A method and system for secure authentication of power grid operators based on quantum communication

By using Bell state sequence generation and decoy particle manipulation in quantum communication, combined with classical communication verification, the problems of impersonation and replay attacks in the security authentication of power grid operators are solved, thereby improving the security and efficiency of the power grid system.

CN119995848BActive Publication Date: 2025-10-31GUIZHOU POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411990549.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-10-31
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

Existing power grid operator security authentication methods are vulnerable to impersonation and replay attacks, and cannot provide adequate protection against advanced persistent threats (APTs). They also have high computational resource requirements, which affects the real-time control and monitoring of the power grid.

Method used

A quantum communication-based security authentication method is adopted. By generating a Bell state sequence and introducing decoy particles, quantum channel transmission, decoy state detection and permutation operations are performed. This method combines classical communication to verify identity and utilizes quantum entanglement and decoy state technology to enhance security.

Benefits of technology

It effectively prevents advanced persistent threats (APTs), improves the security of power grid communications, simplifies operating procedures, is suitable for resource-constrained equipment, reduces authentication latency, and enhances the security protection capabilities of the power grid system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995848B_ABST
    Figure CN119995848B_ABST
Patent Text Reader

Abstract

This invention discloses a secure authentication method and system for power grid operators based on quantum communication, relating to the field of quantum secure authentication technology. The method includes: a power grid control center and a power grid operator generating a Bell state sequence based on a binary key sequence and dividing it to obtain a first sequence and a second sequence; introducing decoy particles into the first sequence to form an extended first sequence, which is then transmitted via a quantum channel; a security center performing decoy state detection, permutation, and decoy state introduction on the extended first sequence to generate a new first sequence, which is then transmitted; the power grid control center and the power grid operator removing the decoy states from the new first sequence to restore the original first sequence; performing Pauli operations and Bell measurements on the second sequence to obtain measurement results; and exchanging the measurement results using classical communication channels to verify identity and achieve secure authentication of the power grid operator. This invention effectively prevents advanced persistent threats (APTs) and other potential security risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum security authentication technology, and in particular to a method and system for power grid operator security authentication based on quantum communication. Background Technology

[0002] In power grid operation, the secure authentication of power grid operators is a crucial link in ensuring the safe and stable operation of the power system. With the rapid development of smart grid technology, the power grid system is becoming increasingly complex and intelligent, and the importance of operator access management and identity authentication has also increased significantly. Current power grid operator security authentication technologies mainly focus on cryptographic methods, physical feature authentication, and edge computing. In terms of cryptographic methods, Elliptic Curve Cryptography (ECC) has become one of the mainstream technologies for power grid security authentication due to its short key length and high security. ECC can achieve efficient identity verification and key negotiation under limited computing resources. At the same time, the introduction of Physically Unclonable Function (PUF) technology significantly enhances the security and uncopyability of authentication protocols by generating unique authentication fingerprints using the inherent physical characteristics of hardware. In the smart grid environment, the application of edge computing technology makes lightweight authentication possible, effectively reducing the computational burden on terminal devices.

[0003] However, existing technologies still face many challenges: First, traditional authentication methods are vulnerable to impersonation attacks during the authentication process, as attackers may intercept legitimate users' authentication information to impersonate them; second, replay attacks are also a prominent issue, as attackers can reuse previously intercepted valid authentication information. More seriously, in the face of increasingly complex advanced persistent threats (APTs), existing authentication mechanisms often cannot provide comprehensive and persistent protection. These attacks are characterized by their high degree of concealment and long duration, which may lead to serious security incidents; in addition, existing authentication methods generally have high computational resource requirements. In practical applications, many power grid terminal devices have limitations in computing power and storage space, and complex authentication algorithms may cause device response delays, affecting the real-time control and monitoring of the power grid. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the problem to be solved by this invention is to provide a quantum communication-based secure authentication method for power grid operators that overcomes the vulnerability of existing authentication methods to impersonation and replay attacks, and may not provide sufficient protection against advanced persistent threats (APTs).

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0007] In a first aspect, embodiments of the present invention provide a secure authentication method for power grid operators based on quantum communication. The method includes: a power grid control center and a power grid operator generating a Bell state sequence based on a binary key sequence and dividing it to obtain a first sequence and a second sequence; introducing decoy particles into the first sequence to form an extended first sequence and transmitting it through a quantum channel; the security center performing decoy state detection, permutation, and decoy state introduction on the extended first sequence to generate a new first sequence and transmitting it; the power grid control center and the power grid operator removing the decoy states from the new first sequence to restore it to the original first sequence; performing Pauli operations and Bell measurements on the second sequence to obtain measurement results; and exchanging the measurement results using a classical communication channel to verify identity and achieve secure authentication of the power grid operator.

[0008] As a preferred embodiment of the quantum communication-based power grid operator security authentication method of the present invention, wherein: generating the Bell state sequence refers to the power grid control center and the power grid operator generating the Bell state sequence S respectively based on the shared binary key sequence. A and Bell state sequence S B .

[0009] As a preferred embodiment of the quantum communication-based power grid operator security authentication method of the present invention, wherein: the generation of the Bell state sequence S A and Bell state sequence S B Including: If k m =00 and k m =01, then the Bell state sequence S A The calculation formula is as follows:

[0010] S A =|Φ + >

[0011] S A ={|Ψ A1 >,|Ψ A2 >,|Ψ A3 >,...,|Ψ A2n >}

[0012]

[0013] Where, k m Let S be the m-th key value in the binary key sequence, where m = 1, 2, ..., 2n, and 2n is the total number of elements in the key sequence; A A Bell state sequence; Ψ Ai The Bell state is generated by the power grid control center using the i-th key in the binary key sequence; if k m =01 and k m=10, then the Bell state sequence S B The calculation formula is as follows:

[0014] S B =|Φ - >

[0015] S B ={|Ψ B1 >,|Ψ B2 >,|Ψ B3 >,...,|Ψ B2n >}

[0016]

[0017] Where, k m Let S be the m-th key value in the binary key sequence, where m = 1, 2, ..., 2n, and 2n is the total number of elements in the key sequence; B A Bell state sequence; Ψ Bi The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

[0018] As a preferred embodiment of the quantum communication-based power grid operator security authentication method of the present invention, wherein obtaining the first sequence and the second sequence includes: the power grid control center transmitting the Bell state sequence S... A Divided into the first particle sequence S A1 and the first quantum bit sequence S A2 The specific formula is as follows:

[0019] S A1 ={|Ψ A1 >,|Ψ A3 >,...,|Ψ A(2n-1) >}

[0020] S A2 ={|Ψ A2 >,|Ψ A4 >,...,|Ψ A(2n) >}

[0021] Among them, S A1 For the first particle sequence; S A2 The first quantum bit sequence; Ψ Ai The Bell state is generated by the power grid control center using the i-th key in the binary key sequence; the power grid operator then uses the Bell state sequence S. B Divided into the second particle sequence S B1 The second quantum bit sequence S B2 The specific formula is as follows:

[0022] S B1 ={|ΨB1 >,|Ψ B3 >,...,|Ψ B(2n-1) >}

[0023] S B2 ={|Ψ B2 >,|Ψ B4 >,...,|Ψ B(2n) >}

[0024] Among them, S B1 For the second particle sequence; S B2 For the second quantum bit sequence; Ψ Bi The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

[0025] As a preferred embodiment of the quantum communication-based power grid operator security authentication method of the present invention, wherein: introducing decoy particles into the first sequence to form an extended first sequence refers to the power grid control center and the power grid operator respectively introducing decoy particles into the first particle sequence S. A1 Second particle sequence S B1 Decoy particles are introduced to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 The introduction of decoy particles forms an extended first particle sequence S'. A1 and the extended second particle sequence S' B1 This refers to randomly selecting the state of the decoy particles in the first particle sequence S. A1 Second particle sequence S B1 Decoy particles are randomly inserted at various positions; the extended first sequence is subjected to decoy state detection, permutation operation, and introduction of decoy states to generate a new first sequence, including the following steps: the security center receives the extended first particle sequence S'. A1 and the extended second particle sequence S' B1 The decoy's state is then detected. If everything is correct, the first particle sequence S is extracted. A1 Second particle sequence S B1 ; For the extracted first particle sequence S A1 Second particle sequence S B1 Perform a substitution operation and reintroduce the decoy state to generate a new first particle sequence. and the new second particle sequence

[0026] As a preferred embodiment of the quantum communication-based power grid operator security authentication method of the present invention, wherein: removing the decoy state from the new first sequence and restoring it to the first sequence refers to the power grid control center and the power grid operator receiving the new first particle sequence. and the new second particle sequence The decoy state is removed, restoring the first particle sequence S. A1 Second particle sequence S B1 The Pauli operation and Bell measurement include the following steps: the power grid control center and power grid operators utilize the first quantum bit sequence S A2 The second quantum bit sequence S B2 Pauli operations are performed based on the pre-shared key to obtain the manipulated qubits; Bell measurements are then performed on the manipulated qubits to obtain the measurement results.

[0027] As a preferred embodiment of the quantum communication-based power grid operator security authentication method of the present invention, the method of exchanging measurement results and verifying identity using classical communication channels includes the following steps: the power grid control center and the power grid operator exchange their respective measurement results through classical communication channels, and verify the identities of both parties by comparing the correlation of the measurement results. If the result shows an association pattern consistent with the expected pre-shared key, the authentication is successful; if the result does not match the expectation, it indicates that there is interference or fraud attempt, and the authentication fails.

[0028] Secondly, to further address the security issues existing in quantum-secure authentication, this invention provides a quantum communication-based power grid operator security authentication system, comprising: a sequence generation module for generating and dividing a Bell state sequence based on a binary key sequence between the power grid control center and the power grid operator to obtain a first particle sequence, a first qubit sequence, a second particle sequence, and a second qubit sequence; a decoy introduction module for introducing decoy particles into the first and second particle sequences to form an extended first particle sequence and an extended second particle sequence; and a security center module for receiving the extended first particle sequence and the extended second particle sequence and performing decoy detection. The system comprises the following modules: a bait state detection module, a substitution operation module, and a decoy state introduction module, which generates new first and second particle sequences and sends them to the power grid control center and the power grid operator; a decoy state removal module, which allows the power grid control center and the power grid operator to remove the decoy states from the new first and second particle sequences, restoring them to their original first and second particle sequences; a measurement result module, which allows the power grid control center and the power grid operator to perform Pauli operations and Bell measurements using the first and second qubit sequences according to a pre-shared key, to obtain the measurement results; and a security authentication module, which allows the power grid control center and the power grid operator to exchange measurement results using classical communication channels and verify the identities of both parties.

[0029] Thirdly, embodiments of the present invention provide a computer device including a memory and a processor, wherein the memory stores a computer program, and the computer program, when executed by the processor, implements any step of the quantum communication-based power grid operator security authentication method described in the first aspect of the present invention.

[0030] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the quantum communication-based power grid operator security authentication method as described in the first aspect of the present invention.

[0031] The beneficial effects of this invention are as follows: The power grid operator security authentication method based on quantum communication of this invention greatly enhances the security of power grid communication by utilizing quantum entanglement, decoy state technology and quantum permutation operations. Through this method, the power grid control center and the operator can securely generate and share keys, effectively preventing advanced persistent threats (APTs) and other potential security risks. In addition, this invention also has the ability to manage keys efficiently and adapt to resource-constrained devices, which not only improves the security protection capabilities of the power grid system, but also simplifies the operation process and is suitable for integration into the existing power grid security architecture. Attached Figure Description

[0032] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0033] Figure 1 This is an overall flowchart of the power grid operator security authentication method based on quantum communication in Example 1.

[0034] Figure 2 This is a schematic diagram of the computer device in Example 3. Detailed Implementation

[0035] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0036] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0037] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0038] Example 1

[0039] Reference Figure 1 This is the first embodiment of the present invention, which provides a power grid operator security authentication method based on quantum communication.

[0040] Existing authentication methods suffer from the following main problems: First, traditional authentication methods are vulnerable to impersonation attacks, where attackers may intercept legitimate users' authentication information to impersonate them. Second, replay attacks are also a significant issue, as attackers can reuse previously intercepted valid authentication information. More seriously, facing increasingly complex Advanced Persistent Threats (APTs), existing authentication mechanisms often fail to provide comprehensive and persistent protection. These attacks are characterized by their high degree of concealment and long duration, potentially leading to serious security incidents. Furthermore, existing authentication methods generally have high computational resource requirements. In practical applications, many power grid terminal devices have limitations in computing power and storage space, and complex authentication algorithms may cause device response delays, affecting the real-time control and monitoring effectiveness of the power grid.

[0041] This application provides a method that can effectively solve the problems mentioned above. The following will describe in detail how to implement the quantum communication-based power grid operator security authentication method with reference to several embodiments.

[0042] Figure 1 A flowchart illustrating the overall process of a quantum communication-based power grid operator security authentication method is provided, including:

[0043] S1: The power grid control center and power grid operators generate a Bell state sequence based on the binary key sequence and divide it to obtain the first sequence and the second sequence.

[0044] Preferably, generating the Bell state sequence refers to the power grid control center and the power grid operator generating the Bell state sequence S respectively based on the shared binary key sequence. A and Bell state sequence S B .

[0045] Specifically, generate the Bell state sequence S. A and Bell state sequence S B Including: If k m =00 and k m =01, then the Bell state sequence SA The calculation formula is as follows:

[0046] S A =|Φ + >

[0047] S A ={|Ψ A1 >,|Ψ A2 >,|Ψ A3 >,...,|Ψ A2n >}

[0048]

[0049] Where, k m Let S be the m-th key value in the binary key sequence, where m = 1, 2, ..., 2n, and 2n is the total number of elements in the key sequence; A A Bell state sequence; Ψ Ai The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

[0050] If k m =01 and k m =10, then the Bell state sequence S B The calculation formula is as follows:

[0051] S B =|Φ - >

[0052] S B ={|Ψ B1 >,|Ψ B2 >,|Ψ B3 >,...,|Ψ B2n >}

[0053]

[0054] Where, k m Let S be the m-th key value in the binary key sequence, where m = 1, 2, ..., 2n, and 2n is the total number of elements in the key sequence; B A Bell state sequence; Ψ Bi The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

[0055] Furthermore, obtaining the first and second sequences includes: the power grid control center will use the Bell state sequence S. A Divided into the first particle sequence S A1 and the first quantum bit sequence S A2 The specific formula is as follows:

[0056] SA1 ={|Ψ A1 >,|Ψ A3 >,...,|Ψ A(2n-1) >}

[0057] S A2 ={|Ψ A2 >,|Ψ A4 >,...,|Ψ A(2n) >}

[0058] Among them, S A1 For the first particle sequence; S A2 The first quantum bit sequence; Ψ Ai The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

[0059] The grid operator will use the Bell state sequence S B Divided into the second particle sequence S B1 The second quantum bit sequence S B2 One sequence contains the first particle of all Bell pairs, and the other contains the second particle, as shown in the following formula:

[0060] S B1 ={|Ψ B1 >,|Ψ B3 >,...,|Ψ B(2n-1) >}

[0061] S B2 ={|Ψ B2 >,|Ψ B4 >,...,|Ψ B(2n) >}

[0062] Among them, S B1 For the second particle sequence; S B2 For the second quantum bit sequence; Ψ Bi The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

[0063] Preferably, this invention introduces a Bell state generation mechanism based on binary key values. By establishing a strict mathematical correspondence between the binary key sequence and the Bell state, the determinism and repeatability of quantum state preparation are ensured. By proposing a scheme to divide the sequence into a particle sequence and a qubit sequence, the efficient allocation of quantum entanglement pairs is achieved, laying the foundation for subsequent security verification.

[0064] S2: Introduce decoy particles into the first sequence to form an extended first sequence and transmit it through a quantum channel.

[0065] Preferably, introducing decoy particles into the first sequence to form an extended first sequence means that the power grid control center and the power grid operator respectively introduce decoy particles into their respective first particle sequences S. A1 Second particle sequence S B1 Decoy particles are introduced to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 .

[0066] Specifically, decoy particles are introduced to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 This refers to randomly selecting the state of the decoy particles in the first particle sequence S. A1 Second particle sequence S B1 Decoy particles are inserted at random positions.

[0067] Preferably, by utilizing the random selection of decoy particle states and inserting them at random positions, the difficulty for eavesdroppers to predict sequence content is significantly increased, and the introduction of decoy particles provides reliable technical support for subsequent quantum channel security detection.

[0068] S3: The security center performs decoy state detection, replacement operation, and introduces decoy state into the extended first sequence, generates a new first sequence, and transmits it.

[0069] Preferably, the extended first sequence is subjected to decoy state detection, permutation operation, and introduction of decoy states to generate a new first sequence, including the following steps: the security center receives the extended first particle sequence S' A1 and the extended second particle sequence S' B1 The decoy's state is then detected. If everything is correct, the first particle sequence S is extracted. A1 Second particle sequence S B1 .

[0070] For the extracted first particle sequence S A1 Second particle sequence S B1 Perform a substitution operation and reintroduce the decoy state to generate a new first particle sequence. and the new second particle sequence

[0071] Ideally, a reliable third-party verification mechanism is constructed through independent testing by the security center. This mechanism consists of a triple protection mechanism: decoy state detection, substitution operation, and reintroduction of decoy state. The introduction of substitution operation breaks the original particle arrangement pattern and increases the randomness of the communication process. The use of multiple decoy states forms a defense-in-depth system, which significantly improves the anti-interference capability.

[0072] S4: The power grid control center and power grid operators remove the decoy state from the new first sequence and restore it to the first sequence.

[0073] Preferably, removing the decoy state from the new first sequence and restoring it to the original first sequence means that the power grid control center and power grid operators receive the new first particle sequence. and the new second particle sequence The decoy state is removed, restoring the first particle sequence S. A1 Second particle sequence S B1 .

[0074] S5: Perform Pauli operation and Bell measurement on the second sequence to obtain the measurement results.

[0075] Specifically, performing the Pauli operation and Bell measurement involves the following steps: the power grid control center and power grid operators utilize the first quantum bit sequence S A2 The second quantum bit sequence S B2 Pauli operations are performed based on the pre-shared key to obtain the resulting qubits.

[0076] The manipulated qubits are subjected to Bell measurements to obtain the measurement results.

[0077] Preferably, a unique verification mechanism is formed by combining the Pauli operation with the Bell measurement. The introduction of the Pauli operation increases the complexity of the quantum state transformation, making it difficult for unauthorized parties to accurately predict the measurement results; while the Bell measurement can effectively detect the correlation of quantum entangled pairs, providing a reliable physical basis for identity verification.

[0078] S6: Use classic communication channels to exchange measurement results, verify identity, and achieve safe authentication of power grid operators.

[0079] Specifically, the exchange of measurement results and identity verification using a classic communication channel includes the following steps: The power grid control center and the power grid operator exchange their respective measurement results through a secure classic communication channel. The identities of both parties are verified by comparing the correlation between the measurement results. If the results show an association pattern consistent with the pre-shared key, the identity verification is successful.

[0080] If the result is not as expected, it indicates that there may be interference or fraud attempts, and the authentication failed.

[0081] Preferably, this invention constructs a complete identity authentication system by combining quantum communication with classical communication. By utilizing the non-cloning and quantum entanglement properties of quantum states, the security of the authentication process is guaranteed at the physical level. Through the superposition of multiple security mechanisms, the technical threshold for identity forgery and man-in-the-middle attacks is significantly improved. Combining classical communication for result verification not only ensures the reliability of the authentication results but also provides a practical failure handling mechanism.

[0082] In summary, the quantum communication-based secure authentication method for power grid operators of this invention greatly enhances the security of power grid communication by utilizing quantum entanglement, decoy state technology, and quantum permutation operations. Through this method, the power grid control center and operators can securely generate and share keys, effectively preventing advanced persistent threats (APTs) and other potential security risks. Furthermore, this invention also possesses efficient key management and adaptability to resource-constrained devices, not only improving the security protection capabilities of the power grid system but also simplifying the operation process, making it suitable for integration into existing power grid security architectures.

[0083] Example 2, an embodiment of the present invention, provides a power grid operator security authentication system based on quantum communication, comprising: a sequence generation module, used by the power grid control center and the power grid operator to generate a Bell state sequence based on a binary key sequence and divide it to obtain a first particle sequence, a first qubit sequence, a second particle sequence, and a second qubit sequence; a decoy introduction module, used to introduce decoy particles into the first particle sequence and the second particle sequence to form an extended first particle sequence and an extended second particle sequence; and a security center module, used to receive the extended first particle sequence and the extended second particle sequence using a security center and perform decoy state detection and substitution operations. The system consists of a decoy state generation module, a decoy state introduction module, a decoy state removal module, a measurement result module, and a security authentication module. The decoy state removal module generates a new first particle sequence and a new second particle sequence, which are then sent to the power grid control center and the power grid operator. The decoy state removal module removes the decoy state from the new first particle sequence and the decoy state, restoring the original first particle sequence and the decoy state to the original first particle sequence and the decoy state. The measurement result module performs Pauli operations and Bell measurements using the first and second qubit sequences and a pre-shared key, obtaining the measurement results. The security authentication module verifies the identities of both parties by exchanging measurement results through classical communication channels.

[0084] Example 3 is an embodiment of the present invention, which differs from the previous embodiment in that:

[0085] like Figure 2As shown, if the function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0086] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0087] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0088] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0089] Example 4 is an embodiment of the present invention, which provides a power grid operator safety authentication method based on quantum communication. In order to verify the beneficial effects of the present invention, a simulation experiment is conducted for scientific demonstration.

[0090] This example demonstrates a six-month experimental study conducted in a provincial power dispatch and control center. The experimental environment was configured as follows: the QKD-2000 quantum key distribution system, developed by Quantum Technology Co., Ltd., was used as the basic equipment for quantum communication. This system has a Bell state preparation rate of 1 GHz and a Bell state measurement accuracy of 99.9%. The total length of the optical fiber channel used in the experiment was 75 kilometers. The signal was enhanced by an erbium-doped fiber amplifier (EDFA), and phase compensation technology was used to maintain the coherence of the quantum states.

[0091] In the specific implementation process, a 1024-bit binary key sequence is first generated as the initial shared key. The power grid control center and the power grid operator generate Bell state sequences based on this key sequence. When the key value is "00" and "01", a Bell state sequence S is generated. A When the key value is "01" and "10", a Bell state sequence S is generated. B To ensure the security of the quantum channel, a decoy state is inserted every 8 qubits in the first sequence. The decoy state is randomly selected from one of four states: |0>, |1>, |+>, and |->. After receiving the extended sequence, the security center first checks the correctness of the decoy state, then performs a quantum state substitution operation based on the Fisher-Yates algorithm. After the substitution, the decoy state is introduced again to form a new sequence. Finally, the power grid control center and the power grid operator perform Pauli operations and Bell measurements, and use the classical channel to exchange measurement results for identity authentication.

[0092] In the experiment, the method proposed in this invention was evaluated from three perspectives: system performance parameters under different communication distances, security performance indicators under different attack scenarios, and performance comparison with traditional authentication methods. Table 1 shows the system performance parameters under different communication distances.

[0093] Table 1 System performance parameters under different communication distances

[0094] Communication distance (km) Photon detection efficiency (%) Quantum bit error rate (%) System stability (%) 10 89.5 0.15 99.95 25 87.2 0.22 99.92 40 84.8 0.31 99.88

[0095] As can be seen from Table 1, the method of the present invention exhibits excellent performance at different communication distances; at a communication distance of 10km, the system can achieve a photon detection efficiency of 89.5% and a quantum bit error rate of only 0.15%. Even in long-distance communication scenarios, the system can still maintain a high detection efficiency.

[0096] Table 2 shows the security performance indicators under different attack scenarios. As can be seen from the table, the method of the present invention has a strong defense capability against various quantum attacks. For the most common intercept and retransmission attack, the system can achieve a detection rate of 99.99% and a defense success rate of 99.98%, with a false alarm rate of only 0.01%. This is mainly due to the dual decoy state strategy and dynamic permutation mechanism adopted in the present invention, which effectively improves the security of the system.

[0097] Table 2 Security Performance Indicators under Different Attack Scenarios

[0098] Attack type Attack detection rate (%) False alarm rate (%) Defense success rate (%) Intercepting resentment attacks 99.99 0.01 99.98 Man-in-the-middle attack 99.98 0.02 99.97 Phase attack 99.95 0.03 99.95

[0099] Table 3 shows a performance comparison between the present invention and traditional authentication methods.

[0100] Table 3 Performance Comparison of the Invention and Traditional Authentication Methods

[0101] Authentication methods Authentication success rate (%) Authentication latency (ms) Method of the present invention 99.95 5.2 RSA digital signature 99.90 12.5 Multi-factor authentication 99.80 925.0

[0102] As can be seen from the table above, the method of this invention has significant advantages over traditional authentication schemes. In terms of authentication success rate, this invention is higher than all other comparative schemes; in terms of authentication latency, this invention only requires 5.2ms, which is 58.4% faster than the fastest RSA digital signature scheme, and is of great significance for building a future-oriented power grid security system.

[0103] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for secure authentication of power grid operators based on quantum communication, characterized in that: include: The power grid control center and power grid operators generate a Bell state sequence based on the binary key sequence and divide it to obtain the first sequence and the second sequence. Decoy particles are introduced into the first sequence to form an extended first sequence, which is then transmitted through a quantum channel. The security center performs decoy state detection, replacement operation, and introduces decoy state into the extended first sequence, generates a new first sequence, and transmits it. The power grid control center and power grid operators remove the decoy state from the new first sequence and restore it to the original first sequence. The second sequence was subjected to Pauli operation and Bell measurement to obtain the measurement results; Using classic communication channels to exchange measurement results and verify identity, a safe authentication system for power grid operators is achieved. The process of obtaining the first sequence and the second sequence includes: The power grid control center will use the Bell state sequence S A Divided into the first particle sequence S A1 and the first quantum bit sequence S A2 The specific formula is as follows: S A1 ={|Ψ A1 >,|Ψ A3 >,...,|Ψ A(2n-1) >} S A2 ={|Ψ A2 >,|Ψ A4 >,...,|Ψ A(2n) >} Among them, S A1 For the first particle sequence; S A2 The first quantum bit sequence; Ψ Ai The Bell state is generated by the power grid control center using the i-th key in the binary key sequence; The grid operator will use the Bell state sequence S B Divided into the second particle sequence S B1 The second quantum bit sequence S B2 The specific formula is as follows: S B1 ={|Ψ B1 >,|Ψ B3 >,...,|Ψ B(2n-1) >} S B2 ={|Ψ B2 >,|Ψ B4 >,...,|Ψ B(2n) >} Among them, S B1 For the second particle sequence; S B2 For the second quantum bit sequence; Ψ Bi The Bell state is generated by the power grid control center using the i-th key in the binary key sequence; Introducing decoy particles into the first sequence to form an extended first sequence refers to the power grid control center and power grid operators respectively introducing decoy particles into the first particle sequence S. A1 Second particle sequence S B1 Decoy particles are introduced to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 ; The introduction of decoy particles forms an extended first particle sequence S. ' A1 and the extended second particle sequence S ' B1 This refers to randomly selecting the state of the decoy particles in the first particle sequence S. A1 Second particle sequence S B1 Decoy particles are inserted at random positions in the middle; The extended first sequence is subjected to decoy state detection, permutation operation, and introduction of decoy states to generate a new first sequence, including the following steps: The security center receives the extended first particle sequence S ' A1 and the extended second particle sequence S ' B1 The decoy's state is then detected. If everything is correct, the first particle sequence S is extracted. A1 Second particle sequence S B1 ; For the extracted first particle sequence S A1 Second particle sequence S B1 Perform a substitution operation and reintroduce the decoy state to generate a new first particle sequence. and the new second particle sequence Removing the decoy state from the new first sequence and restoring it to the original first sequence refers to the power grid control center and power grid operators receiving the new first particle sequence. and the new second particle sequence The decoy state is removed, restoring the first particle sequence S. A1 Second particle sequence S B1 ; The Pauli operation and Bell measurement include the following steps: Grid control centers and grid operators utilize the first quantum bit sequence S A2 The second quantum bit sequence S B2 Pauli operations are performed based on the pre-shared key to obtain the resulting qubits; Bell measurement was performed on the manipulated qubit to obtain the measurement results; The method of exchanging measurement results and verifying identity using classic communication channels includes the following steps: The power grid control center and the power grid operator exchange their measurement results through the classic communication channel. By comparing the correlation of the measurement results, the identities of both parties are verified. If the results show an association pattern consistent with the expected pre-shared key, the authentication is successful. If the result is not as expected, it indicates interference or fraudulent attempts, and authentication has failed.

2. The quantum communication-based power grid operator security authentication method as described in claim 1, characterized in that: The generation of the Bell state sequence refers to the power grid control center and the power grid operator generating the Bell state sequence S respectively based on the shared binary key sequence. A and Bell state sequence S B .

3. The power grid operator security authentication method based on quantum communication as described in claim 2, characterized in that: The generated Bell state sequence S A and Bell state sequence S B include: If k m =00 and k m =01, then the Bell state sequence S A The calculation formula is as follows: S A =|Φ + > S A ={|Ψ A1 >,|Ψ A2 >,|Ψ A3 >,...,|Ψ A2n >} Where, k m Let S be the m-th key value in the binary key sequence, where m = 1, 2, ..., 2n, and 2n is the total number of elements in the key sequence; A A Bell state sequence; Ψ Ai The Bell state is generated by the power grid control center using the i-th key in the binary key sequence; If k m =01 and k m =10, then the Bell state sequence S B The calculation formula is as follows: S B =|Φ - S B ={|Ψ B1 >,|Ψ B2 >,|Ψ B3 >,...,|Ψ B2n >} Where, k m Let S be the m-th key value in the binary key sequence, where m = 1, 2, ..., 2n, and 2n is the total number of elements in the key sequence; B A Bell state sequence; Ψ Bi The Bell state is generated by the power grid control center using the i-th key in the binary key sequence.

4. A power grid operator safety authentication system based on quantum communication, based on the power grid operator safety authentication method based on quantum communication as described in any one of claims 1 to 3, characterized in that: include, The sequence generation module is used by the power grid control center and power grid operators to generate Bell state sequences based on binary key sequences and divide them to obtain the first particle sequence, the first quantum bit sequence, the second particle sequence, and the second quantum bit sequence. The decoy introduction module is used to introduce decoy particles into the first particle sequence and the second particle sequence to form an extended first particle sequence and an extended second particle sequence. The security center module is used to receive the extended first particle sequence and the extended second particle sequence through the security center, and to perform decoy state detection, replacement operation and introduce decoy state, generate a new first particle sequence and a new second particle sequence and send them to the power grid control center and power grid operator; The decoy restoration module is used by the power grid control center and power grid operators to remove the decoy state from the new first particle sequence and the new second particle sequence, restoring them to the first particle sequence and the second particle sequence. The measurement results module is used by the power grid control center and power grid operators to perform Pauli operations and Bell measurements using the first and second qubit sequences and a pre-shared key to obtain measurement results. The security authentication module is used by the power grid control center and power grid operators to exchange measurement results using classic communication channels and verify the identities of both parties.

5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the quantum communication-based power grid operator security authentication method according to any one of claims 1 to 3.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the quantum communication-based power grid operator security authentication method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Quantum dialogue protocol with collective-dephasing noise resisting authentication based on logic Bell states

    CN104468117A

  • Disordered high capacity multiparty quantum key agreement method based on high energy level bell state

    CN108809644A