A quantum-encrypted communication method for low-voltage distribution areas based on a quantum-secure service platform
The quantum-encrypted communication method of the quantum security service platform solves the problems of poor communication security and low key utilization efficiency in low-voltage distribution areas, realizes efficient and secure quantum-encrypted communication, and improves the communication security and efficiency of low-voltage distribution areas.
Patent Information
- Application Number
- CN202411761791.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-03
AI Technical Summary
Low-voltage distribution areas suffer from poor communication security and low key utilization efficiency, making them unable to effectively address the potential threats posed by quantum computers.
A low-voltage distribution area quantum encryption communication method based on a quantum security service platform is adopted. Quantum keys are generated and distributed through a quantum key management platform, and quantum encryption is used for identity authentication and data transmission to ensure the identity security of both parties in communication. Session keys are generated through quantum random numbers for encrypted communication.
It improves the communication security of low-voltage distribution areas, ensures the identity security of both communicating parties, improves the efficiency of key usage, reduces communication costs, and enhances communication efficiency.
Smart Images

Figure CN119544214B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to communication technology, specifically, to a low-voltage quantum encrypted communication method based on a quantum-secure service platform, which aims to improve the security, efficiency, and reliability of data transmission. Background Technology
[0002] With the rapid development of information technology, communication security has become an urgent issue. Traditional encryption methods such as RSA and AES are proving inadequate in the face of the potential threats posed by quantum computers. Quantum communication technology, with its unique non-cloning, unpredictability, and high security, offers a new solution for communication security. This is especially true in inter-station communication, where higher demands are placed on key distribution and data encryption. Summary of the Invention
[0003] The present invention aims to solve the problems of poor communication security and low key utilization efficiency in the existing technology for low-voltage distribution areas, and provides a quantum encrypted communication method for low-voltage distribution areas based on a quantum security service platform.
[0004] To achieve the above objectives, the present invention provides a low-voltage substation quantum encrypted communication method based on a quantum-secure service platform, comprising:
[0005] Step S1: The local communication warehouse of edge device C sends network access authentication data to the main control board. The main control board sends the data to the remote communication warehouse of edge device C, and then the remote communication warehouse of device C sends the network access authentication data to the quantum security service engine of the power distribution master station F. After authentication, the quantum security service engine sends the authentication result to the remote communication warehouse of edge device C, and then through the main control board, it sends it to the local communication warehouse of edge device C.
[0006] Step S2: The terminal device S performs network access authentication;
[0007] Step S3: The side device C obtains the initial key K;
[0008] Step S4: The terminal device S obtains the initial key K;
[0009] Step S5: Session key distribution is performed between the edge device C and the end device S;
[0010] Step S6: The edge device C sends downlink data to the end device S;
[0011] Step S7: The end device S sends uplink data to the side device C;
[0012] Step S8: Update the session key.
[0013] Preferably, the end device S needs to send the data to the local communication warehouse of the edge device C, and then send it to the quantum security service engine of the power distribution master station F step by step; the authentication result is sent from the local communication warehouse of the edge device C to the end device S.
[0014] Preferably, after authentication, the edge device C requests a key from the quantum security service engine. The request data is first sent to the main control board, then to the remote communication warehouse, and then transferred to the quantum security service engine of the power distribution master station F.
[0015] After receiving the request to obtain the initial key, the engine generates an initial key K and encrypts it using the protection key Kc. The encrypted data Kc(K) is then sent to the remote communication warehouse of the edge device C, then to the main control board, and finally sent to the local communication warehouse by the main control board.
[0016] The local communication module of the edge device C decrypts the data Kc(K) according to the injected protection key Kc to obtain the initial key K.
[0017] Preferably, the terminal device S sends the initial key request to the quantum security service engine of the power distribution master station F through the local communication warehouse of the terminal device S.
[0018] After receiving the application data, the engine generates an initial key K and encrypts it using a protection key Ks. The encrypted data Ks(K) is then sent level by level until it reaches the terminal device S.
[0019] The terminal device S decrypts the data Ks(K) according to the injected protection key Ks to obtain the initial key K.
[0020] Preferably, the end device S sends a session key request to the local communication warehouse of the edge device C. The local communication warehouse generates a session key Kh using a quantum random number chip, then encrypts it using an initial key K, and sends the encrypted session key K(Kh) to the end device S. The end device S decrypts the encrypted session key Kh to obtain the session key Kh.
[0021] Preferably, the service data Data generated by the main control board of the edge device C is sent to the local communication warehouse of the edge device C, and then the data is encrypted. The local communication warehouse of the edge device C sends the encrypted data Kh(Data) to the end device S. The end device S decrypts the data Kh(Data) based on the session key Kh to obtain the data Data.
[0022] Preferably, the data Data of the terminal device S is encrypted and sent to the local communication warehouse of the edge device C. The data is decrypted in the local communication warehouse of the edge device C to obtain the service data Data, and then the service data Data is sent to the main control board of the edge device C.
[0023] Preferably, the end device S requests the edge device C to update the session key. The edge device C generates a new session key Kh', encrypts the new session key Kh' using the current session key Kh, and transmits it to the end device S. The end device S decrypts the encrypted data Kh (Kh') using the current session key Kh to obtain the new session key Kh'.
[0024] Preferably, when the amount of encrypted output data reaches the threshold F_data, or when the session key usage time reaches T_limit, the end device S sends an update key request to the side device C. The side device C uses a quantum random number generation chip to regenerate the session key and transmits it to the end device S in encrypted form.
[0025] Preferably, the present invention further includes an identity authentication and initial key distribution method for a quantum security service platform:
[0026] Step S81: Identity authentication method;
[0027] The quantum key management platform generates two sets of associated quantum keys of length 2N, denoted as Ks and Kc.
[0028] Ks=[u1,u2,…,u N ,…,u 2N-1 ,u 2N ],Kc=[v1,v2,…,v N ,…,v 2N-1 ,v 2N ]
[0029] The generated key is distributed to the terminal device S and the edge device C using an offline injection method;
[0030] In the distribution area, each device has a unique identifier. The system retrieves the unique identifiers of its own device and the device to be communicated with. The end device is denoted as As, and the edge device as Ac; As = [s1, s2, ..., s...]. M Ac = [c1, c2, ..., c M ];
[0031] The edge device C uses a portion of the quantum key, Kc′, to encrypt the device's unique identifier Ac, where Kc′ = [v1, v3, ..., v 2N-3 ,v 2N-1The encrypted edge device C has a unique identifier Ac. * =Kc′(Ac), Kc′(·) means encryption is performed using the key Kc′;
[0032] Calculate Ac * hash value The unique identifier Ac of the edge device C and the hash value H(Ac) * ) merge, to obtain Then it is sent layer by layer to the quantum security service engine;
[0033] After receiving the data, the quantum security service engine parses out the unique identifier Ac. *re and hash value H(Ac) * ) re According to the protection key Kc=[v1,v2,…,v N ,…,v 2N-1 ,v 2N ], obtain the encryption key Kc′, calculate the hash value of the unique identifier Ac*re, and compare this hash value with the received H(Ac * ) re If they match, authentication is successful, and the unique identifier Ac will be sent. *re Using Kc″=[v2,v4,…,v 2N-2 ,v 2N Encrypt the data and calculate the hash value of the encrypted result. As the authentication result, it is sent to the edge device C layer by layer. After receiving the data, the edge device compares it with the hash value of the encryption result calculated locally using the key Kc″. If they match, it means that the authentication is successful and communication can proceed.
[0034] Step S82: Initial key distribution method;
[0035] The quantum security service engine generates T sets of random keys K0 of length P.
[0036]
[0037] Select an initial key K from the random key K0, where K = [k1, k2, ..., k T ], where ki is from [k i1 ,k i2 ,…,k iP Select [k] and calculate it as follows: i1 ,k i2 ,…,k iP The binary value of ], i.e., Val([k i1 ,k i2 ,…,k iP Then calculate the remainder e by dividing the value by the key length P.i =mod(Val([k i1 ,k i2 ,…,k iP If k = ]), P), then k i =k i,ei+1 We obtain an initial key K of length T, K = [k1, k2, ..., k T ];
[0038] Using Ks = [u1, u2, ..., u N ,…,u 2N-1 ,u 2N ],Kc=[v1,v2,…,v N ,…,v 2N-1 ,v 2N Encrypt the key K to obtain Ks(K) and Kc(K) respectively. Send KsK() to the end device layer by layer, and send Kc(K) to the edge device.
[0039] Compared with the prior art, the beneficial effects of the present invention are:
[0040] 1) Employing quantum encryption effectively enhances communication security in low-voltage distribution areas;
[0041] 2) Employ a verification method based on unique identity identifiers and encrypted data hash values to ensure the security of the identities of both communicating parties;
[0042] 3) Based on the protection key and the initial key, it can effectively solve the problem of low efficiency in the use of quantum keys in quantum communication, reduce communication costs, and improve communication efficiency. Attached Figure Description
[0043] Figure 1 This invention provides a security protection scheme for low-voltage distribution network services based on quantum encryption.
[0044] Figure 2 This is a flowchart of the edge-to-end quantum key session key distribution and business data transmission process of the present invention. Detailed Implementation
[0045] The present invention will now be described in further detail with reference to the accompanying drawings:
[0046] To better understand the present invention, the embodiments of the present invention will be explained in detail below with reference to the accompanying drawings.
[0047] The present invention provides an embodiment 1 that discloses the relevant structure of the quantum encryption device of the present invention.
[0048] The structure of a quantum encrypted communication system is disclosed in Example 1.
[0049] This invention is based on quantum key technology. It constructs a quantum secure encryption channel between the edge and the end by deploying a quantum key distribution system (QKD), a quantum exchange cryptography machine, and a quantum security service engine on the master station side of the low-voltage distribution area of the power distribution network, integrating quantum security chips in the local communication compartments of edge devices such as power distribution terminals and converged terminals, and integrating security chips (when the devices are embedded) or external security modules (when the devices are external) in end devices such as smart circuit breakers, photovoltaic grid-connected circuit breakers, and LTUs.
[0050] The specific implementation approach is as follows.
[0051] This encrypted communication system includes end nodes, edge nodes, network management communication, and cloud center nodes. Encrypted communication between edge nodes and end nodes in low-voltage distribution areas is achieved through system integration or by adding external security chips.
[0052] (1) Cloud side: The cloud side is the main distribution station of the low-voltage distribution area, which deploys a quantum key distribution system (QKD), a cryptographic exchange machine, and a quantum security service engine to generate quantum session keys (hereinafter referred to as "session keys"). It also has a distribution encryption and authentication device to realize encryption authentication between edge devices and end devices. The session keys and authentication information are transmitted through a secure access server via a communication network.
[0053] (2) Edge-side: The edge-side refers to the distribution terminals in the low-voltage distribution area, such as distribution terminals and converged terminals. Edge equipment includes a remote communication compartment, a local communication compartment, and a main control board. The quantum security chip is deployed in the local communication compartment. The remote communication compartment is mainly used for encrypted communication with the cloud via the communication network, while the local communication compartment is mainly used for encrypted communication with end equipment. The main control board is the center for generating and processing distribution business data. A security chip with a built-in quantum random number generator is deployed in the local communication compartment of the edge equipment, and the session key is encrypted and distributed using a quantum protection key (hereinafter referred to as the "protection key").
[0054] (3) End-side: The end-side refers to the power consumption / generation equipment in the low-voltage distribution area. Security chips are deployed in the end-side equipment, or external security modules with embedded security chips are connected. Security chips are mainly embedded in the end-side equipment, physically integrated with it, and can also be used in external end-side equipment that supports hardware modifications. Security modules are mainly used in external end-side equipment, providing security services through embedded tail modules, external security isolation devices, etc. Quantum key encryption is used to protect the transmission of edge-to-end business data.
[0055] The encrypted communication implementation process of the present invention is disclosed in Embodiment 2 of the present invention, as shown in the appendix. Figure 2 As shown.
[0056] The initial key between the edge and the terminal is uniformly generated and distributed by the quantum security service platform. The session key between the edge and the terminal is generated by the quantum random number built into the edge-side security chip and distributed to the terminal device. The edge device is responsible for maintaining and managing the session key of the terminal device. The edge device is denoted as C, the terminal device as S, and the power distribution master station as F. The quantum-encrypted secure communication method between devices C and S is described below:
[0057] It is understood that edge device C includes a main control board, a local communication module, and a remote communication module. The power distribution master station's quantum security service engine generates quantum protection keys Kc and Ks, and offline charges edge device C (the edge device's local communication module) and end device S.
[0058] Step S1: Edge device C network access authentication.
[0059] Edge device C's local communication warehouse sends network access authentication data to the main control board. The main control board then sends the data to the remote communication warehouse, which in turn sends the network access authentication data to the quantum security service engine of the power distribution master station F. After authentication, the quantum security service engine sends the authentication result to the edge device's remote communication warehouse, then through the main control board, and finally to the local communication warehouse.
[0060] Step S2: End device S network access authentication.
[0061] The network access authentication process for end device S is similar to that for edge devices. The difference lies in the additional step in the communication link. The end device first needs to send data to the local communication warehouse of the edge device, and then send it step by step to the quantum security service engine of the power distribution master station F. Similarly, the authentication result is also sent from the local communication warehouse of the edge device to the end device S.
[0062] Step S3: Side device C obtains the initial key K.
[0063] After successful authentication, edge device C requests a key from the quantum security service engine. The request data is first sent to the main control board, then to the remote communication warehouse, and finally to the quantum security service engine of the power distribution master station F. Upon receiving the request for the initial key, the engine generates an initial key K and encrypts it using a protection key Kc. The encrypted data Kc(K) is then sent to the edge device's remote communication warehouse, then to the main control board, and finally to the local communication warehouse. The edge device's local communication warehouse decrypts the data Kc(K) using the injected protection key Kc to obtain the initial key K.
[0064] Step S4: The end device obtains the initial key K.
[0065] The process by which the terminal device obtains the initial key K is similar to that of its local storage. The difference lies in the additional link in the communication chain: the terminal device S sends its initial key request through its local communication storage to the quantum security service engine of the power distribution master station F. Upon receiving the request data, the engine generates the initial key K and encrypts it using the protection key Ks. It then sends the encrypted data Ks(K) through each level until it reaches the terminal device S. The terminal device S decrypts the data Ks(K) using the injected protection key Ks to obtain the initial key K.
[0066] Step S5: Distribution of session keys between edge devices.
[0067] End device S sends a session key request to the local communication warehouse of edge device C. The local communication warehouse generates a session key Kh using a quantum random number chip, then encrypts it using the initial key K, and sends the encrypted session key K(Kh) to end device S. End device decrypts the encrypted session key Kh to obtain the session key Kh.
[0068] Step S6: Side device C sends downlink data to end device S.
[0069] The business data Data generated by the main control board of edge device C is sent to the local communication warehouse, where it is then encrypted. The local communication warehouse sends the encrypted data Kh(Data) to the end device S. End device S decrypts the data Kh(Data) based on the session key Kh to obtain the data Data.
[0070] Step S7: End device S sends uplink data to edge device C.
[0071] This step is the reverse of step 6. After the data Data from the end device S is encrypted, it is sent to the local communication warehouse of the edge device. The data is decrypted in the local communication warehouse to obtain the business data Data, and then the business data Data is sent to the main control board of the edge device.
[0072] Step S8: Session key update.
[0073] To ensure communication security, the session key needs to be updated periodically. End device S sends a session key update request to edge device C. The edge device generates a new session key Kh', encrypts the new session key Kh' using the current session key Kh, and transmits it to the end device. The end device decrypts the encrypted data Kh(Kh') using the current session key Kh to obtain the new session key Kh'.
[0074] Specifically, in Embodiment 3 of the present invention, an identity authentication and initial key distribution method based on a quantum security service platform is also provided.
[0075] Step S81: Identity authentication method.
[0076] The quantum key management platform generates two sets of associated quantum keys of length 2N, denoted as Ks and Kc.
[0077] Ks=[u1,u2,…,u N ,…,u 2N-1 ,u 2N ],Kc=[v1,v2,…,v N ,…,v 2N-1 ,v 2N ]
[0078] The generated key is distributed to end device S and edge device C using an offline injection method.
[0079] Within a distribution area, each device has a unique identifier (such as a MAC address, a unified distribution area identifier, etc.). First, the system retrieves the unique identifiers of both the current device and the device to be communicated with. Let the end device be denoted as As, and the side device as Ac. As = [s1, s2, ..., s...]. M Ac = [c1, c2, ..., c M ].
[0080] Edge device C uses a portion of the quantum key, Kc′, to encrypt its unique identifier Ac, where Kc′ = [v1, v3, ..., v 2N-3 ,v 2N-1 The encrypted edge device C unique identifier.
[0081] Ac * =Kc′(Ac)
[0082] Here, Kc′(·) represents encryption using the key Kc′. Then, calculate Ac. * hash value
[0083]
[0084] The unique identifier Ac of the edge device C and the hash value H(Ac) * ) merge, to obtain Then it is sent layer by layer to the quantum security service engine.
[0085] After receiving the data, the quantum security service engine parses out the unique identifier Ac. *re and hash value H(Ac) * ) re Then, based on the protection key Kc = [v1, v2, ..., v N ,…,v 2N-1 ,v 2N ], obtain the encryption key Kc′, and then calculate the unique identifier Ac *re The hash value is compared with the received H(Ac) hash value.* ) re If they match, authentication is successful, and the unique identifier Ac will be sent. *re Using Kc″=[v2,v4,…,v 2N-2 ,v 2N Encrypt the data and calculate the hash value of the encrypted result. As the authentication result, it is then sent layer by layer to the edge device C. After receiving the data, the edge device compares it with the hash value of the encryption result calculated locally using the key Kc″. If they match, it means that the authentication is successful and communication can proceed.
[0086] The device authentication method for end device S is the same as that for edge device C.
[0087] Step S82: Initial key distribution method.
[0088] The quantum security service engine generates T sets of random keys K0 of length P.
[0089]
[0090] Select an initial key K from the random key K0, where K = [k1, k2, ..., k T ].
[0091] Where ki is from [k i1 ,k i2 ,…,k iP Select the appropriate option and calculate it as follows.
[0092] Calculate [k] i1 ,k i2 ,…,k iP The binary value of ], i.e., Val([k i1 ,k i2 ,…,k iP Then calculate the remainder by dividing the value by the key length P.
[0093] e i =mod(Val([k i1 ,k i2 ,…,k iP ]),P)
[0094] Then k i =k i,ei+1 Thus, we obtain an initial key K of length T, K = [k1, k2, ..., k T ].
[0095] Then, using Ks = [u1, u2, ..., u N ,…,u 2N-1 ,u 2N ],Kc=[v1,v2,…,vN ,…,v 2N-1 ,v 2N The key K is encrypted to obtain Ks(K) and Kc(K) respectively. Then Ks(K) is sent to the end device layer by layer, and Kc(K) is sent to the edge device.
[0096] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "connected" and "linked" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0097] In the description of this invention, unless otherwise stated, the terms "upper," "lower," "left," "right," "inner," "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.
[0098] Finally, it should be noted that the above technical solution is only one embodiment of the present invention. For those skilled in the art, based on the application methods and principles disclosed in the present invention, it is easy to make various types of improvements or modifications, and not limited to the methods described in the above specific embodiments of the present invention. Therefore, the methods described above are only preferred and have no limiting significance.
Claims
1. A low-voltage substation quantum-encrypted communication based on a quantum-secure service platform, characterized in that: Step S1: The local communication warehouse of edge device C sends network access authentication data to the main control board. The main control board sends the data to the remote communication warehouse of edge device C, and then the remote communication warehouse of edge device C sends the network access authentication data to the quantum security service engine of the power distribution master station F. After the quantum security service engine authenticates, it sends the authentication result to the remote communication warehouse of the edge device C, and then through the main control board, it sends it to the local communication warehouse of the edge device C. Step S2: Terminal device S performs network access authentication; Step S2 further includes: The terminal device S needs to send data to the local communication warehouse of the edge device C, and then send it level by level to the quantum security service engine of the power distribution master station F; the authentication result is sent from the local communication warehouse of the edge device C to the terminal device S; Step S3: The side device C obtains the initial key K; Step S3 further includes: After authentication, the edge device C requests a key from the quantum security service engine. The request data is first sent to the main control board, then to the remote communication warehouse, and then transferred to the quantum security service engine of the power distribution master station F. After receiving the request to obtain the initial key, the engine generates an initial key K and encrypts it using the protection key Kc. The encrypted data Kc(K) is then sent to the remote communication warehouse of the edge device C, then to the main control board, and finally sent to the local communication warehouse by the main control board. The local communication module of the edge device C decrypts the data Kc(K) according to the injected protection key Kc to obtain the initial key; Step S4: The terminal device S obtains the initial key K; Step S5: Session key distribution is performed between the edge device C and the end device S; Step S6: The edge device C sends downlink data to the end device S; Step S7: The end device S sends uplink data to the side device C; Step S8: Update the session key; The method for updating the session key includes: The end device S sends a request to the side device C to update the session key. The side device C generates a new session key Kh', encrypts the new session key Kh' using the current session key Kh, and transmits it to the end device S. The end device S decrypts the encrypted data Kh (Kh') using the current session key Kh to obtain the new session key Kh'. The regular update mechanism includes: When the amount of encrypted output data reaches the threshold F_data, or when the session key usage time reaches T_limit, the end device S sends an update key request to the side device C. The side device C uses a quantum random number generation chip to regenerate the session key and transmits it to the end device S in encrypted form. The method further includes an authentication and initial key distribution method for the quantum security service platform: Step S81: Identity authentication method; The quantum key management platform generates two sets of associated quantum keys of length 2N, denoted as Ks and Kc. , ; The generated key is distributed to the terminal device S and the edge device C using an offline injection method; In the distribution area, each device has a unique identifier. The system retrieves the unique identifiers of the device itself and the device to be communicated with. Let the identifier of the terminal device S be As, and the identifier of the side device C be Ac. , ; The side device C utilizes partial information from the quantum key. The device's unique identifier Ac is encrypted, where = The encrypted edge device C unique identifier , Indicates the use of a key Encrypt; calculate hash value The unique identifier Ac of the edge device C and its hash value Merge, and obtain Then it is sent layer by layer to the quantum security service engine; After receiving the data, the quantum security service engine parses out the unique identifier. and hash value According to the protection key Obtain the encryption key Calculate the unique identifier code The hash value is compared with the received hash value. If they match, authentication is successful, and a unique identifier will be assigned. use = Encrypt the data and calculate the hash value of the encrypted result. As the authentication result, it is sent layer by layer to edge device C. After receiving the data, edge device C uses the local key... The hash values of the encrypted results are calculated and compared. If they match, the authentication is successful and communication can proceed. Step S82: Initial key distribution method; The quantum security service engine generates T sets of random keys K0 of length P. , Select the initial key K from the random key K0. , where ki comes from Select and calculate as follows: The binary value, i.e. Then calculate the remainder by dividing the value by the key length P. ,but ; Obtain an initial key K of length T, ; use , Encrypt the key K separately to obtain and ,Will Send to end device S layer by layer. Send to the edge device.
2. The method according to claim 1, characterized in that, Step S4 further includes: The terminal device S will send the initial key request to the quantum security service engine of the power distribution master station F through the local communication warehouse of the terminal device S. After receiving the application data, the engine generates an initial key K and encrypts it using a protection key Ks. The encrypted data Ks(K) is then sent level by level until it reaches the terminal device S. The terminal device S decrypts the data Ks(K) according to the injected protection key Ks to obtain the initial key K.
3. The method according to claim 2, characterized in that, Step S5 further includes: The end device S sends a session key request to the local communication warehouse of the edge device C. The local communication warehouse generates a session key Kh using a quantum random number chip, then encrypts it using an initial key K, and sends the encrypted session key K (Kh) to the end device S. The end device S decrypts the encrypted session key Kh to obtain the session key Kh.
4. The method according to claim 3, characterized in that, Step S6 further includes: The service data Data generated by the main control board of the edge device C is sent to the local communication warehouse of the edge device C, and then the data is encrypted. The local communication warehouse of the edge device C sends the encrypted data Kh (Data) to the end device S. The end device S decrypts the data Kh (Data) based on the session key Kh to obtain the data Data.
5. The method according to claim 4, characterized in that, Step S7 further includes: After the data Data of the terminal device S is encrypted, it is sent to the local communication warehouse of the edge device C. The data is decrypted in the local communication warehouse of the edge device C to obtain the service data Data, and then the service data Data is sent to the main control board of the edge device C.
Citation Information
Patent Citations
Quantum encryption communication method and system applied to low-voltage transformer area
CN117353905A
Service security protection system and method for power secondary system
CN118764200A
Quantum encryption communication method based on court side end autonomy
CN118869209A