zero a global quantity V it stored during the interval Δ t, the coefficient w ig corresponding to a unit volume, all these coefficients can be 1, the quantity V it can be zero.
[0080] The overall production Pit being: P it = ∑ q P iqt
[0081] The overall consumption Cit being: C it = ∑ q C iqt
[0082] The total quantity Vit being: V it = ∑ q w iq V iqt
[0083] This production, consumption and stock data will most often be considered confidential by node N i. In particular, it must not be known to other nodes in the network of actors, nor to any third party outside the network.
[0084] These production, consumption and stock data are generally not necessarily measurable, either because the node is not equipped with the appropriate measuring means, or because the product Q q cannot be individually identified.
[0085] For example, node Ni can usually measure or have its energy consumption Cit measured during the interval Δt, but it cannot physically distinguish the origin of the electricity or energy source. Therefore, it cannot measure the Ciqt values and determine the proportion of energy from solar or wind sources in its consumption.
[0086] The measurement of an observable quantity is also called observation.
[0087] An observation can be exact, for example represented by a real or complex number. An observation can also be approximated, for example represented by a confidence interval or a probability distribution.
[0088] The values observable by each node N i are, for example: the total amount of energy produced, the total amount of energy consumed, the total stock level.
[0089] The total amount of energy produced is: P it = ∑ q P iqt
[0090] The total amount of energy consumed being: C it = ∑ q C iqt
[0091] The overall stock level being: V it = ∑ q w iq V iqt
[0092] The observation of V iqt values can be carried out in different ways. All values may be known, or only certain values may be known, for example only those corresponding to certain time points, such as only time 0 and time T.
[0093] Observable production, consumption, and stock data can be transmitted to A by actors N i or by a third-party entity. This transmission can be automatic and ensured by a communication network, for example, the internet.
[0094] The third-party entity is, for example, a network manager that measures the production of nodes or an entity that holds a mandate to collect this data.
[0095] The various stakeholders, and in particular consumer stakeholders, may wish to have a quality of service that guarantees compliance with certain constraints relating to the share of green energy supplied to them.
[0096] Actor A must be able to prove this quality of service, in particular by showing that its energy supplies for each time interval Δt effectively supply consumers in accordance with the displayed quality of service indicators.
[0097] For this, it uses a multiflow, which is a theoretical and formal representation of the virtual energy flows between production, consumption and storage nodes of a network of actors.
[0098] This formal representation of virtual energy flows can take the form of an energy allocation table F whose coefficients Fijqt correspond to a quantity of energy or energetic matter of a product Qq allocated to a virtual flow between the source node Ni and the destination node Nj during an interval Δt, this quantity of energy having been, for example, produced, stored, released or consumed within the network of actors.
[0099] The multifloat, in this case, is a 4-dimensional table.
[0100] This formal representation of virtual energy flows can also take the form of an energy allocation table F whose coefficients Fij correspond to a quantity of energy or energetic matter between the source node Ni and the destination node Nj, this quantity of energy or energetic matter having been, for example, produced, stored, released or consumed within the network of actors.
[0101] The multifloat, in this case, is a 2-dimensional table.
[0102] This formal representation of energy flows can also take the form of an energy allocation table F whose coefficients Fijt correspond to a quantity of energy or energetic matter between the source node Ni and the destination node Nj during an interval Δt, this quantity of energy or energetic matter having been, for example, produced, stored, released or consumed within the network of actors.
[0103] The multifloat, in this case, is a 3-dimensional table.
[0104] In the following description, the multiflow F is considered to be a 4-dimensional table. The energy or energy-matter allocation multiflow F must satisfy several constraints modeling the physical reality of the network of actors. These constraints are expressed, for example, by mathematical inequalities or equalities between observable and theoretical values.
[0105] All of these constraints together are called the predefined condition for the validity of the flow.
[0106] Consider the following equation: [Math 12] V iq t − 1 + ∑ j = 0 N F jiqt − ∑ j = 0 N F ijqt = V iqt
[0107] For example, equation (1) represents the conservation of flow at each node of the network and at each instant. In this formulation, an additional node N0 has been added to simplify the notation. Nodes originating from N0 correspond to production, and nodes destined for N0 correspond to consumption.
[0108] When the energy or energy-matter allocation multiflow F is given, the equation above allows us to define the values Viqt and then the values Vit. For the multiflow F to be valid, it must in particular satisfy this other inequality which reflects compliance with storage capacities: [Math 13] 0 ≤ V it ≤ K it
[0109] In particular, for nodes N i with no storage capacity (K it = 0), the stored volumes V iqt are all zero for all t.
[0110] The multi-flow allocation of energy or energetic material F must also be consistent with the observations and measurements that have been carried out.
[0111] For example, when the virtual flux represents the energy produced by the network and consumed by the network, it is necessary to ensure that the virtual flux does not exceed the productions P it observed at each node N i, which translates into the inequalities: [Math 14] ∑ q F 0 iqt ≤ P it
[0112] As another example, it is necessary to ensure that the virtual flow does not exceed the consumption C it observed at each node N i, which translates into the following inequalities: [Math 15] ∑ q F i 0 qt ≤ C it
[0113] The construction of the energy allocation multiflow F is carried out in step 11. It can be carried out by actor A.
[0114] Each node N i of the actor network must then validate this multiflow F by verifying that it is compatible with the physical constraints of node N i and in particular the observations made at this node N i such as the stock level, global consumption or global production.
[0115] The construction of this multiflow F can be carried out by implementing algorithms via computing means, such as a computer for example.
[0116] There are generally several possible multiflows corresponding to the observations made by the network of actors. Constructing the multiflow therefore consists of finding at least one multiflow among those that already exist.
[0117] This construction can be optimized by choosing the multiflow that best meets the requirements of actor A.
[0118] The actor constructing the multiflow F generally wants to build a multiflow with interesting characteristics. For example, they want to demonstrate that the consumer nodes are supplied with green energy according to a predefined performance criterion.
[0119] The performance criterion, for example reflecting the quality of service for the nodes of the network of actors, can be built to optimize the performance criterion.
[0120] The algorithms implemented for the construction of the multiflow F are based, for example, on a mathematical optimization method, in particular by application of a flow optimization algorithm in graphs or, more generally, of a linear or quadratic programming algorithm, in integers or not, or of approximate, heuristic or metaheuristic algorithms.
[0121] The calculation of the multiflow F can include physically measured data, such as electricity production or consumption data from nodes, this data having been provided by nodes N i or by a third-party entity.
[0122] Actor A transmits to each node Ni of the network of actors various performance indicators relating to the multi-stream allocation of energy or energy material F, such as the guaranteed share of green energy. These indicators assess the quality of service promised by actor A to each node Ni.
[0123] The indicator can also be binary and indicate that the energy allocation multiflow F satisfies certain constraints required by a source or destination point. Such a constraint might, for example, reflect the requirement for a power plant to be supplied only by a specified source or a small number of specified sources, or conversely, not to be supplied by a specified source or a small number of specified sources.
[0124] Once the multiflow F is constructed, it is encrypted in step 12, for example by the same computer that calculated it, or by a different computer.
[0125] During the encryption step 12 at least one coefficient of the multiflow F is encrypted.
[0126] It is possible not to fully encrypt the multi-flow F.
[0127] Alternatively, all coefficients of the multiflow F are encrypted during the encryption step. Encrypting all coefficients of the multiflow F ensures the confidentiality of the data at the nodes of the actor network.
[0128] The encryption method is, for example, an asymmetric encryption method.
[0129] A public key infrastructure is advantageously implemented to facilitate key management. This infrastructure can include a web portal that allows nodes to request the secure creation and transmission of a private key and a public key from actor A. This web application can also ensure the secure storage of the private and public keys of all actors or only those actors who wish to use them.
[0130] In one implementation mode of the process, the values F ijqt are encrypted via a symmetric key k ijqt accessible only to nodes N i and N j.
[0131] The k ijqt keys should ideally remain secret.
[0132] Symmetric keys k ijqt can be generated randomly during the encryption phase.
[0133] Alternatively, they may have been generated beforehand.
[0134] Alternatively, keys generated during previous encryptions of previous instances of F can be reused.
[0135] To speed up calculations and generate fewer keys, this symmetric key can be the same for all products Q q or for all times t.
[0136] Symmetric keys are best stored in a secure database.
[0137] We denote {F} the file resulting from the encryption of the multistream F. The file {F} is a computer file, for example a file in CSV, JSON or XML format.
[0138] The file {F} contains at least one piece of information corresponding to a coefficient F ijqt of the multiflow.
[0139] Alternatively, the file {F} contains information elements corresponding to the coefficients F ijqt necessary to describe the multiflow F for at least one instant t.
[0140] Each piece of information in the file {F} can correspond to one or more coefficients F ijqt.
[0141] In particular, each piece of information in the file {F} can be a triplet and correspond to a coefficient Fijqt of the multiflow. Each triplet can have the following structure: cl é = k ijqt PK N i cl é = k ijqt PK N j chiffrement k ijqt produit = Q q ; intervalle = t ; flux = F ijqt
[0142] The first information field, {key = k ijqt} PK(Ni), is accessible only to node N i. It allows it to know that the information concerns it and to obtain the symmetric key to decrypt the 3rd information field.
[0143] The second information field, {key = k ijqt} PK(Nj), is accessible only to node Nj. It allows it to know that the information concerns it and to obtain the symmetric key to decrypt the 3rd information field.
[0144] The third information field is information accessible only to those who possess the symmetric key k ijqt, i.e. N i , N j and possibly A if A archived the symmetric key during encryption.
[0145] The three fields appear in {F} as three encrypted messages.
[0146] The use of a symmetric key ensures the uniqueness of the message contained in the kijqt encryption field, meaning that it ensures that N i and N j have access to the same information.
[0147] The third encryption field kijqt can contain several pieces of information. This information allows N i and N j to verify which coefficient of the multiflow they have decrypted. In the example above, the precision of the product Q q and the time t allows us to know that the numerical value associated with the flow field corresponds to F ijqt.
[0148] Other information can be added to the third encrypted field. For example, there could be a field indicating the location of energy production or consumption. Alternatively, the different pieces of encrypted information in the third field can be encrypted independently. For example, according to the following structure: cl é = k ijqt PK N i cl é = k ijqt PK N j chiffrement k ijqt produit = Q q chiffrement k ijqt intervalle = t chiffrement k ijqt flux = F ijqt
[0149] The information element of {F} is then a quintuple.
[0150] Alternatively, several coefficients of the multiflow F can be present in the same information element of {F}. For example, coefficients corresponding to different times can be grouped, resulting in the following structure: cl é = k ijqt PK N i cl é = k ijqt PK N j chiffrement k ijqt produit = Q q ; flux = F ijqt 1 , F ijqt 2 , …
[0151] The file {F} can contain a number of information elements equal to the number of values F ijqt contained in the multiflow F.
[0152] The file {F} can contain only the information elements corresponding to non-zero Fijqt values. Under these conditions, the number of information elements is less than the number of coefficients in the multiflow F. The file {F} can also contain all the information elements corresponding to non-zero Fijqt values plus at least one information element corresponding to zero Fijqt values.
[0153] These variants allow the file size to be reduced by hiding or not the exact number of non-zero F ijqt values.
[0154] These variants also make it possible to avoid disclosing the number of actors involved in the validation process.
[0155] The file {F} can also contain a number of additional pieces of information, public or not, for each node N i. This information can be associated with a public identifier of the node N i, such as its public key PK(N i) or any administrative identifier.
[0156] Public information is not encrypted. This includes, for example, the name of a power plant or its production capacity.
[0157] Private information is encrypted so that it can only be decrypted by N i, typically using the private key PK -1<(N i). Examples include the name of a consumer, the number of a contract between N i and A, or the stock level at the initial time F is modeled.
[0158] The information contained in file {F} can be stored in a database accessible to A.
[0159] After encryption step 12, the encrypted data resulting from the multi-stream encryption F is published, during a publication step 13, via a computer network. By "published," we mean made accessible to the relevant nodes of the network and preferably to all nodes of the network, or transmitted to the relevant nodes, or even to all nodes of the network.
[0160] To ensure that the {F} file will never be modified or deleted, it can be published by a trusted third party.
[0161] The {F} file can also be published in a distributed registry, for example a blockchain-based registry.
[0162] The distributed ledger can be based on a blockchain (in English) blockchain ), public or private.
[0163] To avoid inserting the entire file {F} into a distributed ledger, the following two-step method can be used instead. In the first step, a hash of {F}, produced for example by a hashing algorithm, or a message authentication code for the file {F}, is calculated. This code is calculated, for example, using a cryptographic hash function, possibly in combination with a secret key, and more specifically, the secret key of actor A. In the second step, the hash or authentication code is published in the distributed ledger. The file {F} is published separately. The message hash or authentication code allows verification that the file has not been modified (integrity check) and confirms its authenticity. The advantage of this method is that the size of the hash or authentication code is much smaller than that of the file {F}.
[0164] When the hash of file {F} has been published in a distributed registry, any authorized user can verify the authenticity of file {F} when they access it. To do this, they compare the hash of the accessed file with the hash published in the distributed registry.
[0165] In particular, the N i nodes can perform this check as an initial step in the validation process, even before decrypting {F}.
[0166] By deciphering in the file {F} all the data to which it has access, the node N has access to the coefficients of the multiflow F corresponding to the flow entering N i, that is to say to the set of coefficients F jiqt with i fixed and j, q and t variable, and to the flow leaving N i, that is to say to the set of coefficients F ijqt with i fixed and j, q and t variable.
[0167] Thus, by deciphering in the file {F} all the data to which it has access, the node N i is able to verify that the equations and inequalities involving the variables F ijqt do indeed satisfy the equations and inequalities of production, consumption and conservation of energy associated with N i.
[0168] The node N i is in particular capable of verifying that the observations made at the node N i are compatible with the flow F.
[0169] In particular, N i can satisfy inequalities (3) and (4).
[0170] Using equations (1), node Ni can calculate the stock levels at different times. Node Ni can then verify that these levels agree with its observed stock levels. Alternatively, node Ni can simply verify that the storage capacities are met, i.e., that inequalities (2) are satisfied.
[0171] If the verification is successful, node Ni issues a validation message. This validation message is preferably signed, for example using the private key PK-1(Ni). This proves that it was indeed issued by Ni.
[0172] This message contains at least the reference to {F} and, for example, the number of information items checked in this file.
[0173] The message may also mention the number of validated information items in which N i is the origin and the number of validated information items in which N i is the destination.
[0174] This validation message is sent to actor A who archives it during a recording step 14.
[0175] The verification can be performed automatically and the message sent automatically to a piece of equipment in A, for example the computer that published the file {F}.
[0176] If the check does not end successfully, node N i does not send a message.
[0177] Alternatively, if the verification does not end successfully, node N i sends an error message, preferably signed.
[0178] This message, whether validation or error, is transmitted via a telecommunications network such as the internet.
[0179] Actor A can publish all signed messages received from nodes N i. For example, the publication is done on a distributed ledger.
[0180] The publication of validation messages can also be done by an actor other than A or by several actors. This publication can be ensured, for example, by a third party, a distributed registry, or one or more nodes N i.
[0181] Validating the information elements of file {F} by all nodes N i ensures that all the required conditions are met. This therefore proves the validity of the multiflow F.
[0182] The validation of the information elements of {F} by a part of the nodes N i may be sufficient to prove the validity of the multiflow F.
[0183] Actor A can advantageously offer a tool, for example a software tool, to nodes N i to allow them to easily send a validation message or an error message. This software tool can be accessible via a web portal.
[0184] There figure 4 represents an example of a graphical interface for such a software tool.
[0185] This interface includes a table 24 showing the hourly consumption data of a node N i. Alternatively, the consumption data can be shown at a time step of 5, 10, 15 or 30 minutes or any other time step corresponding to the time step of the flows, i.e. to the duration of the time intervals Δ t.
[0186] This interface includes, for example, a validation button 21 which allows the user to trigger the sending of a signed message. The user can activate this button 21 when they believe the predefined conditions have been met.
[0187] An error button 22 allows the sending of an error message which invalidates the multiflow F. The user can activate this button 22 when he believes that the predefined conditions are not met.
[0188] Advantageously, the source code of the computer tool is open so that each node can verify how the computer tool performs the validation.
[0189] To preserve the confidentiality of the data, the computer tool codes are executed on a machine belonging to node N i or on a machine administered by node N i or, failing that, on a machine that is not administered by A.
[0190] Alternatively, these codes are executed on a computer belonging to a trusted third party who will have access, preferably in a secure manner, to the production or consumption values of node N i.
[0191] The code can be executed as a web application, with the verification code being executed by the client's web browser.
[0192] The code can advantageously interface with one or more private key storage tools.
[0193] It can also interface with the data source(s) allowing nodes to retrieve actual observed consumption or production data. These data sources include, for example, data files or application programming interfaces (APIs). Manual data entry is also possible.
[0194] The tool can advantageously provide its users, for example the N i nodes, with additional services to encourage regular execution of the tool.
[0195] Such services may include the storage, visualization, and analysis of historical production, consumption, and / or storage data.
[0196] Preferably, the tool runs automatically and recurrently, in the background, that is, without the N i nodes having to activate it manually.
[0197] The tool can advantageously be integrated with the measurement or calculation tool that provides the actual observed consumption, production or storage data.
[0198] Using the messages emitted by the nodes N i, actor A can present proof of the validity of the multiflow F. This proof is illustrated by validation step 15 on the figure 3 .
[0199] In the case where all nodes have provided validation, actor A can claim complete proof of the validity of its flow F.
[0200] Once A receives a validation message, it has partial proof of the validity of the multiflow.
[0201] This proof is strengthened if the messages show that each piece of information in file {F} has been validated twice, once by the source node of the virtual stream (N i ) and once by the destination node of the virtual stream (N j ). For A to do this, it is sufficient to show that the number of validated pieces of information is equal to twice the number of triplets contained in {F}.
[0202] Information elements for which the source node is the same as the destination node can be validated, conventionally, only once or twice, once as source and once as destination.
[0203] In the event that not all nodes have provided validation, actor A can display the validation rate of F.
[0204] The ability for each node Ni to perform the {F} check, however, discourages actor A from deliberately publishing an invalid energy allocation multiflow. Advantageously, the check can be performed repeatedly and at any subsequent time.
[0205] Actor A therefore has no technical solution to erase a potential error. They must therefore explicitly correct F and publish a corrected version of the file {F}, which must then be validated.
[0206] Actor A can advantageously offer a tool, for example a software tool, to archive the cases of invalidity of F detected by a node N i.
[0207] The detection of an invalidity may stem from a calculation error in one of the nodes Ni. Actor A can advantageously propose a tool to analyze the cause of the invalidation. For example, an invalidation may result from the fact that node Ni uses an incorrect observed actual consumption or production value, or in any case, a value different from the one known to actor A.
[0208] This tool can advantageously offer dialogue functionalities allowing either the validation of the file {F} by the node N i, or the publication by A of a corrected multiflow.
[0209] This tool can be advantageously integrated with the message sending assistance tool described in step 14.
[0210] Advantageously, the source code of the computer tool is open so that each node can verify how the computer tool works. Control
[0211] The validation process is advantageously enhanced by control functionalities.
[0212] A control gives the possibility to a trusted third party, for example an auditor, which we call here actor C, to access the data of the multi-flow of energy or energy material allocation.
[0213] This actor C can be a natural person or software running on a computer.
[0214] The control makes it possible to verify that there is no collusion between the actors in the energy distribution network.
[0215] Access to the encrypted file {F} can be opened to third parties C possessing a public key and a private key by adding a field {Key = k ijqt} PK(C) to each of the information elements of the file {F}.
[0216] The presence of this field allows C to obtain the symmetric key of each piece of information and, consequently, to decrypt all the information relating to F ijqt. Alternatively, actor A can maintain in their private database all the information P iqt, C jqt and F ijqt as well as all the keys k ijqt and, possibly, information allowing for a quick link between the rows of the database and the encrypted information of {F}.
[0217] Auditing this database allows us to verify the validity of F and that the encrypted information in {F} corresponds to the content of the database. Example: case without storage
[0218] There figure 2 illustrates an example of implementation of the process according to the invention in the case where the nodes neither store nor release energy or energetic matter.
[0219] In this example, the network of actors, previously denoted N i, is partitioned into two classes of actors, the origin nodes and the destination nodes.
[0220] The n original nodes, individually denoted O i, each possess a positive production value P it.
[0221] These nodes O i are, for example, producers of renewable electricity, having a production P it over a considered time interval Δ t. This capacity can be a production power, for example expressed in MW, or a volume of energy produced, for example expressed in MWh, during this time interval Δ t.
[0222] When t varies, the production Pit can vary. This is referred to as the production curve of Oi as a function of time.
[0223] We also have a set of mactors constituting destination nodes, individually noted D j and each possessing a positive consumption value C jt.
[0224] These nodes D j are, for example, electricity consumers wanting energy from renewable sources, having a consumption need C jt over a time interval Δ t considered. This value, if it corresponds to a physical quantity, must be of the same nature as P it and is considered to be expressed in the same unit, possibly after conversion.
[0225] When t varies, the consumption C jt can vary. We then speak of the consumption curve of D j as a function of time.
[0226] In the absence of storage, the origin Oi of the multiflow F is easily known. Therefore, in our example, there is no need to distinguish between multiflows by product Qq. The multiflow thus corresponds to a flow in a complete bipartite graph.
[0227] The multiflow table is then a 3-dimensional table. The coefficient Fijt corresponds to the energy flux between an origin node Oi and a destination node Dj. This is also referred to as an allocation table at time t.
[0228] The assignment table contains m*n values per time interval. Several of these values may be zero.
[0229] These energy allocation coefficients are positive values which must necessarily satisfy, for any origin O i, any destination D j and any time interval Δ t, the following two sets of inequalities: [Math 19] ∑ j F ijt ≤ P it [Math 20] ∑ i F ijt ≤ C jt
[0230] With P it and C it the observable real values of production and consumption.
[0231] The multiflow of energy or energetic matter allocation data F is valid when the data that compose it satisfy all inequalities (1') and (2'). These inequalities form the predefined condition for the validity of the multiflow F.
[0232] The information contained in F is known to actor A. The latter may be the originator of the construction of the multi-flow F.
[0233] Actor A knows the values P it and C jt of all other actors, and wishes to ensure the confidentiality of this data.
[0234] The P it values were, for example, provided to A by O i or by a third-party entity that measured P it and transmitted the information to A at the same time as to O i.
[0235] The values C jt were, for example, provided to A by D j or by a third-party entity that measured C jt and transmitted the information to A at the same time as to D j.
[0236] The third-party entity is, for example, a network manager who counts a producer's output and transmits the information to its producer and consumer clients, but also to entities that hold a mandate to collect this data.
[0237] Each origin node O i wishes to ensure the confidentiality of its production P it.
[0238] Similarly, each destination node Dj wishes to ensure the confidentiality of its consumption Cjt. This confidentiality can be the subject of contractual relationships between A and the other actors, namely the n origin nodes O i and the m destination nodes D j .
[0239] If we consider an assignment coefficient Fijt between an origin node Oi and a destination node Dj, the numerical value of this assignment coefficient Fijt is considered as information belonging to both Oi and Dj. The origin node Oi is not assumed to know the destination node Dj of this assignment coefficient Fijt and, symmetrically, Dj does not necessarily know the origin Oi of its energy.
[0240] We introduce the possibility for the origin O i to disclose some of the information concerning it to a destination node D j . We denote O ij the set of this information which can be coded in the form of a simple string of characters or any other format such as XML, JSON, YAML.
[0241] Similarly, we denote D ij the set of information concerning D j that this node wishes to reveal to O i.
[0242] The set of information O ij allows the destination D j to calculate performance indicators on the multi-flow of energy or energy material allocation F.
[0243] The set of information D ij allows originally O i to calculate performance indicators on the multi-flow of energy or energy material allocation F.
[0244] For example, if destination D j wants to calculate the share of energy that has a solar origin, each origin O i such that F ij > 0 must publish in O ij the information whether the energy produced is of solar origin or not.
[0245] In some cases, it may be useful to modify the Oij information as a function of time. This information will then be denoted Oijt in the rest of the description.
[0246] Similarly, in some cases, it may be useful to modify the D ji information according to time. This information will then be denoted D jit in the rest of the description.
[0247] The possibility for destination nodes D j to be able to check an indicator and the obligation for origin nodes O i to publish certain information can be contractually fixed between A and each of the other actors.
[0248] Similarly, the possibility for origin nodes O i to be able to verify an indicator and the obligation for destination nodes D j to publish certain information can be contractually fixed between A and each of the other actors.
[0249] Each origin or destination node wants to be sure that the indicators transmitted by A are correct and therefore wants to be able to recalculate them, while being sure that the data from the energy allocation multiflow F to which it has access properly satisfies the inequalities (1') and (2').
[0250] Each node X has a public key PK(X) and a private key PK -1< (X).
[0251] Actor A makes public an encrypted file of energy allocation data F ijt, denoted {F}, based on the public keys of the other actors.
[0252] No node can completely decrypt the energy allocation data encrypted using its private key, but it can retrieve the information that concerns it and only that information.
[0253] Once the file {F} is published, the nodes have the option or the obligation to validate the information concerning them in {F}.
[0254] The set of validations proves the validity of {F}.
[0255] Each energy allocation data Fijt is encrypted using a symmetric key kijt, which can be used with an encryption and decryption algorithm. This key is not disclosed. It can only be known to actor A, who is responsible for encrypting the stream.
[0256] The encryption of each coefficient F ijt here corresponds to the production of a triplet of information containing the following fields: {Key = kijt} PK(Oi): This information, accessible only at the origin Oi, allows it to know that the coefficient concerns it and to obtain the symmetric key to decrypt the third information field. {Key = kijt} PK(Dj): This information, accessible only at the destination Dj, allows it to know that the coefficient concerns it and to obtain the symmetric key to decrypt the third information field. The information in the third field is accessible only to those possessing the symmetric key kijt, that is, Oi, Dj, and possibly A; it provides information about the coefficient. The origin Oi does not know the destination Dj but only the information Dijt that Dj wants to reveal to Oi. Conversely, the destination Dj does not know the origin Oi but only the information Oijt that Oi wants to reveal to Dj.
[0257] The third field being: chiffrement k ijt instant = t flux = F ijt origine = O ijt destination = D jit
[0258] Alternatively, when Oijt and Dijt do not vary over time, the flow variation curve for each origin-destination pair can also be stored using a single symmetric key kij rather than a set of keys kijt. The third field is then: chiffrement k ij origine = O ij ; destination = D ij ; flux = F ijt 1 , F ijt 2 , …
[0259] All these information triplets are published together in {F} by actor A. This set includes, for example, one information triplet for each value Fijt. Alternatively, only information triplets corresponding to non-zero values Fijt can be published in {F}.
[0260] In the case where all of the m xn triplets of information per time interval is not stored in the file {F}, it may be advantageous to make public the number of triplets in which each actor X is present as source or as destination.
[0261] By comparing the sum of these numbers and the number of triplets in the file, it is possible to ensure that information triplets have not been created with fictitious actors.
[0262] We can limit the publication of this information to the sources, in order to ensure total anonymity of the destinations.
[0263] The private information associated with node X contained in file {F} allows X to more easily retrieve information about itself and analyze its validity. The form of this information depends on the format of {F}, but it can be a set of line numbers from {F} or positions in an array. Validation of the encrypted data stream
[0264] The origin and destination nodes participate in the validation of the published encrypted energy allocation data {F}.
[0265] The origin and destination nodes can all systematically validate or invalidate the data concerning them.
[0266] Alternatively, data validation or invalidation can be systematic only for the origin nodes. Data validation or invalidation can also be systematic only for the destination nodes.
[0267] Alternatively, the validation or invalidation of data may not be systematic for the origin and destination nodes.
[0268] Each node X can delegate its validation process to a trusted third party with access to node X's confidential data.
[0269] Once the computer file {F} is published, each origin node O i can find, by decrypting {F} using its private key PK -1< (O i ), the set F(O i ) of cardinality #F(O i ) of information triplets that correspond to a flow F ijt originating from O i .
[0270] By deciphering the first field of a triplet of F(O i ), O i accesses the symmetric key k ijt which then allows it to decipher O ij , D ji and F ijt .
[0271] The origin O i then verifies that the information contained in O ijt is true and that, for all time intervals Δ t present in the file {F}, the following inequality is verified: ∑ j F ijt ≤ P it
[0272] If the verification is successful, O i issues a signed message, for example using his private key, indicating at least the reference to {F} and the number of triples checked in that file.
[0273] This signed message is sent to actor A, who archives it.
[0274] Symmetrically, each destination D j can find, by decrypting {F} using its private key PK -1< (D j ), the set F(D j ) of cardinality #F(D j ) of information triplets which corresponds to a flow F ijt to D j .
[0275] By deciphering the first field of a triplet of F(D j ), D j accesses the symmetric key k ijt which then allows it to decipher O ij , D ji and F ijt .
[0276] The origin Dj then verifies that the information contained in D ji is true and that, for all time intervals Δ t present in the file {F}, the following inequality is verified: ∑ i F ijt ≤ C jt
[0277] If the verification is successful, D j sends a signed message, for example using their private key, indicating the number of lines verified. This signed message is sent to actor A, who archives it.
[0278] Finally, actor A publishes all signed messages received from sources and destinations.
[0279] Any node, whether source, destination or third-party actor, can verify the origin of messages using the public keys of the origins and destinations and calculate the following sums: ∑ i # F O i et ∑ j # F D j
[0280] These two sums must be equal to the number of information triplets in the encrypted file {F}. If this is the case, we have proof that the energy or energetic matter allocation multiflow F produced by actor A is a valid multiflow, that is to say, it satisfies the inequalities of (1') and (2').
[0281] Alternatively, only the origin nodes send a signed validation message.
[0282] These messages are published by A.
[0283] It is then possible to verify that the following sum is indeed equal to the number of triplets in the file {F}: ∑ i # F O i
[0284] This equality ensures that the following series of inequalities is indeed verified for all origins O i: ∑ j F ijt ≤ P it
[0285] This ensures that the multi-flow allocation of energy or energy material proposed by A is indeed able to supply the destinations.
Claims
1. Method for validating an energy or energetic material assignment multi-flow (F) between nodes Ni of a network of actors having computing means, this multi-flow comprising coefficients corresponding to a quantity of energy or of an energetic material of nature Qq assigned to a virtual flow between nodes Ni and Nj of the network of actors at various times, this quantity of energy or of energetic material having been produced, stored, de-stored and / or consumed within the network of actors, this method comprising the following steps, for a given node Ni: • at least one computer encrypting at least the coefficients of the multi-flow involving this node in order to obtain encrypted data, • publishing the encrypted data via a computer network, so as to enable each node Ni to transmit back a validation message certifying compliance with a predefined condition between the data of the multi-flow (F) and real values concerning production, stock level or consumption observed at the node Ni, • recording, in a computer storage device, validation messages sent by the nodes of the network of actors so as to enable validation of the coefficients of the multi-flow.
2. Method according to Claim 1, the publication taking place to a distributed register, in particular a blockchain-based register.
3. Method according to Claim 1 or 2, the encryption step being preceded by a step of calculating the energy or energetic material assignment multi-flow (F), this calculation being carried out using a mathematical optimization method, in particular by applying a graph flow optimization algorithm or, more generally, using an integer or non-integer linear or quadratic programming algorithm, or using approximated heuristic or meta-heuristic algorithms.
4. Method according to any one of the preceding claims, the coefficients of the energy or energetic material assignment multi-flow (F) being encrypted using an asymmetric encryption method.
5. Method according to any one of the preceding claims, all the coefficients of the multi-flow (F) being encrypted in the encryption step and / or the encrypted data being, in addition to coefficients of the multi-flow (F), information concerning the nature of the stored energy and / or the place of production or consumption.
6. Method according to any one of the preceding claims, the encrypted data being contained in a computer file {F}, the computer file {F} containing in particular a number of information elements equal to the number of coefficients of the multi-flow (F) or the computer file {F} containing in particular a number of information elements less than the number of coefficients of the multi-flow (F), said information elements corresponding to the non-zero coefficients of the multi-flow (F), or the computer file {F} containing in particular a number of information elements less than the number of coefficients of the multi-flow (F), said information elements corresponding to the non-zero coefficients of the multi-flow (F) plus at least one information element corresponding to a zero coefficient of the multi-flow (F) .
7. Method according to any one of the preceding claims, the step of recording a validation message in a computer storage device being followed by a step of publishing this validation message to a distributed register, in particular a blockchain-based register.
8. Method according to any one of the preceding claims, all the nodes sending a validation message and / or each node (Ni) of the network of actors having the possibility of transmitting its validation message at any time following the publication of the encrypted data.
9. Method for validating energy or energetic material assignment data in connection with a node Ni of a network of actors having computing means, comprising the following steps: • recovering and decrypting an encrypted version of data from an energy or energetic material assignment multi-flow between this node Ni and the one or more other nodes of the network of actors in connection with this node, • sending a validation message to a predefined recipient if a predefined condition is met between these data and at least one real value concerning production, stock level or consumption observed or measured by this node.
10. Method according to the preceding claim, the multi-flow being a table with four dimensions i, j, q, and t, comprising calculating quantities Viqt of a product Qq virtually stored by the node Ni at the time t using the equation: V iq t − 1 + ∑ j = 0 N F jiqt − ∑ j = 0 N F jiqt = V iqt , Fijqt designating the coefficients of the multi-flow (F) representing the quantity of energy or of energetic material of the product Qq transferred from the node Ni to the node Nj between the times t-1 and t, said predefined condition corresponding to compliance with the following equations: ∑ q F 0 iqt ≤ P it ∑ q F i 0 qt ≤ C it ∑ q W iq V iqt ≤ K it where F0iqt is the quantity of the product Qq virtually produced by the node (Ni) between the times t-1 and t according to the assignment multi-flow (F), Fi0qt is the quantity of the product Qq virtually consumed by the node Ni between the times t-1 and t according to the assignment multi-flow (F), Pit and Cit are the observed real production and consumption values, ΣqwiqViqt is the overall energy stock level and Kit is the storage capacity of the node Ni between the times t-1 and t.
11. Method according to Claim 9 or 10, compliance with the predefined condition between the received data and the observed real value concerning production, stock level or consumption being verified automatically by a software tool interfacing in particular with the one or more items of equipment allowing the nodes to recover the observed real consumption or production data.
12. Method according to any one of Claims 9 to 11, the recovery of an encrypted version of the coefficients of an energy or energetic material assignment multi-flow between this node Ni and the one or more other nodes of the network of actors in connection with this node being followed by verification of the authenticity of this encrypted version.
13. Method according to any one of Claims 9 to 12, the nodes of the network not storing energy or energetic material, the validation message being sent systematically for energy generation nodes only.
14. Method according to any of Claims 9 to 13, the nodes of the network not storing energy or energetic material, the validation message being sent systematically for energy consumption nodes only.
15. Method according to any one of the preceding claims, the energy being physically transported between the nodes (Ni) of the network of actors in the form of electricity and / or the energetic material being gas.