Security assessment method and system for quantum encryption communication network in power system

By grading and classifying quantum encryption communication networks and conducting security scoring, the problem of imperfect power system security assessment in existing technologies has been solved, and security risk assessment and monitoring of quantum encryption communication networks have been realized to meet the complex environmental requirements of power systems.

CN119011252BActive Publication Date: 2025-09-23NARI INFORMATION & COMM TECH +5
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411113064.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-14
Publication Date
2025-09-23
Estimated Expiration
2044-08-14

AI Technical Summary

Technical Problem

Existing security assessment methods are not perfect enough to meet the complex internal elements and environmental requirements of the power system, and cannot effectively respond to the security challenges of quantum encryption communication networks.

Method used

A level-based protection approach is used to classify quantum encryption communication networks, set different security level scores according to different business scenarios, and perform security scoring using network element security indexes and weight coefficients, including the evaluation of quantum key management, key usage, business applications, and quantum network management elements.

Benefits of technology

It realizes the security risk assessment of quantum encryption communication network, provides technical guidelines, provides support for power operation environment monitoring, and meets the design goals of trustworthy security, flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119011252B_ABST
    Figure CN119011252B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for assessing the security of a quantum cryptography communication network in a power system. The method classifies elements according to the type and function of devices in the quantum cryptography communication network, determines a network element security index for each type of element in the quantum cryptography communication network, determines a network element security weight coefficient for each device in each type of element, linearly adds the network element security index and the network element security weight coefficient for each device to obtain an initial security score, determines a security protection requirement level coefficient based on the business scenario of the quantum cryptography communication network, and calibrates the initial security score based on the security protection requirement level coefficient to obtain a security score for the quantum cryptography communication network. The present invention implements a quantum cryptography communication network security assessment method based on the concept of hierarchical protection, reveals the security risks of quantum cryptography communication networks, and provides a technical guideline reference for monitoring power operation environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a network security assessment method, in particular to a security assessment method and system for a power system quantum encryption communication network. Background Art

[0002] In power systems, leveraging the theoretically unconditionally secure communication advantages of quantum cryptography and integrating power communications with quantum communication technologies can enable the secure and reliable operation of production control and management data collection services within core grid nodes and wide-area discrete nodes. Quantum cryptography provides a long-term defense against various computational decryption techniques during grid operation, effectively addressing the new security challenges posed by the development of new power systems and possessing broad application prospects.

[0003] Currently, quantum encryption technology is primarily used in power dispatching operations. Dispatching control centers need to collect status data from various stations and send control commands, placing high demands on the security of communication networks. Existing security assessment methods are inadequate and unable to meet the complex internal elements and environmental requirements of power systems. Summary of the Invention

[0004] Purpose of the invention: The purpose of the present invention is to provide a security assessment method and system for quantum encryption communication networks in power systems based on hierarchical protection.

[0005] Technical solution: The security assessment method for a power system quantum encryption communication network according to the present invention comprises the following steps:

[0006] Classify elements according to the types and functions of devices in the quantum encryption communication network, and determine the network element security index for each type of element in the quantum encryption communication network; and determine the network element security weight coefficient for each device in each type of element;

[0007] The initial security score is obtained by linearly adding the network element security index and network element security weight coefficient of each device;

[0008] A security protection requirement level coefficient is determined according to the business scenario of the quantum encryption communication network, and the initial security score is calibrated according to the security protection requirement level coefficient to obtain a security score of the quantum encryption communication network.

[0009] Furthermore, the element classification according to the type and function of the equipment in the quantum encryption communication network includes:

[0010] The quantum encryption communication network is divided into quantum key management elements, key usage elements, business application elements and quantum network management elements;

[0011] Quantum key management elements include quantum key networking equipment;

[0012] Key usage elements include a power-specific quantum encryption gateway;

[0013] Business application elements include customer business systems and equipment;

[0014] Quantum network management elements include security management systems.

[0015] Furthermore, determining the security protection requirement level coefficient according to the service scenario of the quantum encryption communication network includes: dividing the security protection requirement level of the quantum encryption communication network from low to high,

[0016] The quantum encryption communication network in the distributed renewable energy power generation business scenario has the first security protection requirement level;

[0017] The quantum encryption communication network in the centralized renewable energy power generation business scenario has the second security protection requirement level;

[0018] The quantum encryption communication network in the distribution automation business scenario has the third security protection requirement level;

[0019] The quantum encryption communication network in the power transmission and transformation substation business scenario is the fourth security protection requirement level;

[0020] The quantum encryption communication network in the business scenarios of dispatching centers at the provincial level and above is the fifth level of security protection requirements.

[0021] Furthermore, determining the security protection requirement level coefficient according to the business scenario of the quantum encryption communication network includes:

[0022] According to the security protection requirement levels of the quantum encryption communication network, security protection requirement level coefficients are set from low to high.

[0023] Furthermore, calibrating the initial security score according to the security protection requirement level coefficient to obtain the security score of the quantum encryption communication network includes:

[0024] The security score of a quantum encryption communication network is the ratio of the initial security score to the security protection requirement level coefficient.

[0025] The security assessment system for a power system quantum encryption communication network according to the present invention comprises:

[0026] A network element security coefficient and index calculation unit is used to classify elements according to the type and function of devices in the quantum encryption communication network, determine the network element security index for each type of element in the quantum encryption communication network; and determine the network element security weight coefficient for each device in each type of element;

[0027] A quantum network security initial score calculation unit is used to obtain an initial security score by linearly adding the network element security index and network element security weight coefficient of each device;

[0028] The quantum network security score calculation unit is used to determine the security protection requirement level coefficient according to the business scenario of the quantum encryption communication network, calibrate the initial security score according to the security protection requirement level coefficient, and obtain the security score of the quantum encryption communication network.

[0029] Furthermore, in the network element security coefficient and index calculation unit, the quantum encryption communication network is divided into quantum key management elements, key usage elements, service application elements and quantum network management elements;

[0030] Quantum key management elements include quantum key networking equipment;

[0031] Key usage elements include a power-specific quantum encryption gateway;

[0032] Business application elements include customer business systems and equipment;

[0033] Quantum network management elements include security management systems.

[0034] Furthermore, in the quantum network security scoring calculation unit, the security protection requirement level of the quantum encryption communication network is divided from low to high: the quantum encryption communication network of the distributed new energy power generation business scenario is the first security protection requirement level;

[0035] The quantum encryption communication network in the centralized renewable energy power generation business scenario has the second security protection requirement level;

[0036] The quantum encryption communication network in the distribution automation business scenario has the third security protection requirement level;

[0037] The quantum encryption communication network in the power transmission and transformation substation business scenario is the fourth security protection requirement level;

[0038] The quantum encryption communication network in the business scenarios of dispatching centers at the provincial level and above is the fifth level of security protection requirements.

[0039] Furthermore, in the quantum network security scoring calculation unit, security protection requirement level coefficients are set from low to high according to the security protection requirement levels of the quantum encryption communication network.

[0040] Furthermore, in the quantum network security score calculation unit, the security score of the quantum encryption communication network is the ratio of the initial security score to the security protection requirement level coefficient.

[0041] The electronic device described in the present invention includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the computer program is loaded into the processor, it implements the security assessment method of the power system quantum encryption communication network.

[0042] The computer-readable storage medium of the present invention stores a computer program, and when the computer program is executed by a processor, the security assessment method of the power system quantum encryption communication network is implemented.

[0043] Beneficial effect: Compared with the existing technology, the advantages of the present invention are: the present invention classifies the quantum encryption communication network in the power system, sets different security level scores in different business scenarios, realizes the quantum encryption communication network security assessment method based on the level protection idea, reveals the security risks of the quantum encryption communication network, provides technical guidelines for power operation environment monitoring, and meets the design goals of "trusted security, flexible and efficient". BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 This is a schematic diagram of the classification of quantum encryption communication network elements of the present invention;

[0045] Figure 2 This is a schematic diagram of the quantum encryption communication security score calculation method of the present invention;

[0046] Figure 3 This is a block diagram of the security assessment system for the quantum encryption communication network of the present invention. DETAILED DESCRIPTION

[0047] The technical solution of the present invention will be further described below with reference to the accompanying drawings.

[0048] 1. Classification of security protection requirements for quantum encryption communication networks

[0049] Based on the environmental requirements for power system operation, the security protection requirements for quantum encryption communication networks are graded from light to heavy, divided into level one (autonomous protection), level two (guided protection), level three (supervisory protection), level four (mandatory protection), and level five (special control protection).

[0050] In the power system, business scenarios are generally divided by time or space. In terms of space, the business is often divided into power generation, transmission, transformation, distribution and power consumption; in terms of space, the business is often divided into security zones one, two, three and four. In different business scenarios, the security protection level is different and can be quantitatively graded. According to the security protection requirement level of the quantum encryption communication network from low to high, the security protection requirement level coefficients are set from low to high. In this embodiment, five different scenarios of the power dispatching business are taken as an example to perform security grading of the quantum encryption communication network in the specific business scenario. Refer to Table 1.

[0051] Table 1 Classification of protection levels in different scenarios

[0052]

[0053] 2. Classify quantum encryption communication network elements

[0054] like Figure 1 As shown, the internal elements of the quantum encryption communication network are divided into quantum key management elements, key usage elements, business application elements and quantum network management elements.

[0055] Quantum key management elements include quantum key networking equipment, such as quantum key management machines, quantum key production and management terminals (transmitters, receivers), optical quantum switches, basic network management software, and other equipment, which are used for the generation, management, distribution and trusted relay of quantum keys.

[0056] Key usage elements mainly include power-specific quantum encryption gateways, which use quantum keys to encrypt and decrypt business application layer data, including quantum VPN selection and design and business encryption channel design.

[0057] Business application elements mainly include customer business systems and equipment. The ciphertext encrypted with quantum keys is finally transmitted at the business application layer, including business terminal and business system access design, business channel design, etc.

[0058] Quantum network management elements mainly include security management systems, which monitor and manage terminals, service hosts, and tunnel status.

[0059] 3. Safety Score Calculation Method

[0060] A hierarchical and classified security assessment method for quantum encryption communication networks, such as Figure 2 As shown, it includes the following steps:

[0061] (1) Determine the security index X for each type of network element i .

[0062] Determine their security index, with a numerical range of 0 to 100. In this embodiment, the security index of key management elements, such as quantum key management machines, quantum key generation and management terminals, optical quantum switches, and other network elements closely related to quantum keys, can be assigned a security index of 85 to 100. Key usage elements, including VPN gateways and encryption machines, can be assigned a security index of 75 to 90. Business application elements, including business terminals, business front-end processors, switches, routers, etc., can be assigned a security index of 70 to 85. Network management elements, including security management platforms and remote operation and maintenance hosts, can be assigned a security index of 80 to 95.

[0063] (2) Determine the network element security weight coefficient K for each device i .

[0064] Determine their security weights, ranging from 0 to 100%, with the sum of all element weights reaching 100%. Quantum key management elements have a total weight of approximately 30%, key usage elements have a total weight of 30%, business application elements have a total weight of 25%, and network management elements have a total weight of 15%. All elements within each category share a certain percentage.

[0065] (3) Linearly add the exponents and coefficients of all network elements to obtain the initial security score S'. The formula for linear addition to obtain the initial security score is:

[0066] S'=(K1*X1+K2*X2+···+K n *X n )

[0067] (4) The security score is accurately calculated based on the security protection requirement level coefficient E of the quantum encryption communication network. The security score S of the quantum encryption communication network is S' / E.

[0068] Before calibration, the same initial security score will have different implications for networks with different protection level requirements. For networks with lower protection requirements, it indicates a higher security assessment result; conversely, for networks with higher protection requirements, it indicates a greater security risk. Therefore, it is necessary to divide the initial security score by the protection level coefficient to calibrate the security score.

[0069] like Figure 3 As shown, the security assessment system of the power system quantum encryption communication network of the present invention includes:

[0070] A network element security coefficient and index calculation unit is used to classify elements according to the type and function of devices in the quantum encryption communication network, determine the network element security index for each type of element in the quantum encryption communication network; and determine the network element security weight coefficient for each device in each type of element;

[0071] A quantum network security initial score calculation unit is used to obtain an initial security score by linearly adding the network element security index and network element security weight coefficient of each device;

[0072] The quantum network security score calculation unit is used to determine the security protection requirement level coefficient according to the business scenario of the quantum encryption communication network, calibrate the initial security score according to the security protection requirement level coefficient, and obtain the security score of the quantum encryption communication network.

[0073] In the network element security coefficient and index calculation unit, the quantum encryption communication network is divided into quantum key management elements, key usage elements, business application elements and quantum network management elements; quantum key management elements include quantum key networking equipment; key usage elements include power-specific quantum encryption gateways; business application elements include customer business systems and equipment; quantum network management elements include security management systems.

[0074] In the quantum network security scoring calculation unit, the security protection requirement levels of the quantum encryption communication network are divided from low to high: the quantum encryption communication network of the distributed new energy power generation business scenario is the first security protection requirement level; the quantum encryption communication network of the centralized new energy power generation business scenario is the second security protection requirement level; the quantum encryption communication network of the distribution automation business scenario is the third security protection requirement level; the quantum encryption communication network of the power transmission and transformation substation business scenario is the fourth security protection requirement level; the quantum encryption communication network of the dispatching center business scenario at or above the provincial level is the fifth security protection requirement level.

[0075] The quantum network security score calculation unit sets security protection requirement level coefficients from low to high according to the security protection requirement levels of the quantum encryption communication network. The security score of the quantum encryption communication network is the ratio of the initial security score to the security protection requirement level coefficient.

[0076] The electronic device described in the present invention includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor. When the computer program is loaded into the processor, it implements the security assessment method of the power system quantum encryption communication network.

[0077] The computer-readable storage medium of the present invention stores a computer program, and when the computer program is executed by a processor, the security assessment method of the power system quantum encryption communication network is implemented.

[0078] The computer-readable storage media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage, flash memory, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer.

[0079] The processor is configured to execute the computer program stored in the memory to implement the various steps in the method involved in the above embodiment.

Claims

1. A security assessment method for a power system quantum encryption communication network, characterized in that: The steps include: Classify elements according to the types and functions of devices in the quantum encryption communication network, and determine the network element security index for each type of element in the quantum encryption communication network; and determine the network element security weight coefficient for each device in each type of element; The initial security score is obtained by linearly adding the network element security index and network element security weight coefficient of each device; Determine a security protection requirement level coefficient based on the business scenario of the quantum encryption communication network, calibrate the initial security score based on the security protection requirement level coefficient, and obtain a security score for the quantum encryption communication network; The element classification according to the type and function of the equipment in the quantum encryption communication network includes: The quantum encryption communication network is divided into quantum key management elements, key usage elements, business application elements and quantum network management elements; Quantum key management elements include quantum key networking equipment; Key usage elements include a power-specific quantum encryption gateway; Business application elements include customer business systems and equipment; Quantum network management elements include security management systems.

2. The security assessment method for a power system quantum encryption communication network according to claim 1 is characterized in that: Determining the security protection requirement level coefficient according to the business scenario of the quantum encryption communication network includes: dividing the security protection requirement level of the quantum encryption communication network from low to high, The quantum encryption communication network in the distributed renewable energy power generation business scenario has the first security protection requirement level; The quantum encryption communication network in the centralized renewable energy power generation business scenario has the second security protection requirement level; The quantum encryption communication network in the distribution automation business scenario has the third security protection requirement level; The quantum encryption communication network in the power transmission and transformation substation business scenario is the fourth security protection requirement level; The quantum encryption communication network in the business scenarios of dispatching centers at the provincial level and above is the fifth level of security protection requirements.

3. The security assessment method for a power system quantum encryption communication network according to claim 2 is characterized in that: Determining the security protection requirement level coefficient according to the business scenario of the quantum encryption communication network includes: According to the security protection requirement levels of the quantum encryption communication network, security protection requirement level coefficients are set from low to high.

4. The security assessment method for a power system quantum encryption communication network according to claim 1 is characterized in that: Calibrating the initial security score according to the security protection requirement level coefficient to obtain the security score of the quantum encryption communication network includes: The security score of a quantum encryption communication network is the ratio of the initial security score to the security protection requirement level coefficient.

5. A security assessment system for a power system quantum encryption communication network, characterized in that: include: A network element security coefficient and index calculation unit is used to classify elements according to the type and function of devices in the quantum encryption communication network, determine the network element security index for each type of element in the quantum encryption communication network; and determine the network element security weight coefficient for each device in each type of element; A quantum network security initial score calculation unit is used to obtain an initial security score by linearly adding the network element security index and network element security weight coefficient of each device; A quantum network security score calculation unit is used to determine a security protection requirement level coefficient according to a business scenario of the quantum encryption communication network, calibrate the initial security score according to the security protection requirement level coefficient, and obtain a security score for the quantum encryption communication network; In the network element security coefficient and index calculation unit, the quantum encryption communication network is divided into quantum key management elements, key usage elements, business application elements and quantum network management elements; Quantum key management elements include quantum key networking equipment; Key usage elements include a power-specific quantum encryption gateway; Business application elements include customer business systems and equipment; Quantum network management elements include security management systems.

6. The security assessment system for the power system quantum encryption communication network according to claim 5 is characterized in that: In the quantum network security scoring calculation unit, the security protection requirement level of the quantum encryption communication network is divided from low to high: the quantum encryption communication network of the distributed new energy power generation business scenario is the first security protection requirement level; The quantum encryption communication network in the centralized renewable energy power generation business scenario has the second security protection requirement level; The quantum encryption communication network in the distribution automation business scenario has the third security protection requirement level; The quantum encryption communication network in the power transmission and transformation substation business scenario is the fourth security protection requirement level; The quantum encryption communication network in the business scenarios of dispatching centers at the provincial level and above is the fifth level of security protection requirements.

7. The security assessment system for the power system quantum encryption communication network according to claim 6 is characterized in that: In the quantum network security scoring calculation unit, security protection requirement level coefficients are set from low to high according to the security protection requirement levels of the quantum encryption communication network.

8. The security assessment system for the power system quantum encryption communication network according to claim 5 is characterized in that: In the quantum network security score calculation unit, the security score of the quantum encryption communication network is the ratio of the initial security score to the security protection requirement level coefficient.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the computer program is loaded into a processor, the security assessment method for a power system quantum encryption communication network according to any one of claims 1 to 4 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the security assessment method for a power system quantum encryption communication network according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Security risk assessment method and apparatus

    CN103716177A

  • Risk assessment method for key assets of quantum secret communication system and related equipment

    CN118487758A