Multi-terminal based power distribution automation data security handling method and system

By deploying a mirroring device and device access port in the quantum encryption module, and combining it with a quantum secure storage and application device, the problem of the quantum encryption security service platform being unable to access multiple terminals is solved, thus achieving security for multi-terminal access and data transmission.

CN116668009BActive Publication Date: 2025-11-25ZHEJIANG GUODUN QUANTUM POWER TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310444393.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-24
Publication Date
2025-11-25
Estimated Expiration
2043-04-24

AI Technical Summary

Technical Problem

The existing quantum encryption security service platform cannot connect to multiple terminals simultaneously, and cannot guarantee the security of data transmission between the power distribution master station and the power distribution substation.

Method used

By deploying a mirroring device and multiple device access ports in the quantum encryption module, along with an electronic station key charging interface, and combining it with a quantum secure storage and application device, multi-terminal access can be achieved and data transmission security can be enhanced.

Benefits of technology

It enables multi-terminal access, improves the system's data processing capabilities, and ensures the security of data transmission and the stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668009B_ABST
    Figure CN116668009B_ABST
Patent Text Reader

Abstract

The application discloses a power distribution automation data security processing method and system based on multiple terminals, relates to the field of quantum secure communication applications, and comprises the following steps: deploying an original quantum encryption module image device based on a quantum encryption module; the original quantum encryption module and the image device are respectively connected with at least two device access ports; the original quantum encryption module comprises a power substation key injection interface; a quantum security storage and application device is deployed and connected with the power substation key injection interface; if any device access port acquires a data request, business data is encrypted based on the quantum encryption module, and the power substation is injected with a key based on the quantum security storage and application device; business data is decrypted at the power substation side, control instructions are generated, the control instructions are securely transmitted to the power substation through the injected key, and the like. The application can improve the system data processing capacity and system operation stability, and realizes the security of data transmission between the power distribution master station and the power substation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of quantum secure communication application, in particular to a power distribution automation data security processing method and system based on multiple terminals. BACKGROUND

[0002] With the continuous advancement of energy internet construction, more new power energy facilities are connected in large quantities, and the point-to-surface grid access equipment also increases, which puts forward higher requirements for the safety of grid communication. In order to ensure the safety of grid communication, in the prior art, a quantum encryption security service platform is deployed between the terminal and the power distribution master station, and the security of data transmission is ensured based on the physical characteristics of quantum key, such as non-cloning, uncertainty principle and single photon non-division. Taking Zhejiang as an example, the quantum encryption security service platform system has been deployed in the production control area of 11 municipal power supply companies in Zhejiang province of China State Grid, and the scale transformation of wireless public network remote control of overhead line intelligent switch has been carried out, and the pilot application of local control of low-voltage transformer area has been carried out.

[0003] However, the quantum encryption security service platform deployed at the present stage can only be connected to one or two terminals, and cannot realize the access of more terminals to meet the demand of processing larger data volume. In addition, the quantum encryption security service platform is only deployed on the side of the power distribution master station in the grid, and when data transmission is carried out between the power distribution master station and the power distribution substation, the security of data transmission between the power distribution master station and the power distribution substation cannot be guaranteed. SUMMARY

[0004] The purpose of the present application is to solve the problems that the quantum encryption security service platform on the side of the power distribution master station cannot access multiple terminals and the communication security between the power distribution master station and the power distribution substation. A power distribution automation data security processing method based on multiple terminals is proposed, which can provide quantum encryption function for the access of multiple terminal devices through the mirror device deployed in the quantum encryption module, multiple device access ports provided for the terminal and the power distribution substation key filling interface, and can also realize key filling by connecting the power distribution substation key filling interface and the power distribution substation communication based on the deployed quantum security storage and application device, so as to strengthen the data transmission security between the power distribution master station and the power distribution substation.

[0005] In the first aspect, a technical scheme provided by an embodiment of the present application is a power distribution automation data security processing method based on multiple terminals, which is suitable for a power distribution system including a power distribution master station, a power distribution substation and a quantum encryption module, and includes the following steps:

[0006] A mirror device is deployed to communicate and connect based on the original quantum encryption module of the quantum encryption module, the original quantum encryption module and the mirror device are respectively connected to at least two device access ports for terminal access, and the original quantum encryption module further includes a power distribution substation key filling interface.

[0007] A quantum secure storage and application device is deployed between the power distribution substation, the power distribution master station and the quantum encryption module, and the quantum secure storage and application device is connected to the power distribution substation through a key injection interface;

[0008] If any of the device access ports obtains a data request initiated by a terminal, the quantum encryption module is used for encrypted transmission of service data, and the quantum secure storage and application device is used for key injection of the power distribution substation;

[0009] Service data is decrypted at the power distribution substation side, and corresponding control instructions are generated, the quantum secure storage and application device is used for secure transmission of the control instructions to the power distribution substation through the injection key of the power distribution substation, and power distribution control is performed.

[0010] Optionally, the original quantum encryption module has one end connected to a first device access port and the other end connected to the power distribution master station and the power distribution substation in communication, the original quantum encryption module includes a quantum key generation unit, a quantum key scheduling unit, a quantum key application unit and a quantum network management unit connected in communication, the quantum key generation unit includes a quantum key management server, the quantum key scheduling unit includes a quantum cryptography service engine device, when the quantum key generation unit receives the service data in the data request, the quantum key generation unit is controlled by the quantum key management server to generate a quantum key for encrypted transmission of service data, and the quantum key is output to the quantum key application unit after being scheduled and negotiated by the quantum cryptography service engine device.

[0011] Optionally, the original quantum encryption module based on the quantum encryption module includes a mirror device connected in communication, comprising:

[0012] The quantum cryptography service engine mirror device, the first quantum key server mirror device and the second quantum key server mirror device are deployed in the original quantum encryption module in communication, the quantum cryptography service engine mirror device is connected to a second device access port, one end of the first quantum key server mirror device and the second quantum key server mirror device is connected to a third device access port, and the other end is connected to a fourth device access port, the fourth device access port is connected to the power distribution master station through a secure access gateway, and the first quantum key server mirror device and the second quantum key server mirror device back up data to each other.

[0013] Optionally, the encrypted transmission of service data based on the quantum encryption module includes:

[0014] When the third device access port and the fourth device access port receive a data request, then the quantum key generation unit generates the quantum key through the first quantum key server mirror device or the second quantum key server mirror device, the service data is encrypted based on the quantum key, and is sent to the quantum key scheduling unit;

[0015] If the quantum cipher service engine device in the quantum key scheduling unit fails, the quantum cipher service engine mirror device is switched to schedule and negotiate the quantum key according to a preset rule and then output to the quantum key application unit.

[0016] Optionally, a forward and reverse security isolation device is arranged between the second device access port and the third device access port.

[0017] Optionally, the first device access port, the second device access port, the third device access port and the fourth device access port each include a switch.

[0018] Optionally, the secure access gateway includes a quantum secure access gateway arranged on the side of the quantum encryption module and connected in communication, and a power distribution network security gateway arranged on the side of the power distribution master station, the service data is decrypted and transmitted through the quantum secure access gateway and the power distribution network security gateway, and the decrypted service data is sent to the power distribution master station.

[0019] Optionally, the quantum secure storage and application device includes a first quantum key transmission device connected in communication with the power distribution master station and the quantum encryption module, a second quantum key transmission device arranged in the power distribution substation and performing secret communication with the first quantum key transmission device, and a quantum key refilling substation connected in communication with the second quantum key transmission device, a power distribution substation encryption channel is constructed through the first quantum key transmission device and the second quantum key transmission device, the quantum encryption module refills the quantum key refilling substation through a power distribution substation key refilling interface and the power distribution substation encryption channel, and a fifth device access port is connected between the second quantum key transmission device and the quantum key refilling substation for accessing a terminal device on the side of the power distribution substation.

[0020] Optionally, the service data is decrypted on the side of the power distribution substation and corresponding control instructions are generated, the quantum secure storage and application device is used to perform secret transmission of the control instructions to the power distribution substation for power distribution control by acquiring a refilling key on the side of the power distribution substation, and the method includes:

[0021] corresponding control instructions of the service data are generated, and a refilling key in the quantum key refilling substation is acquired to encrypt the control instructions.

[0022] The control instruction is transmitted to the power distribution substation in secret through the power distribution substation encryption channel, and the power distribution control of the automatic power distribution equipment in the power distribution substation is performed.

[0023] In a second aspect, the technical scheme provided by the embodiment of the present application is a power distribution automation data security processing system based on multiple terminals, which is used to execute the power distribution automation data security processing method based on multiple terminals.

[0024] The first device deployment module is configured to deploy a mirror device of the quantum encryption module in the original quantum encryption module based on a communication connection, the original quantum encryption module and the mirror device are connected to at least two device access ports for terminal access, and the original quantum encryption module further includes a power distribution substation key refilling interface.

[0025] The second device deployment module is configured to deploy a quantum security storage and application device of the communication connection between the power distribution substation, the power distribution master station and the quantum encryption module, and the quantum security storage and application device is connected to the power distribution substation key refilling interface.

[0026] The data encryption and key refilling module is configured to, if any of the device access ports obtains a data request initiated by a terminal, perform business data encryption transmission based on the quantum encryption module, and perform key refilling of the power distribution substation based on the quantum security storage and application device.

[0027] The control module is configured to decrypt the business data and transmit it to the power distribution master station to generate a control instruction, and perform secret transmission of the control instruction to the power distribution substation for power distribution control based on the quantum security storage and application device and the refilling key of the power distribution substation side.

[0028] The present application has the following advantages: by deploying a mirror device and a plurality of device access ports for terminal access in the quantum encryption module, multiple terminal access can be achieved, and the data processing capacity of the system is improved; the mirror device connected to each device access port can perform quantum encryption process as a backup mirror device, ensuring the stability of the system; in addition, a power distribution substation key refilling interface is deployed in the original quantum encryption module, and a quantum security storage and application device is deployed between the power distribution substation and the power distribution master station, the power distribution substation key refilling interface and the quantum security storage and application device are in communication connection, and after connection, key refilling of the power distribution substation can be realized, when data transmission is performed between the power distribution substation and the power distribution master station, the refilling key can be directly retrieved in the power distribution substation for data encryption transmission, ensuring the security of data transmission.

[0029] The foregoing brief summary of the application is only a summary of the technical solutions of the present application, in order to enable the technical means of the present application to be more clearly understood, and can be implemented according to the content of the specification, and in order to enable the above and other purposes, characteristics and advantages of the present application to be more apparent and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS

[0030] Other features, objects, and advantages of the application will become more apparent from the following detailed description of non-limiting embodiments thereof, read in conjunction with the accompanying drawings. The drawings are only for the purpose of illustrating preferred embodiments of the application and are not to be construed as limiting the application. Like reference numerals denote like elements throughout the drawings.

[0031] Figure 1 A flowchart of a multi-terminal-based power distribution automation data security handling method provided for an embodiment of the present application is shown in FIG. 1.

[0032] Figure 2 An overall communication schematic diagram of a power distribution master station, a power distribution secondary station and a quantum encryption module provided for an embodiment of the present application is shown in FIG. 2.

[0033] Figure 3 A structural schematic diagram of a multi-terminal-based power distribution automation data security handling system provided for an embodiment of the present application is shown in FIG. 3. DETAILED DESCRIPTION

[0034] In order to make the purposes, technical solutions and advantages of the present application more clear and apparent, the present application will be further described in detail below in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only the best mode of the present application, which are used to explain the present application, and do not limit the protection scope of the present application, and all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.

[0035] Before the example embodiments are discussed in more detail, it should be mentioned that some of the example embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts depict the operations (or steps) as sequential processes, many of the operations (or steps) can be performed in parallel, concurrently or simultaneously. In addition, the order of the operations can be rearranged. The processes can be terminated when their operations are completed, but can also have additional steps not included in the figures; the processes can correspond to methods, functions, routines, subroutines, subprograms, etc.

[0036] The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. It should also be understood that in the various embodiments of the invention, the sequence number of each process does not imply a specific order of execution; the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the invention.

[0037] It should be understood that in this invention, "multiple" refers to two or more. "And / or" is merely a variable relationship describing the related objects, indicating that three relationships can exist. For example, "and / or B" can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. "Contains A, B, and C", "Contains A, B, and C" means that all three A, B, and C are contained; "Contains A, B, or C" means that one of A, B, and C is contained; "Contains A, B, and / or C" means that any one, two, or three of A, B, and C are contained.

[0038] It should be understood that in this invention, "B corresponding to A", "B corresponding to A", "A and B correspond", or "B and A correspond" means that B is associated with A, and B can be determined based on A. Determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information. Matching A and B is defined as a similarity between A and B that is greater than or equal to a preset threshold.

[0039] Example 1

[0040] like Figure 1 The diagram shown is a flowchart of the multi-terminal-based distribution automation data security handling method provided in this embodiment. The multi-terminal-based distribution automation data security handling method includes the following steps:

[0041] S1. A mirror device for deploying communication connection based on the original quantum encryption module of the quantum encryption module, wherein the original quantum encryption module and the mirror device are respectively connected to at least two device access ports for terminal access, and the original quantum encryption module further includes a power distribution station charging key interface.

[0042] S2. Deploy a quantum-safe storage and application device with communication connection between the power distribution station, the power distribution master station and the quantum encryption module, and the quantum-safe storage and application device is connected to the key charging interface of the power distribution station;

[0043] S3, if any of the device access ports obtains a data request initiated by a terminal, the service data is encrypted and transmitted based on the quantum encryption module, and the quantum secure storage and application device is used to charge the key of the power distribution substation;

[0044] S4, the service data is decrypted at the power distribution substation side, and the corresponding control instruction is generated, the quantum secure storage and application device is used to transmit the control instruction to the power distribution substation for power distribution control by obtaining the charging key of the power distribution substation side.

[0045] Specifically, the power distribution automation data security processing method based on multiple terminals provided by the embodiment of the application is suitable for a power distribution system, and the power distribution system comprises a power distribution master station, a power distribution substation and a quantum encryption module. The power distribution master station can be a municipal power distribution automation master station, and the power distribution substation can be a county workstation. Data interaction can be realized based on the communication connection between the power distribution master station and the power distribution substation. The terminal (FTU) described above includes but is not limited to various electrical devices in the power distribution network, such as circuit breakers, transformers, transformers and the like. The security level of the device data corresponding to different devices can be different. The service data in the data request sent by the terminal can be encrypted based on the quantum encryption module and then transmitted to the power distribution master station to realize communication with the power distribution master station. The data request can include but is not limited to device exception request, fault check request, monitoring data upload request and the like. The control command includes but is not limited to parameter adjustment of the power distribution substation, power distribution control, device state control and the like.

[0046] More specifically, the quantum encryption module described above can refer to a platform for encrypting and decrypting data transmitted between the power distribution terminal and the power distribution master station by quantum encryption technology. The quantum encryption technology is a series of encryption technologies for generating keys, encrypting plaintext, decrypting ciphertext, communicating ciphertext and anti-eavesdropping by using quantum principles. In the quantum encryption module, built-in devices for quantum key generation, encryption and decryption, key distribution and the like are included.

[0047] More specifically, the original quantum encryption module mentioned above can refer to the most basic encryption part in the quantum encryption module. One end of the original quantum encryption module accesses at least two device access ports, and the other end accesses the power distribution master station. Through the original quantum encryption module, data encryption from the terminal to the power distribution master station can be realized. The mirror device mentioned above can be a backup device deployed for the equipment on the key node in the original quantum encryption module. When the quantum equipment on the key node has a problem while the original quantum encryption module is receiving service data based on the device access port for encryption, the mirror device can be replaced to cooperate with other normally operating quantum equipment in the original quantum encryption module to continue the encryption process. In addition, when the mirror device is deployed in the quantum encryption module, one end is connected with at least two device access ports, and the other end communicates with the original quantum encryption module. When the mirror device is started to execute the encryption process, data requests sent by the terminal can be received through the device access port connected with the mirror device.

[0048] More specifically, the original quantum encryption module mentioned above can refer to the most basic encryption part in the quantum encryption module. One end of the original quantum encryption module accesses at least two device access ports, and the other end accesses the power distribution master station. Through the original quantum encryption module, data encryption from the terminal to the power distribution master station can be realized. The mirror device mentioned above can be a backup device deployed for the equipment on the key node in the original quantum encryption module. When the quantum equipment on the key node has a problem while the original quantum encryption module is receiving service data based on the device access port for encryption, the mirror device can be replaced to cooperate with other normally operating quantum equipment in the original quantum encryption module to continue the encryption process. In addition, when the mirror device is deployed in the quantum encryption module, one end is connected with at least two device access ports, and the other end communicates with the original quantum encryption module. When the mirror device is started to execute the encryption process, data requests sent by the terminal can be received through the device access port connected with the mirror device.

[0049] In the embodiment of the present application, by deploying the mirror device and the plurality of device access ports provided for terminal access in the quantum encryption module, multiple terminal access can be realized, and the data processing capacity of the system can be improved. The mirror device connected with each device access port can execute the quantum encryption process as a backup mirror device, thereby ensuring the stability of system operation. In addition, the key injection interface of the power distribution substation is deployed in the original quantum encryption module, and the quantum security storage and application device is deployed between the power distribution substation and the power distribution master station. The key injection interface of the power distribution substation is in communication connection with the quantum security storage and application device. After connection, the key injection of the power distribution substation can be realized. When data transmission is performed between the power distribution substation and the power distribution master station, the injected key can be directly retrieved in the power distribution substation for data encryption transmission, thereby ensuring the security of data transmission.

[0050] In the embodiment, one end of the original quantum encryption module accesses the first device access port, and the other end communicates with the power distribution master station and the power distribution substation. The original quantum encryption module includes a quantum key generation unit, a quantum key scheduling unit, a quantum key application unit, and a quantum network management unit connected in communication. The quantum key generation unit includes a quantum key management server. The quantum key scheduling unit includes a quantum cryptography service engine device. When the quantum key generation unit receives service data in a data request, the quantum key management server controls the quantum key generation unit to generate a quantum key for service data encryption. The quantum key is output to the quantum key application unit after being scheduled and negotiated by the quantum cryptography service engine device.

[0051] Specifically, in the embodiment, the first device access port includes two switches. The switches can provide exclusive telecommunication paths for any two network nodes accessing the switches, such as Ethernet switches, fiber switches, and the like. The quantum key generation unit can generate quantum keys according to quantum characteristics to provide quantum key support for the quantum key scheduling unit and the quantum key application unit. The quantum key scheduling unit can realize storage and output, negotiation and scheduling, and session key injection of quantum keys. The quantum key application unit can use quantum keys to construct a quantum secure encryption transmission channel to improve the security level of the 4G / 5G transmission channel and ensure that service data can be safely transmitted to the power distribution master station or other business systems. The quantum network management unit can realize network management and monitoring of the running state of the quantum devices of the quantum encryption module. The monitoring of the running state can provide operation and maintenance support.

[0052] The quantum key generation unit is deployed with a quantum key management server, and the quantum key scheduling unit is deployed with a quantum cryptography service engine device. The quantum key management server is used to control the generation of quantum keys, and the quantum cryptography service engine device is used to schedule and negotiate quantum keys to ensure that quantum keys can be safely and orderly distributed to the quantum key application unit. When the quantum key management server in the quantum key generation unit receives service data in a data request, the quantum key management server can control the single-transmitting quantum key generation and management terminal and the single-receiving quantum key generation and management terminal in the quantum key generation unit to generate session keys, and control the quantum random number generator in the quantum key generation unit to generate quantum random numbers to generate quantum keys according to the session keys and the random quantum numbers. The service data is encrypted by the quantum key and then transmitted to the quantum key scheduling unit. The quantum key is output to the quantum key application unit after being scheduled and negotiated by the quantum cryptography service engine device.

[0053] In the embodiment, the mirror device of the communication connection deployed by the original quantum encryption module based on the quantum encryption module comprises: a quantum password service engine mirror device, a first quantum key server mirror device and a second quantum key server mirror device deployed in the original quantum encryption module, the quantum password service engine mirror device is connected to a second device access port, one end of the first quantum key server mirror device and the second quantum key server mirror device is connected to a third device access port, and the other end is connected to a fourth device access port, the fourth device access port is connected to the power distribution master station through a secure access gateway, and the first quantum key server mirror device and the second quantum key server mirror device perform mutual data backup.

[0054] Specifically, in combination with Figure 2 the above original quantum security service module, the quantum password service engine mirror device is deployed as a standby device of the quantum password service engine device. When the quantum password service engine device appears abnormal conditions such as downtime, the quantum password service engine mirror device can be switched to realize the same function, and after the quantum password service engine device recovers, the quantum password service engine device is switched to work again. At the same time, the data involved in the switching process of the quantum password service engine mirror device can be synchronized to the quantum password service engine device, so as to ensure the integrity of the data through the backup function. The first quantum key server mirror device and the second quantum key server mirror device are deployed to realize quantum key management. The first quantum key server mirror device and the second quantum key server mirror device are standby devices for each other. When the first quantum key server mirror device is the main device, the second quantum key server mirror device is the standby device. When the second quantum key server mirror device is the main device, the first quantum key server mirror device is the standby device. The first quantum key server mirror device and the second quantum key server mirror device are connected between the third device access port and the fourth device access port. When the third device access port or the fourth device access port has a terminal issuing a data request, and any one of the first quantum key server mirror device and the second quantum key server mirror device cannot work normally, the other one can be switched to work, for example: the main device works abnormally, and is switched to the standby device. After the main device recovers, the standby device is switched to the main device. After switching, the data processed by the standby device during the abnormal period can be synchronized to the main device.

[0055] More specifically, the second device access port, the third device access port and the fourth device access port can be switches, each of which can receive a data request from a terminal in a working state, and the fourth device access port is connected to the power distribution master station through a secure access gateway for encrypted communication. When any one of the device access ports or the quantum device connected to any one of the device access ports cannot work normally, the system can be switched to another normally working device access port. In addition, the first device access port, the second device access port, the third device access port and the fourth device access port can be set to have different communication levels, and different levels of ports are connected to terminals with different security levels, for example, the communication levels of the first device access port, the second device access port, the third device access port and the fourth device access port are in a descending order. The above-mentioned multiple device access ports can realize the disaster recovery function, meet the needs of more terminals, and ensure the uninterrupted service of the key application. The secure access gateway can be used as an entry device in the network, which can realize the construction of a secure encryption tunnel between the quantum encryption module and the power distribution master station, complete the identity authentication and protocol conversion, and realize the data encryption transmission between the quantum encryption module and the power distribution master station.

[0056] In the embodiment, the service data encryption transmission based on the quantum encryption module in the step S3 includes:

[0057] When the third device access port and the fourth device access port receive a data request, the first quantum key server mirror device or the second quantum key server mirror device is used to control the quantum key generation unit to generate the quantum key, the service data is encrypted based on the quantum key, and the encrypted data is sent to the quantum key scheduling unit.

[0058] If the quantum password service engine device in the quantum key scheduling unit fails, the quantum password service engine mirror device is switched to output the quantum key to the quantum key application unit after scheduling and negotiating the quantum key according to a preset rule.

[0059] Specifically, when the communication level of the third device access port is higher than that of the fourth device access port, if data requests are accepted at the same time, the one with the higher communication level can be processed preferentially. When the third device access port and / or the fourth device access port receives a data request, if the first quantum key server mirror device is the primary device, the quantum key generation process is controlled by the primary device under normal working conditions; if the primary device is abnormal, the second quantum key server mirror device as the backup device controls the quantum key generation process. After the quantum key is generated, the service data is encrypted and sent to the quantum key scheduling unit, and the quantum key is distributed to the quantum key application unit through the quantum scheduling unit and the quantum cryptography service engine device. If the quantum cryptography service engine device is abnormal, such as downtime, the quantum cryptography service engine mirror device performs the scheduling negotiation and distribution process, which can ensure the normal operation of the system, improve the stability of the system, and continuously provide encryption services.

[0060] In the embodiment, the second device access port and the third device access port are connected through a quantum key server mirror device. Figure 2 As shown in the figure, a forward and reverse security isolation device is deployed between the second device access port and the third device access port.

[0061] Specifically, the forward and reverse isolation is a network security measure. The forward and reverse isolation device is deployed between the second device access port and the third device access port. Due to the different security levels of the quantum cryptography service engine mirror device and the first and second quantum key server mirror devices, the quantum devices with different security levels can be isolated to prevent information leakage and attacks. The forward and reverse isolation can be achieved in two ways: one is to isolate the quantum devices with high and low security levels in different physical areas through network topology design; the other is to detect and filter data through network security devices, and only allow legal data to pass, for example, a firewall or an intrusion detection system is deployed between the quantum cryptography service engine mirror device and the first quantum key server mirror device. When an attacker attempts to enter the quantum cryptography service engine mirror device with a higher security level, the firewall or intrusion detection system performs data legality detection, and finally only allows legal data to pass, thereby achieving isolation of illegal data.

[0062] In the embodiment, the security access gateway includes a quantum security access gateway connected in communication and deployed on the side of the quantum encryption module, and a power distribution network security gateway deployed on the side of the power distribution master station. The business data is decrypted and transmitted through the quantum security access gateway and the power distribution network security gateway, and the decrypted business data is sent to the power distribution master station.

[0063] Specifically, the second device access port and the third device access port are connected through a quantum key server mirror device. Figure 2As shown, there is a quantum security access area on the quantum encryption module side, and a municipal bureau wireless security access area on the power distribution master station side. The quantum security access gateway is deployed in the quantum security access area, and the power distribution security gateway is deployed in the municipal bureau wireless security access area. A secure encryption channel is formed between the quantum security access gateway and the power distribution security gateway. The quantum key generated in the quantum encryption module and the encrypted service data are transmitted through the secure encryption channel between the quantum security access gateway and the power distribution security gateway, and the encrypted service data is decrypted at the power distribution security gateway side and then sent to the power distribution master station. The secure encryption channel between the quantum security access gateway and the power distribution security gateway can ensure the security of data transmission between the quantum encryption module and the power distribution master station. In addition, a firewall can be deployed between the quantum security access gateway and the power wireless virtual private network (4G / G5), and a multi-operator access switch is deployed between the quantum security access gateway and the power wireless virtual private network. The deployment of the firewall can enhance the data security protection in the power distribution master station.

[0064] In the embodiment, the quantum security storage and application device includes a first quantum key transmission device in communication connection with the power distribution master station and the quantum encryption module, a second quantum key transmission device deployed in the power distribution substation and in secure communication with the first quantum key transmission device, and a quantum key refilling substation in communication with the second quantum key transmission device. A power distribution substation encryption channel is constructed through the first quantum key transmission device and the second quantum key transmission device. The original quantum encryption module performs key refilling on the quantum key refilling substation through the power distribution substation key refilling interface and the power distribution substation encryption channel. The fifth device access port is connected between the second quantum key transmission device and the quantum key refilling substation for accessing the terminal device on the power distribution substation side.

[0065] Specifically, in combination with Figure 2As shown, the power distribution substation encryption channel can be implemented by deploying a first quantum key transmission device and a second quantum key transmission device for communication connection between the power distribution master station and the power distribution substation. The first quantum key transmission device and the second quantum key transmission device can realize encryption and decryption transmission, and improve the security protection level of data communication transmission. The first quantum key transmission device is in communication with the second quantum key transmission device, the quantum encryption module, and the power distribution master station. The second quantum key transmission device is in communication with the quantum key refilling substation and the automatic power distribution electronic device in the power distribution substation based on a fifth device access port, and the fifth device access port is at least two switches. The electronic substation refilling key interface can be arranged in the quantum key refilling device of the quantum encryption module, and connected to the quantum key refilling substation through the power distribution substation encryption channel for quantum key refilling. The quantum key refilling device can refill the quantum key through a U disk / TF card and the like, and the quantum key can be used in a quantum key application terminal. The quantum key is stored in the quantum key refilling substation. When the power distribution substation generates a quantum key demand, the quantum key can be directly obtained on the power distribution substation side without obtaining the quantum key from the power distribution master station side, thereby realizing the key refilling function of the county.

[0066] In the embodiment, the service data decryption and the generation of the corresponding control instruction on the power distribution substation side in step S4 are based on the quantum secure storage and application device, and the control instruction is securely transmitted to the power distribution substation for power distribution control by obtaining the refilling key of the power distribution substation side.

[0067] The control instruction corresponding to the service data is generated, and the refilling key in the quantum key refilling substation is obtained to encrypt the control instruction.

[0068] The control instruction is securely transmitted to the power distribution substation through the power distribution substation encryption channel, and the power distribution control is performed on the automatic power distribution electronic device in the power distribution substation.

[0069] Specifically, after the power distribution master station receives the service data, the corresponding control instruction can be generated for the service data, and the quantum key in the quantum key refilling substation of the power distribution substation can be obtained to encrypt the control instruction. Finally, the data encryption and decryption transmission is performed to the power distribution substation through the power distribution substation encryption channel, and the automatic power distribution electronic device is controlled to perform the corresponding operation according to the control instruction.

[0070] Embodiment two

[0071] In combination Figure 3 As shown, another technical solution provided in the embodiment of the application is a power distribution automation data security disposal system based on multiple terminals, which is used to execute the power distribution automation data security disposal method based on multiple terminals in embodiment one. The system 40 includes:

[0072] The first device deployment module 401 is configured to deploy a mirror device of the quantum encryption module in a communication connection, the original quantum encryption module and the mirror device are connected with at least two device access ports for terminal access respectively, and the original quantum encryption module further comprises a power substation key charging interface.

[0073] The second device deployment module 402 is configured to deploy a quantum security storage and application device of a communication connection among the power substation, the power main station and the quantum encryption module, and the quantum security storage and application device is connected with the power substation key charging interface.

[0074] The data encryption and key charging module 403 is configured to, if any of the device access ports obtains a data request initiated by a terminal, perform business data encryption transmission based on the quantum encryption module, and perform key charging for the power substation based on the quantum security storage and application device.

[0075] The control module 404 is configured to decrypt the business data and transmit the business data to the power main station to generate a control instruction, and perform secret transmission of the control instruction to the power substation for power distribution control based on the quantum security storage and application device by obtaining the charging key of the power substation side.

[0076] In the embodiment, one end of the original quantum encryption module is connected with the first device access port, and the other end is in communication with the power main station and the power substation, the original quantum encryption module comprises a quantum key generation unit, a quantum key scheduling unit, a quantum key application unit and a quantum network unit connected in communication, the quantum key generation unit comprises a quantum key management server, the quantum key scheduling unit comprises a quantum cipher service engine device, and the data encryption and key charging module 403 is specifically configured to: when the quantum key generation unit receives the business data in the data request, control the quantum key generation unit to generate a quantum key for business data encryption through the quantum key management server, and output the quantum key to the quantum key application unit after scheduling and negotiating the quantum key through the quantum cipher service engine device.

[0077] In the embodiment, the first device deployment module 401 is specifically configured to:

[0078] The quantum password service engine mirror device, the first quantum key server mirror device and the second quantum key server mirror device are deployed in the original quantum encryption module, the quantum password service engine mirror device is connected with the second device access port, one end of the first quantum key server mirror device and the second quantum key server mirror device is connected with the third device access port, and the other end is connected with the fourth device access port, the fourth device access port is connected to the power distribution master station through the secure access gateway, and the first quantum key server mirror device and the second quantum key server mirror device perform data mutual backup.

[0079] In the embodiment, the data encryption and key filling module 403 is specifically used for:

[0080] When the third device access port and the fourth device access port receive a data request, the quantum key generation unit is controlled to generate the quantum key through the first quantum key server mirror device or the second quantum key server mirror device, the service data is encrypted based on the quantum key, and the quantum key scheduling unit is sent.

[0081] If the quantum password service engine device in the quantum key scheduling unit fails, the quantum password service engine mirror device is switched to output to the quantum key application unit after scheduling negotiation of the quantum key according to a preset rule.

[0082] In the embodiment, a forward and reverse security isolation device is deployed between the second device access port and the third device access port.

[0083] In the embodiment, the first device access port, the second device access port, the third device access port and the fourth device access port respectively include switches.

[0084] In the embodiment, the secure access gateway includes a quantum secure access gateway connected in communication and deployed on the side of the quantum encryption module, and a power distribution network security gateway deployed on the side of the power distribution master station, the service data is decrypted and transmitted through the quantum secure access gateway and the power distribution network security access gateway, and the decrypted service data is sent to the power distribution master station.

[0085] In the embodiment, the quantum secure storage and application device comprises a first quantum key transmission device in communication connection with the power distribution master station and the quantum encryption module, a second quantum key transmission device deployed in the power distribution substation and performing secret communication with the first quantum key transmission device, and a quantum key refilling substation in communication with the second quantum key transmission device, a power distribution substation encryption channel is constructed through the first quantum key transmission device and the second quantum key transmission device, the original quantum encryption module performs key refilling on the quantum key refilling substation through a power distribution substation key refilling interface and the power distribution substation encryption channel, and a fifth device access port is connected between the second quantum key transmission device and the quantum key refilling substation for accessing a power distribution substation side terminal device.

[0086] In the embodiment, the control module is specifically configured to:

[0087] generate a control instruction corresponding to the service data, and encrypt the control instruction by using a refilling key in the quantum key refilling substation;

[0088] secretly transmit the control instruction to the power distribution substation through the power distribution substation encryption channel, and perform power distribution control on the automatic power distribution equipment in the power distribution substation.

[0089] The power distribution automation data security handling system based on multiple terminals provided in the embodiment can realize each embodiment mode in the power distribution automation data security handling method based on multiple terminals and achieve corresponding technical effects. To avoid repetition, details are not described herein.

[0090] The specific embodiments described above are preferred embodiments of the power distribution automation data security handling method based on multiple terminals of the present application, and do not limit the specific implementation range of the present application. The scope of the present application includes but is not limited to the specific embodiments, and equivalent changes made according to the shape and structure of the present application are within the protection scope of the present application.

Claims

1. A multi-terminal based power distribution automation data security handling method, applicable in a power distribution system, the power distribution system comprising a power distribution master station, a power distribution substation and a quantum encryption module, characterized in that, The method comprises the following steps: An original quantum encryption module of the quantum encryption module is connected with a mirror device of a communication connection of at least two device access ports for terminal access, and the original quantum encryption module further comprises a substation key injection interface; A quantum security storage and application device of a communication connection between the substation, the main power distribution station and the quantum encryption module is arranged, and the quantum security storage and application device is connected with the substation key injection interface; If any of the device access ports obtains a data request initiated by a terminal, the quantum encryption module is used for encrypted transmission of service data, and the quantum security storage and application device is used for key injection of the substation; The main power distribution station side is used for service data decryption and generation of corresponding control instructions, the quantum security storage and application device is used for secret transmission of the control instructions to the substation for power distribution control by obtaining the injection key of the main power distribution station side. The quantum encryption module is used for encrypted transmission of service data, comprising: When the third device access port and the fourth device access port receive a data request, a quantum key generation unit is controlled by a first quantum key server mirror device or a second quantum key server mirror device to generate a quantum key, the quantum key is used for service data encryption, and the quantum key is sent to a quantum key scheduling unit; If the quantum password service engine device in the quantum key scheduling unit fails, the quantum password service engine mirror device is switched to output the quantum key to a quantum key application unit after scheduling and negotiating the quantum key according to a preset rule; The main power distribution station side is used for service data decryption and generation of corresponding control instructions, the quantum security storage and application device is used for secret transmission of the control instructions to the substation for power distribution control by obtaining the injection key of the main power distribution station side. The control instructions are encrypted by obtaining the injection key in the quantum key injection substation, and the control instructions are secret transmitted to the substation through a substation encryption channel to control the automatic substation equipment in the substation. One end of the original quantum encryption module accesses the first device access port, and the other end communicates with the main power distribution station and the substation, the original quantum encryption module comprises a quantum key generation unit, a quantum key scheduling unit, a quantum key application unit and a quantum network management unit connected in communication, the quantum key generation unit comprises a quantum key management server, the quantum key scheduling unit comprises a quantum password service engine device, when the quantum key generation unit receives the service data in the data request, the quantum key generation unit is controlled by the quantum key management server to generate a quantum key for service data encryption, and the quantum key is output to the quantum key application unit after being scheduled and negotiated by the quantum password service engine device.

2. The multi-terminal based power distribution automation data security handling method as claimed in claim 1, wherein, The original quantum encryption module of the quantum encryption module comprises:

3. The multi-terminal based power distribution automation data security handling method as claimed in claim 2, wherein, ​ The quantum password service engine mirror device, the first quantum key server mirror device and the second quantum key server mirror device are deployed in the original quantum encryption module, the quantum password service engine mirror device is connected with the second device access port, one end of the first quantum key server mirror device and the second quantum key server mirror device is connected with the third device access port, and the other end is connected with the fourth device access port, the fourth device access port is connected to the power distribution master station through the secure access gateway, and the first quantum key server mirror device and the second quantum key server mirror device are data mutual backup.

4. The multi-terminal based power distribution automation data security handling method as claimed in claim 3, wherein, The forward and reverse secure isolation devices are deployed between the second device access port and the third device access port.

5. The multi-terminal based power distribution automation data security handling method as claimed in claim 3, wherein, The first device access port, the second device access port, the third device access port and the fourth device access port respectively include switches.

6. The multi-terminal based power distribution automation data security handling method as claimed in claim 3, wherein, The secure access gateway includes a quantum secure access gateway deployed on the side of the quantum encryption module and a power distribution network security gateway deployed on the side of the power distribution master station, the business data is decrypted and transmitted through the quantum secure access gateway and the power distribution network security gateway, and the decrypted business data is sent to the power distribution master station.

7. The multi-terminal based power distribution automation data security handling method as claimed in claim 1 wherein, The quantum secure storage and application device includes a first quantum key transmission device connected with the power distribution master station and the quantum encryption module, a second quantum key transmission device deployed in the power distribution electronic station and performing secret communication with the first quantum key transmission device, and a quantum key charging sub-station connected with the second quantum key transmission device, a power distribution electronic station encryption channel is constructed through the first quantum key transmission device and the second quantum key transmission device, the original quantum encryption module charges the quantum key charging sub-station through the power distribution electronic station key charging interface and the power distribution electronic station encryption channel, and the fifth device access port is connected between the second quantum key transmission device and the quantum key charging sub-station and used for accessing the terminal equipment on the power distribution electronic station side.

8. A multi-terminal based power distribution automation data security handling system for performing the multi-terminal based power distribution automation data security handling method of any one of claims 1-7, characterized by, The system comprises: A first device deployment module is used for deploying mirror devices connected through communication in the original quantum encryption module of the quantum encryption module, the original quantum encryption module and the mirror devices are respectively connected with at least two device access ports for terminal access, and the original quantum encryption module further comprises a power distribution electronic station key charging interface; A second device deployment module is used for deploying quantum secure storage and application devices connected through communication among the power distribution electronic station, the power distribution master station and the quantum encryption module, and the quantum secure storage and application devices are connected with the power distribution electronic station key charging interface; A data encryption and key charging module is used for acquiring a data request initiated by a terminal through any device access port, performing business data encryption transmission based on the quantum encryption module, and charging the power distribution electronic station with keys based on the quantum secure storage and application device. A control module is configured to decrypt the service data and transmit the service data to a power distribution master station to generate a control instruction, and based on the quantum secure storage and application device, the control instruction is transmitted to the power distribution slave station for power distribution control by obtaining a charging key of the power distribution master station.

Citation Information

Patent Citations

  • Electric communication system and method based on quantum secure communication

    CN108880800A

  • Power distribution terminal encryption communication system and method based on quantum encryption

    CN114745109A