Power grid operation and maintenance repair network security protection method and system integrated with information encryption
By utilizing channel reciprocity to generate dynamic physical layer keys in the power grid operation and maintenance emergency repair network, and then using physical layer waveform encoding to encrypt and transmit business data, the problem of data transmission being easily intercepted or cracked is solved, thus improving the security and anti-cracking capability of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QINGHAI HUANGHUA ELECTRICAL IND CO
- Filing Date
- 2026-04-08
- Publication Date
- 2026-07-03
Smart Images

Figure CN122340460A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security protection technology, specifically to a network security protection method and system for power grid operation, maintenance and emergency repair that integrates information encryption. Background Technology
[0002] Power grid operation and maintenance networks undertake crucial tasks such as fault location, status monitoring, emergency repair scheduling, and transmission of service instructions. In practical applications, they must complete service data interaction in a complex, open, and dynamically changing communication environment. Data transmitted in such networks typically exhibits strong real-time characteristics and sensitivity. If a dynamic encryption protection mechanism combined with the communication channel status is lacking during transmission, and the network relies primarily on relatively fixed or static security protection methods, it becomes difficult to adjust protection measures in a timely manner according to changes in link status. This makes transmitted data more susceptible to interception or cracking during communication, thereby affecting the security and reliability of power grid operation and maintenance service transmission. Summary of the Invention
[0003] This application provides a network security protection method and system for power grid operation and maintenance emergency repair with integrated information encryption. It is used to address the technical problem in the prior art that the power grid operation and maintenance emergency repair network lacks a dynamic encryption protection mechanism that combines with the communication channel status during data transmission, which makes the transmitted data easy to be intercepted or cracked.
[0004] In view of the above problems, this application provides a network security protection method and system for power grid operation, maintenance and emergency repair with integrated information encryption.
[0005] The first aspect of this application provides a network security protection method for power grid operation, maintenance, and emergency repair with integrated information encryption, the method comprising:
[0006] Between the communication transmitter and receiver in the power grid operation and maintenance emergency repair network, pilot signals are exchanged to estimate the communication channel between them, extract the channel impulse response, and generate a first dynamic physical layer key using channel reciprocity. At the communication transmitter, power grid operation and maintenance emergency repair service data to be transmitted is acquired. Based on the first dynamic physical layer key, the service data is physically encoded to generate an implicitly encrypted transmission waveform. The implicitly encrypted transmission waveform is transmitted from the communication transmitter to the communication receiver via the communication channel. The communication receiver receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key consistent with that of the communication transmitter. At the communication receiver, the transmission waveform is implicitly decrypted based on the second dynamic physical layer key to recover the service data.
[0007] A second aspect of this application provides a network security protection system for power grid operation, maintenance, and emergency repair with integrated information encryption, the system comprising: The first key generation module is used to estimate the communication channel between the communication transmitter and receiver in the power grid operation and maintenance emergency repair network by exchanging pilot signals, extracting the channel impulse response, and generating a first dynamic physical layer key using channel reciprocity. The waveform encoding module is used to acquire the power grid operation and maintenance emergency repair service data to be transmitted at the communication transmitter, and to perform physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate an implicitly encrypted transmission waveform. The second key generation module is used to send the implicitly encrypted transmission waveform from the communication transmitter to the communication receiver via the communication channel. The communication receiver receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key consistent with that of the communication transmitter. The implicit decryption module is used at the communication receiver to implicitly decrypt the transmission waveform according to the second dynamic physical layer key to recover the service data.
[0008] One or more technical solutions provided in this application have at least the following technical effects or advantages: This application establishes a communication transmission mechanism between a power grid operation and maintenance emergency repair network and a communication receiver. This mechanism involves exchanging pilot signals to estimate the communication channel between the two parties, extracting the channel impulse response, and generating a first dynamic physical layer key using channel reciprocity. At the communication transmission end, power grid operation and maintenance emergency repair service data to be transmitted is acquired. Based on the first dynamic physical layer key, the service data is physically encoded into a waveform to generate an implicitly encrypted transmission waveform. The communication transmission end then transmits the implicitly encrypted transmission waveform to the communication receiver via the communication channel. The communication receiver receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key identical to that of the communication transmission end. Finally, at the communication receiver, the transmission waveform is implicitly decrypted based on the second dynamic physical layer key to recover the service data. This invention addresses the technical problem in existing power grid operation and maintenance networks where the lack of a dynamic encryption protection mechanism that integrates with the communication channel status during data transmission makes transmitted data vulnerable to interception or cracking. By generating a dynamic physical layer key based on the reciprocity of the communication channels between the two parties, and using this key to perform physical layer waveform encoding encryption for transmission of business data, the invention achieves the technical effect of improving the security and anti-cracking capability of data transmission in power grid operation and maintenance networks. Attached Figure Description
[0009] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1 A schematic flowchart of a network security protection method for power grid operation, maintenance and emergency repair with integrated information encryption provided in this application embodiment; Figure 2 A schematic diagram of the structure of a network security protection system for power grid operation, maintenance and emergency repair with integrated information encryption, provided in an embodiment of this application.
[0011] Explanation of reference numerals in the attached diagram: First key generation module 11, waveform encoding module 12, second key generation module 13, implicit decryption module 14. Detailed Implementation
[0012] This application provides a network security protection method and system for power grid operation and maintenance emergency repair networks with integrated information encryption. It addresses the technical problem in existing technologies where power grid operation and maintenance emergency repair networks lack a dynamic encryption protection mechanism that combines communication channel status during data transmission, making transmitted data vulnerable to interception or cracking. By generating a dynamic physical layer key based on the channel reciprocity between the communicating parties, and using this key to perform physical layer waveform encoding encryption for transmission of business data, the application achieves the technical effect of improving the data transmission security and anti-cracking capability of power grid operation and maintenance emergency repair networks.
[0013] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0014] It should be noted that any variation of the terms "comprising" and "having" is intended to cover non-exclusive inclusion, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such processes, methods, products, or devices.
[0015] Example 1, as Figure 1 As shown, this application provides a network security protection method for power grid operation, maintenance, and emergency repair with integrated information encryption. The method includes: Step S100: Between the communication transmitter and receiver of the power grid operation and maintenance emergency repair network, the communication channel between the two parties is estimated by exchanging pilot signals, the channel impulse response is extracted, and the first dynamic physical layer key is generated by using channel reciprocity.
[0016] In this embodiment, between the communication transmitter and receiver of the power grid operation and maintenance network, the communication channel between them is estimated by exchanging pilot signals. Specifically, the communication transmitter sends a first pilot signal to the communication receiver, which estimates the downlink channel and extracts the downlink channel impulse response based on the signal. The communication receiver then sends a second pilot signal to the communication transmitter, which estimates the uplink channel and extracts the uplink channel impulse response based on the signal. After extracting the channel impulse responses between the two parties, the communication transmitter and the communication receiver quantize the downlink channel impulse response and the uplink channel impulse response, respectively, to generate an original key sequence. Then, information negotiation is performed through a public channel, and the original key sequence is corrected for consistency to obtain a negotiated key sequence. Based on channel reciprocity, the negotiated key sequence is subjected to privacy amplification processing to generate a first dynamic physical layer key.
[0017] Furthermore, in the method provided in the application embodiments, between the communication transmitter and the communication receiver of the power grid operation and maintenance emergency repair network, the communication channel between the two parties is estimated by exchanging pilot signals, the channel impulse response is extracted, and a first dynamic physical layer key is generated using channel reciprocity, further comprising: The communication transmitter sends a first pilot signal to the communication receiver, and the communication receiver estimates the downlink channel based on the first pilot signal and extracts the downlink channel impulse response. The communication receiver sends a second pilot signal to the communication transmitter, and the communication transmitter estimates the uplink channel based on the second pilot signal and extracts the uplink channel impulse response. The communication transmitter and the communication receiver respectively quantize the downlink channel impulse response and the uplink channel impulse response to generate an original key sequence. Then, they negotiate information through a public channel and perform consistency correction on the original key sequence to obtain a negotiated key sequence. The negotiated key sequence is then subjected to privacy amplification processing to generate the first dynamic physical layer key.
[0018] In this embodiment, the communication transmitter sends a first pilot signal to the communication receiver. The first pilot signal is a pre-set known reference signal sequence. After receiving the first pilot signal, the communication receiver uses the least squares estimation method to calculate the frequency response estimate of the downlink channel according to the error square minimization criterion between the received signal and the locally stored reference copy of the first pilot signal. The frequency response estimate is then subjected to inverse Fourier transform to convert the frequency domain response to the time domain and extract the downlink channel impulse response. The downlink channel impulse response is used to characterize the multipath delay, amplitude attenuation, and phase change characteristics of the downlink channel.
[0019] The receiving end sends a second pilot signal to the transmitting end. This second pilot signal is a pre-set known reference signal sequence. After receiving the second pilot signal, the transmitting end uses the least squares estimation method to calculate the frequency response estimate of the uplink channel based on the criterion of minimizing the squared error between the received signal and the locally stored reference copy of the second pilot signal. The transmitting end then performs an inverse Fourier transform on the frequency response estimate to convert the frequency domain response to the time domain and extracts the uplink channel impulse response. This uplink channel impulse response is used to characterize the multipath delay, amplitude attenuation, and phase change characteristics of the uplink channel.
[0020] Subsequently, the transmitting and receiving ends of the communication network quantize the extracted downlink and uplink channel impulse responses, respectively. Specifically, for each sampling point in the channel impulse response, a quantization interval is set based on the amplitude information estimated by the channel. Each quantization interval corresponds to a fixed-length bit sequence. The amplitude sample value of each sampling point is mapped to the corresponding quantization interval, and the corresponding bit sequence is output, thereby converting the continuous channel impulse response measurements into a discrete binary sequence. For example, if the amplitude range is set to 0 to 1, divided into four uniform quantization intervals with boundaries of 0, 0.25, 0.5, 0.75, and 1, each interval corresponds to a 2-bit sequence 00, 01, 10, and 11, respectively. When the amplitude sample value of a certain sampling point is 0.3, it falls within the 0.25 to 0.5 interval, and the bit sequence 01 is output. All sampling points are processed sequentially in the above manner to form a binary sequence. The transmitting end generates a first original key sequence, and the receiving end generates a second original key sequence. The first original key sequence is the first sequence, and the second original key sequence is the second sequence. This process generates an original key sequence, which includes a first sequence and a second sequence.
[0021] Next, information negotiation is conducted through a public channel to perform consistency correction on the original key sequence. During this process, the first and second sequences are extracted from the original key sequence, divided into blocks, and parity bits for each block are calculated. The sending and receiving ends exchange parity bits through the public channel to locate inconsistent blocks. Within these inconsistent blocks, a binary search method is used to check and correct inconsistent bits bit by bit until both key sequences are completely consistent, generating the negotiated key sequence.
[0022] Finally, privacy amplification processing is performed on the negotiated key sequence. In this process, the length of the negotiated key sequence is defined as the first length. The communication sender and receiver use the same hash function to perform hash operation on the negotiated key sequence to generate a hash value, and extract a bit sequence of a preset second length from the hash value as the first dynamic physical layer key.
[0023] Furthermore, in the method provided in the application embodiments, the process of negotiating information through a public channel and performing consistency correction on the original key sequence to obtain a negotiated key sequence further includes: Extract the first sequence and the second sequence from the original key sequence, wherein the first sequence corresponds to the communication sender and the second sequence corresponds to the communication receiver; divide the first sequence and the second sequence into blocks and calculate the parity check bit for each block; the communication sender and the communication receiver exchange the parity check bit through a public channel to locate inconsistent blocks; within inconsistent blocks, use a binary search method to check and correct inconsistent bits bit by bit until the key sequences of both parties are completely consistent, thereby generating the negotiated key sequence.
[0024] In this embodiment, a first sequence and a second sequence are first extracted from the original key sequence. The first sequence corresponds to the communication sender, and the second sequence corresponds to the communication receiver. Next, the first and second sequences are divided into blocks. The communication sender and receiver each divide their respective sequences into multiple data blocks according to a preset block length. For example, a 1024-bit sequence is divided into 32 data blocks of 32 bits each. A parity bit is calculated for each data block. The parity bit is obtained by counting the number of binary 1s in the bit sequence within the data block and taking the modulo 2. If the number of 1s in the data block is odd, the parity bit is 1; if it is even, the parity bit is 0. This is used to characterize the parity of the data block using a single bit.
[0025] Subsequently, the sending and receiving ends exchange the parity bits of each data block they have calculated through a public channel. A public channel refers to an information transmission channel between the two parties that can be eavesdropped by a third party but does not need to be kept confidential. The two parties compare the parity bits of data blocks at the same position one by one. For example, in 32 data blocks, if the two parties find that the parity bits of the 5th, 12th, and 28th data blocks are inconsistent, then these three data blocks are identified as inconsistent blocks. If the parity bits of the remaining data blocks are consistent, they are determined to be consistent blocks and no further processing is required.
[0026] Within an inconsistent block, a binary search method is used for verification. The transmitting and receiving ends divide the inconsistent data block into two sub-blocks, calculate the parity check bit for each sub-block, and exchange them through a public channel. Based on the comparison result of the parity check bits, the sub-block containing the inconsistent bit is located. The binary search method is repeated for this sub-block to gradually narrow down the range of inconsistent bits until the specific inconsistent bit is located. For example, for the 5th data block, which is 32 bits long, both parties first divide it into two sub-blocks: the first 16 bits and the last 16 bits. After swapping the parity bits of the two sub-blocks, a comparison is made and it is found that the parity bits of the first 16-bit sub-block are the same, while the parity bits of the last 16-bit sub-block are different. Therefore, the inconsistent bit is located in the last 16-bit sub-block. Then, this 16-bit sub-block is further divided into two sub-blocks: the first 8 bits and the last 8 bits. After swapping the parity bits, the 8-bit sub-block containing the inconsistent bit is located. This process is repeated, and after 5 binary search operations, the specific inconsistent bit is located. After the location is completed, the first sequence held by the communication sender is used as the reference sequence. The communication sender sends the index information of the location of the inconsistent bit through a public channel. The communication receiver corrects the bit value at the corresponding position in the second sequence to be the same as the bit value at the corresponding position in the first sequence. Repeat the above binary search verification operation until all inconsistent bits in inconsistent blocks are corrected. At this point, the first sequence held by the communication sender and the second sequence held by the communication receiver are completely consistent, and both parties output the corrected consistent sequence as the negotiation key sequence.
[0027] Furthermore, in the method provided in the application embodiment, the method of performing privacy amplification processing on the negotiated key sequence to generate the first dynamic physical layer key further includes: The length of the negotiated key sequence is a first length; the communication sender and the communication receiver use the same hash function to perform a hash operation on the key sequence, generate a hash value, and extract a bit sequence of a preset second length as the first dynamic physical layer key.
[0028] Furthermore, the method provided in the application embodiments also includes: The second length is less than or equal to the first length.
[0029] In this embodiment, the length of the negotiation key sequence is first defined as a first length. The negotiation key sequence is the same binary sequence jointly held by the sending and receiving ends after information negotiation and consistency correction. Before privacy amplification processing, the sending and receiving ends first perform length statistics on the negotiation key sequence to determine the total number of bits contained in the sequence, and use this total number of bits as the first length. For example, when the negotiation key sequence contains 256 bits, 256 is determined as the first length, thus providing a length benchmark for setting the subsequent hash output truncation length.
[0030] Next, the sending and receiving ends use the same hash function to perform hash operations on the negotiated key sequence to generate a hash value. The hash function can be the SHA-256 algorithm, which takes an input bit sequence of arbitrary length, fills it, groups it, and iteratively compresses it to output a hash value of fixed length 256 bits. Both parties take the negotiated key sequence of length 1 as input and execute message filling, initial hash value loading, message block processing, and cyclic compression calculation in sequence according to the operation flow of the SHA-256 algorithm to finally obtain a 256-bit hash value.
[0031] Finally, a bit sequence of a preset second length is extracted from the generated hash value as the first dynamic physical layer key, wherein the second length is less than or equal to the first length. The extraction operation is to extract the bits of the second length sequentially starting from the highest bit of the hash value, and output the extracted bit sequence as the first dynamic physical layer key.
[0032] Furthermore, the method provided in the application embodiments also includes: The second length is dynamically determined based on the first length and the amount of information leaked during the information negotiation process; the amount of leaked information includes the number of check bits exchanged between the communication sender and the communication receiver through the public channel during the information negotiation process; the second length is equal to the first length minus the amount of leaked information, and then minus the preset security redundancy length.
[0033] In this embodiment, the second length is dynamically determined based on the first length and the amount of information leaked during the information negotiation process. The leaked information includes the number of parity bits exchanged between the communication sender and receiver via a public channel during the information negotiation process. These parity bits are exchanged by both parties during the information negotiation phase to locate and correct inconsistent bits. For example, during block parity checking, both parties exchange parity bits for each of the 32 data blocks, totaling 32 bits; during binary search parity checking, 24 parity bits are exchanged when locating three inconsistent blocks. Therefore, the total number of parity bits exchanged by both parties via the public channel is 56 bits, and these 56 bits are included in the leaked information.
[0034] When calculating the second length, the second length equals the first length minus the amount of information leaked, and then minus the preset security redundancy length. That is, by subtracting the number of check bits exchanged through the public channel from the total number of original key bits, the impact of public information on key security is eliminated. Then, the preset security redundancy length is further subtracted to ensure that the final generated dynamic physical layer key has sufficient security. For example, if the first length is 256 bits, the amount of information leaked during the information negotiation process is 56 bits, and the preset security redundancy length is 80 bits, then the second length is calculated as 256 minus 56 minus 80 equals 120 bits. The communication sender and receiver extract 120 bits from the hash value generated by the hash operation based on this dynamically determined second length as the final first dynamic physical layer key.
[0035] Step S200: Obtain the power grid operation and maintenance emergency repair service data to be transmitted at the communication sending end, and perform physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate implicitly encrypted transmission waveform.
[0036] In this embodiment, the communication transmitter acquires the power grid operation and maintenance emergency repair service data to be transmitted, and performs baseband modulation on the service data to generate baseband modulation symbols; then the communication transmitter generates waveform encoding control parameters according to the first dynamic physical layer key, and performs physical layer waveform encoding processing on the baseband modulation symbols according to the waveform encoding control parameters; finally, the signal after physical layer waveform encoding processing is radio frequency modulated to generate implicitly encrypted transmission waveforms.
[0037] Furthermore, in the method provided in the application embodiment, the process of acquiring power grid operation and maintenance emergency repair service data to be transmitted at the communication transmitting end, and performing physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate implicitly encrypted transmission waveforms, further includes: The communication transmitter acquires the power grid operation and maintenance emergency repair service data to be transmitted, performs baseband modulation on the service data, and generates baseband modulation symbols; the communication transmitter generates waveform encoding control parameters according to the first dynamic physical layer key; the communication transmitter performs physical layer waveform encoding processing on the baseband modulation symbols according to the waveform encoding control parameters, and performs radio frequency modulation on the signal after waveform encoding processing to generate the transmission waveform.
[0038] Furthermore, the method provided in the application embodiments also includes: The waveform encoding process includes one or more of waveform shaping, phase perturbation, and dynamic switching of spreading code.
[0039] In this embodiment, after the communication transmitting end acquires the power grid operation and maintenance emergency repair service data to be transmitted, it performs baseband modulation on the power grid operation and maintenance emergency repair service data. Specifically, the power grid operation and maintenance emergency repair service data is processed using quadrature phase shift keying modulation. First, the power grid operation and maintenance emergency repair service data is converted into a continuous binary bit stream. Then, the binary bit stream is grouped into groups of 2 bits each, and each group of bits is mapped to a corresponding complex symbol point according to a preset constellation mapping rule, thereby generating baseband modulation symbols. The baseband modulation symbols are used to characterize the amplitude and phase state of the power grid operation and maintenance emergency repair service data in the baseband domain.
[0040] Next, the transmitting end generates waveform encoding control parameters based on the first dynamic physical layer key. Specifically, a key segmentation mapping method is used to transform the parameters of the first dynamic physical layer key. The first dynamic physical layer key is divided into multiple key fields according to a preset bit length, and each key field is mapped to a corresponding control parameter value, thereby generating waveform encoding control parameters. Specifically, some bits in the first dynamic physical layer key can be mapped to phase perturbation parameters to characterize the phase offset value, another part of the bits can be mapped to waveform shaping parameters to characterize the pulse shaping filter parameter values, and yet another part of the bits can be mapped to spreading code dynamic transition parameters to characterize the selection result or switching order of the spreading code sequence. The waveform encoding control parameters are used to control the execution mode and parameter state of the physical layer waveform encoding processing, establishing a correspondence between the physical layer waveform encoding processing and the first dynamic physical layer key.
[0041] Finally, the transmitting end performs physical layer waveform encoding on the baseband modulation symbols according to the waveform encoding control parameters, and then performs radio frequency modulation on the waveform-encoded signal to generate a transmission waveform. In this process, phase perturbation is used as the physical layer waveform encoding method. The perturbation phase value corresponding to each baseband modulation symbol is determined according to the waveform encoding control parameters, and the perturbation phase value is superimposed onto the corresponding baseband modulation symbol phase to generate a phase-perturbed encoded signal. The waveform encoding process also includes one or more of waveform shaping and dynamic spreading code switching. Waveform shaping is used to adjust the time-domain waveform characteristics of the signal, and dynamic spreading code switching is used to control the selection or switching of the spreading code sequence according to the first dynamic physical layer key. Subsequently, orthogonal up-conversion is used to perform radio frequency modulation on the waveform-encoded signal, that is, the encoded signal is decomposed into in-phase and quadrature components, which are multiplied by mutually orthogonal carrier signals and then superimposed to shift the signal to the target radio frequency band, thereby generating a transmission waveform suitable for transmission in a wireless channel. The transmission waveform is an implicitly encrypted transmission waveform containing the control features of the first dynamic physical layer key.
[0042] Step S300: The implicitly encrypted transmission waveform is transmitted from the communication sending end to the communication receiving end via the communication channel. The communication receiving end receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key consistent with that of the communication sending end.
[0043] In this embodiment, the transmitting end sends an implicitly encrypted transmission waveform to the receiving end via a communication channel. The transmission waveform is a wireless transmission signal formed after physical layer waveform encoding and radio frequency modulation. The communication channel characterizes the actual signal propagation path between the transmitting and receiving ends. During the propagation of the transmission waveform through the communication channel, the receiving end processes the received waveform and estimates the communication channel based on the signal propagation response at the current reception time, extracting the current channel impulse response. This current channel impulse response characterizes the time-domain response features of the current communication link under conditions of multipath propagation, delay spread, amplitude attenuation, and phase change. Subsequently, the receiving end utilizes channel reciprocity and, following the same process as the sending end in generating the first dynamic physical layer key, performs quantization, information negotiation, consistency correction, and privacy amplification on the current channel impulse response to generate a second dynamic physical layer key consistent with that of the sending end. The second dynamic physical layer key is dynamic key information generated by the receiving end based on the characteristics of the current communication channel and is consistent with the first dynamic physical layer key held by the sending end, thus providing a key basis for subsequent implicit decryption of the transmission waveform.
[0044] Step S400: At the communication receiving end, the transmission waveform is implicitly decrypted according to the second dynamic physical layer key to recover the service data.
[0045] In this embodiment of the application, when the communication receiving end implicitly decrypts the transmitted waveform according to the second dynamic physical layer key, the inverse operation of waveform encoding processing is performed on the transmitted waveform according to the second dynamic physical layer key to perform implicit decryption on the transmitted waveform and recover the original modulation symbol; subsequently, the original modulation symbol is demodulated to obtain the service data.
[0046] Furthermore, in the method provided in the application embodiments, in which the communication receiving end implicitly decrypts the transmission waveform according to the second dynamic physical layer key to recover the service data, the method further includes: The communication receiver uses the second dynamic physical layer key to perform the inverse operation of waveform encoding on the received waveform, recover the original modulation symbol, and demodulate to obtain the service data.
[0047] In this embodiment, after receiving the transmitted waveform, the communication receiver first performs down-conversion processing on the transmitted waveform to convert the radio frequency signal into a baseband signal. Then, it obtains a second dynamic physical layer key and uses this key to perform the inverse operation of waveform encoding on the received baseband signal, corresponding to the physical layer waveform encoding processing performed by the communication transmitter. The inverse waveform encoding operation includes one or more of phase descrambling, waveform shaping inverse processing, and spread spectrum de-hopping, which are used to eliminate phase disturbances, waveform shaping changes, or dynamic hopping of the spread spectrum code superimposed by the communication transmitter during the waveform encoding stage, thereby recovering the original modulation symbols before the physical layer waveform encoding processing by the communication transmitter.
[0048] After recovering the original modulation symbols, the receiving end demodulates the original modulation symbols according to the demodulation method corresponding to the baseband modulation method of the transmitting end, restoring the modulation symbols to the corresponding binary bit information, thereby obtaining the service data. Through the above processing, the receiving end uses the second dynamic physical layer key to implicitly decrypt the transmitted waveform and realize the recovery of power grid operation and maintenance emergency repair service data.
[0049] In summary, the embodiments of this application have at least the following technical effects: This application establishes a communication transmission mechanism between a power grid operation and maintenance emergency repair network and a communication receiver. This mechanism involves exchanging pilot signals to estimate the communication channel between the two parties, extracting the channel impulse response, and generating a first dynamic physical layer key using channel reciprocity. At the communication transmission end, power grid operation and maintenance emergency repair service data to be transmitted is acquired. Based on the first dynamic physical layer key, the service data is physically encoded into a waveform to generate an implicitly encrypted transmission waveform. The communication transmission end then transmits the implicitly encrypted transmission waveform to the communication receiver via the communication channel. The communication receiver receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key identical to that of the communication transmission end. Finally, at the communication receiver, the transmission waveform is implicitly decrypted based on the second dynamic physical layer key to recover the service data. This invention addresses the technical problem in existing power grid operation and maintenance networks where the lack of a dynamic encryption protection mechanism that integrates with the communication channel status during data transmission makes transmitted data vulnerable to interception or cracking. By generating a dynamic physical layer key based on the reciprocity of the communication channels between the two parties, and using this key to perform physical layer waveform encoding encryption for transmission of business data, the invention achieves the technical effect of improving the security and anti-cracking capability of data transmission in power grid operation and maintenance networks.
[0050] Example 2, based on the same inventive concept as the power grid operation and maintenance emergency repair network security protection method integrating information encryption in the aforementioned examples, such as... Figure 2As shown, this application provides a network security protection system for power grid operation, maintenance, and emergency repair with integrated information encryption. The system and method embodiments in this application are based on the same inventive concept. The system includes: The first key generation module 11 is used to estimate the communication channel between the communication transmitter and the communication receiver in the power grid operation and maintenance emergency repair network by exchanging pilot signals, extracting the channel impulse response, and generating a first dynamic physical layer key using channel reciprocity; the waveform encoding module 12 is used to acquire the power grid operation and maintenance emergency repair service data to be transmitted at the communication transmitter, and perform physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate an implicitly encrypted transmission waveform; the second key generation module 13 is used to send the implicitly encrypted transmission waveform to the communication receiver via the communication channel at the communication transmitter, and the communication receiver receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key consistent with that of the communication transmitter; the implicit decryption module 14 is used to implicitly decrypt the transmission waveform at the communication receiver according to the second dynamic physical layer key to recover the service data.
[0051] Furthermore, the system is also used to implement the following functions: The communication transmitter sends a first pilot signal to the communication receiver, and the communication receiver estimates the downlink channel based on the first pilot signal and extracts the downlink channel impulse response. The communication receiver sends a second pilot signal to the communication transmitter, and the communication transmitter estimates the uplink channel based on the second pilot signal and extracts the uplink channel impulse response. The communication transmitter and the communication receiver respectively quantize the downlink channel impulse response and the uplink channel impulse response to generate an original key sequence. Then, they negotiate information through a public channel and perform consistency correction on the original key sequence to obtain a negotiated key sequence. The negotiated key sequence is then subjected to privacy amplification processing to generate the first dynamic physical layer key.
[0052] Furthermore, the system is also used to implement the following functions: Extract the first sequence and the second sequence from the original key sequence, wherein the first sequence corresponds to the communication sender and the second sequence corresponds to the communication receiver; divide the first sequence and the second sequence into blocks and calculate the parity check bit for each block; the communication sender and the communication receiver exchange the parity check bit through a public channel to locate inconsistent blocks; within inconsistent blocks, use a binary search method to check and correct inconsistent bits bit by bit until the key sequences of both parties are completely consistent, thereby generating the negotiated key sequence.
[0053] Furthermore, the system is also used to implement the following functions: The length of the negotiated key sequence is a first length; the communication sender and the communication receiver use the same hash function to perform a hash operation on the key sequence, generate a hash value, and extract a bit sequence of a preset second length as the first dynamic physical layer key.
[0054] Furthermore, the system is also used to implement the following functions: The second length is less than or equal to the first length.
[0055] Furthermore, the system is also used to implement the following functions: The amount of information leaked includes the number of check bits exchanged between the communication sender and the communication receiver through a public channel during the information negotiation process; the second length is equal to the first length minus the amount of information leaked, and then minus a preset security redundancy length.
[0056] Furthermore, the system is also used to implement the following functions: The communication transmitter acquires the power grid operation and maintenance emergency repair service data to be transmitted, performs baseband modulation on the service data, and generates baseband modulation symbols; the communication transmitter generates waveform encoding control parameters according to the first dynamic physical layer key; the communication transmitter performs physical layer waveform encoding processing on the baseband modulation symbols according to the waveform encoding control parameters, and performs radio frequency modulation on the signal after waveform encoding processing to generate the transmission waveform.
[0057] Furthermore, the system is also used to implement the following functions: The waveform encoding process includes one or more of waveform shaping, phase perturbation, and dynamic switching of spreading code.
[0058] Furthermore, the system is also used to implement the following functions: The communication receiver uses the second dynamic physical layer key to perform the inverse operation of waveform encoding on the received waveform, recover the original modulation symbol, and demodulate to obtain the service data.
[0059] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0060] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A network security protection method for power grid operation, maintenance, and emergency repair integrating information encryption, characterized in that: include: Between the communication transmitter and receiver of the power grid operation and maintenance emergency repair network, the communication channel between the two parties is estimated by exchanging pilot signals, the channel impulse response is extracted, and the first dynamic physical layer key is generated by using the channel reciprocity. The communication transmitting end acquires the power grid operation and maintenance emergency repair service data to be transmitted, and performs physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate implicitly encrypted transmission waveforms. The implicitly encrypted transmission waveform is transmitted from the communication sending end to the communication receiving end via the communication channel. The communication receiving end receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key consistent with that of the communication sending end. At the communication receiving end, the transmission waveform is implicitly decrypted according to the second dynamic physical layer key to recover the service data.
2. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 1, characterized in that, Between the communication transmitter and receiver in the power grid operation and maintenance emergency repair network, pilot signals are exchanged to estimate the communication channel between them, extract the channel impulse response, and generate the first dynamic physical layer key using channel reciprocity, including: The communication transmitter sends a first pilot signal to the communication receiver, and the communication receiver estimates the downlink channel based on the first pilot signal and extracts the downlink channel impulse response. The communication receiving end sends a second pilot signal to the communication sending end, and the communication sending end estimates the uplink channel based on the second pilot signal and extracts the uplink channel impulse response. The communication transmitter and the communication receiver respectively quantize the downlink channel impulse response and the uplink channel impulse response to generate an original key sequence. Then, they negotiate information through a public channel and perform consistency correction on the original key sequence to obtain a negotiated key sequence. The negotiated key sequence is subjected to privacy amplification processing to generate the first dynamic physical layer key.
3. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 2, characterized in that, Information negotiation is conducted through a public channel, and the original key sequence is subjected to consistency correction to obtain a negotiated key sequence, including: Extract a first sequence and a second sequence from the original key sequence, wherein the first sequence corresponds to the communication sending end and the second sequence corresponds to the communication receiving end; The first sequence and the second sequence are divided into blocks, and the parity check bit of each block is calculated. The communication transmitter and the communication receiver exchange the parity check bit through a public channel to locate inconsistent blocks. Within inconsistent blocks, a binary search method is used to verify and correct inconsistent bits bit by bit until the key sequences of both parties are completely consistent, thus generating the negotiated key sequence.
4. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 2, characterized in that, The negotiated key sequence is subjected to privacy amplification processing to generate the first dynamic physical layer key, including: The length of the negotiation key sequence is set to a first length; The communication sending end and the communication receiving end use the same hash function to perform hash operation on the key sequence, generate a hash value, and extract a bit sequence of a preset second length as the first dynamic physical layer key.
5. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 4, characterized in that, The second length is less than or equal to the first length.
6. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 4, characterized in that, The second length is dynamically determined based on the first length and the amount of information leaked during the information negotiation process; The amount of information leaked includes the number of check bits exchanged between the communication sender and the communication receiver through a public channel during the information negotiation process; The second length is equal to the first length minus the amount of information leaked, and then minus the preset security redundancy length.
7. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 1, characterized in that, The communication transmitting end acquires the power grid operation and maintenance emergency repair service data to be transmitted, and performs physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate an implicitly encrypted transmission waveform, including: The communication transmitting end acquires the power grid operation and maintenance emergency repair service data to be transmitted, performs baseband modulation on the service data, and generates baseband modulation symbols; The communication transmitter generates waveform encoding control parameters based on the first dynamic physical layer key; The communication transmitter performs physical layer waveform encoding processing on the baseband modulation symbol according to the waveform encoding control parameters, and performs radio frequency modulation on the signal after waveform encoding processing to generate the transmission waveform.
8. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 7, characterized in that, The waveform encoding process includes one or more of waveform shaping, phase perturbation, and dynamic switching of spreading code.
9. The integrated information encryption-based network security protection method for power grid operation, maintenance, and emergency repair as described in claim 1, characterized in that, At the communication receiving end, implicit decryption of the transmission waveform is performed based on the second dynamic physical layer key to recover the service data, including: The communication receiver uses the second dynamic physical layer key to perform the inverse operation of waveform encoding on the received waveform, recover the original modulation symbol, and demodulate to obtain the service data.
10. A network security protection system for power grid operation, maintenance, and emergency repair with integrated information encryption, characterized in that: The system is used to execute the integrated information encryption network security protection method for power grid operation and maintenance emergency repair as described in any one of claims 1-9, and the system includes: The first key generation module is used to estimate the communication channel between the communication transmitter and the communication receiver in the power grid operation and maintenance emergency repair network by exchanging pilot signals, extracting the channel impulse response, and generating the first dynamic physical layer key using channel reciprocity. The waveform encoding module is used to acquire the power grid operation and maintenance emergency repair service data to be transmitted at the communication transmitting end, and to perform physical layer waveform encoding on the service data according to the first dynamic physical layer key to generate implicitly encrypted transmission waveforms. The second key generation module is used to send the implicitly encrypted transmission waveform to the communication receiving end via the communication channel at the communication sending end. The communication receiving end receives the transmission waveform, extracts the current channel impulse response of the communication channel, and generates a second dynamic physical layer key consistent with that of the communication sending end. An implicit decryption module is used at the communication receiving end to implicitly decrypt the transmission waveform according to the second dynamic physical layer key and recover the service data.