System for smart authentication and method therefor
The smart authentication system addresses security vulnerabilities in smart grid systems by encrypting and batch-verifying messages from smart meters, utilizing blockchain for decentralized authentication, thereby enhancing security and reliability.
Patent Information
- Application Number
- PCT/KR2024/096471
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-20
- Filing Date
- 2024-11-13
- Publication Date
- 2025-05-30
AI Technical Summary
Existing smart grid systems face security vulnerabilities due to complex terminal implementations and physical layer security technologies, which are susceptible to tracking attacks and impersonation attacks, leading to potential system failures and information leakage.
A smart authentication system that includes encrypting information from smart meters using a pre-stored symmetric key, generating a signature value based on encrypted information and a registration certificate, and performing batch verification by an aggregator and central server, utilizing blockchain for decentralized authentication.
This solution reduces the burden of message verification, enhances system security by preventing attacks like DoS, and improves availability and reliability through decentralized authentication using blockchain and DID technology.
Smart Images

Figure KR2024096471_30052025_PF_FP_ABST
Abstract
Description
Smart authentication system and method thereof
[0001] The present invention relates to a smart authentication system and method thereof.
[0002] In general, a smart grid is a next-generation intelligent power grid that utilizes electrical and information and communication technologies to enhance the power grid, thereby providing high-quality power services and maximizing energy efficiency.
[0003] In this smart grid environment, for the efficient operation of power and energy systems and infrastructure, relevant information is collected through smart devices and appropriate services are provided. In particular, the Internet of Things (IoT) is combined with smart grids to support various applications and services, and smart meters, which are responsible for the reliability and stability of the collected data, have developed with important sensing functions and high connectivity.
[0004] However, while the combination of wired networks and wireless communication technologies in smart grid systems enables extensive control, automation, and connectivity, there are security vulnerabilities inherent in existing wireless communications, software, and virtualized operating environments, and they are vulnerable to malicious attacks.
[0005] As the number of smart devices that collect and measure information increases with the advancement of IoT and communication technologies, and the size of messages increases, the load on servers increases, which can affect real-time power distribution and system management. In addition, there is a problem that the server can be attacked by DoS attacks or exposed during network communication by sending an abnormal message to the server, posing a security risk.
[0006] Conventional smart grid systems have proposed key security technologies for smart meter authentication and personal information protection, but they require high complexity in terminal implementation, and physical layer security technologies for advanced key generation and enhanced terminal security are vulnerable to tracking attacks, which may cause problems with personal information protection.
[0007] In addition, a secure communication method between smart meters and service providers was proposed using a protocol utilizing GNY logic and ProVerif automation tools, but it has problems with terminal authentication and vulnerability to most attacks.
[0008] These issues can lead to system-wide failures and collapse through terminals that are vulnerable to physical threats and external attacks due to resource constraints on smart meters.
[0009] The information transmitted from smart meters is analyzed and utilized by the central server for normal system operation and contains sensitive information that can be used to infer individual activities, so technology is required to address the issue of information leakage to other system members or third parties during the communication process.
[0010] <Prior Art Literature>
[0011] (Patent Document 0001) Republic of Korea Patent Publication No. 10-2564375 ("Blockchain-based distributed quantum network system and method for IoT networks," published on August 9, 2023)
[0012] The present invention aims to provide a smart authentication system and method for verifying and processing messages received from a smart meter in advance in an aggregator.
[0013] To solve the above-described problem, a smart authentication system and method are provided.
[0014] A smart authentication system according to one embodiment of the present invention includes: a step of encrypting information collected and measured by a smart meter using a first symmetric key stored in advance; a step of generating a signature value of the encrypted information based on the encrypted information and a previously generated registration certificate value of the smart meter and transmitting the signature value to an aggregator as a message; a step of collectively verifying the signature value of the encrypted information for the message when the aggregator receives a message from each of a plurality of smart meters; a step of combining messages received from each of the plurality of smart meters by the aggregator when the verification is completed, and generating a signature value of the combined message; a step of performing verification on the combined message when the central server receives the combined message; and a step of dividing the combined message and decrypting the combined message when the verification is completed.
[0015] In one embodiment, the method may further include: a step in which the smart meter transmits the public key of the smart meter that has been previously generated to a blockchain to request generation of a distributed identifier of the smart meter; a step in which the blockchain transmits the distributed identifier of the smart meter corresponding to the public key of the smart meter to the smart meter; a step in which the smart meter transmits the distributed identifier of the smart meter to the central server to request registration of the smart meter; a step in which the central server generates the first symmetric key and a registration certificate value of the smart meter that proves that the smart meter is equipment registered with the central server based on the distributed identifier of the smart meter; and a step in which the smart meter verifies the registration certificate value of the smart meter based on the distributed identifier of the smart meter.
[0016] In one embodiment, the step of batch-verifying the signature value of the encrypted information may include a step of batch-verifying the signature value of the encrypted information based on a distributed identifier of the smart meter for a message received from each of the plurality of smart meters by the aggregator.
[0017] In one embodiment, the smart meter may further include a step of generating masking data of the smart meter and a first hash value for user verification based on the ID and password of the smart meter that have already been generated.
[0018] In one embodiment, the smart meter may further include a step of generating a second hash value based on masking data of the smart meter; and a step of verifying whether the first hash value and the second hash value are identical to verify whether the user access is correct.
[0019] In one embodiment, the method may further include: a step in which the aggregator transmits the public key of the aggregator that has been previously generated to a blockchain to request generation of a distributed identifier of the aggregator; a step in which the blockchain generates a distributed identifier of the aggregator corresponding to the public key of the aggregator and transmits the generated identifier to the aggregator; a step in which the aggregator transmits the distributed identifier of the aggregator to the central server to request registration of the aggregator; a step in which the central server generates a registration certificate value of the aggregator that proves that the aggregator is equipment registered with the central server based on the distributed identifier of the aggregator; and a step in which the aggregator verifies the registration certificate value of the aggregator based on the distributed identifier of the aggregator.
[0020] In one embodiment, the step of generating a signature value of the combined message may include a step of the aggregator generating a signature value of the combined message based on a registration certificate value of the aggregator.
[0021] In one embodiment, the step of performing verification on the combined message may include a step in which the central server performs verification on the combined message using a distributed identifier of the aggregator.
[0022] In one embodiment, the method may further include: a step in which the smart meter generates a new challenge value, generates a first request value for key update based on the first symmetric key and the new challenge value, and transmits a key update request message to the central server; when the central server receives the key update request message, the step in which the central server obtains the first symmetric key based on the previously generated initial challenge value, and generates the second request value based on the first symmetric key; and a step in which the central server verifies whether the first request value and the second request value are identical.
[0023] In one embodiment, if the verification result is correct, the central server may generate a second symmetric key and a response value based on the new challenge value and transmit a message to the smart meter; if the smart meter receives the message from the central server, the smart meter may verify the response value based on the new challenge value and the second symmetric key; and if the verification result is correct, the smart meter may update the first symmetric key to the second symmetric key.
[0024] The smart authentication system comprises: a smart meter that encrypts collected and measured information using a pre-stored symmetric key and generates a signature value of the encrypted information based on the encrypted information and the pre-generated registration certificate value of the smart meter; an aggregator that, when receiving a message from each of a plurality of smart meters, collectively verifies the signature value of the encrypted information for the message; when the verification is completed, combines the messages received from each of the plurality of smart meters and generates a signature value of the combined message; a central server that, when receiving the combined message, performs verification on the combined message and, when the verification is completed, splits the combined message and decrypts the combined message; and a blockchain that generates a distributed identifier of the smart meter and a distributed identifier of the aggregator.
[0025] In one embodiment, the smart meter may be characterized by transmitting a public key of the smart meter that has already been generated to the blockchain to request generation of a distributed identifier of the smart meter.
[0026] In one embodiment, the smart meter may be characterized by transmitting a distributed identifier of the smart meter to the central server to request registration of the smart meter.
[0027] In one embodiment, the aggregator may be characterized by collectively verifying the signature value of the encrypted information based on the distributed identifier of the smart meter for each message received from each of the plurality of smart meters.
[0028] In one embodiment, the aggregator may be characterized by transmitting the public key of the aggregator that has been previously generated to the blockchain to request generation of a distributed identifier of the aggregator.
[0029] In one embodiment, the central server may be characterized in that it performs verification on the combined message using the distributed identifier of the aggregator.
[0030] In one embodiment, the aggregator may be characterized by sending a distributed identifier of the aggregator to the central server to request registration of the aggregator.
[0031] In one embodiment, the central server may be characterized in that it generates a registration certificate value of the aggregator that proves that the aggregator is a device registered with the central server based on the distributed identifier of the aggregator.
[0032] In one embodiment, the aggregator may be characterized by generating a signature value of the combined message based on a registration certificate value of the aggregator.
[0033] In one embodiment, the aggregator may be characterized by verifying the registration certificate value of the aggregator based on the distributed identifier of the aggregator.
[0034] According to the smart authentication system and method described above, by performing batch verification on messages transmitted from a plurality of smart meters existing within a management area in an aggregator, the central server can reduce the burden of a large number of message verification processes and reduce the burden of system and service operation.
[0035] Additionally, by verifying messages in the aggregator, abnormal messages can be verified and processed in advance, and attacks such as DoS can be responded to without significantly affecting the overall system operation. In addition, by enabling decentralized authentication using blockchain and DID technology, system availability and reliability can be improved.
[0036] FIG. 1 is a drawing for explaining a smart authentication system according to one embodiment of the present invention.
[0037] FIG. 2 is a flowchart for explaining a smart authentication method according to one embodiment of the present invention.
[0038] Figure 3 is a flowchart for explaining initialization according to one embodiment of the present invention.
[0039] Figure 4 is a flowchart for explaining smart meter registration according to one embodiment of the present invention.
[0040] Figure 5 is a flowchart for explaining aggregator registration according to one embodiment of the present invention.
[0041] Figure 6 is a flowchart for explaining smart authentication according to one embodiment of the present invention.
[0042] FIG. 7 is a drawing for explaining a key update according to one embodiment of the present invention.
[0043] The advantages and features of the present invention, and the methods for achieving them, will become clearer with reference to the embodiments described below together with the accompanying drawings. However, the present invention is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention, and the present invention is defined solely by the scope of the claims.
[0044] The terms used in this specification will be briefly explained, and the present invention will be described in detail.
[0045] The terms used in this invention have been selected from widely used, current terms, taking into account the functions of the invention. However, these terms may vary depending on the intentions of those skilled in the art, precedents, the emergence of new technologies, etc. Furthermore, in certain cases, terms may be arbitrarily selected by the applicant, in which case their meanings will be described in detail in the relevant description of the invention. Therefore, the terms used in this invention should not be defined simply as names, but rather based on their inherent meanings and the overall content of the invention.
[0046] When a part of the specification is said to "include" a component, this does not mean that other components are excluded, but rather that other components may be included, unless otherwise specifically stated. Furthermore, terms such as "part," "module," and "unit" used in the specification mean a unit that processes at least one function or operation, and may be implemented by software, a hardware component such as an FPGA or ASIC, or a combination of software and hardware. However, terms such as "part," "module," and "unit" are not limited to software or hardware. A "part," "module," and "unit" may be configured to reside on an addressable storage medium, or may be configured to execute one or more processors. Thus, as an example, terms such as "part," "module," "unit," etc., include components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, and variables.
[0047] Below, with reference to the attached drawings, embodiments of the present invention are described in detail so that those skilled in the art can easily practice them. Furthermore, in order to clearly explain the present invention, portions irrelevant to the description are omitted in the drawings.
[0048] Terms including ordinal numbers, such as "first," "second," etc., may be used to describe various components, but the components are not limited by the terms. The terms are used solely to distinguish one component from another. For example, without departing from the scope of the present invention, the first component could be referred to as the second component, and similarly, the second component could also be referred to as the first component. The term "and / or" includes any combination of multiple related items or any one of multiple related items.
[0049] Hereinafter, a smart authentication system according to one embodiment of the present invention will be described with reference to the drawings.
[0050] FIG. 1 is a drawing for explaining a smart authentication system according to one embodiment of the present invention.
[0051] As illustrated in FIG. 1, the smart authentication system (1) includes a smart meter (100), an aggregator (200), a central server (300), and a blockchain (400).
[0052] Here, each of the smart meter (100), aggregator (200), and central server (300) can be connected to a blockchain (400).
[0053] The smart meter (100) encrypts the collected and measured information using a pre-stored symmetric key, and generates a signature value of the encrypted information based on the encrypted information and the pre-generated registration certificate value of the smart meter (100).
[0054] Here, the registration certificate value of the smart meter (100) represents a signature value issued by the central server (300) that can prove whether the smart meter (100) has participated in the system (registered).
[0055] A smart meter (100) can request the creation of a distributed identifier for the smart meter (100) by transmitting the public key of the previously created smart meter (100) to the blockchain (400).
[0056] When the aggregator (200) receives a message from each of the plurality of smart meters (100), it collectively verifies the signature value of the encrypted information for each message received from each of the plurality of smart meters (100).
[0057] When verification is completed, the aggregator (200) combines messages received from each of the multiple smart meters (100) and generates a signature value of the combined message.
[0058] The aggregator (200) can collectively verify the signature value of encrypted information based on the distributed identifier of the smart meter (100) for messages received from each of a plurality of smart meters (100).
[0059] The aggregator (200) can request the creation of a distributed identifier of the aggregator by transmitting the public key of the previously created aggregator (200) to the blockchain (400).
[0060] The aggregator (200) can send the aggregator's distributed identifier to the central server (300) to request aggregator registration.
[0061] The aggregator (200) can generate a signature value of the combined message based on the registration certificate value of the aggregator (200).
[0062] Here, the registration certificate value of the aggregator (200) represents a signature value issued by the central server (300) that can prove whether the aggregator (200) has participated in the system (registered).
[0063] The aggregator (200) can verify the registration certificate value of the aggregator (200) based on the distributed identifier of the aggregator (200).
[0064] When the central server (300) receives a combined message, it performs verification on the combined message.
[0065] Once verification is complete, the central server (300) splits the combined message and decrypts the combined message.
[0066] The central server (300) can generate a registration certificate value of the aggregator (200) that proves that the aggregator (200) is equipment registered with the central server (300) based on the distributed identifier of the aggregator (200).
[0067] The central server (300) can perform verification on the combined message using the distributed identifier of the aggregator (200).
[0068] The blockchain (400) can generate a distributed identifier of a smart meter (100) and a distributed identifier of an aggregator (100).
[0069] The blockchain (400) can transmit the distributed identifier of the generated smart meter (100) to the smart meter (100) and transmit the distributed identifier of the generated aggregator (100) to the aggregator (200).
[0070] The process of operating in the smart meter (100), aggregator (200), central server (300), and blockchain (400) will be described in detail later with reference to FIGS. 2 to 7.
[0071]
[0072] Hereinafter, a smart authentication method according to one embodiment of the present invention will be described with reference to the drawings.
[0073] FIG. 2 is a flowchart for explaining a smart authentication method according to one embodiment of the present invention, FIG. 3 is a flowchart for explaining initialization according to one embodiment of the present invention, FIG. 4 is a flowchart for explaining smart meter registration according to one embodiment of the present invention, FIG. 5 is a flowchart for explaining aggregator registration according to one embodiment of the present invention, FIG. 6 is a flowchart for explaining smart authentication according to one embodiment of the present invention, and FIG. 7 is a diagram for explaining key update according to one embodiment of the present invention.
[0074] Referring to FIG. 2, a smart authentication method according to one embodiment of the present invention may be composed of an initialization step (S110), a smart meter registration step (S120), an aggregator registration step (S130), an authentication step (S140), and an update step (S160).
[0075] First, the central server (300) initializes the public variables of the smart authentication system (1) (S110).
[0076] More specifically, referring to FIG. 3, the central server (300) stores a private key (sk TA ) and public key (PK TA ) is created (S111).
[0077] The central server (300) initializes the public variables of the smart authentication system (1) (S112).
[0078] The central server (300) can initialize public variables as in the following mathematical expression 1.
[0079]
[0080] Here, para is a variable required on the elliptic curve, p and q are large prime numbers, G is a group required on the elliptic curve, P is a point on the tower curve (hereinafter referred to as "generator"), and PK TA is the public key, and h() represents the hash function.
[0081] Next, referring again to FIG. 2, the central server (300) registers the smart meter (100) (S120).
[0082] In more detail, referring to FIG. 4, the smart meter (100) receives the ID (ID) of the smart meter (100) from the user. i ) and password (PW i ) is input (S121).
[0083] Below, the ID of the smart meter (100) i ) and password (PW i ) refers to the first ID and first password of the smart meter (100).
[0084] The smart meter (100) has an initial challenge value (C) of the smart meter (100). i ), private key (sk) of smart meter (100) i ) and public key (PK) of smart meter (100) i ) is created (S122).
[0085] Here, the initial challenge value (C) of the smart meter (100) i ) represents a random value.
[0086] The smart meter (100) uses the private key of the generated smart meter to generate the public key (PK) of the smart meter (100) using the following mathematical formula 2. i ) can be generated by calculating.
[0087]
[0088] Here, PK i is the public key of the smart meter, and sk i is the private key of the smart meter, and P represents the creator.
[0089] Smart meter (100) is the DID of the smart meter (100) i To generate a (Decentralized Identifier, DID, distributed identifier) the public key (PK) of the smart meter (100) i) is transmitted to the blockchain (400) to DID i Request for creation, and blockchain (400) receives the public key (PK) of the smart meter (100) i ) corresponding to the DID of the smart meter (100) i is transmitted to the smart meter (100) (S123).
[0090] Here, the blockchain (400) is a public key (PK) of a smart meter (100) i ) and DID of smart meter (100) i can be stored in the form of a DID Document.
[0091] Smart meter (100) is the DID of the smart meter (100) i A request for registration of a smart meter (100) is sent to the central server (300) (S124).
[0092] Specifically, the smart meter (100) has an initial challenge value (C) of the smart meter (100). i ) is input into the built-in PUF (Physical Unclonable Function, physical unclonable technology) to obtain the first digital variable information (Re) of the unique smart meter (100). i ) can be created.
[0093] The smart meter (100) is a first digital variable information (Re) of the smart meter (100). i ) is input into the Fuzzy Extractor to obtain the first secret key (smr) of the smart meter (100). i ) and the first auxiliary string (δ) of the smart meter (100) i ) can be created.
[0094] The smart meter (100) uses a hash function to obtain the first secret key (smr) of the smart meter (100). i ) and the first ID of the smart meter (100) i ) based on the second ID (HID) of the masked smart meter (100) i ) can be created.
[0095] The smart meter (100) uses a hash function to obtain the first secret key (smr) of the smart meter (100). i ), the first ID of the smart meter (100) i ), the first password (PW) of the smart meter (100) i ) based on the masked second password (HPW) i ) can be created.
[0096] Here, the second ID (HID) of the smart meter (100) i ) and second password (HPW i ) is the first ID of the smart meter (100) i ) and first password (PW i ) indicates the ID and password in a masked state.
[0097] The smart meter (100) transmits the DID of the smart meter (100) to the central server (300). i , the second ID (HID) of the smart meter (100) i ), initial challenge value (C) of smart meter (100) i ) can be used to request registration of a smart meter (100).
[0098] The central server (300) is a DID of a smart meter (100). i The first symmetric key (EK) of the smart meter (100) is based on i ) and registration certificate value (SI) of smart meter (100) i ) is created (S125).
[0099] Here, the registration certificate value (SI) of the smart meter (100) i ) represents a value proving that the smart meter (100) is a device registered in the central server (300).
[0100] Specifically, the central server (300) generates a first random number (r i ) and the first random number (r) on the elliptic curve i ) point corresponding to the multiplication (R i) can be created.
[0101] Below, the first random number (r) on the elliptic curve i ) point corresponding to the multiplication (R i ) is referred to as a point on the first elliptic curve.
[0102] The central server (300) uses a hash function to generate a first random number (r i ) and the second ID (HID) of the smart meter (100) i ) based on PHID i can be created.
[0103] Here, PHID i It represents the masking ID of a smart meter (100) that has undergone an additional process, and is referred to as the third ID of the smart meter (100) below.
[0104] The central server (300) receives the third ID (PHID) of the smart meter (100) i ), initial challenge value (C) of smart meter (100) i ) Point on the first elliptic curve (R i ), the private key (sk) of the central server (300) TA ) as shown in the following mathematical formula 3, the first symmetric key (EK) i ) can be created.
[0105]
[0106] Here, EK i is the first symmetric key, h() is the hash function, and PHID i is the third ID of the smart meter, and C i is the initial challenge value of the smart meter, and R i is a point on the first elliptic curve, and sk TA represents the private key of the central server.
[0107] The central server (300) is a DID of a smart meter (100). i , the public key (PK) of the central server (300) TA ), first random number (ri ), point on the first elliptic curve (R i ), the private key (sk) of the central server (300) TA ) based on the registration certificate value (SI) of the smart meter (100) i ) can be created.
[0108] The central server (300) registers the registration certificate value (SI) of the smart meter (100) using the following mathematical formula 4. i ) can be created.
[0109]
[0110] Here, SI i is the registration certificate value of the smart meter, and r i is the first random number, h() is the hash function, and DID i is a distributed identifier of smart meters, and PK TA is the public key of the central server, and R i is a point on the first elliptic curve, and sk TA represents the private key of the central server.
[0111] The central server (300) stores the third ID (PHID) of the smart meter (100), which is information for identifying the smart meter (100). i ), the second ID (HID) of the smart meter (100) i ), DID of smart meter (100) i , point on the first elliptic curve (R i ), initial challenge value (C) of smart meter (100) i ) can be stored in the database.
[0112] The central server (300) provides the DID of the smart meter (100), which is the verification value required to authenticate the smart meter (100). i , point on the first elliptic curve (R i ) can be transmitted to an aggregator (200) that manages the area where the smart meter (100) is located.
[0113] Here, the aggregator (200) is the DID of the smart meter (100).i , point on the first elliptic curve (R i ) can be stored in the database.
[0114] The central server (300) stores the third ID (PHID) of the smart meter (100), which is a value generated through the smart meter registration process. i ), registration certificate value (SI) of smart meter (100) i ), point on the first elliptic curve (R i ), first symmetric key (EK i ) can be transmitted to the smart meter (100).
[0115] Smart meter (100) is the DID of the smart meter (100) i Based on the registration certificate value (SI) of the smart meter (100) i ) is verified (S126).
[0116] The smart meter (100) is registered with the following mathematical formula 5 (SI) i ) can be verified.
[0117]
[0118] Here, SI i is the registration certificate value of the smart meter, P is the generator, h() is the hash function, and DID i is a distributed identifier of smart meters, and PK TA is the public key of the central server, and R i represents a point on the first elliptic curve.
[0119] Smart meter (100) is the third ID of the smart meter (HPW i ) and second password (PHID i Based on the masking data (A) of the smart meter (100) i ) and the first hash value (B) for user verification i ) is created (S127).
[0120] That is, the smart meter (100) uses the ID and password of the smart meter that was previously created to mask the smart meter (100) data (A i ) and the first hash value (B) for user verification i ) can be created.
[0121] Specifically, the smart meter (100) uses the following mathematical expression 6 to obtain the second password (HPW) of the smart meter (100). i ), the third ID (PHID) of the smart meter (100) i ), first symmetric key (EK i ), registration certificate value (SI) of smart meter (100) i ) based on the masking data (A) of the masked smart meter (100) i ) can be generated by calculating.
[0122]
[0123] Here, A i is the masking data of smart meters, and HPW i is the second password of the smart meter, PHID i is the third ID of the smart meter, EK i is the first symmetric key, and SI i Indicates the registration certificate value of the smart meter.
[0124] The smart meter (100) uses the following mathematical formula 7 to obtain the second ID (HID) of the smart meter (100) i ), the second password (HPW) of the smart meter (100) i ), first symmetric key (EK i ), the third ID (PHID) of the smart meter (100) i ) for user verification based on the first hash value (B i ) can be generated by calculating.
[0125]
[0126] Here, B iis the first hash value, h() is the hash function, and HID i is the second ID of the smart meter, and HPW i is the second password of the smart meter, EK i is the first symmetric key, and PHID i represents the third ID of the smart meter.
[0127] Smart meter (100) is masking data (A) of smart meter (100) i ), first hash value (B i ), the first auxiliary string (δ) of the smart meter (100) i ), initial challenge value (C) of smart meter (100) i ), DID of smart meter (100) i can be stored in memory.
[0128] Next, referring again to FIG. 2, the central server (300) registers the aggregator (200) (S130).
[0129] In more detail, referring to FIG. 5, the aggregator (200) has a first ID (ID) of the aggregator (200). j ), the private key (sk) of the aggregator (200) j ), the initial challenge value (C) of any aggregator (200) j ) is selected (S131).
[0130] The aggregator (200) is the private key (sk) of the aggregator (200). j ) using the public key (PK) of the aggregator (200) j ) is created (S132).
[0131] Here, the aggregator (200) uses the following mathematical expression 8 to obtain the public key (PK) of the aggregator (200). j ) can be generated by calculating.
[0132]
[0133] Here, PK J is the public key of the aggregator, and skJ is the private key of the aggregator, and P represents the generator.
[0134] The aggregator (200) is the DID of the aggregator (200). J To generate the public key (PK) of the aggregator (200) in the blockchain (400) j ) is transmitted to the blockchain (400) to DID j Request for creation, and the blockchain (400) receives the public key (PK) of the aggregator (200) j ) DID of the aggregator (200) corresponding to j is transmitted to the aggregator (200) (S133).
[0135] Here, the blockchain (400) is the public key (PK) of the aggregator (200) j ) and DID of the aggregator (200) j can be saved.
[0136] The aggregator (200) is the DID of the aggregator (200). j A request for registration of the aggregator (200) is sent to the central server (300) (S134).
[0137] Specifically, the aggregator (200) has an initial challenge value (C) of the aggregator (200). j ) is input into the built-in PUF to input the digital variable information (Re) of the unique aggregator (200). j ) can be created.
[0138] The aggregator (200) stores digital variable information (Re) of the aggregator (200). j ) into the perch extractor to obtain the secret key (smr) of the aggregator (200) j ) and auxiliary string (δ) of the aggregator (200) j ) can be created.
[0139] The aggregator (200) uses a hash function to obtain the secret key (smr) of the aggregator (200). j ) and the first ID of the aggregator (200) j) using the masked aggregator (200) ID (HID) j ) can be created.
[0140] Below, the ID (HID) of the masked aggregator (200) j ) is the second ID (HID) of the aggregator (200) j ) is referred to as.
[0141] The aggregator (200) transmits the DID of the aggregator (200) to the central server (300). j , the second ID (HID) of the aggregator (200) j ), the initial challenge value (C) of the aggregator (200) j ) can be sent to request registration of the aggregator (200).
[0142] The central server (300) is the DID of the aggregator (200). j The registration certificate value (SI) of the aggregator (200) is based on j ) is created (S135).
[0143] Specifically, the central server (300) generates a second random number (r j ) and the second random number (r) of the generator (P) on the elliptic curve j ) point corresponding to the product (R j ) can be created.
[0144] Below, the second random number (r) of the generator (P) on the elliptic curve j ) point corresponding to the product (R j ) is referred to as a point on the second elliptic curve.
[0145] The central server (300) generates a second random number and a second ID (HID) of the aggregator (200). j ) based on the PHID of the aggregator (200) j can be created.
[0146] Here, PHID jrepresents the masked ID of the aggregator (200) that has gone through an additional process, and is hereinafter referred to as the third ID (PHID) of the aggregator (200). j ) is referred to as.
[0147] The central server (300) is the DID of the aggregator (200). j , the third ID (PHID) of the aggregator (200) j ), the private key (sk) of the central server (300) TA ), point on the second elliptic curve (R j ), the private key (sk) of the central server (300) TA ) to prove that the aggregator (200) is a device registered in the central server (300). j ) can be created.
[0148] The central server (300) uses the following mathematical expression 9 to obtain the registration certificate value (SI) of the aggregator (200). j ) can be generated by calculating.
[0149]
[0150] Here, SI j is the registration certificate value of the aggregator, and r j is the second random number, h() is the hash function, and DID j is the distributed identifier of the aggregator, PHID j is the third ID of the aggregator, and PK TA is the public key of the central server, and R j is a point on the second elliptic curve, and sk TA represents the private key of the central server (300).
[0151] The central server (300) stores the third ID (PHID) of the aggregator (200), which is information for identifying the aggregator (200). j ), the second ID (HID) of the aggregator (200) j ), point on the second elliptic curve (R j), the initial challenge value (C) of the aggregator (200) j ) is stored in the database.
[0152] The central server (300) is the third ID (PHID) of the aggregator (200) j ), registration certificate value (SI) of the aggregator (200) j ), point on the second elliptic curve (R j ) is transmitted to the aggregator (200).
[0153] The aggregator (200) is the DID of the aggregator (200). j The registration certificate value (SI) of the aggregator (200) is based on j ) is verified (S136).
[0154] The aggregator (200) can verify the registration certificate value of the aggregator (200) using the following mathematical expression 10.
[0155]
[0156] Here, SI j is the registration certificate value of the aggregator, P is the generator, h() is the hash function, and DID j is the distributed identifier of the aggregator, and PK TA is the public key of the central server, and R j represents a point on the second elliptic curve.
[0157] The aggregator (200) that has obtained the registration result from the central server (300) uses the second ID (HID) of the aggregator (200) j ), the third ID (PHID) of the aggregator (200) j ), registration certificate value (SI) of the aggregator (200) j ) is used to mask the data (HD) of the aggregator (200) j ) is generated by calculating (S137).
[0158] The central server (300) uses the following mathematical expression 11 to mask the aggregator (200) data (HD j ) can be generated by calculating.
[0159]
[0160] Here, HD j is the masking data of the aggregator, and HID j is the second ID of the aggregator, PHID j is the third ID of the aggregator, and SI j Indicates the registration certificate value of the aggregator.
[0161] The central server (300) is the DID of the aggregator (200). j , masking data (HD) of the aggregator (200) j ), the initial challenge value (C) of the aggregator (200) j ), auxiliary string (δ) of the aggregator (200) j ) is stored in memory.
[0162] Next, referring again to FIG. 2, the smart meter (100) transmits the collected and measured information to the central server (300) via the aggregator (200) for authentication (S140).
[0163] In more detail, referring to FIG. 6, the smart meter (100) collects and measures information (Data i ) to the central server (300) to transmit the first ID (ID) of the smart meter (100) from the user. i ) and first password (PW i ) is input (S141).
[0164] Smart meter (100) is masking data (A) of smart meter (100) generated in the registration stage i ) is used to generate a second hash value (S142).
[0165] Specifically, the smart meter (100) has an initial challenge value (C) of the smart meter (100). i ) is input into the PUF to input the first digital variable information (Re) of the smart meter (100). i ) can be created.
[0166] The smart meter (100) is a first digital variable information (Re) of the smart meter (100) generated through a fuzzy extractor. i ) and the first auxiliary string (δ) of the smart meter (100) i ) based on the first secret key (smr) of the smart meter (100) i ) can be created.
[0167] Smart meter (100) is the ID of smart meter (100) i ) and the first secret key (smr) of the smart meter (100) i ) to the second ID (HID) of the smart meter (100) i ) can be created.
[0168] The smart meter (100) has a first ID (ID) of the smart meter (100) i ), the first password (PW) of the smart meter (100) i ) and the first secret key (smr) of the smart meter (100) i ) to enter the second password (HPW) of the smart meter (100) i ) can be created.
[0169] The smart meter (100) has a second password (HPW) of the smart meter (100) i ) and masking data of smart meter (100) (A i ) based on the third ID (PHID) of the smart meter (100) stored in the memory at the registration stage i ), first symmetric key (EK i ) and registration certificate value (SI) of smart meter (100) i ) can be obtained.
[0170] The smart meter (100) has a second ID (HID) of the smart meter (100) i ), the second password (HPW) of the smart meter (100) i ), first symmetric key (EK i ), the third ID (PHID) of the smart meter (100) i) using the second hash value (B') i ) can be created.
[0171] The smart meter (100) uses the following mathematical expression 12 to obtain the hash value (B') i ) can be created.
[0172]
[0173] Here, B' i is the second hash value, h() is the hash function, and HID i is the second ID of the smart meter, HPW i is the second password of the smart meter, EK i is the first symmetric key, and PHID i represents the third ID of the smart meter.
[0174] The smart meter (100) generates the first hash value (B) at the registration stage. i ) and the second hash value (B' i ) is verified to verify whether it is the correct user's access (S143).
[0175] Once the correct user access request is confirmed, the smart meter (100) generates a first symmetric key (EK i ) is used to encrypt the collected and measured information (S144).
[0176] Specifically, the smart meter (100) has a first timestamp (T i ) and generate the first symmetric key (EK i ) collected and measured using data i ) can be encrypted.
[0177] Here, the first timestamp (T i ) represents a timestamp generated after a valid user access request has been confirmed.
[0178] The smart meter (100) is a first symmetric key (EK) i ) is used to encrypt information (ED) using the following mathematical formula 13. i) can be created.
[0179]
[0180] Here, ED i is the encrypted information, Enc is the encryption function, and EK i is the first symmetric key, and Data i represents information collected and measured from smart meters.
[0181] Smart meter (100) is encrypted information (ED i ) and registration certificate value (SI) of smart meter (100) i ) based on encrypted information (ED) i ) Signature value for integrity and authentication verification (MS i ) is generated and a message is transmitted to the aggregator (200) (S145).
[0182] Here, the smart meter (100) is registered with the central server (300) to prove that the smart meter (100) has registered with the registration certificate value (SI) of the smart meter (100). i ), encrypted information (ED i ), public key (PK) of smart meter (100) i ), DID of smart meter (100) i , the first timestamp (T i ), private key (sk) of smart meter (100) i ) using encrypted information (ED) i ) signature value (MS i ) can be created.
[0183] The smart meter (100) uses the following mathematical formula 14 to encrypt information (ED) i ) signature value (MS i ) can be created.
[0184]
[0185] Here, MS i is the signature value of encrypted information, and SI iis the registration certificate value of the smart meter, h() is a hash function, and ED i is encrypted information, and PK i is the public key of the smart meter, and DID i is the distributed identifier of the smart meter, and T i is the first timestamp, and sk i represents the private key of the smart meter.
[0186] The smart meter (100) transmits encrypted information (ED) to the aggregator (200) i ), the signature value of the encrypted information (MS i ), DID of smart meter (100) i , the first timestamp (T i ) can be sent.
[0187] When the aggregator (200) receives a message transmitted from each of multiple smart meters (100) within the management area, the aggregator (200) signs the encrypted information for the message (MS) to verify its integrity and whether it is a registered smart meter. i ) are verified in batches (S165).
[0188] Here, the aggregator (200) receives messages from multiple smart meters (100) and the DID of the smart meter i The signature value of the encrypted information (MS) based on i ) can be verified in bulk.
[0189] Specifically, the aggregator (200) stores the first timestamp (T) of each message. i ) can be checked.
[0190] The aggregator (200) can check the timestamp of each message using the following mathematical expression 15.
[0191]
[0192] Here, T2 is the timestamp generated after the aggregator receives the message from the smart meter, and Ti is the first timestamp, and △T represents the threshold.
[0193] The aggregator (200) stores the DID of each smart meter (100) in the blockchain (400) and the database of the aggregator (200). i The corresponding public key (PK) i ) can be obtained.
[0194] The aggregator (200) stores the DID of each smart meter stored in the database of the aggregator (200). i Point on the first elliptic curve corresponding to (R i ) and public key (PK) of smart meter (100) i ) to verify the integrity of the message received from each smart meter (100) and whether it is a registered smart meter, using the signature value (MS) of the encrypted information. i ) can be verified in bulk.
[0195] The aggregator (200) uses the following mathematical expression 16 to obtain the signature value (MS) of the encrypted information for each message. i ) can be verified in bulk.
[0196]
[0197] Here, MS i is the signature value of the encrypted information, P is the generator, and R i is a point on the first elliptic curve, h() is a hash function, and DID i is the distributed identifier of the smart meter, and PK TA is the public key of the central server, and ED i is encrypted information, and PK i is the public key of the smart meter, and T i represents the first timestamp.
[0198] If batch verification fails, the aggregator (200) can individually verify messages to detect incorrect messages and retransmit the messages to the smart meter (200) that transmitted the incorrect messages.
[0199] The signature value of the encrypted information for each message (MS i ) is completed, the aggregator (200) generates a second timestamp (T j ) and generate the initial challenge value (C) of the aggregator (200). j ) digital variable information of the aggregator (200) generated based on j ) to obtain the registration certificate value (SI) of the aggregator (200) j ) is created (S147).
[0200] Specifically, the aggregator (200) has an initial challenge value (C) of the aggregator (200). j ) is input into the PUF to input the digital variable information (Re) of the aggregator (200). j ) can be created.
[0201] The aggregator (200) generates digital variable information (Re) of the aggregator (200) through a fuzzy extractor. j ), auxiliary string (δ) of the aggregator (200) j ) as input to the aggregator (200)'s secret key (smr j ) can be obtained.
[0202] The aggregator (200) has a secret key (smr) of the aggregator (200) j ), the first ID of the aggregator (200) j ) to the second ID (HID) of the aggregator (200) j ) and the masking data (HD) of the aggregator (200) stored in the database j ) and the second ID (HID) of the aggregator (200) j ) using the third ID (PHID) of the aggregator (200) j ), registration certificate value (SI) of the aggregator (200) j ) can be obtained.
[0203] The aggregator (200) concatenates (AD) the messages received from each smart meter (100). j ) and the signature value of the combined message (MS j ) is created (S148).
[0204] Combined Message (AD) j ) can be expressed by the following mathematical formula 17.
[0205]
[0206] Here, AD j is a combined message, and DID n is the encrypted information of each smart meter, and DID n represents the decentralized identity of each smart meter.
[0207] The aggregator (200) is a registration certificate value (SI) of the generated aggregator (200). j ), combined message (AD) j ), public key (PK) of the aggregator (200) j ), the third ID (PHID) of the aggregator (200) j ), second timestamp (T j ) to combine the signature value of the message (MS j ) can be created.
[0208] The aggregator (200) uses the following mathematical expression 18 to obtain the signature value (MS) of the combined message. j ) can be generated by calculating.
[0209]
[0210] Here, MS j is the signature value of the combined message, h() is the hash function, and AD j is a combined message, and PK i is the public key of the smart meter, and PHID j is the third ID of the aggregator, and T j is the first timestamp, and sk j represents the aggregator's private key.
[0211] The aggregator (200) combines the messages (AD j ), the signature value of the combined message (MS j ), DID of the aggregator (200) j , the second timestamp (T j ) is transmitted to the central server (300).
[0212] When the central server (300) receives a combined message, it performs verification of the signature value of the combined message (S149).
[0213] Specifically, the central server (300) sends a second timestamp (T j ) can be checked using the following mathematical expression 19.
[0214]
[0215] Here, T3 is the timestamp generated after the central server receives the message from the aggregator, and T i is the first timestamp, and △T represents the threshold.
[0216] The central server (300) stores the DID of the aggregator (200) stored in the blockchain (400). j The corresponding public key (PK) j ) and points on the second elliptic curve (R j ) can be obtained to perform verification on the combined message.
[0217] The central server (300) can perform verification on the combined message using the following mathematical expression 20.
[0218]
[0219] Here, MS j is the signature value of the encrypted information, P is the generator, and R j is a point on the second elliptic curve, h() is a hash function, and DID j is the distributed identifier of the aggregator, and PHID iis the third ID of the aggregator, and PK TA is the public key of the central server, and AD j is a combined message, PK j is the public key of the aggregator, and T j represents the second timestamp.
[0220] Once verification is complete, the central server (300) splits the combined message and decrypts the combined message. DID of the smart meter (100) i The symmetric key (EK) stored in response to i ) is used to decrypt the message (S150).
[0221] Next, referring back to Figure 2, the central server (300) and the smart meter (100) use a symmetric key (EK) to encrypt and decrypt information. i ) has expired or when it is determined that an update is necessary, a key update is performed (S160).
[0222] Referring to FIG. 7, the smart meter (100) receives the first ID (ID) of the smart meter (100) from the user. i ) and first password (PW i ) is input (S161).
[0223] Smart meter (100) is masking data (A) of smart meter (100) generated in the registration stage i ) is used to generate a second hash value (S162).
[0224] The smart meter (100) generates the first hash value (B) at the registration stage. i ) and the second hash value (B' i ) is verified to be the same and to verify whether it is the correct user's access (S163).
[0225] Steps S161 to S163 are identical to steps S141 to S143 of Fig. 5, so duplicate descriptions are omitted.
[0226] Once the access request from the correct user is confirmed, the smart meter (100) sends a new challenge value (C) to the smart meter (100). i new ) and generate the first symmetric key (EK i ) and new challenge values (C) of smart meters (100) i new ) to generate a first request value for key update (S164).
[0227] Specifically, the smart meter (100) has a new challenge value (C) of the smart meter (100). i new ) into the PUF to input new digital variable information (Re) of the smart meter (100). i new ) can be created.
[0228] Below, new digital variable information (Re i new ) is the second digital variable information (Re i new ) is referred to as.
[0229] The smart meter (100) is a second digital variable information (Re) of the smart meter (100). i new ) into the fuzzy extractor to obtain a new secret key (smr) of the smart meter (100). i new ) and a new auxiliary string (δ) of the smart meter (100) i new ) can be created.
[0230] Here, the new secret key (smr) of the smart meter (100) i new ) and a new auxiliary string (δ i new ) is the second secret key (smr) of the smart meter (100) i new ) and the second auxiliary string (δ i new ) is referred to as.
[0231] The smart meter (100) has a second secret key (smr) of the smart meter (100) i new ), the first ID of the smart meter (100) i ) using a new masked ID (HID) i new ) can be created.
[0232] Here, the new masked ID (HID) of the smart meter (100) i new ) is referred to as the fourth ID of the smart meter (100).
[0233] The smart meter (100) has a second secret key (smr) of the smart meter (100) i new ), the first ID of the smart meter (100) i ), the first password (PW) of the smart meter (100) i ) to create a new masked password (HPW i new ) can be created.
[0234] Here, the new masked password (HPW) of the smart meter (100) i new ) is referred to as the fourth password of the smart meter (100).
[0235] The smart meter (100) uses a hash function to obtain the third ID (PHID) of the smart meter (100). i ), first symmetric key (EK i ), public key (PK) of smart meter (100) i ), new challenge value (C) of smart meter (100) i new ) based on the first request value (REQ i ) can be created.
[0236] The smart meter (100) uses the following mathematical expression 21 to obtain the first request value (REQ i ) can be created.
[0237]
[0238] Here, REQ i is the first request value, h() is a hash function, and PHID i is the third ID of the smart meter, EK i is the first symmetric key, and PK i is the public key of the smart meter, and C i new represents a new challenge value of the smart meter (100).
[0239] The smart meter (100) uses the third ID (PHID) of the smart meter (100) to update the first symmetric key. i ), new challenge value (C) of smart meter (100) i new ), DID of smart meter (100) i , the first request value (REQ i ) is transmitted to the central server (300) (S165).
[0240] When the central server (300) receives a key update request message from the smart meter (100), it generates a first symmetric key (EK) based on the initial challenge value of the smart meter (100). i ) and obtain the first symmetric key (EK i ) based on the second request value (REQ i * ) is created (S166).
[0241] Specifically, the central server (300) stores the third ID (PHID) of the smart meter (100) stored in the database i ) using the DID of the smart meter (100) i Point on the first elliptic curve corresponding to (R i ), initial challenge value (C) of smart meter (100) i ) and obtain a third random number (n new ) can be selected.
[0242] The central server (300) receives the third ID (PHID) of the smart meter (100) i), initial challenge value (C) of smart meter (100) i ), point on the first elliptic curve (R i ), the private key (sk) of the central server (300) TA ) using the first symmetric key (EK) i ) can be obtained.
[0243] The central server (300) receives the third ID (PHID) of the smart meter (100) i ), first symmetric key (EK i ), public key (PK) of smart meter (100) i ), new challenge value (C i new ) using the second request value (REQ i * ) can be created.
[0244] The central server (300) uses the following mathematical expression 22 to generate the second request value (REQ i * ) can be generated by calculating.
[0245]
[0246] Here, REQ i * is the second request value, h() is a hash function, and PHID i is the third ID of the smart meter, EK i is the first symmetric key, and PK i is the public key of the smart meter, and C i new represents a new challenge value of the smart meter (100).
[0247] The central server (300) sends the first request value (REQ i ) and the second request value (REQ i * ) is verified to be identical (S167).
[0248] If the test result is correct, the central server (300) sends a new challenge value (C) to the smart meter (100). i new ) based on the second symmetric key (EK)i new ) and response value (REK i ) is created (S168).
[0249] Specifically, the central server (300) generates a third random number (n) of the generator on the elliptic curve. new ) point corresponding to the product (N new ) can be created.
[0250] Below, the third random number (n) of the generator on the elliptic curve new ) point corresponding to the product (N new ) is a point on the third elliptic curve (N new ) is referred to as.
[0251] The central server (300) generates a third random number (n new ), new challenge value (C) of smart meter (100) i new ), point on the third elliptic curve (N new ), the private key (sk) of the central server (300) TA ) using the second symmetric key (EK) i new ) can be created.
[0252] The central server (300) uses the following mathematical expression 23 to generate the second symmetric key (EK) i new ) can be created.
[0253]
[0254] Here, EK i new is the second symmetric key, h() is the hash function, and PHID i is the third ID of the smart meter, and C i new is a new challenge value for smart meters, and N new is a point on the third elliptic curve, and sk TA represents the private key of the central server.
[0255] The central server (300) stores the private key (sk) of the central server (300) TA), the third ID (PHID) of the smart meter (100) i ), new challenge value (C i new ), second symmetric key (EK) i new ), point on the third elliptic curve (N new ), third random number (n new ) to prove integrity using a response value (REK) i ) can be created.
[0256] The central server (300) uses the following mathematical expression 24 to generate a response value (REK i ) can be generated by calculating.
[0257]
[0258] Here, REK i is the response value, and sk TA is the private key of the central server, h() is the hash function, and PHID i is the third ID of the smart meter, and C i new is the new challenge value of the smart meter (100), and EK i new is the second symmetric key, and N new is a point on the third elliptic curve, and n new represents the third random number.
[0259] The central server (300) retrieves the third ID (PHID) of the smart meter (100) from the database. i ), the second ID (HID) of the smart meter (100) i ), DID of smart meter (100) i , point on the first elliptic curve (R i ), new challenge value (C) of smart meter (100) i new ), point on the third elliptic curve (N new ) can be updated.
[0260] The central server (300) is a second symmetric key (EK) i new), response value (REK i ) and the point on the third elliptic curve (N) required for signature verification new ) can be transmitted to the smart meter (100).
[0261] When the smart meter (100) receives a message from the central server (300), the smart meter (100) sends a new challenge value (C) of the smart meter (100). i new ), second symmetric key (EK) i new ) based on the response value (REK) i ) is verified (S169)
[0262] Here, the smart meter (100) uses the following mathematical expression 25 to calculate the response value (REK i ) can be verified.
[0263]
[0264] Here, REK i is the response value, P is the generator, and PK TA is the public key of the central server, h() is the hash function, and PHID i is the third ID of the smart meter, and C i new is the new challenge value for smart meters (100), EK i new is the second symmetric key, and N new represents a point on the third elliptic curve.
[0265] If the verification result is correct, the smart meter (100) uses the first symmetric key (EK i ) as the second symmetric key (EK) i new ) can be updated (S170).
[0266] Specifically, the smart meter (100) uses the following mathematical expression 26 to set the second password (HPW) of the smart meter (100) i ), the third ID (PHID) of the smart meter (100) i ), second symmetric key (EK) inew ) to encrypt the masking data (A) of the smart meter (100) based on i new ) can be updated.
[0267]
[0268] Here, A i new is the masking data of the updated smart meter, and HPW i is the second password of the smart meter, PHID i is the third ID of the smart meter, EK i new represents the second symmetric key.
[0269] The smart meter (100) uses the following mathematical expression 27 to obtain the second ID (HID) of the smart meter (100) i ), the second password (HPW) of the smart meter (100) i ), second symmetric key (EK) i new ), the third ID (PHID) of the smart meter (100) i ) based on the first hash value (B i ) to update the second hash value (B) for user verification. i new ) can be created.
[0270]
[0271] Here, B i new is the second hash value, h() is the hash function, and HID i is the second ID of the smart meter, HPW i is the second password of the smart meter, EK i new is the second symmetric key, and PHID i represents the third ID of the smart meter.
[0272] That is, the smart meter (100) has the masking data (A) of the smart meter (100) updated in the memory.i new ), second hash value (B i new ), new challenge value (C) of smart meter (100) i new ), the second auxiliary string (δ) of the smart meter (100) i new ) can be updated.
[0273]
[0274] As described above, according to the present invention, by performing batch verification of messages transmitted from multiple smart meters within a management area through an aggregator, the central server can reduce the burden of the large-scale message verification process and the burden on system and service operation. Furthermore, by verifying messages in the aggregator, abnormal messages can be verified and processed in advance, and attacks such as DoS can be responded to without significantly impacting overall system operation. Furthermore, by utilizing blockchain and DID technology to implement a decentralized authentication method, system availability and reliability can be improved.
[0275]
[0276] Those skilled in the art will appreciate that the embodiments of the present invention can be implemented in modified forms without departing from the essential characteristics of the above description. Therefore, the disclosed methods should be considered illustrative rather than restrictive. The scope of the present invention is determined by the claims, not the detailed description, and all differences within the scope equivalent thereto should be construed as being included within the scope of the present invention.
[0277]
[0278] <Explanation of symbols>
[0279] 1: Smart Authentication System
[0280] 100: Smart Meter
[0281] 200: Aggregator
[0282] 300: Central Server
[0283] 400: Blockchain
[0284]
[0285] According to the smart authentication system and method of the present invention, by performing batch verification on messages transmitted from a plurality of smart meters existing within a management area in an aggregator, the central server can reduce the burden of a large number of message verification processes and reduce the burden of system and service operation, and thus has high industrial applicability.
[0286] In addition, by verifying messages in the aggregator, abnormal messages can be verified and processed in advance, and attacks such as DoS can be responded to without significantly affecting the overall system operation. In addition, by enabling decentralized authentication using blockchain and DID technology, system availability and reliability can be improved, so it has high industrial applicability.
Claims
1. A step of encrypting information collected and measured by a smart meter using a first symmetric key stored in advance; A step of the smart meter generating a signature value of the encrypted information based on the encrypted information and the previously generated registration certificate value of the smart meter and transmitting a message to the aggregator; When the aggregator receives a message from each of a plurality of smart meters, a step of collectively verifying a signature value of the encrypted information for the message; When the above verification is completed, the aggregator combines messages received from each of the plurality of smart meters and generates a signature value of the combined message; When the central server receives the combined message, performing verification on the combined message; and Once verification is complete, a step of splitting the combined message and decrypting the combined message; A smart authentication method comprising:
2. In paragraph 1, A step of requesting the creation of a distributed identifier of the smart meter by transmitting the public key of the smart meter already created to the blockchain; A step in which the blockchain transmits a distributed identifier of the smart meter corresponding to the public key of the smart meter to the smart meter; A step in which the smart meter transmits the distributed identifier of the smart meter to the central server to request registration of the smart meter; A step in which the central server generates the first symmetric key and the registration certificate value of the smart meter that proves that the smart meter is a device registered with the central server based on the distributed identifier of the smart meter; and A smart authentication method, characterized in that it further includes a step of verifying the registration certificate value of the smart meter based on the distributed identifier of the smart meter.
3. In paragraph 2, The step of batch-verifying the signature value of the above encrypted information is: A smart authentication method, characterized in that it includes a step of collectively verifying the signature value of the encrypted information based on the distributed identifier of the smart meter for the message received from each of the plurality of smart meters by the aggregator.
4. In paragraph 1, A smart authentication method, characterized in that it further includes a step of generating masking data of the smart meter and a first hash value for user verification based on the ID and password of the smart meter previously generated.
5. In paragraph 4, The step of the smart meter generating a second hash value based on the masking data of the smart meter; and A smart authentication method, characterized in that it further includes a step of verifying whether the smart meter is a correct user access by verifying whether the first hash value and the second hash value are identical.
6. In paragraph 1, A step in which the aggregator transmits the public key of the aggregator that has already been generated to the blockchain to request generation of a distributed identifier of the aggregator; A step in which the blockchain generates a distributed identifier of the aggregator corresponding to the public key of the aggregator and transmits it to the aggregator; A step in which the aggregator transmits the distributed identifier of the aggregator to the central server to request registration of the aggregator; A step in which the central server generates a registration certificate value of the aggregator that proves that the aggregator is a device registered with the central server based on the distributed identifier of the aggregator; and A smart authentication method, characterized in that it further includes a step of verifying the registration certificate value of the aggregator based on the distributed identifier of the aggregator.
7. In paragraph 6, The step of generating the signature value of the above combined message is: A smart authentication method, characterized in that it includes a step of generating a signature value of the combined message based on the registration certificate value of the aggregator.
8. In paragraph 6, The step of performing verification on the above combined message is: A smart authentication method, characterized in that it comprises a step in which the central server performs verification on the combined message using the distributed identifier of the aggregator.
9. In paragraph 2, A step in which the smart meter generates a new challenge value, generates a first request value for key update based on the first symmetric key and the new challenge value, and transmits a key update request message to the central server; When the central server receives the key update request message, the central server obtains the first symmetric key based on the generated initial challenge value, and generates the second request value based on the first symmetric key; and A smart authentication method, characterized in that it further includes a step of the central server verifying whether the first request value and the second request value are identical.
10. In paragraph 9, If the verification result is correct, the central server generates a second symmetric key and a response value based on the new challenge value and transmits a message to the smart meter; When the smart meter receives the message from the central server, the smart meter verifies the response value based on the new challenge value and the second symmetric key; and A smart authentication method, characterized in that it includes a step of the smart meter updating the first symmetric key to a second symmetric key if the verification result is correct.
11. A smart meter that encrypts collected and measured information using a previously stored symmetric key and generates a signature value of the encrypted information based on the encrypted information and the previously generated registration certificate value of the smart meter; An aggregator which, when receiving a message from each of a plurality of smart meters, collectively verifies the signature value of the encrypted information for the message, and when the verification is completed, combines the messages received from each of the plurality of smart meters and generates a signature value of the combined message; A central server that, upon receiving the combined message, performs verification on the combined message, and upon completion of verification, splits the combined message and decrypts the combined message; and A blockchain that generates a distributed identifier of the smart meter and a distributed identifier of the aggregator; A smart authentication system including:
12. In paragraph 11, The above smart meter, A smart authentication system characterized by transmitting the public key of the generated smart meter to the blockchain to request generation of a distributed identifier of the smart meter.
13. In paragraph 11, The above smart meter, A smart authentication system characterized in that it transmits the distributed identifier of the smart meter to the central server and makes a request for registration of the smart meter.
14. In paragraph 11, The above aggregator, A smart authentication system characterized in that the signature value of the encrypted information is collectively verified based on the distributed identifier of the smart meter for each message received from the plurality of smart meters.
15. In paragraph 11, The above aggregator, A smart authentication system characterized by transmitting the public key of the generated aggregator to the blockchain to request generation of a distributed identifier of the aggregator.
16. In paragraph 11, The above central server, A smart authentication system characterized by performing verification on the combined message using the distributed identifier of the above aggregator.
17. In paragraph 11, The above aggregator, A smart authentication system characterized in that the distributed identifier of the aggregator is transmitted to the central server to request registration of the aggregator.
18. In paragraph 17, The above central server, A smart authentication system characterized by generating a registration certificate value of the aggregator that proves that the aggregator is equipment registered with the central server based on the distributed identifier of the aggregator.
19. In paragraph 11, The above aggregator, A smart authentication system characterized by generating a signature value of the combined message based on the registration certificate value of the above aggregator.
20. In paragraph 11, The above aggregator, A smart authentication system characterized by verifying the registration certificate value of the aggregator based on the distributed identifier of the aggregator.
Citation Information
Patent Citations
Power information transmitting and receiving system in the smart grid
KR101621931B1
Remote management apparatus and method fof updating batch parameter of smartmeter
KR101807429B1
Preamplifier with active deadtime control circuit and method for operating the same
KR1020250023749A
Remote meter read method and system using blockchain
KR102039357B1
Securitization of assets utilizing distributed-ledgers & smart meters and a user permission framework for information flow
US20230091805A1