Trusted authentication method, apparatus and device for user-side terminal, and storage medium

Verifying the identity authentication information of the user-side terminal through public key encryption and private key decryption methods is solved, and the problem of low password authentication sensitivity in the prior art is solved, thereby achieving higher identity authentication accuracy and power system data security.

WO2025112841A1PCT designated stage expired Publication Date: 2025-06-05GUANGDONG POWER GRID CO LTD DONGGUAN POWER SUPPLY BUREAU
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/120562
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-27
Filing Date
2024-09-24
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

In the prior art, password authentication is low in sensitivity to user-side terminal identity authentication, resulting in user-side terminal being easily invaded and endangering the data security of the power system.

Method used

Public key encryption and private key decryption methods are used to receive encrypted communication requests issued by the user-side terminal, establish a data transmission channel dedicated to identity authentication, verify the identity authentication information of the user-side terminal, and ensure that its true identity is a trusted identity, establish a data channel for information transmission.

Benefits of technology

It improves the identity authentication sensitivity of the user-side terminal and enhances the identity authentication accuracy of the user-side terminal, thereby ensuring the data security of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024120562_05062025_PF_FP_ABST
    Figure CN2024120562_05062025_PF_FP_ABST
Patent Text Reader

Abstract

A trusted authentication method, apparatus and device for a user-side terminal, and a storage medium. The method comprises: receiving an encrypted communication request sent by a user-side terminal, the encrypted communication request sent by the user-side terminal being encrypted by a public key (S10); by means of a private key, decrypting the encrypted communication request sent by the user-side terminal to obtain a communication request of the user-side terminal, the public key and the private key having a one-to-one corresponding relationship (S20); when the communication request of the user-side terminal is obtained, establishing a data transmission channel dedicated to identity authentication and connected to the user-side terminal (S30); on the basis of the data transmission channel, receiving identity authentication information sent by the user-side terminal, and verifying the identity authentication information to obtain a real identity of the user-side terminal (40); and when the real identity of the user-side terminal is a trusted identity, establishing a data channel with the user-side terminal, and performing information transmission on the basis of the data channel (S50).
Need to check novelty before this filing date? Find Prior Art

Description

User-side terminal trusted authentication method, device, equipment and storage medium

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 27, 2023, with application number 202311587800.3, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of user authentication technology, for example, to a user-side terminal trusted authentication method, apparatus, device and storage medium. Background Art

[0003] With the construction and development of the power Internet of Things, the number of smart terminal devices in the power system continues to grow, resulting in more and more terminal applications exposed to the monitoring site. The deployment range of these smart terminals is relatively wide, and the physical environment security is insufficient. These smart terminals on the user side are easily the main targets of network attacks and there is a risk of malicious control. In the user side terminal identity authentication, most of the authentication methods used are based on passwords. This method is prone to invasion of the user side terminal due to password leakage, and has low sensitivity to the identity of the user side terminal, thereby endangering the data security of the power system.

[0004] Summary of the Invention

[0005] The present application provides a user-side terminal trusted authentication method, device, equipment and storage medium, aiming to solve the technical problem of low sensitivity of user-side terminal identity authentication based on password authentication in related technologies.

[0006] An embodiment of the present application provides a method for trusted authentication of a user-side terminal, the method comprising: receiving an encrypted communication request issued by a user-side terminal, the encrypted communication request issued by the user-side terminal being encrypted by a public key; decrypting the encrypted communication request issued by the user-side terminal by using a private key to obtain a communication request of the user-side terminal, the public key and the private key being in a one-to-one correspondence; upon obtaining the communication request of the user-side terminal, establishing a data transmission channel dedicated to identity authentication connected to the user-side terminal; receiving identity authentication information sent by the user-side terminal according to the data transmission channel, verifying the identity authentication information, and obtaining the true identity of the user-side terminal; upon a true identity of the user-side terminal being a trusted identity, establishing a data channel with the user-side terminal, and transmitting information according to the data channel.

[0007] Optionally, the receiving of the encrypted communication request issued by the user side terminal, before the encrypted communication request issued by the user side terminal is encrypted by the public key, also includes: receiving a registration request from the user side terminal, the registration request including the identity information of the user side terminal; generating a key pair based on the identity information in the registration request, the key pair including a one-to-one corresponding public key and private key; sending the key pair to the user side terminal and storing the key, so that the user side terminal encrypts the communication request according to the public key to obtain an encrypted communication request.

[0008] Optionally, the receiving of identity authentication information sent by the user side terminal according to the transmission channel, verifying the identity authentication information, and obtaining the true identity of the user side terminal includes: obtaining the identity authentication information received by other user side terminals when the identity authentication information sent by the user side terminal is received according to the data transmission channel; obtaining an identity authentication vector table according to the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals, the other user side terminals being all user side terminals except the user side terminal; determining the number of identity authentications according to the type of identity authentication information received in the identity authentication vector table; obtaining the identity authentication result of the user side terminal according to the identity authentication number; and obtaining the true identity of the user side terminal according to the user authentication result.

[0009] Optionally, the obtaining of the identity authentication vector table based on the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals includes: broadcasting the received identity authentication information of the user side terminal, and when the other user side terminals receive the identity authentication information of the user side terminal, comparing the received identity information of the user side terminal with the identity authentication information received from the user side terminal to obtain identity voting information; obtaining the identity voting information of the other user side terminals, and obtaining the identity authentication vector table based on the identity voting information.

[0010] Optionally, obtaining the true identity of the user side terminal according to the user authentication result includes: when the user authentication result is authentication passed, outputting the true identity of the user side terminal as a normal user side terminal; when the user authentication result is authentication failed, outputting the true identity of the user side terminal as a first abnormal user side terminal.

[0011] Optionally, obtaining the identity voting information of the other user side terminals and obtaining the identity authentication vector table based on the identity voting information includes: detecting the identity voting information of the other user sides, and when the identity voting information is empty, reducing the voting weight of the other user side terminals whose identity voting information is empty; counting the number of identity voting information of the other user side terminals whose identity voting information is empty; and when the ratio of the number of identity voting information reaches a preset ratio, marking the other user side terminals whose number of identity voting information reaches the preset ratio as second abnormal user side terminals.

[0012] Optionally, after obtaining the true identity of the user side terminal according to the user authentication result, the method further includes: comparing the true identity of the user side terminal with the identity voting information of other user side terminals; when the true identity of the user side terminal is consistent with the identity voting information of the other user side terminals, increasing the voting weight of the user side terminal corresponding to the identity voting information; when the true identity of the user side terminal is inconsistent with the identity voting information of the other user side terminals, reducing the voting weight of the user side terminal corresponding to the identity voting information.

[0013] An embodiment of the present application also proposes a user-side terminal trusted authentication device, which includes: a request receiving module, configured to receive an encrypted communication request issued by a user-side terminal, wherein the encrypted communication request issued by the user-side terminal is encrypted by a public key; a request processing module, configured to decrypt the encrypted communication request issued by the user-side terminal by a private key to obtain the communication request of the user-side terminal, and the public key and the private key are in a one-to-one correspondence; a data transmission channel establishment module, configured to establish a data transmission channel dedicated to identity authentication connected to the user-side terminal when the communication request of the user-side terminal is obtained; an identity authentication module, configured to receive identity authentication information sent by the user-side terminal according to the data transmission channel, verify the identity authentication information, and obtain the true identity of the user-side terminal; a communication establishment module, configured to establish a data channel with the user-side terminal when the true identity of the user-side terminal is a trusted identity, and transmit information according to the data channel.

[0014] An embodiment of the present application also proposes a user-side terminal trusted authentication device, which includes: a memory, a processor, and a user-side terminal trusted authentication program stored on the memory and executable on the processor, wherein the user-side terminal trusted authentication program is configured to implement the user-side terminal trusted authentication method described above.

[0015] An embodiment of the present application further provides a storage medium, on which a user-side terminal trusted authentication program is stored. When the user-side terminal trusted authentication program is executed by a processor, the user-side terminal trusted authentication method described above is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] FIG1 is a schematic diagram of the structure of a user-side terminal trusted authentication device in a hardware operating environment according to an embodiment of the present application;

[0017] FIG2 is a flow chart of a first embodiment of a method for authenticating a user-side terminal according to the present invention;

[0018] FIG3 is a flowchart of an identity authentication method according to an embodiment of the present invention;

[0019] FIG4 is a flow chart of a second embodiment of a method for authenticating a user-side terminal according to the present invention;

[0020] FIG5 is a schematic diagram of user-side terminal identity authentication according to an embodiment of a user-side terminal trusted authentication method of the present application;

[0021] FIG6 is an identity authentication vector table of an embodiment of a user-side terminal trusted authentication method of the present application;

[0022] FIG7 is a structural block diagram of the first embodiment of the user-side terminal trusted authentication device of the present application. DETAILED DESCRIPTION

[0023] It should be understood that the embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0024] Refer to Figure 1, which is a schematic diagram of the structure of a user-side terminal trusted authentication device in the hardware operating environment involved in the embodiment of the present application.

[0025] As shown in Figure 1, the user-side terminal trusted authentication device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is configured to implement connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and optionally the user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as a disk storage. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0026] Those skilled in the art will understand that the structure shown in FIG1 does not constitute a limitation on the user-side terminal trusted authentication device, and may include more or fewer components than shown in the figure, or a combination of some components, or a different arrangement of components.

[0027] As shown in FIG. 1 , the memory 1005 as a storage medium may include an operating system, a network communication module, a user interface module, and a user-side terminal trusted authentication program.

[0028] In the user-side terminal trusted authentication device shown in Figure 1, the network interface 1004 is mainly configured to communicate data with the network server; the user interface 1003 is mainly configured to interact data with the user; the processor 1001 and the memory 1005 in the user-side terminal trusted authentication device of this application can be set in the user-side terminal trusted authentication device, and the user-side terminal trusted authentication device calls the user-side terminal trusted authentication program stored in the memory 1005 through the processor 1001, and executes the user-side terminal trusted authentication method provided by the embodiment of this application.

[0029] An embodiment of the present application provides a user-side terminal trusted authentication method. Referring to FIG. 2 , FIG. 2 is a flow chart of a first embodiment of a user-side terminal trusted authentication method of the present application.

[0030] In this embodiment, the user-side terminal trusted authentication method includes the following steps.

[0031] Step S10: receiving an encrypted communication request sent by a user-side terminal, where the encrypted communication request sent by the user-side terminal is encrypted by a public key.

[0032] It should be noted that the executor of this embodiment is the user-side terminal trusted authentication device, wherein the user-side terminal trusted authentication device has functions such as data processing, data communication and program running. The user-side terminal trusted authentication device can be an integrated controller, control computer and other devices. Of course, it can also be other devices with similar functions. This embodiment does not limit this.

[0033] It is understandable that due to the wide distribution of user-side terminal devices and the lack of physical environment security, there is a possibility that user-side terminal devices may fail or be invaded, becoming malicious terminals. For failed user-side terminals, the threat to the data security of the power system is relatively small, while malicious terminals will continue to attack the power system and try to obtain system data from the power system. During data communication, the server of the power system is in a high-protection environment, which can ensure that the server of the power system will not be attacked. On this basis, it is necessary to authenticate the identity of the user-side terminal devices connected to the power system to ensure that the identity of the terminal establishing the connection is credible. During the data transmission process, the malicious terminal is an abnormal terminal node in the power system, and its purpose is to obtain relevant data in the power system by deceiving it. Therefore, subjectively, the malicious terminal will engage in deception, while the normal terminal is honest, and identity authentication can be performed based on this feature.

[0034] In the implementation, before the power system and the user side establish normal data communication, a data transmission channel dedicated to identity authentication can be built. The business data of the power system will not be involved in this data transmission channel, and the data is isolated from other data communication channels, ensuring that the power system will not be infiltrated by malicious terminal nodes through the identity authentication channel when connected to the power system and steal system data. In this process, the user side can encrypt the communication request with the public key, and the power system can monitor the data request in the network environment. When monitoring the communication request sent to the power system, the user side terminal trusted authentication device can analyze the current encrypted communication request and determine the public key for encrypting the communication request based on the encrypted communication request. The user side terminal trusted authentication device can traverse the code book based on the public key. The code book stores the public key-private key pairs of all user side terminals that establish communication. The corresponding private key can be traversed in the code book based on the public key. After obtaining the private key corresponding to the public key in the encrypted communication request, the user side terminal that currently sends the communication request can complete preliminary verification.

[0035] The receiving of an encrypted communication request issued by a user-side terminal, before the encrypted communication request issued by the user-side terminal is encrypted by a public key, further includes: receiving a registration request from the user-side terminal, the registration request including identity information of the user-side terminal; generating a key pair based on the identity information in the registration request, the key pair including a one-to-one corresponding public key and a private key; sending the key pair to the user-side terminal and storing the key, so that the user-side terminal encrypts the communication request based on the public key to obtain an encrypted communication request.

[0036] In the implementation, the key pair used for communication between the power system and the user-side terminal is allocated when the user-side terminal joins the power system. The key pair for communication between each user-side terminal and the power system is different and unique in history and will not be repeated. When the user-side terminal communicates data with the power system for the first time, it can encrypt the communication request according to the encryption method announced by the power system. The key for the initial encryption is transmitted in a non-public form and provided by the power system to the user-side terminal for the initial communication. The user-side terminal can use its own identity information, including device number, physical address, access network protocol (Internet Protocol, IP address), whether it is a proxy network, request time and other information. After the user-side terminal trusted authentication device receives the identity information of the user-side terminal, it can generate a key pair based on the identity information of the user-side terminal. When generating the key pair, it can generate the key pair according to the Elliptic Curve Cryptography (ECC) method. During the encryption process, it can be used, for example, 2 =x 3 +ax+b. Assume that the private key and public key are d and Q, respectively, i.e., Q = dG, where G is the base point. During public key encryption, a random number r is selected, and the message M is converted into a ciphertext C. This ciphertext is a point pair, C = {rG, M + rQ}, where Q is the public key. For private key decryption, M + rQ - d(rG) = M + r(dG) - d(rG) = M, where d and Q are the private and public keys, respectively. After generating the public and private keys, the user terminal can authenticate the communication request using the key pair obtained from the elliptic encryption algorithm. During the signature authentication process, a message digest is generated from the communication request. In this embodiment, SHA256 can be used to generate a 256-bit digest. After the digest is generated, it can be signed. The process involves generating a random number k. Based on the generated random number k, two large numbers r and s are calculated. r and s are concatenated together to form the signature of the message digest. It should be noted that due to the existence of the random number k, for the same message, the signature generated when using the same algorithm for digital signing will be different.

[0037] After generating a key pair based on the identity information in the registration request, wherein the key pair includes a one-to-one corresponding public key and private key, it also includes: obtaining a key pair update cycle; determining the update time of the key pair based on the current time and the last update time of the key; judging the current time based on the update time of the key pair, and when the current time is equal to the key pair update time, updating the key pair and synchronizing it to the user-side terminal.

[0038] In implementation, to ensure the security of the key pair, the key pair needs to be updated regularly. The update period is set according to actual conditions and can be selected as weekly updates or other time periods. This embodiment does not impose any restrictions on this. At the same time, the update time of the key pair currently used by the user-side terminal is obtained, and the time when the key pair needs to be updated next is calculated based on the obtained update period. The next update time and the current time are used to determine that when the current time reaches the key pair update time, a new key pair can be generated based on the communication data of the preset number of times between the user-side terminal and the power system. The preset number of communication data refers to the nth communication data when the current key pair is used, where n can be set manually or a random number between 0 and m, and m is the total number of communications under the current key pair. If no data communication occurs during the current key pair update period, the key pair is generated based on the update time. In addition, in order to ensure the security of the key pair, the update method can also be set to update according to the number of communications. That is, after the current key pair is used k times, during the k-1 communication, the next round of key pairs can be obtained based on the k-1 communication data, and the key pair can be sent together with the k-th communication.

[0039] Step S20: decrypting the encrypted communication request sent by the user side terminal using the private key to obtain the communication request of the user side terminal, wherein the public key and the private key are in a one-to-one correspondence.

[0040] In the implementation, after receiving the encrypted communication request sent by the user-side terminal, the user-side terminal trusted authentication device can determine the public key used to encrypt the communication request based on the encrypted communication request. The user-side terminal trusted authentication device can traverse the password book based on the public key. The password book stores the public key-private key pairs of all user-side terminals that establish communication. The corresponding private key can be traversed in the password book based on the public key. After obtaining the private key corresponding to the public key in the encrypted communication request, the current encrypted communication request can be decrypted based on the private key to obtain the communication request of the user-side terminal, where the public key and the private key are in a one-to-one correspondence.

[0041] Step S30: upon receiving a communication request from the user-side terminal, establishing a data transmission channel dedicated to identity authentication connected to the user-side terminal.

[0042] Step S40: receiving identity authentication information sent by the user-side terminal according to the data transmission channel, verifying the identity authentication information, and obtaining the real identity of the user-side terminal.

[0043] It should be noted that the identity authentication information is information sent by the user-side terminal to the power system to indicate the identity. When the identity authentication information is transmitted, it is also encrypted according to the key pair obtained by the ECC algorithm to ensure the data security of the identity authentication information.

[0044] In implementation, refer to Figure 3, which is an identity authentication flow chart. Identity authentication information is sent by a user-side terminal to the power system, primarily describing the user-side terminal's identity and access purpose. The user-side terminal trusted authentication device can perform identity authentication based on the user-side terminal's identity and access purpose. When a user-side terminal device sends an identity authentication request to the power system, the identity authentication information is broadcast within the current system. Each user-side terminal in the current power system can receive the identity authentication information of the terminal device undergoing identity authentication. The user-side terminal trusted authentication device can count all the identity authentication information and determine the final identity information based on all the obtained identity authentication information. This can be determined based on the identity authentication ratio. When identity authentication passes, the access purpose is then checked and matched against the user's authenticated identity and access purpose. If the access rights of the authenticated identity are consistent with the access purpose, the current user-side terminal's identity is recognized, thereby obtaining the true identity of the user-side terminal. If the access rights of the authenticated identity are inconsistent with the access purpose, the current user-side terminal's credibility can be reduced, and data requests from the current user-side terminal can be blocked for a certain period of time.

[0045] Step S50: When the real identity of the user-side terminal is a trusted identity, a data channel is established with the user-side terminal, and information is transmitted according to the data channel.

[0046] In the implementation, when the real identity of the user-side terminal is a trusted identity, a data channel is established for the user side of the trusted identity, which is set to transmit business data between the user-side terminal and the power system, and can be accessed to the blockchain according to the public key of the user-side terminal to perform business processing of the user-side terminal. Due to the characteristics of the blockchain, the operations of the user-side terminal on the blockchain are transparent. At this time, the operations of the user-side terminal can also be continuously monitored. When abnormal behavior is found, such as malicious behavior such as large amounts of reading and writing data, the data communication with the current user-side terminal is cut off, and corresponding security protection measures are taken for the data in the blockchain.

[0047] This embodiment receives an encrypted communication request from a user-side terminal, decrypts the encrypted communication request from the user-side terminal using a private key, obtains the communication request from the user-side terminal, establishes a data transmission channel connected to the user-side terminal for identity authentication, receives identity authentication information sent by the user-side terminal according to the data transmission channel, verifies the identity authentication information, and obtains the true identity of the user-side terminal. When the true identity of the user-side terminal is a trusted identity, a data channel is established with the user-side terminal, and information is transmitted according to the data channel. Compared with related technologies, it can realize dual-mechanism authentication of keys and voting. Compared with simple key authentication, this application is more sensitive to user-side terminals and can more accurately authenticate user-side terminals, thereby ensuring the security of data within the power system.

[0048] Refer to FIG4 , which is a flow chart of a second embodiment of a user-side terminal trusted authentication method of the present application.

[0049] Based on the first embodiment described above, the user-side terminal trusted authentication method of this embodiment includes the following steps in step S40:

[0050] Step S401: when identity authentication information sent by the user side terminal is received through the data transmission channel, identity authentication information received by other user side terminals is acquired.

[0051] Step S402: obtaining an identity authentication vector table according to the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals, where the other user side terminals are all user side terminals except the user side terminal.

[0052] Step S403: determining the number of identity authentications according to the type of identity authentication information received in the identity authentication vector table.

[0053] Step S404: Obtain the identity authentication result of the user-side terminal according to the identity authentication quantity.

[0054] Step S405: Obtain the real identity of the user-side terminal according to the user authentication result.

[0055] It should be noted that the identity authentication vector table refers to the vector table formed by the authentication results of the currently authenticated user-side terminal by other user-side terminals other than the currently authenticated user-side terminal. In other words, the currently authenticated user-side terminal is referred to as a. The power system includes multiple user-side terminals, which form a set A. In this case, a∈A. In set A, the remaining user-side terminals that do not include user-side terminal a are set B. In this case, the identity authentication vector table is the authentication result obtained after set B authenticates user-side terminal a.

[0056] In the implementation, it is assumed that in the current power system, the user-side terminal trusted authentication device is M, and there are x malicious terminals in the current power system, including malicious terminals and the total number of all terminals in the user-side terminal trusted authentication device is y. Since the number of malicious terminals is relatively small compared to the total number of terminals, it can be known at this time that y>3x must be satisfied at this time. Therefore, the dominant power of identity authentication is on the side of the normal terminal. Due to the large amount of data, this embodiment will simplify the identity authentication process, as shown in Figure 5, which is a schematic diagram of user-side terminal identity authentication. In Figure 5, it is assumed that the user-side terminal a is the current malicious terminal. It should be known that the malicious terminal will distort the real information. When a user-side terminal trusted authentication device M initiates identity authentication information requests from multiple user-side terminals, it can analyze the information receipt information from each user-side terminal. If the user-side terminal trusted authentication device M sends authentication information T to user-side terminals a, b, and c, respectively, this authentication information will be transmitted between the user-side terminals. While normal user-side terminals transmit information completely, malicious terminals will misinterpret it. The reason for this misinterpretation is unknown, but it is certain that it differs from the correct information. The misinterpreted information is represented by F. Data transmission is shown in Figure 5. Each user-side terminal and the user-side terminal trusted authentication device receives data transmitted by the other three terminals / devices and constructs the identity authentication vector table shown in Figure 6. The user-side terminal trusted authentication device M then receives the information received from user-side terminals a, b, and c, resulting in the identity authentication vector table shown in Figure 6. Figure 6 shows that the malicious terminal can be identified as user-side terminal a, and the true identity of user-side terminal a is determined to be the malicious terminal.

[0057] The obtaining of the identity authentication vector table based on the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals includes: broadcasting the received identity authentication information of the user side terminal, and when the other user side terminals receive the identity authentication information of the user side terminal, comparing the received identity information of the user side terminal with the identity authentication information received by the user side terminal itself to obtain identity voting information; obtaining the identity voting information of the other user side terminals, and obtaining the identity authentication vector table based on the identity voting information.

[0058] In the implementation, the voting information of multiple user-side terminals, that is, the receipt information, is read from the identity authentication vector table as shown in Figure 6. At this time, the results are sorted according to the names of the user-side terminals of the receipts. Since the user-side terminal trusted authentication device is trusted, the user-side terminal that sends different information from the user-side terminal trusted authentication device is voted as a malicious terminal.

[0059] The obtaining of the true identity of the user side terminal according to the user authentication result includes: when the user authentication result is authentication passed, outputting the true identity of the user side terminal as a normal user side terminal; when the user authentication result is authentication failed, outputting the true identity of the user side terminal device as a first abnormal user side terminal.

[0060] It should be noted that abnormal user-side terminals may include malicious terminals and faulty terminals. Malicious terminals may generate negative data and endanger the data security of the power system. In this case, the malicious terminal is referred to as the first abnormal user-side terminal.

[0061] In implementation, after obtaining the user authentication result, the user's true identity is checked. If the user authentication result passes, the true identity of the user terminal is output as a normal user terminal. If the user authentication result fails, the true identity of the user terminal is output as a first abnormal user terminal. If the true identity of the user terminal device is a malicious terminal, corresponding measures can be taken to prohibit the communication request of the current user terminal.

[0062] The obtaining of the identity voting information of the other user side terminals and obtaining the identity authentication vector table according to the identity voting information include: detecting the identity voting information of the other user side terminals, and when the identity voting information is empty, reducing the voting weight of the other user side terminals whose identity voting information is empty; counting the number of identity voting information of the other user side terminals whose identity voting information is empty; and when the proportion of the number of identity voting information reaches a preset proportion, marking the other user side terminals whose proportion of identity voting information reaches the preset proportion as second abnormal user side terminals.

[0063] It should be noted that when a user-side terminal is disconnected due to a fault or data transmission is abnormal due to other reasons, this column of user-side terminals is referred to as a second abnormal user-side terminal.

[0064] In implementation, when performing identity authentication, since each user-side terminal needs to vote, it is necessary for each user-side terminal to have no abnormalities in data transmission. If the voting information of a user-side terminal is lost during identity authentication, then empty data may appear in the identity authentication vector table, and the faulty terminal may be locked based on the empty data. Taking into account possible network fluctuations, a certain degree of tolerance is given to the user-side terminal. That is to say, when this situation occurs in the user-side terminal device, the number of times this situation occurs in the user-side terminal can be counted and compared with the total number of participations to obtain the proportion of identity information votes. When the proportion of the identity voting information reaches a preset proportion, for example, 10%, it is set according to the actual situation. This embodiment does not impose any restrictions on this. The user-side terminal is marked as the second abnormal user-side terminal.

[0065] After obtaining the true identity of the user side terminal according to the user authentication result, it also includes: comparing the true identity of the user side terminal with the identity voting information of other user side terminals; when the true identity of the user side terminal is consistent with the identity voting information of the other user side terminals, increasing the voting weight of the user side terminal corresponding to the identity voting information; when the true identity of the user side terminal is inconsistent with the identity voting information of the other user side terminals, reducing the voting weight of the user side terminal corresponding to the identity voting information.

[0066] In implementation, in order to ensure the accuracy of the identity of the user-side terminal, a reward and punishment mechanism can be added. During each identity authentication, the voting information of each user-side terminal can be detected to determine the voting result of the user-side terminal. For the voting result of the user-side terminal currently applying for identity authentication, if it is consistent with the actual result, the voting weight of the current user-side terminal can be appropriately increased. When the true identity of the user-side terminal is inconsistent with the identity voting information of other user-side terminals, the voting weight of the user-side terminal corresponding to the identity voting information is reduced. In this way, the voting gap between normal user-side terminals and abnormal user-side terminals can be widened, and the influence of abnormal user terminals can be weakened.

[0067] This embodiment checks the user-side terminal that applies for identity authentication by initiating an identity card information request through a trusted authentication device on the user-side terminal, generates an identity authentication vector table based on the voting information fed back by all user-side terminals, determines abnormal user-side terminals based on the identity authentication vector table, and performs corresponding processing on the abnormal user-side terminals. At the same time, the authentication results of each identity authentication are analyzed, the voting weight of the user-side terminal that voted correctly is increased, and the voting weight of the user-side terminal that gave an incorrect vote is reduced, thereby reducing the influence of the abnormal user-side terminals.

[0068] In addition, an embodiment of the present application further proposes a storage medium on which a user-side terminal trusted authentication program is stored. When the user-side terminal trusted authentication program is executed by a processor, the steps of the user-side terminal trusted authentication method described above are implemented.

[0069] Refer to FIG. 7 , which is a structural block diagram of a first embodiment of a trusted authentication device for a user-side terminal of the present application.

[0070] As shown in Figure 7, the user-side terminal trusted authentication device proposed in the embodiment of the present application includes: a request receiving module 10, which is configured to receive an encrypted communication request issued by the user-side terminal, and the encrypted communication request issued by the user-side terminal is encrypted by a public key; a request processing module 20, which is configured to decrypt the encrypted communication request issued by the user-side terminal by a private key to obtain the communication request of the user-side terminal, and the public key and the private key are in a one-to-one correspondence; a data transmission channel establishment module 30, which is configured to establish a data transmission channel dedicated to identity authentication connected to the user-side terminal when the communication request of the user-side terminal is obtained; an identity authentication module 40, which is configured to receive the identity authentication information sent by the user-side terminal according to the data transmission channel, verify the identity authentication information, and obtain the true identity of the user-side terminal; a communication establishment module 50, which is configured to establish a data channel with the user-side terminal when the true identity of the user-side terminal is a trusted identity, and transmit information according to the data channel.

[0071] This embodiment receives an encrypted communication request from a user-side terminal, decrypts the encrypted communication request from the user-side terminal using a private key, obtains the communication request from the user-side terminal, establishes a data transmission channel connected to the user-side terminal for identity authentication, receives identity authentication information sent by the user-side terminal according to the data transmission channel, verifies the identity authentication information, and obtains the true identity of the user-side terminal. When the true identity of the user-side terminal is a trusted identity, a data channel is established with the user-side terminal, and information is transmitted according to the data channel. Compared with related technologies, dual authentication mechanisms of keys and voting can be implemented. Compared with simple key authentication, this application is more sensitive to user-side terminals and can more accurately authenticate user-side terminals, thereby ensuring the security of data within the power system.

[0072] In one embodiment, the request receiving module 10 is further configured to receive a registration request from a user-side terminal, the registration request including identity information of the user-side terminal; generate a key pair based on the identity information in the registration request, the key pair including a one-to-one corresponding public key and a private key; send the key pair to the user-side terminal and store the key, so that the user-side terminal encrypts the communication request according to the public key to obtain an encrypted communication request.

[0073] In one embodiment, the identity authentication module 40 is configured to obtain identity authentication information received by other user side terminals when identity authentication information sent by the user side terminal is received according to the data transmission channel; obtain an identity authentication vector table based on the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals, and the other user side terminals are all user side terminals except the user side terminal; determine the number of identity authentications based on the type of identity authentication information received in the identity authentication vector table; obtain the identity authentication result of the user side terminal based on the identity authentication number; and obtain the true identity of the user side terminal based on the user authentication result.

[0074] In one embodiment, the identity authentication module 40 is configured to broadcast the received identity authentication information of the user side terminal, and when the other user side terminals receive the identity authentication information of the user side terminal, compare the received identity information of the user side terminal with the identity authentication information received by the user side terminal itself to obtain identity voting information; obtain the identity voting information of the other user side terminals, and obtain an identity authentication vector table based on the identity voting information.

[0075] In one embodiment, the identity authentication module 40 is configured to output the true identity of the user side terminal as a normal user side terminal when the user authentication result is authentication passed; and to output the true identity of the user side terminal as a first abnormal user side terminal when the user authentication result is authentication failed.

[0076] In one embodiment, the identity authentication module 40 is configured to detect the identity voting information of the other user side, and when the identity voting information is empty, reduce the voting weight of the other user side terminal whose identity voting information is empty; count the number of identity voting information of the other user side terminal whose identity voting information is empty; when the proportion of the number of identity voting information reaches a preset proportion, mark the other user side terminal whose identity voting information is empty as a second abnormal user side terminal.

[0077] In one embodiment, the identity authentication module 40 is further configured to compare the real identity of the user side terminal with the identity voting information of other user side terminals; when the real identity of the user side terminal is consistent with the identity voting information of the other user side terminals, the voting weight of the user side terminal corresponding to the identity voting information is increased; when the real identity of the user side terminal is inconsistent with the identity voting information of the other user side terminals, the voting weight of the user side terminal corresponding to the identity voting information is reduced.

[0078] It should be understood that the above is only an example and does not constitute any limitation on the technical solution of the present application. In application, technicians in this field can make settings as needed, and the present application does not impose any restrictions on this.

[0079] It should be understood that, although the multiple steps in the flowchart in the embodiment of the present application are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order and can be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and their execution order is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.

[0080] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this application. In actual applications, technicians in this field can select part or all of it according to actual needs to achieve the purpose of this embodiment scheme, and no restrictions are imposed here.

[0081] In addition, it should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0082] Through the description of the above embodiments, those skilled in the art can understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as read-only memory (ROM) / RAM, a magnetic disk, or an optical disk), and includes multiple instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in multiple embodiments of the present application.

Claims

1. A user-side terminal trusted authentication method, comprising: Receiving an encrypted communication request sent by a user side terminal, wherein the encrypted communication request sent by the user side terminal is encrypted by a public key; Decrypting the encrypted communication request sent by the user side terminal using a private key to obtain the communication request of the user side terminal, wherein the public key and the private key are in a one-to-one correspondence; In case of receiving a communication request from the user side terminal, establishing a data transmission channel dedicated to identity authentication connected to the user side terminal; receiving identity authentication information sent by the user side terminal according to the data transmission channel, verifying the identity authentication information, and obtaining the real identity of the user side terminal; In the case that the real identity of the user side terminal is a trusted identity, a data channel with the user side terminal is established, and information is transmitted according to the data channel.

2. The method according to claim 1, wherein the receiving of the encrypted communication request sent by the user side terminal, before the encrypted communication request sent by the user side terminal is encrypted by the public key, further comprises: receiving a registration request from a user-side terminal, wherein the registration request includes identity information of the user-side terminal; Generate a key pair according to the identity information in the registration request, wherein the key pair includes a one-to-one corresponding public key and a private key; The key pair is sent to the user side terminal and the key is stored, so that the user side terminal encrypts the communication request according to the public key to obtain an encrypted communication request.

3. The method of claim 1, wherein: The receiving, according to the data transmission channel, the identity authentication information sent by the user side terminal, and verifying the identity authentication information to obtain the real identity of the user side terminal includes: When the identity authentication information sent by the user side terminal is received according to the data transmission channel, acquiring the identity authentication information received by other user side terminals; Obtaining an identity authentication vector table according to the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals, wherein the other user side terminals are all user side terminals except the user side terminal; Determining the number of identity authentications according to the type of identity authentication information received in the identity authentication vector table; Obtaining an identity authentication result of the user-side terminal according to the identity authentication quantity; The real identity of the user-side terminal is obtained according to the user authentication result.

4. The method of claim 3, wherein: The obtaining of the identity authentication vector table according to the identity authentication information sent by the user side terminal and the identity authentication information received by the other user side terminals includes: Broadcasting the received identity authentication information of the user side terminal, and when the other user side terminals receive the identity authentication information of the user side terminal, comparing the received identity information of the user side terminal with the identity authentication information received from the user side terminal to obtain identity voting information; The identity voting information of the other user-side terminals is obtained, and an identity authentication vector table is obtained according to the identity voting information.

5. The method of claim 3, wherein: The obtaining the real identity of the user-side terminal according to the user authentication result includes: When the user authentication result is that the authentication is passed, outputting the real identity of the user side terminal as a normal user side terminal; When the user authentication result is authentication failure, the real identity of the user side terminal is output as a first abnormal user side terminal.

6. The method of claim 4, wherein: The acquiring the identity voting information of the other user-side terminals and obtaining the identity authentication vector table according to the identity voting information includes: Detecting the identity voting information of the other user side, and if the identity voting information is empty, reducing the voting weight of the other user side terminal whose identity voting information is empty; Counting the number of identity voting information of other user-side terminals whose identity voting information is empty; When the proportion of the number of identity voting information reaches a preset proportion, other user side terminals whose proportion of the number of identity voting information reaches the preset proportion are marked as second abnormal user side terminals.

7. The method according to any one of claims 3 to 6, after obtaining the real identity of the user-side terminal according to the user authentication result, further comprising: Comparing the real identity of the user-side terminal with the identity voting information of other user-side terminals; When the real identity of the user side terminal is consistent with the identity voting information of the other user side terminals, increasing the voting weight of the user side terminal corresponding to the identity voting information; When the real identity of the user side terminal is inconsistent with the identity voting information of the other user side terminals, the voting weight of the user side terminal corresponding to the identity voting information is reduced.

8. A user-side terminal trusted authentication device, comprising: A request receiving module, configured to receive an encrypted communication request sent by a user side terminal, wherein the encrypted communication request sent by the user side terminal is encrypted by a public key; A request processing module, configured to decrypt the encrypted communication request sent by the user side terminal through a private key to obtain the communication request of the user side terminal, wherein the public key and the private key are in a one-to-one correspondence; a data transmission channel establishing module, configured to establish a data transmission channel dedicated to identity authentication connected to the user side terminal in the case of receiving a communication request from the user side terminal; An identity authentication module is configured to receive identity authentication information sent by the user side terminal according to the data transmission channel, verify the identity authentication information, and obtain the real identity of the user side terminal; The communication establishing module is configured to establish a data channel with the user side terminal when the real identity of the user side terminal is a trusted identity, and to transmit information according to the data channel.

9. A user-side terminal trusted authentication device, comprising: A memory, a processor, and a user-side terminal trusted authentication program stored in the memory and executable on the processor, wherein the user-side terminal trusted authentication program is configured to implement the user-side terminal trusted authentication method according to any one of claims 1 to 7.

10. A storage medium storing a user-side terminal trusted authentication program, wherein the user-side terminal trusted authentication program, when executed by a processor, implements the user-side terminal trusted authentication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Electric power Internet of Things access gateway based on a block chain and authentication method for electric power Internet of Things terminal

    CN110086821A

  • Power system security and stability control terminal identity authentication method based on block chain

    CN110324331A

  • Terminal identity authentication method and device, computer equipment and storage medium

    CN114697963A

  • Internet of vehicles data transmission method, device and system and computer equipment

    CN116233188A

  • User side terminal credible authentication method, device and equipment and storage medium

    CN117294539A