A zero-trust-based power scheduling quantum cryptography cloud application system and method

Through the power dispatching quantum cryptography cloud application system based on the zero-trust concept and quantum secure communication, the security of the entire power dispatching system has been improved, the security risks of identity authentication and data encryption have been resolved, and the safety and reliability of the power system have been ensured.

CN114398627BActive Publication Date: 2025-10-21NANJING NARI NETWORK SECURITY TECH CO LTD +4
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210093598.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-26
Publication Date
2025-10-21
Estimated Expiration
2042-01-26

AI Technical Summary

Technical Problem

The existing power dispatching system has security risks in identity authentication and data encryption. Especially in the new power system, the access of semi-trusted and untrusted terminals increases security risks. Traditional encryption methods are not secure enough in wireless public network environments, and the threat of quantum computing is exacerbated.

Method used

The power dispatching quantum cryptography cloud application system based on the zero-trust concept and quantum secure communication technology is adopted. Through the zero-trust platform, unified identity authentication and security behavior analysis are carried out, combined with quantum key management, to achieve end-to-end security improvement of the whole process.

Benefits of technology

It effectively solves the problem of authority creep, ensures that identities are trustworthy, behaviors are knowable, and authorities are controllable, improves the security of data interaction, storage, and use in power dispatching business, and ensures safe, stable, and reliable dispatching of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114398627B_ABST
    Figure CN114398627B_ABST
Patent Text Reader

Abstract

The application discloses a kind of quantum cryptography cloud application systems and methods based on zero trust of electric power dispatching, the system includes electric power dispatching system, zero trust platform and quantum cryptography cloud platform;Based on zero trust platform, dynamic unified identity authentication and security behavior continuous analysis are carried out on electric power dispatching business interaction entity, and quantum key acquisition and business data interaction permission are dynamically controlled, to ensure that the identity of business interaction entity is trusted, behavior is known, and permission is controllable. Business data is transmitted, encrypted, stored and encrypted using quantum keys, improving the security of electric power dispatching business data interaction, storage and use.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a zero-trust-based quantum cryptography cloud application system and method for electric power dispatching, belonging to the technical field of electric power communication. Background Art

[0002] Currently, security measures for power dispatching systems primarily include identity authentication, data encryption, and internal and external network isolation. Internal and external network isolation, based on physical isolation, offers high security. However, with the development of new power systems, the boundaries of traditional information security protection are becoming increasingly blurred, posing challenges to existing identity authentication and data encryption methods.

[0003] At the authentication level, current power dispatching systems generally rely on certificates for authentication, employing a "one-time authentication, default security" permission control strategy. Once a business terminal or data access client passes system authentication, it will no longer need to re-verify its identity during business interactions or during the validity period of the session, and it will continue to have access to the power dispatching system. In this case, even if the business terminal or data access client performs abnormal, unsafe, or even unauthorized operations, the power dispatching system will be unable to identify them, posing a significant security risk. Within the power dispatching system, there is a lack of behavioral monitoring of internal personnel. Outside the power dispatching system, especially in new power systems, a large number of semi-trusted and untrusted terminals are connected to the dispatching system with the addition of massive amounts of distributed renewable energy and multiple loads. Once these personnel or terminals pass system authentication, they pose a significant security risk.

[0004] In terms of data encryption, electric power dispatching systems generally rely on dedicated power fiber-optic networks and power-specific algorithms that meet national security requirements to ensure the secure transmission of business data. Limited by the intranet environment and existing computing power, security is generally well-established. However, with the construction of new power systems and the integration of massive new energy terminals into dispatching systems, cost and construction difficulties have hindered full fiber coverage at the end of the power grid, necessitating the use of wireless public networks and other methods. This significantly increases channel security risks and makes them vulnerable to external attacks. Furthermore, because electric power dispatching systems are deployed within the power grid intranet, they generally assume intranet security and directly read plaintext from the database during data calls, posing a risk of business data leakage. In the future, with the development of quantum computing technology, existing encryption systems will also face significant security risks.

[0005] In summary, the current security enhancement of power dispatching business data has not achieved overall security improvement. Summary of the Invention

[0006] The purpose of the present invention is to provide a zero-trust-based quantum cryptography cloud application system and method for power dispatching. Based on the zero-trust concept and quantum secure communication technology, the security protection scheme of the power dispatching system is end-to-end and full-process security is improved from multiple levels such as identity authentication and data encryption, from the levels of business interaction entities, business communication channels and business data processing.

[0007] In order to achieve the above object, the technical solution adopted by the present invention is as follows:

[0008] The present invention provides a zero-trust-based power dispatching quantum cryptography cloud application system, comprising: a power dispatching system, a zero-trust platform, and a quantum cryptography cloud platform;

[0009] The power dispatching system is connected to the quantum cryptography cloud platform and the zero-trust platform; the quantum cryptography cloud platform and the zero-trust platform are connected;

[0010] The quantum cryptography cloud platform is used to supply quantum keys to the power dispatching system and manage the quantum keys;

[0011] The power dispatching system is used to collect power control business data, upload power control business data based on the quantum key provided by the quantum cryptography cloud platform, and issue control instructions;

[0012] The zero-trust platform is used to perform unified identity authentication of interactive entities in the power dispatching system, generate permission management policies, and send the generated permission management policies to the quantum cryptography cloud platform and the power dispatching system; as well as perform security behavior analysis on interactive entities in the power dispatching system and update the permission management policies based on the analysis results.

[0013] Furthermore, the power dispatching system includes a power dispatching business terminal and a terminal power quantum longitudinal encryption authentication device deployed on the business terminal side, as well as a power dispatching business master station, a master station power quantum longitudinal encryption authentication device, a power control cloud and micro-applications deployed on the business master station side.

[0014] Furthermore, the power dispatching system interaction entity refers to any one of the power dispatching business terminal, the terminal power quantum longitudinal encryption authentication device, the power dispatching business master station, the master station power quantum longitudinal encryption authentication device, the power control cloud, the micro-application, the zero-trust platform and the quantum cryptography cloud platform.

[0015] Furthermore, the zero-trust platform and quantum cryptography cloud platform are both deployed on the business main station side.

[0016] Furthermore, the zero-trust platform and quantum cryptography cloud platform are both connected to the power control cloud through API interfaces;

[0017] The power dispatching business terminal, the terminal power quantum longitudinal encryption authentication device, the power dispatching business master station and the master station power quantum longitudinal encryption authentication device are all connected to the quantum cryptography cloud platform through the FE network port.

[0018] Furthermore, the zero-trust platform is specifically used to:

[0019] Conduct unified identity authentication between power dispatching business interaction entities and the zero-trust platform; as well as identity authentication between power dispatching business interaction entities with data interaction.

[0020] Furthermore, the zero-trust platform is specifically used to:

[0021] When the power dispatching business interaction entity first interacts with data, an initial unified identity authentication is performed to generate an initial permission management policy; the initial permission management policy includes allowing / rejecting the acquisition of quantum keys from the quantum cryptography cloud platform, the length, update frequency, and total amount of the quantum keys; and allowing / rejecting the establishment of a communication link and allowing / rejecting the access to / operation of power dispatching system business data.

[0022] as well as,

[0023] During the data interaction process between power dispatching business interaction entities, the ontological behavior, business data and network traffic between power dispatching business interaction entities are continuously analyzed, dynamic unified identity authentication is triggered based on the analysis results, and a dynamic permission management strategy is generated.

[0024] Furthermore, the quantum cryptography cloud platform is specifically used to:

[0025] If the power dispatching business interaction entity is connected to the quantum cryptography cloud platform, the quantum key is directly supplied to the power dispatching business interaction entity;

[0026] If the power dispatching business interaction entity is not connected to the quantum cryptography cloud platform, the quantum key is supplied to the power control cloud, and the power dispatching business interaction entity obtains the quantum key from the power control cloud.

[0027] Furthermore, the quantum cryptography cloud platform is specifically used to:

[0028] Provide full life cycle management of quantum key generation, distribution, storage, backup, update, revocation, archiving, recovery and security.

[0029] The present invention also provides a zero-trust-based power dispatching data transmission method, comprising:

[0030] Through the aforementioned zero-trust platform, unified identity authentication is performed on the entities interacting with the power dispatching business, generating permission management policies;

[0031] After the unified identity authentication is passed and the authority is obtained, the quantum key is provided to the power dispatching business interaction entity through the aforementioned quantum cryptography cloud platform;

[0032] The collected control business data is transmitted based on the quantum key provided by the quantum cryptography cloud platform.

[0033] Furthermore, the authority management strategy includes quantum key acquisition authority and business data interaction authority.

[0034] Furthermore, the unified identity authentication of the power dispatching business interaction entity includes:

[0035] Unified identity authentication between power dispatching business interaction entities and the zero-trust platform;

[0036] as well as,

[0037] Identity authentication between interactive entities in power dispatching business with data interaction.

[0038] Furthermore, the unified identity authentication of the power dispatching business interaction entity is performed, and the authentication method includes at least any two of identity information authentication, behavior information authentication and security credential authentication;

[0039] The identity information includes MAC address, user physiological characteristics, mobile phone verification code and email verification link;

[0040] The behavior information includes application for communication resources, business data reading, writing and modification permissions;

[0041] The security credentials include digital certificates and digital signatures.

[0042] Furthermore, the unified identity authentication for the electric power dispatching business interaction entity includes two methods: initial unified identity authentication and dynamic unified identity authentication;

[0043] When a power dispatching business interaction entity first interacts with data, it performs initial unified identity authentication and generates an initial permission management policy. The initial permission management policy includes allowing / rejecting the acquisition of quantum keys from the quantum cryptography cloud platform, and obtaining the length, update frequency, and total amount of quantum keys; as well as allowing / rejecting the establishment of a communication link and allowing / rejecting access to / operation of power dispatching system business data.

[0044] During data interaction, dynamic unified identity authentication is performed when the corresponding trigger conditions are met, and a dynamic permission management strategy is generated;

[0045] The trigger conditions include when a communication link or service session is re-established; when a current communication link or service session requests a higher authority; and when re-authentication is required based on the results of continuous security behavior analysis;

[0046] The dynamic permission management and control strategy includes: maintaining the current permission, revoking all current permissions, specifying the revocation of a current permission, adding new permissions, and performing secondary identity authentication.

[0047] Furthermore, the provision of quantum keys to the power dispatching service interaction entity includes the following two methods:

[0048] Directly supply quantum keys to power dispatching business interaction entities through the quantum cryptography cloud platform;

[0049] The quantum key is supplied to the power control cloud through the quantum cryptography cloud platform, and the power dispatching business interaction entity obtains the quantum key from the power control cloud.

[0050] Furthermore, the transmission of the control business data collected based on the quantum key provided by the quantum cryptography cloud platform includes:

[0051] The power dispatching business terminal uses the acquired quantum key to encrypt data, and the master station and terminal power quantum longitudinal encryption authentication device use the acquired quantum key to establish an encrypted tunnel;

[0052] Transmit the encrypted data to the power dispatching service master station through an encrypted tunnel;

[0053] The power dispatching business master station stores the received data in the power control cloud;

[0054] The micro-application uses homomorphic encryption technology to perform operations on encrypted data in the power control cloud, and performs decryption operations using the quantum key obtained through the API interface.

[0055] Furthermore, it also includes: continuously analyzing the ontological behavior, business data and network traffic between the interactive entities of the power dispatching business, and triggering dynamic unified identity authentication based on the analysis results.

[0056] Furthermore, the ontological behaviors between the power dispatching business interaction entities include: security credential verification, identity information authentication, data interaction behavior perception and business data processing authority;

[0057] The business data between the interactive entities of the power dispatching business includes: the data packet type, data packet size, data collection cycle, data collection trigger conditions of the power dispatching business terminal status quantity collection data and the power dispatching business master station control data, as well as the time, access location, access duration, access carrier, and business data accessed by the power dispatching personnel to the power control cloud;

[0058] The network traffic between interactive entities in the power dispatching business includes: periodic traffic or burst traffic, point-to-point traffic or converged traffic, traffic direction, traffic threshold and traffic interaction mode.

[0059] Furthermore, the triggering condition for triggering dynamic unified identity authentication is any one of the following:

[0060] The power dispatching business interaction entity applies for new permissions;

[0061] Changes in the ontological behavior, business data, or network traffic between interactive entities in the power dispatching business;

[0062] Reach the set time period.

[0063] The beneficial effects of the present invention are:

[0064] (1) The present invention performs continuous identity authentication, security behavior analysis and lean permission management on the entities interacting with the power dispatching business based on the zero-trust platform, solving the permission creep problem that may exist in the current "one-time authentication, default security" permission control strategy. It can effectively ensure that the identity is trustworthy, the behavior is knowable and the permission is controllable in the process of quantum key acquisition and power dispatching business data interaction.

[0065] (2) Based on the principles of “trusted identity, knowable behavior, and controllable authority”, the present invention integrates quantum secure communication technology and performs transmission encryption, storage encryption, and operation encryption on business data based on quantum keys, thereby expanding the application scenarios of quantum secure communication technology from transmission channel encryption to storage encryption and operation encryption, which can effectively improve the security of data interaction, storage, and use in power dispatching business.

[0066] (3) Based on the zero-trust concept and quantum secure communication technology, the present invention provides end-to-end and full-process security improvements to the power dispatching system security protection solution at multiple levels, such as identity authentication and data encryption, from the perspectives of business interaction entities, business communication channels, and business data processing, thereby ensuring the safe, stable, efficient, and reliable dispatching of the power system and improving power supply reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] Figure 1 An embodiment of the present invention provides a zero-trust-based quantum cryptography cloud application system architecture for power scheduling.

[0068] Figure 2 A flow chart of a zero-trust-based power dispatching data transmission method provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0069] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

[0070] One embodiment of the present invention provides a zero-trust-based quantum cryptography cloud application system for power dispatching, see Figure 1 , consisting of a power dispatching system, a zero-trust platform, and a quantum cryptography cloud platform.

[0071] Specifically, the power dispatch system consists of a power dispatch service terminal and a terminal power quantum longitudinal encryption authentication device deployed on the service terminal side; and a power dispatch service master station, a master station power quantum longitudinal encryption authentication device, a power control cloud, and a power control cloud micro-application deployed on the service master station side. The power dispatch system primarily collects power control service data and issues control commands. It interconnects with the quantum cryptography cloud platform and the zero-trust platform via APIs or physical interfaces.

[0072] The Zero Trust Platform, deployed on the main service station, is primarily used to implement dynamic, unified identity authentication, continuous analysis of security behaviors, and dynamic permission management for all interacting entities in the power dispatching system. The Zero Trust Platform is interconnected with the power control cloud via an API.

[0073] The quantum cryptography cloud platform is deployed on the business main station side and is mainly used to realize the functions of quantum key supply, use and management of the power dispatching system. It is interconnected with the power dispatching business interaction entity through API interface or physical interface.

[0074] It should be noted that the power dispatching business interaction entities include power dispatching business terminals, power dispatching business master stations, power quantum vertical encryption authentication devices, quantum cryptography cloud platforms, power control cloud, power control cloud micro-applications, etc.

[0075] Another specific embodiment of the present invention provides a zero-trust based power dispatching data transmission method, the implementation process of which is shown in FIG. Figure 2 , including the following steps:

[0076] Step 1: Build a zero-trust power dispatching quantum cryptography cloud application system consisting of a power dispatching system, a zero-trust platform, and a quantum cryptography cloud platform.

[0077] Step 2: Use the zero-trust platform to perform initial / dynamic unified identity authentication on the power dispatching business interaction entities, and generate initial permission control policies / dynamically update permission control policies.

[0078] Step 3: According to the initial authority management strategy of the zero-trust platform, the quantum cryptography cloud platform provides quantum keys to the power dispatching business interaction entities and performs quantum key management.

[0079] Step 4: Based on the quantum key provided by the quantum cryptography cloud platform, the transmission encryption, storage encryption and computational encryption of the power dispatching system business data and the power control cloud data are performed.

[0080] Step 5: Collect and continuously analyze the characteristics of the ontological behavior, business data, network traffic, etc. between the interactive entities of the power dispatching business, and repeat steps 2-4 based on the results of the security behavior analysis.

[0081] In this embodiment, a zero-trust platform is used to perform unified identity authentication on the power dispatching business interaction entities, including two levels: first, unified identity authentication between the power dispatching business interaction entities and the zero-trust platform; second, identity authentication between the power dispatching business interaction entities with data interaction.

[0082] The power dispatching business interaction entities with data interaction include: between the power dispatching business terminal and the power dispatching business master station for building a business channel, between the two power quantum longitudinal encryption authentication devices for building a communication channel, and between the power dispatching business terminal, the power dispatching business master station, the power quantum longitudinal encryption authentication device, the power control cloud, the power control cloud micro-application and the quantum cryptography cloud platform for building a quantum key acquisition channel.

[0083] It should be noted that using the zero-trust platform to perform unified identity authentication for entities interacting with power dispatching services includes two scenarios: initial unified identity authentication and dynamic unified identity authentication. Initial unified identity authentication generates an initial permission control policy, while dynamic unified identity authentication generates a dynamically updated permission control policy.

[0084] Furthermore, the initial / dynamic unified identity authentication adopts a multi-factor authentication method, which includes at least two or more of the following: unique identity information such as MAC address / user physiological characteristics / mobile phone verification code / email verification link, behavioral information such as application for communication resources / business data reading, writing and modifying permissions, and security credentials such as digital certificates / digital signatures.

[0085] Furthermore, the initial permission control strategy includes two levels: quantum key acquisition and business data exchange. Quantum key acquisition includes allowing / denying the acquisition of quantum keys from the quantum cryptography cloud platform, as well as the length, update frequency, and total amount of quantum keys. Business data exchange includes allowing / denying the establishment of communication links and allowing / denying access to / operation of power dispatch system business data.

[0086] Furthermore, dynamic unified identity authentication is triggered based on the zero trust concept, specifically in the following situations: ① when a communication link or business session is re-established; ② when a higher authority is requested for the current communication link or business session; ③ when re-authentication is deemed necessary based on the continuous analysis results of security behavior in step 5.

[0087] The dynamic update permission management strategy includes: ① Maintaining the current permissions, that is, maintaining the current quantum key acquisition permissions, communication links, encryption channels, business channels and business data processing permissions; ② Reclaiming / partially reclaiming the current permissions, that is, reclaiming all the current quantum key acquisition, communication links, encryption channels, business channels and business data processing permissions, or reclaiming only one of them; ③ Adding new permissions and performing secondary identity authentication, etc.

[0088] Furthermore, the dynamic update permission management strategy adopts the principle of minimization, including two levels: quantum key acquisition and business data interaction. ① Quantum key acquisition permissions can be further refined into: the request, response, connection, and closure of the quantum key acquisition session between the power dispatching business interaction entity and the quantum cryptography cloud platform; as well as the length, update frequency, and total amount of the acquired quantum key. ② Business data interaction permissions can be further refined into the request, response, connection, and closure of the communication link, encryption channel, and business channel between the power dispatching business interaction entities; and in the process of power dispatching business data processing, for the permission levels of different power dispatching business interaction entities, in addition to setting large-scale operation permissions such as read, write, modify, and delete, further fine-grained permissions such as data objects, time periods, and specific fields for the above operations are set.

[0089] In this embodiment, the prerequisite for the quantum cryptography cloud platform to supply quantum keys to power dispatching business interaction entities is that the business interaction entities have completed dynamic unified identity authentication through the zero-trust platform and obtained initial quantum key acquisition permissions and business data interaction permissions.

[0090] Among them, the unified identity authentication process includes: identity authentication between the power quantum longitudinal encryption authentication devices on the master side and the terminal side is passed and a communication channel is established to ensure that the synchronized quantum key is obtained from the quantum cryptography cloud platform; identity authentication between the power dispatching business terminal and the power dispatching business master station is passed to ensure that the synchronized quantum key is obtained from the quantum cryptography cloud platform; identity authentication between the power dispatching business master station and the power control cloud / micro application is passed to ensure that the synchronized quantum key is obtained from the quantum cryptography cloud platform; identity authentication between the quantum cryptography cloud platform and the power dispatching business interaction entity is passed and a communication channel is established to ensure that the synchronized quantum key is obtained from the quantum cryptography cloud platform.

[0091] Furthermore, the quantum key supply methods include obtaining it through direct connection with the physical interface of the quantum cryptography cloud device (such as the FE network port) (such as the power quantum longitudinal encryption authentication device, the power dispatching business master station, etc.), and obtaining it through the power control cloud through the API interface (such as the power control cloud micro-application, etc.).

[0092] In this embodiment, the quantum key management function of the quantum cryptography cloud platform specifically includes: full life cycle management of quantum keys, including generation, distribution, storage, backup, update, revocation, archiving, recovery, and security management.

[0093] In this embodiment, the quantum cryptography cloud platform provides synchronized quantum keys for the power dispatching service terminal and the power dispatching service master station for encryption and decryption processes respectively;

[0094] Specifically, the encrypted transmission of business data in the power dispatching system includes two levels: first, encrypted transmission at the business data level, that is, the use of quantum keys for data encryption and decryption between the power dispatching business terminal and the power dispatching business master station; second, encrypted transmission at the communication channel level, that is, the use of quantum keys between paired power quantum longitudinal encryption authentication devices to establish encrypted tunnels for encrypted transmission and decryption of business data.

[0095] The secure storage of the power dispatching system's business data is mainly based on the quantum key obtained from the quantum cryptography cloud platform.

[0096] The encryption operation of the power control cloud data uses homomorphic encryption technology to operate on the ciphertext of the power dispatching business data encrypted by the quantum key to calculate the desired result.

[0097] In this embodiment, the ontological behaviors of the electric power dispatching business interaction entity include security credential verification, identity information authentication, data interaction behavior perception, business data processing authority, etc.

[0098] The business data of the business interaction entity includes the data packet type, data packet size, data collection cycle, data collection trigger conditions of the business terminal status quantity collection data and the business master station control data, as well as the access time, access location, access duration, access carrier, and accessed business data of the power dispatching personnel to the power control cloud system.

[0099] The network traffic characteristics of business interaction entities include periodic traffic or burst traffic, point-to-point traffic or converged traffic, traffic direction, traffic threshold, traffic interaction mode, etc.

[0100] Specifically, the trigger conditions for continuous security behavior analysis include: ① a business interaction entity applying for new permissions; ② changes in the underlying behavior, business data, or network traffic characteristics between the aforementioned business interaction entities; and ③, after a set fixed time period, in addition to the aforementioned two situations. This period is set based on the permissions of the business interaction entity. For entities that remotely control business terminals, it can be set to seconds; for entities whose business terminals only collect information, it can be set to minutes.

[0101] If the security behavior continuous analysis result shows a change, or if the security behavior continuous analysis result does not change but after a fixed time period, steps 2-4 are repeated. The fixed time period is determined based on the service access duration.

[0102] Glossary of relevant technical terms

[0103] Zero Trust Theory: According to NIST, Zero Trust is an evolving set of cybersecurity paradigms that shifts the focus of network defense from static, network-based perimeters to users, devices, and resources. The Zero Trust security model assumes that attackers already exist on the network and that an enterprise's own network infrastructure (intranet) is no different from other networks (such as the public internet). It no longer assumes that content is trustworthy.

[0104] Quantum secure communication theory: Based on the fundamental principles of quantum mechanics, such as quantum indivisibility, non-cloning, and uncertainty, this technology enables secure long-distance distribution of quantum keys. Based on quantum keys and Shannon's "one-time pad" theory, it enables secure transmission of business data.

[0105] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0107] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1The function specified in one or more boxes.

[0108] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A zero-trust-based quantum cryptography cloud application system for power dispatching, characterized in that: include: Power dispatching system, zero-trust platform, and quantum cryptography cloud platform; The power dispatching system is connected to the quantum cryptography cloud platform and the zero-trust platform; the quantum cryptography cloud platform is connected to the zero-trust platform; the zero-trust platform and the quantum cryptography cloud platform are both deployed on the business master station side; the zero-trust platform and the quantum cryptography cloud platform are both connected to the power control cloud through an API interface; The quantum cryptography cloud platform is used to supply quantum keys to the power dispatching system and manage the quantum keys; The power dispatching system includes a power dispatching service terminal and a terminal power quantum longitudinal encryption authentication device deployed on the service terminal side, as well as a power dispatching service master station, a master station power quantum longitudinal encryption authentication device, a power control cloud and micro-applications deployed on the service master station side; The power dispatching service terminal, the terminal power quantum longitudinal encryption authentication device, the power dispatching service master station and the master station power quantum longitudinal encryption authentication device are all connected to the quantum cryptography cloud platform through the FE network port; The power dispatching system is used to collect power control business data, upload power control business data based on the quantum key provided by the quantum cryptography cloud platform, and issue control instructions; The zero-trust platform is used to perform unified identity authentication of interactive entities in the power dispatching system, generate permission management policies, and send the generated permission management policies to the quantum cryptography cloud platform and the power dispatching system; and conduct security behavior analysis on interactive entities in the power dispatching system and update the authority management strategy based on the analysis results; The zero trust platform is used to: Conduct unified identity authentication between power dispatching business interaction entities and the zero-trust platform; and identity authentication between entities interacting with power dispatching services that have data interaction; When the power dispatching business interaction entity first interacts with data, it performs initial unified identity authentication and generates an initial permission management policy; The initial permission management policy includes allowing / rejecting the acquisition of quantum keys from the quantum cryptography cloud platform, and obtaining the length, update frequency, and total amount of quantum keys; as well as allowing / rejecting the establishment of communication links and allowing / rejecting the access / operation of power dispatch system business data; as well as, During the data interaction process between power dispatching business interaction entities, the ontological behavior, business data and network traffic between power dispatching business interaction entities are continuously analyzed, dynamic unified identity authentication is triggered based on the analysis results, and a dynamic permission management strategy is generated.

2. A zero-trust-based quantum cryptography cloud application system for power dispatching according to claim 1, characterized in that: The power dispatching system interaction entity refers to any one of the power dispatching business terminal, the terminal power quantum longitudinal encryption authentication device, the power dispatching business master station, the master station power quantum longitudinal encryption authentication device, the power control cloud, the micro application, the zero trust platform and the quantum cryptography cloud platform.

3. A zero-trust-based quantum cryptography cloud application system for power dispatching according to claim 2, characterized in that: The quantum cryptography cloud platform is specifically used to: If the power dispatching business interaction entity is connected to the quantum cryptography cloud platform, the quantum key is directly supplied to the power dispatching business interaction entity; If the power dispatching business interaction entity is not connected to the quantum cryptography cloud platform, the quantum key is supplied to the power control cloud, and the power dispatching business interaction entity obtains the quantum key from the power control cloud.

4. A zero-trust-based quantum cryptography cloud application system for power dispatching according to claim 1, characterized in that: The quantum cryptography cloud platform is specifically used to: Provide full life cycle management of quantum key generation, distribution, storage, backup, update, revocation, archiving, recovery and security.

5. A zero-trust-based power dispatching data transmission method, characterized in that: The zero-trust-based quantum cryptography cloud application system for power dispatching according to any one of claims 1 to 4 is implemented, and the method includes: Perform unified identity authentication on power dispatching business interaction entities through the zero-trust platform to generate permission management and control strategies; After the unified identity authentication is passed and the authority is obtained, the quantum key is provided to the power dispatching business interaction entity through the quantum cryptography cloud platform; The collected control business data is transmitted based on the quantum key provided by the quantum cryptography cloud platform.

6. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: The authority management and control strategy includes quantum key acquisition authority and business data interaction authority.

7. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: The unified identity authentication of the power dispatching business interaction entity includes: Unified identity authentication between power dispatching business interaction entities and the zero-trust platform; as well as, Identity authentication between interactive entities in power dispatching business with data interaction.

8. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: The unified identity authentication of the power dispatching business interaction entity is performed, and the authentication method includes at least any two of identity information authentication, behavior information authentication and security credential authentication; The identity information includes MAC address, user physiological characteristics, mobile phone verification code and email verification link; The behavior information includes application for communication resources, business data reading, writing and modification permissions; The security credentials include digital certificates and digital signatures.

9. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: The unified identity authentication for the electric power dispatching business interaction entity includes two methods: initial unified identity authentication and dynamic unified identity authentication; When the power dispatching business interaction entity first interacts with data, it performs initial unified identity authentication and generates initial permission management policy; The initial permission management policy includes allowing / rejecting the acquisition of quantum keys from the quantum cryptography cloud platform, and obtaining the length, update frequency, and total amount of quantum keys; as well as allowing / rejecting the establishment of communication links and allowing / rejecting the access / operation of power dispatch system business data; During data interaction, dynamic unified identity authentication is performed when the corresponding trigger conditions are met, and a dynamic permission management strategy is generated; The trigger conditions include when a communication link or service session is re-established; when a current communication link or service session applies for a higher authority; and, when recertification is required based on the results of ongoing analysis of security behavior; The dynamic permission management and control strategy includes: maintaining the current permission, revoking all current permissions, specifying the revocation of a current permission, adding new permissions, and performing secondary identity authentication.

10. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: The provision of quantum keys to the power dispatching service interaction entity includes the following two methods: Directly supply quantum keys to power dispatching business interaction entities through the quantum cryptography cloud platform; The quantum key is supplied to the power control cloud through the quantum cryptography cloud platform, and the power dispatching business interaction entity obtains the quantum key from the power control cloud.

11. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: The transmission of the control business data collected by the quantum key provided by the quantum cryptography cloud platform includes: The power dispatching business terminal uses the acquired quantum key to encrypt the collected control business data, and the master station and terminal power quantum longitudinal encryption authentication device use the acquired quantum key to establish an encrypted tunnel; Transmit the encrypted data to the power dispatching service master station through an encrypted tunnel; The power dispatching business master station stores the received data in the power control cloud; The micro-application uses homomorphic encryption technology to perform operations on encrypted data in the power control cloud, and performs decryption operations using the quantum key obtained through the API interface.

12. The method for transmitting power dispatch data based on zero trust according to claim 5, characterized in that: Also includes: Continuously analyze the ontological behavior, business data, and network traffic between interactive entities in the power dispatching business, and trigger dynamic unified identity authentication based on the analysis results.

13. A zero-trust-based power dispatching data transmission method according to claim 12, characterized in that: The ontological behaviors between the power dispatching business interaction entities include: security credential verification, identity information authentication, data interaction behavior perception and business data processing authority; The business data between the interactive entities of the power dispatching business includes: the data packet type, data packet size, data collection cycle, data collection trigger conditions of the power dispatching business terminal status quantity collection data and the power dispatching business master station control data, as well as the time, access location, access duration, access carrier, and business data accessed by the power dispatching personnel to the power control cloud; The network traffic between interactive entities in the power dispatching business includes: periodic traffic or burst traffic, point-to-point traffic or converged traffic, traffic direction, traffic threshold and traffic interaction mode.

14. The method for transmitting power dispatch data based on zero trust according to claim 12, characterized in that: The triggering condition for triggering dynamic unified identity authentication is any of the following: The power dispatching business interaction entity applies for new permissions; Changes in the ontological behavior, business data, or network traffic between interactive entities in the power dispatching business; Reach the set time period.