Substation dispatching data network security communication method based on quantum tunnel encryption

By deploying quantum-secure communication terminals in the substation dispatch data network and using quantum tunneling encryption technology to provide end-to-end protection for remote control protocol data, the problem of separating security mechanisms from business applications is solved. This achieves resistance to quantum computing and deployment flexibility, and supports a smooth transition between old and new systems.

CN120811596AActive Publication Date: 2025-10-17INNER MONGOLIA HUIQIANG TECH CO LTD

Patent Information

Application Number
CN202511104210.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-10-17
Estimated Expiration
2045-08-07

AI Technical Summary

Technical Problem

In the existing security protection system of substation dispatch data network, the security mechanism is separated from business applications, resulting in a lack of endpoint security, inability to resist quantum computing threats, and reliance on dedicated fiber optic networks, which limits deployment flexibility and economy.

Method used

Using a method based on quantum tunnel encryption, quantum secure communication terminals are deployed at the dispatching master station and substation. Through quantum key distribution and post-quantum cryptography technology, the telecontrol protocol data is encapsulated, encrypted and digitally signed at the application layer to build an end-to-end secure communication system that is compatible with multiple network media.

Benefits of technology

It achieves end-to-end security protection, resists quantum computing attacks, enhances networking flexibility, reduces deployment costs, and supports a smooth transition and seamless integration of new and old systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811596A_ABST
    Figure CN120811596A_ABST
Patent Text Reader

Abstract

The invention discloses a substation dispatching data network security communication method based on quantum tunnel encryption, relates to the technical field of large-scale power grid security assurance, and aims to solve the problems of endpoint security loss, boundary solidification, weak quantum threat resistance and inflexible deployment of a dispatching data network. According to the method, the establishment of a secure session and the encapsulation, encryption and restoration of data are realized by integrating quantum key distribution and a post quantum cryptographic operation module through quantum secure communication terminals deployed in a dispatching master station and a transformer substation. According to the method, application layer encryption and signature are carried out on telecontrol protocol data, a double-layer encryption tunnel is constructed, and transmission of various physical network media is supported. By means of the scheme, end-to-end protection is achieved, quantum attacks are effectively resisted, double encryption is provided, and networking flexibility and smooth evolution are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of large-scale power grid security, in particular to a substation dispatching data network security communication method based on quantum tunnel encryption. BACKGROUND

[0002] As a core component of national critical information infrastructure, the safe and stable operation of the power grid system is directly related to the national economy and people's livelihood and social order. Among them, the substation dispatching data network undertakes the function of connecting the dispatching master station and the subordinate substations, is responsible for the real-time collection of massive telemetry and remote signaling data, and the accurate issuance of remote control and remote adjustment instructions, and is the lifeline of ensuring the accurate perception, reliable control and efficient decision-making of the entire power grid. Therefore, ensuring the confidentiality, integrity and availability of information interaction in this data network has always been the core issue in the field of power system automation and information security technology.

[0003] For a long period of history, in order to cope with the increasingly complex network security threats, the power industry generally follows the overall protection strategy of "security zoning, network specialization, horizontal isolation, and vertical authentication". Under the guidance of this strategy, the mainstream technical practice is to deploy power-specific vertical encryption authentication devices. Specifically, the device is usually set at the boundary of different security areas such as dispatching master stations and substations, and its core function is to use tunnel encryption technologies such as IPSec to establish a logical security pipeline on the physical communication link. All business data crossing the security area boundary is encrypted before entering the pipeline and decrypted after reaching the opposite end, thereby effectively protecting the confidentiality of data in the wide-area transmission process and preventing the risk of eavesdropping or interception on public or untrusted network links. This mode based on boundary protection and channel encryption has played a key protective role against attacks from external networks at a certain stage of development, and has provided a basic guarantee for the stable operation of the dispatching data network.

[0004] However, with the continuous deepening of the intelligent level of the power grid, the extension of the Internet of Things trend, and the evolution of network attack methods, the inherent limitations of this traditional security architecture, which relies on border protection and network layer encryption, are becoming increasingly prominent. The reason for this is that the core design philosophy of this architecture is to embed security capabilities in specific network gateways, forming a defense model with a strong outer shell and a soft inner core. The deep-seated technical contradiction lies in the separation of security mechanisms and business applications themselves. For example, the IEC 104 telecontrol communication protocol widely used in dispatching data networks does not fully consider security elements in its initial design, and essentially exchanges data in plaintext. Although vertical encryption devices encrypt the transmission channel, the data is still in plaintext form within the internal network of each security zone before and after entering and leaving the encryption device. This means that once an attacker penetrates the internal network of a substation through other means, they can bypass the protection of the vertical encryption device and directly send fake remote control commands or tamper with the telemetry data sent to the terminal devices within the station, causing serious damage to the power grid. This security model protects the "channel", but fails to protect the "source" and "sink", and the security protection does not truly sink to the source of data generation and the endpoint of final consumption.

[0005] Furthermore, the security of classical cryptography systems is rooted in the computational complexity of mathematical problems such as large number factorization and discrete logarithm. With the rapid development of quantum computing technology, its powerful parallel computing capabilities pose a revolutionary threat to existing public key cryptography systems. Once practical quantum computers are available, the encryption algorithms currently widely used for identity authentication and key agreement may be easily broken, at which point the entire protection system based on vertical encryption authentication devices will be rendered useless, and the power grid security will face a serious challenge. In addition, in terms of actual deployment, traditional solutions rely heavily on dedicated optical fiber networks to ensure the reliability and security of physical links, but in remote, harsh, or temporary deployment scenarios, the laying of optical fibers is costly and time-consuming, greatly limiting the flexibility and response speed of networking. Although wireless public network technologies such as 5G provide new solutions, their open access characteristics pose much stricter requirements on communication encryption strength and end-to-end protection capabilities than before.

[0006] Therefore, how to build a security protection capability that extends from the network border to the business application endpoint based on the existing power grid dispatching data network architecture, which can resist the disruptive impact of future quantum computing, is compatible with various network access methods, and ensures smooth transition and seamless integration with existing business systems, achieving true end-to-end internal security, has become a key challenge and technical problem that needs to be solved for technical personnel in the field. SUMMARY

[0007] The technical problem to be solved by the present application is to overcome the lack of end point security, the solidification of protection boundary and the inherent vulnerability of classical cryptography system in the face of quantum computing threats caused by the separation of security mechanism and business application in the existing substation dispatching data network security protection system. The existing technology relies on the deployment of vertical encryption authentication devices at the network boundary, which can only guarantee the confidentiality of the transmission channel, but cannot provide protection from the source to the terminal for the transmission content itself, such as telecontrol communication data in International Electrotechnical Commission 104 protocol (IEC 104) in the form of plaintext within the network. Once the attacker penetrates into the security area, the boundary protection can be bypassed, and the business end point is directly threatened. In addition, the public key cryptography algorithm relied on by the system cannot resist the cracking attack of future quantum computers, which poses a fundamental challenge to the long-term security of the power grid. At the same time, the over-reliance on dedicated optical fiber networks also limits the deployment flexibility and economy in complex geographical environments.

[0008] To solve the above technical problems, the present application provides a substation dispatching data network security communication method based on quantum tunnel encryption, which aims to build a two-layer, end-to-end security protection architecture deeply integrating quantum cryptography technology and post-quantum cryptography technology. The method deploys quantum secure communication terminals at the dispatching master station and the substations, sinks the security capability from the network boundary to the source of application data, performs application layer encapsulation encryption and digital signature on the original telecontrol protocol data, and on this basis, builds an encrypted logical tunnel based on quantum keys for transmission. This not only makes up for the lack of security mechanism in the telecontrol protocol itself, realizes the end point protection of data, but also uses the unconditional security of quantum key distribution and the anti-computing attack characteristics of post-quantum cryptography algorithm to build the next generation of secure communication system that can resist classical and quantum computing attacks, and is compatible with multiple physical network media, realizing the protection goal of security, flexibility and smooth evolution.

[0009] In order to achieve the above application purpose, the present application is realized by the following technical scheme:

[0010] The present application discloses a substation dispatching data network security communication method based on quantum tunnel encryption, which establishes secure communication between a dispatching master station and one or more substations, and the dispatching master station and the one or more substations are both deployed with quantum secure communication terminals. The method comprises the following steps: a secure session establishment step, a signaling end data encapsulation and encryption step, and a receiving end decryption and data restoration step.

[0011] The quantum secure communication terminal is a special hardware device, which is internally integrated with a quantum key distribution module, a post-quantum cryptography operation module, a security protocol processing engine, a key management and synchronization unit and a multi-network interface module.

[0012] The quantum key distribution module contains a phase-encoded, decoyed-state BB84 protocol quantum signal transmitter or receiver. The transmitter uses a narrow-linewidth distributed feedback laser with a central wavelength of 1550 nanometers as its light source, phase-modulating photons via an asymmetric Mach-Zehnder interferometer. The receiver utilizes an array of superconducting nanowire single-photon detectors with a response wavelength range of 1500 to 1600 nanometers, a dark count rate of less than 100 times per second, and a detection efficiency greater than 20%. This module is responsible for executing the quantum key distribution protocol over an independent quantum channel between the quantum secure communication terminals of the communicating parties, generating a shared original key with information-theoretic security.

[0013] The post-quantum cryptographic module embeds a dedicated field-programmable gate array chip with hardware acceleration logic for executing post-quantum cryptographic algorithms based on modular lattice cryptography. Specifically, the module implements a key encapsulation mechanism algorithm based on a modular version of a learning algorithm with rounding problems, which is used to securely negotiate a shared secret during the initial authentication phase. Simultaneously, the module implements a digital signature algorithm based on a modular version of a learning algorithm with rounding problems, which is used to authenticate communicating entities and sign critical data messages to ensure integrity and non-repudiation. The algorithms executed by this module are designed to be equivalent to the Level 3 security level defined by the National Institute of Standards and Technology's post-quantum cryptography standardization process.

[0014] The security protocol processing engine utilizes a multi-core network processor with a built-in hardware encryption and decryption acceleration unit, operating at a core frequency of no less than 1.2 GHz. This engine is responsible for executing the encapsulation and decapsulation operations of the Quantum Secure Telecontrol Application Protocol (QSTAP) and the Quantum Secure Tunneling Protocol (QSTP), as defined in this invention. The engine performs in-depth processing of raw telecontrol protocol messages originating from local service terminals based on pre-defined security policies.

[0015] The key management and synchronization unit includes a secure storage chip with physical tamper-resistant properties. It is used to store the original key generated by the quantum key distribution module, the post-processed session master key, and various working keys generated from the session master key via a key derivation function (KDF). The key derivation function uses the extract-extend key derivation function (HKDF) based on the Secure Hash Algorithm 3 (SHA-3). This unit is responsible for the full lifecycle management of all key generation, storage, distribution, update, and destruction, and maintains state synchronization with the key management unit of the peer device.

[0016] The multi-network interface module is physically integrated with a single-mode optical fiber interface supporting the 1000BASE-LX standard, used to connect the quantum channel and the main data channel; and a wireless communication module supporting the fifth-generation mobile communication new radio (5G NR) standard, which includes a radio frequency front end and a baseband processor, and supports communication in the 3.5 GHz frequency band, used as a backup or main data transmission channel. The module has built-in link aggregation and intelligent fault switching logic to ensure the redundancy and high availability of the communication link.

[0017] Further, the secure session establishment step has the following specific process:

[0018] First, initial authentication and key agreement based on post-quantum cryptography are performed. The quantum secure communication terminal of the communication initiator generates a pair of temporary post-quantum public and private keys through its post-quantum cryptography operation module, and sends the public key together with a randomly generated challenge number to the communication responder. After receiving the information, the quantum secure communication terminal of the responder uses its pre-stored long-term post-quantum private key representing its identity to digitally sign the concatenation of the initiator's public key and the challenge number, and returns the signature together with its own long-term post-quantum public key and a ciphertext capsule of the shared secret generated by its post-quantum cryptography operation module to the initiator. The ciphertext capsule is encrypted using the temporary post-quantum public key of the initiator through the aforementioned key encapsulation mechanism algorithm. After receiving the response, the initiator first verifies the validity of the signature using the pre-stored long-term post-quantum public key of the responder to complete the authentication of the responder's identity; after verification, it uses its temporary post-quantum private key to decrypt the ciphertext capsule and obtain the shared secret. At this point, the two parties have established an initial shared secret that is resistant to quantum computing attacks and has been authenticated in both directions.

[0019] Second, quantum key distribution and session master key generation are performed. After successful initial authentication, the quantum key distribution modules of the two communication parties start the quantum key distribution process through the quantum channel. Both parties perform the aforementioned entangled state BB84 protocol, and stop transmitting and receiving quantum signals after a predetermined time (e.g., 300 seconds) or after generating a bit sequence of a predetermined length. Subsequently, both parties perform key agreement post-processing steps such as basis vector comparison, error rate estimation, error bit removal, and parameter negotiation through a public but encrypted classical channel using the initial shared secret. Specifically, error bit removal uses low-density parity check code (LDPC) for efficient error correction. After error correction, both parties use privacy amplification based on a two-way universal hash function to compress and purify the corrected key, eliminating information that may be leaked to eavesdroppers during the post-processing process, and finally generate a 256-bit long session master key (MSK) with unconditional security.

[0020] Finally, the working key derivation is performed. The key management and synchronization units of both parties take the session master key as input, and send it into the aforementioned extraction-expansion key derivation function based on secure hash algorithm 3. The function takes the session identifier, the identities of the two parties of communication, and other information as salt and information input, and derives at least four independent working keys: a group of 128-bit application layer encryption keys (K_APP_ENC) for encrypting the payload of the quantum secure telecontrol application protocol; a group of 128-bit application layer message authentication code keys (K_APP_MAC) for verifying the integrity of the application layer data; a group of 128-bit tunnel layer encryption keys (K_TUN_ENC) for encrypting the payload of the quantum secure tunnel protocol; and a group of 128-bit tunnel layer message authentication code keys (K_TUN_MAC) for verifying the integrity of the tunnel layer data. After the derivation is completed, the secure session is established, and the system enters the standby state.

[0021] Further, the data encapsulation and encryption step of the sending end has the following specific process:

[0022] When the security protocol processing engine of the quantum secure communication terminal of the sending end listens to an application protocol data unit (APDU) conforming to the format of the International Electrotechnical Commission 104 regulation and originating from the local dispatching application or the terminal device of the substation through its internal port, the step is triggered.

[0023] Firstly, a quantum secure telecontrol application protocol (QSTAP) message is constructed. The security protocol processing engine takes the complete IEC 104 APDU intercepted as the basic payload. The engine then creates a QSTAP message header, which contains the following fields: a 4-byte version and compatibility flag field for identifying the protocol version and backward compatibility mode; an 8-byte session identifier (SPI) for pointing to the currently effective session master key and related working keys; an 8-byte sequence number for preventing replay attacks, which is strictly monotonically increasing at each time of packet sending; and a 2-byte payload length field.

[0024] Second step, application layer encryption and integrity protection. The security protocol processing engine invokes an authenticated encryption algorithm module based on the Advanced Encryption Standard (AES) working in Galois / Counter Mode (GCM). This module uses the aforementioned derived application layer encryption key (K_APP_ENC) and application layer message authentication code key (K_APP_MAC) as parameters to encrypt and authenticate the payload of the QSTAP packet, i.e. the original IEC 104 APDU. The QSTAP packet header is used as associated data (AAD) in the authentication and encryption process, its integrity is protected but it is not encrypted itself. The result of the encryption and authentication calculation is a ciphertext payload and a 128-bit message authentication code (MAC). This message authentication code is appended after the ciphertext payload.

[0025] Third step, post-quantum digital signature. To achieve non-repudiation, the security protocol processing engine invokes the post-quantum cryptographic operation module with the complete QSTAP packet (including the packet header, ciphertext payload and message authentication code) as a whole data block. This module uses the sender's long-term post-quantum private key to perform the aforementioned digital signature algorithm on this data block, generating a post-quantum digital signature. This signature is appended at the end of the QSTAP packet.

[0026] Fourth step, constructing the quantum secure tunnel protocol (QSTP) packet. The security protocol processing engine uses the complete QSTAP packet that has been encrypted and signed at the application layer as the payload of the quantum secure tunnel protocol. The engine creates a QSTP packet header that contains only an 8-byte tunnel session identifier (T-SPI) to indicate which set of tunnel layer working keys to use for the peer device.

[0027] Fifth step, tunnel layer encryption and integrity protection. Similar to the application layer encryption, the security protocol processing engine invokes the authenticated encryption algorithm module again, but this time using the tunnel layer encryption key (K_TUN_ENC) and tunnel layer message authentication code key (K_TUN_MAC). This module encrypts and authenticates the payload of the QSTP packet, i.e. the aforementioned complete QSTAP packet. The QSTP packet header is used as associated data. The result is a tunnel ciphertext payload and a tunnel message authentication code.

[0028] Sixth step, final encapsulation and sending. The security protocol processing engine combines the QSTP packet header, tunnel ciphertext payload and tunnel message authentication code into a complete QSTP packet, and uses it as the payload of a new Internet Protocol (IP) datagram. The source and destination addresses of this IP datagram are the addresses of the quantum secure communication terminals of the sender and receiver, respectively. Finally, this IP datagram is sent out through the multi-network interface module via the currently selected physical link (dedicated optical fiber or 5G wireless network).

[0029] Further, the receiving end decryption and data restoration step, the specific process is as follows:

[0030] When the quantum secure communication terminal of the receiving end receives an IP datagram, and its protocol field is identified as QSTP, the step is triggered.

[0031] First, tunnel layer decapsulation and verification. The security protocol processing engine extracts the QSTP packet from the received IP datagram. According to the tunnel session identifier in the QSTP packet header, the corresponding tunnel layer encryption key (K_TUN_ENC) and tunnel layer message authentication code key (K_TUN_MAC) are retrieved from the key management and synchronization unit. The engine calls the authentication encryption algorithm module to decrypt and verify the tunnel ciphertext payload and tunnel message authentication code. If the message authentication code verification fails, it indicates that the data has been tampered with during transmission, and the packet is discarded immediately and a security event is recorded. If the verification is successful, the decrypted payload is obtained, which is a complete QSTAP packet with a post-quantum digital signature.

[0032] Second, post-quantum digital signature verification. The security protocol processing engine calls the post-quantum cryptographic operation module to verify the post-quantum digital signature attached to the decrypted QSTAP packet using the pre-stored long-term post-quantum public key of the sending end. If the signature verification fails, it indicates that the packet is illegal or the content has been tampered with, and the packet is discarded immediately and a security event is recorded. This step ensures the authenticity and non-repudiation of the data.

[0033] Third, application layer decapsulation and verification. After successful signature verification, the security protocol processing engine parses the QSTAP packet header to obtain the session identifier (SPI) and sequence number. The engine first checks the sequence number to ensure that it is greater than the last successfully received packet sequence number to prevent replay attacks. Then, according to the session identifier, the corresponding application layer encryption key (K_APP_ENC) and application layer message authentication code key (K_APP_MAC) are retrieved from the key management and synchronization unit. The engine calls the authentication encryption algorithm module to decrypt and verify the ciphertext payload and message authentication code in the QSTAP packet. If the message authentication code verification fails, the packet is discarded.

[0034] Fourth, restore the original data and forward. After successful application layer message authentication code verification, the engine obtains the decrypted plaintext payload, which is the original, unmodified International Electrotechnical Commission 104 protocol application protocol data unit (APDU). The security protocol processing engine forwards this APDU to the local dispatch master application system or substation monitoring background it protects through its internal port, completing a secure, end-to-end data communication process.

[0035] As a preferred embodiment of the present application, in order to ensure smooth transition and seamless integration with the existing dispatching data network infrastructure, the security protocol processing engine of the quantum secure communication terminal is built-in with a set of compatibility policy control logic. This logic is based on a configurable peer device capability registry. When communicating with legacy devices that do not support the methods described in the present application, the version and compatibility flag field is set to "legacy mode". In this mode, the security protocol processing engine of the quantum secure communication terminal will not perform any QSTAP or QSTP encapsulation operations, but will forward the intercepted IEC 104 packets in a transparent bridge manner directly to the existing longitudinal encryption authentication device deployed in series with the quantum secure communication terminal, which will complete the traditional network layer tunnel encryption. When communicating with a peer that also deploys a quantum secure communication terminal but the quantum channel between them has not been established or is not available, the flag field is set to "hybrid mode". In this mode, the security protocol processing engine only performs QSTAP encapsulation, encryption and signature at the application layer, and then delivers the generated protected QSTAP packets directly to the existing longitudinal encryption authentication device for transport layer encryption. Only when both parties have completed deployment and the quantum channel is available, "full mode" is enabled to perform all the steps described in the present application.

[0036] Compared with the prior art, the present application has the following advantages:

[0037] (1) Real end-to-end security protection is achieved. The present application extends the security protection capability from the network boundary to the source of data generation and the end point of final consumption by encrypting and signing the IEC 104 and other telecontrol protocol data at the application layer, completely solving the inherent defect of the traditional boundary protection model "strong shell, soft core", i.e. even if the attacker penetrates into the substation internal network, he cannot analyze or forge the protected dispatching instructions and data.

[0038] (2) A forward-looking security system that can resist quantum computing attacks is built. The present application creatively integrates two key quantum era cryptography technologies: using the information-theoretic security of quantum key distribution (QKD) to ensure the absolute security of session key exchange, making it immune to any computing power attack; and using post-quantum cryptography (PQC) algorithms to solve the problem of quantum attack resistance in identity authentication and digital signature, building a full-link, future-oriented defense-in-depth system.

[0039] (3) Dual encryption and deep defense capability is provided. The present application implements double-layer encryption protection of business data through QSTAP encapsulation at the application layer and QSTP encapsulation at the tunnel layer. Application layer encryption protects the data content itself, while tunnel layer encryption hides the protocol features and traffic patterns of internal communication, effectively resisting complex traffic analysis attacks and significantly improving the overall protection strength.

[0040] (4) Enhanced flexibility of networking and reduced deployment costs. The quantum secure communication terminal integrates support for multiple network media such as wired optical fiber and 5G wireless public network, and has intelligent link switching capability. This enables remote areas, temporary scenarios or substations without optical fiber laying conditions to quickly and economically access the dispatching data network using wireless public networks, while ensuring communication security through the powerful encryption mechanism provided by the application, greatly improving the flexibility and response speed of power grid construction.

[0041] (5) Ensure smooth evolution and service of the old and new systems. The compatibility mode designed by the application enables the new quantum secure communication terminal to coexist and work with the existing vertical encryption authentication device, supports gradual and regional upgrade deployment, avoids the huge risks and investment waste caused by "one-size-fits-all" system reform, and ensures the continuity and stability of power grid dispatching services during the security upgrade process.

[0042] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the following embodiments of the present application are described in detail below, and the accompanying drawings are described as follows. BRIEF DESCRIPTION OF DRAWINGS

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0044] Figure 1 is the deployment architecture diagram of the secure communication system in the present application.

[0045] Figure 2 is the internal structure block diagram of the quantum secure communication terminal in the present application.

[0046] Figure 3 is the overall flowchart of the secure communication method described in the present application. DETAILED DESCRIPTION

[0047] In order to make the purposes, technical solutions and advantages of the embodiments of the present application more clear, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments.

[0048] Reference Figure 1, which shows a system deployment architecture applied by the substation dispatching data network security communication method based on quantum tunnel encryption disclosed by the present application. The architecture builds a secure communication link between a dispatching master station and one or more remote substations. Different from the traditional mode of deploying security devices at the network boundary, the core of the present application is to deploy a dedicated quantum security communication terminal in the local area network of the dispatching master station and in the local area network of each substation that needs to perform secure communication. The dispatching application server in the dispatching master station and the remote terminal unit (RTU) or monitoring background system in the substation are connected to the quantum security communication terminal in the area where they are located through a standard Ethernet interface. Between the dispatching master station and the substation, there are two logically separated channels: one is a quantum channel used to perform quantum key distribution protocol, which is usually a dedicated, low-loss single-mode optical fiber in physical form; the other is a data channel used to transmit encrypted business data, which can multiplex the optical fiber used by the quantum channel to realize channel sharing through wavelength division multiplexing technology, or it can be a completely independent physical link, such as another optical fiber, a microwave link, or a fifth-generation mobile communication (5G) wireless link based on a public network as shown in the embodiment. Through this deployment mode, the quantum security communication terminal becomes a necessary passageway for dispatching business data entering and exiting the local network, thereby forming an end-point level security protection for the original business data.

[0049] Next, refer to Figure 2 , which shows the internal functional structure diagram of the quantum security communication terminal as the core execution entity of the technical solution of the present application in detail. The terminal is designed as a highly integrated special-purpose hardware device, which contains five key functional modules inside, working cooperatively to realize the security communication method described in the present application. The five modules are: quantum key distribution module, post-quantum cryptographic operation module, security protocol processing engine, key management and synchronization unit, and multi-network interface module.

[0050] Specifically, the quantum key distribution module is the basis for implementing information theory security key agreement. In the embodiment, the module implements a complete quantum key distribution transceiver system based on phase encoding decoy state BB84 protocol. When the terminal is used as a transmitting terminal, a distributed feedback (DFB) laser with a center wavelength precisely stabilized at 1550.12 nanometers and a spectral line width less than 100 kilohertz is used as a core light source. The light pulse generated by the laser has a pulse width precisely controlled at 500 picoseconds and a repetition frequency of 100 megahertz. After passing through an adjustable optical attenuator, the light pulse is injected into an asymmetric Mach-Zehnder interferometer composed of a lithium niobate (LiNbO3) waveguide. By applying an accurate driving voltage (0V, 1.57V, 3.14V, 4.71V, corresponding to 0, π / 2, π, 3π / 2 phase, respectively) to the phase modulator of the interferometer, the four quantum states (|0>, |1>, |+>, |->) of each photon are encoded. At the same time, by randomly modulating the intensity of the light pulse, a pulse sequence with three different average photon numbers of signal state, decoy state and vacuum state is generated to resist photon number splitting attack. When the terminal is used as a receiving terminal, a superconducting nanowire single-photon detector (SNSPD) array is used as a core detection component. The array is packaged in a cryostat with a working temperature of 2.2 kelvin. The detection efficiency of the array is higher than 90% at a wavelength of 1550 nanometers. The dark count rate is strictly controlled to be less than 50 times per second, and the time jitter is less than 50 picoseconds. The received photons are subjected to base vector selection through an interferometer symmetrical with the structure of the transmitting terminal and are detected by the detector array. The overall function of the module is to complete the transmission and reception of quantum signals with the quantum key distribution module of the opposite terminal on a quantum channel, and to generate shared raw key materials for the upper layer.

[0051] The post-quantum cryptographic operation module aims to solve the security problem of identity authentication and digital signature in the era of quantum computing. The core of the module is a field programmable gate array (FPGA) chip, specifically a Virtex UltraScale+ VU9P of Xilinx. On the FPGA, the special hardware acceleration logic for executing post-quantum cryptographic algorithms based on modular lattice cryptography is solidified through hardware description language. In this embodiment, two algorithms are specifically integrated, both of which meet the third level of security defined in the National Institute of Standards and Technology (NIST) post-quantum cryptography standardization process. The first is a key encapsulation mechanism (KEM) algorithm, which uses a variant of CRYSTALS-Kyber for quantum attack-resistant shared secret negotiation in the initial authentication phase. The second is a digital signature algorithm, which uses a variant of CRYSTALS-Dilithium for authentication of the identity of a communication entity and signing of critical data messages to ensure their integrity and non-repudiation. The hardware acceleration logic inside the FPGA mainly includes multiple parallel polynomial multiplication units based on number theoretic transform (NTT), as well as hardware pipelines specially designed for sampling, rounding, and other lattice cryptography core operations, which optimize the delay of signature and verification operations to sub-millisecond level.

[0052] The security protocol processing engine is the center of data encapsulation and processing in the present application. The engine uses a high-performance multi-core network processor, such as Layerscape LX2160A of NXP, which contains 16 ARM Cortex-A72 cores with a working frequency of 2.2 GHz. The processor integrates a powerful hardware encryption and decryption coprocessor, which can provide line-speed processing capability for authentication and encryption operations of the advanced encryption standard (AES) in Galois / counter mode (GCM). The main responsibility of the engine is to execute the two core protocols defined in the present application: encapsulation and decapsulation of quantum secure telecontrol application protocol (QSTAP), and encapsulation and decapsulation of quantum secure tunneling protocol (QSTP). The engine listens to the original International Electrotechnical Commission 104 protocol (IEC104) messages from local service terminals (such as dispatching master station applications) through its internal high-speed switching structure, and according to the preset security policy and current session state, it processes, encapsulates and encrypts the messages, or decrypts, verifies and restores the received encrypted messages.

[0053] The key management and synchronization unit is the cornerstone of the entire security system, responsible for the secure life cycle management of all keys. The core of this unit is a secure storage chip with physical tamper-proof (Physical Unclonable Function, PUF) features, such as STSAFE-A110 from STMicroelectronics. This chip provides a hardware-isolated secure execution environment for storing raw keys generated by the quantum key distribution module, session master keys generated after processing, and various working keys generated by the session master key through the key derivation function (KDF). Once all sensitive key materials are stored, they cannot be directly read by external devices. The unit also has a hardware implementation of the extraction-expansion key derivation function (HKDF) based on the secure hash algorithm 3 (SHA-3). It is responsible for determining multiple independent and unrelated working keys for different encryption and authentication tasks based on different context information (e.g., salt value and information tag) from a high-entropy session master key. At the same time, the unit synchronizes the state with the corresponding unit of the opposite device through a secure internal channel, ensuring that both parties use the correct key set at any time, and is responsible for the timely update and secure destruction of the key.

[0054] The multi-network interface module provides flexible network access and link redundancy capabilities for the terminal. This module physically integrates a series of interfaces. One is a single-mode fiber SFP+ interface supporting the 1000BASE-LX standard, used to connect long-distance quantum channels and primary data channels. The second is a wireless communication module supporting the 5th Generation Mobile Communication New Radio (5G NR) standard. This module contains a Qualcomm Snapdragon X65 baseband processor and a complete RF front-end inside, supporting communication at 3.5 GHz (n78 band) and 4.9 GHz (n79 band, dedicated to the power grid). This 5G interface can be used as the preferred data transmission channel in areas where fiber resources are scarce, or as a backup channel for the primary fiber link. The module has built-in intelligent fault switching logic based on real-time link quality monitoring. This logic continuously monitors the delay, jitter, and packet loss rate of the fiber link and the 5G link by periodically sending small probe packets. Once the performance indicators of the primary link deteriorate and continue to exceed the preset threshold (e.g., delay greater than 50 ms or packet loss rate higher than 0.1% for more than 5 seconds), the module will automatically and seamlessly switch the data stream to the backup link, while reporting the link switching event to the upper-layer security protocol processing engine. The entire process is transparent to the upper-layer service, ensuring high availability and service continuity of the communication link.

[0055] After a detailed description of the core hardware entities and their functional modules of the system, the following will combine the system architecture with the system's security protocol and its implementation to further illustrate the system's security architecture. Figure 3The flow chart shows the specific steps of the substation dispatching data network security communication method based on quantum tunnel encryption proposed by the present application, which systematically describes the specific steps of the method. The whole method can be divided into three logically continuous stages: the security session establishment step, the sending end data encapsulation and encryption step, and the receiving end decryption and data restoration step.

[0056] First, the security session establishment step is performed. The goal of this step is to establish a security session context with double authentication, forward security and complete working key between two quantum security communication terminals. This step is composed of a series of accurately coordinated sub-steps.

[0057] The first sub-step is the initial authentication and key agreement based on post-quantum cryptography. The purpose of this process is to securely establish an initial shared secret without any pre-shared key, and to complete a strong authentication of the identity of both communicating parties, and the process can resist attacks by quantum computers. Assuming that the terminal on the dispatch master station side is the communication initiator, and the terminal on the substation side is the responder. The initiator generates a pair of temporary and one-time post-quantum public and private key pairs (PQC_ephem_pub, PQC_ephem_priv) through its post-quantum cryptography operation module, where the key algorithm is the aforementioned CRYSTALS-Kyber. At the same time, the initiator generates a 256-bit random number as a challenge number (Challenge). Subsequently, the initiator encapsulates the temporary public key PQC_ephem_pub and the challenge number Challenge in an "authentication request" message and sends it to the responder through the data channel. After receiving the request, the terminal of the responder first retrieves the pre-stored long-term post-quantum private key (PQC_longterm_priv) representing its own legal identity from its key management and synchronization unit, which is the private key of the aforementioned CRYSTALS-Dilithium algorithm. It uses this long-term private key to digitally sign the concatenated byte string of the received initiator's temporary public key PQC_ephem_pub and the challenge number Challenge, generating a post-quantum signature (Signature). Next, the responder calls its post-quantum cryptography operation module and uses the initiator's temporary public key PQC_ephem_pub as input to execute the key encapsulation mechanism algorithm (Kyber.Encaps), generating a shared secret (SharedSecret) and its corresponding ciphertext encapsulator (Ciphertext). Finally, the responder encapsulates its own long-term post-quantum public key (PQC_longterm_pub), the generated post-quantum signature Signature, and the ciphertext encapsulator Ciphertext in an "authentication response" message and sends it back to the initiator. After receiving the response, the initiator performs two key verification actions: first, it uses the responder's long-term post-quantum public key PQC_longterm_pub pre-stored in the local trusted list to verify the signature Signature in the response message. The verification data body is the temporary public key and the challenge number sent by the initiator himself before. If this step is verified, the identity of the responder is successfully authenticated. Second, after the identity authentication is successful, the initiator uses its own saved temporary post-quantum private key PQC_ephem_priv to perform the key decapsulation operation (Kyber.Decaps) on the ciphertext encapsulator Ciphertext in the response message, thereby recovering the shared secret SharedSecret consistent with the responder.At this point, both parties have completed a mutual authentication that can resist both passive and active quantum attacks without pre-shared symmetric keys, and have securely negotiated an initial shared secret. This secret will be used to protect the subsequent key agreement process.

[0058] The second sub-step is quantum key distribution and session master key generation. After the initial authentication is successful and a secure classical communication channel is established (all communication contents are symmetrically encrypted and authenticated using the key derived from the shared secret), the quantum key distribution modules of both parties start the quantum key distribution process through the quantum channel. Both parties strictly implement the pre-configured decoy-state BB84 protocol. In a typical embodiment, the process of transmitting and receiving quantum signals lasts for 300 seconds. During this period, the transmitting party sends a sequence of optical pulses containing signal states, decoy states, and vacuum states at a frequency of 100 megahertz, and the receiving party performs synchronous detection. After 300 seconds, assuming that both parties exchange about 3x10^10 pulses on a 25-kilometer optical fiber link with a total attenuation of 5 decibels, the receiving party detects about 3x10^8 valid photon events. Subsequently, both parties enter the post-processing stage of the key agreement. The communication in this stage is conducted through the data channel and is protected by the initial shared secret generated in the previous step. First, the base vector comparison (Sifting) is performed, in which both parties publish their respective base vector sequences used for encoding and detection, and filter out the events with consistent base vectors. After this process, the length of the key string is reduced to about 1.5x10^8 bits. Next, the error rate estimation (QBER Estimation) is performed, in which both parties randomly extract a small portion of the filtered bits for comparison and calculate the quantum channel error rate. Meanwhile, using the statistical information of the decoy states, the gain and error rate of single-photon pulses are accurately estimated, allowing the judgment of the disturbance possibly introduced by an eavesdropper, and the calculation of the upper bound of the length of the final secure key. In this example, it is assumed that the estimated QBER is 1.2%. Subsequently, error bit elimination (Error Correction) is performed, in which efficient low-density parity-check codes (LDPC) are used to correct errors in the filtered key. For example, using an LDPC code with a code rate of 0.9, all error bits are corrected through 10 rounds of iteration. Finally, the most critical step is privacy amplification (Privacy Amplification). In order to eliminate all information that may be leaked to the eavesdropper during the post-processing process (especially in the error correction stage), both parties use privacy amplification technology based on a two-way universal hash function. They input the error-corrected key into a hash function based on SHA-256 for compression and purification, and finally generate one or more session master keys (MSKs) with a length of 256 bits and information-theoretic security. After this process, the initial negotiated PQC shared secret is destroyed, and all subsequent communication security is based on this MSK.

[0059] The third sub-step is the derivation of working keys. The key management and synchronization unit of both parties sends the newly generated 256-bit session master key MSK as input key material (IKM) into the built-in SHA-3-based HKDF module. The function uses the unique identifier of the current session (e.g., a 64-bit session ID) as a salt value and a predefined string (e.g., "QSTAP-AES128GCM-KEYS") as information input (info) to derive at least four sets of 128-bit working keys through the extract-expand two-stage process: a set of application layer encryption keys (K_APP_ENC) for AES-128-GCM encryption of the QSTAP payload; a set of application layer message authentication code keys (K_APP_MAC), which, although the AES-GCM mode has its own authentication, can be used for independent MAC calculation or as key input for GCM in some high-security scenarios; a set of tunnel layer encryption keys (K_TUN_ENC) for AES-128-GCM encryption of the QSTP payload; and a set of tunnel layer message authentication code keys (K_TUN_MAC). After the derivation is complete, the complete secure session is established, all necessary key materials are ready and securely stored, and the system enters a standby state, ready to process business data.

[0060] When the secure session is established, the system enters the normal communication phase. The data encapsulation and encryption steps performed by the quantum secure communication terminal of the sending end will be described in detail below. This step is triggered when the secure protocol processing engine detects an IEC 104 application protocol data unit (APDU) originating from the local business terminal (e.g., dispatch master application server) it protects.

[0061] The first step is to build a quantum secure telecontrol application protocol (QSTAP) message. The secure protocol processing engine considers the complete IEC 104 APDU, whether it is a telemetering, telesignaling, or remote control instruction, as its basic payload. The engine then creates a QSTAP message header in memory. The message header structure is precisely defined as follows: a 4-byte version and compatibility flag field, where the high 1 byte represents the major version number, the next 1 byte represents the minor version number, and the last 2 bytes are flag bits for compatibility mode control; an 8-byte session identifier (SPI), which uniquely points to the current effective session master key MSK and the entire set of working keys derived therefrom, ensuring that the receiving end can correctly retrieve the keys; an 8-byte sequence number, which is strictly monotonically increasing and maintained by the sending end within the current session, used to prevent replay attacks; and a 2-byte payload length field indicating the length of the subsequent encrypted payload.

[0062] Second, application layer encryption and integrity protection. The security protocol processing engine invokes its built-in hardware encryption co-processor to perform AES-128-GCM authenticated encryption algorithm. It obtains the application layer encryption key K_APP_ENC for the current session from the key management and synchronization unit. The input of the encryption operation includes: the original IEC 104 APDU as plaintext, and K_APP_ENC as key. In order to generate an initialization vector (IV) that is unique for each encryption, the engine concatenates an 8-byte sequence number with a 4-byte fixed value to form a 96-bit IV, which meets the requirement of GCM mode for IV uniqueness. At the same time, the engine takes the entire QSTAP packet header created in the first step as the associated data (AAD) in the authenticated encryption process. This means that the integrity of the header will be protected, and any tampering with the header will be detected upon decryption, but the header itself is transmitted in plaintext form to facilitate possible policy processing by network intermediate devices. The result of the encryption calculation is a ciphertext payload of the same length as the original APDU, and a 128-bit (16-byte) message authentication code (MAC), also known as an authentication tag. The MAC is appended to the ciphertext payload to form the protected QSTAP payload portion.

[0063] Third, post-quantum digital signature for non-repudiation. In order to provide the highest level of security assurance, especially for critical remote control instructions, it is necessary to ensure the absolute authenticity of the source and the non-repudiation afterwards. The security protocol processing engine takes the complete QSTAP packet generated in the previous two steps (including the plaintext header, the ciphertext payload, and the 128-bit MAC) as a whole data block. It invokes the post-quantum cryptographic operation module and passes in the sender's long-term post-quantum private key (PQC_longterm_priv). The post-quantum cryptographic operation module uses the CRYSTALS-Dilithium signature algorithm to calculate the SHA3-512 hash value of the data block, generating a post-quantum digital signature of approximately 2420 bytes in length. This signature is appended to the end of the entire QSTAP packet.

[0064] Fourth, construct the quantum secure tunnel protocol (QSTP) packet. The purpose of this step is to hide the internal application layer security protocol details from the outside network, providing an additional layer of protection against traffic analysis. The security protocol processing engine takes the complete QSTAP packet that has been encrypted and signed at the application layer (header + ciphertext payload + MAC + signature) as the payload of the quantum secure tunnel protocol. The engine creates a very simple QSTP packet header that only contains an 8-byte tunnel session identifier (T-SPI) to indicate which set of tunnel layer working keys the opposite device should use for decryption.

[0065] Fifth, tunnel layer encryption and integrity protection. Similar to the process of application layer encryption, the security protocol processing engine invokes the hardware encryption co-processor again. But this time, it obtains the tunnel layer encryption key K_TUN_ENC from the key management unit. It encrypts the entire QSTAP packet in the fourth step as the QSTP payload as plaintext. Similarly, the QSTP packet header (i.e., T-SPI) is used as AAD, and a separate sequence number maintained by the tunnel layer is used to generate IV. The result of the encryption operation is a tunnel ciphertext payload and a 128-bit tunnel message authentication code.

[0066] Sixth, final encapsulation and transmission. The security protocol processing engine combines the QSTP packet header, the tunnel ciphertext payload, and the tunnel message authentication code into a complete QSTP packet. This packet is encapsulated as the payload in a standard Internet Protocol (IP) datagram. The protocol field of the IP datagram is set to a reserved custom value (e.g., 254) to identify that it carries the QSTP protocol. The source and destination addresses of the IP header are the IP addresses of the quantum secure communication terminals of the sending and receiving ends, respectively. Finally, the constructed IP datagram is transmitted through the multi-network interface module via the currently selected physical link (e.g., the primary dedicated optical fiber or the backup 5G wireless network).

[0067] Correspondingly, when the multi-network interface module of the quantum secure communication terminal of the receiving end receives an IP datagram and discovers that it is the QSTP protocol by parsing the protocol field, the receiving end decryption and data restoration step is triggered. This process is the exact inverse operation of the sending end encapsulation and encryption process.

[0068] First, tunnel layer decapsulation and verification. The security protocol processing engine extracts the QSTP packet from the IP datagram. It first parses the 8-byte tunnel session identifier (T-SPI) in the QSTP packet header and uses it as an index to quickly retrieve the corresponding tunnel layer encryption key K_TUN_ENC from the key management and synchronization unit. Subsequently, the engine invokes the hardware encryption co-processor to perform the decryption and verification operations of AES-128-GCM. It uses the QSTP packet header as AAD and the tunnel ciphertext payload and tunnel message authentication code as inputs. The co-processor simultaneously performs decryption and re-computation and comparison of the authentication tag. If the computed tag does not match the tag attached to the packet, it indicates that the data has been tampered with or damaged during transmission, and the packet is immediately discarded and a high-priority security alert log is generated. If the verification is successful, the decrypted plaintext payload is output, which is a complete QSTAP packet with a post-quantum digital signature.

[0069] Second step, post-quantum digital signature verification. The engine submits the decrypted QSTAP packet and its attached post-quantum digital signature to the post-quantum cryptographic operation module. Meanwhile, it finds the sender's long-term post-quantum public key (PQC_longterm_pub) from the local trusted list according to the IP source address or the sender's information in the QSTAP packet header. The post-quantum cryptographic operation module uses the public key and the CRYSTALS-Dilithium verification algorithm to verify the signature. If the signature verification fails, it indicates that the packet is not signed by the claimed sender, or the packet content (even if it is ciphertext) has been tampered with after signing and before tunnel encryption. Similarly, the packet is immediately discarded and recorded as a signature forgery attack event. This step is the key barrier to ensure data authenticity and non-repudiation.

[0070] Third step, application layer decapsulation and verification. After successful signature verification, the security protocol processing engine begins to process the QSTAP packet. It parses the QSTAP packet header to obtain the 8-byte session identifier (SPI) and the 8-byte sequence number. First, the engine compares this sequence number with the last successfully received sequence number of the current session. If it is less than or equal to, it is determined as a replay attack and the packet is discarded. If it is greater, the latest sequence number recorded locally is updated. Next, the corresponding application layer encryption key K_APP_ENC is retrieved from the key management unit according to the SPI. The engine again calls the hardware encryption and decryption coprocessor to perform AES-128-GCM decryption and verification on the ciphertext payload and message authentication code in the QSTAP packet. The QSTAP packet header also participates in the verification as AAD. If the authentication fails, the packet is discarded.

[0071] Fourth step, restore original data and forward. After successful application layer message authentication code verification, the engine finally obtains the decrypted plaintext payload. This payload is the original, unmodified International Electrotechnical Commission 104 protocol application protocol data unit (APDU). By this time, all security encapsulation layers have been peeled off and verified one by one. The security protocol processing engine forwards this pure APDU to the local dispatching host application system or substation monitoring background it protects through an internal physical port. For the local business system, it receives a standard, directly parseable IEC104 packet, as if there was no encryption link in the communication process, thus achieving complete transparency to the existing business system.

[0072] As a preferred embodiment of the present application, in order to ensure that the technical solution can adapt to the complex inventory environment of power grid dispatching data network, realize the smooth transition and seamless integration of new and old systems, the security protocol processing engine of the quantum secure communication terminal internally solidifies a set of refined compatibility strategy control logic. The core of this logic is a "counterpart device capability registry" which can be remotely configured by network administrators. This registry takes the IP address or logical identifier of the counterpart device as the index, and records the security capability level of each counterpart device. When initiating communication, the engine will query this table and set the corresponding mode flag in the "version and compatibility flag field" of the QSTAP packet header according to the query result. There are three working modes:

[0073] First, Full Mode. When the registry shows that the counterpart device is also equipped with a full-featured quantum secure communication terminal as described in the present application, and the quantum channel between the two is normal and can continuously generate keys, the system uses this mode. In this mode, the terminal will fully perform all the security steps described above, including QSTAP encapsulation encryption signature and QSTP tunnel encapsulation encryption, providing the highest level of security protection.

[0074] Second, Hybrid Mode. When the registry shows that the counterpart device is also a quantum secure communication terminal of the same model, but the quantum channel between the two has been interrupted (such as cable failure) or has not been initialized, the system automatically downgrades to this mode. In this mode, the generation of session keys will degenerate into complete reliance on the aforementioned post-quantum cryptography-based key encapsulation mechanism for negotiation. The terminal will only perform QSTAP encapsulation, encryption and signature at the application layer, i.e. complete the third step of data encapsulation and encryption to the sending terminal. After that, the generated protected QSTAP packet will no longer be encapsulated in the QSTP tunnel, but will be directly submitted to the existing longitudinal encryption and authentication device deployed in series with the quantum secure communication terminal, which will use traditional IPsec and other protocols for transport layer encryption. This mode ensures that even in the extreme case of quantum channel failure, the end-to-end security of core business data is still guaranteed.

[0075] Thirdly, the legacy mode. When the registry shows that the opposite end device is a legacy terminal that does not support the method described in the application, and only the legacy longitudinal encryption authentication device is deployed, the system enables this mode. In this mode, the security protocol processing engine of the quantum secure communication terminal will not perform any encapsulation operation of QSTAP or QSTP. It will intercept the local IEC 104 packet as ordinary IP traffic, directly and without modification, to the serially deployed longitudinal encryption authentication device, and complete the traditional network layer tunnel encryption in a transparent bridge manner. This mode enables the new terminal to seamlessly interface with the huge inventory system, supports the power grid to be upgraded and deployed gradually, regionally and in batches, avoiding the huge risks, investment waste and impact on key business continuity caused by "one-size-fits-all" system transformation.

[0076] In order to illustrate the technical advantages of the application, the method of the application and the traditional method are compared.

[0077] 1. Implementation of the method of the application:

[0078] The scenario is set as follows: a dispatching application in a dispatching master station in Beijing needs to send a remote control opening command to a remote terminal unit in a 220kV substation in Tianjin. The two places are connected by a G.652.D standard single-mode optical fiber with a total length of 140km, and the total link attenuation of the optical fiber is 28 decibels. Since the distance exceeds the security transmission limit of single-span QKD, two trusted relay nodes are deployed along the way to divide the entire link into three independent quantum channels. The dispatching master station and the substation both deploy the quantum secure communication terminal described in the application.

[0079] Before operation, the quantum secure communication terminals at both ends first perform the security session establishment step.

[0080] Initial authentication: the master station terminal initiates an initial authentication process based on CRYSTALS-Kyber768 and CRYSTALS-Dilithium2 to the substation terminal. On the FPGA (Spartan Virtex UltraScale+VU9P) built-in the terminal, the average delay of Kyber768 key generation, encapsulation and decapsulation operations is 45 microseconds, 55 microseconds and 50 microseconds respectively. The average delay of Dilithium2 signature and verification operations is 120 microseconds and 60 microseconds respectively. The total time consumption of the entire interaction (request-response) to establish the initial shared secret is about 280 microseconds, plus the network transmission delay.

[0081] Quantum key generation: Three segments of quantum channels simultaneously and in parallel initiate the decoy-state BB84 protocol. The average attenuation of each segment of channel is about 9.3 decibels. The quantum key distribution module works at a frequency of 100 megahertz. In a key generation period of 300 seconds, the system can generate about 1.2x10^6 256-bit session master keys (MSKs) in total according to the performance of the three links, and the average key generation rate is about 4,000 MSKs per second. These keys are stored in the key pool of the key management and synchronization unit.

[0082] Working key derivation: An MSK is taken out of the key pool, and K_APP_ENC, K_APP_MAC, K_TUN_ENC and K_TUN_MAC, four groups of 128-bit working keys, are derived through HKDF-SHA3. This process takes less than 5 microseconds on the network processor.

[0083] When the dispatcher issues a remote opening command, an IEC 104 APDU (10 bytes long) containing the command is generated and sent to the quantum secure communication terminal on the master station side.

[0084] QSTAP encapsulation and encryption: The engine creates a QSTAP header (22 bytes) and uses K_APP_ENC to perform AES-128-GCM encryption on the 10-byte APDU, generating a 10-byte ciphertext and a 16-byte MAC. This step takes about 1.5 microseconds on the hardware co-processor.

[0085] PQC signature: The QSTAP message (22+10+16=48 bytes) is submitted to the post-quantum cryptographic operation module, and a Dilithium2 signature is generated using the long-term private key, generating a 2420-byte signature. This step takes 120 microseconds.

[0086] QSTP encapsulation and encryption: The QSTAP message with signature (48+2420=2468 bytes) is used as the payload, a QSTP header (8 bytes) is added, and AES-128-GCM encryption is performed using K_TUN_ENC. Due to the large payload, this step takes about 8 microseconds.

[0087] Sending: The final IP datagram (total length about 2500 bytes) is sent through the data channel.

[0088] After the quantum secure communication terminal on the substation side receives the IP message, it performs the reverse operation.

[0089] QSTP decryption and verification: It takes about 8 microseconds.

[0090] PQC signature verification: It takes about 60 microseconds.

[0091] QSTAP decryption verification: about 1.5 microseconds.

[0092] Finally, the original 10-byte remote control instruction APDU is successfully restored and sent to the remote terminal unit. From the master station terminal receiving the APDU to the substation terminal forwarding the restored APDU, the total one-way processing delay introduced by the entire security processing process is about 1.5+120+8+8+60+1.5=199 microseconds. This delay can be completely ignored for the real-time requirements of power grid dispatching services.

[0093] 2. Implementation of the traditional method:

[0094] The same dispatching scenario from Beijing to Tianjin is adopted. However, the security protection uses the current technology widely used in the power grid: deploying a vertical encryption authentication device at the network export of the dispatching master station and the substation. The device is based on a commercial firewall platform, uses the IPsec protocol to build a VPN tunnel, the authentication method is RSA-4096 certificate, the encryption algorithm is AES-256-CBC, and the hash algorithm is SHA-256.

[0095] Under this architecture, the IEC 104 remote control instruction APDU (10 bytes) generated by the dispatching master station application is transmitted in plaintext form in the master station intranet. When it reaches the vertical encryption device at the network export, the entire IP packet (containing the plaintext APDU) is encapsulated and encrypted by the IPsec protocol, and then transmitted through the optical fiber data channel. At the substation side, the vertical encryption device decrypts the IPsec packet and restores the original IP packet. The IP packet is then transmitted in plaintext form in the substation intranet and finally reaches the remote terminal unit.

[0096] The one-way processing delay of this scheme is mainly contributed by the encapsulation / decapsulation and encryption / decryption operations of IPsec. Under the same hardware performance, its delay is about 400 microseconds.

[0097] Performance and security comparison of the method of the present application and the traditional method:

[0098] Table 1 quantitatively and qualitatively compares the method of the present application and the traditional method in multiple key dimensions.

[0099] Table 1

[0100]

[0101] Through data comparison of the method and the conventional method, it can be clearly seen that the substation dispatching data network security communication method based on quantum tunnel encryption has fundamental and obvious advantages in the depth of security model, resistance to future threats, protection granularity of key business data, flexibility of deployment, smoothness of system evolution and other aspects compared with the prior art. It not only solves the security short board of the current dispatching data network, but also builds a solid, forward-looking and feasible technical framework for the network security of the next generation power system.

[0102] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Various modifications and changes can be made by those skilled in the art based on the spirit and principles of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for secure communication of a substation dispatching data network based on quantum tunnel encryption, which is applied between a dispatching master station and a substation, wherein both the dispatching master station and the substation are equipped with quantum secure communication terminals, and is characterized in that: The method includes the following steps: establishing a secure session, establishing a secure session context including a session master key and a group of working keys derived from the session master key between the quantum secure communication terminals of the communicating parties; data encapsulation and encryption at the sending end, performing application layer encapsulation encryption and tunnel layer encapsulation encryption on the original telecontrol protocol message from the local service terminal at the sending end to generate a double-layer encrypted datagram to be sent; and decryption and data restoration at the receiving end, performing tunnel layer decryption verification and application layer decryption verification on the received datagram to be sent at the receiving end to restore the original telecontrol protocol message and forward it to the local service terminal.

2. The method according to claim 1, characterized in that The quantum secure communication terminal is internally integrated with: A quantum key distribution module is used to execute a quantum key distribution protocol between the communicating parties through a quantum channel to generate a shared original key; Post-quantum cryptography operation module, used to execute post-quantum cryptography algorithms for identity authentication and digital signature; Security protocol processing engine, used to perform protocol encapsulation, decapsulation, encryption and decryption operations at the application layer and tunnel layer; A key management and synchronization unit, configured to manage and store the session master key and the working key throughout their life cycle; The multi-network interface module is used to provide data channel access capabilities of at least two different physical media and perform link aggregation and fault switching between the data channels.

3. The method according to claim 2, characterized in that The quantum key distribution module executes the phase-encoded decoy state BB84 protocol; When the quantum secure communication terminal is used as a transmitting end, the quantum signal transmitter in the quantum key distribution module uses a narrow linewidth distributed feedback laser with a central wavelength of 1550 nanometers as a light source, phase modulates photons through an asymmetric Mach-Zehnder interferometer, and randomly modulates the intensity of the light pulse to generate a pulse sequence of signal state, decoy state and vacuum state; When the quantum secure communication terminal serves as the receiving end, the quantum signal receiver in the quantum key distribution module uses a superconducting nanowire single-photon detector array with a response wavelength range of 1500 to 1600 nanometers, a dark count rate of less than 100 times per second, and a detection efficiency of more than 20% for basis vector selection and photon detection.

4. The method according to claim 2, characterized in that The post-quantum cryptographic operation module is embedded with a field programmable gate array chip, which has hardware acceleration logic for executing a post-quantum cryptographic algorithm based on modular lattice cryptography. The post-quantum cryptographic operation module specifically performs: A key encapsulation mechanism algorithm based on learning a modular version of the rounding problem is used to securely negotiate a shared secret during the initial authentication phase of establishing the secure session; The digital signature algorithm based on learning a modular version with rounding problem is used to authenticate the communication entity in the establishment of the secure session and to digitally sign the key data message in the data encapsulation and encryption of the sending end.

5. The method according to claim 2, characterized in that The multi-network interface module is physically integrated with: A single-mode optical fiber interface supporting the 1000BASE-LX standard, used to connect the quantum channel with the optical fiber link serving as the primary data channel; A wireless communication module that supports the fifth-generation new air interface standard for mobile communications. This module includes an RF front-end and baseband processor, supports communication in the 3.5 GHz frequency band, and can be used as a backup or primary data transmission channel. The link aggregation and intelligent fault switching logic built into the multi-network interface module periodically monitors the delay, jitter and packet loss rate of each link. When the performance indicators of the main link deteriorate and continue to exceed the preset threshold, it automatically switches the data flow to the backup link seamlessly.

6. The method according to claim 1, characterized in that The secure session establishment specifically includes: Initial authentication and key agreement based on post-quantum cryptography: The quantum secure communication terminal of the communication initiator generates a temporary post-quantum public-private key pair and sends the temporary public key and a random challenge number to the responder; the responder uses its long-term post-quantum private key to digitally sign the received concatenation of the initiator's temporary public key and the challenge number, and uses the initiator's temporary public key to generate a ciphertext encapsulation of the shared secret through the key encapsulation mechanism algorithm, and returns the signature, its own long-term post-quantum public key and the ciphertext encapsulation to the initiator; the initiator authenticates the responder's identity by verifying the signature, and uses its temporary post-quantum private key to decrypt the ciphertext encapsulation to obtain the shared secret, thereby establishing an initial shared secret that has undergone two-way authentication; Quantum key distribution and session master key generation: After successful initial authentication, the quantum key distribution modules of both parties execute the quantum key distribution protocol over the quantum channel. Subsequently, both parties perform basis vector comparison, bit error rate estimation, error bit elimination using low-density parity-check codes, and privacy amplification technology based on a two-way universal hash function over a classical channel protected by the initial shared secret, ultimately generating a 256-bit session master key with unconditional security. Working key derivation: The key management and synchronization units of both parties take the session master key as input, use the extract-extend key derivation function based on the secure hash algorithm 3, and use the session identifier and the identity identifiers of the communicating parties as salt values ​​and information input to derive at least four sets of independent working keys, including: application layer encryption key, application layer message authentication code key, tunnel layer encryption key, and tunnel layer message authentication code key.

7. The method according to claim 6, characterized in that The data encapsulation and encryption at the sending end specifically include: Constructing a quantum secure telecontrol application protocol message: The security protocol processing engine uses the intercepted complete IEC 104 protocol application protocol data unit as a basic payload and creates a quantum secure telecontrol application protocol message header including a version compatibility flag, a session identifier, a sequence number, and a payload length field; Performing application-layer encryption and integrity protection: The security protocol processing engine calls an authenticated encryption algorithm module based on the Advanced Encryption Standard and operating in Galois / Counter mode, uses the application-layer encryption key to encrypt the basic payload, and simultaneously authenticates the quantum secure telecontrol application protocol message header as associated data to generate a ciphertext payload and an application-layer message authentication code; Performing post-quantum digital signature: The security protocol processing engine treats the quantum secure telecontrol application protocol message header, the ciphertext payload, and the application layer message authentication code as a whole data block, calls the post-quantum cryptographic operation module, uses the long-term post-quantum private key of the sender to execute the digital signature algorithm on the data block, generates a post-quantum digital signature, and appends it to the end of the message; Constructing a quantum secure tunnel protocol message: The security protocol processing engine uses the complete quantum secure telecontrol application protocol message that has been encrypted and signed at the application layer as the tunnel layer payload, and creates a quantum secure tunnel protocol message header that only contains a tunnel session identifier; Perform tunnel layer encryption and integrity protection: The security protocol processing engine calls the authentication encryption algorithm module again, uses the tunnel layer encryption key to encrypt the tunnel layer payload, and authenticates the quantum secure tunnel protocol message header as associated data to generate a tunnel ciphertext payload and a tunnel message authentication code; Final encapsulation and transmission: combining the quantum secure tunneling protocol message header, the tunnel ciphertext payload, and the tunnel message authentication code into a complete quantum secure tunneling protocol message, encapsulating it in the payload of an Internet Protocol datagram, and sending it out through the multi-network interface module.

8. The method according to claim 7, characterized in that The receiving end decryption and data restoration specifically include: Tunnel layer decapsulation and verification: The security protocol processing engine extracts the quantum secure tunnel protocol message from the received Internet Protocol datagram, retrieves the corresponding tunnel layer encryption key based on the tunnel session identifier in the message header, and calls the authentication encryption algorithm module to decrypt and verify the tunnel ciphertext payload and tunnel message authentication code. If the verification fails, the message is discarded. If successful, the decrypted, complete quantum secure telecontrol application protocol message is obtained; Post-quantum digital signature verification: The security protocol processing engine calls the post-quantum cryptographic operation module and uses the pre-stored long-term post-quantum public key of the sender to verify the post-quantum digital signature attached to the decrypted quantum secure telecontrol application protocol message. If the verification fails, the message is discarded. Application layer decapsulation and verification: After the signature verification is successful, the security protocol processing engine parses the quantum secure telecontrol application protocol message header, checks the sequence number to prevent replay attacks, retrieves the corresponding application layer encryption key based on the session identifier, and calls the authentication encryption algorithm module to decrypt and verify the ciphertext payload and application layer message authentication code in the message. If the verification fails, the message is discarded; Restore the original data and forward it: After successful application layer verification, the decrypted plaintext payload, that is, the original International Electrotechnical Commission 104 protocol application protocol data unit, is obtained and forwarded to the local service terminal.

9. The method according to claim 8, characterized in that The security protocol processing engine has a built-in compatibility policy control logic based on a configurable peer device capability registry. Based on the results of querying the registry, different operating mode flags are set in the version and compatibility flag fields of the quantum secure telecontrol application protocol message header. The operating modes include: Full mode: When both communicating parties are equipped with the quantum secure communication terminal and the quantum channel between them is available, all the steps in claim 1 are executed; Hybrid mode: This mode is enabled when both communicating parties are equipped with quantum secure communication terminals but the quantum channel between them is unavailable. In this case, the generation of session keys is reduced to negotiation based solely on the key encapsulation mechanism of post-quantum cryptography, and the terminals only perform application-layer encapsulation, encryption, and signing, before handing the protected messages over to the existing serially deployed vertical encryption and authentication devices for transport-layer encryption. Traditional mode: It is enabled when the opposite device is a traditional device that does not support the method of the present invention. At this time, the security protocol processing engine does not perform any encapsulation encryption operation, but directly forwards the intercepted original remote control protocol message to the existing vertical encryption authentication device deployed in serial in the form of a transparent bridge.

Citation Information

Patent Citations

  • 5G quantum security differential protection communication system and communication method

    CN118714556A

  • 5G quantum encryption communication method and device based on RedCap

    CN119277378A

  • Authentication method and system based on Ksession shared session key MAC

    CN119583064A

  • Power grid data secure transmission system and method based on quantum cryptography, and medium

    CN120389855A

  • Anti-quantum tunnel communication security enhancement method and system based on software definition

    CN120434048A

Cited By

  • SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

    CN121283626A

  • IEC104 protocol communication method based on fusion of QRNG and PQC

    CN121619098A

  • IEC104 protocol communication method based on qrng and pqc fusion

    CN121619098B

  • Quantum key distribution and anti-quantum signature secure fusion method

    CN121814463A