Modern smart grids rely on advanced metering infrastructure (AMI) to collect fine-grained consumption readings for operational services such as grid monitoring, load forecasting, and demand--supply balancing. However, these high-frequency readings can reveal sensitive information about consumers' daily activities. To address this privacy concern, we propose a collusion-resistant privacy-preserving aggregation protocol for smart metering operational services. The protocol distributes noise-cancellation responsibility among a configurable group of $K$ designated smart meters. Each non-designated meter perturbs its reading using $K$ independent noise components, while corresponding cancellation values ensure that noise is removed only from the final aggregate. The protocol combines Paillier homomorphic encryption with a KEM--KDF--AEAD construction. Paillier encryption enables the aggregator to compute an encrypted aggregate without decrypting individual contributions, while authenticated encryption protects exchanged noise components between smart meters. Under the considered collusion and meter-exposure model, the exact reading of a trusted and unexposed meter remains protected as long as at least one designated and one non-designated meter remain unexposed. We evaluate the protocol in terms of computational, memory, communication, and privacy overheads. Privacy is evaluated using normalized conditional entropy (NCE) and normalized root-mean-square error (NRMSE). The results show that increasing the noise scale increases NCE and uncertainty about individual readings, while NRMSE quantifies the gradual loss of privacy as additional opposite-role meters are exposed. Overall, the protocol provides exact aggregate consumption values required for operational services while protecting individual fine-grained readings against the considered adversarial coalition.
翻译:暂无翻译