A power grid key management method and system based on quantum communication

CN118944863BActive Publication Date: 2026-08-11GUIZHOU POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-26
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0006]因此,本发明所要解决的问题在于如何提升电网密钥管理系统的整体安全性和可靠性,以应对量子计算机发展带来的安全威胁,并解决现有量子密钥分发系统在实际应用中的技术不足

Benefits of technology

[0035]本发明有益效果为:本发明通过量子密钥分发模块生成和发送量子比特,并将对应的时间戳传输至量子密钥储存模块和经典密钥生成模块,确保密钥的时间戳同步性;量子密钥储存模块按时间戳顺序存储量子比特和对应时间戳,提高密钥存储的可靠性和可追溯性;根据接收量子比特的测量结果,通过经典密钥生成模块将密钥明文加密生成密钥,并将密钥、时间戳和索引传输至密钥存储模块,确保密钥生成的安全性;密钥读取模块根据索引从密钥存储模块中获取密钥,并进行多重身份验证,增强密钥使用过程中的安全性,解决密钥管理和多重身份验证的技术难题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118944863B_ABST
    Figure CN118944863B_ABST
Patent Text Reader

Abstract

This invention discloses a power grid key management method and system based on quantum communication, relating to the field of key management technology. The method includes generating and transmitting qubits, and transmitting timestamps to a quantum key storage module and a classical key generation module. Based on the measurement results of the received qubits, the generation module encrypts the plaintext key to generate a new key. According to an index, the key reading module retrieves the key from the key storage module and performs multi-factor authentication. This invention generates and transmits qubits via a quantum key distribution module, transmitting the corresponding timestamps to the quantum key storage module and the classical key generation module, ensuring key timestamp synchronization. Based on the measurement results of the received qubits, the generation module encrypts the plaintext key to generate a new key, retrieves the key from the key storage module according to an index, and performs multi-factor authentication, enhancing the security of key usage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of key management technology, and in particular to a power grid key management method and system based on quantum communication. Background Technology

[0002] With the continuous advancement of power grid intelligence and informatization, power grid security has become an increasingly important concern. Traditional power grid key management methods mainly rely on classical encryption techniques, such as symmetric and asymmetric encryption. However, classical encryption techniques are gradually revealing their security limitations in the face of ever-increasing computing power and the development prospects of quantum computers. In particular, the development of quantum computers poses a serious threat to existing public-key encryption systems. To address this challenge, quantum communication technology, as an emerging encryption method, has gradually become a research hotspot due to its unique advantages in information security. Based on the principles of quantum mechanics, quantum communication technology utilizes the properties of quantum states, such as the non-cloning nature and quantum entanglement, to provide unconditionally secure key distribution, namely quantum key distribution (QKD). The introduction of QKD is expected to fundamentally solve the security problems faced by traditional encryption techniques.

[0003] While quantum communication technology theoretically provides an unconditionally secure means of key distribution, existing technologies still have some shortcomings in practical applications. First, the stability and reliability of quantum key distribution systems are limited by current technological levels. Quantum bits are susceptible to environmental noise and equipment instability during transmission, leading to a high error rate and affecting the efficiency and security of key generation. Second, existing quantum key management methods lack effective timestamp management and synchronization mechanisms when integrated with power grid systems, which is particularly important in large-scale power grid applications. Furthermore, existing technologies still need improvement in key storage and access control; secure key storage and multi-factor authentication mechanisms are not yet perfect.

[0004] Therefore, a power grid key management method and system based on quantum communication is proposed to address the above-mentioned technical shortcomings, solve the technical challenges of key management and multi-factor authentication, and significantly improve the overall security level of the power grid system. Summary of the Invention

[0005] In view of the security and reliability problems of existing power grid key management methods in the face of the development of quantum computers, this invention is proposed.

[0006] Therefore, the problem to be solved by this invention is how to improve the overall security and reliability of the power grid key management system in order to cope with the security threats brought about by the development of quantum computers and to solve the technical shortcomings of existing quantum key distribution systems in practical applications.

[0007] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0008] In a first aspect, embodiments of the present invention provide a power grid key management method based on quantum communication, comprising: generating and transmitting qubits through a quantum key distribution module, and transmitting the corresponding timestamps to a quantum key storage module and a classical key generation module; receiving and storing qubits and corresponding timestamps in time order through the quantum key storage module; encrypting the plaintext of the key to generate a key through the classical key generation module based on the measurement results of the received qubits, and transmitting the key, timestamps, and indexes to the key storage module; and retrieving the key from the key storage module based on the index, and performing multi-factor authentication.

[0009] As a preferred embodiment of the quantum communication-based power grid key management method of the present invention, the quantum key distribution module includes the following steps: using a laser to generate amplitude and phase-modulated quantum signals of coherent states, and encoding qubits into continuous random variables, as shown in the following formula:

[0010] |ψ>=cosθ|0>+e iφ sinθ|1>;

[0011] Where ψ and φ are randomly selected angles.

[0012] The modulated quantum signal is transmitted to the quantum key storage module through a public quantum channel, and a local oscillator signal is generated using the same laser source. The received quantum signal and the local oscillator signal are then subjected to interferometry. The measurement result is compared with the modulation value from the quantum key distribution module, and error correction and privacy amplification are performed by exchanging some measurement results through a publicly available classical channel. The specific formula is as follows:

[0013]

[0014] Where Q is the bit error rate of the qubit, N is the total number of qubits, and x i To receive the measurement results of the quantum signal, y i This is the measurement result of the local oscillator signal.

[0015] The quantum key storage module receives and stores the qubits and their corresponding timestamps in timestamp order, and then transmits them to the classical key generation module.

[0016] As a preferred embodiment of the quantum communication-based power grid key management method of the present invention, the classical key generation module includes the following steps: obtaining qubits of equal length to the plaintext binary code of the key to be encrypted; performing a bit-by-bit XOR operation between the qubits and the plaintext binary code to obtain the first ciphertext, as shown in the following formula:

[0017]

[0018] Where C1 is the first ciphertext, P is the plaintext, and K is the first ciphertext. q Keys generated for quantum purposes;

[0019] The first ciphertext is encrypted using an asymmetric encryption algorithm to generate a key, and the generated key, the corresponding timestamp, and the index are transmitted to the key storage module.

[0020] The key storage module receives and stores the key, corresponding timestamp, and index transmitted by the classic key generation module.

[0021] As a preferred embodiment of the quantum communication-based power grid key management method of the present invention, the asymmetric encryption algorithm is the RSA algorithm; the RSA algorithm includes the following steps: selecting a random integer lattice base as the private key; perturbing this private key integer lattice base by adding finite noise to generate a perturbed integer lattice base as the public key; encoding the first ciphertext as a point in the integer lattice, and adding structured noise around the first ciphertext using the public key base; the decryptor uses the private key base to find the point in the integer lattice containing the noise point, and outputs the point containing the noise as the key, with the relevant formula as follows:

[0022] C2 = A·s + a (mod q);

[0023] Where C2 is the key, A is the public key matrix, s is the encoded information, a is the error vector, and q is the modulus.

[0024] As a preferred embodiment of the power grid key management method based on quantum communication described in this invention, the key reading module includes the following steps: authenticating the key requester's identity through the key reading module; querying the key storage module to obtain the corresponding timestamp based on the index corresponding to the key requester's identity, and simultaneously determining whether the key requester's identity matches the index; simultaneously querying the corresponding qubit in the quantum key storage module based on the timestamp; decrypting the key using an asymmetric decryption algorithm to obtain an intermediate value of the key; performing an XOR operation between the intermediate value and the qubit obtained from the quantum key storage module to obtain the plaintext key; and sending the plaintext key to the key requester.

[0025] As a preferred embodiment of the quantum communication-based power grid key management method of the present invention, the identity authentication includes zero-knowledge proof, biometric identification, and behavioral pattern authentication; the identity authentication includes: when the identity of the index and the key requester matches, the quantum key storage module queries the corresponding qubit according to the timestamp corresponding to the index, decrypts it using an asymmetric decryption algorithm to obtain the key, and performs an XOR operation on the qubit and the key to obtain the key ciphertext; when the identity of the index and the key requester does not match, the key request is rejected and the number of unauthorized accesses is recorded; if the number of unauthorized accesses is greater than the predicted number, a security alarm is triggered.

[0026] In a preferred embodiment of the quantum communication-based power grid key management method of the present invention, the relevant formula for identity authentication is as follows:

[0027] S = r + c·x (mod q);

[0028] Where S is the response sent by the key requester, r is a random number, c is the challenge, x is the private key, and q is the modulus.

[0029] The relevant formulas for the decryption process are as follows:

[0030]

[0031] Where P is the recovered plaintext, C2 is the key, and K is the key. q The key generated for quantum computing.

[0032] Secondly, embodiments of the present invention provide a power grid key management system based on quantum communication, comprising: a quantum key distribution module for generating and transmitting qubits, and transmitting the corresponding timestamps to a quantum key storage module and a classical key generation module; a quantum key storage module for receiving and storing qubits and corresponding timestamps in timestamp order; a classical key generation module for encrypting the plaintext of the key to generate a key based on the measurement results of the received qubits, and transmitting the key, timestamp, and index to the key storage module; and a key reading module for reading the key from the key storage module according to the index and performing multi-factor authentication.

[0033] Thirdly, embodiments of the present invention provide a computer device, including a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program instructions are executed by the processor, they implement the steps of the power grid key management method based on quantum communication as described in the first aspect of the present invention.

[0034] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program instructions are executed by a processor, they implement the steps of the power grid key management method based on quantum communication as described in the first aspect of the present invention.

[0035] The beneficial effects of this invention are as follows: This invention generates and transmits qubits through a quantum key distribution module, and transmits the corresponding timestamps to a quantum key storage module and a classical key generation module, ensuring the synchronization of key timestamps; the quantum key storage module stores qubits and corresponding timestamps in timestamp order, improving the reliability and traceability of key storage; based on the measurement results of the received qubits, the classical key generation module encrypts the plaintext key to generate a new key, and transmits the key, timestamp, and index to the key storage module, ensuring the security of key generation; the key reading module retrieves the key from the key storage module according to the index and performs multi-factor authentication, enhancing the security of key usage and solving the technical challenges of key management and multi-factor authentication. Attached Figure Description

[0036] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0037] Figure 1 This is a flowchart of the power grid key management method based on quantum communication in Example 1.

[0038] Figure 2 This is a system architecture diagram of the power grid key management method based on quantum communication in Example 1. Detailed Implementation

[0039] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0040] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0041] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0042] Example 1

[0043] Reference Figures 1-2 This is the first embodiment of the present invention, which provides a power grid key management method based on quantum communication, including:

[0044] S1: Generate and send qubits through the quantum key distribution module, and transmit the corresponding timestamps to the quantum key storage module and the classical key generation module.

[0045] Specifically, the quantum key distribution module includes the following steps: using a laser to generate amplitude and phase-modulated quantum signals of coherent states, and encoding qubits into continuous random variables, as shown in the following formula:

[0046] |ψ>=cosθ|0>+e iφ sinθ|1>;

[0047] Where ψ and φ are randomly selected angles.

[0048] Furthermore, the modulated quantum signal is transmitted to the quantum key storage module through a public quantum channel, and a local oscillator signal is generated using the same laser source. The received quantum signal and the local oscillator signal are then subjected to interferometric measurement. The measurement result is compared with the modulation value from the quantum key distribution module, and error correction and privacy amplification are performed by exchanging some measurement results through a publicly available classical channel. The specific formula is as follows:

[0049]

[0050] Where Q is the bit error rate of the qubit, N is the total number of qubits, and x i To receive the measurement results of the quantum signal, y i This is the measurement result of the local oscillator signal.

[0051] Furthermore, the quantum key storage module receives and stores the qubits and their corresponding timestamps in timestamp order, and then transmits them to the classical key generation module.

[0052] Specifically, if the measurement result and modulation value match perfectly, the transmission is confirmed as successful, this bit is used as a valid key bit, and the processing of the next bit continues; if the measurement result and modulation value are less than a predetermined threshold, the sender is contacted through the classical channel to confirm whether it is a normal error; if it is confirmed as a normal error, error correction is performed; if it cannot be confirmed, this bit is discarded; if the measurement result and modulation value are greater than a predetermined threshold, this bit is immediately discarded, and an anomaly is recorded; if multiple consecutive bits exceed a preset number, the key distribution process is paused, the security protocol is initiated, and the quantum channel is re-established; if the measurement result is completely random and unrelated to the modulation value, it is suspected that the quantum channel has been completely intercepted, the current key distribution session is immediately terminated, and the system administrator is notified to conduct a security check.

[0053] S2 receives and stores qubits and their corresponding timestamps in time sequence through the quantum key storage module.

[0054] Based on the measurement results of the received qubits, S3 encrypts the plaintext key to generate a new key through the classical key generation module, and then transmits the key, timestamp, and index to the key storage module.

[0055] Specifically, the classical key generation module includes the following steps: obtaining qubits of equal length to the plaintext binary code of the key to be encrypted; performing a bitwise XOR operation between the qubits and the plaintext binary code to obtain the first ciphertext, as shown in the following formula:

[0056]

[0057] Where C1 is the first ciphertext, P is the plaintext, and K is the first ciphertext. q The key generated for quantum computing.

[0058] Furthermore, the first ciphertext is encrypted using an asymmetric encryption algorithm to generate a key, and the generated key, corresponding timestamp, and index are transmitted to the key storage module; the key storage module receives and stores the key, corresponding timestamp, and index transmitted by the classic key generation module.

[0059] S4 uses the index to retrieve the key from the key storage module and performs multi-factor authentication.

[0060] Specifically, the key reading module includes the following steps: authenticating the key requester's identity through the key reading module; querying the key storage module to obtain the corresponding timestamp based on the index corresponding to the key requester's identity, and simultaneously determining whether the key requester's identity matches the index; simultaneously querying the corresponding qubit in the quantum key storage module based on the timestamp; decrypting the key using an asymmetric decryption algorithm to obtain the intermediate value of the key; performing an XOR operation between the intermediate value and the qubit obtained from the quantum key storage module to obtain the plaintext key; and sending the plaintext key to the key requester.

[0061] Furthermore, identity authentication includes zero-knowledge proofs, biometrics, and behavioral pattern authentication. Identity authentication involves the following steps: when the identity of the index and the key requester matches, the quantum key storage module queries the corresponding qubit based on the timestamp of the index, decrypts it using an asymmetric decryption algorithm to obtain the key, and performs an XOR operation on the qubit and the key to obtain the key ciphertext. When the identity of the index and the key requester does not match, the key request is rejected, and the number of unauthorized accesses is recorded. If the number of unauthorized accesses exceeds the predicted number, a security alarm is triggered.

[0062] Furthermore, the relevant formula for identity verification is as follows:

[0063] S = r + c·x (mod q);

[0064] Where S is the response sent by the key requester, r is a random number, c is the challenge, x is the private key, and q is the modulus.

[0065] Specifically, the relevant formulas for the decryption process are as follows:

[0066]

[0067] Where P is the recovered plaintext, C2 is the key, and K is the key. q The key generated for quantum computing.

[0068] Furthermore, this embodiment also provides a power grid key management system based on quantum communication, including: a quantum key distribution module for generating and sending qubits, and transmitting the corresponding timestamps to a quantum key storage module and a classical key generation module; a quantum key storage module for receiving and storing qubits and corresponding timestamps in timestamp order; a classical key generation module for encrypting the plaintext key to generate a key based on the measurement results of the received qubits, and transmitting the key, timestamp, and index to the key storage module; and a key reading module for reading the key from the key storage module according to the index and performing multi-factor authentication.

[0069] This embodiment also provides a computer device applicable to the power grid key management method based on quantum communication, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the power grid key management method based on quantum communication as proposed in the above embodiment.

[0070] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.

[0071] This embodiment also provides a storage medium storing a computer program. When executed by a processor, the program performs the following steps: generating and sending qubits through a quantum key distribution module, and transmitting the corresponding timestamps to a quantum key storage module and a classical key generation module; receiving and storing qubits and corresponding timestamps in timestamp order through the quantum key storage module; encrypting the plaintext key to generate a key through the classical key generation module based on the measurement results of the received qubits, and transmitting the key, timestamp, and index to the key storage module; and retrieving the key from the key storage module based on the index, and performing multi-factor authentication.

[0072] In summary, this invention generates and transmits qubits through a quantum key distribution module, and transmits the corresponding timestamps to a quantum key storage module and a classical key generation module, ensuring the synchronization of key timestamps. The quantum key storage module stores qubits and their corresponding timestamps in timestamp order, improving the reliability and traceability of key storage. Based on the measurement results of the received qubits, the classical key generation module encrypts the plaintext key to generate a new key, and transmits the key, timestamp, and index to the key storage module, ensuring the security of key generation. The key reading module retrieves the key from the key storage module according to the index and performs multi-factor authentication, enhancing the security of key usage and solving the technical challenges of key management and multi-factor authentication.

[0073] Example 2

[0074] Referring to Table 1, the second embodiment of the present invention provides a power grid key management method based on quantum communication. To verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0075] Specifically, in the quantum key distribution module, a narrow-linewidth laser with a wavelength of 1550 nm is used to generate coherent photons. A high-speed electro-optic modulator encodes the qubits into continuous random variables. Specifically, a phase encoding scheme is employed, randomly selecting four phase states: 0°, 45°, 90°, and 135°. The encoded quantum signal is transmitted to each power substation via a 50 km long low-loss optical fiber (loss <0.2 dB / km). At the receiving end, a superconducting nanowire single-photon detector (SNSPD) is used for detection, achieving a quantum efficiency of up to 93% and a dark count rate as low as 1 Hz.

[0076] Furthermore, to improve system security and efficiency, an improved BB84 protocol is implemented. In this protocol, in addition to randomly selecting the coding basis, the sender dynamically adjusts the average number of photons in a single pulse (ranging from 0.1 to 0.5) to resist photon number splitting attacks. Simultaneously, the receiver employs Measurement Device Independent Quantum Key Distribution (MDI-QKD) technology to perform Bell state measurements through relay nodes, effectively preventing attacks from all detector ends.

[0077] Furthermore, the quantum key storage module uses a high-performance solid-state drive array to store the received qubit information and its corresponding nanosecond-level precise timestamps. The storage system employs a RAID 10 configuration, ensuring both data security and improved read / write speeds. To further enhance security, all stored data is encrypted using AES-256.

[0078] Specifically, the classical key generation module employs a hybrid encryption strategy; it performs an XOR operation between the plaintext key to be encrypted and an equal-length qubit to obtain a preliminary encrypted ciphertext; it then uses an improved lattice cryptography algorithm to perform a secondary encryption on the ciphertext; and it adopts an encryption scheme based on the Ring-LWE problem, whose security is based on the difficulty of the shortest vector problem in a lattice, and is considered to be resistant to attacks by quantum computers.

[0079] Furthermore, a multi-factor authentication mechanism is implemented in the key reading module; zero-knowledge proofs are performed using the Schnorr protocol based on elliptic curves to verify the identity of the requester; multimodal biometric technology is adopted, combining fingerprint, iris, and facial features for identity verification; and machine learning algorithms are used to analyze user behavior patterns to further improve the accuracy of identity verification.

[0080] Furthermore, as shown in Table 1, the key generation rate of this invention reaches 15.6 kbps, which is about 53% higher than the traditional BB84 quantum key distribution method. This significant improvement is mainly due to the improved BB84 protocol and efficient quantum state modulation technology. The higher key generation rate allows the system to update the key more frequently, thereby greatly enhancing communication security.

[0081] Table 1 Comparison between the present invention and prior art

[0082] feature This invention Traditional RSA encryption BB84 Quantum Key Distribution Key generation rate (kbps) 15.6 N / A 10.2 Quantum bit error rate (%) 0.8 N / A 1.5 Resistance to quantum computing attacks (Levels 1-5) 5 1 5 System throughput (Mbps) 856 712 625 Key update frequency (once per minute) 30 0.1 20

[0083] Specifically, in terms of qubit error rate, this invention controls the qubit error rate to 0.8%, a significant reduction compared to the 1.5% of the BB84 method. This is mainly attributed to the use of a high-performance superconducting single-photon detector and an advanced error correction algorithm. The lower error rate not only improves the reliability of the system but also reduces the computational resources required for subsequent error correction.

[0084] Furthermore, in terms of resistance to quantum computing attacks, both this invention and the BB84 method exhibit the highest level (level 5) resistance, while traditional RSA encryption is highly vulnerable to quantum computers (level 1). This invention, by combining quantum key distribution and quantum cryptography algorithms (such as lattice-based encryption), provides robust security for the future quantum computing era.

[0085] Furthermore, the system throughput of this invention reaches 856 Mbps, which is approximately 20% and 37% higher than traditional RSA encryption and BB84 methods, respectively. This high throughput is mainly attributed to the innovative hybrid encryption strategy and efficient key management mechanism, enabling the system to meet the needs of large-scale, real-time data transmission in smart grids. Regarding key update frequency, this invention achieves a key update frequency of 30 times per minute, far exceeding the 0.1 times / minute of traditional RSA encryption and the 20 times / minute of BB84. Frequent key updates significantly improve system security; even if an attacker successfully cracks the key at a certain point in time, they cannot eavesdrop on or tamper with the communication content for an extended period.

[0086] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A power grid key management method based on quantum communication, characterized in that: include, The quantum key distribution module generates and sends qubits, and transmits the corresponding timestamps to the quantum key storage module and the classical key generation module. The quantum key storage module receives and stores qubits and their corresponding timestamps in timestamp order. Based on the measurement results of the received qubits, the plaintext key is encrypted to generate a new key through the classical key generation module, and the key, timestamp, and index are transmitted to the key storage module. Based on the index, the key reading module retrieves the key from the key storage module and performs multi-factor authentication; The measurement results are compared with the modulation values ​​of the quantum key distribution module. Error correction and privacy amplification are performed by exchanging the measurement results through a publicly available classical channel, as shown in the following formula: in, For the bit error rate, The total number of qubits, To receive the measurement results of the quantum signal, The measurement results are for the local oscillator signal; The quantum key storage module receives and stores the qubits and their corresponding timestamps in timestamp order, and then transmits them to the classical key generation module. The classic key generation module includes the following steps: Obtain qubits of the same length as the plaintext binary code of the key to be encrypted; The first ciphertext is obtained by performing a bitwise XOR operation between the qubits and the plaintext binary code, as shown in the following formula: in, This is the first ciphertext. For plain text, Keys generated for quantum purposes; The first ciphertext is encrypted using an asymmetric encryption algorithm to generate a key, and the generated key, the corresponding timestamp, and the index are transmitted to the key storage module. The key storage module receives and stores the key, corresponding timestamp, and index transmitted by the classic key generation module. The key reading module includes the following steps: The key requester's identity is authenticated through the key reading module; Based on the index corresponding to the key requester's identity, query the key storage module to obtain the corresponding timestamp, and at the same time determine whether there is a preset binding relationship between the key requester's identity and the index; Simultaneously, in the quantum key storage module, the corresponding quantum bit is queried based on the timestamp; The key is decrypted using an asymmetric decryption algorithm to obtain an intermediate value of the key. The plaintext key is obtained by performing an XOR operation between the intermediate value and the qubit obtained from the quantum key storage module. Send the plaintext key to the key requester; The identity authentication includes zero-knowledge proofs, biometrics, and behavioral pattern authentication; the identity authentication includes, When the identity of the index and the key requester matches, the quantum key storage module queries the corresponding qubit according to the timestamp of the index, decrypts it using an asymmetric decryption algorithm to obtain the intermediate value of the key, and performs an XOR operation on the intermediate value of the qubit and the key to obtain the plaintext key. If the identity of the index and key requester does not match, the key request is rejected and the number of unauthorized accesses is recorded. If the number of unauthorized accesses exceeds a preset threshold, a security alert will be triggered.

2. The power grid key management method based on quantum communication as described in claim 1, characterized in that: The quantum key distribution module includes the following steps: A coherent state amplitude and phase modulated quantum signals are generated using a laser, and the qubits are encoded into continuous random variables, as shown in the following formula: Where θ and φ are randomly selected angles; The modulated quantum signal is transmitted to the quantum key storage module through a public quantum channel, and the same laser source is used to generate a local oscillator signal; The received quantum signal and the local oscillator signal are subjected to interferometric measurement.

3. The power grid key management method based on quantum communication as described in claim 2, characterized in that: The asymmetric encryption algorithm is an improved lattice cipher algorithm; the improved lattice cipher algorithm includes the following steps: Choose a random integer lattice base as the private key; By adding finite noise to perturb the integer base of this private key, a perturbed integer base is generated as the public key; The first ciphertext is encoded as a point in an integer dot matrix, and structured noise is added around the first ciphertext using a public key base. The decryptor uses the private key base to find the integer points in the integer matrix that contain noisy points, and outputs the noisy points as the key. The relevant formula is as follows: in, For the key, For public key matrix, For encoded information, For the error vector, It is the modulus.

4. A power grid key management system based on quantum communication, based on the power grid key management method based on quantum communication according to any one of claims 1 to 3, characterized in that: include, The quantum key distribution module is used to generate and send qubits, and transmit the corresponding timestamps to the quantum key storage module and the classical key generation module; A quantum key storage module is used to receive and store qubits and their corresponding timestamps in timestamp order; The classical key generation module is used to encrypt the plaintext key to generate a key based on the measurement results of the received qubits, and transmit the key, timestamp, and index to the key storage module; The key reading module is used to read the key from the key storage module according to the index and perform multi-factor authentication.

5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the power grid key management method based on quantum communication as described in any one of claims 1 to 3.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the power grid key management method based on quantum communication as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Mobile quantum secret communication method, gateway, mobile terminal and server

    CN111404671A

  • Quantum key management method and system based on block chain

    CN112073182A