WO2016165675A1 - 一种面向输电线路无线通信网络的安全通信方法 - Google Patents

一种面向输电线路无线通信网络的安全通信方法 Download PDF

Info

Publication number
WO2016165675A1
WO2016165675A1 PCT/CN2016/081247 CN2016081247W WO2016165675A1 WO 2016165675 A1 WO2016165675 A1 WO 2016165675A1 CN 2016081247 W CN2016081247 W CN 2016081247W WO 2016165675 A1 WO2016165675 A1 WO 2016165675A1
Authority
WO
WIPO (PCT)
Prior art keywords
node
information
key
data
public key
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/081247
Other languages
English (en)
French (fr)
Inventor
郭经红
姚继明
黄红兵
范骕程
李炳林
梁云
张�浩
王瑶
张旭苹
许国良
王萍
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nanjing University
State Grid Zhejiang Electric Power Co Ltd
Nanjing Tech University
Global Energy Interconnection Research Institute Co Ltd
State Grid Corp of China SGCC
Original Assignee
Nanjing University
State Grid Zhejiang Electric Power Co Ltd
Nanjing Tech University
Global Energy Interconnection Research Institute Co Ltd
State Grid Corp of China SGCC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nanjing University, State Grid Zhejiang Electric Power Co Ltd, Nanjing Tech University, Global Energy Interconnection Research Institute Co Ltd, State Grid Corp of China SGCC filed Critical Nanjing University
Publication of WO2016165675A1 publication Critical patent/WO2016165675A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/04Arrangements for maintaining operational condition

Definitions

  • the present invention relates to a method in the field of power system communication technology, and in particular to a secure communication method for a transmission line wireless communication network.
  • the state monitoring technology of transmission lines has been developed to a certain extent in China, mainly in the research and application of line ice monitoring technology, insulation pollution monitoring technology, line theft monitoring technology, and wire temperature monitoring technology.
  • line ice monitoring technology On the basis of making full use of advanced monitoring equipment and diagnostic technology, an all-round and multi-factor real-time monitoring system for transmission lines is established to timely predict disaster information, achieve rapid fault location, shorten fault recovery time, and effectively improve power supply reliability.
  • the reliable transmission of various types of condition monitoring information is inseparable from the robust communication network support.
  • the network laying on the main transmission lines is mainly OPGW, which has the advantages of fast speed, large capacity and strong anti-interference ability.
  • the present invention provides a new secure communication method for a transmission line wireless communication network.
  • the present invention provides a secure communication method for a transmission line wireless communication network.
  • a secure communication method for a transmission line wireless communication network comprising:
  • the newly added node n uploads status data to the control center through the node n-1 that has been communicated;
  • the control center issues a control command
  • the link status is checked in real time to determine whether a faulty node has occurred, and if so, the link self-healing method is used to repair the wireless communication network.
  • the authenticating the newly added node comprises:
  • the node n sends the request interaction information M0 to the previously authenticated node n-1. After receiving the request information, the node n-1 returns the confirmation message M1 to confirm the interaction, and establishes a communication relationship.
  • the node n generates verification information. And sent to the authentication server of the control center;
  • E is an encryption algorithm, K n is an authentication key of node n, T is a time stamp, C 2 is a verification code, and
  • the authentication server receives the authentication information M2, the node n of Cognitive the decryption key K n Obtaining the decrypted timestamp T';
  • the assigning a key to the new device comprises:
  • the cognitive server of the control center After the verification, the cognitive server of the control center generates information.
  • M00 is the private key of node n and is sent to node n;
  • M01 and M10 respectively contain the public key of the verification object, and are respectively sent to node n and node n-1;
  • C00, C01, and C10 respectively represent M00, M01, and M10.
  • Verification code used to verify whether the information has an error during transmission;
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n;
  • K n and K n-1 are node n and node Authentication key of n-;
  • the node n has its public key PU n
  • the form is sent to node n-1 and broadcast to the remaining neighboring i nodes;
  • the node n-1 will be the public key of the neighboring i nodes Replying to the node n to complete the assignment of the public key;
  • E is an encryption algorithm
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n
  • Request represents request information
  • C5 and C0 j represent verification codes.
  • the newly added node uploading data includes the following steps:
  • the node n sends communication handshake information to the node n-1.
  • the node n-1 decrypts the handshake information, determines that the verification is correct, generates a reply message and sends the message to the node n;
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n
  • Mn represents uploaded data
  • Mn′ represents the decoded data after decoding
  • Cn represents a verification code
  • N-1 represents the node identifier
  • the data encryption method comprises the following steps:
  • Receiving information Mi+1,0 Mn
  • the information Mi, 0 Mn
  • Ci transmitted by the new node i is obtained.
  • control center sends a control command to the node, including the following steps:
  • Any node receives the issued control command E is an encryption algorithm
  • k is the target node label
  • CM k is the control command content
  • PU k is the public key of node k
  • C k is the verification code of node k
  • the node label k determines whether the information is the information sent to itself;
  • control command is decrypted to obtain a command, and if not, a new check code is generated by using the communication key of the node, and then sent to the next node.
  • the link self-healing method comprises:
  • a new handshake information is generated by using the public key of the next node in the neighboring i-node key structure stored in the faulty node, and the new handshake information is sent to the next node until the handshake is successful;
  • the neighboring i-node key structure stores a public key of its forward and backward i nodes; wherein i is equal to 2 or 3.
  • the present invention has the following beneficial effects:
  • the present invention addresses a special communication security requirement of a power system, and proposes a secure communication method for a wireless communication network of a transmission line.
  • the provided method has a special design for the key structure and is different from other communication protocols or
  • the method uses an asymmetric encryption algorithm.
  • the method provided by the present invention performs security protection from multiple levels, specifically, hardware device authentication, data integrity authentication, and confidentiality guarantee during data transmission, which can make up for the lack of single-level encryption and has higher Security.
  • the present invention comprehensively considers the actual situation of the wireless communication application of the transmission line, and carries out the high adaptation design of the communication method, proposes the "adjacent i-node key structure" and applies the asymmetric encryption algorithm, so that the protocol supports the new device at any time. Access and autonomy for the monitoring of breakpoints and network recovery, on the basis of ensuring communication security, overcome the vulnerability caused by the network structure itself, and improve the flexibility of the network.
  • the power supply of each device in the present invention can adopt the power supply mode of clean energy, and has advantages in terms of equipment cost and flexibility of constructing the network.
  • the system can be proposed. Consumption optimization method.
  • 1 is a network communication model diagram for a transmission line in the embodiment
  • FIG. 3 is a flowchart of a public key distribution process in an initialization process in the embodiment
  • FIG. 5 is a flowchart of data processing of an encryption function in a data uploading process in the embodiment
  • FIG. 6 is a flowchart of issuing a control command in the embodiment
  • FIG. 7 is a flowchart of detecting a fault point and a link self-healing in the embodiment.
  • the invention provides a secure communication method for a transmission line wireless communication network, comprising the following steps:
  • the newly added node n uploads status data to the control center through the node n-1 that has been communicated;
  • the control center issues a control command
  • the link status is checked in real time to determine whether a faulty node has occurred, and if so, the link self-healing method is used to repair the wireless communication network.
  • the authentication of the newly added node includes the following steps:
  • the node n sends the request interaction information M0 to the previously authenticated node n-1. After receiving the request information, the node n-1 returns the confirmation message M1 to confirm the interaction, and establishes a communication relationship.
  • the node n generates verification information. And sent to the authentication server of the control center;
  • E is an encryption algorithm, K n is an authentication key of node n, T is a time stamp, C 2 is a verification code, and
  • the authentication server receives the authentication information M2, the node n of Cognitive the decryption key K n Obtaining the decrypted timestamp T';
  • assigning a key to a new device includes the following steps:
  • the cognitive server of the control center After the verification, the cognitive server of the control center generates information.
  • M00 is the private key of node n and is sent to node n;
  • M01 and M10 respectively contain the public key of the verification object, and are respectively sent to node n and node n-1;
  • C00, C01, and C10 respectively represent M00, M01, and M10.
  • Verification code used to verify whether the information has an error during transmission;
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n;
  • K n and K n-1 are node n and node Authentication key of n-;
  • the node n has its public key PU n
  • the form is sent to node n-1 and broadcast to the remaining neighboring i nodes;
  • the node n-1 will be the public key of the neighboring i nodes Replying to the node n to complete the assignment of the public key;
  • E is an encryption algorithm
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n
  • Request represents request information
  • C5 and C0 j represent verification codes.
  • the newly added node uploading data specifically includes the following steps:
  • the node n sends communication handshake information to the node n-1.
  • the node n-1 decrypts the handshake information, determines that the verification is correct, generates a reply message and sends the message to the node n;
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n
  • Mn represents uploaded data
  • Mn′ represents the decoded data after decoding
  • Cn represents a verification code
  • N-1 represents the node identifier
  • the data encryption method described above specifically includes the following steps:
  • Receiving information Mi+1,0 Mn
  • the information Mi, 0 Mn
  • Ci transmitted by the new node i is obtained.
  • control center sends a control command to the node, which specifically includes the following steps:
  • Any node receives the issued control command E is an encryption algorithm
  • k is the target node label
  • CM k is the control command content
  • PU k is the public key of node k
  • C k is the verification code of node k
  • the node label k determines whether the information is the information sent to itself;
  • control command is decrypted to obtain a command, and if not, a new check code is generated by using the communication key of the node, and then sent to the next node.
  • the link self-healing method includes the following steps:
  • a new handshake information is generated by using the public key of the next node in the neighboring i-node key structure stored in the faulty node, and the new handshake information is sent to the next node until the handshake is successful;
  • the neighboring i-node key structure stores the public keys of its forward and backward i nodes; where i is equal to 2 or 3.
  • a network communication model for a transmission line in the embodiment; in this embodiment, a network communication model for a transmission line is provided, including a control center and each node of a communication network, wherein the communication network node includes: two-way Gateway Data Acquisition Unit (DGD) and multiple Data Acquisition Units (DAUs).
  • DDD Gateway Data Acquisition Unit
  • DAUs Data Acquisition Units
  • the control center includes a main processing unit such as an authentication server (AS) and a data collection center server (DCC), and uses a fiber-optic composite overhead ground line (OPGW) to establish a connection with a two-way gateway data acquisition unit (DGD) located on the tower along the transmission line.
  • a main processing unit such as an authentication server (AS) and a data collection center server (DCC)
  • OPGW fiber-optic composite overhead ground line
  • the data acquisition unit (DAU) between each two two-way gateway data acquisition unit (DGD) and the previous two-way gateway data acquisition unit (DGD) form a communication area through the wireless chain network, and then pass through the two-way gateway data acquisition unit (DGD). After convergence, it is transmitted to the control center through the optical fiber composite overhead ground line (OPGW).
  • OPGW optical fiber composite overhead ground line
  • the communication of each node is realized by using the above-mentioned secure communication method for the wireless communication network of the transmission line.
  • the initializing the wireless communication network includes two parts: one, authentication of the new device, and second, assigning a key to the new device.
  • the node n is a device newly connected to the power grid, and the node n-1 is a device that has established a safety network with the control center, and the node n needs to establish a network relationship through the node n-1. Specifically, the following steps are included:
  • the node n sends the request interaction information M0 to the node n-1. After receiving the request information, the node n-1 returns the confirmation message M1 after confirming the interaction, and performs simple handshake by the mutual interaction information M0 and M1, the node n and the node n-1. ;
  • Node n still cannot trust node n-1 and has no means to verify it.
  • the verification information is processed to generate new verification information. After transmission, sent to the cognitive server AS of the control center through node n-1;
  • E is the encryption algorithm
  • K n is the authentication key of node n
  • T is the timestamp, used to prevent repeated attacks
  • C 2 is the verification code
  • represents the connection relationship.
  • the cognitive server AS After receiving the verification message M2, the cognitive server AS first uses the authentication key K n of the node n that has its own Decrypt, obtain the decrypted timestamp T', and then use T' to decrypt E T (K n ) to obtain the message K n ' to be verified, and verify node n by comparing K n and K n ', if K n and K n ' are the same , then complete the verification and proceed to step 4, otherwise return to step 1.
  • the cognitive server AS After the verification is completed, the cognitive server AS generates 3 pieces of information.
  • E represents an encryption algorithm
  • PU n-1 and PU n respectively represent a public key of node n-1 and a public key of node n;
  • node n which is the private key of node n (the private key is unique to node n and the server side, and is a key that is not public to other nodes);
  • M01 and M10 are respectively sent to the node n and the node n-1, respectively, and contain the public key of the verification object, which is different from the private key, and the public key is used for sending the identity verification to the other party, so that the node n and the node n-1 can mutually verification;
  • C00, C01, and C10 respectively represent the verification codes of M00, M01, and M10, which are used to verify whether an error occurs in the transmission of information.
  • node n will have its public key PU n
  • the form is sent to node n-1 and broadcast to the remaining i nodes in a similar form;
  • node n-1 will use the public key of the next i node as
  • the form of C0 j (representing the verification code of M0 j ) is returned to the node n to complete the allocation of the public key, as shown in the flowchart of the public key distribution process in the initialization process in this embodiment.
  • E denotes an encryption algorithm
  • PU n-1 and PU n respectively represent the public key of node n-1 and the public key of node n
  • Request represents request information
  • C5 and C0 j represent verification codes.
  • adjacent i-node key structure refers to a node having both its forward and backward i-node public keys.
  • FIG. 4 is a flow chart of uploading data in the embodiment; in this embodiment, an environment in which a secure network has been constructed is completed.
  • data is to be uploaded (for example, starting from node n, the data is transmitted to the authentication server AS), the process of uploading data is as follows:
  • Node n sends handshake information to node n-1. After receiving the handshake information, the node n-1 decrypts and judges the handshake information, and if the verification information is correct, the reply information is generated. The reply information is sent to the node n; the node n decrypts and judges the reply information, and if the verification information is correct, the verification process is completed.
  • PU n and PU n-1 respectively represent the public key of node n and node n-1; n and n-1 represent node identifiers.
  • FEn data encryption function
  • FIG. 5 is a flowchart of data processing of an encryption function in data uploading in the embodiment; in this embodiment, the upload data of the node i is encrypted.
  • the encrypted data information Mi is added to the data set Mn
  • Mi is further X or X+1 to generate a new verification segment.
  • the monitoring data is generally sent periodically, and the command transmission time has a certain randomness.
  • the data file is generally large, and the control commands are generally small.
  • the uploaded data needs to contain all nodes, and the commands may only be for individual nodes.
  • FIG. 6 is a flowchart of sending a control command in this embodiment.
  • the process of issuing a control command is as follows;
  • Any node receives the issued command E denotes an encryption algorithm
  • k is the target node label
  • CM k is the control command content
  • PU k is the public key of node k
  • C k is the verification code of node k.
  • the check code C k is used to determine whether the information is in error. If the error occurs, the node receiving the command does not perform any processing. If it is correct, it is judged whether the information is sent to itself through the destination node label k in the middle of the information;
  • the command is obtained by decrypting the private key PU k (the information of the public key encryption in the asymmetric encryption must be encrypted with the private key, and the private key of k is only stored in the k and the server segment, thereby ensuring security) If not, a new check code C k is generated by using the communication key of the node to be sent to the next node. At this point, complete the entire data upload, the protection process issued by the command.
  • FIG. 7 is a flowchart of detecting a fault point and a link self-healing in the embodiment.
  • the communication network is monitored in real time for failure, and if the fault is encountered, the link is self-healing.
  • the specific process is as follows:
  • the detection method of the fault point determining whether the fault point is completed by the handshake information, when the handshake information of the sending node is not recovered, or the reply error is considered, the sending node is regarded as a fault node, and the "adjacent i-node key structure" is utilized.
  • the public key of the latter node stored in the middle generates a new handshake information and sends it to the next node until the handshake is successful.
  • both receiving parties update the default key and generate a new communication key for normal communication. Therefore, repeated detection can be avoided during the next communication until the fault point is repaired, and the initialization process is resumed.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明提供了一种面向输电线路无线通信网络的安全通信方法,包括:所述方法包括:初始化所述无线通信网络,判断是否新增节点,若有则对新增饿节点进行认证并为新设备分配密钥;新增的所述节点n通过已通信的节点n-1向控制中心上传状态数据;所述控制中心下发控制命令;实时检查链路状态,判断是否出现故障节点,若出现则运用链路自愈方法修复所述无线通信网络。本发明提供的方法中,提出了"相邻i节点密钥结构"并应用了非对称加密算法,使协议支持新设备随时接入以及自主对于断点进行监测和网络恢复,在保证通信安全的基础上克服了由于网络结构本身带来的脆弱性问题,并且提高了网络的灵活性。

Description

一种面向输电线路无线通信网络的安全通信方法 技术领域
本发明涉及一种电力系统通信技术领域的方法,具体讲涉及一种面向输电线路无线通信网络的安全通信方法。
背景技术
近年来,输电线路的状态监测技术在国内得到一定程度的发展,主要表现为线路覆冰监测技术、绝缘子污秽状况监测技术、线路偷盗监测技术、导线温度监测技术等的研究和应用。在充分利用先进的监测设备和诊断技术的基础上,建立全方位和多要素的输电线路实时监测系统,及时预告灾害信息,实现故障快速定位,缩短故障恢复时间,有效提高供电的可靠性。各类状态监测信息的可靠传输离不开健壮的通信网络支撑。目前,主要输电线路上的网络铺设以OPGW为主,其拥有速度快,容量大,抗干扰能力强等优点。但同时,考虑到设备成本、能源供给(设备不可通过高压输电线路直接供电)等问题,在线路区域不是每个杆塔都配备有OPGW接入点,在实际环境中,相隔一定距离才有一个接入点。因此,其他杆塔上的节点数据信息需要通过一个链式无线网络(因为输电线路为线型)传输给接入点再通过OPGW传输。
由于电力行业的数据安全要求特殊性(通信网络上传的数据可以为电力公司的输电线路检修、巡检提供辅助决策),再加上无线网络本身的开放性,所以需要一套完整的网络安全协议来对通信网络进行保护。包括对于设备是否被伪造和替换、传输过程中数据的完整性、数据本身的加密保护,同时由于实际应用的需要,要考虑在网络构建完成后如何将新的节点加入以完成的网络中。对于链式网络结构本身的对于断点的脆弱性,也要考虑如何通过协议层来解决恢复。
针对上述问题,本发明提供一种新的面向输电线路无线通信网络的安全通信方法。
发明内容
为克服上述现有技术的不足,本发明提供一种面向输电线路无线通信网络的安全通信方法。
实现上述目的所采用的解决方案为:
一种面向输电线路无线通信网络的安全通信方法,所述方法包括:
初始化所述无线通信网络,判断是否新增节点,若有则对新增饿节点进行认证并为新设 备分配密钥;
新增的所述节点n通过已通信的节点n-1向控制中心上传状态数据;
所述控制中心下发控制命令;
实时检查链路状态,判断是否出现故障节点,若出现则运用链路自愈方法修复所述无线通信网络。
优选地,所述对新增的节点进行认证,包括:
S101、所述节点n向已安全验证的前一节点n-1发送请求交互信息M0,所述节点n-1接收请求信息后确认交互则返回确认消息M1,建立通信关系;
S102、所述节点n生成验证信息
Figure PCTCN2016081247-appb-000001
并发送至所述控制中心的认证服务器;E为加密算法,Kn为节点n的认证密钥,T为时间戳,C2为验证码,||表示连接关系;
S103、所述认证服务器接收所述验证信息M2,运用所述节点n的认知密钥Kn解密
Figure PCTCN2016081247-appb-000002
获得解密后的时间戳T′;
通过所述解密后的时间戳T′解密ET(Kn)获得待验证信息Kn′,比较所述节点n的认证密钥Kn和所述验证信息Kn′验证所述节点n;若相同则完成验证,若不同则返回步骤S101。
优选地,所述为新设备分配密钥,包括:
S111、验证后,所述控制中心的认知服务器生成信息
Figure PCTCN2016081247-appb-000003
Figure PCTCN2016081247-appb-000004
Figure PCTCN2016081247-appb-000005
其中,M00为节点n的私钥,发给节点n;M01和M10分别包含验证对象的公钥,分别发送给节点n和节点n-1;C00、C01、C10分别表示M00、M01、M10的验证码,用于验证信息在发送过程中是否发生错误;PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥;Kn、Kn-1为节点n和节点n-的认证密钥;
S112、根据相邻i节点密钥结构,所述节点n将其公钥PUn
Figure PCTCN2016081247-appb-000006
形式发送给节点n-1,并广播给剩下的相邻i个节点;
所述节点n-1将所述相邻i个节点的公钥
Figure PCTCN2016081247-appb-000007
回复给所述节点n,完成公钥的分配;
其中,E为加密算法,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Request表 示请求信息,C5、C0j表示验证码。
优选地,所述新增的所述节点上传数据,包括以下步骤:
S201、所述节点n向所述节点n-1发送通信握手信息;
S202、所述节点n-1解密所述握手信息,判断其验证无误后,产生回复信息并发送至并所述节点n;
S203、所述节点n解密所述回复信息,判断其信息验证无误,运行数据加密方法加密上传的数据,产生加密信息Mn,0=Mn||Mn′||Cn,并发送给所述节点n-1;
S204、所述节点n-1通过所述校验码Cn验证所述加密信息Mn,0=Mn||Mn′||Cn,验证通过则重复步骤S201至S204直到发送到节点0;
其中,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Mn表示上传的数据,Mn′表示解码后的所述上传的数据,Cn表示验证码;n、n-1表示节点标识。
优选地,所述数据加密方法包括以下步骤:
从待加密的节点i的上一节点i+1处接收信息Mi+1,0=Mn||Mn-1||…||Mi-1||Mi+1′||Ci+1,从中提取验证段信息Mi+1′,将所述验证段信息Mi+1′与自身的数据信息节点i中的数据Di异或;
用节点i自身的公钥PUi加密Di获得Mi;
将加密后的数据信息Mi添加到数据集Mn||Mn-1||…||Mi-1完成新信息的数据段;
将所述加密后的数据信息Mi再与所述验证段信息Mi+1′异或后生成新的验证段Mi′,并利用Mi′生成新的校验码Ci
组合上述数据,获得新节点i发送的信息Mi,0=Mn||Mn-1||…||Mi||Mi′||Ci。
优选地,所述控制中心向节点发送控制命令,包括以下步骤:
任意节点接收下发的所述控制命令
Figure PCTCN2016081247-appb-000008
E为加密算法,k为目标节点标号,CMk为控制命令内容,PUk为节点k的公钥,Ck为节点k的验证码;
通过校验码Ck判断信息是否正确;若错误则不做处理,若正确则节点标号k判断此信息是否为发送给自身的信息;
若是则解密所述控制命令获得命令,若不是则利用本节点的通信密钥生成新的校验码后发送给下一个节点。
优选地,所述链路自愈方法包括:
若出现故障节点,利用所述故障节点存有的相邻i节点密钥结构中的后一节点的公钥生成新的握手信息发送给后一节点,直至握手成功;
更新发送节点和接收节点的默认密钥、通信密钥,通过数据上传和命令下发过程进行通信。
优选地,所述相邻i节点密钥结构中存储其前向和后向i个节点的公钥;其中,i等于2或3。
与现有技术相比,本发明具有以下有益效果:
1、本发明针对电力系统的特殊通信安全需求,提出了一种面向输电线路无线通信网络的安全通信方法,提供的方法中对于密钥的结构进行了特殊的设计,并且区别于其他通信协议或方法,使用了非对称加密算法。
2、本发明提供的方法从多个层面进行了安全防护,具体来说,包括硬件设备认证、数据完整性认证以及数据传输过程中的保密性保证,可以弥补单一层面加密的不足,具有更高的安全性。
3、本发明综合考虑输电线路无线通信应用实际情况,对通信方法进行了高适应的相关设计,提出了“相邻i节点密钥结构”并应用了非对称加密算法,使协议支持新设备随时接入以及自主对于断点进行监测和网络恢复,在保证通信安全的基础上克服了由于网络结构本身带来的脆弱性问题,并且提高了网络的灵活性。
4、本发明中各设备的供电均可采用清洁能源的供电方式,在设备的成本和构筑网络的灵活性方面也更具备优势,另外,考虑到清洁能源的供电稳定性问题,提出了系统能耗优化方式。
附图说明
图1为本实施例中面向输电线路的网络通信模型图;
图2为本实施例中初始化中认证和私钥分配的流程图;
图3为本实施例中初始化过程中公钥分配过程流程图;
图4为本实施例中上传数据流程图;
图5为本实施例中数据上传进程中加密函数的数据处理流程图;
图6为本实施例中下发控制命令的流程图;
图7为本实施例中对于故障点的检测及链路自愈流程图。
具体实施方式
下面结合附图对本发明的具体实施方式做进一步的详细说明。
本发明提供一种面向输电线路无线通信网络的安全通信方法,包括以下步骤:
初始化所述无线通信网络,判断是否新增节点,若有则对新增饿节点进行认证并为新设备分配密钥;
新增的所述节点n通过已通信的节点n-1向控制中心上传状态数据;
所述控制中心下发控制命令;
实时检查链路状态,判断是否出现故障节点,若出现则运用链路自愈方法修复所述无线通信网络。
上述,对新增的节点进行认证,具体包括以下步骤:
S101、所述节点n向已安全验证的前一节点n-1发送请求交互信息M0,所述节点n-1接收请求信息后确认交互则返回确认消息M1,建立通信关系;
S102、所述节点n生成验证信息
Figure PCTCN2016081247-appb-000009
并发送至所述控制中心的认证服务器;E为加密算法,Kn为节点n的认证密钥,T为时间戳,C2为验证码,||表示连接关系;
S103、所述认证服务器接收所述验证信息M2,运用所述节点n的认知密钥Kn解密
Figure PCTCN2016081247-appb-000010
获得解密后的时间戳T′;
通过所述解密后的时间戳T′解密ET(Kn)获得待验证信息Kn′,比较所述节点n的认证密钥Kn和所述验证信息Kn′验证所述节点n;若相同则完成验证,若不同则返回步骤S101。
上述,为新设备分配密钥,具体包括以下步骤:
S111、验证后,所述控制中心的认知服务器生成信息
Figure PCTCN2016081247-appb-000011
Figure PCTCN2016081247-appb-000012
Figure PCTCN2016081247-appb-000013
其中,M00为节点n的私钥,发给节点n;M01和M10分别包含验证对象的公钥,分别发送给节点n和节点n-1;C00、C01、C10分别表示M00、M01、M10的验证码,用于验证信息在发送过程中是否发生错误;PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥;Kn、Kn-1为节点n和节点n-的认证密钥;
S112、根据相邻i节点密钥结构,所述节点n将其公钥PUn
Figure PCTCN2016081247-appb-000014
形式发送给节点n-1,并广播给剩下的相邻i个节点;
所述节点n-1将所述相邻i个节点的公钥
Figure PCTCN2016081247-appb-000015
回复给所述节点n,完成公钥的分配;
其中,E为加密算法,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Request表示请求信息,C5、C0j表示验证码。
上述,新增的所述节点上传数据,具体包括以下步骤:
S201、所述节点n向所述节点n-1发送通信握手信息;
S202、所述节点n-1解密所述握手信息,判断其验证无误后,产生回复信息并发送至并所述节点n;
S203、所述节点n解密所述回复信息,判断其信息验证无误,运行数据加密方法加密上传的数据,产生加密信息Mn,0=Mn||Mn′||Cn,并发送给所述节点n-1;
S204、所述节点n-1通过所述校验码Cn验证所述加密信息Mn,0=Mn||Mn′||Cn,验证通过则重复步骤S201至S204直到发送到节点0;
其中,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Mn表示上传的数据,Mn′表示解码后的所述上传的数据,Cn表示验证码;n、n-1表示节点标识。
上述,数据加密方法,具体包括以下步骤:
从待加密的节点i的上一节点i+1处接收信息Mi+1,0=Mn||Mn-1||…||Mi-1||Mi+1′||Ci+1,从中提取验证段信息Mi+1′,将所述验证段信息Mi+1′与自身的数据信息节点i中的数据Di异或;
用节点i自身的公钥PUi加密Di获得Mi;
将加密后的数据信息Mi添加到数据集Mn||Mn-1||…||Mi-1完成新信息的数据段;
将所述加密后的数据信息Mi再与所述验证段信息Mi+1′异或后生成新的验证段Mi′,并利用Mi′生成新的校验码Ci
组合上述数据,获得新节点i发送的信息Mi,0=Mn||Mn-1||…||Mi||Mi′||Ci。
上述,控制中心向节点发送控制命令,具体包括以下步骤:
任意节点接收下发的所述控制命令
Figure PCTCN2016081247-appb-000016
E为加密算法,k为目标节点标号,CMk为控制命令内容,PUk为节点k的公钥,Ck为节点k的验证码;
通过校验码Ck判断信息是否正确;若错误则不做处理,若正确则节点标号k判断此信息是否为发送给自身的信息;
若是则解密所述控制命令获得命令,若不是则利用本节点的通信密钥生成新的校验码后发送给下一个节点。
上述,链路自愈方法,具体包括以下步骤:
若出现故障节点,利用所述故障节点存有的相邻i节点密钥结构中的后一节点的公钥生成新的握手信息发送给后一节点,直至握手成功;
更新发送节点和接收节点的默认密钥、通信密钥,通过数据上传和命令下发过程进行通信。
所述相邻i节点密钥结构中存储其前向和后向i个节点的公钥;其中,i等于2或3。
图1为本实施例中面向输电线路的网络通信模型图;本实施例中,提供一种面向输电线路的网络通信模型,包括控制中心和通信网络的各个节点,其中,通信网络节点包括:双向网关数据采集单元(DGD)和多个数据采集单元(DAU)。
控制中心包括认证服务器(AS)和数据采集中心服务器(DCC)等主要处理单元,利用光纤复合架空地线(OPGW)与位于输电线路沿线杆塔上的双向网关数据采集单元(DGD)建立连接。
每两个双向网关数据采集单元(DGD)之间的数据采集单元(DAU)与前一个双向网关数据采集单元(DGD)通过无线链型网络构成一个通信区域,再经过双向网关数据采集单元(DGD)汇聚后通过光纤复合架空地线(OPGW)传送给控制中心。
运用上述面向输电线路无线通信网络的安全通信方法实现各节点的通信。
图2为本实施例中初始化中认证和私钥分配的流程图;本实施例中,初始化无线通信网络包括两部分:一、对新设备的认证,二、为新设备分配密钥。
节点n为新接入电网的设备,节点n-1为与控制中心已建立安全网络的设备,节点n需通过节点n-1建立网络关系。具体包括以下步骤:
①、节点n向节点n-1发送请求交互信息M0,节点n-1接收请求信息后确认交互则返回确认消息M1,通过双方的交互信息M0和M1,节点n和节点n-1进行简单握手;
②、节点n仍不能信任节点n-1且暂无手段验证,对其验证信息进行加工生成新的验证信息
Figure PCTCN2016081247-appb-000017
后进行传输,通过节点n-1发送到控制中心的认知服务器AS;
其中,E表示加密算法,Kn为节点n的认证密钥,T为时间戳,用于防止重复攻击,C2为验证码,||表示连接关系。
③、认知服务器AS收到验证消息M2后先用存在自身的节点n的认证密钥Kn
Figure PCTCN2016081247-appb-000018
解密,获得解密后的时间戳T′,再用T′解密ET(Kn)获得待验证消息Kn′,通过比较Kn和Kn′验证节点n,若Kn和Kn′相同,则完成验证进入步骤④,否则返回步骤①。
④、完成验证后,认知服务器AS生成3个信息
Figure PCTCN2016081247-appb-000019
Figure PCTCN2016081247-appb-000020
Figure PCTCN2016081247-appb-000021
其中,E表示加密算法,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥;
M00发给节点n,为节点n的私钥(该私钥为节点n和服务器端独有的,对其他节点是不公开的密钥);
M01和M10分别发送给节点n和节点n-1,分别包含验证对象的公钥,不同于私钥,该公钥用于发送给对方进行身份验证的,让节点n和节点n-1可以互相验证;
C00、C01、C10分别表示M00、M01、M10的验证码,用来验证信息在发送过程中是否发生错误。
⑤、根据“相邻i节点密钥结构”的要求,节点n将其公钥PUn
Figure PCTCN2016081247-appb-000022
形式发送给节点n-1并以类似的形式以此广播给剩下的i个节点;
同时,节点n-1将后i节点的公钥以
Figure PCTCN2016081247-appb-000023
C0j(表示M0j的验证码)的形式回复给节点n,以完成公钥的分配,如图3本实施例中初始化过程中公钥分配过程流程图所示。
其中,E表示加密算法,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Request表示请求信息,C5、C0j表示验证码。
上述“相邻i节点密钥结构”,是指一个节点同时拥有其前向和后向i个节点的公钥。
图4为本实施例中上传数据流程图;本实施例中,在一个安全网络已经构建完成的环境 下,当要进行数据的上传时候(如从节点n开始,将数据传输至认证服务器AS),其上传数据过程如下:
①、节点n向节点n-1发送握手信息
Figure PCTCN2016081247-appb-000024
节点n-1接收握手信息后对其解密并判断,若验证信息无误,产生答复信息
Figure PCTCN2016081247-appb-000025
将答复信息发送给节点n;节点n接收答复信息后对其解密并判断,若验证信息无误后,完成验证过程。PUn、PUn-1分别表示节点n和节点n-1的公钥;n、n-1表示节点标识。
通过上述握手信息
Figure PCTCN2016081247-appb-000026
和答复信息
Figure PCTCN2016081247-appb-000027
完成通信双方节点n和节点n-1的验证。
②、由节点n执行数据加密函数(function encryption,FEn),将经过FEn处理后获得加密后的上传数据Mn,0,Mn,0=Mn||Mn′||Cn,将其发给节点n-1,当节点n-1通过校验码Cn(Cn为Mn,0信息的验证码)验证完Mn,0=Mn||Mn′||Cn后,节点n-1将重复如图4的过程直到节点0(DGD)。
图5为本实施例中数据上传中加密函数的数据处理流程图;本实施例中,对节点i的上传数据进行加密。
确定节点i的加密函数FEi,首先,其从节点i+1处收到的信息Mi+1,0=Mn||Mn-1||…||Mi-1||Mi+1′||Ci+1中的提取中间验证段信息(与下方对应)Mi+1′,将Mi+1′与自身的数据信息节点i中的待加密的数据Di异或,通过增强关联性提升雪崩效应提高安全性;
然后,用节点i自身的公钥PUi加密Di获得Mi,确保只有拥有节点i私钥的服务器端和其自身可以解密;
接着,将加密后的数据信息Mi添加到数据集Mn||Mn-1||…||Mi-1之后完成新信息的数据段;Mi再与Mi+1′异或后生成新的验证段Mi′,并利用Mi′生成新的校验码Ci
最后,将以上过程中产生的各类数据组合在一起,获得新节点i发送的信息Mi,0=Mn||Mn-1||…||Mi||Mi′||Ci。
控制命令的下发流程区别于数据的上传流程主要有三点:
1、监测数据一般为定时发送,命令发送时间有一定的随机性。
2、数据文件一般较大,而控制命令一般较小。
3、上传的数据需包含所有节点,命令可能只针对个别节点。
图6为本实施例中下发控制命令的流程图,本实施例中,下发控制命令的过程如下;
任意节点收到下发的命令
Figure PCTCN2016081247-appb-000028
E表示加密算法,k为目标节点标号,CMk为控制命令内容,PUk为节点k的公钥,Ck为节点k的验证码。
通过校验码Ck判断信息是否出错,若错误,接收命令的节点不做任何处理,若正确,则通过信息中间的目的节点标号k判断此信息是否是发给自己的;
若是,则通过自身的私钥PUk解密获得命令(非对称加密中公钥加密的信息必须用私钥才能加密,而k的私钥只有k和服务器段存有,通过此保证安全性),若不是则利用本节点的通信密钥生成新的校验码Ck发送给下一个节点。至此,完成整个数据上传、命令下发的保护过程。
图7为本实施例中对于故障点的检测及链路自愈流程图。本实施例中,系统运行过程中,实时监测通信网络是否出现故障,若遇到故障则进行链路自愈。具体过程如下:
首先,需对故障节点进行判断,并找到最近的一个可以正常工作的节点;
其次,需要对发送方和接收方的默认密钥、通信密钥进行更新;
然后,通过进行上述数据上传和命令下发操作。
故障点的检测方法:通过握手信息是否完成确定故障点,当发送节点的握手信息得不到回复,或回复错误时候,认为该发送节点为故障节点,并利用“相邻i节点密钥结构”中存储的后一节点的公钥生成新的握手信息发送给后一节点,直至握手成功。
握手成功后,接收双方均将默认密钥更新,并生成新的通信密钥,进行正常通信。从而,下次通信时候可避免重复的检测,直至故障点修复,重新进行初始化进程。
经过测试发现,跳过故障点进行通信会增大能耗,考虑到设备是自身供电,因此对能耗有一定要求。通过模拟发现,一定程度的提高发射功率可以在跳过节点时有效的减少能耗,并得出i=2或3是最理想的状况,i=4或者5时设备需要较高的发射功率和能耗进行工作,i≥6时由于能耗过高,不宜采用。
最后应当说明的是:以上实施例仅用于说明本申请的技术方案而非对其保护范围的限制,尽管参照上述实施例对本申请进行了详细的说明,所属领域的普通技术人员应当理解:本领域技术人员阅读本申请后依然可对申请的具体实施方式进行种种变更、修改或者等同替换,但这些变更、修改或者等同替换,均在申请待批的权利要求保护范围之内。

Claims (8)

  1. 一种面向输电线路无线通信网络的安全通信方法,其特征在于:所述方法包括:
    初始化所述无线通信网络,判断是否新增节点,若有则对新增饿节点进行认证并为新设备分配密钥;
    新增的所述节点n通过已通信的节点n-1向控制中心上传状态数据;
    所述控制中心下发控制命令;
    实时检查链路状态,判断是否出现故障节点,若出现则运用链路自愈方法修复所述无线通信网络。
  2. 如权利要求1所述的方法,其特征在于:所述对新增的节点进行认证,包括:
    S101、所述节点n向已安全验证的前一节点n-1发送请求交互信息M0,所述节点n-1接收请求信息后确认交互则返回确认消息M1,建立通信关系;
    S102、所述节点n生成验证信息
    Figure PCTCN2016081247-appb-100001
    并发送至所述控制中心的认证服务器;E为加密算法,Kn为节点n的认证密钥,T为时间戳,C2为验证码,||表示连接关系;
    S103、所述认证服务器接收所述验证信息M2,运用所述节点n的认知密钥Kn解密
    Figure PCTCN2016081247-appb-100002
    获得解密后的时间戳T′;
    通过所述解密后的时间戳T′解密ET(Kn)获得待验证信息Kn′,比较所述节点n的认证密钥Kn和所述验证信息Kn′验证所述节点n;若相同则完成验证,若不同则返回步骤S101。
  3. 如权利要求1所述的方法,其特征在于:所述为新设备分配密钥,包括:
    S111、验证后,所述控制中心的认知服务器生成信息
    Figure PCTCN2016081247-appb-100003
    Figure PCTCN2016081247-appb-100004
    Figure PCTCN2016081247-appb-100005
    其中,M00为节点n的私钥,发给节点n;M01和M10分别包含验证对象的公钥,分别发送给节点n和节点n-1;C00、C01、C10分别表示M00、M01、M10的验证码,用于验证信息在发送过程中是否发生错误;PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥;Kn、Kn-1为节点n和节点n-的认证密钥;
    S112、根据相邻i节点密钥结构,所述节点n将其公钥PUn
    Figure PCTCN2016081247-appb-100006
    形式发送给节点n-1,并广播给剩下的相邻i个节点;
    所述节点n-1将所述相邻i个节点的公钥
    Figure PCTCN2016081247-appb-100007
    回复给所述节点n,完成公钥的分配;
    其中,E为加密算法,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Request表示请求信息,C5、C0j表示验证码。
  4. 如权利要求1所述的方法,其特征在于:所述新增的所述节点上传数据,包括以下步骤:
    S201、所述节点n向所述节点n-1发送通信握手信息;
    S202、所述节点n-1解密所述握手信息,判断其验证无误后,产生回复信息并发送至并所述节点n;
    S203、所述节点n解密所述回复信息,判断其信息验证无误,运行数据加密方法加密上传的数据,产生加密信息Mn,0=Mn||Mn′||Cn,并发送给所述节点n-1;
    S204、所述节点n-1通过所述校验码Cn验证所述加密信息Mn,0=Mn||Mn′||Cn,验证通过则重复步骤S201至S204直到发送到节点0;
    其中,PUn-1、PUn分别表示节点n-1的公钥和节点n的公钥,Mn表示上传的数据,Mn′表示解码后的所述上传的数据,Cn表示验证码;n、n-1表示节点标识。
  5. 如权利要求4所述的方法,其特征在于:所述数据加密方法,包括以下步骤:
    从待加密的节点i的上一节点i+1处接收信息Mi+1,0=Mn||Mn-1||…||Mi-1||Mi+1′||Ci+1,从中提取验证段信息Mi+1′,将所述验证段信息Mi+1′与自身的数据信息节点i中的数据Di异或;
    用节点i自身的公钥PUi加密Di获得Mi;
    将加密后的数据信息Mi添加到数据集Mn||Mn-1||…||Mi-1完成新信息的数据段;
    将所述加密后的数据信息Mi再与所述验证段信息Mi+1′异或后生成新的验证段Mi′,并利用Mi′生成新的校验码Ci
    组合上述数据,获得新节点i发送的信息Mi,0=Mn||Mn-1||…||Mi||Mi′||Ci。
  6. 如权利要求1所述的方法,其特征在于:所述控制中心向节点发送控制命令,包括以下步骤:
    任意节点接收下发的所述控制命令
    Figure PCTCN2016081247-appb-100008
    E为加密算法,k为目标节 点标号,CMk为控制命令内容,PUk为节点k的公钥,Ck为节点k的验证码;
    通过校验码Ck判断信息是否正确;若错误则不做处理,若正确则节点标号k判断此信息是否为发送给自身的信息;
    若是则解密所述控制命令获得命令,若不是则利用本节点的通信密钥生成新的校验码后发送给下一个节点。
  7. 如权利要求1所述的方法,其特征在于:所述链路自愈方法包括:
    若出现故障节点,利用所述故障节点存有的相邻i节点密钥结构中的后一节点的公钥生成新的握手信息发送给后一节点,直至握手成功;
    更新发送节点和接收节点的默认密钥、通信密钥,通过数据上传和命令下发过程进行通信。
  8. 如权利要求3或7所述的方法,其特征在于:所述相邻i节点密钥结构中存储其前向和后向i个节点的公钥;其中,i等于2或3。
PCT/CN2016/081247 2015-04-17 2016-05-06 一种面向输电线路无线通信网络的安全通信方法 Ceased WO2016165675A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510182163.0 2015-04-17
CN201510182163.0A CN104902469B (zh) 2015-04-17 2015-04-17 一种面向输电线路无线通信网络的安全通信方法

Publications (1)

Publication Number Publication Date
WO2016165675A1 true WO2016165675A1 (zh) 2016-10-20

Family

ID=54034809

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/081247 Ceased WO2016165675A1 (zh) 2015-04-17 2016-05-06 一种面向输电线路无线通信网络的安全通信方法

Country Status (2)

Country Link
CN (1) CN104902469B (zh)
WO (1) WO2016165675A1 (zh)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112822253A (zh) * 2020-12-31 2021-05-18 广州技象科技有限公司 一种电力物联网的用电数据跳传方法及装置
CN112989417A (zh) * 2021-03-25 2021-06-18 湘潭大学 一种针对多智能体中存在不诚实节点的安全一致性方案
CN114401130A (zh) * 2022-01-06 2022-04-26 辽宁大学 一种全因失效免疫的传输方法及系统
CN115085990A (zh) * 2022-06-09 2022-09-20 江苏祥泰电力实业有限公司 一种基于光纤环网的无人机巡检数据传输系统
CN116033418A (zh) * 2022-12-23 2023-04-28 格睿通智能科技(深圳)有限公司 一种应用于消防物联网的无线通信加密方法及系统
CN116599758A (zh) * 2023-06-15 2023-08-15 广东电网有限责任公司广州供电局 信息交互方法及继电保护故障信息系统
CN117499442A (zh) * 2023-12-27 2024-02-02 天津数智物联科技有限公司 一种用于物联网能源监测装置的数据高效处理方法
WO2024041213A1 (zh) * 2022-08-23 2024-02-29 华为技术有限公司 通信方法、装置、系统及存储介质
CN119718753A (zh) * 2024-12-20 2025-03-28 盘古未来(北京)科技有限公司 一种板卡故障自动智能检测方法及系统

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104902469B (zh) * 2015-04-17 2019-01-25 国家电网公司 一种面向输电线路无线通信网络的安全通信方法
CN105306142A (zh) * 2015-09-18 2016-02-03 国网冀北电力有限公司信息通信分公司 一种提高光纤传输可靠性的装置和方法
CN112019489B (zh) * 2019-05-31 2022-03-04 华为技术有限公司 验证方法及装置
CN116506528A (zh) * 2023-05-06 2023-07-28 北京石头创新科技有限公司 一种多层级通讯方法、设备、系统和介质

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070011435A1 (en) * 2005-06-02 2007-01-11 Samsung Electronics Co., Ltd. Mesh node association method in a mesh network, and mesh network supporting the same
CN101621434A (zh) * 2008-06-30 2010-01-06 华为技术有限公司 无线网状网络系统以及密钥分配的方法
CN102421095A (zh) * 2011-11-30 2012-04-18 广州杰赛科技股份有限公司 无线网状网的接入认证方法
CN202353820U (zh) * 2011-08-16 2012-07-25 福建望诚电子有限公司 一种新型无线网络系统
US20140013117A1 (en) * 2012-07-09 2014-01-09 Electronics And Telecommunications Research Institute Authentication method of wireless mesh network
CN103647788A (zh) * 2013-12-23 2014-03-19 国网重庆市电力公司 一种智能电网中的节点安全认证方法
CN103686709A (zh) * 2012-09-17 2014-03-26 中兴通讯股份有限公司 一种无线网格网认证方法和系统
CN104902469A (zh) * 2015-04-17 2015-09-09 国家电网公司 一种面向输电线路无线通信网络的安全通信方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101807818B (zh) * 2010-02-25 2012-07-04 华北电力大学 基于id的配电网自动化通信系统的设备接入认证方法
CN103227987B (zh) * 2013-04-08 2016-05-04 哈尔滨工程大学 一种异构传感网认证组密钥管理方法
CN103763095B (zh) * 2014-01-06 2017-01-18 华南理工大学 一种智能变电站密钥管理方法

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070011435A1 (en) * 2005-06-02 2007-01-11 Samsung Electronics Co., Ltd. Mesh node association method in a mesh network, and mesh network supporting the same
CN101621434A (zh) * 2008-06-30 2010-01-06 华为技术有限公司 无线网状网络系统以及密钥分配的方法
CN202353820U (zh) * 2011-08-16 2012-07-25 福建望诚电子有限公司 一种新型无线网络系统
CN102421095A (zh) * 2011-11-30 2012-04-18 广州杰赛科技股份有限公司 无线网状网的接入认证方法
US20140013117A1 (en) * 2012-07-09 2014-01-09 Electronics And Telecommunications Research Institute Authentication method of wireless mesh network
CN103686709A (zh) * 2012-09-17 2014-03-26 中兴通讯股份有限公司 一种无线网格网认证方法和系统
CN103647788A (zh) * 2013-12-23 2014-03-19 国网重庆市电力公司 一种智能电网中的节点安全认证方法
CN104902469A (zh) * 2015-04-17 2015-09-09 国家电网公司 一种面向输电线路无线通信网络的安全通信方法

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112822253A (zh) * 2020-12-31 2021-05-18 广州技象科技有限公司 一种电力物联网的用电数据跳传方法及装置
CN112989417A (zh) * 2021-03-25 2021-06-18 湘潭大学 一种针对多智能体中存在不诚实节点的安全一致性方案
CN112989417B (zh) * 2021-03-25 2022-04-22 湘潭大学 一种针对多智能体中存在不诚实节点的安全一致性方案
CN114401130A (zh) * 2022-01-06 2022-04-26 辽宁大学 一种全因失效免疫的传输方法及系统
CN115085990A (zh) * 2022-06-09 2022-09-20 江苏祥泰电力实业有限公司 一种基于光纤环网的无人机巡检数据传输系统
CN115085990B (zh) * 2022-06-09 2023-11-07 江苏祥泰电力实业有限公司 一种基于光纤环网的无人机巡检数据传输系统
WO2024041213A1 (zh) * 2022-08-23 2024-02-29 华为技术有限公司 通信方法、装置、系统及存储介质
CN116033418A (zh) * 2022-12-23 2023-04-28 格睿通智能科技(深圳)有限公司 一种应用于消防物联网的无线通信加密方法及系统
CN116599758A (zh) * 2023-06-15 2023-08-15 广东电网有限责任公司广州供电局 信息交互方法及继电保护故障信息系统
CN117499442A (zh) * 2023-12-27 2024-02-02 天津数智物联科技有限公司 一种用于物联网能源监测装置的数据高效处理方法
CN117499442B (zh) * 2023-12-27 2024-05-10 天津数智物联科技有限公司 一种用于物联网能源监测装置的数据高效处理方法
CN119718753A (zh) * 2024-12-20 2025-03-28 盘古未来(北京)科技有限公司 一种板卡故障自动智能检测方法及系统

Also Published As

Publication number Publication date
CN104902469B (zh) 2019-01-25
CN104902469A (zh) 2015-09-09

Similar Documents

Publication Publication Date Title
WO2016165675A1 (zh) 一种面向输电线路无线通信网络的安全通信方法
CN107094155B (zh) 一种基于联盟区块链的数据安全存储方法及装置
CN100581102C (zh) 一种无线传感器网络中数据安全传输的方法
CN102448061B (zh) 一种基于移动终端防钓鱼攻击的方法和系统
CN108566436B (zh) 一种基于区块链的分布式电力设备信息采集系统和方法
CN107249009A (zh) 一种基于区块链的数据校验方法及系统
CN111447283A (zh) 一种用于实现配电站房系统信息安全的方法
CN104639311A (zh) 一种智能电网中用电隐私及完整性保护的聚合方法及系统
CN116887073A (zh) 一种基于计算机网络通信的电能表数据采集控制系统
CN103501293B (zh) 一种智能电网中终端可信接入的认证方法
CN105323754A (zh) 一种基于预共享密钥的分布式鉴权方法
CN114745180A (zh) 接入认证方法、装置和计算机设备
CN113382016A (zh) 智能电网环境下可容错的安全轻量级数据聚合方法
CN102916809A (zh) 基于状态估计的智能电网控制命令动态认证方法
CN107231628B (zh) 一种适用于多应用场景的安全数据融合方法
CN102612035B (zh) 多级分簇无线传感器网络中能量高效的身份认证方法
CN104994085B (zh) 一种无线传感器网络中身份认证方法及系统
Zhang et al. An adaptive security protocol for a wireless sensor‐based monitoring network in smart grid transmission lines
CN119788279A (zh) 终端的通信方法、服务器的通信方法、控制器、终端及服务器
CN103823691B (zh) 基于网络编码的无线传感器网络安全在线重编程方法
CN119051956A (zh) 基于物联网的数据传输保护方法及系统
Alohali et al. Secure and energy-efficient multicast routing in smart grids
CN101646172A (zh) 一种分布式mesh网络中产生密钥的方法和装置
Lv et al. A highly reliable lightweight distribution network communication encryption scheme
Choi et al. An efficient message authentication for non-repudiation of the smart metering service

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16779650

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16779650

Country of ref document: EP

Kind code of ref document: A1