A substation relay protection communication authentication method based on continuous variable quantum key distribution

By evaluating channel quality, generating quantum keys, and establishing a mapping relationship between key blocks and frame sequence numbers, quantum authentication is performed on GOOSE messages. This solves the problems of quantum cracking threats and insufficient response time in existing substation communication authentication schemes, and achieves secure and efficient quantum key distribution authentication.

CN122179103AActive Publication Date: 2026-06-09JIANGSU YUANNENG ELECTRIC POWER ENG
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIANGSU YUANNENG ELECTRIC POWER ENG
Filing Date
2026-05-09
Publication Date
2026-06-09

Smart Images

  • Figure CN122179103A_ABST
    Figure CN122179103A_ABST
Patent Text Reader

Abstract

The application discloses a substation relay protection communication authentication method based on continuous variable quantum key distribution, and belongs to the technical field of wireless communication; the method is: evaluating the physical channel quality of each link, screening a safe link; generating quantum keys by using the safe link, and cutting the generated quantum keys according to the key block granularity; adopting a GQA handshake protocol to establish a complete mapping relationship between the key block and the frame sequence number; performing GQA quantum authentication encapsulation on a GOOSE message; and completing the authentication of a receiving end by adopting a three-layer verification mode. The application establishes the mapping relationship between the key block and the frame sequence number by the handshake protocol, the sending end and the receiving end independently calculate the corresponding key block index according to the frame sequence number, any additional key negotiation or synchronous communication is not needed in the message authentication process, the communication of the key block between the sending end and the receiving end is guaranteed, the communication response time is reduced, and the security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of wireless communication technology, specifically relating to a substation relay protection communication authentication method based on continuous variable quantum key distribution. Background Technology

[0002] Substation relay protection systems are the core line of defense for ensuring the safe and stable operation of power systems. Their intelligent electronic devices communicate in real-time via substation event protocol messages for general-purpose applications to achieve critical protection functions such as circuit breaker tripping and fault isolation. These messages are extremely sensitive to latency; the entire response time from fault detection to tripping command execution must be within milliseconds. Any authentication mechanism must not exceed this real-time constraint.

[0003] Current substation communication authentication schemes primarily rely on classical cryptography based on computational complexity assumptions, whose security rests on the computational difficulty of specific mathematical problems. With the development of quantum computing technology, classical public-key cryptography based on problems such as large integer factorization and discrete logarithms faces the potential threat of being efficiently cracked by quantum algorithms. Although post-quantum cryptographic algorithms are being standardized, their security still relies on unproven computational complexity assumptions and cannot provide unconditional security guarantees in the information theory sense. For critical infrastructure such as relay protection that is crucial to power grid security, it is necessary to seek authentication schemes whose security does not depend on any computational complexity assumptions.

[0004] Quantum key distribution (QKD) technology enables information-theoretically secure key sharing between communicating parties based on fundamental principles of quantum mechanics. Its security is guaranteed by physical laws rather than computational assumptions. Continuous-variable QKD schemes employ Gaussian modulation of coherent states and coherent detection, which can be implemented using standard telecommunications optics and are highly compatible with existing fiber optic infrastructure, offering engineering deployment advantages in short-distance multimode fiber optic environments within substations. However, applying continuous-variable QKD to substation relay protection communication authentication faces the following challenges: the single-round complete key negotiation process of QKD takes significantly longer than the millisecond-level response time constraint of relay protection messages, making on-demand real-time negotiation impossible; the QKD hub within the substation forms a one-to-many star topology with multiple intelligent electronic devices, requiring solutions for multi-link independent channel evaluation, key pool management, and key-to-message mapping.

[0005] Therefore, the technical problem that this invention aims to solve is how to seamlessly embed quantum keys into the existing message authentication process without increasing communication overhead, and achieve compatibility with the existing communication protocols of substations. Summary of the Invention

[0006] The purpose of this invention is to provide a substation relay protection communication authentication method based on continuous variable quantum key distribution to solve the problems mentioned in the background art.

[0007] The objective of this invention is achieved as follows: a substation relay protection communication authentication method based on continuous variable quantum key distribution, characterized by the following steps:

[0008] Step S1: Evaluate the physical channel quality of each link, filter secure links, and form a set of secure links;

[0009] Step S2: Generate a quantum key using a secure link, and then divide the generated quantum key into key block granularities and inject them into the corresponding key pools of each link in sequence;

[0010] Step S3: Use the GQA handshake protocol to establish a complete mapping relationship between key blocks and frame sequence numbers;

[0011] Step S4: Perform GQA quantum-certified encapsulation on each GOOSE message sent by the Q-Hub;

[0012] Step S5: Verify the message from the receiving end using a three-layer authentication method to complete the receiver authentication.

[0013] Preferably, in step S1, evaluating the physical channel quality of each link, filtering secure links, and forming a set of secure links specifically involves:

[0014] Calculate the effective channel transmittance for each link: The effective channel transmittance is the product of all loss factors. ;

[0015] in, For the quantum efficiency of coherent detectors. For fiber end-face coupling efficiency, The attenuation coefficient of multimode fiber. The physical length of the optical fiber for each link. , This represents the total number of IEDs. Effective channel transmittance;

[0016] The expression for estimating the noise level in each link channel is: ;

[0017] in, The equivalent contribution of the detector's electronic noise referred to the channel input. For the electronic noise variance of the coherent detector; Contribution to signal variance This refers to the actual working modulation variance used in this round; Normalized variance;

[0018] based on and In the current working modulation variance Calculate the theoretical secure key rate :

[0019] ;

[0020] Among them, the theoretical security key rate This represents the number of secure key bits extracted per quantum pulse under the current channel and modulation parameters. For Q-Hub and The classic mutual information between them; This indicates the lower limit of information coordination efficiency; This is the upper bound of the amount of Holevo information obtained by the eavesdropper under the Gaussian collective attack hypothesis.

[0021] Convert the theoretical secure key rate of a single pulse to a bit key rate: ;

[0022] in, The repetition frequency of the quantum pulse;

[0023] The optimal working modulation variance is solved iteratively using a segmentation search method. ;

[0024] After convergence, the current channel parameters are obtained. Optimal operating modulation variance and the corresponding maximum theoretical security key rate ;

[0025] In optimal working modulation variance Below, to Solving for the noise threshold yields the safety threshold. : ;

[0026] when At that time, the coordination part of Alice-Bob mutual information More information than Holevo, the eavesdropper There is a positive security key margin; when At this point, channel noise has rendered the eavesdropper's information advantage impossible to eliminate through privacy amplification, rendering the link unusable for key distribution; the channel security decision rules are as follows:

[0027] ;in, For a set of secure links.

[0028] Preferably, step S3 uses the GQA handshake protocol to establish a complete mapping relationship between the key block and the frame sequence number, specifically as follows:

[0029] Step S3-1: Generate the initial frame sequence number and construct the handshake request frame, specifically as follows:

[0030] Q-Hub uses a built-in QRNG as its link. Independently generate initial frame sequence The frame sequence number space is a 32-bit unsigned integer space. , Uniformly and randomly selected within this space; Q-Hub slave link Take the first key from the key pool The key pool retrieval strategy is strictly sequential, meaning the first retrieval... The second time it was taken out And so on, skipping or randomly selecting items is not allowed;

[0031] Construct a handshake request frame: ;

[0032] in, The plaintext payload of the handshake request frame, ; For frame sequence number, For link identification, Challenge value, The current time; This indicates the calculation of the HMAC-SHA256 message authentication code for the plaintext payload of the handshake request frame: ;

[0033] Step S3-2: Verify the handshake request frame and construct the handshake response frame;

[0034] Step S3-3: Q-Hub verifies the handshake response frame and constructs a handshake completion confirmation frame;

[0035] Step S3-4: Verify the handshake completion confirmation frame and complete the handshake process, and establish a mapping relationship between the key block and the frame sequence number.

[0036] Preferably, in step S3-2, the handshake request frame is verified and a handshake response frame is constructed. Upon receiving the handshake request frame, the following three-stage verification is performed sequentially. Once all verifications pass, a handshake response frame is constructed, as follows:

[0037] Phase 1: Timeliness Verification Record local reception time ,calculate With frame timestamp The difference, if If the handshake request frame times out, then the handshake request frame is deemed to have timed out. The handshake request frame is discarded, and a timeout notification is returned to the Q-Hub via the classic authentication channel; upon receiving the timeout notification, the Q-Hub will disconnect the link. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number And construct a new handshake request frame and resend it; if the retry count reaches... Then the link If the handshake is marked as failed, the handshake process for that link is terminated and an operational alarm is triggered. It can only be re-initiated after manual intervention. This is the frame transmission timeout threshold. This represents the maximum number of retries for a single-link handshake process.

[0038] The second phase is clock synchronization verification: After the timeliness verification is passed, the Q-Hub and... Clock synchronization verification is performed via the NTP protocol: Q-Hub uses this to estimate the clock discrepancy between the two parties.

[0039] ;

[0040] in, For Q-Hub, record the local timestamp of the NTP request issued. for Record the local timestamp of the received NTP request. For the local timestamp of the NTP response, Record the local timestamp of the received NTP response for Q-Hub; if If the clocks of both parties are too far off, the Q-Hub will wait. Complete NTP clock synchronization convergence; if the waiting time exceeds back Still greater than Then the link Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link If the handshake fails, the handshake process for that link will be terminated and an operational alarm will be triggered. When the clock synchronization verification is successful, proceed to step S3-3; where, The timeout threshold for NTP synchronization;

[0041] The third stage, MAC verification: After the clock synchronization verification is successful. Retrieve the first key from the local key pool. ,by For the key pair received Plaintext payload Recalculate HMAC-SHA256:

[0042] ;

[0043] Calculation results With the frame carried Perform a bit-by-bit comparison; if the comparison is inconsistent, it indicates that the first block of the key between the two parties is inconsistent or the message has been tampered with during transmission. A handshake failure notification is returned to Q-Hub via the classic authentication channel; upon receiving this notification, Q-Hub will disconnect the link. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number And construct a new handshake request frame and resend it; if the retry count reaches... Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0044] If the comparison matches, the MAC verification passes, indicating that... The completeness of the content and the authenticity of the source have been confirmed; Will Mark as handshake used, and continue with the following actions:

[0045] Calculate the challenge response value: from Extract challenge value Retrieve the second key Calculate the challenge response ;

[0046] Constructing the handshake response frame: ;

[0047] Will Send to Q-Hub via the classic authentication channel, and Marked as handshake used.

[0048] Preferably, in step S3-3, the Q-Hub verifies the handshake response frame and constructs the handshake completion confirmation frame, specifically as follows:

[0049] Q-Hub received Then, record the local reception time. And perform the following four verifications in sequence:

[0050] MAC integrity verification: For key pairs Recalculate HMAC-SHA256 and compare the result with the one carried in the frame. Bit-by-bit comparison; if the comparison is inconsistent, it indicates that the contents of the key pools of both parties are inconsistent or the message has been tampered with, and the trustworthiness of the key pool can no longer be guaranteed; Q-Hub will link The key pool is emptied and marked as to be rebuilt, and then the link is... The channel quality assessment is re-executed in step S1, and the channel transmittance measurement, over-noise estimation and security decision are completed in sequence. After the decision is passed, the operations in steps S2 to S3 are re-executed. If the comparison is consistent, the MAC integrity verification is passed and the next step is executed.

[0051] Frame sequence number continuity verification: verification Frame sequence number Is it equal to The Q-Hub verifies that the handshake response frame belongs to the legitimate response of the current handshake session and is not a historical frame replayed by an attacker; if they do not match, the Q-Hub will link... Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number Construct a handshake request frame with a new key block and retransmit it; if the retry count reaches [a certain value], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0052] Challenge response correctness verification: Q-Hub local verification Calculate the key:

[0053] ;and Carried in Bit-by-bit comparison; if the comparison is inconsistent, it indicates... The holdings Inconsistency with Q-Hub poses a risk of man-in-the-middle attacks or key pool corruption; Q-Hub will link... The key pool is emptied and marked as to be rebuilt, and then the link is... Repeat steps S1 to S3;

[0054] Clock Deviation Verification: Q-Hub Extraction Carried in Local timestamp Combined with local sending time The local reception time recorded in this step Based on the round-trip delay of the handshake request frame, the clock offset between the two parties is estimated.

[0055] ;

[0056] in, For Q-Hub side pairing based on the symmetric transmission delay assumption The best estimate of the processing time; if If the clock offset between the two parties is too large, the Q-Hub will link the two devices. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0057] After all four verifications are passed, Q-Hub confirms. It is confirmed that the Q-Hub possesses a key block identical to its own, has correctly received the initial frame sequence number, and that the clock offset between both parties is within acceptable limits; the Q-Hub will Marked as handshake used;

[0058] Q-Hub retrieved the third key. Construct a handshake confirmation frame:

[0059] ;

[0060] in, The plaintext payload of the handshake confirmation frame, Frame sequence number ; A fixed-length 9-byte handshake completion flag string encoded in ASCII; For key calculation, ;

[0061] Q-Hub will Send via classic authentication channel to Afterwards, Marked as handshake used.

[0062] Preferably, in steps S3-4 The handshake confirmation frame is verified, the handshake process is completed, and a mapping relationship between the key block and the frame sequence number is established, specifically as follows:

[0063] receive Then, perform the following verifications in sequence:

[0064] MAC integrity verification: For key pairs Recalculate HMAC-SHA256 and compare it with the one carried in the frame. Bit-by-bit alignment;

[0065] Frame sequence number continuity verification: verification Frame sequence number Is it equal to This confirms that the handshake confirmation frame is a legitimate follow-up response to the current handshake session, and not a historical frame replayed by an attacker.

[0066] Handshake completion flag verification: Verify whether the payload contains Flag string;

[0067] After all three verifications are passed Will Marking the handshake as used confirms the handshake process is complete; after the link i handshake process is completed, Q-Hub and Both parties based their decisions on the confirmed initial frame sequence number. Establish a mapping relationship between key block numbers and frame sequence numbers: ;in, This represents the total number of key blocks.

[0068] Preferably, in step S4, GQA quantum authentication encapsulation is performed on each GOOSE message sent by the Q-Hub, and GQA authentication encapsulation is performed on the sending end. The Q-Hub performs GQA authentication encapsulation on each message sent to the link. Triggered when a GOOSE message is sent, specifically:

[0069] Step S4-1: Obtain the sequence number of the frame to be sent and calculate the pool index of the key block:

[0070] Define Q-Hub maintenance link Frame sequence number counter The initial value is The sequence number increases monotonically after each frame is sent; the sequence number of the current frame to be sent is... Calculate the pool index of the corresponding key block:

[0071] ;

[0072] Each link key pool is Take from the key pool If the verification status is "unused", it is marked as "used" by the sender; if The key pool has been exhausted, so message transmission on this link is suspended and a warning is triggered; among them, The total number of key blocks;

[0073] Step S4-2: From the original message Extract the fields to be authenticated to form the authentication payload. :

[0074] ;

[0075] in, For application identifiers; This is a raw GOOSE protocol data unit; The local timestamp when this frame was sent to Q-Hub; This is a bit string concatenation operation;

[0076] Step S4-3: Obtain the MAC value of this frame, and set the MAC value... With frame sequence number As an extension field for GQA authentication, it is appended to the original GOOSE message to form a GQA enhanced GOOSE message. After encapsulation, it is sent to the classic communication channel. The serial number counter increments. ;

[0077] The expression to retrieve the MAC value of this frame is: ;

[0078] Constructing GQA Enhanced GOOSE Messages The expression is: ;

[0079] in, This refers to the key block granularity.

[0080] Preferably, step S5 employs a three-layer verification method to verify the received message, specifically as follows:

[0081] The three layers of verification are: the first layer verifies the message format and timeliness, the second layer detects frame sequence number replay, and the third layer verifies the integrity and authenticity of the quantum key MAC.

[0082] The first layer is message format and timeliness verification. Message format verification: Check whether the total message length meets the requirements. ;

[0083] in, 32 represents the minimum length of the original GOOSE message; 32 represents the length of the frame sequence number field. For key block granularity;

[0084] After the format verification is passed, the MAC value is extracted from the end of the message. With frame sequence number The main body serves as the original message. If the format verification fails, the frame will be discarded.

[0085] Message timeliness verification: From Extract the Q-Hub sending timestamp from the GOOSEPDU ,by Local clock reads the received time Calculate message transmission delay: ;

[0086] like The message is then deemed expired and the frame is discarded. This is the message timeliness threshold;

[0087] Messages that pass the first-level verification will proceed to the second-level frame sequence number replay detection. The second-level frame sequence number replay detection is as follows: Maintain the set of sequence numbers of successfully received frames. and the current maximum received frame sequence number ,right The following judgment shall be executed:

[0088] ;

[0089] The first rule ensures accurate replay of historical frames within the detection window; the second rule discards expired frames that exceed the historical window to prevent attackers from bypassing window detection with expired historical frames; other cases include... New frames and out-of-order frames not appearing within the window are allowed to continue MAC verification; among them... To replay the detection sliding window width, indicating The current maximum received frame sequence number The range of previously retained historical serial number records;

[0090] Key block index and MAC verification: by Calculate the index within the corresponding key block pool: ,take out If it has already been marked as used by the receiver, it is determined to be an out-of-window exact replay frame and is discarded directly; otherwise, the authentication payload is reconstructed. And calculate the expected MAC value: ,Will With the message carried Perform bit-by-bit constant-time comparison verification: ;

[0091] Verification result processing: MAC verification passed: [The following text appears to be a separate, unrelated sentence:] ... Mark as used by the receiver, update and The original GOOSE message deliver The upper-level relay protection application executes the corresponding protection actions;

[0092] MAC verification failed: Discard the frame. Keep it in an unused state and log failure events. If the link In the sliding window The cumulative number of failures exceeded Q-Hub marked the link as abnormal and triggered an operation and maintenance alarm;

[0093] Frame sequence number space management: When the frame sequence number near At that time, the Q-Hub triggers the link. Repeat step S3 to generate a new initial frame sequence number. Reset the serial number space to prevent wraparound from causing security vulnerabilities.

[0094] Compared with the prior art, the present invention has the following improvements and advantages:

[0095] 1. A fixed mapping relationship between key blocks and frame sequence numbers is established through a handshake protocol. The sending end and the receiving end independently calculate the corresponding key block index based on the frame sequence number. No additional key negotiation or synchronization communication is required during the message authentication process, ensuring communication of key blocks between the sending end and the receiving end.

[0096] 2. The message authentication code is calculated using a unique quantum key block for each message frame. The key block is strictly used only once, and the authentication security does not depend on any computational complexity assumptions, thus ensuring the security of the key block. At the same time, the time-consuming quantum key negotiation process is completed in the initialization phase through the key pool pre-filling mechanism. When the message is sent, only one key block index lookup and one message authentication code calculation are required, reducing the response time requirement. Attached Figure Description

[0097] Figure 1 This is a flowchart illustrating the method of the present invention.

[0098] Figure 2 A structural comparison diagram of the GQA-enhanced GOOSE frame format and the standard IEC 61850 GOOSE frame format.

[0099] Figure 3 For Q-Hub and A schematic diagram illustrating the process of establishing a static mapping relationship between key block indexes and frame sequence numbers.

[0100] Figure 4 This diagram illustrates the comparison of the success rate of forgery under different key block lengths.

[0101] Figure 5This diagram illustrates the comparison between two indicators: authentication processing delay and the probability of successful forgery.

[0102] Figure 6 A heatmap diagram illustrating the security scoring of the GQA quantum certification scheme.

[0103] Figure 7 A thermal diagram illustrating the delay in the authentication process for the GQA quantum authentication scheme. Detailed Implementation

[0104] The invention will be further summarized below with reference to the accompanying drawings.

[0105] like Figure 1 As shown, a substation relay protection communication authentication method based on continuous variable quantum key distribution is presented. The method includes the following steps:

[0106] In step S1, the physical channel quality of each link is evaluated, secure links are selected, and a set of secure links is formed. Specifically, this is manifested as follows:

[0107] In the substation relay protection system, the quantum key distribution hub Q-Hub serves as the key distribution center node. It is connected point-to-point with each intelligent electronic device (IED) through indoor multimode optical fiber. Each IED undertakes core protection functions such as circuit breaker tripping and fault isolation. The authentication key of its control message is uniformly distributed by Q-Hub.

[0108] To evaluate the channel quality of point-to-point fiber optic links, the physical fiber optic connections between the indoor multimode fiber optic Q-Hub and various intelligent electronic devices (IEDs) within the substation are first abstracted into a star node topology. The set of nodes in the indoor multimode fiber optic topology is as follows: ,in, The total number of IEDs; Q-Hub is the central node, and each intelligent electronic device (IED) is abstracted as a relay protection terminal node, expressed as: Each Q-Hub to The fiber optic links constitute an independent quantum key distribution channel;

[0109] The core task of this step is to solve two fundamental problems that precede quantum key distribution: the Q-Hub and various... The question of whether the indoor multimode fiber channel possesses the physical conditions for securely generating quantum keys, and what modulation parameters, under current channel conditions, can maximize the key generation rate, is addressed as follows:

[0110] Q-Hub acts as the sender Alice, and various As the receiver, Bobc independently performs channel evaluation on each link based on the GG02 protocol framework:

[0111] Calculate the effective channel transmittance for each link: The effective channel transmittance is the product of all loss factors. ;

[0112] in, For the quantum efficiency of coherent detectors. The fiber end-face coupling efficiency characterizes the efficiency of optical signals coupling from the optical fiber into the detector optical system, and is obtained through actual measurement and calibration. The multimode fiber attenuation coefficient is determined by the selected fiber type and operating wavelength. The physical length of the optical fiber for each link. , This represents the total number of IEDs. Effective channel transmittance is a comprehensive measure of the signal attenuation caused by fiber transmission loss, optical coupling loss, and detector quantum efficiency. It is a core parameter describing the physical quality of the channel in the GG02 protocol security proof.

[0113] Estimate the noise level of each link channel: For The normalized variance is obtained by statistically analyzing the measurement results of the orthogonal components in the current round. In normalized variance After subtracting the vacuum fluctuation background, signal variance contribution, and detector electronic noise reduction term, the channel over-noise is obtained: ;

[0114] in, The equivalent contribution of the detector's electronic noise referred to the channel input. The electronic noise variance of the coherent detector is obtained through actual measurement and calibration under shading. Contribution to signal variance This refers to the actual working modulation variance used in this round;

[0115] Calculating the theoretical secure key rate: based on and In the current working modulation variance Calculate the theoretical secure key rate : ;

[0116] Among them, the theoretical security key rate It represents the net number of secure key bits that can be extracted from each quantum pulse under the current channel and modulation parameters. Its physical meaning is the remainder after deducting the amount of information that can be obtained by the eavesdropper from the Alice-Bob mutual information. For Q-Hub and The classic mutual information between them , For the total equivalent noise, and Each noise component corresponds strictly; This represents the lower limit of information coordination efficiency, serving as a coordination efficiency parameter to ensure that the theoretical prediction value is a conservative estimate. The upper bound of the Holevo information that an eavesdropper can obtain under the Gaussian collective attack hypothesis:

[0117] ;

[0118] in, For the von Neumann entropy auxiliary function, Q-Hub and The first and second symplectic eigenvalues ​​of the joint state covariance matrix; They are respectively The first and second symplectic eigenvalues ​​of the end-conditional covariance matrix; each symplectic eigenvalue is derived from... , , Calculate as follows:

[0119] ; ;

[0120] ; ;

[0121] in, Equivalent additional noise for heterodyne detection; joint state The symplectic eigenvalues ​​are:

[0122] ;

[0123] conditional state The symplectic eigenvalues ​​are:

[0124] ;

[0125] in, The conditional covariance matrix determinant is given by... , , and The security proof formula for standard Gaussian state CV-QKD is used; the derivation of the above symplectic eigenvalues ​​follows the security analysis framework of the GG02 protocol under Gaussian collective attack.

[0126] Convert the theoretical secure key rate of a single quantum pulse to a bit key rate: ;

[0127] in, The repetition frequency of the quantum pulse;

[0128] Obtaining the optimal working modulation variance: Based on function property analysis: With modulation variance The value increases monotonically, but its growth rate gradually slows down. Similarly, with modulation variance It increases with increasing amplitude, and its growth rate exceeds [a certain percentage] in the high modulation variance region. The growth rate; the difference between the two , This represents the lower limit of information coordination efficiency, serving as a coordination efficiency parameter to ensure that the theoretical prediction value is a conservative estimate; therefore, it exhibits a unimodal characteristic of first increasing and then decreasing. The optimal working modulation variance is solved iteratively using a segmentation search method.

[0129] ;

[0130] After iterative convergence, the current channel parameters are obtained. Optimal operating modulation variance and the corresponding maximum theoretical security key rate ; within the search range There exists one and only one modulation variance in memory. make The maximum value obtained is the maximum theoretical security key rate. ;

[0131] Channel security decision: This is a necessary condition for the link to be used for quantum key distribution, under optimal working modulation variance. Below, to Solving for the noise threshold yields the safety threshold. : ;

[0132] when At that time, the reconcilable part of the Alice-Bob interaction information More information than Holevo, the eavesdropper There is a security key reserve; when At that point, channel noise has rendered the eavesdropper's information advantage impossible to eliminate through privacy amplification, rendering the link unusable for key distribution; the decision rule is as follows:

[0133] ;

[0134] The set of secure links is defined as follows: ;

[0135] Links marked as unavailable The system will not proceed to the next step. Instead, it will record the reason for the rejection and trigger an operation and maintenance alarm, prompting on-site personnel to check the status of the fiber optic link or investigate potential sources of interference.

[0136] After completing this step, you will have a complete understanding of the physical channel characteristics and optimal operating parameters of each security link.

[0137] In step S2, a quantum key is generated using a secure link, and the generated quantum key is divided into key block granularity and injected sequentially into the key pool corresponding to each link. Specifically, this is manifested as follows:

[0138] The purpose of this step is to resolve the structural contradiction between CV-QKD key negotiation and the real-time constraints of relay protection: the time taken for a single round of complete key negotiation in CV-QKD ranges from hundreds of milliseconds to several seconds, far exceeding the 4ms response time constraint of GOOSE messages. If the on-demand real-time negotiation mode is adopted, the authentication mechanism will be unusable under the real-time constraint.

[0139] Determine the number of quantum pulses in this round and prepare quantum states: Define the target quantity for key replenishment in this round. The difference between the target storage size and the current storage size of the key pool: ,in, For link The current storage size of the key pool at the start of this round. This represents the target storage size of the key pool; it aims to ensure that the amount of key generated in a single round meets the replenishment needs of that round as much as possible. It should meet the following requirements:

[0140] ;

[0141] in, This refers to the key block granularity, which is the bit length of each key block in the key pool. The total number of quantum pulses; Indicates the maximum theoretical security key rate;

[0142] Determine the total number of quantum pulses Then, Q-Hub connects the links. Independent preparation Gaussian-modulated coherent states:

[0143] The two orthogonal components of the phase space are sampled independently: ,by Gaussian-modulated coherent states prepared in phase space coordinates The expression is: ,in, These are the orthogonal components of the real part; These are the orthogonal components of the imaginary part;

[0144] Completed Gaussian-modulated coherent state sequence Quantum pulses are transmitted sequentially via indoor multimode optical fiber to their corresponding locations, according to their numerical order. Q-Hub retains all preparation values ​​locally. .

[0145] Quantum pulses were measured and basis alignment was performed using heterodyne detection. Received quantum pulse sequence Then, each quantum pulse is measured using heterodyne detection; heterodyne detection refers to the interference of the local oscillator light and the signal light in a 90° optical mixer to simultaneously obtain... and Measurement values ​​of the biorthogonal components;

[0146] quantum pulse , The measurement results of the bioorthogonal components are obtained simultaneously through heterodyne detection. The measurement results of the two components are described by the following channel models: , ;

[0147] in, The noise is the independent synthesized noise on each orthogonal component. The synthesized noise includes the vacuum fluctuation background, the channel over-noise reduction term, and the detector electronic noise. The variance of the synthesized noise is: ;

[0148] Heterodyne detection of all quantum pulses was completed, and a biorthogonal component measurement sequence was obtained. Because Alice had already prepared each quantum pulse during the fabrication stage... and All were recorded, and The corresponding heterodyne detection was also obtained. and The data from both sides exhibit corresponding correlations on both orthogonal components, eliminating the need for classical channel alignment measurement basis selection to screen effective quantum pulses. All quantum pulse data can be retained across their biorthogonal components, thus increasing the number of effective quantum pulses. ;

[0149] The biorthogonal component measurement data of each quantum pulse is expanded into a single-component data sequence, and the expansion rules are as follows: for the k-th quantum pulse ( ), and take its q component as the first The nth independent data point, p component as the nth Each independent data point, processed according to this rule for all The quantum pulses are sequentially expanded to obtain Each single-component data pair; after expansion, the Alice end prepares a value sequence denoted as... , The sequence of end measurements is denoted as The correspondence between each element and the original two-component data is as follows:

[0150] , ;

[0151] in, Expanded data pairs sequence This forms the original relevant data basis for subsequent key extraction;

[0152] Parameter estimation and security verification of data pairs: After basis alignment, the data pairs held by both parties... In the middle, Alice's and of There are differences introduced by channel noise, and the measured values ​​of channel transmittance and channel noise in this round have not yet been determined, so key extraction cannot be performed directly; this operation extracts a portion of the data pair sequence to estimate the actual channel parameters in this round, and verifies whether the secure key generation conditions are met in this round.

[0153] from Randomly selected from data pairs data pairs are used as parameter estimation samples, denoted as ... The set of indexes of the randomly selected estimated samples is denoted as . Both parties publicly disclose the complete value of the sample through a classic authentication channel; Alice publicly discloses... , public This ensures that both parties can obtain complete sample data pairs;

[0154] Using publicly available sample data pairs as input, estimate the actual channel transmittance in this round. and actual channel noise The optimal working modulation variance used in this round of preparation The Alice-Bob mutual information estimate for this round was obtained. Holevo information estimates for Eve Then, the actual usable security key rate for this round is calculated: ;

[0155] Verify the safety of this round of operations:

[0156] ;

[0157] when If the channel noise exceeds the security threshold, the security key cannot be extracted. The system discards all data from this round and re-executes the channel security decision to check for persistent channel anomalies; this is used for parameter estimation. All data pairs are discarded regardless of the verification result to prevent publicly available data from contaminating the security of the final key. The remaining number of valid data pairs that can be used for key extraction is: The corresponding valid data pair sequence is denoted as ,in, The set of remaining indices after removing the estimated samples;

[0158] Information Coordination: After the parameter estimation verification is passed, both parties hold... Group related data However, due to the presence of channel noise, and Differences exist between them, making direct use as a shared key impossible. These differences are eliminated through information exchange over a classic channel, aligning the relevant continuous measurements into identical original key bit strings. This process is called information coordination. Information coordination is achieved using reverse multidimensional coordination combined with multi-level LDPC codes.

[0159] Depend on Will exist After joint rotation encoding in 3D space, LDPC check information is generated and sent to Alice. Alice uses the check information to... Correct to Consistency, actual coordination efficiency must meet After coordination, the effective mutual information on Alice's side is: ;

[0160] After the information coordination was completed, Alice and Both parties possess the same original key data, with a length of [length missing]. bit; at this point, the original key has not yet achieved information-theoretic security, because the eavesdropper Eve may have obtained some information from the intercepted data of the quantum channel and the coordination information on the classical channel, and Eve's information advantage can be eliminated through privacy amplification.

[0161] Privacy Amplification: After information coordination is completed, although Alice and The same original key was shared, but eavesdropper Eve may have obtained partial information about the original key through quantum channel eavesdropping and classical coordination channel monitoring. This operation compresses the original key into a shorter final key using privacy amplification. This compression dilutes Eve's residual information to a negligible level. The primary task of privacy amplification is to determine the length of the compressed final key. The security proof from the Gaussian collective attack demonstrates that the maximum number of securely extractable bits from the original key is . Based on this, deduct the safety margin. Additional compression required The final key length is obtained as follows: ;

[0162] when If the channel parameters in this round are insufficient to support the extraction of the security key, the data in this round should be discarded and the channel security decision should be re-executed.

[0163] when At that time, in a definite Constructing Privacy Amplification Operators: Alice and A randomly generated [data] is negotiated through the classic authentication channel. 3D Toeplitz matrix As a general linear hash function, when information coordination is complete, the output held by each party is of length [length missing]. The original key bit vector of bit, denoted as For the original key bit vector Perform linear compression: The final key vector is obtained. Alice and Both parties independently possess identical final keys that satisfy information-theoretic security. , length is The bit can be injected into the key pool.

[0164] Key block splitting and key pool injection: Currently, both parties hold a key block of length... The final quantum key of bit To facilitate subsequent steps of retrieving data frame by frame according to frame sequence number, According to key block granularity Sequentially split into several key blocks, with insufficient remaining after splitting. The last bit of data is discarded;

[0165] The total number of key blocks that can be injected in this round is: The key blocks are numbered in temporary order according to the generation order. The corresponding link is injected block by block for each index in the pool. The key pool, with each key block initially marked as unused, forms the following data structure: ,in, This represents the total number of key blocks accumulated across all injection rounds; a temporary sequential number is used here instead of a frame sequence number, and the random starting value of the frame sequence number is generated by QRNG during the handshake; after completing the key block injection for this round, the system checks the current key pool storage. Has it been achieved? If this is not achieved, then the process for establishing the link begins from the quantum state preparation step. Restart a new round of key generation until the key pool has accumulated a certain amount of storage. After pre-filling, Q-Hub and Both parties each hold a sequence of identical key blocks, which are stored in their local key pools in numerical order.

[0166] like Figure 2 , Figure 3 As shown, step S3 uses the GQA handshake protocol to establish a complete mapping relationship between the key block and the frame sequence number, specifically as follows:

[0167] Q-Hub and various Both parties possess identical key block sequences. Key blocks are numbered in temporary sequence. This is an index within the pool, and its status is marked as unused. At this time, the binding relationship between the key block and the GOOSE frame has not been established, the consistency of the key pools of both parties has not been explicitly verified, and the clock alignment status of both parties has not been confirmed. Therefore, the conditions for performing message authentication are not met.

[0168] This step addresses the three issues mentioned above using the GQA handshake protocol: generating random column initial frame sequence numbers using QRNG. A mapping relationship between key blocks and frame numbers is established, and a challenge-response mechanism for quantum key protection is used to verify the consistency of keys between the two parties. NTP timestamps are used to confirm clock alignment. The Q-Hub acts as the handshake initiator. As the responder to the handshake, each link's handshake process is independent and can be executed in parallel. The classic messages throughout the handshake process are transmitted through an independent classic authentication channel within the substation.

[0169] Step S3-1: Generate initial frame sequence number and construct handshake request frame: Q-Hub uses built-in QRNG as the link Independently generate initial frame sequence The frame sequence number space is a 32-bit unsigned integer space. , Uniformly and randomly selected within this space;

[0170] Q-Hub from the link Take the first key from the key pool. The key pool retrieval strategy is strictly sequential, meaning the first retrieval... The second time it was taken out And so on, skipping or randomly selecting items is not allowed;

[0171] Q-Hub generates 128-bit random challenge values ​​using QRNG. This challenge value is used for Prove that they do indeed possess the agreed-upon key;

[0172] Frame sequence number Link Identifier Challenge Value and current timestamp Assembled as plaintext payload ;

[0173] by Using the key, calculate the HMAC-SHA256 message authentication code for the plaintext payload: ;

[0174] The completed handshake request frame is: ;

[0175] Q-Hub will Send via classic authentication channel to Simultaneously record the sending time. .

[0176] Step S3-2, which verifies the handshake request frame and constructs the handshake response frame, specifically involves:

[0177] receive Then, the following three-stage verification is performed in sequence. After all three stages pass, a handshake response frame is constructed:

[0178] Phase 1: Timeliness Verification Record local reception time ,calculate With frame timestamp The difference, if If the frame times out, it is determined that the frame has timed out. The frame is discarded, and a timeout notification is returned to Q-Hub via the classic authentication channel; upon receiving the timeout notification, Q-Hub will disconnect the link. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number And construct a new handshake request frame and resend it; if the retry count reaches... Then the link If the handshake is marked as failed, the handshake process for that link is terminated and an operational alarm is triggered. It can only be re-initiated after manual intervention. This is the frame transmission timeout threshold.

[0179] The second phase, clock synchronization verification: After the timeliness verification is passed, the Q-Hub and... Clock synchronization verification via NTP protocol: Q-Hub records the local timestamp of the NTP request. , Record the local timestamp of the received NTP request. and the local timestamp of the NTP response Q-Hub records the local timestamp of the received NTP response. Q-Hub uses this to estimate the clock discrepancy between the two devices:

[0180] ;

[0181] like If the clocks of both parties are too far off, the Q-Hub will wait. Complete NTP clock synchronization convergence; if the waiting time exceeds back Still greater than Then the link Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link If the handshake fails, the handshake process for that link will be terminated and an operational alarm will be triggered. When the clock synchronization verification is successful, proceed to step S3-3; where, Set the timeout threshold for NTP synchronization.

[0182] The third stage is MAC verification: after the clock synchronization verification is passed, Retrieve the first key from the local key pool. ,by For the key pair received Plaintext payload Recalculate HMAC-SHA256:

[0183] ;

[0184] Calculation results With the frame carried Perform a bit-by-bit comparison; if the comparison is inconsistent, it indicates that the first block of the key between the two parties is inconsistent or the message has been tampered with during transmission. A handshake failure notification is returned to Q-Hub via the classic authentication channel; upon receiving this notification, Q-Hub will disconnect the link. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number And construct new Frame retransmission; if the retry count reaches [a certain threshold]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0185] If the comparison matches, the MAC verification passes, indicating that... The completeness of the content and the authenticity of the source have been confirmed; Will Mark as handshake used, and continue with the following actions:

[0186] Calculate the challenge response value: from Extract challenge value Retrieve the second key block. Calculate the challenge response ;

[0187] Constructing the handshake response frame: ;

[0188] Will Send to Q-Hub via the classic authentication channel, and Marked as handshake used.

[0189] Step S3-3: The Q-Hub verifies the handshake response frame and constructs a handshake completion confirmation frame, specifically as follows:

[0190] Q-Hub received Then, record the receiving time. Retrieve the second key block. Perform the following four verifications in sequence:

[0191] MAC integrity verification: For key pairs Recalculate HMAC-SHA256 and compare the result with the one carried in the frame. Bit-by-bit comparison; if the comparison is inconsistent, it indicates that the contents of the key pools of both parties may be inconsistent or the messages may have been tampered with, and the trustworthiness of the key pools can no longer be guaranteed; Q-Hub will link The key pool is emptied and marked as to be rebuilt, and then the link is... Return to step S1 and re-execute the channel quality assessment, sequentially completing the channel transmittance measurement, over-noise estimation, and security decision. After passing the decision, re-execute steps S2 to S3. If the comparison is consistent, the MAC integrity verification passes and the next step is executed.

[0192] Frame sequence number continuity verification: verification Frame sequence number Is it equal to This confirms that the handshake response frame is a legitimate response to the current handshake session and not a historical frame replayed by an attacker.

[0193] If they are inconsistent, Q-Hub will link Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number Construct a handshake request frame with a new key block and retransmit it; if the retry count reaches [a certain value], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0194] Challenge response correctness verification: Q-Hub local verification Calculate the key:

[0195] ;and Carried in Bit-by-bit comparison; if the comparison is inconsistent, it indicates... The holdings Inconsistency with Q-Hub poses a risk of man-in-the-middle attacks or key pool misalignment; Q-Hub will link... The key pool is emptied and marked as to be rebuilt, and then the link is... Repeat steps S1 to S3;

[0196] Clock Deviation Verification: Q-Hub Extraction Carried in Local timestamp Combined with local sending time The local reception time recorded in this step Based on the round-trip delay of the handshake request frame, the clock offset between the two parties is estimated.

[0197] ;

[0198] in, For Q-Hub side pairing based on the symmetric transmission delay assumption The best estimate of the processing time; if If the clock offset between the two parties is too large, the Q-Hub will link the two devices. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0199] After all four verifications are passed, Q-Hub confirms. It is confirmed that the Q-Hub possesses a key block identical to its own, has correctly received the initial frame sequence number, and that the clock offset between the two parties is within acceptable limits; the Q-Hub will Marked as handshake used;

[0200] Q-Hub retrieves the 3rd key block. Construct a handshake confirmation frame:

[0201] ;

[0202] in, For plaintext payload, Frame sequence number ; A fixed-length 9-byte handshake completion flag string encoded in ASCII; For key calculation, ;

[0203] Q-Hub will Send via classic authentication channel to Afterwards, Marked as handshake used.

[0204] In steps S3-4 The verification handshake confirmation frame completes the handshake process and establishes a mapping relationship between the key block and the frame sequence number, specifically as follows:

[0205] Upon receiving the handshake confirmation frame, the following verifications are performed sequentially:

[0206] MAC integrity verification: For key pairs Recalculate HMAC-SHA256 and compare it with the one carried in the frame. Bit-by-bit alignment;

[0207] Frame sequence number continuity verification: verification Frame sequence number Is it equal to This confirms that the handshake confirmation frame is a legitimate follow-up response to the current handshake session, and not a historical frame replayed by an attacker.

[0208] Handshake completion flag verification: Verify whether the payload contains Flag string;

[0209] If any verification fails, then A handshake failure notification is returned to Q-Hub via the classic authentication channel. Q-Hub increments the retry count for link i by 1. If the retry count has not been reached... Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm;

[0210] After all three verifications are passed Will Mark as handshake used, confirming the handshake process is complete;

[0211] After the link i handshake process is completed, Q-Hub and Both parties based their decisions on the confirmed initial frame sequence number. Establish a mapping relationship between key block numbers and frame sequence numbers:

[0212] ;

[0213] The mapping relationship serves as the index basis for the sequence number to the key block in step S4: the frame sequence number is... The GOOSE message uses the number in the key pool Authentication is performed on the key block;

[0214] The handshake process consumes the first 3 key blocks in total. , , All of them have been marked as handshake used in steps S3-3 to S3-5 respectively, and subsequent message authentication operations will start from the 4th key. They are retrieved sequentially, and the corresponding first frame sequence number is:

[0215] ;

[0216] The mapping relationship ensures that when the Q-Hub sends a frame with a sequence number of 1, 2, 3, 4 When sending a GOOSE message, both parties can independently calculate the key block number to be used. This allows direct retrieval from the local key pool. This eliminates the need to negotiate the key via the classic channel during each authentication, thus avoiding additional communication delays introduced during the authentication process.

[0217] After the handshake process is completed, the initial storage capacity of the key pool available for message authentication is:

[0218] ;

[0219] At this point, Q-Hub and various IEDi ( A complete mapping relationship between key blocks and frame sequence numbers has been established synchronously between them. Sequence number of the first frame of each link The fourth key has been confirmed. All key blocks are currently unused, fulfilling all the prerequisites for message authentication.

[0220] In step S4, GQA quantum-certified encapsulation is performed on each GOOSE message sent by the Q-Hub, specifically as follows:

[0221] It is responsible for performing GQA quantum-certified encapsulation on each GOOSE message sent by the Q-Hub, and for... Each received GQA-enhanced GOOSE message undergoes authentication verification and decapsulation. The core encapsulation mechanism is as follows: the corresponding key block is indexed by the current frame sequence number, the MAC is calculated for the key fields of the message and appended to the original message; the receiving end independently recalculates the MAC using the same key block and compares it to verify the authenticity of the message's source, the integrity of its content, and the freshness of its sequence. Since each message uses a unique key block, GQA quantum authentication achieves unconditionally secure message authentication in an information theory sense, and its security does not depend on any computational complexity assumptions.

[0222] The sending end performs GQA authentication encapsulation, which is performed by Q-Hub on each link. Triggered when a GOOSE message is sent, the specific process is as follows:

[0223] Frame sequence number allocation and key block index: Q-Hub maintenance link Frame sequence number counter The initial value is The sequence number increases monotonically after each frame is sent; a sequence number is assigned to the current frame to be sent. Calculate the index within the corresponding key block pool: Take from the key pool If the verification status is "unused", it is marked as "used" by the sender; if The key pool has been exhausted. The transmission of messages on this link will be suspended and a warning will be triggered. The link will resume after manual intervention.

[0224] From the original message Extract the fields to be authenticated to form the authentication payload. :

[0225] ;in, The application identifier is a unique identifier for the publisher of a GOOSE message as defined by the IEC 61850 standard. This is a raw GOOSE protocol data unit, containing a timestamp. Status number Serial Number and dataset All business data fields; The frame sequence number; The local timestamp when this frame was sent to Q-Hub; This is a bit string concatenation operation;

[0226] Calculate MAC: For key pairs Calculate HMAC-SHA256 and take the first half. As the MAC value for this frame: ;

[0227] Message encapsulation and transmission: Frame sequence number With MAC value As a GQA authentication extension header, it is appended to the original GOOSE message to form a GQA enhanced GOOSE message. : After encapsulation, it is sent to the classic communication channel. The serial number counter increments. .

[0228] Step S5 employs a three-layer authentication method to verify the received message, completing the receiver authentication process. Specifically:

[0229] Format verification and field extraction: The total length of the verification message must not be less than the sum of the minimum length of the original GOOSE message and the length of the GQA authentication header; otherwise, it will be discarded. The GQA authentication header consists of a frame sequence number field and a MAC value field, occupying a fixed area. After the format verification is passed, the message is split into three parts: the message body is recorded as the original message to be verified. The frame sequence number appended to the end of the message is denoted as The MAC value appended to the end of the message is denoted as ;

[0230] Replay attack detection: Maintain the set of sequence numbers of successfully received frames. and the current maximum received frame sequence number ,right The following judgment shall be executed:

[0231] .

[0232] The first rule ensures accurate replay of historical frames within the detection window; the second rule discards expired frames that exceed the historical window to prevent attackers from bypassing window detection with expired historical frames; other cases include... New frames and out-of-order frames not appearing within the window are allowed to continue MAC verification; among them... The width of the sliding window for replay detection indicates the IED. i The current maximum received frame sequence number The range of previously retained historical serial number records;

[0233] Key block index and MAC verification: by Calculate the index within the corresponding key block pool: ,take out If it has already been marked as used by the receiver, it is determined to be an out-of-window exact replay frame and is discarded directly; otherwise, the authentication payload is reconstructed. And calculate the expected MAC value: ,Will With the message carried Perform bit-by-bit constant-time comparison verification: ;

[0234] Verification result processing: MAC verification passed: [The following text appears to be a separate, unrelated sentence:] ... Mark as used by the receiver, update and The original GOOSE message deliver The upper-level relay protection application executes the corresponding protection actions;

[0235] MAC verification failed: Discard the frame. Keep it in an unused state and log failure events. If the link In the sliding window The cumulative number of failures exceeded Q-Hub marked the link as abnormal and triggered an operation and maintenance alarm.

[0236] Frame sequence number space management: Q-Hub continuously monitors the link Frame sequence number counter ,when At that time, the Q-Hub triggers the link. Serial number space reset process: Q-Hub pauses link New message transmission is achieved through the built-in QRNG for the link. Regenerate the initial frame sequence number and follow the complete handshake process from steps S3-1 to S3-5. The mapping relationship between the key block and the new frame sequence number is re-established; after the handshake is completed, message transmission is resumed with the new initial frame sequence number. The sliding window and replay detection state under the original sequence number space are cleared and re-initialized with the new sequence number space to prevent sequence number wraparound from causing security vulnerabilities; among them, To reserve a safety margin of frames.

[0237] To verify the effectiveness of the method of the present invention, comparative experiments were conducted under the following simulation environment:

[0238] Key block length exist Values ​​are taken within the bit range; the simulation platform is based on the IEC 61850 substation communication architecture, and GOOSE messages are encapsulated according to the IEC 61850-8-1 standard; the quantum key is generated by the BB84 protocol distribution module and pre-stored in the key pools of the sender and receiver.

[0239] The comparison schemes include: Scheme B: IEC 62351-6 digital signature scheme, which uses RSA / ECDSA asymmetric signature to authenticate GOOSE messages, and is the recommended scheme of the current IEC international standard; Scheme C: an ablation version of the method of this invention that removes the one-time use constraint of the quantum key pool, that is, allows the key block to be reused in multiple authentications, and the remaining steps are consistent with the method of this invention; Scheme D: the original GOOSE protocol without authentication, that is, the original protocol of IEC 61850-8-1, which does not deploy any message authentication mechanism; Scheme E: the pre-shared key HMAC scheme, which uses a classic pre-shared symmetric key to perform HMAC operation for message authentication, and the key is pre-injected offline.

[0240] like Figure 4 As shown, the probability of successful forgery With key block length The changes show that the method of the present invention (Scheme A) is significantly better than all the comparison schemes in the entire test range of 32-256 bits; the five curves show clear hierarchical separation on logarithmic coordinates, with Scheme A at the bottom and the largest downward slope;

[0241] exist At the bit location, the probability of successful forgery using the method of this invention is: The probability of successful forgery is higher than that of scheme B. It was reduced by approximately 32 orders of magnitude; At the bit position, the probability of successful forgery by the method of the present invention is further reduced to Compared to Option B This represents a reduction of approximately 66 orders of magnitude, demonstrating that the security advantage of the method in this invention continues to increase with the key block length. Ablation scheme C in... The probability of successful forgery at bit is This is approximately 10 orders of magnitude higher than the method of this invention, indicating that the one-time use mechanism of the quantum key pool contributes 10 orders of magnitude in security gain. The probability of successful forgery under the same parameters for scheme E is... This is approximately 17 orders of magnitude higher than the method of this invention. Scheme D does not deploy any authentication mechanism, so the probability of successful forgery is always 1, allowing attackers to forge messages unconditionally.

[0242] The above results verify that the quantum key one-time pad authentication mechanism used in this invention can maintain a strictly linear relationship between the effective number of secure bits and the key block length. This fundamentally eliminates the security bit reduction problem caused by key reuse and algorithm implementation constraints in classical cryptographic schemes.

[0243] like Figure 5 As shown, when considering both authentication processing latency and the probability of successful forgery, the method of this invention demonstrates a significant advantage in breaking the traditional trade-off between security and latency.

[0244] exist At bit position, the authentication processing delay of the method of this invention is 91. The probability of successful forgery is Compared to Option B, the delay is 1897. Probability of forgery These improvements represent increases of 95.2% and 32 orders of magnitude, respectively; Solution E has a delay of 49 seconds under the same parameters. The probability of counterfeiting is 46% lower than that of the method of this invention, but its probability of counterfeiting is lower. The method of this invention is 17 orders of magnitude higher than that of the present invention; the method of this invention uses 42 The delay increment is traded for a safety gain of 17 orders of magnitude. Within the 4 ms time limit for Class A protection messages specified in the IEC 61850-5 standard, this increment accounts for only 1.05% of the limit, which is a completely acceptable engineering loss.

[0245] from Figure 5 The bar chart further reveals that the delay of scheme B increases with... The increase exhibits a significant non-linear growth, from 653 at 32 bits. Climbing to 3423 at 256 bits ;exist At bit 1, the delay of Scheme B has exceeded the IEC 61850-5 Class A real-time limit of 3000. This no longer meets the real-time requirements of substation protection communication. However, the delay in the method of this invention remains consistently between 65 and 125 seconds. The range is only 2.2%–4.2% of the IEC limit, providing ample real-time margin across all parameter ranges.

[0246] The method of this invention employs a quantum key pre-distribution architecture, moving the computationally intensive key negotiation process to an offline stage. The online authentication stage only requires lightweight symmetric cryptographic operations, thus simultaneously achieving information-theory-level security and sub-millisecond latency. In contrast, Scheme B requires the generation and verification of asymmetric signatures for each authentication, with computational complexity increasing superlinearly with key length, resulting in a sharp deterioration in latency that inevitably comes with improved security.

[0247] Figure 6 The security scores of four authentication schemes (A, B, C, and E) with eight key block lengths are displayed in the form of a heatmap. Row correspondence scheme, column correspondence The color gradation transitions from light warm colors (low rating, low safety) to deep cool colors (high rating, high safety); for example... Figure 6 As shown, the row containing the method of this invention is displayed in the darkest shade across all columns, with the safety score ranging from... The 9.6 linear climb at bit 1 to At bit 77.1, the color gradient is uniform and has the largest slope; schemes C and E decrease sequentially. The scores for the bit values ​​are 57.8 and 42.3 respectively; Scheme B has the lowest score across all parameters. The bit depth is only 11.6, and the color gradation always stays in the light warm color area; the color gradation between the four rows is clearly distinguishable, and the row of the method of the present invention forms the strongest visual contrast with the row of scheme B, indicating that the method of the present invention has a security dominance over the current standard scheme in the entire parameter space.

[0248] Figure 7 The heatmap illustrates the processing delays of four authentication schemes (A, B, C, and E). The color swatches use a segmented mapping, 0-200. The low-latency range is mapped to the green color system, 200-3600. High-latency ranges are mapped to a yellow-to-red color scheme to fully demonstrate the subtle differences between low-latency solutions; for example... Figure 7 As shown, the three lines of this invention (Scheme A), Scheme C, and Scheme E are all presented in green, with delay values ​​concentrated between 31 and 125. The differences among the three ranges are all sub-millisecond in an engineering sense. Row B transitions from yellow to dark red, corresponding to 653-3423. The delayed span creates a distinct color scheme differentiation from the other three schemes. When the bit is used, the grid points of Scheme B are marked with diagonal shading, indicating that its delay has exceeded the IEC 61850-5 Class A real-time limit.

[0249] comprehensive Figure 6and Figure 7 Based on the information, in a grid of 32 evaluation points consisting of 4 schemes × 8 parameters, the method of this invention achieves the best performance across all 32 grid points in the security dimension; in the delay dimension, the absolute value of the method of this invention (65-125) Although slightly higher than scheme E (31-74) Scheme C (60-119) However, it only accounts for 2.2%–4.2% of the IEC limit, which is far below the safety margin range of engineering constraints; while Scheme B is the worst among all schemes in terms of both safety and delay. The above panoramic analysis further verifies the robustness and comprehensive superiority of the method of the present invention in the full parameter space.

[0250] Based on the simulation results above, the method of this invention, through a quantum key pool one-time pad authentication mechanism and a lightweight online verification architecture, outperforms the current IEC international standard digital signature scheme in both the probability of successful forgery and the authentication processing latency. This fundamentally breaks through the inherent trade-off in classical authentication systems where security improvements inevitably come at the cost of increased latency. Ablation experiments further confirm that the one-time use constraint of quantum keys is the key source of the aforementioned security gains, and full-parameter heatmap analysis verifies the robustness and consistency of this advantage across the entire test parameter space.

[0251] The above description is merely an embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of the claims of the present invention.

Claims

1. A substation relay protection communication authentication method based on continuous variable quantum key distribution, characterized in that: The method includes the following steps: Step S1: Evaluate the physical channel quality of each link, filter secure links, and form a set of secure links; Step S2: Generate a quantum key using a secure link, and then divide the generated quantum key into key block granularities and inject them into the corresponding key pools of each link in sequence; Step S3: Use the GQA handshake protocol to establish a complete mapping relationship between key blocks and frame sequence numbers; Step S4: Perform GQA quantum-certified encapsulation on each GOOSE message sent by the Q-Hub; Step S5: Verify the message from the receiving end using a three-layer authentication method to complete the receiver authentication.

2. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 1, characterized in that: In step S1, the physical channel quality of each link is evaluated, secure links are selected, and a set of secure links is formed. Specifically, this involves: Calculate the effective channel transmittance for each link: The effective channel transmittance is the product of all loss factors. ; in, For the quantum efficiency of coherent detectors. For fiber end-face coupling efficiency, The attenuation coefficient of multimode fiber. The physical length of the optical fiber for each link. , This represents the total number of IEDs. Effective channel transmittance; The expression for estimating the noise level in each link channel is: ; in, The equivalent contribution of the detector's electronic noise referred to the channel input. The electronic noise variance of the coherent detector; Contribution to signal variance This refers to the actual working modulation variance used in this round; Normalized variance; based on and In the current working modulation variance Calculate the theoretical secure key rate : ; Among them, the theoretical security key rate This represents the number of secure key bits extracted per quantum pulse under the current channel and modulation parameters. For Q-Hub and The classic mutual information between them; This indicates the lower limit of information coordination efficiency; This is the upper bound of the amount of Holevo information obtained by the eavesdropper under the Gaussian collective attack hypothesis. Convert the theoretical secure key rate of a single pulse to a bit key rate: ; in, The repetition frequency of the quantum pulse; The optimal working modulation variance is solved iteratively using a segmentation search method. ; After convergence, the current channel parameters are obtained. Optimal operating modulation variance and the corresponding maximum theoretical security key rate ; In optimal working modulation variance Below, to Solving for the noise threshold yields the safety threshold. : ; when At that time, the coordination part of Alice-Bob mutual information More information than Holevo, the eavesdropper There is a positive security key margin; when At this point, channel noise has rendered the eavesdropper's information advantage impossible to eliminate through privacy amplification, rendering the link unusable for key distribution; the channel security decision rules are as follows: ;in, For a set of secure links.

3. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 1, characterized in that: In step S3, the GQA handshake protocol is used to establish a complete mapping relationship between the key block and the frame sequence number, specifically as follows: Step S3-1: Generate the initial frame sequence number and construct the handshake request frame, specifically as follows: Q-Hub uses a built-in QRNG as its link. Independently generate initial frame sequence The frame sequence number space is a 32-bit unsigned integer space. , Uniformly and randomly selected within this space; Q-Hub slave link Take the first key from the key pool The key pool retrieval strategy is strictly sequential, meaning the first retrieval... The second time it was taken out And so on, skipping or randomly selecting items is not allowed; Construct a handshake request frame: ; in, The plaintext payload of the handshake request frame, ; For frame sequence number, For link identification, Challenge value, The current time; This indicates the calculation of the HMAC-SHA256 message authentication code for the plaintext payload of the handshake request frame: ; Step S3-2: Verify the handshake request frame and construct the handshake response frame; Step S3-3: Q-Hub verifies the handshake response frame and constructs a handshake completion confirmation frame; Step S3-4: Verify the handshake completion confirmation frame and complete the handshake process, and establish a mapping relationship between the key block and the frame sequence number.

4. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 3, characterized in that: In step S3-2, the handshake request frame is verified and a handshake response frame is constructed. Upon receiving the handshake request frame, the following three-stage verification is performed sequentially. Once all verifications pass, a handshake response frame is constructed, as follows: Phase 1: Timeliness Verification Record local reception time ,calculate With frame timestamp The difference, if If the handshake request frame times out, then the handshake request frame is deemed to have timed out. The handshake request frame is discarded, and a timeout notification is returned to the Q-Hub via the classic authentication channel; upon receiving the timeout notification, the Q-Hub will disconnect the link. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number And construct a new handshake request frame and resend it; if the retry count reaches... Then the link If the handshake is marked as failed, the handshake process for that link is terminated and an operational alarm is triggered. It can only be re-initiated after manual intervention. This is the frame transmission timeout threshold. This represents the maximum number of retries for a single-link handshake process. The second phase is clock synchronization verification: After the timeliness verification is passed, the Q-Hub and... Clock synchronization verification is performed via the NTP protocol: Q-Hub uses this to estimate the clock discrepancy between the two parties. ; in, The Q-Hub records the local timestamp of the NTP request issued. for Record the local timestamp of the received NTP request. For the local timestamp of the NTP response, Record the local timestamp of the received NTP response for Q-Hub; if If the clocks of both parties are too far off, the Q-Hub will wait. Complete NTP clock synchronization convergence; if the waiting time exceeds back Still greater than Then the link Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link If the handshake fails, the handshake process for that link will be terminated and an operational alarm will be triggered. When the clock synchronization verification is successful, proceed to step S3-3; where, The timeout threshold for NTP synchronization; The third stage, MAC verification: After the clock synchronization verification is successful. Retrieve the first key from the local key pool. ,by For the key pair received Plaintext payload Recalculate HMAC-SHA256: ; Calculation results With the frame carried Perform a bit-by-bit comparison; if the comparison is inconsistent, it indicates that the first block of the key between the two parties is inconsistent or the message has been tampered with during transmission. A handshake failure notification is returned to Q-Hub via the classic authentication channel; upon receiving this notification, Q-Hub will disconnect the link. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number And construct a new handshake request frame and resend it; if the retry count reaches... Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm; If the comparison matches, the MAC verification passes, indicating that... The completeness of the content and the authenticity of the source have been confirmed; Will Mark as handshake used, and continue with the following actions: Calculate the challenge response value: From Extract challenge value Retrieve the second key Calculate the challenge response ; Constructing the handshake response frame: ; Will Send to Q-Hub via the classic authentication channel, and Marked as handshake used.

5. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 3, characterized in that: In step S3-3, the Q-Hub verifies the handshake response frame and constructs the handshake completion confirmation frame, specifically as follows: Q-Hub received Then, record the local reception time. And perform the following four verifications in sequence: MAC integrity verification: For key pairs Recalculate HMAC-SHA256 and compare the result with the one carried in the frame. Bit-by-bit comparison; if the comparison is inconsistent, it indicates that the contents of the key pools of both parties are inconsistent or the message has been tampered with, and the trustworthiness of the key pool can no longer be guaranteed; Q-Hub will link The key pool is emptied and marked as to be rebuilt, and then the link is... The channel quality assessment is re-executed in step S1, and the channel transmittance measurement, over-noise estimation and security decision are completed in sequence. After the decision is passed, the operations in steps S2 to S3 are re-executed. If the comparison is consistent, the MAC integrity verification is passed and the next step is executed. Frame sequence number continuity verification: verification Frame sequence number Is it equal to This confirms that the handshake response frame is a legitimate response to the current handshake session and not a historical frame replayed by an attacker. If they are inconsistent, Q-Hub will link Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number Construct a handshake request frame with a new key block and retransmit it; if the retry count reaches [a certain value], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm; Challenge response correctness verification: Q-Hub local verification Calculate the key: ;and Carried in Bit-by-bit comparison; if the comparison does not match, it indicates The holdings Inconsistency with Q-Hub poses a risk of man-in-the-middle attacks or key pool corruption; Q-Hub will link... The key pool is emptied and marked as to be rebuilt, and then the link is... Repeat steps S1 to S3; Clock Deviation Verification: Q-Hub Extraction Carried in Local timestamp Combined with local sending time The local reception time recorded in this step Based on the round-trip delay of the handshake request frame, the clock offset between the two parties is estimated. ; in, For Q-Hub side pairing under the assumption of symmetric transmission delay The best estimate of the processing time; if If the clock offset between the two parties is too large, the Q-Hub will link the two devices. Increment the retry count by 1 if the retry count has not been reached. Then it is a link. Regenerate the initial frame sequence number and construct a new handshake request frame to retransmit; if the retry count reaches [a certain threshold], [the frame will be retransmitted]. Then the link Mark as handshake failure, terminate the handshake process of this link and trigger an operation and maintenance alarm; After all four verifications are passed, Q-Hub confirms. It is confirmed that the Q-Hub possesses a key block identical to its own, has correctly received the initial frame sequence number, and that the clock offset between both parties is within acceptable limits; the Q-Hub will Marked as handshake used; Q-Hub retrieved the third key. Construct a handshake confirmation frame: ; in, The plaintext payload of the handshake confirmation frame, Frame sequence number ; A fixed-length 9-byte handshake completion flag string encoded in ASCII; For key calculation, ; Q-Hub will Send via classic authentication channel to Afterwards, Marked as handshake used.

6. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 3, characterized in that: In step S3-4 The handshake confirmation frame is verified, the handshake process is completed, and a mapping relationship between the key block and the frame sequence number is established, specifically as follows: receive Then, perform the following verifications in sequence: MAC integrity verification: For key pairs Recalculate HMAC-SHA256 and compare it with the one carried in the frame. Bit-by-bit alignment; Frame sequence number continuity verification: verification Frame sequence number Is it equal to This confirms that the handshake confirmation frame is a legitimate follow-up response to the current handshake session, and not a historical frame replayed by an attacker. Handshake completion flag verification: Verify whether the payload contains Flag string; After all three verifications are passed Will Mark as handshake used, confirming the handshake process is complete; After the link i handshake process is completed, Q-Hub and Both parties based their decisions on the confirmed initial frame sequence number. Establish a mapping relationship between key block numbers and frame sequence numbers: ;in, This represents the total number of key blocks.

7. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 1, characterized in that: In step S4, GQA quantum authentication encapsulation is performed on each GOOSE message sent by the Q-Hub. The sending end performs GQA authentication encapsulation, and the Q-Hub performs this encapsulation on each link. Triggered when a GOOSE message is sent, specifically: Step S4-1: Obtain the sequence number of the frame to be sent and calculate the pool index of the key block: Define Q-Hub maintenance link Frame sequence number counter The initial value is The sequence number increases monotonically after each frame is sent; the sequence number of the current frame to be sent is... Calculate the pool index of the corresponding key block: ; Each link key pool is Take from the key pool If the verification status is "unused", it is marked as "used" by the sender; if The key pool has been exhausted, so message transmission on this link is suspended and a warning is triggered; among them, The total number of key blocks; Step S4-2: From the original message Extract the fields to be authenticated to form the authentication payload. : ; in, For application identifiers; This is a raw GOOSE protocol data unit; The local timestamp when this frame was sent to Q-Hub; This is a bit string concatenation operation; Step S4-3: Obtain the MAC value of this frame, and set the MAC value... With frame sequence number As an extension field for GQA authentication, it is appended to the original GOOSE message to form a GQA enhanced GOOSE message. After encapsulation, it is sent to the classic communication channel. The serial number counter increments. ; The expression to retrieve the MAC value of this frame is: ; Constructing GQA Enhanced GOOSE Messages The expression is: ; in, This refers to the key block granularity.

8. The substation relay protection communication authentication method based on continuous variable quantum key distribution according to claim 1, characterized in that: In step S5, a three-layer verification method is used to verify the message received by the receiving end, specifically as follows: The three layers of verification are: the first layer verifies the message format and timeliness, the second layer detects frame sequence number replay, and the third layer verifies the integrity and authenticity of the quantum key MAC. The first layer is message format and timeliness verification. Message format verification: Check whether the total message length meets the requirements. ; in, 32 represents the minimum length of the original GOOSE message; 32 represents the length of the frame sequence number field. For key block granularity; After the format verification is passed, the MAC value is extracted from the end of the message. With frame sequence number The main body serves as the original message. If the format verification fails, the frame will be discarded. Message timeliness verification: From Extract the Q-Hub sending timestamp from the GOOSEPDU ,by Local clock reads the received time Calculate message transmission delay: ; like The message is then deemed expired and the frame is discarded. This is the message timeliness threshold; Messages that pass the first-level verification will proceed to the second-level frame sequence number replay detection. The second-level frame sequence number replay detection is as follows: Maintain the set of sequence numbers of successfully received frames. and the current maximum received frame sequence number ,right The following judgment shall be executed: ; The first rule ensures accurate replay of historical frames within the detection window; the second rule discards expired frames that exceed the historical window to prevent attackers from bypassing window detection with expired historical frames; other cases include... New frames and out-of-order frames not appearing within the window are allowed to continue MAC verification; among them... To indicate the width of the sliding window for replay detection, The current maximum received frame sequence number The range of previously retained historical serial number records; Key block index and MAC verification: by Calculate the index within the corresponding key block pool: ,take out If it has already been marked as used by the receiver, it is determined to be an out-of-window exact replay frame and is discarded directly; otherwise, the authentication payload is reconstructed. And calculate the expected MAC value: ,Will With the message carried Perform bit-by-bit constant-time comparison verification: ; Verification result processing: MAC verification passed: [The following text appears to be a separate, unrelated sentence:] ... Mark as used by the receiver, update and The original GOOSE message deliver The upper-level relay protection application executes the corresponding protection actions; MAC verification failed: Discard the frame. Keep it in an unused state and log failure events. If the link In the sliding window The cumulative number of failures exceeded Q-Hub marked the link as abnormal and triggered an operation and maintenance alarm; Frame sequence number space management: When the frame sequence number near At that time, the Q-Hub triggers the link. Repeat step S3 to generate a new initial frame sequence number. Reset the serial number space to prevent wraparound from causing security vulnerabilities.

Citation Information

Patent Citations

  • Method, device and equipment for optimizing quantum key distribution handshake protocol

    CN120811606A

  • Certificateless post-quantum TLS handshake method based on KEM and IBE

    CN121603205A

  • Authentication method and system, a quantum communication network, and a node for quantum communication

    US20230275752A1

  • Systems, methods, kits, and apparatuses for edge-distributed storage and querying in value chain networks

    WO2022240906A1