综合智慧能源 ›› 2024, Vol. 46 ›› Issue (9): 86-96.doi: 10.3969/j.issn.2097-0706.2024.09.010

• 新能源与人工智能 • 上一篇    

基于一次一密的5G馈线终端通信安全防护方法

王录泽a(), 刘增稷a(), 周霞b,*(), 张腾飞a()   

  1. a.南京邮电大学 自动化学院 人工智能学院,南京 210023
    b.南京邮电大学 碳中和先进技术研究院,南京 210023
  • 收稿日期:2023-12-19 修回日期:2024-03-04 出版日期:2024-09-25
  • 通讯作者: *周霞(1978),女,高级工程师,博士,从事电力系统分析与仿真等方面的研究,zhouxia@njupt.edu.cn
  • 作者简介:王录泽(1998),男,硕士生,从事智能配电网技术等方面的研究,w18151688331@163.com
    刘增稷(1993),男,讲师,博士,从事电力信息物理系统网络安全等方面的研究,liuzengji_njupt@163.com
    张腾飞(1980),男,教授,博士,从事智能配电网与配电物联网技术等方面的研究,zhangtf@njupt.edu.cn
  • 基金资助:
    国家自然科学基金项目(62073173)

Communication security protection method for 5G feeder terminals based on one-time pad

WANG Luzea(), LIU Zengjia(), ZHOU Xiab,*(), ZHANG Tengfeia()   

  1. a. College of Automation & College of Artificial Intelligence,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    b. Institute of Carbon Neutral Advanced Technology,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
  • Received:2023-12-19 Revised:2024-03-04 Published:2024-09-25
  • Supported by:
    National Natural Science Foundation of China(62073173)

摘要:

针对5G通信环境中,馈线自动化(FA)终端之间对等通信容易受到非法干扰和窃听的问题,提出一种基于一次一密的馈线终端(FTU)通信安全防护方法,旨在提升FTU在5G环境下通信的安全性。首先,在FTU内集成加解密安全芯片,并通过预充注在加解密安全芯片内的密钥向安全服务移动引擎进行双向身份认证,安全服务平台向身份认证成功的FTU分发一定数量的根密钥;其次,加解密安全芯片采用基于改进Shamir的密钥扩散算法,将根密钥动态扩散生成新的会话密钥;最后,需要进行对等通信的FTU双方获得新的会话密钥,并使用SM4加密算法进行一次加密通信。试验结果表明,FTU每次加密通信都使用了不同的会话密钥和初始向量,使得加密结果不可预测。所提方法不仅提升了5G场景下FTU对等通信的安全性,并且相较于其他方法,所提方法在5G高速、大数据量的通信环境中具有较低的计算开销。

关键词: 配电自动化, 馈线终端, 一次一密, 5G通信, 通信安全, 密钥扩散, 智能电网

Abstract:

A communication security protection method is proposed for feeder terminal units (FTU) in 5G environment to address the vulnerability of peer-to-peer communication between feeder automation(FA) terminals to illegal interferences and eavesdropping. This method utilizes a one-time one-pad encryption and decryption mechanism to enhance the security of FTU communication. Firstly,an encryption and decryption security chip is integrated into FTU,enabling two-way identity authentication with the security service mobile engine using pre-loaded keys. Upon successful authentication,the security service platform distributes a set number of root keys to the authenticated FA. Secondly,an improved Shamir key diffusion algorithm is employed by the encryption and decryption security chip to dynamically diffuse these root keys and generate new session keys. Finally,both feeder terminals engaging in peer-to-peer communication obtain unique session keys to their corresponding encrypted communication instances using SM4 encryption algorithm. Experimental results demonstrate that distinct session keys and initial vectors are used in different pairs of communicating feeder terminals,ensuring unpredictable encryption outcomes. This proposed method not only enhances the security of peer-to-peer communication among feeder terminals in 5G scenarios, but also reduces the computational costs compared to other methods suitable for high-speed and large-volume communications in 5G environments.

Key words: distribution automation, feeder terminal, one-time pad, 5G communication, communication security, key diffusion, smart grid

中图分类号: