Power distribution communication network access control method and system

By using quantum access controllers in the distribution communication network for quantum authentication verification, the problem of insufficient identity verification and security of distribution terminals during network access is solved, and higher network security and reliability are achieved.

CN120074949AActive Publication Date: 2025-05-30MAINTENANCE BRANCH OF STATE GRID FUJIAN ELECTRIC POWER +1

Patent Information

Application Number
CN202510512716.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-05-30
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

Existing power distribution terminals lack unified authentication management during network access, cannot effectively identify and verify terminal identity, and there is a risk of being faked and cyber attacks. Traditional encryption technology appears fragile when facing quantum computers.

Method used

The quantum access controller is used to access the network through the aggregation port, and the media access control address of the distribution terminal is obtained based on the address resolution protocol, and quantum authentication legality verification is used using the quantum key. If the verification is passed, the media access control address of the network node is updated to the address of the legal terminal; if it is not passed, it is updated to the address of the quantum access controller to block data communication of the illegal terminal.

Benefits of technology

It effectively improves the security of the power distribution communication network, prevents illegal terminal access and data tampering, and ensures the security and reliability of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074949A_ABST
    Figure CN120074949A_ABST
Patent Text Reader

Abstract

The invention discloses a power distribution communication network admission control method and system, and the method comprises the steps: enabling a quantum admission controller to be accessed to a network through a convergence port, and obtaining a media access control address of a power distribution terminal which is accessed to the network based on an address resolution protocol; and performing quantum authentication validity verification on the power distribution terminal based on the media access control address and the quantum key by using the quantum admission controller, and if the result is legal, indicating that the terminal can access the network. If the result is illegal, updating the media access control address in the address resolution protocol information of other network nodes under the two-layer switch corresponding to the quantum access controller as the media access control address of the power distribution terminal; if yes, updating the media access control address in the address resolution protocol information of other network nodes under the two-layer switch corresponding to the quantum admission controller into the media access control address of the quantum admission controller, thereby effectively improving the security of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of distribution communication networks, and in particular, to a method and system for access control of distribution communication networks. Background Art

[0002] With the continuous advancement of the construction of smart grids and the rapid development of power communication technologies, as an important part of smart grids, the construction and development of power optical fiber communication access networks have received extensive attention. Optical fiber communication has been widely used in the field of power communication due to its advantages such as high speed, large capacity, and strong anti-interference ability. The existing security module verification of distribution automation terminals is mainly realized through traditional one-way function keys, which to a certain extent solves the problems of security authentication of master station downlink instructions and data integrity verification, and can prevent malicious behaviors such as impersonating the master station to operate power equipment to a certain extent.

[0003] However, the existing solutions have problems of lack of access control for distribution terminals and lack of unified authentication management for network access devices of distribution terminals. They cannot implement legal authentication and identification of the identity of terminals by the master station, and there is still a possibility that the terminals accessing the master station system are impersonated. Attackers can even initiate network attacks on the master station system by using the terminal as a springboard based on the controlled terminal. In addition, the currently used traditional cryptographic devices mainly include VPN (Virtual Private Network technology), cryptographic cards, server cryptographic machines, etc. The cryptographic algorithms used are based on asymmetric cryptographic technologies, and the security of their keys is guaranteed by the security of the inverse calculation algorithm of one-way functions. With the enhancement of computing power, all one-way functions will appear vulnerable, and the security of their keys cannot be guaranteed. At the same time, since quantum computers can easily crack the asymmetric algorithms regarded as unbreakable in traditional encryption systems, the development of quantum computing technology also poses a huge threat to traditional encryption technologies. Summary of the Invention

[0004] The technical problem to be solved by the present invention is: to provide a method and system for access control of distribution communication networks, which can effectively improve the security of the system.

[0005] To solve the above technical problem, a technical solution adopted by the present invention is: A method for access control of distribution communication networks, comprising the steps of: Using a quantum access controller set at a sub-station of the power grid system to access the network through an aggregation port, and obtaining the media access control address of a distribution terminal accessing the network based on the address resolution protocol; Using the quantum access controller to perform quantum authentication legality verification on the distribution terminal based on the media access control address and a quantum key, and obtaining a legality verification result; If the legality verification result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal; If the legality verification result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.

[0006] To solve the above technical problems, another technical solution adopted by the present invention is: A power distribution communication network access control system includes a quantum access controller provided at a sub-station of a power grid system, a quantum access control center provided at a regional management layer of the power grid system, and a quantum authentication switch provided at an important site of the power grid system. The quantum access controller includes a first memory, a first processor, and a first computer program stored on the first memory and executable on the first processor. The quantum access control center includes a second memory, a second processor, and a second computer program stored on the second memory and executable on the second processor. The quantum authentication switch includes a third memory, a third processor, and a third computer program stored on the third memory and executable on the third processor. When the first processor executes the first computer program, the following steps are implemented: Access the network through an aggregation port and obtain the media access control address of the power distribution terminal accessing the network based on the address resolution protocol; Perform quantum authentication legality verification on the power distribution terminal based on the media access control address and a quantum key to obtain a legality verification result; If the legality verification result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal; If the legality verification result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.

[0007] The beneficial effects of the present invention are as follows: The quantum access controller set at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control address of the power distribution terminal accessing the network based on the address resolution protocol. The quantum access controller performs quantum authentication legality verification on the power distribution terminal based on the media access control address and the quantum key. If the result is legal, it indicates that the terminal can access the network, and updates the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal to achieve normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permissions, and updates the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key, based on the identity authentication method of the quantum key and quantum communication technology, avoiding the possibility of being cracked, ensuring the security and reliability of authentication, and thus effectively improving the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 It is a step flow chart of a power distribution communication network access control method according to an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a power distribution communication network access control system according to an embodiment of the present invention; Figure 3 It is a network overall architecture diagram in the power distribution communication network access control method according to an embodiment of the present invention; Figure 4 It is a deployment schematic diagram in the power distribution communication network access control method according to an embodiment of the present invention; Figure 5 It is a network traffic detection schematic diagram in the power distribution communication network access control method according to an embodiment of the present invention; Figure 6 It is a schematic diagram of an authentication system in the power distribution communication network access control method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0009] To describe in detail the technical content, achieved objectives and effects of the present invention, the following is described in conjunction with the embodiments and with reference to the accompanying drawings.

[0010] Please refer to Figure 1 , a power distribution communication network access control method, including the steps: The quantum access controller set at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control address of the power distribution terminal accessing the network based on the address resolution protocol; The quantum access controller is used to perform a legality check on the power distribution terminal based on the media access control address and the quantum key, and obtain a legality check result; If the legality check result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal; If the legality check result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.

[0011] As can be seen from the above description, the beneficial effects of the present invention are as follows: The quantum access controller set at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control address of the power distribution terminal accessing the network based on the address resolution protocol. The quantum access controller is used to perform a quantum authentication legality check on the power distribution terminal based on the media access control address and the quantum key. If the result is legal, it indicates that the terminal can access the network. Update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal, so that other network nodes can correctly identify and communicate with this legal terminal to achieve normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permission. Update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key and the identity authentication method based on the quantum key and quantum communication technology to avoid the possibility of being cracked, ensuring the security and reliability of the authentication, and thus effectively improving the security of the system.

[0012] Furthermore, it further includes: The quantum access controller is used to receive a request for a new power distribution terminal to access the power grid system; The quantum access controller is used to associate and bind the media access control address and the Internet protocol address of the new power distribution terminal with the quantum certificate according to the request, and upload the bound media access control address, the Internet protocol address and the quantum certificate to the quantum access control center set in the regional management layer of the power grid system; The quantum access control center is used to authenticate and authorize the new power distribution terminal based on the bound media access control address, the Internet protocol address and the quantum certificate, and obtain the authentication and authorization result; If the authentication and authorization result is passed, the quantum access control center is used to send a release message to the quantum access controller, and file the new power distribution terminal; The quantum access controller is used to admit the new power distribution terminal and perform fingerprint detection on the new power distribution terminal to obtain the baseline standard of the new power distribution terminal; The quantum access controller is used to upload the baseline standard of the new power distribution terminal to the quantum access control center.

[0013] As can be seen from the above description, the quantum access control center authenticates and authorizes the new power distribution terminal based on the bound media access control address, the Internet protocol address and the quantum certificate, so as to judge whether the new power distribution terminal is legal based on quantum technology and set authentication rules. When the authentication and authorization are passed, the quantum access control center files the new power distribution terminal for subsequent management and monitoring. The quantum access controller obtains the baseline standard of the new power distribution terminal through fingerprint detection and uploads it to the quantum access control center. In this way, by continuously improving the fingerprint baseline, the quantum access control center can more accurately identify and manage the power distribution terminal, timely discover abnormal changes in the equipment, and ensure the safe and stable operation of the system.

[0014] Furthermore, it further includes: The quantum access control center is used to collect the network data of all power distribution terminals through a traffic probe; The quantum access control center is used to analyze and extract the network data to obtain the network asset fingerprint of the power distribution terminal; The quantum access control center is used to monitor the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain the monitoring result; If the monitoring result shows that the network asset fingerprint or the behavior does not conform to the baseline standard of the power distribution terminal, the quantum access control center is used to output a security warning message and perform address resolution protocol spoofing.

[0015] As described above, the quantum access control center continuously monitors the network asset fingerprints and behaviors of all distribution terminals, and keeps track of the characteristic changes of the distribution terminals in real time. When the network asset fingerprints or behaviors do not conform to the baseline standards of the distribution terminals, it is determined that there may be a risk of illegal access or a security problem with the terminal. The quantum access control center will immediately issue a security alarm and also adopt the technical means of address resolution protocol spoofing to prevent the illegal access of the distribution terminal, thus effectively ensuring the security of the system.

[0016] Furthermore, before the quantum access controller disposed at the sub-station of the power grid system accesses the network through the aggregation port, it further includes: Using the quantum access controller disposed at the sub-station of the power grid system and / or the quantum authentication switch disposed at the important site of the power grid system, sending an authentication request to the quantum access control center disposed at the regional management layer of the power grid system, where the authentication request includes the quantum keys of the quantum access controller and / or the quantum authentication switch; Using the quantum access control center to proofread the quantum keys of the quantum access controller and / or the quantum authentication switch based on the quantum key system to obtain a proofreading result; If the proofreading result is passed, use the quantum access control center to establish files of the quantum access controller and / or the quantum authentication switch, and send an instruction to enable the access blocking function to the quantum access controller and / or the quantum authentication switch.

[0017] As described above, the quantum access controller and the quantum authentication switch can initiate an authentication request to the quantum access control center separately or simultaneously, and need to prove their legitimate identities to be allowed to access the network. The quantum key is a key with extremely high security generated based on the principles of quantum mechanics, and its security stems from the characteristics such as the non-clonability and uncertainty of the quantum state. The quantum access control center proofreads the quantum keys of the quantum access controller and / or the quantum authentication switch based on the quantum key system. After the proofreading is passed, files of the quantum access controller and / or the quantum authentication switch are established, and an instruction to enable the access blocking function is sent to the quantum access controller and / or the quantum authentication switch, which is convenient for device management and subsequent monitoring, and endows them with the right to prevent unauthorized devices from accessing the network, so as to ensure the security of the system.

[0018] Furthermore, it further includes: Using the quantum access control center disposed at the regional management layer of the power grid system to upload the whitelist of the distribution terminals that have obtained access to the authentication system for proxy authentication review; The quantum access control center is used to receive the audit result encapsulation data returned by the authentication system and send the audit result encapsulation data to the quantum access controller; The quantum access controller is used to parse the audit result encapsulation data to obtain audit result parsing data and send the audit result parsing data to the quantum access control center; The quantum access control center is used to send a release instruction to the quantum access controller based on the audit result parsing data; The quantum access controller is used to release the power distribution terminal corresponding to the audit result parsing data.

[0019] As can be seen from the above description, proxy authentication initiated by the quantum access control center in the form of white list distribution can also be used to achieve centralized management of the access of power distribution terminals, and can more efficiently ensure system security.

[0020] Please refer to Figure 2 , a power distribution communication network access control system, including a quantum access controller set at a sub-station of the power grid system, a quantum access control center set at the regional management layer of the power grid system, and a quantum authentication switch set at an important site of the power grid system. The quantum access controller includes a first memory, a first processor, and a first computer program stored on the first memory and executable on the first processor. The quantum access control center includes a second memory, a second processor, and a second computer program stored on the second memory and executable on the second processor. The quantum authentication switch includes a third memory, a third processor, and a third computer program stored on the third memory and executable on the third processor. When the first processor executes the first computer program, the following steps are implemented: Access the network through the aggregation port and obtain the media access control address of the power distribution terminal accessing the network based on the address resolution protocol; Perform a legality check on the power distribution terminal based on the media access control address and the quantum key to obtain a legality check result; If the legality check result is legal, update the media access control address in the address resolution protocol information of other network nodes under the second-layer switch corresponding to the quantum access controller to the media access control address of the power distribution terminal; If the legality check result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the second-layer switch corresponding to the quantum access controller to the media access control address of the quantum access controller.

[0021] As can be seen from the above description, the beneficial effects of the present invention are as follows: The quantum access controller provided at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control address of the power distribution terminal accessing the network based on the address resolution protocol. The quantum access controller performs quantum authentication and legality verification on the power distribution terminal based on the media access control address and the quantum key. If the result is legal, it indicates that the terminal can access the network. The media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller is updated to the media access control address of the power distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal to achieve normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permissions. The media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller is updated to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key, and the identity authentication method based on the quantum key and quantum communication technology, avoiding the possibility of being cracked, ensuring the security and reliability of authentication, and thus effectively improving the security of the system.

[0022] Further, when the first processor executes the first computer program, the following steps are further implemented: Receive a request for a new power distribution terminal to access the power grid system; According to the request, associate and bind the media access control address and the Internet protocol address of the new power distribution terminal with the quantum certificate, and upload the bound media access control address, the Internet protocol address and the quantum certificate to the quantum access control center; When the second processor executes the second computer program, the following steps are implemented: Authenticate and authorize the new power distribution terminal based on the bound media access control address, the Internet protocol address and the quantum certificate to obtain an authentication and authorization result; If the authentication and authorization result is passed, send a release message to the quantum access controller and create a file for the new power distribution terminal; When the first processor executes the first computer program, the following steps are further implemented: Admit the new power distribution terminal and perform fingerprint detection on the new power distribution terminal to obtain the baseline standard of the new power distribution terminal; Upload the baseline standard of the new power distribution terminal to the quantum access control center.

[0023] As described above, the quantum access control center authenticates and authorizes a new power distribution terminal based on the bound media access control address, Internet protocol address, and quantum certificate, and determines whether the new power distribution terminal is legal based on quantum technology and the set authentication rules. When the authentication and authorization are passed, the quantum access control center creates a file for the new power distribution terminal for subsequent management and monitoring. The quantum access controller obtains the baseline standard of the new power distribution terminal through fingerprint detection and uploads it to the quantum access control center. By continuously improving the fingerprint baseline in this way, the quantum access control center can more accurately identify and manage power distribution terminals, timely detect abnormal changes in equipment, and ensure the safe and stable operation of the system.

[0024] Further, when the second processor executes the second computer program, the following steps are also implemented: Collect network data of all power distribution terminals through a traffic probe; Analyze and extract the network data to obtain the network asset fingerprint of the power distribution terminal; Monitor the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain a monitoring result; If the monitoring result shows that the network asset fingerprint or the behavior does not match the baseline standard of the power distribution terminal, output a security warning message and perform an address resolution protocol spoofing.

[0025] As described above, the quantum access control center continuously monitors the network asset fingerprints and behaviors of all power distribution terminals, and real-time grasps the characteristic changes of power distribution terminals. When the network asset fingerprint or behavior does not match the baseline standard of the power distribution terminal, it is determined that the terminal may have a risk of illegal access or a security problem. The quantum access control center will immediately issue a security warning and also take the technical means of address resolution protocol spoofing to prevent illegal access of the power distribution terminal, thus effectively ensuring the security of the system.

[0026] Further, when the first processor executes the first computer program, and / or when the third processor executes the third computer program, the following steps are also implemented: Send an authentication request to the quantum access control center set in the regional management layer of the power grid system, and the authentication request includes the quantum keys of the quantum access controller and / or the quantum authentication switch; When the second processor executes the second computer program, the following steps are also implemented: Verify the quantum keys of the quantum access controller and / or the quantum authentication switch based on the quantum key system to obtain a verification result; If the verification result is passed, a file of the quantum access controller and / or the quantum authentication switch is established, and an instruction to enable the access blocking function is sent to the quantum access controller and / or the quantum authentication switch.

[0027] As can be seen from the above description, the quantum access controller and the quantum authentication switch can initiate an authentication request to the quantum access control center separately or simultaneously, and need to prove their legal identities to be allowed to access the network. The quantum key is a key with extremely high security generated based on the principles of quantum mechanics, and its security stems from the characteristics of the non-clonability and uncertainty of quantum states. The quantum access control center verifies the quantum keys of the quantum access controller and / or the quantum authentication switch based on the quantum key system. After the verification is passed, a file of the quantum access controller and / or the quantum authentication switch is established, and an instruction to enable the access blocking function is sent to the quantum access controller and / or the quantum authentication switch, which facilitates the management and subsequent monitoring of the devices, and endows them with the right to prevent unauthorized devices from accessing the network, thus ensuring the system security.

[0028] Further, when the second processor executes the second computer program, the following steps are also implemented: Upload the whitelist of the power distribution terminals that have obtained access to the authentication system for proxy authentication review; Receive the audit result encapsulation data returned by the authentication system, and send the audit result encapsulation data to the quantum access controller; When the first processor executes the first computer program, the following steps are also implemented: Parse the audit result encapsulation data to obtain the audit result parsing data, and send the audit result parsing data to the quantum access control center; When the second processor executes the second computer program, the following steps are also implemented: Send a release instruction to the quantum access controller based on the audit result parsing data; When the first processor executes the first computer program, the following steps are also implemented: Use the quantum access controller to release the power distribution terminal corresponding to the audit result parsing data.

[0029] As can be seen from the above description, proxy authentication initiated by the quantum access control center in the form of whitelist distribution can also be used to achieve centralized management of the access of power distribution terminals, and can more efficiently ensure system security.

[0030] The above-mentioned power distribution communication network access control method and system of the present invention can be applied to the power grid system, which will be described below through specific embodiments: Please refer toFigure 1 , Figures 3 - 6 , Embodiment 1 of the present invention is as follows: A power distribution communication network access control method, including the steps: S1. Use the quantum access controller (NAP) set at the sub-station of the power grid system and / or the quantum authentication switch set at the important site of the power grid system to send an authentication request to the quantum access control center (NAC) set at the regional management layer of the power grid system. The authentication request includes the quantum key of the quantum access controller and / or the quantum authentication switch, as Figure 3 shown.

[0031] Among them, the quantum access controller and the quantum authentication switch can be newly accessed or powered on again.

[0032] S2. Use the quantum access control center to proofread the quantum key of the quantum access controller and / or the quantum authentication switch based on the quantum key system to obtain a proofreading result.

[0033] S3. If the proofreading result is passed, use the quantum access control center to establish a file of the quantum access controller and / or the quantum authentication switch, and send an instruction to turn on the access blocking function to the quantum access controller and / or the quantum authentication switch.

[0034] In an optional implementation manner, the physical port of the quantum authentication switch is default in a locked state. If the proofreading result is passed, the physical port changes to a released state for the power distribution terminal to access the Internet through the port. If the proofreading result is not passed, the physical port remains in the locked state.

[0035] The quantum authentication switch writes the quantum key into the key storage medium, and the key storage medium is applied to the quantum authentication switch.

[0036] In an optional implementation manner, use the quantum access control center to continuously monitor the heartbeat and traffic probe of the quantum authentication switch to determine whether the quantum authentication switch is online.

[0037] S4. Use the quantum access controller set at the sub-station of the power grid system to access the network through the aggregation port, and obtain the media access control (MAC) address of the power distribution terminal accessing the network based on the address resolution protocol (ARP).

[0038] In an optional implementation manner, the power distribution terminal can be a notebook, an Internet of Things terminal, etc.

[0039] S5. Use the quantum access controller to perform quantum authentication and legality verification on the power distribution terminal based on the media access control address and the quantum key, and obtain the legality verification result.

[0040] S6. If the legality verification result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal.

[0041] S7. If the legality verification result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller. At this time, the actual terminal data in the network cannot be sent out to block and isolate the data of the illegal power distribution terminal.

[0042] For example, as Figure 4 shown, the specific deployment mode is to deploy 1 set of quantum access control centers at the location of the access switch of the city company and 1 quantum access controller at the aggregation switch of each site. The quantum access controller accesses the network through the Trunk port (port aggregation), obtains the MAC address of the power distribution terminal accessing the network through the ARP technology, and based on the MAC address and the quantum key, the quantum access controller performs quantum authentication and legality verification on the power distribution terminal. If it is legal, update the MAC address in the ARP information of other network nodes (including switches and network terminals) under the same layer 2 switch to the MAC address of the power distribution terminal that has passed the authentication. If the legality verification fails, update the MAC address of the ARP information on the network node to the MAC address of the quantum access controller.

[0043] Through the quantum key technology, unified authentication management is realized, and the permission management process of substations and power distribution stations is more convenient. The authentication and access of security devices and the proxy authentication of power distribution terminals are realized, and stronger security control capabilities are achieved. It uses the true random number of quantum keys to avoid the possibility of being cracked. At the same time, quantum authentication realizes an autonomous and controllable unified key source, greatly improving the security of the system.

[0044] In an alternative embodiment, it further includes: Use the quantum access controller to receive a request for a new power distribution terminal to access the power grid system.

[0045] Use the quantum access controller to associate and bind the media access control address and the Internet protocol (IP) address of the new power distribution terminal with the quantum certificate according to the request, and upload the bound media access control address, the Internet protocol address, and the quantum certificate to the quantum access control center set in the regional management layer of the power grid system.

[0046] In an alternative embodiment, when uploading the bound Media Access Control address, the Internet Protocol address, and the quantum certificate, it is transmitted through HTTPS (Hyper Text Transfer Protocol Secure), which ensures the security of data transmission.

[0047] The quantum access control center is used to authenticate and authorize the new power distribution terminal based on the bound Media Access Control address, the Internet Protocol address, and the quantum certificate, and obtain the authentication and authorization result.

[0048] If the authentication and authorization result is passed, the quantum access control center is used to send a release message to the quantum access controller and create a file for the new power distribution terminal.

[0049] The quantum access controller is used to admit the new power distribution terminal and perform fingerprint detection on the new power distribution terminal to obtain the baseline standard of the new power distribution terminal.

[0050] The quantum access controller is used to upload the baseline standard of the new power distribution terminal to the quantum access control center.

[0051] In an alternative embodiment, as Figure 5 shown, it further includes: The quantum access control center is used to collect network data of all power distribution terminals through a traffic probe.

[0052] The quantum access control center is used to analyze and extract the network data to obtain the network asset fingerprint of the power distribution terminal.

[0053] In an alternative embodiment, the network asset fingerprint includes a MAC address, a power distribution terminal name, an operating system version feature, and / or a network open port feature.

[0054] The quantum access control center is used to monitor the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal, and obtain the monitoring result.

[0055] If the monitoring result shows that the network asset fingerprint or the behavior does not match the baseline standard of the power distribution terminal, the quantum access control center is used to output a security warning message and perform Address Resolution Protocol spoofing to prevent the illegal access of the power distribution terminal.

[0056] In addition to verifying the fingerprint information of the distribution terminal to detect anomalies, in an optional implementation, it also includes: performing weak password monitoring or intrusion detection on the distribution terminal. Among them, the weak password monitoring of the distribution terminal includes: using the quantum access controller to actively scan the distribution terminal to determine whether there is a weak password, and if so, uploading the security alarm information to the quantum access control center. Performing intrusion detection on the distribution terminal includes: using the quantum access controller to perform intrusion detection on the network traffic of the distribution terminal to determine whether there is a network attack behavior, and if so, uploading the security alarm information to the quantum access control center.

[0057] In an optional implementation, after the security alarm information is output, the local personnel will conduct a comprehensive assessment and analysis. If any illegal behavior is found, the distribution station operation and maintenance personnel will be notified through a dedicated APP to conduct an investigation; if it is determined to be a legal behavior after investigation, the quantum access control center will be used to update the baseline standard of the distribution terminal and confirm the alarm; if it is determined to be an illegal behavior after investigation, the quantum access control center will be used to link the quantum access controller to block access to the distribution terminal. At the same time, the quantum access control center will link the quantum authentication switch to close the physical port and adjust the strategy.

[0058] In an optional implementation, it also includes: The quantum access control center set up at the regional management level of the power grid system uploads the white list of distribution terminals that have obtained access to the authentication system for proxy authentication review.

[0059] In an optional implementation, when uploading the whitelist, it is encrypted and transmitted via HTTPS.

[0060] The quantum access control center is used to receive the audit result encapsulation data returned by the authentication system, and the audit result encapsulation data is sent to the quantum access controller.

[0061] The audit result encapsulation data is parsed by using the quantum admission controller to obtain audit result parsing data, and the audit result parsing data is sent to the quantum admission control center.

[0062] The quantum admission control center is used to parse the data based on the audit result and send a release instruction to the quantum admission controller.

[0063] The quantum access controller is used to release the distribution terminal corresponding to the audit result analysis data.

[0064] Among them, Figure 6As shown, the authentication system consists of a sending end and a receiving end, which are connected through a quantum channel and a classical channel. The quantum channel is used to transmit quantum state information, and the classical channel is used to transmit other information except quantum states.

[0065] The sending end is composed of a decoy state light source, a quantum state modulation module, a quantum random number generator, and a data processing module. Among them, the functions of the decoy state light source include randomly modulating the intensity of optical pulses to prepare signal state optical pulses and decoy state optical pulses. The quantum state modulation module loads encoded information onto the signal state optical pulses and decoy state optical pulses according to the random sequence input by the quantum random number generator to complete the preparation of the quantum state. The quantum state can be characterized by physical quantities such as polarization, phase, time, spin, and momentum.

[0066] The receiving end is composed of a detection module, a quantum state demodulation module, a quantum random number generator, and a data processing module. The functions of the quantum demodulation module include measurement basis selection and quantum state measurement, where the selection of the measurement basis is random. Subsequently, the detection module detects the measured optical pulses. The receiving end notifies the sending end of the selected measurement basis information through the classical channel, and the sending end compares the encoding basis used in quantum state preparation with the measurement basis of the receiving end. The data processing modules of both parties negotiate processes such as basis comparison, error correction, privacy amplification, and consistency verification through the classical channel to generate a symmetric quantum key.

[0067] In an alternative embodiment, it further includes: the quantum access control center performs traffic analysis on the network deployment network probe to obtain traffic analysis results, and uploads the traffic analysis results to the network security monitoring platform for situation awareness analysis, early warning, and linkage processing.

[0068] Please refer to Figure 2 , Embodiment 2 of the present invention is: A power distribution communication network access control system includes a quantum access controller disposed at a sub-station of a power grid system, a quantum access control center disposed at a regional management layer of the power grid system, and a quantum authentication switch disposed at an important site of the power grid system. The quantum access controller includes a first memory, a first processor, and a first computer program stored on the first memory and executable on the first processor. The quantum access control center includes a second memory, a second processor, and a second computer program stored on the second memory and executable on the second processor. The quantum authentication switch includes a third memory, a third processor, and a third computer program stored on the third memory and executable on the third processor. When the first processor executes the first computer program, it implements each step executed by the quantum access controller in the power distribution communication network access control method in Embodiment 1. When the second processor executes the second computer program, it implements each step executed by the quantum access control center in the power distribution communication network access control method in Embodiment 1. When the third processor executes the third computer program, it implements each step executed by the quantum authentication switch in the power distribution communication network access control method in Embodiment 1.

[0069] In summary, the present invention provides a method and system for access control of a distribution communication network. A quantum access controller disposed at a sub-station of a power grid system accesses the network through an aggregation port, and obtains the media access control address of a distribution terminal accessing the network based on the Address Resolution Protocol. The quantum access controller performs a quantum authentication legality check on the distribution terminal based on the media access control address and a quantum key. If the result is legal, it indicates that the terminal can access the network. The media access control address in the Address Resolution Protocol information of other network nodes under the corresponding layer-2 switch of the quantum access controller is updated to the media access control address of the distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal for normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permission. The media access control address in the Address Resolution Protocol information of other network nodes under the corresponding layer-2 switch of the quantum access controller is updated to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data. Moreover, by using the true random numbers of the quantum key and the identity authentication method based on the quantum key and quantum communication technology, the possibility of being cracked is avoided, ensuring the security and reliability of the authentication, thus effectively improving the security of the system. Additionally, the quantum access control center authenticates and authorizes a new distribution terminal based on the bound media access control address, Internet Protocol address, and quantum certificate to determine whether the new distribution terminal is legal based on quantum technology and set authentication rules. When the authentication and authorization pass, the quantum access control center creates a file for the new distribution terminal for subsequent management and monitoring. The quantum access controller obtains the baseline standard of the new distribution terminal through fingerprint detection and uploads it to the quantum access control center. In this way, by continuously improving the fingerprint baseline, the quantum access control center can more accurately identify and manage distribution terminals, timely detect abnormal changes in devices, and ensure the safe and stable operation of the system.

[0070] The above are only embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent transformation made using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, shall be included in the patent protection scope of the present invention by the same token.

Claims

1. A distribution communication network access control method, characterized in that: Includes steps: Using a quantum access controller set at a sub-site of the power grid system to access the network through an aggregation port, and obtaining a media access control address of a distribution terminal accessing the network based on an address resolution protocol; Using the quantum access controller to perform a quantum authentication legitimacy check on the power distribution terminal based on the media access control address and the quantum key to obtain a legitimacy check result; If the validity check result is valid, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the power distribution terminal; If the legitimacy check result is illegal, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the quantum admission controller.

2. A distribution communication network access control method according to claim 1, characterized in that: Also includes: Using the quantum access controller to receive a request from a new power distribution terminal to access the power grid system; Using the quantum access controller to associate and bind the media access control address and the Internet Protocol address of the new distribution terminal with the quantum certificate according to the request, and uploading the bound media access control address, the Internet Protocol address and the quantum certificate to a quantum access control center set at the regional management layer of the power grid system; Using the quantum access control center to authenticate the new power distribution terminal based on the bound media access control address, the Internet protocol address and the quantum certificate, to obtain an authentication result; If the authentication result is passed, the quantum access control center sends release information to the quantum access controller, and files the new power distribution terminal; Using the quantum access controller to access the new power distribution terminal, and performing fingerprint detection on the new power distribution terminal to obtain a baseline standard of the new power distribution terminal; The quantum access controller is used to upload the baseline standard of the new power distribution terminal to the quantum access control center.

3. A distribution communication network access control method according to claim 2, characterized in that: Also includes: Using the quantum access control center to collect network data of all power distribution terminals through flow probes; Analyzing and extracting the network data using the quantum access control center to obtain a network asset fingerprint of the power distribution terminal; Using the quantum access control center to monitor the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain a monitoring result; If the monitoring result is that the network asset fingerprint or the behavior does not meet the baseline standard of the distribution terminal, the quantum access control center is used to output a security warning message and perform address resolution protocol spoofing.

4. A distribution communication network access control method according to claim 1, characterized in that: Before the quantum admission controller provided at the sub-site of the power grid system is used to access the network through the aggregation port, the method further includes: Using a quantum access controller disposed at a sub-site of a power grid system and / or a quantum authentication switch disposed at an important site of the power grid system, an authentication request is sent to a quantum access control center disposed at a regional management layer of the power grid system, wherein the authentication request includes a quantum key of the quantum access controller and / or the quantum authentication switch; Using the quantum access control center to calibrate the quantum key of the quantum access controller and / or the quantum authentication switch based on a quantum key system to obtain a calibration result; If the proofreading result is passed, the quantum access control center is used to create a file of the quantum access controller and / or the quantum authentication switch, and an access blocking function activation instruction is sent to the quantum access controller and / or the quantum authentication switch.

5. A distribution communication network access control method according to claim 1, characterized in that: Also includes: The quantum access control center set up at the regional management level of the power grid system is used to upload the white list of distribution terminals that have obtained access to the authentication system for proxy authentication review; Using the quantum access control center to receive the audit result encapsulation data returned by the authentication system, and sending the audit result encapsulation data to the quantum access controller; Utilizing the quantum access controller to parse the audit result encapsulation data to obtain audit result parsing data, and sending the audit result parsing data to the quantum access control center; Utilizing the quantum access control center to parse data based on the audit result and send a release instruction to the quantum access controller; The quantum access controller is used to release the distribution terminal corresponding to the audit result analysis data.

6. A distribution communication network access control system, comprising a quantum access controller arranged at a sub-site of a power grid system, a quantum access control center arranged at a regional management level of the power grid system, and a quantum authentication switch arranged at an important site of the power grid system, wherein the quantum access controller comprises a first memory, a first processor, and a first computer program stored in the first memory and executable on the first processor, the quantum access control center comprises a second memory, a second processor, and a second computer program stored in the second memory and executable on the second processor, the quantum authentication switch comprises a third memory, a third processor, and a third computer program stored in the third memory and executable on the third processor, characterized in that: When the first processor executes the first computer program, the following steps are implemented: Accessing the network through the aggregation port, and obtaining the media access control address of the power distribution terminal accessing the network based on the address resolution protocol; Performing a quantum authentication legitimacy check on the power distribution terminal based on the media access control address and the quantum key to obtain a legitimacy check result; If the validity check result is valid, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the power distribution terminal; If the legitimacy check result is illegal, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the quantum admission controller.

7. A distribution communication network access control system according to claim 6, characterized in that: When the first processor executes the first computer program, the following steps are further implemented: Receiving a request from a new power distribution terminal to access the power grid system; Associating and binding the media access control address and the Internet Protocol address of the new power distribution terminal with the quantum certificate according to the request, and uploading the bound media access control address, the Internet Protocol address and the quantum certificate to the quantum access control center; When the second processor executes the second computer program, the following steps are implemented: Authenticating the new power distribution terminal based on the bound media access control address, the Internet Protocol address and the quantum certificate to obtain an authentication result; If the authentication result is passed, the release information is sent to the quantum access controller, and the new power distribution terminal is archived; When the first processor executes the first computer program, the following steps are further implemented: Allowing access to the new power distribution terminal and performing fingerprint detection on the new power distribution terminal to obtain a baseline standard of the new power distribution terminal; The baseline standard of the new power distribution terminal is uploaded to the quantum access control center.

8. A distribution communication network access control system according to claim 7, characterized in that: When the second processor executes the second computer program, the second processor further implements the following steps: Collect network data from all distribution terminals through flow probes; Analyzing and extracting the network data to obtain a network asset fingerprint of the power distribution terminal; Monitoring the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain a monitoring result; If the monitoring result is that the network asset fingerprint or the behavior does not conform to the baseline standard of the power distribution terminal, a security warning message is output and address resolution protocol spoofing is performed.

9. A distribution communication network access control system according to claim 6, characterized in that: When the first processor executes the first computer program, and / or when the third processor executes the third computer program, the following steps are further implemented: Sending an authentication request to a quantum access control center disposed at a regional management layer of the power grid system, wherein the authentication request includes a quantum key of the quantum access controller and / or the quantum authentication switch; When the second processor executes the second computer program, the second processor further implements the following steps: Proofreading the quantum key of the quantum access controller and / or the quantum authentication switch based on a quantum key system to obtain a proofreading result; If the proofreading result is passed, a file of the quantum access controller and / or the quantum authentication switch is created, and an access blocking function activation instruction is sent to the quantum access controller and / or the quantum authentication switch.

10. A distribution communication network access control system according to claim 6, characterized in that: When the second processor executes the second computer program, the second processor further implements the following steps: Upload the whitelist of distribution terminals that have been granted access to the authentication system for proxy authentication review; Receiving the audit result encapsulated data returned by the authentication system, and sending the audit result encapsulated data to the quantum admission controller; When the first processor executes the first computer program, the following steps are further implemented: Parsing the audit result encapsulated data to obtain audit result parsed data, and sending the audit result parsed data to the quantum access control center; When the second processor executes the second computer program, the second processor further implements the following steps: Sending a release instruction to the quantum admission controller based on the audit result parsed data; When the first processor executes the first computer program, the following steps are further implemented: The quantum access controller is used to release the distribution terminal corresponding to the audit result analysis data.

Citation Information

Patent Citations

  • Terminal security access control method

    CN104363228A

  • Electric power wide area industrial control network communication method based on quantum communication technology

    CN106685650A

  • Resource and admission control subsystem and method thereof in ngn

    US20090116382A1

  • Systems, Methods, and Apparatus for Electrical Grid Quantum Key Distribution

    US20120213371A1

  • Authentication of smart grid communications using quantum key distribution

    US20240113870A1

Cited By

  • Power communication network security operation and maintenance method based on secondary authentication

    CN121462194A