A method and system for access control of a distribution communication network
By using quantum access controller and quantum key for authentication and verification in the network access of the distribution terminal, the problem of insufficient identity verification and security during network access by existing distribution terminals is solved, and higher security and reliability are achieved.
Patent Information
- Application Number
- CN202510512716.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-04-23
AI Technical Summary
Existing power distribution terminals lack unified authentication management during network access, cannot effectively identify and verify terminal identity, and there is a risk of being faked and cyber attacks. Traditional encryption technology appears fragile when facing quantum computers.
The quantum access controller is used to access the network through the aggregation port, and the media access control address of the distribution terminal is obtained based on the address resolution protocol, and quantum authentication legality verification is used to use the quantum key. If the verification is passed, the media access control address is updated to allow terminal access; if it is not passed, the address resolution protocol information is updated to block data communication of the illegal terminal.
It effectively improves the security of the system, ensures the legitimacy of the terminal and the security of data communication, prevents access to illegal terminals and data tampering, and uses the true random number of quantum keys to avoid the possibility of being cracked.
Smart Images

Figure CN120074949B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of distribution communication networks, and particularly to a method and system for access control of distribution communication networks. Background Art
[0002] With the continuous advancement of the construction of smart grids and the rapid development of power communication technologies, as an important part of smart grids, the construction and development of power fiber optic communication access networks have received extensive attention. Fiber optic communication has been widely used in the field of power communication due to its advantages such as high speed, large capacity, and strong anti-interference ability. The existing verification of the security module of distribution automation terminals is mainly achieved through traditional one-way function keys, which to a certain extent solves the problems of security authentication of master station downlink instructions and data integrity verification, and can prevent malicious behaviors such as impersonating the master station to operate power equipment to a certain extent.
[0003] However, the existing solutions have problems of lack of access control for distribution terminals and lack of unified authentication management for network access devices of distribution terminals. They cannot implement legal authentication and identification of the identity of terminals by the master station, and there is still a possibility that the terminals accessing the master station system are impersonated. Attackers can even initiate network attacks on the master station system by using the terminal as a springboard based on controlling the terminal. In addition, the currently used traditional cryptographic devices mainly include VPN (Virtual Private Network technology), cryptographic cards, server cryptographic machines, etc. The used cryptographic algorithms are based on asymmetric cryptographic technologies, and the security of their keys is guaranteed by the security of the inverse calculation algorithm of one-way functions. With the enhancement of computing power, all one-way functions will appear vulnerable, and the security of their keys cannot be guaranteed. At the same time, since quantum computers can easily crack the asymmetric algorithms regarded as unbreakable in traditional encryption systems, the development of quantum computing technology also poses a huge threat to traditional encryption technologies. Summary of the Invention
[0004] The technical problem to be solved by the present invention is: to provide a method and system for access control of distribution communication networks, which can effectively improve the security of the system.
[0005] To solve the above technical problem, a technical solution adopted by the present invention is:
[0006] A method for access control of distribution communication networks, comprising the steps of:
[0007] Using a quantum access controller set at a sub-station of the power grid system to access the network through an aggregation port, and obtaining the media access control address of a distribution terminal accessing the network based on the address resolution protocol;
[0008] Use the quantum access controller to perform quantum authentication legality verification on the power distribution terminal based on the media access control address and the quantum key, and obtain a legality verification result;
[0009] If the legality verification result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal;
[0010] If the legality verification result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.
[0011] To solve the above technical problems, another technical solution adopted by the present invention is:
[0012] A power distribution communication network access control system includes a quantum access controller provided at a sub-station of the power grid system, a quantum access control center provided at the regional management layer of the power grid system, and a quantum authentication switch provided at an important site of the power grid system. The quantum access controller includes a first memory, a first processor, and a first computer program stored on the first memory and executable on the first processor. The quantum access control center includes a second memory, a second processor, and a second computer program stored on the second memory and executable on the second processor. The quantum authentication switch includes a third memory, a third processor, and a third computer program stored on the third memory and executable on the third processor. When the first processor executes the first computer program, the following steps are implemented:
[0013] Access the network through an aggregation port, and obtain the media access control address of the power distribution terminal accessing the network based on the address resolution protocol;
[0014] Perform quantum authentication legality verification on the power distribution terminal based on the media access control address and the quantum key, and obtain a legality verification result;
[0015] If the legality verification result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal;
[0016] If the legality verification result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.
[0017] The beneficial effects of the present invention are as follows: The quantum access controller set at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control address of the power distribution terminal accessing the network based on the address resolution protocol. The quantum access controller performs quantum authentication legality verification on the power distribution terminal based on the media access control address and the quantum key. If the result is legal, it indicates that the terminal can access the network, and updates the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal to achieve normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permission, and updates the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key and the identity authentication method based on the quantum key and quantum communication technology to avoid the possibility of being cracked, ensuring the security and reliability of authentication, and thus effectively improving the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is a step flowchart of a power distribution communication network access control method according to an embodiment of the present invention;
[0019] Figure 2 It is a schematic structural diagram of a power distribution communication network access control system according to an embodiment of the present invention;
[0020] Figure 3 It is a network overall architecture diagram in the power distribution communication network access control method according to an embodiment of the present invention;
[0021] Figure 4 It is a deployment schematic diagram in the power distribution communication network access control method according to an embodiment of the present invention;
[0022] Figure 5 It is a network traffic detection schematic diagram in the power distribution communication network access control method according to an embodiment of the present invention;
[0023] Figure 6 It is a schematic diagram of an authentication system in the power distribution communication network access control method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To describe in detail the technical content, the achieved objectives and the effects of the present invention, the following is described in conjunction with the embodiments and with reference to the accompanying drawings.
[0025] Please refer to Figure 1 , a method for access control of a distribution communication network, comprising the steps of:
[0026] Using a quantum access controller set at a sub-station of the power grid system to access the network through an aggregation port, and obtaining the media access control address of a power distribution terminal accessing the network based on the address resolution protocol;
[0027] Using the quantum access controller to perform a legality check on the power distribution terminal based on the media access control address and a quantum key, and obtaining a legality check result;
[0028] If the legality check result is legal, updating the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal;
[0029] If the legality check result is illegal, updating the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.
[0030] As can be seen from the above description, the beneficial effects of the present invention are as follows: Using a quantum access controller set at a sub-station of the power grid system to access the network through an aggregation port, and obtaining the media access control address of a power distribution terminal accessing the network based on the address resolution protocol, using the quantum access controller to perform quantum authentication legality check on the power distribution terminal based on the media access control address and a quantum key. If the result is legal, it indicates that the terminal can access the network, and updating the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal to achieve normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access rights, and updating the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key and the identity authentication method based on the quantum key and quantum communication technology to avoid the possibility of being cracked, ensuring the security and reliability of the authentication, thereby effectively improving the security of the system.
[0031] Furthermore, it further includes:
[0032] Use the quantum access controller to receive a request for a new power distribution terminal to access the power grid system;
[0033] Use the quantum access controller to associate and bind the media access control address and the Internet protocol address of the new power distribution terminal with a quantum certificate according to the request, and upload the bound media access control address, the Internet protocol address, and the quantum certificate to the quantum access control center set in the regional management layer of the power grid system;
[0034] Use the quantum access control center to authenticate and authorize the new power distribution terminal based on the bound media access control address, the Internet protocol address, and the quantum certificate to obtain an authentication and authorization result;
[0035] If the authentication and authorization result is passed, use the quantum access control center to send a release message to the quantum access controller and create a file for the new power distribution terminal;
[0036] Use the quantum access controller to admit the new power distribution terminal and perform fingerprint detection on the new power distribution terminal to obtain the baseline standard of the new power distribution terminal;
[0037] Use the quantum access controller to upload the baseline standard of the new power distribution terminal to the quantum access control center.
[0038] As can be seen from the above description, the quantum access control center authenticates and authorizes the new power distribution terminal based on the bound media access control address, the Internet protocol address, and the quantum certificate to determine whether the new power distribution terminal is legal based on quantum technology and set authentication rules. When the authentication and authorization are passed, the quantum access control center creates a file for the new power distribution terminal for subsequent management and monitoring. The quantum access controller obtains the baseline standard of the new power distribution terminal through fingerprint detection and uploads it to the quantum access control center. By continuously improving the fingerprint baseline in this way, the quantum access control center can more accurately identify and manage the power distribution terminal, timely detect abnormal changes in the equipment, and ensure the safe and stable operation of the system.
[0039] Furthermore, it further includes:
[0040] Use the quantum access control center to collect network data of all power distribution terminals through a traffic probe;
[0041] Use the quantum access control center to analyze and extract the network data to obtain the network asset fingerprint of the power distribution terminal;
[0042] The quantum access control center is used to monitor the network asset fingerprint and the behavior of the distribution terminal based on the baseline standard of the distribution terminal, and obtain a monitoring result;
[0043] If the monitoring result shows that the network asset fingerprint or the behavior does not conform to the baseline standard of the distribution terminal, the quantum access control center is used to output a security warning message and perform Address Resolution Protocol (ARP) spoofing.
[0044] As can be seen from the above description, the quantum access control center continuously monitors the network asset fingerprints and behaviors of all distribution terminals, and real-time grasps the characteristic changes of the distribution terminals. When the network asset fingerprint or behavior does not conform to the baseline standard of the distribution terminal, it is determined that there may be a risk of illegal access or a security problem with the terminal. The quantum access control center will immediately issue a security warning and also adopt the technical means of ARP spoofing to prevent the illegal access of the distribution terminal, thus effectively ensuring the security of the system.
[0045] Further, before the quantum access controller disposed at the sub-station of the power grid system accesses the network through the aggregation port, it further includes:
[0046] The quantum access controller disposed at the sub-station of the power grid system and / or the quantum authentication switch disposed at the important site of the power grid system are used to send an authentication request to the quantum access control center disposed at the regional management layer of the power grid system, and the authentication request includes the quantum key of the quantum access controller and / or the quantum authentication switch;
[0047] The quantum access control center is used to proofread the quantum key of the quantum access controller and / or the quantum authentication switch based on the quantum key system, and obtain a proofreading result;
[0048] If the proofreading result is passed, the quantum access control center is used to establish a file of the quantum access controller and / or the quantum authentication switch, and send an instruction to enable the access blocking function to the quantum access controller and / or the quantum authentication switch.
[0049] As described above, the quantum access controller and the quantum authentication switch can initiate an authentication request to the quantum access control center either individually or simultaneously. They need to prove their legitimate identities to be allowed to access the network. The quantum key is a key with extremely high security generated based on the principles of quantum mechanics. Its security stems from the characteristics such as the non-clonability and uncertainty of quantum states. The quantum access control center verifies the quantum keys of the quantum access controller and / or the quantum authentication switch based on the quantum key system. After successful verification, it establishes the profiles of the quantum access controller and / or the quantum authentication switch, and sends an instruction to enable the access blocking function to the quantum access controller and / or the quantum authentication switch, facilitating the management and subsequent monitoring of the devices, and endowing them with the right to prevent unauthorized devices from accessing the network, thereby ensuring system security.
[0050] Furthermore, it also includes:
[0051] The quantum access control center set in the regional management layer of the power grid system uploads the whitelist of the power distribution terminals that have obtained access to the authentication system for proxy authentication review;
[0052] The quantum access control center receives the data encapsulating the review result returned by the authentication system, and sends the data encapsulating the review result to the quantum access controller;
[0053] The quantum access controller analyzes the data encapsulating the review result to obtain the analyzed review result data, and sends the analyzed review result data to the quantum access control center;
[0054] The quantum access control center sends a release instruction to the quantum access controller based on the analyzed review result data;
[0055] The quantum access controller releases the power distribution terminal corresponding to the analyzed review result data.
[0056] As described above, it is also possible to achieve centralized management of the access of power distribution terminals through proxy authentication initiated by the quantum access control center in the form of issuing a whitelist, which can more efficiently ensure system security.
[0057] Please refer to Figure 2, a distribution communication network access control system, including a quantum access controller set at a sub-station of the power grid system, a quantum access control center set at the regional management layer of the power grid system, and a quantum authentication switch set at an important site of the power grid system. The quantum access controller includes a first memory, a first processor, and a first computer program stored on the first memory and executable on the first processor. The quantum access control center includes a second memory, a second processor, and a second computer program stored on the second memory and executable on the second processor. The quantum authentication switch includes a third memory, a third processor, and a third computer program stored on the third memory and executable on the third processor. When the first processor executes the first computer program, the following steps are implemented:
[0058] Access the network through the aggregation port and obtain the media access control address of the distribution terminal accessing the network based on the address resolution protocol;
[0059] Perform a legality check on the distribution terminal based on the media access control address and the quantum key to obtain a legality check result;
[0060] If the legality check result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the distribution terminal;
[0061] If the legality check result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller.
[0062] As can be seen from the above description, the beneficial effects of the present invention are as follows: The quantum access controller provided at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control address of the power distribution terminal accessing the network based on the address resolution protocol. The quantum access controller performs quantum authentication and legality verification on the power distribution terminal based on the media access control address and the quantum key. If the result is legal, it indicates that the terminal can access the network, and the media access control address in the address resolution protocol information of other network nodes under the layer-2 switch corresponding to the quantum access controller is updated to the media access control address of the power distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal to realize normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permission, and the media access control address in the address resolution protocol information of other network nodes under the layer-2 switch corresponding to the quantum access controller is updated to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key, and the identity authentication method based on the quantum key and quantum communication technology, avoiding the possibility of being cracked, ensuring the security and reliability of authentication, and thus effectively improving the security of the system.
[0063] Further, when the first processor executes the first computer program, the following steps are also implemented:
[0064] Receive a request for a new power distribution terminal to access the power grid system;
[0065] Associate and bind the media access control address and the Internet protocol address of the new power distribution terminal with the quantum certificate according to the request, and upload the bound media access control address, the Internet protocol address and the quantum certificate to the quantum access control center;
[0066] When the second processor executes the second computer program, the following steps are implemented:
[0067] Authenticate and authorize the new power distribution terminal based on the bound media access control address, the Internet protocol address and the quantum certificate to obtain an authentication and authorization result;
[0068] If the authentication and authorization result is passed, send a release message to the quantum access controller and create a file for the new power distribution terminal;
[0069] Further, when the first processor executes the first computer program, the following steps are also implemented:
[0070] Grant access to the new power distribution terminal and perform fingerprint detection on the new power distribution terminal to obtain the baseline standard of the new power distribution terminal;
[0071] Upload the baseline standard of the new power distribution terminal to the quantum access control center.
[0072] As can be seen from the above description, the quantum access control center authenticates and authorizes the new power distribution terminal based on the bound media access control address, Internet protocol address, and quantum certificate, and determines whether the new power distribution terminal is legal based on quantum technology and set authentication rules. When the authentication and authorization are passed, the quantum access control center creates a file for the new power distribution terminal for subsequent management and monitoring. The quantum access controller obtains the baseline standard of the new power distribution terminal through fingerprint detection and uploads it to the quantum access control center. In this way, by continuously improving the fingerprint baseline, the quantum access control center can more accurately identify and manage the power distribution terminal, timely detect abnormal changes in the device, and ensure the safe and stable operation of the system.
[0073] Further, when the second processor executes the second computer program, the following steps are also implemented:
[0074] Collect network data of all power distribution terminals through a traffic probe;
[0075] Analyze and extract the network data to obtain the network asset fingerprint of the power distribution terminal;
[0076] Monitor the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain a monitoring result;
[0077] If the monitoring result shows that the network asset fingerprint or the behavior does not match the baseline standard of the power distribution terminal, output a security warning message and perform Address Resolution Protocol (ARP) spoofing.
[0078] As can be seen from the above description, the quantum access control center continuously monitors the network asset fingerprints and behaviors of all power distribution terminals, and real-time grasps the characteristic changes of the power distribution terminals. When the network asset fingerprint or behavior does not match the baseline standard of the power distribution terminal, it is determined that the terminal may be at risk of illegal access or there is a security problem. The quantum access control center will immediately issue a security warning and also take the technical means of ARP spoofing to prevent illegal access to the power distribution terminal, thus effectively ensuring the security of the system.
[0079] Further, when the first processor executes the first computer program, and / or when the third processor executes the third computer program, the following steps are also implemented:
[0080] Send an authentication request to the quantum access control center set in the regional management layer of the power grid system, where the authentication request includes the quantum key of the quantum access controller and / or the quantum authentication switch.
[0081] When the second processor executes the second computer program, it also implements the following steps:
[0082] Based on the quantum key system, proofread the quantum key of the quantum access controller and / or the quantum authentication switch to obtain a proofreading result.
[0083] If the proofreading result is passed, establish a file for the quantum access controller and / or the quantum authentication switch, and send an instruction to enable the access blocking function to the quantum access controller and / or the quantum authentication switch.
[0084] As can be seen from the above description, the quantum access controller and the quantum authentication switch can initiate an authentication request to the quantum access control center separately or simultaneously, and need to prove their legitimate identities to be allowed to access the network. The quantum key is a key with extremely high security generated based on the principles of quantum mechanics, and its security stems from the characteristics of the non-clonability and uncertainty of quantum states. The quantum access control center proofreads the quantum key of the quantum access controller and / or the quantum authentication switch based on the quantum key system. After the proofreading is passed, a file for the quantum access controller and / or the quantum authentication switch is established, and an instruction to enable the access blocking function is sent to the quantum access controller and / or the quantum authentication switch, which facilitates the management and subsequent monitoring of the device, and endows them with the right to prevent unauthorized devices from accessing the network, thereby ensuring system security.
[0085] Furthermore, when the second processor executes the second computer program, it also implements the following steps:
[0086] Upload the whitelist of the power distribution terminals that have obtained access to the authentication system for proxy authentication review.
[0087] Receive the audit result encapsulation data returned by the authentication system, and send the audit result encapsulation data to the quantum access controller.
[0088] When the first processor executes the first computer program, it also implements the following steps:
[0089] Parse the audit result encapsulation data to obtain audit result parsing data, and send the audit result parsing data to the quantum access control center.
[0090] When the second processor executes the second computer program, it also implements the following steps:
[0091] Parse the data based on the audit result and send a release instruction to the quantum access controller;
[0092] When the first processor executes the first computer program, the following steps are also implemented:
[0093] Use the quantum access controller to release the power distribution terminal corresponding to the parsed data of the audit result.
[0094] As can be seen from the above description, proxy authentication initiated by the quantum access control center in the form of a whitelist can also be used to achieve centralized management of the access of power distribution terminals, and can more efficiently ensure system security.
[0095] The above method and system for access control of a power distribution communication network according to the present invention can be applied to a power grid system, which will be described below through specific embodiments:
[0096] Please refer to Figure 1 、 Figures 3 - 6 , Embodiment 1 of the present invention is:
[0097] A method for access control of a power distribution communication network, including the steps of:
[0098] S1. Use a quantum access controller (NAP) set at a sub-station of the power grid system and / or a quantum authentication switch set at an important site of the power grid system to send an authentication request to a quantum access control center (NAC) set at the regional management layer of the power grid system. The authentication request includes the quantum keys of the quantum access controller and / or the quantum authentication switch, as Figure 3 shown.
[0099] Among them, the quantum access controller and the quantum authentication switch can be newly accessed or powered on again.
[0100] S2. Use the quantum access control center to proofread the quantum keys of the quantum access controller and / or the quantum authentication switch based on the quantum key system to obtain a proofreading result.
[0101] S3. If the proofreading result is passed, use the quantum access control center to establish files of the quantum access controller and / or the quantum authentication switch, and send an instruction to turn on the access blocking function to the quantum access controller and / or the quantum authentication switch.
[0102] In an optional implementation manner, the physical port of the quantum authentication switch is default to a locked state. If the proofreading result is passed, the physical port changes to a released state for the power distribution terminal to access the Internet through the port. If the proofreading result is not passed, the physical port remains in the locked state.
[0103] The quantum authentication switch writes the quantum key into the key storage medium, and the key storage medium is applied to the quantum authentication switch.
[0104] In an alternative embodiment, the quantum access control center is utilized to continuously monitor the heartbeat and traffic probe of the quantum authentication switch to determine whether the quantum authentication switch is online.
[0105] S4. The quantum access controller disposed at the sub-station of the power grid system accesses the network through the aggregation port, and obtains the media access control (MAC) address of the power distribution terminal accessing the network based on the address resolution protocol (ARP).
[0106] In an alternative embodiment, the power distribution terminal may be a notebook, an Internet of Things terminal, etc.
[0107] S5. The quantum access controller performs quantum authentication legality verification on the power distribution terminal based on the media access control address and the quantum key to obtain a legality verification result.
[0108] S6. If the legality verification result is legal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the power distribution terminal.
[0109] S7. If the legality verification result is illegal, update the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum access controller to the media access control address of the quantum access controller. At this time, the actual terminal data in the network cannot be sent out to block and isolate the data of the illegal power distribution terminal.
[0110] For example, as Figure 4 shown, the specific deployment mode is to deploy 1 set of quantum access control centers at the access switch location of the city company, and deploy 1 quantum access controller at the aggregation switch of each site. The quantum access controller accesses the network through the Trunk port (port aggregation), obtains the MAC address of the power distribution terminal accessing the network through the ARP technology, and based on the MAC address and the quantum key, the quantum access controller performs quantum authentication legality verification on the power distribution terminal. If it is legal, update the MAC address in the ARP information of other network nodes (including switches and network terminals) under the same layer 2 switch to the MAC address of the power distribution terminal with successful authentication. If the legality verification is not passed, update the MAC address of the ARP information on the network node to the MAC address of the quantum access controller.
[0111] Unified authentication management is achieved through quantum key technology, making the permission management process for substations and power distribution stations more convenient. Authentication and access for security devices and proxy authentication for power distribution terminals are realized, achieving stronger security control capabilities. It uses the true random numbers of quantum keys to avoid the possibility of being cracked. At the same time, quantum authentication realizes an autonomous and controllable unified key source, greatly enhancing the security of the system.
[0112] In an alternative embodiment, it further includes:
[0113] Using the quantum access controller to receive a request for a new power distribution terminal to access the power grid system.
[0114] Using the quantum access controller to associate and bind the media access control address and Internet Protocol (IP) address of the new power distribution terminal with a quantum certificate according to the request, and uploading the bound media access control address, Internet Protocol address, and quantum certificate to the quantum access control center set in the regional management layer of the power grid system.
[0115] In an alternative embodiment, when uploading the bound media access control address, Internet Protocol address, and quantum certificate, it is transmitted through HTTPS (Hyper Text Transfer Protocol Secure), ensuring the security of data transmission.
[0116] Using the quantum access control center to authenticate and authorize the new power distribution terminal based on the bound media access control address, Internet Protocol address, and quantum certificate to obtain an authentication and authorization result.
[0117] If the authentication and authorization result is passed, the quantum access control center is used to send a release message to the quantum access controller and create a file for the new power distribution terminal.
[0118] Using the quantum access controller to admit the new power distribution terminal and perform fingerprint detection on the new power distribution terminal to obtain the baseline standard of the new power distribution terminal.
[0119] Using the quantum access controller to upload the baseline standard of the new power distribution terminal to the quantum access control center.
[0120] In an alternative embodiment, as Figure 5 shown, it further includes:
[0121] Using the quantum access control center to collect network data of all power distribution terminals through a traffic probe.
[0122] The network data is analyzed and extracted by using the quantum access control center to obtain a network asset fingerprint of the power distribution terminal.
[0123] In an optional implementation, the network asset fingerprint includes a MAC address, a power distribution terminal name, an operating system version feature, and / or a network open port feature.
[0124] The quantum access control center is used to monitor the network asset fingerprint and the behavior of the distribution terminal based on the baseline standard of the distribution terminal to obtain a monitoring result.
[0125] If the monitoring result is that the network asset fingerprint or the behavior does not meet the baseline standard of the distribution terminal, the quantum access control center is used to output a security warning message and perform address resolution protocol spoofing to prevent illegal access to the distribution terminal.
[0126] In addition to verifying the fingerprint information of the distribution terminal to detect anomalies, in an optional implementation, it also includes: performing weak password monitoring or intrusion detection on the distribution terminal. Among them, the weak password monitoring of the distribution terminal includes: using the quantum access controller to actively scan the distribution terminal to determine whether there is a weak password, and if so, uploading the security alarm information to the quantum access control center. Performing intrusion detection on the distribution terminal includes: using the quantum access controller to perform intrusion detection on the network traffic of the distribution terminal to determine whether there is a network attack behavior, and if so, uploading the security alarm information to the quantum access control center.
[0127] In an optional implementation, after the security alarm information is output, the local personnel will conduct a comprehensive assessment and analysis. If any illegal behavior is found, the distribution station operation and maintenance personnel will be notified through a dedicated APP to conduct an investigation; if it is determined to be a legal behavior after investigation, the quantum access control center will be used to update the baseline standard of the distribution terminal and confirm the alarm; if it is determined to be an illegal behavior after investigation, the quantum access control center will be used to link the quantum access controller to block access to the distribution terminal. At the same time, the quantum access control center will link the quantum authentication switch to close the physical port and adjust the strategy.
[0128] In an optional implementation, it also includes:
[0129] The quantum access control center set up at the regional management level of the power grid system uploads the white list of distribution terminals that have obtained access to the authentication system for proxy authentication review.
[0130] In an optional implementation, when uploading the whitelist, it is encrypted and transmitted via HTTPS.
[0131] The quantum access control center is used to receive the audit result encapsulation data returned by the authentication system and send the audit result encapsulation data to the quantum access controller.
[0132] The quantum access controller is used to parse the audit result encapsulation data to obtain audit result parsing data and send the audit result parsing data to the quantum access control center.
[0133] The quantum access control center is used to send a release instruction to the quantum access controller based on the audit result parsing data.
[0134] The quantum access controller is used to release the power distribution terminal corresponding to the audit result parsing data.
[0135] Among them, as Figure 6 shown, the authentication system consists of a sending end and a receiving end, and the two are connected through a quantum channel and a classical channel. The quantum channel is used to transmit quantum state information, and the classical channel is used to transmit other information except quantum states.
[0136] The sending end consists of a decoy state light source, a quantum state modulation module, a quantum random number generator, and a data processing module. Among them, the functions of the decoy state light source include randomly modulating the intensity of optical pulses to prepare signal state optical pulses and decoy state optical pulses. The quantum state modulation module loads encoded information on the signal state optical pulses and decoy state optical pulses according to the random sequence input by the quantum random number generator to complete the preparation of the quantum state. The quantum state can be characterized by physical quantities such as polarization, phase, time, spin, and momentum.
[0137] The receiving end consists of a detection module, a quantum state demodulation module, a quantum random number generator, and a data processing module. The functions of the quantum demodulation module include measurement basis selection and quantum state measurement, and the selection of the measurement basis is random. Subsequently, the detection module detects the measured optical pulses. The receiving end informs the sending end of the selected measurement basis information through the classical channel, and the sending end compares the encoding basis used in quantum state preparation with the measurement basis of the receiving end. The data processing modules of both parties negotiate through the classical channel to generate a symmetric quantum key through processes such as basis comparison, error correction, privacy amplification, and consistency verification.
[0138] In an alternative embodiment, it further includes: the quantum access control center performs traffic analysis on the network deployment network probe to obtain a traffic analysis result and uploads the traffic analysis result to the network security monitoring platform for situation awareness analysis, early warning, and linkage processing.
[0139] Please refer to Figure 2 , the second embodiment of the present invention is:
[0140] A power distribution communication network access control system includes a quantum access controller disposed at a sub-station of the power grid system, a quantum access control center disposed at the regional management layer of the power grid system, and a quantum authentication switch disposed at an important site of the power grid system. The quantum access controller includes a first memory, a first processor, and a first computer program stored on the first memory and executable on the first processor. The quantum access control center includes a second memory, a second processor, and a second computer program stored on the second memory and executable on the second processor. The quantum authentication switch includes a third memory, a third processor, and a third computer program stored on the third memory and executable on the third processor. When the first processor executes the first computer program, it implements each step executed by the quantum access controller in the power distribution communication network access control method in Embodiment 1. When the second processor executes the second computer program, it implements each step executed by the quantum access control center in the power distribution communication network access control method in Embodiment 1. When the third processor executes the third computer program, it implements each step executed by the quantum authentication switch in the power distribution communication network access control method in Embodiment 1.
[0141] In summary, the present invention provides a method and system for access control of a distribution communication network. A quantum access controller disposed at a sub-station of the power grid system accesses the network through an aggregation port, and obtains the media access control address of a distribution terminal accessing the network based on the address resolution protocol. The quantum access controller performs quantum authentication and legality verification on the distribution terminal based on the media access control address and a quantum key. If the result is legal, it indicates that the terminal can access the network, and the media access control address in the address resolution protocol information of other network nodes under the layer-2 switch corresponding to the quantum access controller is updated to the media access control address of the distribution terminal, so that other network nodes can correctly identify and communicate with the legal terminal to achieve normal network interaction. If the result is illegal, it means that the terminal may have security risks or does not have access permissions, and the media access control address in the address resolution protocol information of other network nodes under the layer-2 switch corresponding to the quantum access controller is updated to the media access control address of the quantum access controller. In this way, when other network nodes send data, the data originally intended for the illegal terminal will be sent to the quantum access controller, blocking and isolating the data communication between the illegal terminal and other devices in the network, preventing the illegal terminal from obtaining or tampering with data, and using the true random number of the quantum key, based on the quantum key and the identity authentication method of quantum communication technology, avoiding the possibility of being cracked, ensuring the security and reliability of authentication, and thus effectively improving the security of the system. In addition, the quantum access control center authenticates and authorizes a new distribution terminal based on the bound media access control address, Internet protocol address and quantum certificate to determine whether the new distribution terminal is legal based on quantum technology and the set authentication rules. When the authentication and authorization pass, the quantum access control center creates a file for the new distribution terminal for subsequent management and monitoring. The quantum access controller obtains the baseline standard of the new distribution terminal through fingerprint detection and uploads it to the quantum access control center. By continuously improving the fingerprint baseline in this way, the quantum access control center can more accurately identify and manage distribution terminals, timely detect abnormal changes in devices, and ensure the safe and stable operation of the system.
[0142] The above are only embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent transformation made using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, shall be included in the patent protection scope of the present invention by the same token.
Claims
1. A distribution communication network access control method, characterized in that: Includes steps: Using a quantum access controller set at a sub-site of the power grid system to access the network through an aggregation port, and obtaining a media access control address of a distribution terminal accessing the network based on an address resolution protocol; Using the quantum access controller to perform a quantum authentication legitimacy check on the power distribution terminal based on the media access control address and the quantum key to obtain a legitimacy check result; If the validity check result is valid, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the power distribution terminal; If the result of the legitimacy check is illegal, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the quantum admission controller; Also includes: Using the quantum access controller to receive a request from a new power distribution terminal to access the power grid system; Using the quantum access controller to associate and bind the media access control address and the Internet Protocol address of the new distribution terminal with the quantum certificate according to the request, and uploading the bound media access control address, the Internet Protocol address and the quantum certificate to a quantum access control center set at the regional management layer of the power grid system; Using the quantum access control center to authenticate the new power distribution terminal based on the bound media access control address, the Internet protocol address and the quantum certificate, to obtain an authentication result; If the authentication result is passed, the quantum access control center sends release information to the quantum access controller, and files the new power distribution terminal; Using the quantum access controller to access the new power distribution terminal, and performing fingerprint detection on the new power distribution terminal to obtain a baseline standard of the new power distribution terminal; Uploading the baseline standard of the new power distribution terminal to the quantum access control center using the quantum access controller; Before the quantum admission controller provided at the sub-site of the power grid system is used to access the network through the aggregation port, the method further includes: Using a quantum access controller disposed at a sub-site of a power grid system and / or a quantum authentication switch disposed at an important site of the power grid system, an authentication request is sent to a quantum access control center disposed at a regional management layer of the power grid system, wherein the authentication request includes a quantum key of the quantum access controller and / or the quantum authentication switch; Using the quantum access control center to calibrate the quantum key of the quantum access controller and / or the quantum authentication switch based on a quantum key system to obtain a calibration result; If the proofreading result is passed, the quantum access control center is used to create a file of the quantum access controller and / or the quantum authentication switch, and an access blocking function activation instruction is sent to the quantum access controller and / or the quantum authentication switch.
2. A distribution communication network access control method according to claim 1, characterized in that: Also includes: Using the quantum access control center to collect network data of all power distribution terminals through flow probes; Analyzing and extracting the network data using the quantum access control center to obtain a network asset fingerprint of the power distribution terminal; Using the quantum access control center to monitor the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain a monitoring result; If the monitoring result is that the network asset fingerprint or the behavior does not meet the baseline standard of the distribution terminal, the quantum access control center is used to output a security warning message and perform address resolution protocol spoofing.
3. A distribution communication network access control method according to claim 1, characterized in that: Also includes: The quantum access control center set up at the regional management level of the power grid system is used to upload the white list of distribution terminals that have obtained access to the authentication system for proxy authentication review; Using the quantum access control center to receive the audit result encapsulation data returned by the authentication system, and sending the audit result encapsulation data to the quantum access controller; Utilizing the quantum access controller to parse the audit result encapsulation data to obtain audit result parsing data, and sending the audit result parsing data to the quantum access control center; Utilizing the quantum access control center to parse data based on the audit result and send a release instruction to the quantum access controller; The quantum access controller is used to release the distribution terminal corresponding to the audit result analysis data.
4. A distribution communication network access control system for implementing a distribution communication network access control method according to any one of claims 1 to 3, comprising a quantum access controller arranged at a sub-site of a power grid system, a quantum access control center arranged at a regional management level of the power grid system, and a quantum authentication switch arranged at an important site of the power grid system, wherein the quantum access controller comprises a first memory, a first processor, and a first computer program stored in the first memory and executable on the first processor, the quantum access control center comprises a second memory, a second processor, and a second computer program stored in the second memory and executable on the second processor, the quantum authentication switch comprises a third memory, a third processor, and a third computer program stored in the third memory and executable on the third processor, characterized in that: When the first processor executes the first computer program, the following steps are implemented: Accessing the network through the aggregation port, and obtaining the media access control address of the power distribution terminal accessing the network based on the address resolution protocol; Performing a quantum authentication legitimacy check on the power distribution terminal based on the media access control address and the quantum key to obtain a legitimacy check result; If the validity check result is valid, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the power distribution terminal; If the legitimacy check result is illegal, the media access control address in the address resolution protocol information of other network nodes under the layer 2 switch corresponding to the quantum admission controller is updated to the media access control address of the quantum admission controller.
5. A distribution communication network access control system according to claim 4, characterized in that: When the first processor executes the first computer program, the following steps are implemented: Receiving a request from a new power distribution terminal to access the power grid system; Associating and binding the media access control address and the Internet Protocol address of the new power distribution terminal with the quantum certificate according to the request, and uploading the bound media access control address, the Internet Protocol address and the quantum certificate to the quantum access control center; When the second processor executes the second computer program, the following steps are implemented: Authenticating the new power distribution terminal based on the bound media access control address, the Internet Protocol address and the quantum certificate to obtain an authentication result; If the authentication result is passed, the release information is sent to the quantum access controller, and the new power distribution terminal is archived; When the first processor executes the first computer program, the following steps are further implemented: Allowing access to the new power distribution terminal and performing fingerprint detection on the new power distribution terminal to obtain a baseline standard of the new power distribution terminal; The baseline standard of the new power distribution terminal is uploaded to the quantum access control center.
6. A distribution communication network access control system according to claim 5, characterized in that: When the second processor executes the second computer program, the second processor further implements the following steps: Collect network data from all distribution terminals through flow probes; Analyzing and extracting the network data to obtain a network asset fingerprint of the power distribution terminal; Monitoring the network asset fingerprint and the behavior of the power distribution terminal based on the baseline standard of the power distribution terminal to obtain a monitoring result; If the monitoring result is that the network asset fingerprint or the behavior does not conform to the baseline standard of the power distribution terminal, a security warning message is output and address resolution protocol spoofing is performed.
7. A distribution communication network access control system according to claim 4, characterized in that: When the first processor executes the first computer program, and / or when the third processor executes the third computer program, the following steps are further implemented: Sending an authentication request to a quantum access control center disposed at a regional management layer of the power grid system, wherein the authentication request includes a quantum key of the quantum access controller and / or the quantum authentication switch; When the second processor executes the second computer program, the second processor further implements the following steps: Proofreading the quantum key of the quantum access controller and / or the quantum authentication switch based on a quantum key system to obtain a proofreading result; If the proofreading result is passed, a file of the quantum access controller and / or the quantum authentication switch is created, and an access blocking function activation instruction is sent to the quantum access controller and / or the quantum authentication switch.
8. A distribution communication network access control system according to claim 4, characterized in that: When the second processor executes the second computer program, the second processor further implements the following steps: Upload the whitelist of distribution terminals that have been granted access to the authentication system for proxy authentication review; Receiving the audit result encapsulated data returned by the authentication system, and sending the audit result encapsulated data to the quantum admission controller; When the first processor executes the first computer program, the following steps are further implemented: Parsing the audit result encapsulated data to obtain audit result parsed data, and sending the audit result parsed data to the quantum access control center; When the second processor executes the second computer program, the second processor further implements the following steps: Sending a release instruction to the quantum admission controller based on the audit result parsed data; When the first processor executes the first computer program, the following steps are further implemented: The quantum access controller is used to release the distribution terminal corresponding to the audit result analysis data.
Citation Information
Patent Citations
Terminal security access control method
CN104363228A
Electric power wide area industrial control network communication method based on quantum communication technology
CN106685650A