Power grid operator security authentication method and system based on quantum communication
Through the power grid operator security authentication method based on quantum communication, quantum entanglement and bait state technology are used to solve the problems of vulnerable attacks and high computing resources in the prior art, and high security and efficient key management are achieved.
Patent Information
- Application Number
- CN202411990549.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-12-31
AI Technical Summary
Existing power grid operator security certification technology is susceptible to impersonation attacks and replay attacks, and cannot provide sufficient protection when facing advanced persistent threats APT, and there is also the problem of high demand for computing resources.
The grid operator safety authentication method based on quantum communication is adopted. By generating Bell state sequences, introducing bait particles, quantum channel transmission, bait state detection and replacement operations are performed, combining Pauli operation and Bell measurements, and the measurement results are exchanged using classic communication channels to verify identity.
It significantly enhances the security of power grid communications, effectively prevents advanced persistent threats APT and other potential security risks, has the ability to efficiently manage keys and adapt to resource-constrained devices, and simplifies the operation process.
Smart Images

Figure CN119995848A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum security authentication technology, and in particular to a method and system for security authentication of power grid operators based on quantum communication. Background Art
[0002] In power grid operation, security authentication of power grid operators is a key link to ensure safe and stable operation of power systems. With the rapid development of smart grid technology, power grid systems are becoming increasingly complex and intelligent, and the importance of operator authority management and identity authentication has also increased significantly. Current power grid operator security authentication technologies are mainly focused on cryptographic methods, physical feature authentication, and edge computing. In terms of cryptographic methods, elliptic curve cryptography (ECC) has become one of the mainstream technologies for power grid security authentication due to its shorter key length and higher security. ECC can achieve efficient identity authentication and key negotiation under limited computing resources. At the same time, the introduction of physical unclonable function (PUF) technology significantly enhances the security and non-replicability of the authentication protocol by utilizing the inherent physical properties of hardware to generate unique authentication fingerprints. In the smart grid environment, the application of edge computing technology makes lightweight authentication possible, effectively reducing the computing burden of terminal devices.
[0003] However, existing technologies still face many challenges: First, during the identity authentication process, traditional authentication methods are vulnerable to impersonation attacks, where attackers may intercept the authentication information of legitimate users to impersonate their identities; second, replay attacks are also a prominent problem, where attackers can reuse previously intercepted valid authentication information. What is more serious is that in the face of increasingly complex advanced persistent threats (APTs), existing authentication mechanisms often cannot provide comprehensive and lasting protection. Such attacks are highly concealed and last for a long time, which may lead to serious security incidents; in addition, existing authentication methods generally have the problem of high computing resource requirements. In actual applications, many power grid terminal devices have limitations in computing power and storage space, and complex authentication algorithms may cause device response delays, affecting the real-time control and supervision of the power grid. Summary of the invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the problem to be solved by the present invention is how to provide a method for secure authentication of power grid operators based on quantum communication, which overcomes the fact that existing authentication methods are vulnerable to impersonation attacks and replay attacks, and may not provide sufficient protection when facing advanced persistent threats (APTs).
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, an embodiment of the present invention provides a method for secure authentication of power grid operators based on quantum communication, which includes a power grid control center and a power grid operator generating a Bell state sequence according to a binary key sequence and dividing it to obtain a first sequence and a second sequence; introducing decoy particles into the first sequence to form an extended first sequence and transmitting it through a quantum channel; the security center performs decoy state detection, permutation operation and introduction of decoy states on the extended first sequence to generate a new first sequence and transmit it; the power grid control center and the power grid operator remove the decoy states from the new first sequence and restore it to the first sequence; perform Pauli operation and Bell measurement on the second sequence to obtain measurement results; exchange measurement results using classical communication channels, verify identity, and achieve secure authentication of power grid operators.
[0008] As a preferred solution of the quantum communication-based power grid operator security authentication method of the present invention, wherein: the generation of the Bell state sequence refers to the power grid control center and the power grid operator generating the Bell state sequence S respectively according to the shared binary key sequence A and Bell state sequence S B .
[0009] As a preferred solution of the method for secure authentication of power grid operators based on quantum communication described in the present invention, wherein: the Bell state sequence S is generated A and Bell state sequence S B Including: If k m =00 and k m =01, then the Bell state sequence S A The calculation formula is as follows:
[0010] S A =|Φ + >
[0011] S A ={|Ψ A1 >,|Ψ A2 >,|Ψ A3 >,...,|Ψ A2n >}
[0012]
[0013] Among them, k m is the mth key value in the binary key sequence, m = 1, 2, ..., 2n, where 2n is the total number of elements in the key sequence; S A is the Bell state sequence; Ai is the Bell state generated by the grid control center using the i-th key in the binary key sequence; if k m =01 and k m=10, then the Bell state sequence S B The calculation formula is as follows:
[0014] S B =|Φ - >
[0015] S B ={|Ψ B1 >,|Ψ B2 >,|Ψ B3 >,...,|Ψ B2n >}
[0016]
[0017] Among them, k m is the mth key value in the binary key sequence, m = 1, 2, ..., 2n, where 2n is the total number of elements in the key sequence; S B is the Bell state sequence; Bi It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
[0018] As a preferred solution of the method for secure authentication of power grid operators based on quantum communication of the present invention, the obtaining of the first sequence and the second sequence comprises: the power grid control center converts the Bell state sequence S A Divided into the first particle sequence S A1 and the first quantum bit sequence S A2 , the specific formula is as follows:
[0019] S A1 ={|Ψ A1 >,|Ψ A3 >,...,|Ψ A(2n-1) >}
[0020] S A2 ={|Ψ A2 >,|Ψ A4 >,...,|Ψ A(2n) >}
[0021] Among them, S A1 is the first particle sequence; S A2 is the first quantum bit sequence; Ψ Ai is the Bell state generated by the grid control center using the ith key in the binary key sequence; the grid operator converts the Bell state sequence S B Divided into the second particle sequence S B1 and the second qubit sequence S B2 , the specific formula is as follows:
[0022] S B1 ={|ΨB1 >,|Ψ B3 >,...,|Ψ B(2n-1) >}
[0023] S B2 ={|Ψ B2 >,|Ψ B4 >,...,|Ψ B(2n) >}
[0024] Among them, S B1 is the second particle sequence; S B2 is the second quantum bit sequence; Bi It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
[0025] As a preferred solution of the method for secure authentication of power grid operators based on quantum communication described in the present invention, wherein: introducing decoy particles into the first sequence to form an extended first sequence means that the power grid control center and the power grid operator respectively introduce decoy particles into the first particle sequence S A1 and the second particle sequence S B1 Introduce decoy particles to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 The bait particles are introduced to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 Refers to the random selection of the bait particle state, in the first particle sequence S A1 and the second particle sequence S B1 Inserting bait particles at random positions in the extended first sequence; performing bait state detection, replacement operation and introduction of bait state on the extended first sequence to generate a new first sequence, including the following steps: the security center receives the extended first particle sequence S' A1 and the extended second particle sequence S' B1 And detect the bait state, if it is correct, extract the first particle sequence S A1 and the second particle sequence S B1 ; For the first particle sequence S extracted A1 and the second particle sequence S B1 Perform the permutation operation and reintroduce the decoy state to generate a new first particle sequence and the new second particle sequence
[0026] As a preferred solution of the method for secure authentication of power grid operators based on quantum communication of the present invention, wherein: removing the decoy state of the new first sequence and restoring it to the first sequence means that the power grid control center and the power grid operator receive the new first particle sequence and the new second particle sequence And remove the bait state and restore to the first particle sequence S A1 and the second particle sequence S B1 The Pauli operation and Bell measurement include the following steps: the power grid control center and the power grid operator use the first quantum bit sequence S A2 and the second qubit sequence S B2 , perform Pauli operation according to the pre-shared key to obtain the quantum bit after the operation; perform Bell measurement on the quantum bit after the operation to obtain the measurement result.
[0027] As a preferred solution of the quantum communication-based power grid operator security authentication method described in the present invention, the method of exchanging measurement results and verifying identity through classical communication channels includes the following steps: the power grid control center and the power grid operator exchange their respective measurement results through classical communication channels, and verify the identities of both parties by comparing the correlation of the measurement results. If the results show an association pattern consistent with the expected pre-shared key, the identity authentication is successful; if the results are inconsistent with expectations, it indicates that there is interference or fraud attempt, and the identity authentication fails.
[0028] In the second aspect, in order to further solve the security problems existing in quantum security authentication, the present invention provides a quantum communication-based power grid operator security authentication system, which includes: a sequence generation module, which is used for the power grid control center and the power grid operator to generate and divide the Bell state sequence according to the binary key sequence to obtain a first particle sequence, a first quantum bit sequence, a second particle sequence, and a second quantum bit sequence; a bait introduction module, which is used to introduce bait particles into the first particle sequence and the second particle sequence to form an extended first particle sequence and an extended second particle sequence; a security center module, which is used to use the security center to receive the extended first particle sequence and the extended second particle sequence and perform bait introduction. Bait state detection, replacement operation and introduction of bait state, generate new first particle sequence and new second particle sequence and send them to the power grid control center and the power grid operator; bait restoration module, used for the power grid control center and the power grid operator to remove the bait state of the new first particle sequence and the new second particle sequence, and restore them to the first particle sequence and the second particle sequence; measurement result module, used for the power grid control center and the power grid operator to use the first quantum bit sequence and the second quantum bit sequence to perform Pauli operation and Bell measurement according to the pre-shared key to obtain the measurement result; security authentication module, used for the power grid control center and the power grid operator to exchange measurement results using classical communication channels and verify the identities of both parties.
[0029] In a third aspect, an embodiment of the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the method for secure authentication of power grid operators based on quantum communication as described in the first aspect of the present invention is implemented.
[0030] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the method for secure authentication of power grid operators based on quantum communication as described in the first aspect of the present invention.
[0031] Beneficial effects of the invention: The power grid operator security authentication method based on quantum communication of the invention greatly enhances the security of power grid communication by utilizing quantum entanglement, decoy state technology and quantum substitution operation. Through this method, the power grid control center and the operator can safely generate and share keys, effectively preventing advanced persistent threats (APT) and other potential security risks; in addition, the invention also has the ability of efficient key management and adaptability to resource-constrained devices, which not only improves the security protection capability of the power grid system, but also simplifies the operation process, and is suitable for integration into the existing power grid security architecture. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them:
[0033] Figure 1 This is an overall flow chart of the power grid operator security authentication method based on quantum communication in Example 1.
[0034] Figure 2 This is a schematic diagram of the structure of the computer device in Example 3. DETAILED DESCRIPTION
[0035] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0036] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0037] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0038] Example 1
[0039] Reference Figure 1 , which is the first embodiment of the present invention, provides a power grid operator security authentication method based on quantum communication.
[0040] The existing identity authentication methods mainly have the following problems: First, during the identity authentication process, traditional authentication methods are prone to impersonation attacks, and attackers may intercept the authentication information of legitimate users to impersonate identities; second, replay attacks are also a prominent problem, and attackers can reuse valid authentication information intercepted before. What is more serious is that in the face of increasingly complex advanced persistent threats (APTs), existing authentication mechanisms often cannot provide comprehensive and lasting protection. Such attacks are highly concealed and last for a long time, which may lead to serious security incidents; in addition, existing authentication methods generally have the problem of high computing resource requirements. In actual applications, many power grid terminal devices have limitations in computing power and storage space, and complex authentication algorithms may cause device response delays, affecting the real-time control and supervision of the power grid.
[0041] The present application provides an effective solution to the above-mentioned problems. Next, a plurality of embodiments will be combined to explain in detail how to implement the quantum communication-based power grid operator security authentication method.
[0042] Figure 1 The overall flow chart of the power grid operator security authentication method based on quantum communication is shown, including:
[0043] S1: The grid control center and the grid operator generate a Bell state sequence according to the binary key sequence and divide it to obtain a first sequence and a second sequence.
[0044] Preferably, generating the Bell state sequence means that the power grid control center and the power grid operator respectively generate the Bell state sequence S according to the shared binary key sequence A and Bell state sequence S B .
[0045] Specifically, generate the Bell state sequence S A and Bell state sequence S B Including: If k m =00 and k m =01, then the Bell state sequence SA The calculation formula is as follows:
[0046] S A =|Φ + >
[0047] S A ={|Ψ A1 >,|Ψ A2 >,|Ψ A3 >,...,|Ψ A2n >}
[0048]
[0049] Among them, k m is the mth key value in the binary key sequence, m = 1, 2, ..., 2n, where 2n is the total number of elements in the key sequence; S A is the Bell state sequence; Ai It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
[0050] If k m =01 and k m =10, then the Bell state sequence S B The calculation formula is as follows:
[0051] S B =|Φ - >
[0052] S B ={|Ψ B1 >,|Ψ B2 >,|Ψ B3 >,...,|Ψ B2n >}
[0053]
[0054] Among them, k m is the mth key value in the binary key sequence, m = 1, 2, ..., 2n, where 2n is the total number of elements in the key sequence; S B is the Bell state sequence; Bi It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
[0055] Further, obtaining the first sequence and the second sequence includes: the power grid control center converts the Bell state sequence S A Divided into the first particle sequence S A1 and the first quantum bit sequence S A2 , the specific formula is as follows:
[0056] SA1 ={|Ψ A1 >,|Ψ A3 >,...,|Ψ A(2n-1) >}
[0057] S A2 ={|Ψ A2 >,|Ψ A4 >,...,|Ψ A(2n) >}
[0058] Among them, S A1 is the first particle sequence; S A2 is the first quantum bit sequence; Ψ Ai It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
[0059] The grid operator converts the Bell state sequence S B Divided into the second particle sequence S B1 and the second qubit sequence S B2 , one sequence contains the first particles of all Bell pairs, and the other contains the second particles. The specific formula is as follows:
[0060] S B1 ={|Ψ B1 >,|Ψ B3 >,...,|Ψ B(2n-1) >}
[0061] S B2 ={|Ψ B2 >,|Ψ B4 >,...,|Ψ B(2n) >}
[0062] Among them, S B1 is the second particle sequence; S B2 is the second quantum bit sequence; Bi It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
[0063] Preferably, the present invention introduces a Bell state generation mechanism based on binary key values, and ensures the certainty and repeatability of quantum state preparation by establishing a strict mathematical correspondence between the binary key sequence and the Bell state; by proposing a scheme for dividing the sequence into a particle sequence and a quantum bit sequence, the effective allocation of quantum entangled pairs is achieved, laying the foundation for subsequent security verification.
[0064] S2: Introduce decoy particles into the first sequence to form an extended first sequence and transmit it through the quantum channel.
[0065] Preferably, introducing decoy particles into the first sequence to form an extended first sequence means that the power grid control center and the power grid operator respectively introduce decoy particles into their respective first particle sequences S A1 and the second particle sequence S B1 Introduce decoy particles to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 .
[0066] Specifically, bait particles are introduced to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 Refers to the random selection of the bait particle state, in the first particle sequence S A1 and the second particle sequence S B1 Insert bait particles at random positions in the
[0067] Preferably, by randomly selecting the state of decoy particles and inserting them at random positions, the difficulty for eavesdroppers to predict the content of the sequence is significantly increased. The introduction of decoy particles provides reliable technical support for subsequent quantum channel security testing.
[0068] S3: The security center performs bait state detection, replacement operation, and introduction of bait state on the extended first sequence, generates a new first sequence, and transmits it.
[0069] Preferably, performing bait state detection, replacement operation and introduction of bait state on the extended first sequence to generate a new first sequence includes the following steps: the security center receives the extended first particle sequence S' A1 and the extended second particle sequence S' B1 And detect the bait state, if it is correct, extract the first particle sequence S A1 and the second particle sequence S B1 .
[0070] For the first particle sequence S extracted A1 and the second particle sequence S B1 Perform the permutation operation and reintroduce the decoy state to generate a new first particle sequence and the new second particle sequence
[0071] Preferably, through independent testing by the security center, a trusted third-party verification mechanism is built, namely a triple protection mechanism of bait state detection, replacement operation and reintroduction of bait state. The introduction of replacement operation breaks the original particle arrangement pattern and increases the randomness of the communication process. The use of multiple bait states forms a defense-in-depth system and significantly improves the anti-interference capability.
[0072] S4: The grid control center and the grid operator remove the bait state from the new first sequence and restore it to the first sequence.
[0073] Preferably, removing the bait state from the new first sequence and restoring it to the first sequence means that the power grid control center and the power grid operator receive the new first particle sequence. and the new second particle sequence And remove the bait state and restore to the first particle sequence S A1 and the second particle sequence S B1 .
[0074] S5: Perform Pauli operation and Bell measurement on the second sequence to obtain a measurement result.
[0075] Specifically, the Pauli operation and Bell measurement include the following steps: the power grid control center and the power grid operator use the first quantum bit sequence S A2 and the second qubit sequence S B2 , perform Pauli operation according to the pre-shared key to obtain the quantum bit after the operation.
[0076] Perform Bell measurement on the operated quantum bits to obtain measurement results.
[0077] Preferably, a unique verification mechanism is formed by combining the Pauli operation with the Bell measurement, wherein the introduction of the Pauli operation increases the complexity of the quantum state transformation, making it difficult for unauthorized persons to accurately predict the measurement results; while the Bell measurement can effectively detect the correlation of quantum entangled pairs, providing a reliable physical basis for identity authentication.
[0078] S6: Use classical communication channels to exchange measurement results, verify identities, and achieve secure authentication of grid operators.
[0079] Specifically, the measurement results are exchanged and the identity is verified using a classic communication channel, including the following steps: the power grid control center and the power grid operator exchange their respective measurement results through a secure classic communication channel, and the identities of both parties are verified by comparing the correlation of the measurement results. If the results show an association pattern consistent with the expected pre-shared key, the identity verification is successful.
[0080] If the results are not as expected, there may be tampering or fraud attempts and the authentication failed.
[0081] Preferably, the present invention constructs a complete identity authentication system by combining quantum communication with classical communication, and utilizes the non-cloning of quantum states and quantum entanglement characteristics to ensure the security of the authentication process from a physical level; through the superposition of multiple security mechanisms, the technical threshold for identity forgery and man-in-the-middle attacks is significantly improved; and combined with classical communication for result verification, the reliability of the authentication results is guaranteed, and a practical failure handling mechanism is provided.
[0082] In summary, the power grid operator security authentication method based on quantum communication of the present invention greatly enhances the security of power grid communication by utilizing quantum entanglement, decoy state technology and quantum substitution operation. Through this method, the power grid control center and the operator can safely generate and share keys, effectively preventing advanced persistent threats APT and other potential security risks; in addition, the present invention also has the ability of efficient key management and adaptability to resource-constrained devices, which not only improves the security protection capability of the power grid system, but also simplifies the operation process, and is suitable for integration into the existing power grid security architecture.
[0083] Embodiment 2 is an embodiment of the present invention, which provides a power grid operator security authentication system based on quantum communication, including: a sequence generation module, which is used for the power grid control center and the power grid operator to generate and divide the Bell state sequence according to the binary key sequence to obtain the first particle sequence, the first quantum bit sequence, the second particle sequence and the second quantum bit sequence; a bait introduction module, which is used to introduce bait particles into the first particle sequence and the second particle sequence to form an extended first particle sequence and an extended second particle sequence; a security center module, which is used to use the security center to receive the extended first particle sequence and the extended second particle sequence and perform bait state detection and replacement operation. The invention relates to a method for generating a first particle sequence and a second particle sequence by performing a Pauli operation and introducing a bait state, generating a new first particle sequence and a new second particle sequence and sending them to a power grid control center and a power grid operator; a bait restoration module is used for the power grid control center and the power grid operator to remove the bait state of the new first particle sequence and the new second particle sequence and restore them to the first particle sequence and the second particle sequence; a measurement result module is used for the power grid control center and the power grid operator to use the first quantum bit sequence and the second quantum bit sequence to perform Pauli operation and Bell measurement according to a pre-shared key to obtain a measurement result; a security authentication module is used for the power grid control center and the power grid operator to exchange measurement results using a classical communication channel and verify the identities of both parties.
[0084] Embodiment 3 is an embodiment of the present invention, which is different from the previous embodiment in that:
[0085] like Figure 2As shown, if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0086] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0087] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0088] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0089] Example 4 is an embodiment of the present invention, which provides a power grid operator security authentication method based on quantum communication. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through simulation experiments.
[0090] This example simulates a 6-month experimental study in a provincial power dispatching and control center. The experimental environment is configured as follows: the QKD-2000 quantum key distribution system developed by Quantum Technology Company is used as the basic quantum communication equipment. The system has a Bell state preparation rate of 1GHz and a Bell state measurement accuracy of 99.9%; the total length of the optical fiber channel used in the experiment is 75 kilometers, and the signal is enhanced by an erbium-doped fiber amplifier EDFA, and phase compensation technology is used to maintain the coherence of the quantum state.
[0091] In the specific implementation process, a binary key sequence of 1024 bits is first generated as the initial shared key. The power grid control center and the power grid operator generate Bell state sequences based on the key sequence. When the key value is "00" and "01", the Bell state sequence S is generated. A ; When the key value is "01" and "10", the Bell state sequence S is generated B ; To ensure the security of the quantum channel, a decoy state is inserted every 8 quantum bits in the first sequence, and the decoy state randomly selects one of the four states: |0>, |1>, |+>, and |->; After receiving the extended sequence, the security center first detects the correctness of the decoy state, and then performs a quantum state permutation operation based on the Fisher-Yates algorithm. After the permutation, the decoy state is reintroduced to form a new sequence; Finally, the power grid control center and the power grid operator perform Pauli operations and Bell measurements, and perform identity authentication by exchanging measurement results through classical channels.
[0092] In the experiment, the method proposed in the present invention is evaluated from three perspectives: system performance parameters under different communication distances, security performance indicators under different attack scenarios, and performance comparison with traditional authentication methods. Table 1 is a table of system performance parameters under different communication distances.
[0093] Table 1 System performance parameters at different communication distances
[0094] Communication distance (km) Photon detection efficiency (%) Quantum bit error rate (%) System stability (%) 10 89.5 0.15 99.95 25 87.2 0.22 99.92 40 84.8 0.31 99.88
[0095] It can be seen from Table 1 that the method of the present invention exhibits excellent performance at different communication distances; at a communication distance of 10 km, the system can achieve a photon detection efficiency of 89.5%, and the quantum bit error rate is only 0.15%. Even in long-distance communication scenarios, the system can still maintain a high detection efficiency.
[0096] As shown in Table 2, it is a table of security performance indicators under different attack scenarios. It can be seen from the table that the method of the present invention has extremely strong defense capabilities against various types of quantum attacks; for the most common interception and retransmission attacks, the system can achieve a detection rate of 99.99% and a defense success rate of 99.98%, with a false alarm rate of only 0.01%. This is mainly due to the dual decoy state strategy and dynamic replacement mechanism adopted by the present invention, which effectively improves the security of the system.
[0097] Table 2 Security performance indicators under different attack scenarios
[0098] Attack Types Attack detection rate (%) False alarm rate (%) Defense success rate (%) Intercept and retransmit attack 99.99 0.01 99.98 Man-in-the-middle attacks 99.98 0.02 99.97 Phase Attack 99.95 0.03 99.95
[0099] Table 3 is a performance comparison table of the present invention and the traditional authentication method.
[0100] Table 3 Performance comparison between the present invention and traditional authentication methods
[0101] Authentication method Certification success rate (%) Authentication delay (ms) Method of the present invention 99.95 5.2 RSA Digital Signature 99.90 12.5 Multi-factor authentication 99.80 925.0
[0102] It can be seen from the above table that the method of the present invention has significant advantages over traditional authentication schemes. In terms of authentication success rate, the present invention is higher than all other comparison schemes; in terms of authentication delay, the present invention only takes 5.2ms, which is 58.4% faster than the fastest RSA digital signature scheme, and is of great significance for building a future-oriented power grid security system.
[0103] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should be included in the scope of the claims of the present invention.
Claims
1. A method for secure authentication of power grid operators based on quantum communication, characterized in that: include: The power grid control center and the power grid operator generate a Bell state sequence according to the binary key sequence and divide it to obtain a first sequence and a second sequence; introducing decoy particles into the first sequence to form an extended first sequence and transmit it through a quantum channel; The security center performs bait state detection, replacement operation and introduction of bait state on the extended first sequence, generates a new first sequence and transmits it; The power grid control center and the power grid operator remove the bait state from the new first sequence and restore it to the first sequence; performing Pauli operation and Bell measurement on the second sequence to obtain a measurement result; Exchange measurement results using classic communication channels, verify identities, and achieve secure authentication of grid operators.
2. The method for secure authentication of power grid operators based on quantum communication according to claim 1, characterized in that: The generation of the Bell state sequence refers to the power grid control center and the power grid operator generating the Bell state sequence S respectively according to the shared binary key sequence A and Bell state sequence S B .
3. The method for secure authentication of power grid operators based on quantum communication according to claim 2, characterized in that: The generated Bell state sequence S A and Bell state sequence S B include: If k m = 00 and k m =01, then the Bell state sequence S A The calculation formula is as follows: Among them, k m is the mth key value in the binary key sequence, m = 1, 2, ..., 2n, where 2n is the total number of elements in the key sequence; S A is the Bell state sequence; Ai is the Bell state generated by the power grid control center using the i-th key in the binary key sequence; If k m =01 and k m =10, then the Bell state sequence S B The calculation formula is as follows: Among them, k m is the mth key value in the binary key sequence, m = 1, 2, ..., 2n, where 2n is the total number of elements in the key sequence; S B is the Bell state sequence; Bi It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
4. The method for secure authentication of power grid operators based on quantum communication as claimed in claim 3, characterized in that: The obtaining of the first sequence and the second sequence comprises: The power grid control center will Bell state sequence S A Divided into the first particle sequence S A1 and the first quantum bit sequence S A2 , the specific formula is as follows: S A1 ={|Ψ A1 >,|Ψ A3 >,...,|Ψ A(2n-1) >} S A2 ={|Ψ A2 >,|Ψ A4 >,...,|Ψ A(2n) >} Among them, S A1 is the first particle sequence; S A2 is the first quantum bit sequence; Ψ Ai is the Bell state generated by the power grid control center using the i-th key in the binary key sequence; The grid operator converts the Bell state sequence S B Divided into the second particle sequence S B1 and the second qubit sequence S B2 , the specific formula is as follows: S B1 ={|Ψ B1 >,|Ψ B3 >,...,|Ψ B(2n-1) >} S B2 ={|Ψ B2 >,|Ψ B4 >,...,|Ψ B(2n) >} Among them, S B1 is the second particle sequence; S B2 is the second quantum bit sequence; Bi It is the Bell state generated by the power grid control center using the i-th key in the binary key sequence.
5. The method for secure authentication of power grid operators based on quantum communication according to claim 4, characterized in that: Introducing decoy particles into the first sequence to form an extended first sequence means that the power grid control center and the power grid operator respectively introduce decoy particles into the first particle sequence S A1 and the second particle sequence S B1 Introduce decoy particles to form an extended first particle sequence S' A1 and the extended second particle sequence S' B1 ; The introduction of bait particles forms an extended first particle sequence S' A1 and the extended second particle sequence S' B1 Refers to the random selection of the bait particle state, in the first particle sequence S A1 and the second particle sequence S B1 Insert bait particles at random positions in the Performing bait state detection, replacement operation, and introduction of bait state on the extended first sequence to generate a new first sequence includes the following steps: The security center receives the extended first particle sequence S' A1 and the extended second particle sequence S' B1 And detect the bait state, if it is correct, extract the first particle sequence S A1 and the second particle sequence S B1 ; For the first particle sequence S extracted A1 and the second particle sequence S B1 Perform the permutation operation and reintroduce the decoy state to generate a new first particle sequence and the new second particle sequence 6. The method for secure authentication of power grid operators based on quantum communication according to claim 5, characterized in that: The decoy state of the new first sequence is removed, and the restoration to the first sequence means that the power grid control center and the power grid operator receive the new first particle sequence. and the new second particle sequence And remove the bait state and restore to the first particle sequence S A1 and the second particle sequence S B1 ; The Pauli operation and Bell measurement include the following steps: Grid control centers and grid operators use the first quantum bit sequence S A2 and the second qubit sequence S B2 , perform Pauli operation according to the pre-shared key to obtain the quantum bit after the operation; Perform Bell measurement on the operated quantum bits to obtain measurement results.
7. The method for secure authentication of power grid operators based on quantum communication according to claim 6, characterized in that: The method of exchanging measurement results and verifying identity by using a classic communication channel includes the following steps: The grid control center and the grid operator exchange their respective measurement results through the classic communication channel. The identities of both parties are verified by comparing the correlation of the measurement results. If the results show a correlation pattern consistent with the expected pre-shared key, the identity verification is successful; If the results are not as expected, it indicates tampering or a fraudulent attempt and the authentication fails.
8. A power grid operator security authentication system based on quantum communication, based on the power grid operator security authentication method based on quantum communication according to any one of claims 1 to 7, characterized in that: include, A sequence generation module is used for the power grid control center and the power grid operator to generate and divide the Bell state sequence according to the binary key sequence to obtain a first particle sequence, a first quantum bit sequence, a second particle sequence and a second quantum bit sequence; A decoy introduction module, used for introducing decoy particles into the first particle sequence and the second particle sequence to form an extended first particle sequence and an extended second particle sequence; A security center module, used to receive the extended first particle sequence and the extended second particle sequence using the security center and perform decoy state detection, replacement operation and introduction of decoy state, generate a new first particle sequence and a new second particle sequence and send them to the power grid control center and the power grid operator; A decoy restoration module is used for the power grid control center and the power grid operator to remove the decoy state of the new first particle sequence and the new second particle sequence and restore them to the first particle sequence and the second particle sequence; A measurement result module, used for the power grid control center and the power grid operator to use the first quantum bit sequence and the second quantum bit sequence to perform Pauli operation and Bell measurement according to the pre-shared key to obtain a measurement result; The security authentication module is used for the grid control center and the grid operator to exchange measurement results using classic communication channels and verify the identities of both parties.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the quantum communication-based power grid operator security authentication method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the quantum communication-based power grid operator security authentication method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Quantum dialogue protocol with collective-dephasing noise resisting authentication based on logic Bell states
CN104468117A
Disordered high capacity multiparty quantum key agreement method based on high energy level bell state
CN108809644A
Quantum key distribution method with superdense coding characteristic in quantum communication networks
CN109495262A
Verifiable quantum key negotiation method
CN110932856A
Measurement device independent quantum secure direct communication with user authentication
US20230188222A1