An Efficient Method for Key Distribution and Data Encryption in Distribution Areas Based on Quantum Communication
Through the key management platform based on quantum communication and offline charging technology, the problems of low key distribution efficiency and insufficient data encryption security are solved in the station area, efficient and secure data encryption communication are achieved, and the security and authentication reliability of quantum communication are enhanced.
Patent Information
- Application Number
- CN202411639862.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-18
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-11-18
AI Technical Summary
The existing technology has low key distribution efficiency and insufficient data encryption security, so it is unable to effectively deal with the potential threats of quantum computers.
The key management platform based on quantum communication is adopted to realize identity authentication and session key generation between side devices and end devices by charging offline quantum protection keys and certificates, and data encryption and decryption are used to ensure communication security.
It improves the efficiency of key distribution and the security of data encryption, reduces the demand for quantum channels, enhances the authentication security between the nodes of the communication, and prevents information forgery and tampering.
Smart Images

Figure CN119135457B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to communication technologies, and particularly, to a method for efficiently distributing area keys and encrypting data based on quantum communication technology, aiming to improve the security, efficiency, and reliability of data transmission. Background Art
[0002] With the rapid development of information technology, communication security has become an urgent problem to be solved. Traditional encryption methods such as RSA and AES are unable to cope with the potential threats of quantum computers. Quantum communication technology, with its unique features of non-clonability, unpredictability, and high security, provides a new solution for communication security. Especially in area communication, higher requirements are put forward for key distribution and data encryption. Summary of the Invention
[0003] The present invention aims to solve the problems of low efficiency of area key distribution and insufficient security of data encryption in the prior art, and provides a method for efficiently distributing area keys and encrypting data based on quantum communication.
[0004] To achieve the above object, the present invention provides a method for efficiently distributing area keys and encrypting data based on quantum communication technology, including:
[0005] Step S1: The quantum key management platform injects the quantum protection key Kc and certificate into the local communication warehouse of the edge device, and injects the quantum protection key Ks and certificate into the end device; the quantum key management platform generates a quantum key and certificate, and transmits the protection key Kc and certificate to the local communication warehouse of the edge device through offline injection, and transmits the protection key Ks and certificate to the end device.
[0006] Step S2: The end device S authenticates its identity to the local communication warehouse of the edge device C.
[0007] Step S3: The local communication warehouse of the edge device C authenticates its identity to the end device S.
[0008] Step S4: The local communication warehouse of the edge device C generates a session key Kh.
[0009] Step S5: Encryption and decryption of downlink data.
[0010] Step S6: Encryption and decryption of uplink data.
[0011] Step S7: Session key update.
[0012] Preferably, step S2 further includes:
[0013] The terminal device S sends its network access certificate to the local communication warehouse of the edge device C. The local communication warehouse of the edge device C authenticates the certificate and sends the authentication result to the terminal device S.
[0014] Preferably, step S3 further includes:
[0015] The local communication warehouse of the edge device C sends its network access certificate to the terminal device S. The terminal device S authenticates the certificate and sends the authentication result to the local communication warehouse of the edge device C;
[0016] After steps S2 and S3, a certified communication connection is established between the local communication warehouse of the edge device C and the terminal device S.
[0017] Preferably, step S4 further includes:
[0018] Step S4.1: The terminal device S transmits the dispersion factor to the local communication warehouse of the edge device C through the established channel;
[0019] Step S4.2: The local communication warehouse of the edge device C uses the quantum protection key Kc and the dispersion factor to calculate the protection key Ks of the terminal device;
[0020] Step S4.3: According to the key composition requirements, a set of session keys Kh is randomly generated; and the session keys are encrypted using the protection key Ks to obtain the encrypted session key Ks(Kh);
[0021] Step S4.4: Through the established channel, the local communication warehouse of the edge device C transmits the encrypted session key Ks(Kh) to the terminal device S;
[0022] Step S4.5: The terminal device S receives the encrypted session key Ks(Kh) and decrypts it to obtain the session key Kh.
[0023] Preferably, step S5 further includes:
[0024] Step S5.1: The main control board of the edge device C sends a downstream plaintext data Data to the local communication warehouse of the edge device C;
[0025] Step S5.2: The local communication warehouse of the edge device C encrypts the downstream plaintext data Data using the session key Kh;
[0026] Step S5.3: The terminal device decrypts the encrypted data Kh(Data) to obtain the downstream plaintext data Data. Preferably, step S6 further includes:
[0027] Step S6.1: The terminal device encrypts the upstream plaintext data Data using the session key Kh;
[0028] Step S6.2: The local communication bin of edge device C decrypts the encrypted data Kh(Data) with the session key Kh to obtain the uplink plaintext data Data;
[0029] Step S6.3: The local communication bin of edge device C sends the uplink plaintext data Data to the main control board of edge device C.
[0030] Preferably, step S7 further includes:
[0031] The terminal device S sends a request to update the session key to edge device C. The local communication bin of edge device C regenerates a new set of session keys Kh', encrypts the new session key Kh' with the session key Kh and transmits it to the terminal device. The terminal device decrypts the encrypted data Kh(Kh') with the session key Kh to obtain the new session key Kh'.
[0032] Preferably, the specific calculation method of the protection key Ks is as follows:
[0033] The quantum key management platform generates two sets of correlated quantum keys of length N, denoted as U and V, U = [u1, u2,..., u N , V = [v1, v2,..., v N ;
[0034] Randomly generate a set of keys of length 2N, [r1, r2,..., r N , r N+1 , r N+2 ,..., r 2N . Insert the first half at intervals into U and the second half at intervals into V, so as to obtain the protection key Ks and Kc of length 2N;
[0035] Ks = [u1, r1, u2, r2,..., u N , r N , Kc = [v1, r N+1 , v2, r N+2 ,..., v N , r 2N ;
[0036] Distribute the generated keys above to the terminal device S and the edge device C in an offline charging manner.
[0037] Preferably, the specific calculation method of the protection key Ks further includes:
[0038] In the power distribution area, each device has a unique identification code. The terminal device constructs a dispersion factor as follows:
[0039] In the system, obtain the unique identification codes of the device itself and the device to be communicated with. Denote the terminal device as As and the edge device as Ac;
[0040] As = [s1, s2, …, s M , Ac = [c1, c2, …, c M ;
[0041] For the terminal device As, use the quantum key U to encrypt (As, Ac) to form a new encrypted sequence [s'1, s'2, …, s' M , c'1, c'2, …, c' M ;
[0042] According to the quantum key U, determine the quantum key V, and use this key to encrypt the random sequence [r1, r2, …, r N to obtain [r'1, r'2, …, r' N ;
[0043] Transmit the sequence [s'1, s'2, …, s' M , c'1, c'2, …, c' M , r'1, r'2, …, r' N to the edge device C through the established channel, and the edge device C analyzes the above data.
[0044] Preferably, the specific calculation method of the protection key Ks further includes:
[0045] Take the first 2M values [s'1, s'2, …, s' M , c'1, c'2, …, c' M , determine the quantum key U of the terminal device through the quantum key V, and then decrypt it to obtain the unique identification code As = [s1, s2, …, s M , Ac = [c1, c2, …, c M , and then compare it with the unique identification code in the system. If they are the same, it means that the data is secure and not tampered with;
[0046] Similarly, decrypt [r'1, r'2, …, r' N to obtain [r1, r2, …, r N , then merge the quantum key U and the random sequence [r'1, r'2, …, r' N to obtain Ks = [u1, r1, u2, r2, …, u N , r N .
[0047] Compared with the prior art, the beneficial effects of the present invention are:
[0048] 1) The off-line charging of quantum keys can ensure the security of system communication, give full play to the confidentiality characteristics of quantum keys, and do not require the establishment of a quantum channel, with high cost-effectiveness.
[0049] 2) During the communication transmission process of the key, the initial quantum key is not transmitted through the channel, ensuring the security of the key.
[0050] 3) By verifying the unique identification code, the security of authentication between the communication parties' nodes is further increased, and the simulation information is forged and tampered with. Brief Description of the Drawings
[0051] Figure 1 This is a security protection solution for low-voltage distribution network services based on quantum encryption of the present invention.
[0052] Figure 2 This is a flowchart of the edge-end quantum key session key distribution and service data transmission protection of the present invention. Detailed Embodiment
[0053] The present invention will be further described in detail below with reference to the accompanying drawings:
[0054] To better understand the present invention, the embodiments of the present invention will be explained in detail below with reference to the accompanying drawings.
[0055] Embodiment 1 of the present invention discloses the related structure of the quantum encryption device of the present invention.
[0056] The structure of the quantum encryption communication system is disclosed in Embodiment 1.
[0057] Based on the quantum key technology, by integrating quantum security chips in the local communication bins of edge devices such as distribution terminals and fusion terminals, and integrating security chips (embedded) or external security modules (external) in end devices such as intelligent circuit breakers, photovoltaic grid-connected circuit breakers, and charging piles, an edge-end quantum security encryption channel is constructed.
[0058] The structure of the high-efficiency distribution data encryption system for the key in the distribution network area based on quantum communication is as Figure 1 shown:
[0059] This encryption communication system includes edge nodes and end nodes, and realizes encrypted communication between the edge nodes and the end nodes by adding security chips in the form of embedded or external security modules.
[0060] Generally, the edge side of the distribution network area of the substation is a distribution terminal. A security chip with a built-in quantum random number generator is deployed in the local communication bin of the edge device, and the quantum session key is encrypted and sent down through the quantum protection key.
[0061] In particular, the security chip of the quantum random number generator can be a quantum random number generator, a quantum random number chip, or other devices or means that can generate true random numbers.
[0062] The end - side of the distribution network in the substation area mainly consists of power consumption (power generation) node devices in the power grid. A security chip is embedded in the end - device or a security module integrated with an external security chip is connected.
[0063] The security chip on the end - side is mainly embedded in the end - device and integrated with the device in an embedded manner, which is called the embedded mode of secure communication; it can also be used for external end - devices; the security module provides security services for the end - device through hardware transformation, such as embedding a tail - end module, an external security isolation device, etc., which is called the external mode of secure communication.
[0064] The end - side device protects the transmission of edge - end service data through quantum key encryption.
[0065] On the other hand, the present invention discloses the composition of the encryption communication system equipment.
[0066] In the process of realizing quantum encryption communication in the distribution network of the substation area, the following equipment is involved:
[0067] (1) The key management platform is used to generate and distribute the initial protection key and certificate for "edge - end" communication, and it is the basic platform for communication key management in the distribution network of the substation area. In quantum encryption secure communication, the protection key and certificate are generally filled in offline.
[0068] (2) The edge - device mainly includes the edge - device main control board and the local communication bin. The device main control board is the device for information generation, processing, and execution, and the local communication bin is the encryption secure communication device. The main control board and the local communication bin constitute the secure communication and information processing control node of the edge - device.
[0069] (3) The end - device includes the end - device functional system and the encryption secure communication module. The end - device functional system is mainly the corresponding facilities and equipment for the distribution network terminal, such as various types of power consumption devices, power grid security protection devices, etc. The secure communication module is the main carrier for realizing quantum encryption secure communication.
[0070] The protection key between the edge and the end is uniformly generated and distributed by the key management platform. The session key between the edge and the end is generated by the quantum random number built in the security chip on the edge - side and distributed to the end - device, and the edge - device is responsible for the maintenance and management of the session key of the end - device.
[0071] In the second embodiment of the present invention, the process of realizing the encryption communication of the present invention is disclosed, as shown in the appendix Figure 2 as follows.
[0072] Denote the edge - device as C and the end - device as S. The method for realizing quantum encryption secure communication between devices C and S is described as follows:
[0073] It can be understood that the edge - device includes the main control board and the local communication bin.
[0074] Step S1: The quantum key management platform injects the quantum protection key Kc and the certificate into the local communication repository of the edge device, and the quantum key management platform injects the quantum protection key Ks and the certificate into the end device;
[0075] The key management platform generates a quantum key and a certificate, and transfers the protection key Kc and the certificate to the local communication repository of the edge device through offline injection, and transfers the protection key Ks and the certificate to the end device.
[0076] Step S2: The end device S authenticates itself to the local communication repository in the edge device C.
[0077] The end device S sends its network access certificate to the local communication repository of the edge device C. The local communication repository authenticates the certificate and sends the authentication result to the end device S.
[0078] Step S3: The local communication repository of the edge device C authenticates itself to the end device S.
[0079] Similarly, the local communication repository of the edge device C sends its network access certificate to the end device S. The end device authenticates the certificate and sends the authentication result to the local communication repository of the edge device C.
[0080] After Step S2 and Step S3, an authenticated communication connection is established between the local communication repository of the edge device C and the end device S.
[0081] Step S4: The local communication repository of the edge device C generates a session key Kh.
[0082] Step S4.1: The end device S transmits the dispersion factor to the local communication repository of the edge device C through the established channel.
[0083] Step S4.2: The local communication repository of the edge device C calculates the protection key Ks of the end device by using the quantum protection key Kc and the dispersion factor.
[0084] Step S4.3: According to the key composition requirements, a group of session keys Kh are randomly generated. And the session key is encrypted by using the protection key Ks to obtain the encrypted session key Ks(Kh).
[0085] Step S4.4: Through the established channel, the local communication repository of the edge device C transmits the encrypted session key Ks(Kh) to the end device S.
[0086] Step S4.5: The end device S receives the encrypted session key Ks(Kh) and decrypts it to obtain the session key Kh.
[0087] Step S5: Encryption and decryption of downlink data.
[0088] Step S5.1: The main control board of edge device C sends a downlink plaintext data Data to the local communication bin;
[0089] Step S5.2: The local communication bin of edge device C encrypts the downlink plaintext data Data with the session key Kh;
[0090] Step S5.3: The end device S decrypts the encrypted data Kh(Data) to obtain the downlink plaintext data Data.
[0091] Step S6: Encryption and decryption of uplink data.
[0092] Step S6.1: The end device S encrypts the uplink plaintext data Data with the session key Kh;
[0093] Step S6.2: The local communication bin of edge device C decrypts the encrypted data Kh(Data) with the session key Kh to obtain the uplink plaintext data Data;
[0094] Step S6.3: The local communication bin of edge device C sends the uplink plaintext data Data to the main control board of edge device C.
[0095] Step S7: Key update.
[0096] To ensure communication security, the session key needs to be updated regularly. The end device S sends a request to update the session key to the edge device C. The local communication bin of the edge device C regenerates a new set of session keys Kh', encrypts the new session key Kh' with the current session key Kh and transmits it to the end device S. The end device S decrypts the encrypted data Kh(Kh') with the current session key Kh to obtain the new session key Kh'.
[0097] Specifically, an embodiment of the present invention also provides a method for calculating the protection key Ks.
[0098] The quantum key management platform generates two sets of correlated quantum keys of length N, denoted as U and V, U = [u1, u2, …, u N , V = [v1, v2, …, v N . To ensure key security, improve the utilization efficiency of quantum keys, and enhance economy, in the following way
[0099] Randomly generate a set of keys of length 2N [r1, r2, …, r N , r N+1 , r N+2 , …, r 2N . The first half is inserted into U at intervals, and the second half is inserted into V at intervals, so as to obtain the protection keys KS and Kc of length 2N.
[0100] Ks = [u1, r1, u2, r2, …, u N , r N , Kc = [v1, r N+1 , v2, r N+2 , …, v N , r 2N
[0101] The generated secret keys above are distributed to the end device S and the edge device C in an offline injection manner.
[0102] In the power distribution area, each device has a unique identification code (such as MAC code, unified power distribution area identification code, etc.). The end device constructs the dispersion factor as follows:
[0103] First, obtain the unique identification codes of this device and the device to communicate with in the system. Denote the end device as As and the edge device as Ac.
[0104] As = [s1, s2, …, s M , Ac = [c1, c2, …, c M
[0105] For the end device As, use the quantum key U to encrypt (As, Ac) to form a new encrypted sequence [s'1, s'2, …, s' M , c'1, c'2, …, c' M . Determine the quantum key V according to the quantum key U, and use this key to encrypt the random sequence [r1, r2, …, r N to obtain [r'1, r'2, …, r' N .
[0106] Transmit the sequence [s'1, s'2, …, s' M , c'1, c'2, …, c' M , r'1, r'2, …, r' N to the edge device C through the established channel, and the edge device C analyzes the above data.
[0107] First, take the first 2M values [s'1, s'2, …, s' M , c'1, c'2, …, c' M , determine the quantum key U of the edge device C through the quantum key V, and then decrypt it to obtain the unique identification codes As = [s1, s2, …, s M , Ac = [c1, c2, …, c M , and then compare with the unique identification codes in the system. If they are the same, it means the data is secure and not tampered with. Similarly, [r'1, r'2, …, r' N can be decrypted to obtain [r1, r2, …, rN , then merge the quantum key U and the random sequence [r'1, r'2, …, r' N to obtain Ks = [u1, r1, u2, r2, …, u N , r N .
[0108] In the description of the present invention, it should be noted that, unless otherwise clearly specified and limited, the terms "connected" and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0109] In the description of the present invention, unless otherwise stated, the orientation or positional relationship indicated by the terms "upper", "lower", "left", "right", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention.
[0110] Finally, it should be noted that the above technical solution is only one implementation manner of the present invention. For those skilled in the art, on the basis of the application methods and principles disclosed in the present invention, various types of improvements or deformations can be easily made, and it is not limited to the methods described in the above specific implementation manners of the present invention. Therefore, the above-described manner is only preferred and does not have a restrictive meaning.
Claims
1. A method for realizing efficient distribution of substation area keys and data encryption based on quantum communication technology, characterized in that: Step S1: The quantum key management platform injects the quantum protection key Kc and certificate into the local communication warehouse of edge device C, and the quantum key management platform injects the quantum protection key Ks and certificate into end device S; The quantum key management platform generates quantum keys and certificates, and transmits the protection key Kc and certificate to the local communication warehouse of the edge device C through offline injection, and transmits the protection key Ks and certificate to the end device S; Step S2: The end device S authenticates its identity to the local communication warehouse of the edge device C; Step S3: The local communication warehouse of the edge device C authenticates its identity to the end device S; Step S4: The local communication warehouse of the edge device C generates a session key Kh; Step S5: Encryption and decryption of downlink data; Step S6: Encryption and decryption of uplink data; Step S7: Session key update; Step S2 further includes: The end device S sends its network access certificate to the local communication warehouse of the edge device C, the local communication warehouse of the edge device C authenticates its certificate, and sends the authentication result to the end device S; Step S3 further includes: The local communication warehouse of the edge device C sends its network access certificate to the end device S, the end device S authenticates its certificate, and sends the authentication result to the local communication warehouse of the edge device C; After the steps S2 and S3, a communication connection through authentication is established between the local communication warehouse of the edge device C and the end device S; The step S4 further includes: Step S4.1: The end device S transmits the dispersion factor to the local communication warehouse of the edge device C through the established channel; Step S4.2: The local communication warehouse of the edge device C calculates the protection key Ks of the end device by using the quantum protection key Kc and the dispersion factor; Step S4.3: According to the key composition requirements, randomly generate a group of session keys Kh; and encrypt the session keys by using the protection key Ks to obtain the encrypted session key Ks(Kh); Step S4.4: Through the established channel, the local communication warehouse of the edge device C transmits the encrypted session key Ks(Kh) to the end device S; Step S4.5: The end device S receives the encrypted session key Ks(Kh), decrypts it, and obtains the session key Kh; The step S7 further includes: The end device S sends a request to the edge device C to update the session key. The local communication warehouse of the edge device C regenerates a new group of session keys Kh', encrypts the new session keys Kh' by using the session key Kh and transmits them to the end device. The end device decrypts the encrypted data Kh(Kh') by using the session key Kh to obtain the new session key Kh'; The specific calculation method of the protection key Ks is as follows, The quantum key management platform generates two sets of correlated quantum keys of length N, denoted as U and V. , ; Randomly generate a set of keys of length 2N , insert the first half at intervals into U, and insert the second half at intervals into V, so as to obtain the protection keys Ks and Kc of length 2N; , ; The generated keys above are distributed to the end device S and the edge device C in an offline injection manner; The specific calculation method of the protection key Ks further includes: In the substation area, each device has a unique identification code. The construction dispersion factor of the terminal device is as follows: Obtain the unique identification codes of this device and the device to communicate with in the system. Denote the unique identification code of the terminal device as As and the unique identification code of the edge device as Ac; , ; For the unique identification code As of the terminal device, the quantum key U is used to encrypt (As, Ac) to form a new encrypted sequence ; Determine a quantum key V based on the quantum key U, and encrypt the random sequence using the quantum key V to obtain ; Transmit the sequence to the edge device C through the established channel for parsing the above data; The specific calculation method of the protection key Ks further includes: Take the first 2M values , determine the quantum key U of the edge device C through the quantum key V, and then decrypt it to obtain , , and then compare it with the unique identification code in the system. If they are consistent, it means that the data is secure and not tampered with; Decrypt to obtain , then merge the quantum key U and the random sequence to get .
2. The method according to claim 1, characterized in that, The step S5 further includes: Step S5.1: The main control board of the edge device C sends a downlink plaintext data Data to the local communication bin of the edge device C; Step S5.2: The local communication bin of the edge device C encrypts the downlink plaintext data Data with the session key Kh; Step S5.3: The terminal device decrypts the encrypted data Kh(Data) to obtain the downlink plaintext data Data; The step S6 further includes: Step S6.1: The terminal device encrypts the uplink plaintext data Data with the session key Kh; Step S6.2: The local communication bin of the edge device C decrypts the encrypted data Kh(Data) with the session key Kh to obtain the uplink plaintext data Data; Step S6.3: The local communication bin of the edge device C sends the uplink plaintext data Data to the main control board of the edge device C.
Citation Information
Patent Citations
5G virtual quotient key library distribution method based on quantum security
CN114040390A
Session key negotiation method, device and equipment
CN116132043A
Quantum encryption communication method and system applied to low-voltage transformer area
CN117353905A