Power grid data secure transmission system and method based on quantum cryptography, and medium

Through the power grid data security transmission system based on quantum cryptography, the dynamic allocation of quantum keys and dual-factor authentication methods are adopted to solve the problem of insufficient security in the power grid data transmission process, and the confidentiality, integrity and availability of data transmission are improved.

CN120389855AActive Publication Date: 2025-07-29GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Patent Information

Application Number
CN202510521117.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-07-29
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

The existing power grid data security transmission management system lacks effective encryption and monitoring mechanisms during data transmission, resulting in an increase in the risk of data loss and leakage, and is unable to effectively respond to complex and diverse security threats, affecting the stable operation of the power grid and the safety of user power use.

Method used

The power grid data security transmission system based on quantum cryptography is adopted, and through the collaborative mechanism of the power grid data access module, quantum key allocation module, communication security management module and power grid security communication module, the dynamic allocation, dual-factor authentication and quantum encryption transmission are realized to ensure the confidentiality, integrity and availability of data transmission.

Benefits of technology

It realizes security protection for the entire process of power grid data transmission, improves the security and reliability of power grid data communication, and meets the high requirements for data security of smart grids.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389855A_ABST
    Figure CN120389855A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric power communication security, in particular to a power grid data secure transmission system and method based on quantum cryptography and a medium, comprising: a power grid data access module extracts identities of a power grid data request end and a target response end; the quantum key distribution module obtains an original shared key pre-stored by the two communication parties, and generates a quantum key according to the one-time session password and the original shared key; the communication security management module analyzes the shared key information from the quantum key received by the target response end to obtain analyzed shared key information, and performs communication security verification on the original shared key and the analyzed shared key information; and the power grid security communication module encrypts the to-be-transmitted power grid data when the communication security verification result is that the verification is passed, and transmits the power grid encrypted data to the target response end. Through cooperation mechanisms such as quantum key dynamic distribution and security verification, security protection of power grid data transmission is realized, and power grid data communication security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of power communication security technology, and in particular to a power grid data security transmission system, method and medium based on quantum cryptography. Background Art

[0002] With the continuous development of smart grid technology, the application of intelligent communication and information processing technology in power energy systems is becoming increasingly extensive, covering multiple links of power systems such as power generation, transmission, distribution and users. The popularization of intelligent metering equipment has brought about the generation of massive power data. This data is of great significance for energy planning, energy production and distribution optimization, etc. However, the rapid expansion of data scale and the increase in interaction complexity have also brought new information security challenges. In particular, the security risks in the data transmission process are becoming increasingly prominent. It is urgent to introduce more advanced communication security technologies to ensure the security of smart grid data throughout its life cycle.

[0003] However, although the existing power grid data security transmission management system can identify and restrict abnormal data access to a certain extent, reducing the frequency of unauthorized access incidents, there are still many problems. The existing power grid data security transmission management system mainly focuses on monitoring and restricting abnormal access to power grid data, but ignores the security of the data transmission process after data access is passed. During the data transmission process, due to the lack of effective encryption and monitoring mechanisms, the risk of data loss and leakage increases significantly, which not only leads to the leakage of sensitive information, but also poses a threat to the stable operation of the power grid and the safety of users' electricity use. Therefore, improving the security control level of the data transmission process and ensuring the confidentiality, integrity and availability of power grid data during transmission have become key issues that need to be urgently addressed in the current power grid data security field.

[0004] In summary, the existing power grid data security transmission management system still has significant shortcomings and is difficult to effectively respond to increasingly complex and diverse security threats. Therefore, a more secure and reliable data security transmission technology is urgently needed to solve these problems and ensure the security and integrity of data transmission in smart grids. Summary of the Invention

[0005] To solve the above technical problems, the present invention provides a system, method and medium for secure transmission of power grid data based on quantum cryptography.

[0006] In a first aspect, the present invention provides a power grid data security transmission system based on quantum cryptography, comprising:

[0007] The power grid data access module is used to determine the data transmission mode of the target response end according to the power grid data access application uploaded by the power grid data request end, and extract the identity of the power grid data request end and the identity of the target response end according to the data transmission mode;

[0008] A quantum key distribution module, which is used to obtain the originally shared keys pre-stored by both communication parties according to the identity identifier of the power grid data request end and the identity identifier of the target response end received, generate a one-time session password by using a quantum random number generator, generate a quantum key according to the one-time session password and the originally shared key, and distribute the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol;

[0009] A communication security management module, which is used to parse the shared key information from the quantum key received from the target response end to obtain the parsed shared key information, and perform matching verification on the originally shared key and the parsed shared key information to generate a communication security verification result;

[0010] A power grid secure communication module, which is used to encrypt the power grid data to be transmitted by using the one-time session password when the communication security verification result is verified, generate power grid encrypted data, and transmit the power grid encrypted data to the target response end.

[0011] In a further embodiment, the quantum key distribution module includes a shared key request unit, a shared key control unit, a session key generation unit, a quantum key generation unit, and a quantum key distribution unit;

[0012] The shared key request unit is used to receive the identity identifier of the power grid data request end and the identity identifier of the target response end sent by the power grid data access module, generate a shared key request according to the identity identifier of the power grid data request end and the identity identifier of the target response end, and send the shared key request to the shared key control unit;

[0013] The shared key control unit is used to, in response to the shared key request, retrieve the originally shared keys pre-stored by the power grid data request end and the target response end from the database, and feedback the originally shared key to the quantum key generation unit;

[0014] The session key generation unit is used to generate a one-time session password by using a quantum random number generator;

[0015] The quantum key generation unit is used to perform an exclusive OR operation on the originally shared key and the one-time session password, and append the identity identifier of the power grid data request end to generate a quantum key;

[0016] The quantum key distribution unit is used to distribute the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol.

[0017] In a further embodiment, the communication security management module includes a quantum key extraction unit, a shared key matching unit, and a verification decision unit;

[0018] The quantum key extraction unit is used to parse the shared key information from the quantum key received from the target responder to obtain the parsed shared key information;

[0019] The shared key matching unit is used to compare the original shared key with the parsed shared key information to obtain a matching verification result;

[0020] The verification decision unit is used to verify the identities of both communication parties according to the matching verification result, and when the original shared key is verified to be consistent with the parsed shared key information, it determines that the identity verification of both communication parties passes and allows the power grid data requester to communicate with the target responder; when the original shared key is verified to be inconsistent with the parsed shared key information, it determines that the identity verification of both communication parties fails and rejects the power grid data requester to communicate with the target responder.

[0021] In a further embodiment, the communication security management module further includes a quantum transmission acquisition unit and a quantum encryption transmission unit;

[0022] The quantum transmission acquisition unit is used to collect the quantum key generation statistical times, identity verification statistical times, and quantum encryption transmission channel information in the current communication environment during a preset statistical period when the identity verification of both communication parties passes;

[0023] The quantum encryption transmission unit is used to calculate the quantum communication performance index according to the quantum key generation statistical times, identity verification statistical times, and quantum encryption transmission channel information in the current communication environment; wherein, the quantum communication performance index includes a key distribution success rate coefficient, a communication verification accuracy coefficient, a quantum channel performance coefficient, and a quantum encryption transmission stability coefficient.

[0024] In a further embodiment, the communication security management module further includes a power grid communication security assessment module;

[0025] The power grid communication security assessment module is used to calculate the power grid data communication security index according to the quantum communication performance index, and compare the power grid data communication security index with a preset power grid data communication security value. If the power grid data communication security index meets the preset power grid data communication security value, it determines that the current power grid data communication is secure and generates a communication security verification result.

[0026] In a further embodiment, the calculation process of the power grid data communication security index is as follows:

[0027] Take the square root of the quantum channel performance coefficient and then perform an exponential operation to obtain a quantum channel quality correction factor;

[0028] Calculate the sum of squares of the success rate coefficient of key distribution, the accuracy coefficient of communication verification, and the stability coefficient of quantum encryption transmission to obtain a comprehensive performance index;

[0029] Multiply the comprehensive performance index by the quantum channel quality correction factor to obtain the power grid data communication security index.

[0030] In a further embodiment, the success rate coefficient of key distribution is the ratio of the number of successfully generated quantum keys to the number of attempted generated quantum keys during the quantum encryption transmission process within a preset statistical period;

[0031] The accuracy coefficient of communication verification is the proportion of the number of correctly verified identities to the sum of the number of correctly verified identities and the number of incorrectly verified identities;

[0032] The quantum channel performance coefficient is the ratio of the channel capacity to the product of the natural logarithm of the quantum bit error rate and the natural logarithm of the signal transmission path loss.

[0033] In a further embodiment, the calculation process of the stability coefficient of quantum encryption transmission is as follows:

[0034] Within a preset statistical period, sum up the ratios of the amount of original data before all successful quantum encryption transmissions to the corresponding transmission time to obtain the total original transmission efficiency, and calculate the transmission efficiency factor based on the total original transmission efficiency and the number of quantum encryption transmissions within the preset statistical period;

[0035] Sum up the ratios of the amount of data after all successful quantum encryption transmissions to the amount of original data to obtain the total data integrity, and calculate the data integrity factor based on the total data integrity and the number of successful quantum encryption transmissions within the preset statistical period;

[0036] Sum up the ratios of the amount of recovered data to the duration required for recovering quantum encryption transmission for all quantum encryption transmissions that encounter failures to obtain the total failure recovery efficiency, and calculate the failure recovery efficiency factor based on the total failure recovery efficiency and the number of quantum encryption transmissions that encounter failures within the preset statistical period;

[0037] Multiply the transmission efficiency factor, the data integrity factor, and the failure recovery efficiency factor to obtain the stability coefficient of quantum encryption transmission.

[0038] In a second aspect, the present invention provides a power grid data secure transmission method based on quantum cryptography, and the method includes the following steps:

[0039] Determine the data transmission method of the target responder according to the power grid data access application uploaded by the power grid data requester, and extract the identity identifier of the power grid data requester and the identity identifier of the target responder according to the data transmission method;

[0040] Obtain the original shared key pre-stored by both communication parties according to the identity identifier of the power grid data requester and the identity identifier of the target responder, and generate a one-time session password by using a quantum random number generator;

[0041] Generate a quantum key according to the one-time session password and the original shared key, and distribute the quantum key to the power grid data requester and the target responder through a quantum key distribution protocol;

[0042] Parse the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and match and verify the original shared key with the parsed shared key information to generate a communication security verification result;

[0043] When the communication security verification result is verified to pass, encrypt the power grid data to be transmitted by using the one-time session password to generate encrypted power grid data, and transmit the encrypted power grid data to the target responder.

[0044] In a third aspect, the present invention further provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0045] The present invention provides a power grid data secure transmission system, method and medium based on quantum cryptography. The system includes a power grid data access module for determining the data transmission mode of a target responder according to a power grid data access application uploaded by a power grid data requestor, and extracting the identity identifier of the power grid data requestor and the identity identifier of the target responder according to the data transmission mode; a quantum key distribution module for obtaining the original shared keys pre-stored by both communication parties according to the received identity identifier of the power grid data requestor and the identity identifier of the target responder, generating a one-time session password by using a quantum random number generator, generating a quantum key according to the one-time session password and the original shared key, and distributing the quantum key to the power grid data requestor and the target responder through a quantum key distribution protocol; a communication security management module for parsing the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and performing matching verification on the original shared key and the parsed shared key information to generate a communication security verification result; and a power grid secure communication module for encrypting the power grid data to be transmitted by using the one-time session password when the communication security verification result is passed, generating encrypted power grid data, and transmitting the encrypted power grid data to the target responder. Compared with the prior art, through the collaborative mechanism of dynamic quantum key distribution, dual identity authentication and quantum encrypted transmission, the system realizes the security protection of the entire process of power grid data transmission, ensures the confidentiality, integrity and availability of power grid data during the transmission process, greatly improves the power grid data communication security level, and meets the high requirements of smart grids for data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 is a block diagram of a power grid data secure transmission system based on quantum cryptography provided by an embodiment of the present invention;

[0047] Figure 2 is a schematic flow chart of a power grid data secure transmission method based on quantum cryptography provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] The embodiments of the present invention will be specifically described below in conjunction with the accompanying drawings. The presentation of the embodiments is only for the purpose of illustration and should not be construed as a limitation of the present invention. The accompanying drawings are for reference and illustration only and do not constitute a limitation on the scope of patent protection of the present invention, because many changes can be made to the present invention without departing from the spirit and scope of the present invention.

[0049] Referring to Figure 1 , an embodiment of the present invention provides a power grid data secure transmission system based on quantum cryptography. As Figure 1 shown, the power grid data secure transmission system includes a power grid data access module 101, a quantum key distribution module 102, a communication security management module 103 and a power grid secure communication module 104 connected in sequence.

[0050] In some embodiments, the power grid data access module 101 is configured to determine the data transmission mode of the target responder according to the power grid data access application uploaded by the power grid data request end, and extract the identity identifier of the power grid data request end and the identity identifier of the target responder according to the data transmission mode.

[0051] Specifically, the power grid data access module receives the power grid data access application submitted by the power grid data request end. The power grid data access application includes at least the request end account ID and the identification information of the target power grid data to be accessed. This request end account ID serves as the unique identity identifier of the request end for subsequent identity authentication and traceability. After receiving the power grid data access application, the power grid data access module 101 retrieves in the preset power grid data transmission permission database according to the identification information of the target power grid data to be accessed, and obtains the target power grid data responder account ID with the transmission permission of the target power grid data to be accessed and the target responder data transmission mode corresponding to the target power grid data.

[0052] The power grid data access module judges the obtained target responder data transmission mode. If it is determined that the target responder data transmission mode is quantum encryption transmission, considering the extremely high requirements of quantum encryption transmission for data security, in this embodiment, a secure communication channel needs to be established for the request end and the responder. At this time, the power grid data access module will transmit the account IDs of the power grid data request end and the target responder to the quantum key distribution module, so that the quantum key distribution module can generate quantum keys for the request end and the responder according to these two account IDs and start the quantum encryption transmission process, thereby ensuring the security of subsequent data transmission. On the contrary, if it is determined that the target responder data transmission mode is other transmission types that are not quantum encryption transmission, such as traditional symmetric encryption transmission or plaintext transmission, etc., considering that these transmission modes have relatively low requirements for security and do not require the intervention of the quantum key distribution module, the power grid data access module will not transmit data to the quantum key distribution module, but continue to process the subsequent data access requests according to the corresponding non-quantum encryption transmission process. In summary, when quantum encryption transmission is required, the power grid data access module can extract the identity identifier of the power grid data request end and the identity identifier of the target responder according to the data transmission mode to ensure the security and accuracy of data transmission.

[0053] In some embodiments, the quantum key distribution module 102 is configured to obtain the pre-stored original shared keys of both communication parties according to the received identity identifier of the power grid data request end and the identity identifier of the target response end, generate a one-time session password by using a quantum random number generator, generate a quantum key based on the one-time session password and the original shared key, and distribute the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol. In this embodiment, the quantum key distribution module includes a shared key request unit, a shared key control unit, a session key generation unit, a quantum key generation unit, and a quantum key distribution unit. The specific function descriptions are as follows:

[0054] The shared key request unit is configured to receive the identity identifier of the power grid data request end and the identity identifier of the target response end sent by the power grid data access module, generate a shared key request according to the identity identifier of the power grid data request end and the identity identifier of the target response end, and send the shared key request to the shared key control unit;

[0055] The shared key control unit is configured to, in response to the shared key request, retrieve the pre-stored original shared keys of the power grid data request end and the target response end from the database, and feedback the original shared keys to the quantum key generation unit;

[0056] The session key generation unit is configured to generate a one-time session password by using a quantum random number generator;

[0057] The quantum key generation unit is configured to perform an exclusive OR operation on the original shared key and the one-time session password, and append the identity identifier of the power grid data request end to generate a quantum key;

[0058] The quantum key distribution unit is configured to distribute the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol.

[0059] Specifically, after receiving the grid data request - side account ID and the target response - side account ID transmitted by the grid data access module, the quantum key distribution module 102 immediately initiates an interaction process with the shared key control module. The shared key request unit sends shared key request information to the shared key control module according to the grid data request - side identity identifier and the target response - side identity identifier, and obtains the pre - stored original shared keys of the grid data request - side and the target response - side corresponding to the received account IDs. After receiving this request, the shared key control module quickly retrieves and matches according to the pre - established mapping relationship database between the account ID and the shared key, obtains the shared keys of the grid data request - side and the target response - side, and returns them to the quantum key generation unit. At the same time, the session key generation unit starts the quantum random number generator. Based on the principles of quantum mechanics, the quantum random number generator generates truly random numbers, and uses these random numbers to generate a one - time session password. This one - time session password has a high degree of randomness and unpredictability, providing a key security factor for the subsequent generation of quantum keys.

[0060] Then, the quantum key generation unit performs an exclusive - OR operation on the obtained shared key and the generated one - time session password, extracts the account ID of the grid data request - side therefrom, and attaches it to the end of the processed key. This step not only enhances the uniqueness and traceability of the key, but also facilitates identity authentication and key management in the subsequent data transmission process. After the above - mentioned processing, a quantum key is finally generated. Finally, the quantum key distribution unit distributes the generated quantum key to the grid data request - side and the target response - side through a quantum key distribution protocol (such as the BB84 protocol). The quantum key distribution protocol ensures the security, integrity, and confidentiality of the quantum key during the transmission process, preventing the key from being stolen or tampered with during transmission, providing a solid guarantee for the secure transmission of grid data.

[0061] In some embodiments, the communication security management module 103 is used to parse the shared key information from the quantum key received from the target response - side, obtain the parsed shared key information, and perform a matching verification on the original shared key and the parsed shared key information to generate a communication security verification result.

[0062] In some embodiments, the communication security management module includes a quantum key extraction unit, a shared key matching unit, and a verification decision unit;

[0063] The quantum key extraction unit is used to parse the shared key information from the quantum key received from the target response - side to obtain the parsed shared key information;

[0064] The shared key matching unit is used to compare the original shared key with the parsed shared key information to obtain a matching verification result;

[0065] The verification decision-making unit is used to verify the identities of both communication parties based on the matching verification result, and when the original shared key is verified to be consistent with the parsed shared key information, it determines that the identity verification of both communication parties is passed, and allows the grid data request end to communicate with the target response end; when the original shared key is verified to be inconsistent with the parsed shared key information, it determines that the identity verification of both communication parties fails, and rejects the communication between the grid data request end and the target response end.

[0066] Specifically, the quantum key extraction unit in the communication security management module extracts key information from the quantum key returned by the target response end received, specifically including: the account ID of the grid data request end (used to identify the unique identity of the requestor), the parsed shared key information, and the session key (the key used to establish a temporary communication session). Then, after successfully extracting the account ID of the grid data request end, the shared key matching unit compares and checks the original shared key information fed back by the shared key control module with the shared key information extracted from the quantum key bit by bit to ensure that each bit of the shared key information is exactly the same, thereby verifying the validity of the shared key between both parties. When the shared key information is verified to be consistent, the verification decision-making unit determines that the identity verification of both communication parties is successful. At this time, communication is allowed, and the extracted session key is sent to the grid data target response end through a secure channel so that both parties can establish a secure temporary communication session based on this session key. On the contrary, if the shared key information is verified to be inconsistent, the verification decision-making unit determines that the identity verification of both communication parties fails. At this time, communication is rejected, and measures such as recording abnormal logs and triggering alarms are taken to prevent potential security threats, so as to effectively verify the identity of the grid data target response end and ensure that only legitimate requestors can establish a secure communication session with the target response end.

[0067] In some embodiments, the communication security management module further includes a quantum transmission acquisition unit and a quantum encryption transmission unit, and the specific function descriptions are as follows:

[0068] The quantum transmission acquisition unit is used to collect the quantum key generation statistical times, identity verification statistical times, and the quantum encryption transmission channel information in the current communication environment during the preset statistical period when the identity verification of both communication parties is passed.

[0069] The quantum encryption transmission unit is used to calculate the quantum communication performance indicators according to the quantum key generation statistical times, identity verification statistical times, and the quantum encryption transmission channel information in the current communication environment; wherein, the quantum communication performance indicators include the key distribution success rate coefficient, the communication verification accuracy coefficient, the quantum channel performance coefficient, and the quantum encryption transmission stability coefficient.

[0070] Specifically, when the identity authentication of both communication parties is passed, the quantum transmission acquisition unit collects the statistical number of quantum key generations, the statistical number of identity authentications, and the quantum encryption transmission channel information in the current communication environment within a preset statistical period. Among them, the statistical number of quantum key generations includes the number of attempts to generate quantum keys and the number of successful generations of quantum keys in the quantum encryption transmission process within the preset statistical period. The statistical number of identity authentications includes the number of correct identity authentications and the number of incorrect identity authentications between the two communication parties. The quantum encryption transmission channel information in the current communication environment includes quantum channel data and quantum encryption transmission information in the current communication environment. The quantum channel data includes the quantum bit error rate coefficient, the signal transmission path loss, and the channel capacity. The quantum encryption transmission information includes the number of quantum encryption transmissions, the number of successful quantum encryption transmissions, the data volume before the i-th quantum encryption transmission, the transmission time, the data volume after the quantum encryption transmission ends, the number of quantum encryption transmissions that encounter network failures or device failures, the duration required to resume quantum encryption transmission each time a network failure or device failure is encountered, and the amount of restored data. It should be noted that the quantum bit error rate coefficient, the signal transmission path loss, and the channel capacity can be directly obtained by existing technologies, and the specific acquisition methods are not elaborated in this embodiment.

[0071] Then, the quantum encryption transmission unit calculates the key distribution success rate coefficient based on the number of attempts to generate quantum keys and the number of successful generations of quantum keys, calculates the communication verification accuracy coefficient based on the number of correct identity authentications and the number of incorrect identity authentications between the two communication parties, calculates the quantum channel performance coefficient based on the quantum channel data, and calculates the quantum encryption transmission stability coefficient based on the quantum encryption transmission information. Specifically, in this embodiment, the key distribution success rate coefficient is calculated according to the ratio of the number of successful generations of quantum keys to the number of attempts to generate quantum keys in the quantum encryption transmission process within the preset statistical period. The specific calculation formula for the key distribution success rate coefficient is:

[0072]

[0073] In the formula, βcf is the key distribution success rate coefficient; Nac is the number of successfully generated quantum keys within the preset statistical period; Naz is the number of attempts to generate quantum keys within the preset statistical period.

[0074] At the same time, in this embodiment, the communication verification accuracy coefficient is calculated according to the proportion of the number of correct identity authentications to the sum of the number of correct identity authentications and the number of incorrect identity authentications. The specific calculation formula for the communication verification accuracy coefficient is:

[0075]

[0076] Wherein, βyz is the communication verification accuracy coefficient; Nbz is the number of times of correct identity verification within a preset statistical period; Nbc is the number of times of incorrect identity verification within a preset statistical period.

[0077] In this embodiment, the quantum channel performance coefficient is calculated according to the ratio of the channel capacity to the product of the natural logarithm of the quantum bit error rate and the natural logarithm of the signal transmission path loss. The specific calculation formula of the quantum channel performance coefficient is:

[0078]

[0079] Wherein, Xdm is the quantum channel performance coefficient; Rm is the channel capacity; αm is the latest quantum bit error rate coefficient within a preset statistical period; e is the natural constant; Pm is the signal transmission path loss; ln(*) is the natural logarithm.

[0080] Meanwhile, in this embodiment, the calculation process of the quantum encryption transmission stability coefficient is as follows:

[0081] Within a preset statistical period, the ratios of the original data volume before all successful quantum encryption transmissions to the corresponding transmission times are accumulated and summed to obtain the total original transmission efficiency. Then, based on the total original transmission efficiency and the number of quantum encryption transmissions within the preset statistical period, the transmission efficiency factor is calculated;

[0082] The ratios of the data volume after all successful quantum encryption transmissions to the original data volume are accumulated and summed to obtain the total data integrity. Then, based on the total data integrity and the number of successful quantum encryption transmissions within the preset statistical period, the data integrity factor is calculated;

[0083] The ratios of the recovered data volume to the duration required for recovering quantum encryption transmissions in all quantum encryption transmissions that encounter failures are accumulated and summed to obtain the total failure recovery efficiency. Then, based on the total failure recovery efficiency and the number of quantum encryption transmissions that encounter failures within the preset statistical period, the failure recovery efficiency factor is calculated;

[0084] Multiply the transmission efficiency factor, the data integrity factor, and the failure recovery efficiency factor to obtain the quantum encryption transmission stability coefficient. The specific calculation formula of the quantum encryption transmission stability coefficient is:

[0085]

[0086] In the formula, βsw is the quantum encryption transmission stability coefficient; Ncg is the number of successful quantum encryption transmissions; Mai is the amount of original data before the i-th successful quantum encryption transmission; Tci is the transmission time corresponding to the amount of original data before the successful quantum encryption transmission; Ncz is the number of quantum encryption transmissions within a preset statistical period; Mbi is the amount of data after the i-th successful quantum encryption transmission; Ny is the number of quantum encryption transmissions that encounter network failures or equipment failures; Mhi is the amount of recovered data during the quantum encryption transmission when the i-th network failure or equipment failure occurs; Thi is the time required to resume the quantum encryption transmission when the i-th network failure or equipment failure occurs.

[0087] Based on the above embodiments, in some embodiments, the communication security management module further includes a power grid communication security evaluation module, which is used to calculate the power grid data communication security index according to the quantum communication performance indicators, and compare the power grid data communication security index with a preset power grid data communication security value. If the power grid data communication security index meets the preset power grid data communication security value, it is determined that the current power grid data communication is secure, and a communication security verification result is generated.

[0088] Specifically, the power grid communication security evaluation module receives the key distribution success rate coefficient, communication verification accuracy coefficient, quantum channel performance coefficient, and quantum encryption transmission stability coefficient calculated by the quantum encryption transmission unit within a preset statistical period. These coefficients are the basic data for evaluating the power grid communication security, and calculate the power grid data communication security index according to the received above coefficients. In this embodiment, the calculation process of the power grid data communication security index is as follows:

[0089] Take the square root of the quantum channel performance coefficient and then perform an exponential operation to obtain a quantum channel quality correction factor;

[0090] Calculate the sum of squares of the key distribution success rate coefficient, the communication verification accuracy coefficient, and the quantum encryption transmission stability coefficient to obtain a comprehensive performance index;

[0091] Multiply the comprehensive performance index by the quantum channel quality correction factor to obtain the power grid data communication security index. The specific calculation formula of the power grid data communication security index is:

[0092]

[0093] In the formula, Yz is the power grid data communication security index; exp(*) is an exponential function with the natural constant e as the base.

[0094] After calculating the power grid data communication security index, in this embodiment, the power grid data communication security index is compared with a preset power grid data communication security value. If the calculated power grid data communication security index is greater than or equal to the power grid data communication security value, it is determined that the power grid data communication security meets the expectation, and the current power grid data communication is secure; otherwise, it is determined that the power grid data communication security does not meet the expectation, and the current power grid data communication is insecure. According to the comparison result, the power grid communication security assessment module generates a communication security verification result and outputs a corresponding instruction to the power grid security management center based on the generated communication security verification result. If the power grid data communication security meets the expectation, an instruction indicating that the power grid data communication security meets the expectation is output; if the power grid data communication security does not meet the expectation, an instruction indicating that the power grid data communication security does not meet the expectation and needs to be maintained and optimized is output to take timely measures to ensure the power grid communication security. In addition, the database in this embodiment is used to store the data information of all modules in the system, including the identity information of power grid platform users and power grid platform management personnel, for subsequent security auditing and management. It should be noted that all preset values (such as the power grid data communication security value, etc.) in this embodiment are selected based on actual needs, and the specific values are not elaborated here.

[0095] Based on the above embodiment, in some embodiments, the power grid security communication module 104 is used to encrypt the power grid data to be transmitted using a one-time session password when the communication security verification result is verified passed, generate encrypted power grid data, and transmit the encrypted power grid data to the target response end.

[0096] Specifically, after the communication security management module completes the verification of the identity and key consistency of both communication parties and generates a communication security verification result that passes the verification, the key utilization unit of the power grid security communication module 104 will receive and extract the one-time session password contained in and confirmed to be valid after security verification in the verification result. Then, this embodiment will call this one-time session password as the encryption key and use a pre-selected encryption algorithm (such as the AES algorithm, etc.) to perform bit-by-bit encryption processing on the power grid data to be transmitted, converting the power grid data to be transmitted into the encrypted power grid data ciphertext. Then, the encrypted power grid data is encapsulated into a standard data packet format in ciphertext form and securely transmitted to the target response end by the data transmission unit through a pre-established and security-certified classical channel (such as an optical fiber communication network, a dedicated power line carrier communication channel, etc.). During the transmission process, the power grid security communication module 104 will adopt a data integrity verification mechanism (such as CRC verification, HMAC verification, etc.) to ensure that the data packet has not been damaged or tampered with during the transmission process.

[0097] When the target responder receives the grid encrypted data, the internal secure communication module will perform the opposite operations: First, it uses the same one-time session password as the sender (or the decryption key dynamically generated based on the shared key) to call the corresponding decryption algorithm to decrypt the grid encrypted data, restoring the original plaintext grid data. Then, it verifies the correctness of the decryption result by validating the data integrity check code, and submits the decrypted plaintext grid data to the subsequent service processing module for further processing. Through the above steps, the grid secure communication module can ensure that, on the premise that the communication security verification passes, the one-time session password is used to encrypt and transmit the grid data to be transmitted efficiently and securely, thus effectively guaranteeing the confidentiality, integrity, and availability of the grid data during the transmission process.

[0098] In this embodiment, after receiving the account IDs of the grid data requester and the target responder, the shared key of the two communication parties is obtained. Then, a one-time session password is generated using a quantum random number generator, and the processing is performed in combination with the shared key and the session password. During the processing, the account ID of the grid data requester is appended to the end of the key to generate a quantum key. This process securely sends the generated quantum key to the grid data requester and the target responder through the quantum key distribution protocol. This module introduces a one-time password mechanism to ensure that each key is used only once, and the characteristics of the quantum key distribution protocol make the distribution process of the session key immune to replay and eavesdropping attacks, thus strongly guaranteeing the secure transmission of the grid data. In addition, this embodiment also strictly verifies the authentication information assigned to the grid data target responder. Only when the verification is successful is the communication allowed to continue; if the verification fails, the communication is immediately rejected to prevent illegal access. After the communication is completed, the shared key control module of this embodiment updates the shared key using a one-time session password. This dynamic update mechanism avoids the risk of man-in-the-middle attacks to a certain extent and further improves the security of the communication.

[0099] Meanwhile, this embodiment encrypts the grid data to be transmitted using a one-time session password, and securely transmits the encrypted grid data ciphertext to the grid data requester through a classical channel. The target responder decrypts the grid data ciphertext using the received quantum key to restore the plaintext grid data. Since quantum encryption technology is adopted, the security of the session key does not depend on computational complexity, so it can resist attacks from quantum computers and significantly enhance the security of grid data communication.

[0100] An embodiment of the present invention provides a power grid data secure transmission system based on quantum cryptography. The system includes a power grid data access module for determining the data transmission mode of the target responder according to the power grid data access application uploaded by the power grid data requester, and extracting the identity identifier of the power grid data requester and the identity identifier of the target responder according to the data transmission mode; a quantum key distribution module for obtaining the original shared keys pre-stored by both communication parties according to the received identity identifier of the power grid data requester and the identity identifier of the target responder, generating a one-time session password by using a quantum random number generator, generating a quantum key according to the one-time session password and the original shared key, and distributing the quantum key to the power grid data requester and the target responder through a quantum key distribution protocol; a communication security management module for parsing the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and performing a matching verification on the original shared key and the parsed shared key information to generate a communication security verification result; a power grid secure communication module for encrypting the power grid data to be transmitted by using the one-time session password when the communication security verification result is verified, generating encrypted power grid data, and transmitting the encrypted power grid data to the target responder. Compared with the prior art, the system realizes the security protection of the entire process of power grid data transmission through the collaborative mechanism of quantum key dynamic distribution, dual identity authentication, and quantum encryption transmission, ensures the confidentiality, integrity, and availability of power grid data during the transmission process, improves the security and reliability of power grid data communication, and meets the high requirements of smart grids for data security.

[0101] In one embodiment, as Figure 2 shown, an embodiment of the present invention provides a power grid data secure transmission method based on quantum cryptography. The method includes the following steps:

[0102] S1. Determine the data transmission mode of the target responder according to the power grid data access application uploaded by the power grid data requester, and extract the identity identifier of the power grid data requester and the identity identifier of the target responder according to the data transmission mode;

[0103] S2. Obtain the original shared keys pre-stored by both communication parties according to the identity identifier of the power grid data requester and the identity identifier of the target responder, and generate a one-time session password by using a quantum random number generator;

[0104] S3. Generate a quantum key according to the one-time session password and the original shared key, and distribute the quantum key to the power grid data requester and the target responder through a quantum key distribution protocol;

[0105] S4. Parse the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and perform a matching verification on the original shared key and the parsed shared key information to generate a communication security verification result;

[0106] S5. When the communication security verification result is verified to be passed, use the one-time session password to encrypt the power grid data to be transmitted, generate encrypted power grid data, and transmit the encrypted power grid data to the target responder.

[0107] It should be noted that the magnitudes of the serial numbers of the above processes do not mean the sequence of execution. The execution sequence of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0108] For the specific limitations on a power grid data secure transmission method based on quantum cryptography, reference can be made to the above limitations on a power grid data secure transmission system based on quantum cryptography, which will not be elaborated here. Those of ordinary skill in the art can realize that, combining the various modules and steps described in the embodiments disclosed in the present application, they can be implemented in hardware, software, or a combination of both. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0109] The embodiment of the present invention provides a power grid data secure transmission method based on quantum cryptography. The method includes determining the data transmission mode of the target responder according to the power grid data access application uploaded by the power grid data requester, and extracting the identity identifier of the power grid data requester and the identity identifier of the target responder according to the data transmission mode; obtaining the original shared keys pre-stored by both communication parties according to the identity identifier of the power grid data requester and the identity identifier of the target responder, and generating a one-time session password by using a quantum random number generator; generating a quantum key according to the one-time session password and the original shared key, and distributing the quantum key to the power grid data requester and the target responder through a quantum key distribution protocol; parsing the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and matching and verifying the original shared key with the parsed shared key information to generate a communication security verification result; when the communication security verification result is verified to be passed, using the one-time session password to encrypt the power grid data to be transmitted, generating encrypted power grid data, and transmitting the encrypted power grid data to the target responder. Compared with the prior art, through the collaborative mechanism of dynamic quantum key distribution, dual identity verification, and quantum encrypted transmission, this method realizes the security protection of the entire process of power grid data transmission, ensures the confidentiality, integrity, and availability of power grid data during the transmission process, improves the security and reliability of power grid data communication, and meets the high requirements of smart grids for data security.

[0110] In one embodiment, the embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented.

[0111] In the above embodiment, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as an SSD), etc.

[0112] Those skilled in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods.

[0113] The above embodiments only represent several preferred implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and substitutions can be made, and these improvements and substitutions should also be regarded as the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the protection scope of the claims.

Claims

1. A power grid data secure transmission system based on quantum cryptography, characterized in that, Including: A power grid data access module, configured to determine the data transmission mode of the target responder according to the power grid data access application uploaded by the power grid data requestor, and extract the identity identifier of the power grid data requestor and the identity identifier of the target responder according to the data transmission mode; A quantum key distribution module, configured to obtain the pre-stored original shared keys of both communication parties according to the received identity identifier of the power grid data requestor and the identity identifier of the target responder, generate a one-time session password by using a quantum random number generator, generate a quantum key according to the one-time session password and the original shared key, and distribute the quantum key to the power grid data requestor and the target responder through a quantum key distribution protocol; A communication security management module, configured to parse out the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and perform matching verification on the original shared key and the parsed shared key information to generate a communication security verification result; A power grid secure communication module, configured to encrypt the power grid data to be transmitted by using the one-time session password to generate power grid encrypted data when the communication security verification result is verified, and transmit the power grid encrypted data to the target responder.

2. The power grid data security transmission system based on quantum cryptography according to claim 1, wherein: The quantum key distribution module includes a shared key request unit, a shared key control unit, a session key generation unit, a quantum key generation unit, and a quantum key distribution unit; The shared key request unit is configured to receive the identity identifier of the power grid data requestor and the identity identifier of the target responder sent by the power grid data access module, generate a shared key request according to the identity identifier of the power grid data requestor and the identity identifier of the target responder, and send the shared key request to the shared key control unit; The shared key control unit is configured to, in response to the shared key request, retrieve the pre-stored original shared keys of the power grid data requestor and the target responder from the database, and feed back the original shared key to the quantum key generation unit; The session key generation unit is configured to generate a one-time session password by using a quantum random number generator; The quantum key generation unit is configured to perform an exclusive OR operation on the original shared key and the one-time session password, and append the identity identifier of the power grid data requestor to generate a quantum key; The quantum key distribution unit is configured to distribute the quantum key to the power grid data requestor and the target responder through a quantum key distribution protocol.

3. A power grid data security transmission system based on quantum cryptography according to claim 1, characterized in that: The communication security management module includes a quantum key extraction unit, a shared key matching unit, and a verification decision unit; The quantum key extraction unit is configured to parse out the shared key information from the quantum key received from the target responder to obtain the parsed shared key information; The shared key matching unit is configured to compare the original shared key with the parsed shared key information to obtain a matching verification result; The verification decision-making unit is used to verify the identities of both communication parties based on the matching verification result, and when the original shared key is verified to be consistent with the parsed shared key information, it determines that the identity verification of both communication parties is passed, and allows the grid data request end to communicate with the target response end; when the original shared key is verified to be inconsistent with the parsed shared key information, it determines that the identity verification of both communication parties fails, and rejects the communication between the grid data request end and the target response end.

4. The secure power grid data transmission system based on quantum cryptography according to claim 3, wherein: The communication security management module further includes a quantum transmission acquisition unit and a quantum encryption transmission unit; The quantum transmission acquisition unit is used to collect the statistical number of quantum key generations, the statistical number of identity verifications, and the quantum encryption transmission channel information in the current communication environment during the quantum encryption transmission process within a preset statistical period when the identity verification of both communication parties is passed. The quantum encryption transmission unit is used to calculate the quantum communication performance index based on the statistical number of quantum key generations, the statistical number of identity verifications, and the quantum encryption transmission channel information in the current communication environment; wherein, the quantum communication performance index includes a key distribution success rate coefficient, a communication verification accuracy coefficient, a quantum channel performance coefficient, and a quantum encryption transmission stability coefficient.

5. The secure power grid data transmission system based on quantum cryptography as claimed in claim 4, characterized in that: The communication security management module further includes a grid communication security evaluation module; The grid communication security evaluation module is used to calculate the grid data communication security index based on the quantum communication performance index, and compare the grid data communication security index with a preset grid data communication security value. If the grid data communication security index meets the preset grid data communication security value, it determines that the current grid data communication is secure and generates a communication security verification result.

6. The secure power grid data transmission system based on quantum cryptography according to claim 5, characterized in that, The calculation process of the grid data communication security index is as follows: Take the square root of the quantum channel performance coefficient and then perform an exponential operation to obtain a quantum channel quality correction factor; Calculate the sum of the squares of the key distribution success rate coefficient, the communication verification accuracy coefficient, and the quantum encryption transmission stability coefficient to obtain a comprehensive performance index; Multiply the comprehensive performance index by the quantum channel quality correction factor to obtain the grid data communication security index.

7. The power grid data security transmission system based on quantum cryptography according to claim 5, characterized in that: The key distribution success rate coefficient is the ratio of the number of successful quantum key generations to the number of attempted quantum key generations during the quantum encryption transmission process within a preset statistical period; The communication verification accuracy coefficient is the ratio of the number of correctly verified identities to the sum of the number of correctly verified identities and the number of incorrectly verified identities; The quantum channel performance coefficient is the ratio of the channel capacity to the product of the natural logarithm of the quantum bit error rate and the natural logarithm of the signal transmission path loss.

8. A power grid data secure transmission system based on quantum cryptography according to claim 5, characterized in that, The calculation process of the quantum encryption transmission stability coefficient is as follows: Accumulate the ratios of the amount of original data before successful quantum encryption transmission to the corresponding transmission time within a preset statistical period to obtain the total original transmission efficiency, and calculate the transmission efficiency factor based on the total original transmission efficiency and the number of quantum encryption transmissions within the preset statistical period. Accumulate and sum up the ratios of the data volume successfully transmitted by all quantum encryptions to the original data volume to obtain the total data integrity, and calculate the data integrity factor based on the total data integrity and the number of successful quantum encryption transmissions within the preset statistical period; Accumulate and sum up the ratios of the recovered data volume to the duration required for recovering the quantum encryption transmission in all quantum encryption transmissions that encounter failures to obtain the total failure recovery efficiency, and calculate the failure recovery efficiency factor based on the total failure recovery efficiency and the number of quantum encryption transmissions that encounter failures within the preset statistical period; Multiply the transmission efficiency factor, the data integrity factor, and the failure recovery efficiency factor to obtain the quantum encryption transmission stability coefficient.

9. A method for secure transmission of power grid data based on quantum cryptography, characterized in that, The method includes the following steps: Determine the data transmission method of the target responder according to the power grid data access application uploaded by the power grid data requester, and extract the identity identifier of the power grid data requester and the identity identifier of the target responder according to the data transmission method; Obtain the pre-stored original shared key of both communication parties according to the identity identifier of the power grid data requester and the identity identifier of the target responder, and generate a one-time session password using a quantum random number generator; Generate a quantum key based on the one-time session password and the original shared key, and distribute the quantum key to the power grid data requester and the target responder through a quantum key distribution protocol; Parse the shared key information from the quantum key received from the target responder to obtain the parsed shared key information, and match and verify the original shared key with the parsed shared key information to generate a communication security verification result; When the communication security verification result is verified to pass, encrypt the power grid data to be transmitted using the one-time session password to generate encrypted power grid data, and transmit the encrypted power grid data to the target responder.

10. A computer-readable storage medium, characterized in that: A computer program is stored in the computer-readable storage medium, and when the computer program is run, the method described in claim 9 is implemented.

Citation Information

Patent Citations

  • Method and device for realizing safety communication between terminal devices

    CN101005359A

  • Bidirectional authentication method and system based on shared key, and terminal

    CN110958209A

  • Data protection method fusing quantum key in TLS

    CN119834967A

  • Authentication and key negotiation method, gateway, sensor and electronic equipment

    WO2023115667A1

  • Chinese national cryptographic algorithm-based identity authentication and data encryption method for coap

    WO2025000590A1

Cited By

  • Substation dispatching data network security communication method based on quantum tunnel encryption

    CN120811596A

  • Electric energy meter data transmission method and device, electric energy meter and storage medium

    CN121000527A

  • Electric energy meter data transmission method and device, electric energy meter and storage medium

    CN121000527B