Quantum secure power trusted WLAN communication system, method, device and storage medium
By introducing quantum random number chips and media into trusted WLAN communication systems, combined with quantum identification servers and key service platforms, the problem of insufficient security of random number strength and key negotiation in power services is solved, and dynamic service adaptation and high-security quantum secure power trusted WLAN communication is realized.
Patent Information
- Application Number
- CN202510604044.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-08-15
AI Technical Summary
The existing trusted WLAN communication systems have insufficient random number strength, poor key negotiation security in power services, and lack dynamic adaptability to different business scenarios, making it difficult to meet the high security needs of the power system.
The quantum random number chip and quantum security medium are used, combined with the quantum identification server and key service platform, to realize quantum random number generation, key storage and distribution, identity authentication and key management are carried out through quantum digital certificates and challenge response mechanisms, and security strategies are dynamically adjusted to adapt to the characteristics of power business.
It significantly improves the randomness of random numbers, the security of encrypted communications and the unpredictability of keys, enhances the system's anti-attack capabilities and service adaptability, and ensures high security and flexibility of power services.
Smart Images

Figure CN120499653A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of quantum secure power communication and trusted WLAN wireless communication, and in particular relates to a quantum secure power trusted WLAN communication system, method, device and storage medium. Background Art
[0002] With the rapid development of digital and intelligent technologies, the power industry has increasingly stringent requirements for data communication security. Power services involve multiple processes, including power generation, transmission, distribution, and consumption. Real-time, reliable, and confidential data transmission is crucial. Currently, wireless local area network (WLAN) technology is widely used in power systems, providing a flexible and efficient communication method for services such as remote monitoring, smart meters, and equipment status monitoring. However, the unique nature of the power industry places far greater demands on communication security than in other industries, particularly in areas such as protecting critical infrastructure, preventing eavesdropping, and preventing tampering.
[0003] Currently, trusted WLAN communication systems primarily rely on traditional public-private key cryptography to ensure data transmission security. In this system, communicating parties authenticate each other using an asymmetric encryption algorithm (such as RSA or ECC) and negotiate a session key based on the Diffie-Hellman key exchange protocol. The session key is then used to encrypt the communication data using a symmetric encryption algorithm (such as AES) to ensure confidentiality and integrity during transmission.
[0004] Although traditional encryption technologies can meet the security needs of power services to a certain extent, they still have the following limitations: First, random number generation relies on the trusted WLAN itself, which lacks randomness strength, making the key easy to predict or crack. Second, during the session key negotiation process, attackers may steal or tamper with key information through man-in-the-middle attacks or replay attacks. Finally, existing encryption mechanisms lack the ability to dynamically adapt to the characteristics of power services and cannot adjust security policies according to different business scenarios (such as real-time control and batch data transmission), making it difficult to cope with diverse security threats. Ultimately, the existing trusted WLAN communication system has poor random number strength, key negotiation security, and dynamic business adaptation capabilities. Summary of the Invention
[0005] Purpose of the invention: The purpose of the present invention is to provide a quantum-secure power trusted WLAN communication system that can improve random number strength, key agreement security, and dynamic service adaptation capabilities; on the other hand, to provide a quantum-secure power trusted WLAN communication method.
[0006] Technical solution: The communication system of the present invention includes:
[0007] The quantum wireless terminal QSTA is used to carry power services to access the quantum trusted WLAN communication system, dynamically adapting to the security requirements of different business scenarios and enhancing the reliability and anti-attack capabilities of communications;
[0008] The quantum wireless access point (QAP) provides wireless communication access services for QSTAs and connects to the quantum key service platform and the service master station via a wired channel, ensuring end-to-end data transmission security and service adaptation flexibility. Both the QSTA and QAP have built-in quantum random number chips and quantum security media. The quantum random number chip is used to generate quantum random numbers in real time, and the quantum security media is used to store the pre-set quantum keys from the quantum key service platform. It can generate high-strength quantum random numbers in real time for encryption and securely store pre-set quantum keys, significantly improving the random number strength and key security of power service access.
[0009] The quantum authentication server QAS is connected to the quantum random number generator through the Ethernet port to realize the certificate management and authentication of QSTA and QAP, effectively resisting forgery and man-in-the-middle attacks, and ensuring the identity credibility and session security of both communicating parties;
[0010] The quantum random number generator provides QAS with quantum random numbers for quantum digital certificate signature verification, fundamentally improving the security of the quantum digital certificate signature and verification process, avoiding algorithm vulnerabilities that may be caused by traditional pseudo-random numbers, and providing a solid randomness foundation for the cryptographic operations of the entire system;
[0011] The quantum key service platform provides QSTA and QAP with pre-installed quantum key injection and online key distribution services, enabling remote secure management and efficient key distribution, ensuring the key freshness and anti-cracking capabilities for long-term communications, and meeting the high security requirements of the power business.
[0012] Preferably, both the QSTA and QAP have built-in quantum random number chips and quantum security media, realizing a dual security enhancement mechanism. The quantum random number chip is used to generate quantum random numbers in real time, fundamentally ensuring the unpredictability of the key generation process and effectively resisting attacks based on pseudo-random number vulnerabilities. The quantum security media is used to store the quantum keys preset from the quantum key service platform. Through physical isolation storage, it not only provides a high-security key storage solution, but also establishes a trusted initial key foundation for subsequent quantum key distribution and dynamic updates, thereby constructing a full-process quantum security protection system from key generation, storage to distribution.
[0013] Preferably, both the QSTA and QAP implement identity authentication through quantum digital certificates, and the signature in the quantum digital certificate is generated by quantum random numbers. The true quantum random numbers introduced in the certificate signing process fundamentally eliminate the periodicity or predictability problems that may exist in traditional pseudo-random numbers, making the digital signature unique and non-replicable. Secondly, the certificate signing mechanism based on quantum random numbers effectively resists reverse engineering attacks and replay attacks on pseudo-random number algorithms, establishing a trusted identity authentication foundation for subsequent secure communications.
[0014] Preferably, the functions of the quantum random number generator and quantum key service platform are integrated into the QAS, forming a hardware device that integrates quantum random number generation, key distribution and identity authentication. Through hardware-level integration, the system deployment structure is optimized, and the communication overhead between multiple devices is reduced. At the same time, through the localization of quantum random number generation and key distribution, the overall security and operational efficiency of the system are enhanced, providing a more integrated quantum security protection foundation for power WLAN communication.
[0015] The communication method of the present invention comprises the following steps:
[0016] During the device initialization phase, the quantum wireless terminal QSTA and the quantum wireless access point QAP each use a built-in quantum random number chip to generate a key pair and obtain a quantum digital certificate containing quantum random number characteristics through the quantum authentication server QAS. This ensures that the initial identities and keys of QSTA and QAP are unpredictable and resistant to cracking, laying a trusted foundation for subsequent secure communications while avoiding security risks that may be introduced by traditional pseudo-random numbers.
[0017] During the identity authentication phase, QSTA and QAP complete bidirectional authentication by exchanging quantum digital certificates and quantum random number challenges. After the QAS verifies the validity of the certificate, a trusted connection is established, effectively preventing identity forgery and man-in-the-middle attacks, ensuring a trusted connection between the communicating parties. At the same time, quantum random numbers are used to enhance the security of the challenge-response process and improve the authentication strength.
[0018] During the first unicast quantum key distribution phase, the QAP uses the quantum key pre-installed in the quantum secure medium to complete key relay transmission through the quantum key service platform and establish an encrypted communication channel with the QSTA to ensure the security and efficiency of the initial key distribution and prevent the key from being stolen or tampered during transmission.
[0019] During the multicast quantum key distribution phase, the QAP applies for a multicast key from the quantum key service platform. Each QSTA obtains and decrypts the multicast key through an encrypted communication channel to establish secure group communication. This not only ensures the confidentiality and integrity of the multicast key, but also improves the key management efficiency of group communication, meeting the security requirements of multi-device collaboration in the power business while reducing the computational and communication overhead of key distribution.
[0020] During the unicast quantum key update phase, QSTA and QAP negotiate a new key based on the current session key and dynamically adjust the key update frequency according to the characteristics of the power business to ensure the forward security of long-term communication. At the same time, they optimize the key update strategy to adapt to the security requirements of different businesses and enhance the system's flexibility and anti-attack capabilities.
[0021] Preferably, the device initialization stage includes:
[0022] QAP uses its built-in quantum random number chip to generate quantum random numbers as key seeds for the elliptic curve encryption algorithm, generates public and private key pairs, and generates a certificate signing request file containing the public key and applicant information;
[0023] After receiving the certificate signing request file, the QAS uses the quantum random number generated by the external quantum random number generator to generate a signature pair, signs the certificate signing request file, generates a quantum digital certificate containing the quantum random number, and returns it to the QAP;
[0024] QSTA uses its built-in quantum random number chip to generate quantum random numbers as the key seed of the elliptic curve encryption algorithm, generates public and private key pairs and generates the corresponding certificate signing request file;
[0025] After receiving the certificate signing request file from QSTA, QAS uses the quantum random number generated by the external quantum random number generator to generate a signature pair, signs the certificate signing request file from QSTA, generates a quantum digital certificate containing the quantum random number, and returns it to QSTA.
[0026] The built-in quantum random number chips in QAP and QSTA generate high-entropy quantum random numbers as the key seeds for the elliptic curve encryption algorithm, ensuring the unpredictability of public and private key pairs and their resistance to quantum computing attacks. At the same time, QAS uses true random numbers generated by an external quantum random number generator to sign certificate signature requests, so that the final quantum digital certificate has quantum random number characteristics, fundamentally eliminating the risk of certificate forgery that may be caused by traditional pseudo-random numbers. This solution uses quantum random number enhancement in both key generation and certificate issuance, achieving dual security reinforcement of device identity and keys, and establishing a highly reliable cryptographic foundation for subsequent quantum secure communications.
[0027] Preferably, the identity authentication stage includes:
[0028] The QAP sends an authentication activation message to the QSTA, which contains the QAP's quantum digital certificate information and the first quantum random number challenge;
[0029] The QSTA responds to the authentication activation message and returns an access authentication request message to the QAP. The message includes the key index Index_A corresponding to the quantum key Key_A injected into the QSTA quantum secure medium, the QSTA's quantum digital certificate, the second quantum random number challenge, and the QSTA's digital signature.
[0030] The QAP sends the received QSTA quantum digital certificate together with its own quantum digital certificate, the first quantum random number challenge, and the second quantum random number challenge to the QAS for certificate verification;
[0031] After the QAS verifies the quantum digital certificates of both parties, it returns a certificate authentication response message to the QAP. The message contains the certificate verification results of both parties, the first quantum random number challenge, the second quantum random number challenge, and the digital signature of the QAS.
[0032] The QAP sends an access authentication response message to the QSTA based on the certificate authentication response message. The message contains the certificate verification result of the QAS. The QAP chooses to reject or accept the QSTA's access based on the certificate authentication result. After receiving the access authentication response, the QSTA knows whether the QAP is trustworthy based on the authentication result, and thus determines whether to access this QAP.
[0033] Through the two-way exchange of quantum digital certificates and the dual quantum random number challenge mechanism, combined with the centralized certificate verification of QAS, a high-strength two-way identity authentication system is constructed. During the authentication process, QAP and QSTA not only exchange quantum digital certificates with quantum random number characteristics, but also achieve real-time session verification through dynamically generated quantum random number challenges (first and second challenges), effectively resisting replay attacks and man-in-the-middle attacks. At the same time, with the help of QAS's centralized verification of the certificates of both parties, the legitimacy of the device identity and the credibility of the communication link are ensured. This mechanism further strengthens the integrity and non-repudiation of the authentication process through the injection of quantum key indexes and digital signatures in the quantum secure medium, ultimately realizing trusted access control based on quantum security enhancement, and establishing a solid trust foundation for subsequent key negotiation.
[0034] Preferably, the first unicast quantum key distribution stage includes:
[0035] The QAP uses the pre-loaded quantum key in its quantum secure medium to complete the authentication and registration with the quantum key service platform;
[0036] QAP selects the quantum key Key_B injected into the quantum secure medium as the relay protection key, and sends the key index Index_B and the key index Index_A provided by QSTA to the quantum key service platform;
[0037] The quantum key service platform parses and obtains the keys Key_A and Key_B corresponding to Index_A and Index_B, calculates the XOR value of the two (Key_B⊕Key_A) and returns it to the QAP;
[0038] QAP obtains the key Key_A through XOR operation, calculates its hash value HASH_A and sends it to QSTA for verification;
[0039] QSTA compares the received HASH_A with the locally calculated Key_A hash value. After verification, it establishes an encrypted data channel based on Key_A. If the verification fails, it restarts the identity authentication process.
[0040] Secure key relay is achieved through the pre-installed quantum keys (Key_A and Key_B) in the quantum secure medium. The quantum key service platform only transmits the key component that has been XOR-encrypted (Key_B⊕Key_A) to ensure the confidentiality of the key during transmission; QAP locally restores Key_A and verifies the hash value with QSTA, which not only avoids the risk of plaintext key transmission but also ensures the integrity and correctness of key distribution; this mechanism utilizes the non-replicable nature of the pre-installed quantum key, combined with the dual protection of XOR encryption and hash verification, to quickly establish a highly secure encrypted data channel without the need for online negotiation. At the same time, the mechanism that automatically triggers re-authentication in the event of verification failure further improves the system's fault tolerance and security.
[0041] Preferably, the QAP uses the pre-set quantum key in its quantum secure medium to complete the authentication registration with the quantum key service platform, including:
[0042] The QAP sends an authentication registration request containing the unique ID of the secure medium to the subkey service platform;
[0043] After verifying the legitimacy of the secure medium ID, the quantum key service platform selects the 16-byte quantum key preset in the secure medium as the authentication key Key_X and generates a quantum random number challenge code;
[0044] After obtaining the authentication key Key_X, the QAP uses the HMAC algorithm to calculate the quantum random number challenge code to generate a first message authentication code;
[0045] The quantum key service platform uses the same authentication key Key_X to perform an HMAC operation on the quantum random number challenge code to generate a second message authentication code;
[0046] The authentication registration of the secure medium is completed by comparing the consistency of the first message authentication code and the second message authentication code.
[0047] Through the two-factor authentication mechanism of the unique ID of the quantum secure medium and the pre-set injected quantum key Key_X, combined with the dynamic verification of the quantum random number challenge code, high-strength identity authentication is achieved between the QAP and the quantum key service platform; this scheme uses the non-replicable injected quantum key as the authentication basis of the HMAC algorithm, and ensures the legitimate identity of the communicating parties by comparing the quantum random number challenge code message authentication code (first and second MAC) generated at both ends. It not only prevents the access of counterfeit devices, but also ensures the unpredictability of the challenge response through quantum random numbers, thereby establishing a secure and reliable authentication channel for subsequent key distribution, effectively resisting replay attacks and man-in-the-middle attacks.
[0048] Preferably, the multicast quantum key distribution stage includes:
[0049] QSTA uses the quantum key injected into its quantum secure medium to complete the authentication and registration with the quantum key service platform;
[0050] The QAP initiates a group creation request to the quantum key service platform, obtains the group ID, the encrypted multicast quantum key, and the corresponding protection key index, and uses the charged quantum key corresponding to the protection key index to decrypt and obtain the multicast quantum key plaintext;
[0051] The QAP distributes the group ID to each QSTA through the established unicast quantum key encryption channel;
[0052] Each QSTA requests the quantum key service platform to obtain the encrypted multicast quantum key corresponding to the group ID through the unicast quantum key encryption channel. The quantum key service platform returns the multicast quantum key ciphertext and the corresponding protection key index to the QSTA. The QSTA uses its own quantum key to decrypt and obtain the multicast quantum key plaintext.
[0053] The secure distribution of multicast keys is achieved through a dual encryption mechanism (charged quantum key decryption + unicast quantum key encryption channel). The QAP first uses the preset charged quantum key to decrypt the multicast quantum key plaintext, and then distributes the group ID through the established unicast secure channel. After each QSTA obtains the encrypted multicast key through the unicast channel, it uses its own charged quantum key for secondary decryption. This not only ensures the end-to-end security of the multicast key during transmission, but also realizes efficient group key management through the centralized control of the quantum key service platform. Through the innovative "group ID index + double encryption" architecture, this solution not only ensures the security of multicast communication keys, but also significantly improves the key distribution efficiency of multi-device collaborative communication in the power WLAN system.
[0054] Preferably, the unicast quantum key update phase includes:
[0055] The QSTA uses the current unicast quantum key as the session ID to apply for a new unicast quantum key from the quantum key service platform, obtains the encrypted new unicast quantum key and the corresponding protection key index, and uses the injected quantum key corresponding to the protection key index to decrypt the new unicast quantum key plaintext.
[0056] QSTA calculates the hash value H_NewA of the new unicast quantum key plaintext and sends it to the quantum wireless access point QAP;
[0057] QAP obtains the new unicast quantum key plaintext in the same way as QSTA and calculates its hash value H_NewB;
[0058] The QAP compares H_NewB with the received H_NewA. If they are consistent, the key update is confirmed to be successful. If they are inconsistent, the QSTA is notified to re-initiate the key update process.
[0059] Through a dynamic update mechanism based on the current session key, combined with the secure distribution of the quantum key service platform and the decryption protection of the injected quantum key, the secure rotation of the unicast quantum key is achieved; the consistency and integrity of the key update are ensured by using two-way verification of hash values, which not only guarantees the forward security of the key update, but also improves the reliability of the update process through the automatic retry mechanism; this solution uses the triple protection of "session ID binding + quantum key protection + hash verification" to effectively prevent key leakage and man-in-the-middle attacks while meeting the dynamic security needs of the power business, significantly improving the confidentiality and anti-cracking capabilities of long-term communications.
[0060] Preferably, the unicast quantum key dynamically adjusts the update frequency according to the characteristics of different power services carried, and the dynamic adjustment is based on the following strategy:
[0061] QSTA identifies the service type of the message by regularly analyzing the characteristic values of the communication message. The service security level is positively correlated with the key update frequency.
[0062] QSTA monitors business communication traffic in real time and automatically increases the key update frequency when the business communication traffic exceeds the preset threshold.
[0063] By intelligently sensing the characteristics of power services (service type security level and communication traffic load), adaptive dynamic adjustment of key update frequency is achieved, optimizing system resource consumption while ensuring the protection strength of high-security service communications. This solution intelligently associates service security requirements with the key update mechanism, ensuring high-intensity protection for critical services through a positive correlation mechanism with security levels, and dynamically responding to sudden communication risks with the help of a traffic threshold trigger mechanism, achieving an optimal balance between security and communication efficiency, and significantly improving the security adaptability and operational performance of the power WLAN system for different service scenarios.
[0064] A computer device, characterized in that it includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute the quantum secure power trusted WLAN communication method.
[0065] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the quantum secure power trusted WLAN communication method is implemented.
[0066] Beneficial effects: Compared with the existing technology, the present invention has the following significant advantages: 1. Quantum random numbers are used to participate in the identity authentication of the trusted WLAN communication system. The randomness of quantum improves the randomness strength of random numbers; 2. Quantum keys are used and generated and securely distributed by a third-party quantum key service platform, which improves the security of encrypted communication; 3. The encryption mechanism of the trusted WLAN communication system is dynamically adjusted for power business, and the business adaptability is stronger. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 It is a structural schematic diagram of the present invention. DETAILED DESCRIPTION
[0068] The technical solution of the present invention will be further described below with reference to the accompanying drawings.
[0069] like Figure 1 As shown, the communication system of the present invention includes the following devices:
[0070] Quantum Wireless Terminal (QSTA): Used in the wireless service layer, it carries power services to access the quantum trusted WLAN communication system; it contains a quantum random number chip and quantum secure medium. The quantum random number chip is used to generate quantum random numbers in real time, and the quantum secure medium is used to store the injected quantum keys preset from the quantum key service platform.
[0071] Quantum Wireless Access Point (QAP): Used in the wireless access layer, it provides wireless communication access services for quantum terminals QSTA, and connects to the quantum key service platform and the business main station through a wired channel; it contains a quantum random number chip and quantum secure medium. The quantum random number chip is used to generate quantum random numbers in real time, and the quantum secure medium is used to store the injected quantum keys preset from the quantum key service platform.
[0072] Quantum Authentication Server (QAS): Used in the core control layer to implement certificate management and authentication of quantum terminals QSTA and quantum access points QAP, including certificate issuance, cancellation, freezing, binding, and other management, as well as responding to QAP's certificate verification requests and making responses; connected to the quantum random number generator through the Ethernet port, using quantum random numbers in the quantum digital certificate signature verification process.
[0073] Quantum random number generator: used in the core control layer to provide quantum random numbers for the quantum identification server QAS.
[0074] Quantum key service platform: used in the core control layer, providing pre-set quantum key injection and online quantum key distribution services for quantum terminals QSTA and quantum access points QAP.
[0075] The functions of the quantum random number generator and quantum key service platform are integrated into QAS, forming a hardware device that integrates quantum random number generation, key distribution and identity authentication.
[0076] A communication method corresponding to the communication system comprises the following steps:
[0077] Step 1: Device initialization based on quantum security enhancement:
[0078] (11) QAP uses the built-in quantum random number chip to generate quantum random numbers as the key seed of the elliptic curve encryption algorithm, generates a public-private key pair, and then generates a certificate signing request file P10 containing the public key and applicant information;
[0079] (12) The QAS receives the certificate signature request file from the QAP, generates a signature pair using the quantum random number generated by the external quantum random number generator, signs the certificate signature request file P10, obtains a quantum digital certificate containing the quantum random number, and returns the certificate to the corresponding QAP;
[0080] (13) QSTA uses the built-in quantum random number chip to generate quantum random numbers as the key seed of the elliptic curve encryption algorithm, generates a public-private key pair, and then generates a certificate signing request file P10 containing the public key and applicant information;
[0081] (14) QAS receives the certificate signature request file from QSTA, uses the quantum random number generated by the external quantum random number generator to generate a signature pair, signs the certificate signature request file P10, obtains the quantum digital certificate containing the quantum random number, and returns the certificate to the corresponding QSTA.
[0082] Step 2: Quantum-enhanced identity authentication:
[0083] (21) Authentication initiation: After the QSTA associates with the QAP through channel scanning, the QAP sends an authentication activation message to the QSTA. This message includes the QAP's quantum digital certificate information and quantum random number challenge 1 (32 bytes);
[0084] (22) Access Authentication Request: After receiving the authentication activation message from the QAP, the QSTA sends an access authentication request message to the QAP. This message includes the key index Index_A corresponding to the quantum key Key_A injected into the QSTA quantum secure medium, the quantum digital certificate information of the QSTA, the quantum random number challenge 2 (32 bytes), and the message signature of the QSTA.
[0085] (23) Certificate authentication request: After receiving the access authentication request from the QSTA, the QAP sends a certificate authentication request message to the QAS. This message includes the QAP's quantum digital certificate, the QSTA's quantum digital certificate, quantum random number challenge 1, and quantum random number challenge 2.
[0086] (24) Certificate authentication response: After receiving the certificate authentication request from the QAP, the QAS performs a quantum digital certificate authentication check, generates an authentication result, and sends a certificate authentication response message to the QAP; the authentication result includes the QAP quantum digital certificate and its authentication result, the QSTA quantum digital certificate and its authentication result, quantum random number challenge 1, quantum random number challenge 2, and the QAS signature on the first four items of information;
[0087] (25) Access Authentication Response: After receiving the quantum digital certificate authentication response message from the QAS, the QAP sends an access authentication response message to the QSTA. This message includes the certificate authentication result of the QAS. The QAP rejects or accepts the QSTA's access based on the certificate authentication result. After receiving the access authentication response, the QSTA determines whether the QAP is trustworthy based on the authentication result, and thus determines whether to access this QAP.
[0088] Step 3: First unicast quantum key distribution based on quantum security enhancement:
[0089] (31) QAP uses the quantum key in its own quantum secure medium to complete the authentication and registration with the quantum key service platform, which mainly includes:
[0090] The QAP sends an authentication registration request to the subkey service platform, including the unique ID of the secure medium it holds;
[0091] The quantum key service platform queries whether the secure medium ID is a secure medium that has been charged by the platform. If no charging record is found, the authentication registration failure is returned. If a charging record is found, the quantum key service platform selects the 16-byte charged quantum key in the secure medium as the authentication key Key_X, whose key index is Index_X. At the same time, it uses the quantum random number generator to generate a quantum random number challenge code R, and returns Index_X and Rand_X to the QAP.
[0092] The QAP queries the plaintext key corresponding to Index_X to obtain the authentication key Key_X, then uses Key_X to perform an HMAC operation on Rand_X to obtain the message authentication code MAC1 and send it to the quantum key service platform;
[0093] The quantum key service platform also uses Key_X to perform HMAC operation on Rand_X to obtain the message authentication code MAC2;
[0094] Compare MAC1 and MAC2. If they are consistent, the QAP's secure medium is successfully authenticated and registered with the quantum key service platform. If they are inconsistent, the QAP's secure medium is illegal and cannot communicate with the quantum key service platform.
[0095] (32) QAP selects the quantum key Key_B filled in its own quantum secure medium as the relay protection key. The key index value of Key_B is Index_B. QAP sends Index_B and Index_A transmitted by QSTA in step S2-2 to the quantum key service platform.
[0096] (33) The quantum key service platform parses the keys Key_A and Key_B corresponding to Index_A and Index_B respectively, and returns Key_B⊕Key_A to the QAP;
[0097] (34) QAP calculates Key_B⊕(Key_B⊕Key_A) and obtains Key_A. At the same time, it calculates the hash value HASH_A of Key_A and sends it to QSTA.
[0098] (35) QSTA compares the received hash value of HASH_A with its own Key_A to see if they are consistent. If the hash values are consistent, the first unicast quantum key relay is completed, and Key_A can be used to establish an encrypted data channel between QSTA and QAP; if the hash values are inconsistent, go to step S2-2 to restart authentication and key negotiation.
[0099] Step 4: Multicast quantum key distribution based on quantum security enhancement:
[0100] (41) QSTA uses the quantum key in its own quantum secure medium to complete the authentication and registration with the quantum key service platform. The steps are the same as those for the QAP to complete the authentication and registration with the quantum key service platform.
[0101] (42) The QAP creates a group and applies for a group key from the quantum key service platform. The quantum key service platform returns the group ID, the multicast quantum key ciphertext, and the corresponding protection key index to the QAP. The QAP uses the charged quantum key corresponding to the protection key index to decrypt and obtain the multicast quantum key plaintext.
[0102] (43) QAP uses a unicast quantum key encryption channel to notify each subordinate QSTA of the group ID;
[0103] (44) QSTA uses the unicast quantum key encryption channel to obtain the multicast quantum key corresponding to the group ID from the quantum key service platform. The quantum key service platform returns the multicast quantum key ciphertext and the corresponding protection key index to QSTA. QSTA uses the injection quantum key corresponding to the protection key index to decrypt and obtain the multicast quantum key plaintext.
[0104] Step 5: Unicast quantum key update based on quantum security enhancement:
[0105] (51) QSTA uses the current unicast quantum key as the session ID to apply for a new unicast quantum key from the quantum key service platform. The quantum key service platform returns the new unicast quantum key ciphertext and the corresponding protection key index to QSTA. QSTA uses the injection quantum key corresponding to the protection key index to decrypt and obtain the new unicast quantum key plaintext.
[0106] (52) QSTA calculates the new unicast quantum key HASH value H_NewA and notifies QAP;
[0107] (53) Similar to step (51), the QAP uses the current unicast quantum key as the session ID to apply for a new unicast quantum key from the quantum key service platform. The quantum key service platform returns the new unicast quantum key ciphertext and the corresponding protection key index to the QAP. The QAP uses the injection quantum key corresponding to the protection key index to decrypt and obtain the new unicast quantum key plaintext.
[0108] (54) QAP calculates the new unicast quantum key HASH value H_NewB and compares it with H_NewA. If they are consistent, it feedbacks that the QSTA unicast key update is successful; if they are inconsistent, it feedbacks that the QSTA unicast key update fails and goes to step (51) to restart the unicast key update;
[0109] The QSTA unicast quantum key dynamically adjusts the update frequency according to the characteristics of different power services carried, and the dynamic adjustment is based on the following strategies:
[0110] QSTA regularly analyzes communication messages, extracts message feature values, and determines the service type of the message. The higher the service level, the higher the frequency of unicast key update.
[0111] QSTA regularly checks the service communication traffic volume. The larger the traffic volume, the higher the frequency of unicast key update.
[0112] The invention also discloses an electronic device.
[0113] Specifically, the electronic device can be a computer device such as a desktop computer, a laptop computer, a PDA, and a cloud server. The computer device may include, but is not limited to, a processor and a memory. The processor and the memory may be connected via a bus or other means. The processor may be a central processing unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, graphics processing units (GPU), embedded neural network processors (NPU) or other dedicated deep learning coprocessors, discrete gate or transistor logic devices, discrete hardware components and other chips, or a combination of the above-mentioned chips.
[0114] As a non-transient computer-readable storage medium, the memory can be used to store non-transient software programs, non-transient computer executable programs and modules. The processor executes various functional applications and data processing of the processor by running the non-transient software programs, instructions and modules stored in the memory. The memory may include a program storage area and a data storage area, wherein the program storage area may store a control unit, an application required for at least one function; the data storage area may store data created by the processor, etc. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory. In some embodiments, the memory may optionally include a memory remotely located relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network and a combination thereof.
[0115] The invention also discloses a computer-readable storage medium.
[0116] Specifically, a computer-readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the method in the above-mentioned method implementation is implemented. Those skilled in the art will understand that the implementation of all or part of the process in the above-mentioned embodiment method of the present application can be completed by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it may include the process of the implementation of each of the above-mentioned methods. Among them, the storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk (Hard Disk Drive, abbreviated: HDD) or a solid-state drive (SSD), etc.; the storage medium may also include a combination of the above-mentioned types of memories.
Claims
1. A quantum secure power trusted WLAN communication system, characterized in that: include: The quantum wireless terminal QSTA is used to carry power services and access the quantum trusted WLAN communication system; Quantum wireless access point QAP, used to provide wireless communication access services for QSTA and connect the quantum key service platform and the business main station through a wired channel; The quantum authentication server QAS is connected to the quantum random number generator through the Ethernet port to realize the certificate management and authentication of QSTA and QAP; Quantum random number generator, which provides QAS with quantum random numbers for quantum digital certificate signature verification; The quantum key service platform provides pre-installed quantum keys and online key distribution services for QSTA and QAP.
2. The communication system according to claim 1, wherein: Both the QSTA and QAP have built-in quantum random number chips and quantum secure media. The quantum random number chip is used to generate quantum random numbers in real time, and the quantum secure media is used to store the charged quantum keys preset from the quantum key service platform.
3. The communication system according to claim 1, wherein: Both the QSTA and QAP implement identity authentication through quantum digital certificates, and the signatures in the quantum digital certificates are generated through quantum random numbers.
4. The communication system according to claim 1, wherein: The functions of the quantum random number generator and quantum key service platform are integrated into the QAS, forming a hardware device that integrates quantum random number generation, key distribution and identity authentication.
5. A quantum secure power trusted WLAN communication method, characterized in that: The following steps are involved: During the device initialization phase, the quantum wireless terminal QSTA and the quantum wireless access point QAP respectively use the built-in quantum random number chip to generate a key pair and obtain a quantum digital certificate containing quantum random number characteristics through the quantum authentication server QAS; During the identity authentication phase, QSTA and QAP complete bidirectional authentication by exchanging quantum digital certificates and quantum random number challenges. The QAS then verifies the validity of the quantum digital certificate and establishes a trusted connection. In the first unicast quantum key distribution phase, the QAP uses the quantum key pre-set in the quantum secure medium to complete key relay transmission through the quantum key service platform and establish an encrypted communication channel with the QSTA; During the multicast quantum key distribution phase, the QAP applies for the multicast key from the quantum key service platform. Each QSTA obtains and decrypts the multicast key through an encrypted communication channel to establish secure group communication. During the unicast quantum key update phase, QSTA and QAP negotiate a new key based on the current session key and dynamically adjust the key update frequency according to the characteristics of the power business. The communication method according to claim 5 , wherein: The device initialization phase includes: QAP uses its built-in quantum random number chip to generate quantum random numbers as key seeds for the elliptic curve encryption algorithm, generates public and private key pairs, and generates a certificate signing request file containing the public key and applicant information; After receiving the certificate signing request file, the QAS uses the quantum random number generated by the external quantum random number generator to generate a signature pair, signs the certificate signing request file, generates a quantum digital certificate containing the quantum random number, and returns it to the QAP; QSTA uses its built-in quantum random number chip to generate quantum random numbers as the key seed of the elliptic curve encryption algorithm, generates public and private key pairs and generates the corresponding certificate signing request file; After receiving the certificate signing request file from QSTA, QAS uses the quantum random number generated by the external quantum random number generator to generate a signature pair, signs the certificate signing request file from QSTA, generates a quantum digital certificate containing the quantum random number, and returns it to QSTA.
7. The communication method according to claim 5, wherein: The identity authentication stage includes: The QAP sends an authentication activation message to the QSTA, which contains the QAP's quantum digital certificate information and the first quantum random number challenge; The QSTA responds to the authentication activation message and returns an access authentication request message to the QAP. The message includes the key index Index_A corresponding to the quantum key Key_A injected into the QSTA quantum secure medium, the QSTA's quantum digital certificate, the second quantum random number challenge, and the QSTA's digital signature. The QAP sends the received QSTA quantum digital certificate together with its own quantum digital certificate, the first quantum random number challenge, and the second quantum random number challenge to the QAS for certificate verification; After the QAS verifies the quantum digital certificates of both parties, it returns a certificate authentication response message to the QAP. The message contains the certificate verification results of both parties, the first quantum random number challenge, the second quantum random number challenge, and the digital signature of the QAS. The QAP sends an access authentication response message to the QSTA based on the certificate authentication response message. The message contains the certificate verification result of the QAS. The QAP chooses to reject or accept the QSTA's access based on the certificate authentication result. After receiving the access authentication response, the QSTA knows whether the QAP is trustworthy based on the authentication result, and thus determines whether to access this QAP.
8. The communication method according to claim 5, wherein: The first unicast quantum key distribution phase includes: The QAP uses the pre-loaded quantum key in its quantum secure medium to complete the authentication and registration with the quantum key service platform; QAP selects the quantum key Key_B injected into the quantum secure medium as the relay protection key, and sends the key index Index_B and the key index Index_A provided by QSTA to the quantum key service platform; The quantum key service platform parses and obtains the keys Key_A and Key_B corresponding to Index_A and Index_B, calculates the XOR value of the two (Key_B⊕Key_A) and returns it to the QAP; QAP obtains the key Key_A through XOR operation, calculates its hash value HASH_A and sends it to QSTA for verification; QSTA compares the received HASH_A with the locally calculated Key_A hash value. After verification, it establishes an encrypted data channel based on Key_A. If the verification fails, it restarts the identity authentication process.
9. The communication method according to claim 8, wherein: The QAP uses the pre-set quantum key in its quantum secure medium to complete the authentication and registration with the quantum key service platform, including: The QAP sends an authentication registration request containing the unique ID of the secure medium to the subkey service platform; After verifying the legitimacy of the unique ID of the secure medium, the quantum key service platform selects the 16-byte quantum key preset in the secure medium as the authentication key Key_X and generates a quantum random number challenge code; After obtaining the authentication key Key_X, the QAP uses the HMAC algorithm to calculate the quantum random number challenge code to generate a first message authentication code; The quantum key service platform uses the same authentication key Key_X to perform an HMAC operation on the quantum random number challenge code to generate a second message authentication code; The authentication registration of the secure medium is completed by comparing the consistency of the first message authentication code and the second message authentication code.
10. The communication method according to claim 5, wherein: The multicast quantum key distribution stage includes: QSTA uses the quantum key injected into its quantum secure medium to complete the authentication and registration with the quantum key service platform; The QAP initiates a group creation request to the quantum key service platform, obtains the group ID, the encrypted multicast quantum key, and the corresponding protection key index, and uses the charged quantum key corresponding to the protection key index to decrypt and obtain the multicast quantum key plaintext; The QAP distributes the group ID to each QSTA through the established unicast quantum key encryption channel; Each QSTA requests the quantum key service platform to obtain the encrypted multicast quantum key corresponding to the group ID through the unicast quantum key encryption channel. The quantum key service platform returns the multicast quantum key ciphertext and the corresponding protection key index to the QSTA. The QSTA uses its own quantum key to decrypt and obtain the multicast quantum key plaintext.
11. The communication method according to claim 5, wherein: The unicast quantum key update phase includes: The QSTA uses the current unicast quantum key as the session ID to apply for a new unicast quantum key from the quantum key service platform, obtains the encrypted new unicast quantum key and the corresponding protection key index, and uses the injected quantum key corresponding to the protection key index to decrypt the new unicast quantum key plaintext. QSTA calculates the hash value H_NewA of the new unicast quantum key plaintext and sends it to the quantum wireless access point QAP; QAP obtains the new unicast quantum key plaintext in the same way as QSTA and calculates its hash value H_NewB; The QAP compares H_NewB with the received H_NewA. If they are consistent, the key update is confirmed to be successful. If they are inconsistent, the QSTA is notified to re-initiate the key update process.
12. The communication method according to claim 11, wherein: The unicast quantum key dynamically adjusts the update frequency according to the characteristics of different power services carried, and the dynamic adjustment is based on the following strategies: QSTA identifies the service type of the message by regularly analyzing the characteristic values of the communication message. The service security level is positively correlated with the key update frequency. QSTA monitors business communication traffic in real time and automatically increases the key update frequency when the business communication traffic exceeds the preset threshold.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the quantum secure power trusted WLAN communication method according to any one of claims 4 to 12 is implemented.
14. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, wherein: When the processor executes the program, the quantum secure power trusted WLAN communication method according to any one of claims 4 to 12 is implemented.
Citation Information
Cited By
Electric energy meter data transmission method and device, electric energy meter and storage medium
CN121000527A