Xia Zhe, Liu Tao, Wang Jingjing, Chen Shi
School of Computer Science and Artificial Intelligence, Wuhan University of Technology, Wuhan, China.
State Grid Hubei Electric Power Co., Ltd., Information Communication Company, Wuhan, China.
Heliyon. 2023 Jun 16;9(7):e17240. doi: 10.1016/j.heliyon.2023.e17240. eCollection 2023 Jul.
Smart grid provides convenience for power generation, consumption and distribution. Authenticated key exchange (AKE) is a fundamental technique to protect data transmission from interception and tampering in smart grid. However, since the smart meters only have limited resources in computation and communication, most of the existing AKE schemes are inefficient for smart grid. First, many schemes have to use large security parameters to compensate the loose reduction in their security proofs. Second, most of these schemes require at least three-round of communication to negotiate a secret session key with explicit key confirmation. To alleviate these issues, we propose a novel two-round AKE scheme with tight security for smart grid. Our proposed scheme integrates Diffie-Hellman key exchange and a tightly secure digital signature, in which not only mutual authentication can be realized but also the communicating parties can confirm that session keys are negotiated between them explicitly. Compared with the existing AKE schemes, the overheads in both communication and computation are lighter in our proposed scheme, because fewer rounds of communication are required and smaller security parameters can be used to achieve the same security level. Therefore, our scheme contributes to a more practical solution for secure key establishment in smart grid.
智能电网为发电、用电和配电提供了便利。认证密钥交换(AKE)是保护智能电网中数据传输不被拦截和篡改的一项基本技术。然而,由于智能电表在计算和通信方面资源有限,现有的大多数AKE方案对智能电网而言效率低下。首先,许多方案不得不使用大量安全参数来弥补其安全证明中宽松的归约。其次,这些方案中的大多数需要至少三轮通信来协商一个带有明确密钥确认的秘密会话密钥。为缓解这些问题,我们提出了一种新颖的、具有紧安全性的两轮AKE方案用于智能电网。我们提出的方案集成了迪菲 - 赫尔曼密钥交换和一个具有紧安全性的数字签名,其中不仅可以实现相互认证,而且通信双方能够明确确认他们之间协商出了会话密钥。与现有的AKE方案相比,我们提出的方案在通信和计算方面的开销更小,因为所需的通信轮数更少,并且可以使用更小的安全参数来达到相同的安全级别。因此,我们的方案为智能电网中安全密钥建立提供了一个更实用的解决方案。