Quantum-based power distribution automation protection methods and systems

By implementing built-in isolation and hardening of the quantum security service platform and redundancy deployment of key node devices, the security risks and low communication levels of the quantum encryption platform have been resolved, enabling stable system operation and localized management.

CN116455564BActive Publication Date: 2026-05-26FANERJIA INTELLIGENT ELECTRIC CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FANERJIA INTELLIGENT ELECTRIC CO LTD
Filing Date
2023-04-19
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Quantum encryption platforms have security risks, some nodes have outdated equipment, and the level of communication security at the prefecture and county levels is low, making localized management difficult.

Method used

By implementing built-in isolation and hardening of the quantum security service platform and redundancy deployment of key node devices, a secure communication channel is established to achieve forward and reverse physical isolation and device redundancy, thereby enhancing security and stability.

Benefits of technology

It improved the security and system stability of the quantum encryption platform, enhanced the security of local and county-level communications, and enabled localized management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455564B_ABST
    Figure CN116455564B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for power distribution automation protection based on quantum encryption, relating to the field of quantum secure communication applications. The method includes: strengthening the quantum security service platform with built-in isolation and redundancy deployment of key node equipment; establishing a first secure communication channel between the power distribution master station and the quantum security service platform, and a second secure communication channel between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway. If a power distribution terminal initiates a data request, a session key is obtained through the quantum security service platform; a quantum key is obtained based on the session key for data encryption; the session key is then injected into the quantum key injection substation through the second secure communication channel; the data is decrypted through the secure access gateway; and the decrypted business data is sent to the power distribution master station. This invention enhances the security of the quantum encryption platform, ensures stable system operation, improves the security level of communication with local governments, and enables localized management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum secure communication application technology, specifically to a power distribution automation protection method and system based on quantum encryption. Background Technology

[0002] With the continuous advancement of the energy internet construction, a large number of new power consumption facilities are being connected to the grid. The widespread grid connection equipment places higher demands on grid communication security. Taking Zhejiang as an example, all 11 municipal power supply companies in Zhejiang Province have deployed quantum encryption security service platform systems, carried out large-scale transformation of wireless public network remote control for overhead line intelligent switches, and conducted pilot applications for local control of low-voltage distribution areas.

[0003] In existing technologies, when power distribution terminals undergo hardware upgrades, a quantum encryption chip is typically installed on the mainboard of the core unit, connected in series between the State Grid encryption module and the communication module. This chip is used for data transmission between the power distribution terminal and the quantum communication device for remote monitoring, remote maintenance, and program upgrades. However, with the increasing adoption of quantum encryption applications, the quantum encryption platform remains deployed on the external network, posing security risks. Furthermore, the platform often uses single-device architectures at some nodes, making it unable to function properly in case of anomalies. Additionally, the communication security level of county and prefecture-level main stations is low, and the injection of protection keys (key filling) must be centralized at the municipal bureau's main station, leading to difficulties in localized management. Summary of the Invention

[0004] The purpose of this invention is to address the security risks of quantum encryption platforms in quantum encryption applications, the lack of diversity in some node devices, and the low level of communication security at the prefecture and county levels. It proposes a power distribution automation protection method based on quantum encryption, which enhances the security of the quantum encryption platform and ensures stable system operation while improving the security of communication with prefectures and counties, thus achieving localized management.

[0005] In a first aspect, the technical solution provided in this embodiment of the invention is a power distribution automation protection method based on quantum encryption, applicable to power distribution networks. The power distribution network includes a power distribution master station, a power distribution substation, and a quantum security service platform. The power distribution substation includes a quantum key injection substation. The method comprises the following steps:

[0006] The quantum security service platform is equipped with built-in isolation and hardening, as well as redundant deployment of key node devices;

[0007] A first secure communication channel is established between the power distribution master station and the quantum security service platform, and a second secure communication channel is established between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway.

[0008] If the power distribution terminal initiates a data request, it obtains a session key through the quantum security service platform, encrypts the data using a quantum key based on the session key, and then injects the session key into the quantum key injection substation of the power distribution station through the second secure communication channel.

[0009] The data is decrypted through the secure access gateway, and the decrypted business data is sent to the power distribution master station.

[0010] Optionally, the quantum security service platform includes a raw quantum security service module, which includes a quantum key generation module, a quantum key scheduling module, a quantum key application module, and a quantum network management module connected by communication. The step of internally isolating and hardening the quantum security service platform includes:

[0011] The quantum key generation module, the quantum key scheduling module, the quantum key application module, and the quantum network management module are reinforced with forward and reverse isolation. The quantum key generation module is connected to the power distribution terminal through a first communication connection terminal, and the data request is sent to the quantum key generation module through the first signal connection terminal.

[0012] Optionally, the redundant deployment of critical node devices in the quantum security service platform includes:

[0013] Based on the original quantum security service module, a quantum cryptography service engine mirror device, a first quantum key service mirror device, a second quantum key service mirror device, and a forward and reverse security isolation device are deployed. The quantum cryptography service engine mirror device is connected to the forward and reverse security isolation device through a second communication connection terminal. The forward and reverse security isolation device is connected to one end of the first quantum key service mirror device and the second quantum key service mirror device through a third communication connection terminal. The other end of the first quantum key service mirror device and the second quantum key service mirror device is connected to a fourth communication connection terminal. The fourth communication connection terminal is connected to the secure access gateway.

[0014] Optionally, the quantum key generation module includes a single-send quantum key generation and management terminal, a single-receiver quantum key generation and management terminal, and a quantum random number generator. The step of obtaining a session key through the quantum security service platform and then using the session key to obtain a quantum key for data encryption includes:

[0015] If any communication connection terminal receives a data request sent by the power distribution terminal, a quantum random number is generated by the quantum random number generator, and a session key is generated by the single-sender quantum key generation and management terminal and the single-receiver quantum key generation and management terminal.

[0016] The quantum key scheduling module generates the quantum key based on the session key and the quantum random number, and uses the quantum key to encrypt the business data contained in the data request.

[0017] Optionally, the quantum key scheduling module includes a cryptographic exchange machine, a quantum cryptographic service engine device, and a quantum key injection device. The step of encrypting the business data contained in the data request using the quantum key includes:

[0018] The business data is encrypted using the exchange cryptographic machine, and the quantum key is distributed to the quantum cryptographic service engine device.

[0019] According to the preset scheduling and negotiation rules, the quantum cryptography service engine device distributes the quantum key to the quantum key application module and performs key injection on the quantum key through the quantum key injection device;

[0020] If an abnormal event is detected in the quantum cryptography service engine device, the quantum key is distributed to the quantum key application module through the quantum cryptography service engine mirror device according to the preset scheduling negotiation rules.

[0021] Optionally, the quantum network management module includes a quantum network management database server and a quantum network management service server connected in communication. During the quantum encryption process, the quantum network management database server and the quantum network management service server are used to perform network management and monitoring of the operating status of the quantum key generation module, the quantum key scheduling module, and the quantum key application module.

[0022] Optionally, the secure access gateway includes a quantum secure access gateway connected to and deployed on one side of the quantum secure service platform, and a distribution network security gateway deployed on the side of the distribution master station. The step of decrypting data through the secure access gateway and sending the decrypted service data to the distribution master station includes:

[0023] The service data is encrypted and transmitted through the quantum secure access gateway and the distribution network secure access gateway, and then decrypted through the distribution network secure gateway on the distribution master station side, and the decrypted service data is sent to the distribution master station.

[0024] Optionally, the second secure communication channel includes a first quantum key transmission device that is communicatively connected to the power distribution master station and the quantum security service platform, and a second quantum key transmission device deployed in the power distribution substation and communicating securely with the first quantum key transmission device. The second quantum key transmission device communicates with the quantum key charging substation and the power distribution equipment in the power distribution substation. The first quantum key transmission device and the second quantum key transmission device are used for communication transmission between the power distribution master station and the power distribution substation, and for the quantum key charging device to charge the quantum key charging substation with quantum keys.

[0025] Secondly, the present invention also provides a quantum-encrypted power distribution automation protection system, used to execute the quantum-encrypted power distribution automation protection method described in any embodiment, the system comprising:

[0026] The quantum security service platform deployment module is used to perform built-in isolation hardening and redundant deployment of key node devices on the quantum security service platform.

[0027] The channel establishment module is used to establish a first secure communication channel between the power distribution master station and the quantum security service platform, and a second secure communication channel between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway.

[0028] The key acquisition module is used to acquire a session key through the quantum security service platform if the power distribution terminal initiates a data request, acquire a quantum key based on the session key to encrypt the data, and inject the session key into the quantum key injection substation of the power distribution station through the second secure communication channel.

[0029] The master station data transmission module is used to decrypt data through the secure access gateway and send the decrypted business data to the power distribution master station.

[0030] Optionally, the quantum security service platform includes a raw quantum security service module, which comprises a quantum key generation module, a quantum key scheduling module, a quantum key application module, and a quantum network management module connected by communication links. The quantum security service platform is internally isolated and hardened. The quantum security service platform deployment module is specifically used for:

[0031] The quantum key generation module, the quantum key scheduling module, the quantum key application module, and the quantum network management module are reinforced with forward and reverse isolation. The quantum key generation module is connected to the power distribution terminal through a first communication connection terminal, and the data request is sent to the quantum key generation module through the first signal connection terminal.

[0032] The beneficial effects of this invention are as follows: By embedding isolation and hardening into the quantum security service platform, this invention achieves forward and reverse physical isolation, enhancing the platform's security level. Redundant deployment of critical node devices in the quantum security service platform allows for replacement in case of malfunctions, ensuring stable system operation. Furthermore, by establishing a first and a second secure communication channel, during power distribution, when a data request is received from a power distribution terminal, encrypted data transmission can be performed via the first secure communication channel, ensuring the security of encrypted data transmission. The second secure communication channel enables encrypted data transmission between the power distribution master station and the distribution substation, further enhancing data transmission security. Moreover, the quantum security service platform can perform key filling at the quantum key filling substation of the distribution substation via the second secure communication channel, facilitating data encryption and decryption operations at the distribution substation and enabling localized management. Therefore, this invention enhances the security of the quantum encryption platform, ensures stable system operation, improves the security of communication with local governments, and achieves localized management.

[0033] The above description of the invention is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description

[0034] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings. The drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings.

[0035] Figure 1 A flowchart illustrating a power distribution automation protection method based on quantum encryption provided in an embodiment of the present invention;

[0036] Figure 2 This is an overall topology diagram of the power distribution master station and power distribution substation provided in an embodiment of the present invention;

[0037] Figure 3 This is a schematic diagram of the structure of a power distribution automation protection system based on quantum encryption, provided in an embodiment of the present invention. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only one preferred embodiment of this invention and are only used to explain this invention. They do not limit the scope of protection of this invention. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0039] Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the operations (or steps) as sequential processes, many of the operations (or steps) can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but it may also have additional steps not included in the figures; the process may correspond to a method, function, procedure, subroutine, subroutine, etc.

[0040] The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. It should also be understood that in the various embodiments of the invention, the sequence number of each process does not imply a specific order of execution; the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the invention.

[0041] It should be understood that in this invention, "multiple" refers to two or more. "And / or" is merely a variable relationship describing the related objects, indicating that three relationships can exist. For example, "and / or B" can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. "Contains A, B, and C", "Contains A, B, and C" means that all three A, B, and C are contained; "Contains A, B, or C" means that one of A, B, and C is contained; "Contains A, B, and / or C" means that any one, two, or three of A, B, and C are contained.

[0042] It should be understood that in this invention, "B corresponding to A", "B corresponding to A", "A and B correspond", or "B and A correspond" means that B is associated with A, and B can be determined based on A. Determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information. Matching A and B is defined as a similarity between A and B that is greater than or equal to a preset threshold.

[0043] Example 1

[0044] like Figure 1 The diagram shown is a flowchart of the power distribution automation protection method based on quantum encryption provided in this embodiment. The power distribution automation protection method based on quantum encryption includes the following steps:

[0045] S1. The quantum security service platform is reinforced with built-in isolation and redundant deployment of key node devices;

[0046] S2. Establish a first secure communication channel between the power distribution master station and the quantum security service platform, and a second secure communication channel between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway.

[0047] S3. If the power distribution terminal initiates a data request, it obtains a session key through the quantum security service platform, obtains a quantum key based on the session key to encrypt the data, and injects the session key into the quantum key injection substation of the power distribution station through the second secure communication channel.

[0048] S4. Decrypt the data through the secure access gateway and send the decrypted business data to the power distribution master station.

[0049] Specifically, the quantum-encrypted power distribution automation protection method provided in this embodiment of the invention is applicable to power distribution networks. A power distribution network may include a power distribution master station, power distribution substations, and a quantum security service platform. A quantum key injection substation is deployed in the power distribution substation. The power distribution master station may refer to a municipal-level power distribution automation master station, and the power distribution substation may refer to a county-level workstation. Feeder Terminal Units (FTUs) can communicate with the power distribution master station via the quantum security service platform. Data requests sent via the quantum security service platform are encrypted and uploaded to the power distribution master station, enabling communication with the master station. Similarly, the power distribution master station can also encrypt commands issued via the quantum security service platform before sending commands to the FTUs. Data requests may include, but are not limited to, fault check requests and monitoring data upload requests; commands may include, but are not limited to, adjusting and controlling the power distribution terminals to achieve fault location and isolation.

[0050] More specifically, the aforementioned quantum security service platform can refer to a platform that uses quantum encryption technology to encrypt and decrypt data transmitted between power distribution terminals and power distribution master stations. Quantum encryption technology utilizes quantum principles for key generation, plaintext obfuscation encryption, ciphertext decryption, ciphertext communication, and anti-eavesdropping, among other encryption techniques. The quantum security service platform includes built-in devices for quantum key generation, encryption / decryption, and key distribution. To enhance the security level of these built-in devices, risk isolation techniques can be used for risk isolation and hardening. For example, forward and reverse isolation techniques in network security measures can be used to isolate and harden the built-in devices. The aforementioned critical nodes can include essential equipment with high operational loads within the quantum security service platform, such as quantum cryptography service engine devices and quantum key service devices. In this embodiment, to avoid system instability caused by downtime at critical nodes, at least one set of redundant critical node devices can be deployed in the quantum security service platform. When a critical node device fails, the system can switch to the redundant critical node device to continue providing normal operation services, ensuring the normal operation of the system.

[0051] More specifically, the aforementioned first secure communication channel can be a channel for secure data transmission between the quantum security service platform and the power distribution master station. The aforementioned second secure communication channel can be a channel for secure data transmission between the power distribution master station and the power distribution substation. Specifically, the quantum security service platform and the power distribution master station can achieve encrypted communication based on a secure access gateway, and the power distribution master station and the power distribution substation can achieve encrypted communication by setting up an encrypted transmission device. The secure access gateway can act as an entry device in the network, establishing a secure encrypted tunnel between the quantum security service platform and the power distribution master station, completing identity authentication and protocol conversion, and realizing encrypted data transmission between the quantum security service platform and the power distribution master station.

[0052] More specifically, when a power distribution terminal initiates a data request, the quantum security service platform outputs a session key and uses this session key to obtain a quantum key to encrypt the business data in the data request. Simultaneously, the second secure communication channel can also be used for communication between the quantum security service platform and the power distribution substation. This channel is used to inject the session key into a quantum key injection substation deployed in the power distribution substation. When the power distribution master station and the power distribution substation transmit encrypted data, the session key can be directly obtained from the quantum key injection substation, eliminating the need to obtain it from the quantum security service platform on the power distribution master station side. This allows the session key to be distributed down to the district / county level, enabling localized management, improving work efficiency, and simultaneously enabling district / county access to quantum secure communication functionality. Each request corresponds to one quantum key, following a one-time pad encryption principle. The encrypted business data can be decrypted at the secure access gateway on the power distribution master station side and sent to the power distribution master station. Upon receiving the business data, the power distribution master station can respond to the data request. For example, if the business data indicates a high-temperature fault at point A, the power distribution master station issues a control command to shut down point A.

[0053] In this embodiment of the invention, by embedding isolation and hardening into the quantum security service platform, forward and reverse physical isolation can be achieved, improving the platform's security protection level. By redundant deployment of key node devices in the quantum security service platform, replacement can be performed when key node devices malfunction, ensuring stable system operation. Furthermore, a first secure communication channel and a second secure communication channel are established. During power distribution, when a data request is received from a power distribution terminal, encrypted data transmission can be performed via the first secure communication channel, ensuring the security of encrypted data transmission. The second secure communication channel enables encrypted data transmission between the power distribution master station and the power distribution substation, enhancing data transmission security. Moreover, the quantum security service platform can perform key filling at the quantum key filling substation of the power distribution substation via the second secure communication channel, facilitating data encryption and decryption operations at the power distribution substation and enabling localized management. Therefore, this invention enhances the security of the quantum encryption platform, ensures stable system operation, improves the security of communication with local governments, and achieves localized management.

[0054] In this embodiment, the quantum security service platform includes a basic quantum security service module, which includes a quantum key generation module, a quantum key scheduling module, a quantum key application module, and a quantum network management module connected by communication. Step S1 above, which involves internally isolating and hardening the quantum security service platform, includes:

[0055] The quantum key generation module, the quantum key scheduling module, the quantum key application module, and the quantum network management module are reinforced with forward and reverse isolation. The quantum key generation module is connected to the power distribution terminal through a first communication connection terminal, and the data request is sent to the quantum key generation module through the first signal connection terminal.

[0056] Specifically, the aforementioned original quantum security service module can refer to the basic quantum security service platform. The built-in isolation hardening and redundant deployment of key node devices in this invention are deployments based on the basic quantum security service platform. The aforementioned quantum key generation module can generate quantum keys based on quantum properties, providing quantum key support for the quantum key scheduling module and the quantum key application module. The aforementioned quantum key scheduling module can realize quantum key storage and output, negotiation scheduling, and session key filling. The aforementioned quantum key application module can utilize quantum keys to construct quantum secure encrypted transmission channels, such as the first secure communication channel, to improve the security level of 4G / 5G transmission channels and ensure that business data can be securely transmitted to the secure access area and forwarded to the power distribution master station or other business systems. Among them, the secure access area includes the quantum secure access area deployed on the quantum security service platform side and the municipal bureau wireless secure access area deployed on the power distribution master station side. The aforementioned quantum network management module can realize network management and monitoring of the operating status of quantum devices on the quantum security service platform, and monitoring the operating status can provide operation and maintenance support. The aforementioned first communication connection end can refer to multiple switches deployed in the original quantum security service module. Each switch can provide a dedicated electrical signal path for any two network nodes connected to it, such as an Ethernet switch or a fiber optic switch. In this embodiment, one end of the switch can be connected to a power distribution terminal, and the other end can be communicatively connected to the quantum key generation module of the original quantum security service module. After the power distribution terminal sends a data request, the data is transmitted to the quantum key generation module via the switch to generate a quantum key.

[0057] More specifically, isolation and hardening can be achieved through forward and reverse isolation. Forward and reverse isolation is a network security measure that isolates quantum devices with different security levels to prevent information leakage and attacks. This can be achieved in two ways: First, through network topology design, high-security and low-security quantum devices are isolated in different physical areas. For example, after dividing the quantum devices in the quantum security service platform according to preset security levels, the quantum key generation module and quantum key scheduling module are isolated in a first-level security area, and the quantum key application module is isolated in a second-level security area. The first-level security area has a higher security level than the second-level security area. Second, network security devices perform security detection and filtering on data, allowing only legitimate data to pass. For example, a firewall or intrusion detection system is deployed in the original quantum security service module of the quantum security service platform. When an attacker intends to enter the quantum security service platform or some of its quantum devices, the firewall or intrusion detection system checks the legitimacy of the data, ultimately allowing only legitimate data to pass, thus isolating illegitimate data.

[0058] After the above-mentioned reinforcement based on forward and reverse isolation, even if an attacker successfully enters the low-security area of ​​the quantum security service platform, they will not be able to directly attack the high-security quantum devices. This achieves the division of the internal and external network security boundaries of the quantum security service platform, thereby improving network security.

[0059] In this embodiment, step S1 above, which involves redundant deployment of critical node devices in the quantum security service platform, includes:

[0060] Based on the original quantum security service module, a quantum cryptography service engine mirror device, a first quantum key service mirror device, a second quantum key service mirror device, and a forward and reverse security isolation device are deployed. The quantum cryptography service engine mirror device is connected to the forward and reverse security isolation device through a second communication connection terminal. The forward and reverse security isolation device is connected to one end of the first quantum key service mirror device and the second quantum key service mirror device through a third communication connection terminal. The other end of the first quantum key service mirror device and the second quantum key service mirror device is connected to a fourth communication connection terminal. The fourth communication connection terminal is connected to the secure access gateway.

[0061] Specifically, in combination Figure 2As shown, based on the original quantum security service module, a quantum cryptography service engine mirror device can be deployed as a backup device for the quantum cryptography service engine device in the quantum key scheduling module. A first quantum key service mirror device and a second quantum key service mirror device can also be deployed to implement quantum key management. The first and second quantum key service mirror devices serve as backup devices for each other. When the first quantum key service mirror device is the master device, the second quantum key service mirror device is the backup device; when the second quantum key service mirror device is the master device, the first quantum key service mirror device is the backup device. Furthermore, at least one forward and reverse security isolation device is deployed between the first and second quantum key service mirror devices and the quantum cryptography service engine mirror device for forward and reverse isolation reinforcement, enhancing the security and protection level of data transmission, such as by adding a firewall. The deployed quantum cryptography service engine mirror device, first quantum key service mirror device, second quantum key service mirror device, and forward and reverse security isolation device constitute a complete set of redundant critical node devices.

[0062] More specifically, the aforementioned second, third, and fourth communication connection terminals can be service exits provided for power distribution terminals, and each communication connection terminal can include at least one switch. In this embodiment, each communication connection terminal includes two switches, and by providing multiple service exits, disaster recovery functionality can be achieved, ensuring uninterrupted service for key applications. The aforementioned fourth communication connection terminal is connected to a secure access gateway, and a quantum network management proxy server is connected between the third and fourth communication connection terminals for network management and monitoring of the newly deployed first and second quantum key service mirror devices. By deploying multiple switches, more power distribution equipment can be connected to meet the needs of more devices. Furthermore, to address the issue of excessive data requests and large data volumes during quantum key generation due to the increase in power distribution equipment, the deployment of a quantum cryptography service engine mirror device, a first quantum key service mirror device, a second quantum key service mirror device, and a forward and reverse security isolation device not only ensures the management and security protection level of quantum key generation but also enhances the stability and data processing capabilities of the quantum security service platform by deploying mirror devices to assist in the operation.

[0063] In this embodiment, the quantum key generation module includes a single-send quantum key generation and management terminal, a single-receiver quantum key generation and management terminal, and a quantum random number generator. In step S3 above, obtaining a session key through the quantum security service platform and then using that session key to obtain a quantum key for data encryption includes:

[0064] If any communication connection terminal receives a data request sent by the power distribution terminal, a quantum random number is generated by the quantum random number generator, and a session key is generated by the single-sender quantum key generation and management terminal and the single-receiver quantum key generation and management terminal.

[0065] The quantum key scheduling module generates the quantum key based on the session key and the quantum random number, and uses the quantum key to encrypt the business data contained in the data request.

[0066] Specifically, when any of the aforementioned switches receives a data request from the power distribution terminal, it can transmit the data request to the quantum key generation module. In this embodiment, two quantum random number generators can randomly generate two quantum random numbers for the data request. A single-sender quantum key generation and management terminal and a single-receiver quantum key generation and management terminal are then used to generate and output session keys. The generated quantum random numbers and session keys are transmitted to the quantum key scheduling module for quantum key generation and negotiation scheduling. The generated quantum keys are then used to encrypt the business data. The single-sender and single-receiver quantum key generation and management terminals are managed and monitored through a quantum key management system server.

[0067] In this embodiment, the quantum key scheduling module includes a switching cryptographic machine, a quantum cryptographic service engine device, and a quantum key injection device. The step of encrypting the business data contained in the data request using the quantum key includes: encrypting the business data using the switching cryptographic machine and distributing the quantum key to the quantum cryptographic service engine device.

[0068] According to the preset scheduling and negotiation rules, the quantum cryptography service engine device distributes the quantum key to the quantum key application module and performs key injection on the quantum key through the quantum key injection device;

[0069] If an abnormal event is detected in the quantum cryptography service engine device, the quantum key is distributed to the quantum key application module through the quantum cryptography service engine mirror device according to the preset scheduling negotiation rules.

[0070] Specifically, the aforementioned session key and quantum random number are transmitted to an exchange cryptographic machine deployed in the quantum key scheduling module. The exchange cryptographic machine generates and stores a quantum key based on the session key and quantum random number, and then transmits the generated quantum key to the quantum cryptographic service engine device. The quantum cryptographic service engine device schedules and negotiates the quantum key according to preset scheduling and negotiation rules, ensuring that the quantum key can be distributed securely and orderly to the quantum key application module. In this embodiment, there are two exchange cryptographic machines, each connected to one random quantum number and one session key. There are also two quantum key filling devices, responsible for filling the quantum key via USB key / TF card, etc., and using it in the quantum key application terminal. Specifically, the quantum key can be output to one quantum key filling machine via two cryptographic switches, and a one-pad encrypted session key can be output to the other quantum key filling machine. The two quantum key filling machines then fill the quantum devices in the quantum key application module with keys.

[0071] More specifically, during the operation of the quantum security service platform, the key application service of the quantum cryptography service engine device may experience abnormal events, including but not limited to downtime. If the quantum network management module detects an abnormal event in the quantum cryptography service engine device, it can switch the quantum cryptography service engine device to a quantum cryptography service engine mirror device to provide emergency services. After the quantum cryptography service engine device recovers, the emergency service will be shut down and data will be synchronized with the quantum cryptography service engine mirror device. The quantum cryptography service engine device and its mirror device have the same functions, such as distributing quantum keys according to preset scheduling and negotiation rules.

[0072] In this embodiment, the quantum network management module includes a quantum network management database server and a quantum network management service server connected in communication. During the quantum encryption process, the quantum network management database server and the quantum network management service server are used to perform network management and monitoring of the operating status of the quantum key generation module, the quantum key scheduling module, and the quantum key application module.

[0073] Specifically, the aforementioned quantum network management database server is primarily used to deploy database engine software, providing applications with functions including but not limited to querying, updating, transaction management, indexing, caching, and query optimization. The aforementioned quantum network management business server primarily provides business logic for the application and does not store business data. During quantum encryption, the quantum network management database server and the quantum network management business server can be used to perform network management and monitoring of the operational status of each quantum device in the quantum key generation module, the quantum key scheduling module, and the quantum key application module, enabling real-time understanding of the operational status of each quantum device and providing data support for backend maintenance personnel.

[0074] In this embodiment, the secure access gateway includes a quantum secure access gateway connected to and deployed on one side of the quantum secure service platform, and a distribution network security gateway deployed on the side of the distribution master station. The above step S4 specifically includes: encrypting and transmitting the service data through the quantum secure access gateway and the distribution network security access gateway, decrypting it through the distribution network security gateway on the side of the distribution master station, and sending the decrypted service data to the distribution master station.

[0075] Specifically, in combination Figure 2 As shown, multiple quantum-secure access gateways can be deployed on one side of the quantum-secure service platform, and multiple distribution security gateways can be deployed on the other side of the distribution substation. The quantum-secure access gateways are located in the quantum-secure access area, while the distribution security gateways are located in the municipal wireless security access area on the distribution substation side. The quantum-secure access gateways and distribution security gateways communicate via a convergence switch, converting encrypted service data received by the multiple quantum-secure access gateways into two outputs to the distribution security gateway. After data decryption by the distribution security gateway, the decrypted service data can be sent to the distribution substation via a wireless private network acquisition server. Forward and reverse security isolation devices can be deployed between the wireless private network acquisition server and the distribution substation for security protection, ensuring the security of service data transmission. Furthermore, a firewall can be deployed between the quantum-secure access gateway and the power wireless virtual private network (4G / G5), and a multi-carrier access switch can be deployed between the quantum-secure access gateway and the power wireless virtual private network. Deploying the firewall strengthens data security within the distribution substation.

[0076] In this embodiment, the second secure communication channel includes a first quantum key transmission device that is communicatively connected to the power distribution master station and the quantum security service platform, and a second quantum key transmission device deployed in the power distribution substation and communicating securely with the first quantum key transmission device. The second quantum key transmission device communicates with the quantum key charging substation and the power distribution equipment in the power distribution substation. The first quantum key transmission device and the second quantum key transmission device are used for communication transmission between the power distribution master station and the power distribution substation, and for the quantum key charging device to charge the quantum key charging substation with quantum keys.

[0077] Specifically, in combination Figure 2As shown, the aforementioned second secure communication channel can achieve encrypted transmission of business data using quantum keys by deploying two first quantum key transmission devices and two second quantum key transmission devices in the power distribution master station and the power distribution substation, respectively. The first quantum key transmission devices communicate with the second quantum key transmission devices, the quantum security service platform, and the power distribution master station, respectively. The second quantum key transmission devices communicate with the quantum key injection substation and the power distribution automation substation in the power distribution substation via multiple switches. Based on the injection key interface and management services provided by the quantum key injection device in the quantum security service platform, the second secure channel can be used to connect to the quantum key injection substation to inject quantum keys and store them in the substation. Therefore, data encryption and decryption transmission between the power distribution master station and the power distribution substation based on the second secure communication channel can improve the security level of data communication transmission. Deploying quantum key injection substations on the power distribution substation side to implement the quantum key injection function eliminates the need to obtain quantum keys from the power distribution master station side, enabling local management of key injection on the power distribution substation side.

[0078] Example 2

[0079] Combination Figure 3 As shown, this embodiment of the invention also provides a quantum-encrypted power distribution automation protection system, used to execute the quantum-encrypted power distribution automation protection method described in Embodiment 1. The system 40 includes:

[0080] The quantum security service platform deployment module 401 is used to perform built-in isolation hardening and redundant deployment of key node devices on the quantum security service platform.

[0081] The channel establishment module 402 is used to establish a first secure communication channel between the power distribution master station and the quantum security service platform, and a second secure communication channel between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway.

[0082] The key acquisition module 403 is used to acquire a session key through the quantum security service platform if the power distribution terminal initiates a data request, acquire a quantum key based on the session key to encrypt the data, and inject the session key into the quantum key injection substation of the power distribution station through the second secure communication channel.

[0083] The master station data transmission module 404 is used to decrypt data through the secure access gateway and send the decrypted business data to the power distribution master station.

[0084] In this embodiment, the quantum security service platform includes a raw quantum security service module, which includes a quantum key generation module, a quantum key scheduling module, a quantum key application module, and a quantum network management module connected by communication. The quantum security service platform is internally isolated and hardened. The quantum security service platform deployment module 401 is specifically used to: perform forward and reverse isolation hardening on the quantum key generation module, the quantum key scheduling module, the quantum key application module, and the quantum network management module, and the quantum key generation module is connected to the power distribution terminal through a first communication connection terminal, and the data request is sent to the quantum key generation module through the first signal connection terminal.

[0085] In this embodiment, the quantum security service platform deployment module 401 is further configured to: deploy a quantum cryptography service engine mirror device, a first quantum key service mirror device, a second quantum key service mirror device, and a forward and reverse security isolation device on top of the original quantum security service module. The quantum cryptography service engine mirror device is connected to the forward and reverse security isolation device via a second communication connection terminal. The forward and reverse security isolation device is connected to one end of the first quantum key service mirror device and the second quantum key service mirror device via a third communication connection terminal. The other end of the first quantum key service mirror device and the second quantum key service mirror device is connected to a fourth communication connection terminal. The fourth communication connection terminal is connected to the secure access gateway.

[0086] In this embodiment, the quantum key generation module includes a single-send quantum key generation and management terminal, a single-receiver quantum key generation and management terminal, and a quantum random number generator. The key acquisition module 403 is specifically used for:

[0087] If any communication connection terminal receives a data request sent by the power distribution terminal, a quantum random number is generated by the quantum random number generator, and a session key is generated by the single-sender quantum key generation and management terminal and the single-receiver quantum key generation and management terminal.

[0088] The quantum key scheduling module generates the quantum key based on the session key and the quantum random number, and uses the quantum key to encrypt the business data contained in the data request.

[0089] In this embodiment, the quantum key scheduling module includes a switching cryptographic machine, a quantum cryptographic service engine device, and a quantum key injection device. The key acquisition module 403 is further used for:

[0090] The business data is encrypted using the exchange cryptographic machine, and the quantum key is distributed to the quantum cryptographic service engine device.

[0091] According to the preset scheduling and negotiation rules, the quantum cryptography service engine device distributes the quantum key to the quantum key application module and performs key injection on the quantum key through the quantum key injection device;

[0092] If an abnormal event is detected in the quantum cryptography service engine device, the quantum key is distributed to the quantum key application module through the quantum cryptography service engine mirror device according to the preset scheduling negotiation rules.

[0093] In this embodiment, the quantum network management module includes a quantum network management database server and a quantum network management service server connected in communication. During the quantum encryption process, the key acquisition module 403 is further used to: perform network management and monitoring of the operating status of the quantum key generation module, the quantum key scheduling module, and the quantum key application module through the quantum network management database server and the quantum network management service server.

[0094] In this embodiment, the secure access gateway includes a quantum secure access gateway connected to and deployed on one side of the quantum secure service platform, and a distribution network security gateway deployed on the side of the distribution master station. The data transmission module 404 is specifically used to: encrypt and transmit the service data through the quantum secure access gateway and the distribution network security access gateway, decrypt the data through the distribution network security gateway on the side of the distribution master station, and send the decrypted service data to the distribution master station.

[0095] In this embodiment, the second secure communication channel includes a first quantum key transmission device that is communicatively connected to the power distribution master station and the quantum security service platform, and a second quantum key transmission device deployed in the power distribution substation and communicating securely with the first quantum key transmission device. The second quantum key transmission device communicates with the quantum key charging substation and the power distribution equipment in the power distribution substation. The first quantum key transmission device and the second quantum key transmission device are used for communication transmission between the power distribution master station and the power distribution substation, and for the quantum key charging device to charge the quantum key charging substation with quantum keys.

[0096] The specific embodiments described above are preferred embodiments of the power distribution automation protection method based on quantum encryption of the present invention, and are not intended to limit the specific scope of the present invention. The scope of the present invention includes, but is not limited to, these specific embodiments. All equivalent changes made in accordance with the shape and structure of the present invention are within the protection scope of the present invention.

Claims

1. A quantum-encryption-based power distribution automation protection method, applicable to power distribution networks, wherein the power distribution network includes a power distribution master station, a power distribution substation, and a quantum security service platform, and the power distribution substation includes a quantum key injection substation, characterized in that, Includes the following steps: The quantum security service platform is equipped with built-in isolation and hardening, as well as redundant deployment of key node devices; A first secure communication channel is established between the power distribution master station and the quantum security service platform, and a second secure communication channel is established between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway. If the power distribution terminal initiates a data request, it obtains a session key through the quantum security service platform, encrypts the data using a quantum key based on the session key, and then injects the session key into the quantum key injection substation of the power distribution station through the second secure communication channel. The data is decrypted through the secure access gateway, and the decrypted business data is sent to the power distribution master station. The quantum security service platform includes a basic quantum security service module, which comprises a quantum key generation module, a quantum key scheduling module, a quantum key application module, and a quantum network management module connected via communication links. The built-in isolation and hardening of the quantum security service platform includes: The quantum key generation module, the quantum key scheduling module, the quantum key application module, and the quantum network management module are reinforced with forward and reverse isolation. The quantum key generation module is connected to the power distribution terminal through a first communication connection terminal, and the data request is sent to the quantum key generation module through the first communication connection terminal. The redundant deployment of critical node devices in the quantum security service platform includes: Based on the original quantum security service module, a quantum cryptography service engine mirror device, a first quantum key service mirror device, a second quantum key service mirror device, and a forward and reverse security isolation device are deployed. The quantum cryptography service engine mirror device is connected to the forward and reverse security isolation device through a second communication connection terminal. The forward and reverse security isolation device is connected to one end of the first quantum key service mirror device and the second quantum key service mirror device through a third communication connection terminal. The other end of the first quantum key service mirror device and the second quantum key service mirror device is connected to a fourth communication connection terminal. The fourth communication connection terminal is connected to the secure access gateway. The quantum key generation module includes a single-send quantum key generation and management terminal, a single-receiver quantum key generation and management terminal, and a quantum random number generator. The step of obtaining a session key through the quantum security service platform and then using the session key to obtain a quantum key for data encryption includes: If any communication connection terminal receives a data request sent by the power distribution terminal, a quantum random number is generated by the quantum random number generator, and a session key is generated by the single-sender quantum key generation and management terminal and the single-receiver quantum key generation and management terminal. The quantum key scheduling module generates the quantum key based on the session key and the quantum random number, and uses the quantum key to encrypt the business data included in the data request.

2. The power distribution automation protection method based on quantum encryption as described in claim 1, characterized in that, The quantum key scheduling module includes a cryptographic exchange machine, a quantum cryptographic service engine device, and a quantum key injection device. The step of encrypting the business data contained in the data request using the quantum key includes: The business data is encrypted using the exchange cryptographic machine, and the quantum key is distributed to the quantum cryptographic service engine device. According to the preset scheduling and negotiation rules, the quantum cryptography service engine device distributes the quantum key to the quantum key application module and performs key injection on the quantum key through the quantum key injection device; If an abnormal event is detected in the quantum cryptography service engine device, the quantum key is distributed to the quantum key application module through the quantum cryptography service engine mirror device according to the preset scheduling negotiation rules.

3. The power distribution automation protection method based on quantum encryption as described in claim 1, characterized in that, The quantum network management module includes a quantum network management database server and a quantum network management service server connected in communication. During the quantum encryption process, the quantum network management database server and the quantum network management service server are used to perform network management and monitoring of the operating status of the quantum key generation module, the quantum key scheduling module, and the quantum key application module.

4. The power distribution automation protection method based on quantum encryption as described in claim 1, characterized in that, The secure access gateway includes a quantum secure access gateway connected to and deployed on one side of the quantum secure service platform, and a distribution network security gateway deployed on the side of the distribution master station. The step of decrypting data through the secure access gateway and sending the decrypted service data to the distribution master station includes: The service data is encrypted and transmitted through the quantum secure access gateway and the distribution network security gateway, and then decrypted through the distribution network security gateway on the distribution master station side, and the decrypted service data is sent to the distribution master station.

5. The power distribution automation protection method based on quantum encryption as described in claim 2, characterized in that, The second secure communication channel includes a first quantum key transmission device that is communicatively connected to the power distribution master station and the quantum security service platform, and a second quantum key transmission device deployed in the power distribution substation and communicating securely with the first quantum key transmission device. The second quantum key transmission device communicates with the quantum key charging substation and the power distribution equipment in the power distribution substation. The first quantum key transmission device and the second quantum key transmission device are used for communication transmission between the power distribution master station and the power distribution substation, and for the quantum key charging device to charge the quantum key charging substation with quantum keys.

6. A quantum-encrypted power distribution automation protection system, used to execute the quantum-encrypted power distribution automation protection method according to any one of claims 1 to 5, characterized in that, The system includes: The quantum security service platform deployment module is used to perform built-in isolation hardening and redundant deployment of key node devices on the quantum security service platform. The channel establishment module is used to establish a first secure communication channel between the power distribution master station and the quantum security service platform, and a second secure communication channel between the power distribution master station and the power distribution substation. The first secure communication channel includes a secure access gateway. The key acquisition module is used to acquire a session key through the quantum security service platform if the power distribution terminal initiates a data request, acquire a quantum key based on the session key to encrypt the data, and inject the session key into the quantum key injection substation of the power distribution station through the second secure communication channel. The master station data transmission module is used to decrypt data through the secure access gateway and send the decrypted business data to the power distribution master station.

7. The power distribution automation protection system based on quantum encryption as described in claim 6, wherein the quantum security service platform includes an original quantum security service module, the original quantum security service module including a quantum key generation module, a quantum key scheduling module, a quantum key application module, and a quantum network management module connected by communication, and the quantum security service platform is characterized by the following: The quantum security service platform deployment module is specifically used for: The quantum key generation module, the quantum key scheduling module, the quantum key application module, and the quantum network management module are reinforced with forward and reverse isolation. The quantum key generation module is connected to the power distribution terminal through a first communication connection terminal, and the data request is sent to the quantum key generation module through the first communication connection terminal.