A quantum key usage and storage method for remote power communication

By introducing a dual-key pool and random selection of multiple encryption algorithms into the power communication system, the problem of low key generation rate in remote power communication is solved, the system's security and anti-cracking capabilities are improved, and the stability and security of information transmission are ensured.

CN116232569BActive Publication Date: 2026-01-27ANHUI NORMAL UNIV +1
View PDF 18 Cites 0 Cited by

Patent Information

Application Number
CN202211679315.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2026-01-27
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

Existing quantum communication technologies for power grids suffer from a low key generation rate in long-distance power communication, resulting in insufficient key quantity and vulnerability to cracking, failing to meet the security requirements of power systems. This is especially true in ultra-high voltage power grids where the transmission distance is long and the environment is harsh, further reducing the key generation rate.

Method used

A dual-key pool mechanism is adopted, including active and backup pools for both the sender and receiver. By grouping and numbering the keys and randomly selecting encryption methods using multiple symmetric encryption algorithms, it is ensured that each key group uses a different encryption algorithm, combined with classic channel transmission of key data packets.

Benefits of technology

This improves the security of power communication systems, increases the difficulty of cracking, and ensures that even if the quantum key distribution system encounters problems, it can continuously provide sufficient keys, avoiding the security degradation caused by key reuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232569B_ABST
    Figure CN116232569B_ABST
Patent Text Reader

Abstract

The application discloses a quantum key use and storage method for remote power communication, both the sender and the receiver have two key pools, one key pool is used for encryption and decryption, and the other key pool is used for accepting new security keys transmitted by a quantum key distribution system. Some binary bits in each group of keys are used as flag bits. The sender randomly selects a group of keys, determines an encryption algorithm according to the flag bits of the keys, encrypts plaintext information to obtain ciphertext, and places the number of the keys and the ciphertext together to obtain a data packet. The receiver finds the corresponding keys according to the key number in the data packet, knows the encryption algorithm according to the flag bits, and decrypts. When the quantum key distribution system fails, the application can ensure that both parties still have enough keys, since each group of keys adopts different encryption methods, the encryption methods of various data packets are different, the difficulty of cracking by attackers is increased, and the security is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application pertains to the field of power communication, and in particular to a method for using and storing quantum keys for remote power communication. Background Technology

[0002] The power grid contains various devices that ensure its normal operation. These devices communicate with each other, and the power communication network is an information and digital network, a dedicated network for the power system. It is primarily used to transmit power system-related data to maintain the safe and stable operation of the power system. In terms of power grid production operations, with the development of the Global Energy Internet and the further improvement of ultra-high voltage backbone networks, the information carrying network is becoming increasingly open, leading to ever-increasing security risks. Traditional physical isolation defenses can be breached through cross-network intrusion, power dispatch instructions can be maliciously tampered with, and power transaction information can be stolen. These are all significant security threats that could lead to widespread power outages and production stoppages, ultimately halting societal functioning. Therefore, maintaining the security of the power grid is a crucial task.

[0003] Employing quantum communication technology can improve the security of power grids. The security of classical encryption algorithms is limited and gradually decreases with the development of technology and mathematical algorithms. In contrast, quantum secure communication is based on the fundamental laws of quantum mechanics, so its "unconditional security" is not affected by the simplification of mathematical calculations. In recent years, a large number of documents on quantum communication technology have emerged, such as Chinese patents with publication numbers CN109714162A, CN110572265A, CN110768793A, CN111786782A, CN111817792A, CN111884798A, CN112491537A, CN112994877A, CN112910636A, CN113259315A, CN114338013A, CN114374901A, CN114553404A, CN114944916A, CN115085915A, and CN215344586U. Ye Zihao from Xi'an University of Electronic Science and Technology published his master's thesis, "Simulation Research on Quantum Metropolitan Area Network Key Management and End-to-End Communication Methods," in June 2021.

[0004] Existing quantum communication technologies cannot meet the needs of the power grid. Currently, power grid security management and communication security mainly include system protection, relay protection, dispatch automation, and video conferencing with encryption requirements. Taking system protection as an example, the maximum transmission distance for system protection is 5000 kilometers. Data is transmitted between regions via ultra-high voltage (UHV) communication lines, characterized by long transmission distances, high real-time requirements, and large bandwidth. However, quantum channels transmit weak single-photon signals via optical fibers, making them susceptible to environmental influences. Various environments exist along communication lines spanning thousands of kilometers, and optical fibers connected to high-voltage cables can experience wind vibration, galloping, and icing. Although combining UHV power grid services with quantum encryption technology can significantly improve the security level of transmission, the long spans, long transmission distances, and harsh electromagnetic environments of substations in UHV power grids can still have adverse effects.

[0005] The main drawback of existing quantum communication technology in power grids is its low secure key generation rate, which refers to the number of secure keys generated per second. In quantum key distribution, one party generates the initial quantum key, which is then transmitted to the other. Both parties then need to perform basis vector comparison, error correction, and other processing. Some devices also perform security amplification to ultimately generate a shared key. The secure key refers to the final shared key generated by the quantum key distribution device. The secure key generation rate is the number of secure keys generated per second, also known as the "secure key generation rate."

[0006] In her professional master's thesis, "Research on Testing Technology of Power Quantum Secure Communication System," published in March 2019, Ma Ruxin of North China Electric Power University pointed out that a 50MHz phase-type QKD system can generate keys stably and normally in an overhead power environment (the total length of the loopback fiber is approximately 1.973km, and the attenuator is 14.73dB), with a secure key generation rate of approximately 1700bps. When the temperature drops below 0 degrees Celsius, the generation rate drops to 1500bps. Using relays can effectively extend the communication distance. However, due to the long transmission distance (reaching thousands of kilometers), various extreme environments and even human attacks and sabotage may be encountered along the way, further reducing the secure key generation rate.

[0007] Classical communication channels offer high transmission speeds, reaching tens of Mbps, while quantum key generation rates are too low, only 1.5 Kbps. This results in a severe shortage of effective keys, necessitating the repeated use of the same key and encryption method, compromising security. In power communication networks, large amounts of power information are continuously transmitted, containing much repetition in plaintext. For example, most power dispatch instructions share the same main parts, differing only in parameters; similarly, most power telemetry instructions also share the same main parts, differing only in parameters. This similarity in plaintext information makes keys easier to crack, posing a vulnerability to the power system. Summary of the Invention

[0008] To address the problems existing in the prior art, this invention discloses a method for using and storing quantum keys in remote power communication;

[0009] Both the sender and the receiver have two key pools: the sender's active pool and the sender's backup pool, and the receiver's active pool and the receiver's backup pool. The sender's key pool and the receiver's key pool have the same capacity.

[0010] The active pool of keys is used to encrypt and decrypt data; the backup pool is used to store the security keys transmitted by the quantum key distribution system.

[0011] When the backup pool is full, it is converted into the active pool, and the original active pool becomes the backup pool. All old keys in the backup pool are discarded, and the backup pool accepts new security keys. When the backup pool is full of new security keys, the backup pool and the active pool are swapped again, and the backup pool becomes the new active pool, and the old active pool becomes the backup pool. The key distribution and the swapping of the active pool and the backup pool are repeated.

[0012] The communicating parties divide the key into groups and number each group of keys; the binary bits in each group of keys are used as flag bits;

[0013] The sender receives a set of plaintext information; the sender randomly selects a set of keys from the existing pool, reads the flag bits, and determines the encryption algorithm based on the flag bits; the sender uses the key to encrypt the set of plaintext information according to the encryption algorithm to obtain a set of ciphertext; the sender puts the key number and the set of ciphertext together to obtain a data packet; the sender transmits the data packet to the receiver through the classic channel.

[0014] The receiver reads the key number in the data packet, finds the corresponding key in the active pool based on the key number, knows the encryption algorithm based on the flag bit, and decrypts the data packet to obtain the plaintext;

[0015] The encryption algorithm described is a symmetric encryption algorithm.

[0016] Preferably, the encryption algorithm includes AES, or SM4, or ZUC encryption algorithms, and each key is 128 bits long.

[0017] This invention offers beneficial technical advantages. It solves the problem in remote power communication systems where insufficient security keys are generated due to low key generation rates, leading to key reuse and vulnerability to cracking, and reduced security. The key pool in this invention is divided into a current pool and a backup pool. The current pool always contains a sufficient number of keys, ensuring secure encryption even if the quantum key distribution system malfunctions, resulting in a very low key generation rate. Once the quantum key distribution system recovers, the backup pool is filled with new security keys before becoming the current pool. Although the same set of keys is used multiple times, each set employs a different encryption method. Because keys are randomly selected, adjacent data packets use different keys and encryption methods. Even if an attacker knows the key number, they do not know the key content or encryption method, requiring them to try multiple encryption algorithms, thus increasing the difficulty of cracking the encryption and effectively improving network communication security. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention and do not constitute a limitation of the present invention.

[0019] Figure 1 These are the active pool and backup pool of the sender and receiver in the embodiments of the present invention.

[0020] Figure 2 In this embodiment of the invention, the keys are grouped and numbered.

[0021] Figure 3 This is a flag bit for the key used in embodiments of the present invention.

[0022] Figure 4 This describes the encryption, data transmission, and decryption processes in this embodiment of the invention.

[0023] Figure 5 In this embodiment of the invention, the key number and a set of ciphertext are put together to form a data packet. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. In addition, the present invention may repeat reference numerals and / or reference text in different embodiments. Such repetition is for the purpose of simplification and clarity, and does not in itself indicate the relationship between the various implementation methods and / or settings discussed.

[0025] This embodiment describes a method for using and storing quantum keys in remote power communication. Both the sender and receiver have two key pools: a sender's active pool and a sender's backup pool, and a receiver's active pool and a receiver's backup pool. The sender's key pool and the receiver's key pool have the same capacity. The keys in the active pool are used to encrypt and decrypt data; the backup pool stores the security keys transmitted by the quantum key distribution system, i.e., the shared keys generated by the quantum key distribution device between the two parties. (Reference) Figure 1 .

[0026] When the backup pool is full, it is converted into the active pool, and the original active pool becomes the backup pool. All old keys in the backup pool are discarded. The backup pool receives new security keys from the quantum key distribution system. When the backup pool is full of new security keys, the backup pool and the active pool are swapped again, and the backup pool becomes the new active pool, and the old active pool becomes the backup pool. Security keys are distributed repeatedly, and the active pool and backup pool are swapped repeatedly.

[0027] Based on the estimated key generation rate of approximately 1500 bps for quantum communication in power systems as reported in the literature, with continuous key transmission 24 hours a day, 123.6 Mbit of keys would be obtained daily. In this embodiment, both the backup pool and the active pool have a key capacity of 128 Mbit, meaning they can both store 128 Mbit of keys. If the quantum key distribution system malfunctions, the keys in the backup pool can only be fully updated and the backup pool can only be converted into the active pool after the fault is recovered. The active pool always contains 128 Mbit of keys, ensuring that even if the quantum key distribution system malfunctions and the secure key generation rate is very low, there will always be enough keys to ensure effective encryption of information.

[0028] The communicating parties divide the key into packets; Figure 2 This describes the key grouping process in this embodiment of the invention. Both communicating parties divide their existing key pools into multiple groups using the same method. In this embodiment, the groups are formed according to the order of the binary numbers. The first binary number is the first group of keys, the next binary number is the second group of keys, and so on, until the nth group of keys, which is the last group. Figure 2Each key group is 128 bits long, resulting in 1M key groups. In other embodiments, the last binary number can be used as the first key group, and the first binary number can be used as the nth key group.

[0029] Both communicating parties assign a number to each set of keys; in this embodiment, the set number of each key is the same as the serial number. Figure 2 In the diagram, the key number of the first group is 1, the key number of the second group is 2, the key number of the third group is 3, the key number of the kth group is k, and so on, with the key number of the last group being 1048576.

[0030] Both communicating parties use certain binary bits from each key as flag bits, see reference. Figure 3 In this embodiment, the first, third, and fifth binary bits are used as flag bits. These three binary digits, arranged together, can produce eight possible results, corresponding to the decimal numbers 0, 1, 2, 3, 4, 5, 6, and 7. Figure 3 In the example, the result is 110, which corresponds to the decimal number 6.

[0031] exist Figure 3 In this embodiment, decimal numbers 0 to 7 each correspond to an encryption algorithm:

[0032] 0 corresponds to the AES algorithm, which uses only the AES algorithm for encryption and encrypts only once.

[0033] 1 corresponds to the SM4 algorithm, which is used only for encryption and is encrypted only once.

[0034] 2 corresponds to the ZUC algorithm, which is used only for encryption and is encrypted only once;

[0035] 3 corresponds to ZUC+SM4. First, use the ZUC algorithm to encrypt once to obtain an intermediate result, then use the SM4 algorithm to perform an encryption operation on the intermediate result, and use the final result as the ciphertext.

[0036] The algorithm corresponding to 4 is AES+SM4. First, the AES algorithm is used to encrypt the intermediate result once, and then the SM4 algorithm is used to encrypt the intermediate result once. The final result is used as the ciphertext.

[0037] 5 corresponds to AES+ZUC. First, use the AES algorithm to encrypt once to obtain an intermediate result, then use the ZUC algorithm to encrypt the intermediate result once, and use the final result as the ciphertext.

[0038] 6 corresponds to XOR+AES, which first uses the key to perform an XOR operation on the plaintext, and then uses the AES algorithm to encrypt it;

[0039] 7 corresponds to XOR+ZUC, which first uses the key to perform an XOR operation on the plaintext, and then uses the ZUC algorithm to encrypt it.

[0040] The positions of the flag bits used by both communicating parties are completely identical. In other embodiments, other binary bits can be selected as flag bits, such as the 2nd binary bit, the mth binary bit, the jth binary bit, the last binary bit, and so on. Those skilled in the art can also choose other binary bits in the key as flag bits without any creative effort. The above embodiments provide several algorithms for corresponding flag bits; this is merely an exemplary correspondence method. Those skilled in the art can also use other algorithms to correspond flag bits without any creative effort.

[0041] In the above embodiment, three binary bits were selected as flag bits. In other embodiments, one, two, four or more binary bits may be selected as flag bits.

[0042] In one embodiment, two binary bits are used as flag bits. These two binary bits can produce four results, corresponding to the decimal numbers 0, 1, 2, and 3, which correspond to the XOR, XOR+AES, AES, and AES+SM4 algorithms, respectively.

[0043] The sender receives a set of plaintext information; the sender randomly selects a set of keys from the existing pool, reads the flag bits, and determines the encryption algorithm based on the flag bits, referring to... Figure 4 The plaintext information is encrypted using the key and the encryption algorithm to obtain a set of ciphertext.

[0044] The sender combines the key number with the ciphertext to obtain a data packet. In the previous embodiment, the key pool contains 1M keys, each represented by a 24-bit binary number (3 bytes). The first two bytes of the key number are placed at the beginning of the ciphertext, and the last byte is placed at the end, resulting in a data packet. (Refer to...) Figure 5 In another embodiment, all bytes representing the key number are placed before the ciphertext. Those skilled in the art can determine the positions of the key number and ciphertext within the data packet without requiring any inventiveness.

[0045] The sender transmits the data packet to the receiver via a classic channel, which in this embodiment is constructed using optical fibers. The technique of transmitting data via a classic channel is well-known in the art.

[0046] The receiver receives the data packet, reads the key number from the packet, finds the corresponding key based on the key number, obtains the encryption algorithm based on the flag bits, decrypts the ciphertext, and obtains a set of plaintext; (Reference) Figure 4The right side of the image shows the encryption method used for different keys in this invention. Each data packet is encrypted differently. Even if an attacker knows the key number, they do not know the specific content of the key, and therefore do not know the encryption method. Attackers would need to try multiple encryption algorithms, increasing the difficulty of cracking the encryption. This effectively improves the security of network communication.

[0047] The encryption algorithm used in this embodiment is a symmetric encryption algorithm because both parties use the same key. The advantage of symmetric encryption algorithms is their high encryption efficiency, making them suitable for large-scale data encryption.

[0048] The encryption algorithms used in this embodiment include AES, SM4, and ZUC, with each key being 128 bits long. There are various symmetric encryption algorithms, and their design methods are publicly available. New symmetric encryption algorithms are disclosed annually in the "National Cryptography Technology Competition" held by the Chinese Association for Cryptologic Research. Dozens of encryption algorithms have been disclosed in the Competition for Authenticated Encryption: Security, Applicability, and Robustness held in the United States. However, AES, SM4, and ZUC algorithms have gained widespread acceptance. These three algorithms have long been fully disclosed, with detailed descriptions available in publicly available materials. Furthermore, all three algorithms have become national standards. They possess several significant advantages: they can be implemented in hardware, have high computational speed, and the relevant hardware and software are readily available.

[0049] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for using and storing quantum keys in remote power communication, characterized in that: Both the sender and the receiver have two key pools: the sender's active pool and the sender's backup pool, and the receiver's active pool and the receiver's backup pool. The sender's key pool and the receiver's key pool have the same capacity. The security keys in the active pool are used to encrypt and decrypt data; the backup pool is used to store the security keys transmitted by the quantum key distribution system. When the backup pool is full, it is converted into the active pool, and the original active pool becomes the backup pool. All old security keys in the backup pool are discarded, and the backup pool receives new security keys. When the backup pool is full of new security keys, the backup pool and the active pool are swapped, and the backup pool becomes the new active pool, and the old active pool is converted into the backup pool. Security keys are repeatedly distributed, and the active pool and the backup pool are repeatedly swapped. The two communicating parties group the security keys and assign a number to each group of security keys; Use a portion of the bits in each binary security key as flag bits; The sender receives a set of plaintext information; the sender randomly selects a set of security keys from the existing pool, reads the flag bits, and determines the encryption algorithm based on the flag bits. The plaintext information is encrypted using the security key and the encryption algorithm to obtain a ciphertext. The security key number and the ciphertext are then combined to form a data packet. The sender transmits the data packet to the receiver via a classic channel. The receiver reads the security key number in the data packet, finds the corresponding security key in the active pool based on the security key number, knows the encryption algorithm based on the flag bit, and decrypts the data packet to obtain the plaintext; The encryption algorithm described is a symmetric encryption algorithm.

2. The method for using and storing quantum keys in remote power communication according to claim 1, characterized in that: The encryption algorithms include AES, SM4, and ZUC, with each security key being 128 bits long.

Citation Information

Patent Citations

  • A quantum key expansion method and system

    CN109714162A

  • Terminal security access gateway method, device and system based on quantum communication

    CN110572265A

  • Two-stage quantum state cooperative multicast method based on butterfly network structure

    CN110768793A

  • 2M link terminal equipment special for electric power and encryption and decryption method of 2M link data

    CN111786782A

  • Quantum remote state transfer system adapted to power protection service

    CN111817792A