A quantum cryptography-based secure data transmission system, method, and medium for power grids.
By generating one-time session ciphers and quantum keys using quantum cryptography, and combining dual authentication and quantum encrypted transmission, the security issues in power grid data transmission are solved, ensuring data confidentiality, integrity, and availability, and improving the security and reliability of power grid data communication.
Patent Information
- Application Number
- CN202510521117.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2045-04-24
AI Technical Summary
The existing power grid data security transmission management system lacks effective encryption and monitoring mechanisms during data transmission, which increases the risk of data loss and leakage, and fails to effectively cope with complex and diverse security threats, affecting the stable operation of the power grid and the safety of users' electricity consumption.
A quantum cryptography-based power grid data security transmission system is adopted. A one-time session cipher and quantum key are generated through a quantum key distribution module. Combined with a communication security management module, dual authentication and quantum encrypted transmission are performed to ensure the confidentiality, integrity and availability of data transmission.
It achieves full-process security protection for power grid data transmission, improves the security and reliability of power grid data communication, and meets the high requirements of smart grids for data security.
Smart Images

Figure CN120389855B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power communication security technology, and in particular to a power grid data security transmission system, method and medium based on quantum cryptography. Background Technology
[0002] With the continuous development of smart grid technology, the application of smart communication and information processing technology in power energy systems is becoming increasingly widespread, covering multiple links in the power system such as power generation, transmission, distribution, and users. The popularization of intelligent metering equipment has led to the generation of massive amounts of power data. This data is of great significance for energy planning and optimization of energy production and distribution. However, the rapid expansion of data scale and the increase in interaction complexity have also brought new information security challenges. In particular, the security risks in the data transmission process are becoming increasingly prominent, and there is an urgent need to introduce more advanced communication security technologies to ensure the security of smart grid data throughout its entire life cycle.
[0003] However, while existing power grid data security transmission management systems can identify and restrict abnormal data access to a certain extent, reducing the frequency of unauthorized access events, many problems still exist. These systems primarily focus on monitoring and restricting abnormal access to power grid data, neglecting the security of data transmission after access is granted. During data transmission, the lack of effective encryption and monitoring mechanisms significantly increases the risk of data loss and leakage. This not only leads to the leakage of sensitive information but also threatens the stable operation of the power grid and the electricity safety of users. Therefore, improving the security control level of the data transmission process and ensuring the confidentiality, integrity, and availability of power grid data during transmission has become a critical issue that urgently needs to be addressed in the field of power grid data security.
[0004] In summary, existing power grid data security transmission management systems still have significant shortcomings and are unable to effectively cope with increasingly complex and diverse security threats. Therefore, there is an urgent need for a more secure and reliable data security transmission technology to solve these problems and ensure the security and integrity of data transmission in smart grids. Summary of the Invention
[0005] To address the above technical problems, this invention provides a quantum cryptography-based secure data transmission system, method, and medium for power grids.
[0006] In a first aspect, the present invention provides a quantum cryptography-based secure data transmission system for power grids, comprising:
[0007] The power grid data access module is used to determine the data transmission method of the target response end based on the power grid data access application uploaded by the power grid data requesting end, and to extract the identity identifier of the power grid data requesting end and the identity identifier of the target response end based on the data transmission method.
[0008] The quantum key distribution module is used to obtain the original shared key pre-stored by both communicating parties based on the identity identifier of the receiving power grid data requester and the identity identifier of the target responder, generate a one-time session password using a quantum random number generator, generate a quantum key based on the one-time session password and the original shared key, and distribute the quantum key to the power grid data requester and the target responder through a quantum key distribution protocol.
[0009] The communication security management module is used to parse the shared key information from the quantum key received from the target response end, obtain the parsed shared key information, and match and verify the original shared key with the parsed shared key information to generate a communication security verification result.
[0010] The power grid security communication module is used to encrypt the power grid data to be transmitted using the one-time session password when the communication security verification result is successful, generate encrypted power grid data, and transmit the encrypted power grid data to the target response end.
[0011] In a further embodiment, the quantum key distribution module includes a shared key request unit, a shared key control unit, a session key generation unit, a quantum key generation unit, and a quantum key distribution unit;
[0012] The shared key request unit is used to receive the grid data request terminal identity identifier and the target response terminal identity identifier sent by the grid data access module, generate a shared key request based on the grid data request terminal identity identifier and the target response terminal identity identifier, and send the shared key request to the shared key control unit.
[0013] The shared key control unit is used to respond to the shared key request by retrieving the original shared key pre-stored by the power grid data request terminal and the target response terminal from the database, and feeding back the original shared key to the quantum key generation unit;
[0014] The session key generation unit is used to generate a one-time session password using a quantum random number generator;
[0015] The quantum key generation unit is used to perform an XOR operation on the original shared key and the one-time session password, and add the grid data request terminal identity identifier to generate a quantum key;
[0016] The quantum key distribution unit is used to distribute the quantum key to the power grid data requester and the target response end through a quantum key distribution protocol.
[0017] In a further implementation, the communication security management module includes a quantum key extraction unit, a shared key matching unit, and a verification decision unit;
[0018] The quantum key extraction unit is used to parse the shared key information from the quantum key received from the target response end to obtain the parsed shared key information;
[0019] The shared key matching unit is used to compare the original shared key with the parsed shared key information to obtain a matching verification result;
[0020] The verification decision unit is used to verify the identities of both communicating parties based on the matching verification results. When the original shared key and the parsed shared key information are consistent, the unit determines that the identity verification of both communicating parties is successful and allows the power grid data requester to communicate with the target responseer. When the original shared key and the parsed shared key information are inconsistent, the unit determines that the identity verification of both communicating parties fails and refuses the power grid data requester to communicate with the target responseer.
[0021] In a further embodiment, the communication security management module also includes a quantum transmission acquisition unit and a quantum encrypted transmission unit;
[0022] The quantum transmission acquisition unit is used to acquire, within a preset statistical period, the number of quantum key generation statistics, the number of authentication statistics, and the quantum encryption transmission channel information under the current communication environment during the quantum encryption transmission process when the authentication of both parties is successful.
[0023] The quantum encryption transmission unit is used to calculate quantum communication performance indicators based on the number of quantum key generation statistics, the number of authentication statistics, and the quantum encryption transmission channel information under the current communication environment; wherein, the quantum communication performance indicators include key distribution success rate coefficient, communication verification accuracy coefficient, quantum channel performance coefficient, and quantum encryption transmission stability coefficient.
[0024] In a further embodiment, the communication security management module also includes a power grid communication security assessment module;
[0025] The power grid communication security assessment module is used to calculate the power grid data communication security index based on the quantum communication performance index, and compare the power grid data communication security index with the preset power grid data communication security value. If the power grid data communication security index meets the preset power grid data communication security value, the current power grid data communication is determined to be secure, and a communication security verification result is generated.
[0026] In a further implementation scheme, the calculation process for the power grid data communication security index is as follows:
[0027] The quantum channel quality correction factor is obtained by taking the square root of the quantum channel performance coefficient and then performing an exponential operation.
[0028] The sum of the squares of the key distribution success rate coefficient, the communication verification accuracy coefficient, and the quantum encryption transmission stability coefficient is calculated to obtain a comprehensive performance index.
[0029] Multiplying the comprehensive performance index and the quantum channel quality correction factor yields the power grid data communication security index.
[0030] In a further implementation, the key allocation success rate coefficient is the ratio of the number of successful quantum key generation to the number of quantum key generation attempts during the quantum encryption transmission process within a preset statistical period.
[0031] The communication verification accuracy coefficient is the ratio of the number of times the identity is correctly verified to the sum of the number of times the identity is correctly verified and the number of times the identity is incorrectly verified.
[0032] The quantum channel performance coefficient is the ratio of channel capacity to the product of the natural logarithm of the quantum bit error rate and the natural logarithm of the signal transmission path loss.
[0033] In a further implementation, the calculation process for the quantum encrypted transmission stability coefficient is as follows:
[0034] Within a preset statistical period, the ratios of the original data volume before all successful quantum encryption transmissions to the corresponding transmission time are summed to obtain the original transmission efficiency sum. Based on the original transmission efficiency sum and the number of quantum encryption transmissions within the preset statistical period, the transmission efficiency factor is calculated.
[0035] The ratios of the data volume after all successful quantum encryption transmissions to the original data volume are summed to obtain the total data integrity. The data integrity factor is then calculated based on the total data integrity and the number of successful quantum encryption transmissions within a preset statistical period.
[0036] The ratio of the amount of data recovered to the time required to recover the quantum encrypted transmission in all failed quantum encrypted transmissions is summed to obtain the total fault recovery efficiency. The fault recovery efficiency factor is calculated based on the total fault recovery efficiency and the number of failed quantum encrypted transmissions within a preset statistical period.
[0037] Multiplying the transmission efficiency factor, the data integrity factor, and the fault recovery efficiency factor together yields the quantum encryption transmission stability coefficient.
[0038] Secondly, the present invention provides a method for secure transmission of power grid data based on quantum cryptography, the method comprising the following steps:
[0039] The data transmission method of the target response terminal is determined based on the power grid data access request uploaded by the power grid data request terminal, and the identity identifier of the power grid data request terminal and the identity identifier of the target response terminal are extracted based on the data transmission method.
[0040] The original shared key pre-stored by both communicating parties is obtained based on the identity identifiers of the power grid data requesting end and the target response end, and a one-time session cipher is generated using a quantum random number generator;
[0041] A quantum key is generated based on the one-time session cipher and the original shared key, and the quantum key is distributed to the power grid data requester and the target responseer through a quantum key distribution protocol;
[0042] The shared key information is parsed from the quantum key received from the target response end to obtain the parsed shared key information. The original shared key is then matched and verified with the parsed shared key information to generate a communication security verification result.
[0043] When the communication security verification result is successful, the one-time session password is used to encrypt the power grid data to be transmitted, generating encrypted power grid data, and the encrypted power grid data is transmitted to the target response end.
[0044] Thirdly, the present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described method.
[0045] This invention provides a quantum cryptography-based secure power grid data transmission system, method, and medium. The system includes a power grid data access module for determining the data transmission method of the target response end based on a power grid data access request uploaded by the power grid data requesting end, and extracting the identity identifiers of the power grid data requesting end and the target response end based on the data transmission method; a quantum key distribution module for obtaining the original shared key pre-stored by both communicating parties based on the received identity identifiers of the power grid data requesting end and the target response end, generating a one-time session cipher using a quantum random number generator, generating a quantum key based on the one-time session cipher and the original shared key, and distributing the quantum key to the power grid data requesting end and the target response end through a quantum key distribution protocol; a communication security management module for parsing the shared key information from the quantum key received by the target response end, obtaining parsed shared key information, matching and verifying the original shared key with the parsed shared key information, and generating a communication security verification result; and a power grid secure communication module for encrypting the power grid data to be transmitted using the one-time session cipher when the communication security verification result is successful, generating encrypted power grid data, and transmitting the encrypted power grid data to the target response end. Compared with existing technologies, this system achieves full-process security protection for power grid data transmission through a collaborative mechanism of dynamic quantum key allocation, dual authentication, and quantum encrypted transmission. It ensures the confidentiality, integrity, and availability of power grid data during transmission, significantly improves the security level of power grid data communication, and meets the high requirements of smart grids for data security. Attached Figure Description
[0046] Figure 1 This is a block diagram of a quantum cryptography-based secure data transmission system for power grids provided in an embodiment of the present invention;
[0047] Figure 2 This is a schematic diagram of the process of a quantum cryptography-based secure data transmission method for power grids provided in an embodiment of the present invention. Detailed Implementation
[0048] The embodiments of the present invention are described in detail below with reference to the accompanying drawings. The embodiments are given for illustrative purposes only and should not be construed as limiting the present invention. The accompanying drawings are for reference and illustration only and do not constitute a limitation on the scope of patent protection of the present invention, because many changes can be made to the present invention without departing from the spirit and scope of the present invention.
[0049] refer to Figure 1 This invention provides a quantum cryptography-based secure data transmission system for power grids, such as... Figure 1 As shown, the power grid data security transmission system includes a power grid data access module 101, a quantum key distribution module 102, a communication security management module 103, and a power grid security communication module 104 connected in sequence.
[0050] In some implementations, the power grid data access module 101 is used to determine the data transmission method of the target response terminal based on the power grid data access application uploaded by the power grid data request terminal, and extract the identity identifier of the power grid data request terminal and the identity identifier of the target response terminal based on the data transmission method.
[0051] Specifically, the power grid data access module receives a power grid data access application submitted by the power grid data requesting end. The power grid data access application includes at least the requesting end account ID and the identification information of the target power grid data to be accessed. This requesting end account ID serves as the unique identifier of the requesting end and is used for subsequent authentication and traceability. After receiving the power grid data access application, the power grid data access module 101 will search the preset power grid data transmission permission database according to the identification information of the target power grid data to be accessed, and obtain the target power grid data response end account ID with the permission to access the target power grid data and the target response end data transmission method corresponding to the target power grid data.
[0052] The power grid data access module determines the data transmission method of the target response end. If the data transmission method is determined to be quantum encrypted transmission, considering the extremely high security requirements of quantum encrypted transmission, this embodiment needs to establish a secure communication channel between the requesting and responding ends. In this case, the power grid data access module will transmit the account IDs of the power grid data requesting end and the target response end to the quantum key distribution module, so that the quantum key distribution module can generate quantum keys for the requesting and responding ends based on these two account IDs and start the quantum encrypted transmission process, thereby ensuring the security of subsequent data transmission. Conversely, if the data transmission method of the target response end is determined to be a non-quantum encrypted transmission type, such as traditional symmetric encryption transmission or plaintext transmission, considering that these transmission methods have relatively low security requirements and do not require the intervention of the quantum key distribution module, the power grid data access module will not transmit data to the quantum key distribution module, but will continue to process subsequent data access requests according to the corresponding non-quantum encrypted transmission process. In summary, when quantum encrypted transmission is required, the power grid data access module can extract the identity identifiers of the power grid data requesting end and the target response end based on the data transmission method, ensuring the security and accuracy of data transmission.
[0053] In some implementations, the quantum key distribution module 102 is used to obtain the original shared key pre-stored by both communicating parties based on the received grid data requester identity identifier and target response identifier, generate a one-time session cipher using a quantum random number generator, generate a quantum key based on the one-time session cipher and the original shared key, and distribute the quantum key to the grid data requester and the target response end through a quantum key distribution protocol. In this embodiment, the quantum key distribution module includes a shared key request unit, a shared key control unit, a session key generation unit, a quantum key generation unit, and a quantum key distribution unit. Specific functional descriptions are as follows:
[0054] The shared key request unit is used to receive the grid data request terminal identity identifier and the target response terminal identity identifier sent by the grid data access module, generate a shared key request based on the grid data request terminal identity identifier and the target response terminal identity identifier, and send the shared key request to the shared key control unit.
[0055] The shared key control unit is used to respond to the shared key request by retrieving the original shared key pre-stored by the power grid data request terminal and the target response terminal from the database, and feeding back the original shared key to the quantum key generation unit;
[0056] The session key generation unit is used to generate a one-time session password using a quantum random number generator;
[0057] The quantum key generation unit is used to perform an XOR operation on the original shared key and the one-time session password, and add the grid data request terminal identity identifier to generate a quantum key;
[0058] The quantum key distribution unit is used to distribute the quantum key to the power grid data requester and the target response end through a quantum key distribution protocol.
[0059] Specifically, after receiving the power grid data requester account ID and target response account ID transmitted from the power grid data access module, the quantum key distribution module 102 immediately initiates the interaction process with the shared key control module. The shared key request unit sends shared key request information to the shared key control module according to the identity identifiers of the power grid data requester and the target response, and obtains the pre-stored original shared keys of the power grid data requester and the target response corresponding to the received account IDs. After receiving the request, the shared key control module performs a rapid search and matching based on the pre-established mapping relationship database between account IDs and shared keys to obtain the shared keys of the power grid data requester and the target response, and returns them to the quantum key generation unit. At the same time, the session key generation unit starts the quantum random number generator. The quantum random number generator is based on the principles of quantum mechanics and generates truly random numbers. These random numbers are used to generate a one-time session cipher. This one-time session cipher has a high degree of randomness and unpredictability, providing a key security factor for the subsequent generation of quantum keys.
[0060] Then, the quantum key generation unit performs an XOR operation on the obtained shared key and the generated one-time session password to extract the account ID of the power grid data requester, and appends it to the end of the processed key. This step not only enhances the uniqueness and traceability of the key, but also facilitates authentication and key management in the subsequent data transmission process. After the above processing, the quantum key is finally generated. Finally, the quantum key distribution unit distributes the generated quantum key to the power grid data requester and the target response end through a quantum key distribution protocol (such as the BB84 protocol). The quantum key distribution protocol ensures the security, integrity and confidentiality of the quantum key during transmission, preventing the key from being stolen or tampered with during transmission, and providing a solid guarantee for the secure transmission of power grid data.
[0061] In some implementations, the communication security management module 103 is used to parse the shared key information from the quantum key received from the target response end, obtain the parsed shared key information, and match and verify the original shared key with the parsed shared key information to generate a communication security verification result.
[0062] In some implementations, the communication security management module includes a quantum key extraction unit, a shared key matching unit, and a verification decision unit;
[0063] The quantum key extraction unit is used to parse the shared key information from the quantum key received from the target response end to obtain the parsed shared key information;
[0064] The shared key matching unit is used to compare the original shared key with the parsed shared key information to obtain a matching verification result;
[0065] The verification decision unit is used to verify the identities of both communicating parties based on the matching verification results. When the original shared key and the parsed shared key information are consistent, the unit determines that the identity verification of both communicating parties is successful and allows the power grid data requester to communicate with the target responseer. When the original shared key and the parsed shared key information are inconsistent, the unit determines that the identity verification of both communicating parties fails and refuses the power grid data requester to communicate with the target responseer.
[0066] Specifically, the quantum key extraction unit in the communication security management module extracts key information from the quantum key returned by the target response end. This information includes: the account ID of the power grid data requester (used to uniquely identify the requester), the parsed shared key information, and the session key (used to establish a temporary communication session). After successfully extracting the power grid data requester's account ID, the shared key matching unit compares the original shared key information fed back by the shared key control module with the shared key information extracted from the quantum key, ensuring that each bit of the shared key information is completely consistent. This verifies the validity of the shared key between the two parties. If the shared key information is consistent, the verification decision unit determines that the identity verification of both parties is successful, allowing communication. The extracted session key is then sent to the target response end of the power grid data through a secure channel, enabling both parties to establish a secure temporary communication session based on this session key. Conversely, if the shared key information is inconsistent, the verification decision unit determines that the identity verification of both parties has failed, rejecting communication and taking measures such as recording abnormal logs and triggering alarms to prevent potential security threats. This effectively verifies the identity of the target response end of the power grid data, ensuring that only legitimate requesters can establish a secure communication session with the target response end.
[0067] In some implementations, the communication security management module further includes a quantum transmission acquisition unit and a quantum encryption transmission unit, the specific functions of which are described below:
[0068] The quantum transmission acquisition unit is used to acquire, within a preset statistical period, the number of quantum key generation statistics, the number of authentication statistics, and the quantum encryption transmission channel information under the current communication environment during the quantum encryption transmission process when the authentication of both parties is successful.
[0069] The quantum encryption transmission unit is used to calculate quantum communication performance indicators based on the number of quantum key generation statistics, the number of authentication statistics, and the quantum encryption transmission channel information under the current communication environment; wherein, the quantum communication performance indicators include key distribution success rate coefficient, communication verification accuracy coefficient, quantum channel performance coefficient, and quantum encryption transmission stability coefficient.
[0070] Specifically, when both communicating parties pass authentication, the quantum transmission acquisition unit collects the quantum key generation statistics, authentication statistics, and quantum encryption transmission channel information under the current communication environment within a preset statistical period. The quantum key generation statistics include the number of quantum key attempts and successful quantum key generation during the quantum encryption transmission process within the preset statistical period. The authentication statistics include the number of times both communicating parties successfully authenticated each other and the number of times authentication failed. The quantum encryption transmission channel information under the current communication environment includes quantum channel data and quantum encryption transmission information under the current communication environment. The quantum channel data includes the quantum error rate coefficient, signal transmission path loss, and channel capacity. The quantum encryption transmission information includes the number of quantum encryption transmissions, the number of successful quantum encryption transmissions, the amount of data before the i-th quantum encryption transmission, the transmission time, the amount of data after the quantum encryption transmission, the number of quantum encryption transmissions encountered due to network or equipment failures, and the time and amount of data required to recover quantum encryption transmission each time a network or equipment failure occurs. It should be noted that the quantum error rate coefficient, signal transmission path loss, and channel capacity can be directly derived from existing technologies, and the specific acquisition method will not be described in detail here.
[0071] Then, the quantum encryption transmission unit calculates the key allocation success rate coefficient based on the number of quantum key generation attempts and the number of successful quantum key generation attempts; it calculates the communication verification accuracy coefficient based on the number of correct authentication attempts and the number of incorrect authentication attempts between the communicating parties; it calculates the quantum channel performance coefficient based on the quantum channel data; and it calculates the quantum encryption transmission stability coefficient based on the quantum encryption transmission information. Specifically, in this embodiment, the key allocation success rate coefficient is calculated based on the ratio of the number of successful quantum key generation attempts to the number of quantum key generation attempts during the quantum encryption transmission process within a preset statistical period. The specific calculation formula for the key allocation success rate coefficient is as follows:
[0072]
[0073] In the formula, βcf is the key distribution success rate coefficient; Nac is the number of times a quantum key was successfully generated within a preset statistical period; and Naz is the number of times a quantum key was attempted to be generated within a preset statistical period.
[0074] Meanwhile, this embodiment calculates the communication verification accuracy coefficient based on the ratio of the number of correct identity verifications to the sum of the number of correct identity verifications and the number of incorrect identity verifications. The specific formula for calculating the communication verification accuracy coefficient is as follows:
[0075]
[0076] In the formula, βyz is the communication verification accuracy coefficient; Nbz is the number of times the identity is correctly verified within the preset statistical period; and Nbc is the number of times the identity is incorrectly verified within the preset statistical period.
[0077] In this embodiment, the quantum channel performance coefficient is calculated based on the ratio of the channel capacity to the product of the natural logarithm of the quantum bit error rate and the natural logarithm of the signal transmission path loss. The specific formula for calculating the quantum channel performance coefficient is as follows:
[0078]
[0079] In the formula, Xdm is the quantum channel performance coefficient; Rm is the channel capacity; αm is the latest quantum bit error rate coefficient within the preset statistical period; e is the natural constant; Pm is the signal transmission path loss; and ln(*) is the natural logarithm.
[0080] Meanwhile, in this embodiment, the calculation process for the quantum encryption transmission stability coefficient is as follows:
[0081] Within a preset statistical period, the ratios of the original data volume before all successful quantum encryption transmissions to the corresponding transmission time are summed to obtain the original transmission efficiency sum. Based on the original transmission efficiency sum and the number of quantum encryption transmissions within the preset statistical period, the transmission efficiency factor is calculated.
[0082] The ratios of the data volume after all successful quantum encryption transmissions to the original data volume are summed to obtain the total data integrity. The data integrity factor is then calculated based on the total data integrity and the number of successful quantum encryption transmissions within a preset statistical period.
[0083] The ratio of the amount of data recovered to the time required to recover the quantum encrypted transmission in all failed quantum encrypted transmissions is summed to obtain the total fault recovery efficiency. The fault recovery efficiency factor is calculated based on the total fault recovery efficiency and the number of failed quantum encrypted transmissions within a preset statistical period.
[0084] Multiplying the transmission efficiency factor, the data integrity factor, and the fault recovery efficiency factor yields the quantum encryption transmission stability coefficient. The specific formula for calculating the quantum encryption transmission stability coefficient is as follows:
[0085]
[0086] In the formula, βsw is the quantum encryption transmission stability coefficient; Ncg is the number of successful quantum encryption transmissions; Mai is the amount of original data before the i-th successful quantum encryption transmission; Tci is the transmission time corresponding to the amount of original data before the successful quantum encryption transmission; Ncz is the number of quantum encryption transmissions within a preset statistical period; Mbi is the amount of data after the i-th successful quantum encryption transmission ends; Ny is the number of quantum encryption transmissions that encounter network failures or device failures; Mhi is the amount of data recovered during quantum encryption transmission when encountering network failures or device failures for the i-th time; Thi is the time required to recover quantum encryption transmission when encountering network failures or device failures for the i-th time.
[0087] Based on the above embodiments, in some implementations, the communication security management module further includes a power grid communication security assessment module. The power grid communication security assessment module is used to calculate the power grid data communication security index according to the quantum communication performance index, and compare the power grid data communication security index with a preset power grid data communication security value. If the power grid data communication security index meets the preset power grid data communication security value, the current power grid data communication is determined to be secure, and a communication security verification result is generated.
[0088] Specifically, the power grid communication security assessment module receives key allocation success rate coefficient, communication verification accuracy coefficient, quantum channel performance coefficient, and quantum encryption transmission stability coefficient calculated by the quantum encryption transmission unit within a preset statistical period. These coefficients are the basic data for assessing power grid communication security. Based on the received coefficients, the module calculates the power grid data communication security index. In this embodiment, the calculation process of the power grid data communication security index is as follows:
[0089] The quantum channel quality correction factor is obtained by taking the square root of the quantum channel performance coefficient and then performing an exponential operation.
[0090] The sum of the squares of the key distribution success rate coefficient, the communication verification accuracy coefficient, and the quantum encryption transmission stability coefficient is calculated to obtain a comprehensive performance index.
[0091] Multiplying the comprehensive performance index by the quantum channel quality correction factor yields the power grid data communication security index. The specific formula for calculating the power grid data communication security index is as follows:
[0092]
[0093] In the formula, Yz is the power grid data communication security index; exp(*) is an exponential function with the natural constant e as the base.
[0094] After calculating the power grid data communication security index, this embodiment compares the power grid data communication security index with a preset power grid data communication security value. If the calculated power grid data communication security index is greater than or equal to the power grid data communication security value, it is determined that the power grid data communication security meets expectations and the current power grid data communication is secure; otherwise, it is determined that the power grid data communication security does not meet expectations and the current power grid data communication is insecure. Based on the comparison result, the power grid communication security assessment module generates a communication security verification result and outputs corresponding instructions to the power grid security management center based on the generated communication security verification result. If the power grid data communication security meets expectations, an instruction indicating that the power grid data communication security meets expectations is output; if the power grid data communication security does not meet expectations, an instruction indicating that the power grid data communication security does not meet expectations and maintenance and optimization are required is output so that timely measures can be taken to ensure the power grid communication security. In addition, the database in this embodiment is used to store data information of all modules in the system, including the identity information of power grid platform users and power grid platform management personnel, for subsequent security auditing and management. It should be noted that all preset values in this embodiment (such as the power grid data communication security value, etc.) are selected based on actual needs, and the specific values are not limited in detail here.
[0095] Based on the above embodiments, in some implementations, the power grid security communication module 104 is used to encrypt the power grid data to be transmitted using a one-time session password when the communication security verification result is successful, generate encrypted power grid data, and transmit the encrypted power grid data to the target response end.
[0096] Specifically, after the communication security management module completes the consistency verification of the identities and keys of both communicating parties and generates a verified communication security verification result, the key utilization unit of the power grid security communication module 104 receives and extracts the one-time session password, which has been verified and confirmed to be valid, contained in the verification result. Then, in this embodiment, the one-time session password is used as the encryption key, and a pre-selected encryption algorithm (such as AES algorithm) is used to encrypt the power grid data to be transmitted bit by bit, converting the power grid data to be transmitted into encrypted power grid data ciphertext. Then, the encrypted power grid data is encapsulated in ciphertext form into a standard data packet format, and is securely transmitted to the target response end by the data transmission unit through a pre-established, securely certified classic channel (such as fiber optic communication network, dedicated power line carrier communication channel, etc.). During the transmission process, the power grid security communication module 104 uses a data integrity verification mechanism (such as CRC check, HMAC check, etc.) to ensure that the data packet is not damaged or tampered with during the transmission process.
[0097] When the target response end receives the encrypted power grid data, its internal secure communication module performs the opposite operation: First, it uses the same one-time session cipher as the sender (or a decryption key dynamically generated based on a shared key) to call the corresponding decryption algorithm to decrypt the encrypted power grid data, recovering the original plaintext power grid data. Then, it verifies the correctness of the decryption result by verifying the data integrity check code, and submits the decrypted plaintext power grid data to the subsequent business processing module for further processing. Through the above steps, the power grid secure communication module can ensure that, under the premise of successful communication security verification, it uses the one-time session cipher to efficiently and securely encrypt and transmit the power grid data to be transmitted, thereby effectively protecting the confidentiality, integrity, and availability of the power grid data during transmission.
[0098] This embodiment, upon receiving the account IDs of the power grid data requester and the target response, obtains the shared key between the two communicating parties. Then, it uses a quantum random number generator to generate a one-time session cipher, which is then processed in conjunction with the shared key and the session cipher. During processing, the account ID of the power grid data requester is appended to the end of the key to generate a quantum key. This process, through a quantum key distribution protocol, securely sends the generated quantum key to the power grid data requester and the target response. This module introduces a one-time cipher mechanism to ensure that each key is used only once. Furthermore, the characteristics of the quantum key distribution protocol ensure that the session key distribution process is unaffected by replay and eavesdropping attacks, thus effectively guaranteeing the secure transmission of power grid data. In addition, this embodiment strictly verifies the authentication information assigned to the target response of the power grid data. Only if the verification is successful is communication allowed to continue; if the verification fails, communication is immediately rejected to prevent unauthorized access. After communication is completed, the shared key control module of this embodiment updates the shared key using a one-time session cipher. This dynamic update mechanism, to a certain extent, avoids the risk of man-in-the-middle attacks, further improving communication security.
[0099] Meanwhile, this embodiment uses a one-time session cipher to encrypt the power grid data to be transmitted, and then securely transmits the encrypted power grid data ciphertext to the power grid data requesting end through a classical channel. The target response end uses the received quantum key to decrypt the power grid data ciphertext and recover the plaintext power grid data. Since quantum encryption technology is used, the security of the session key does not depend on computational complexity, so it can resist attacks from quantum computers and significantly improve the security of power grid data communication.
[0100] This invention provides a quantum cryptography-based secure power grid data transmission system. The system includes a power grid data access module for determining the data transmission method of the target response end based on a power grid data access request uploaded by the power grid data requesting end, and extracting the identity identifiers of the power grid data requesting end and the target response end based on the data transmission method; a quantum key distribution module for obtaining the pre-stored original shared key between the communicating parties based on the received identity identifiers of the power grid data requesting end and the target response end, generating a one-time session cipher using a quantum random number generator, generating a quantum key based on the one-time session cipher and the original shared key, and distributing the quantum key to the power grid data requesting end and the target response end through a quantum key distribution protocol; a communication security management module for parsing the shared key information from the quantum key received by the target response end, obtaining parsed shared key information, matching and verifying the original shared key with the parsed shared key information, and generating a communication security verification result; and a power grid secure communication module for encrypting the power grid data to be transmitted using the one-time session cipher when the communication security verification result is successful, generating encrypted power grid data, and transmitting the encrypted power grid data to the target response end. Compared with existing technologies, this system achieves full-process security protection for power grid data transmission through a collaborative mechanism of dynamic quantum key allocation, dual authentication, and quantum encrypted transmission. It ensures the confidentiality, integrity, and availability of power grid data during transmission, improves the security and reliability of power grid data communication, and meets the high requirements of smart grids for data security.
[0101] In one embodiment, such as Figure 2 As shown, this embodiment of the invention provides a method for secure data transmission in power grids based on quantum cryptography, the method comprising the following steps:
[0102] S1. Determine the data transmission method of the target response terminal based on the power grid data access request uploaded by the power grid data request terminal, and extract the identity identifier of the power grid data request terminal and the identity identifier of the target response terminal based on the data transmission method;
[0103] S2. Obtain the original shared key pre-stored by both communicating parties based on the identity identifier of the power grid data requesting end and the identity identifier of the target responding end, and generate a one-time session password using a quantum random number generator;
[0104] S3. Generate a quantum key based on the one-time session cipher and the original shared key, and distribute the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol;
[0105] S4. Parse the shared key information from the quantum key received from the target response end to obtain the parsed shared key information, and match and verify the original shared key with the parsed shared key information to generate a communication security verification result;
[0106] S5. When the communication security verification result is successful, the one-time session password is used to encrypt the power grid data to be transmitted, generate encrypted power grid data, and transmit the encrypted power grid data to the target response terminal.
[0107] It should be noted that the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0108] For specific limitations regarding a quantum cryptography-based secure data transmission method for power grids, please refer to the above-described limitations regarding a quantum cryptography-based secure data transmission system for power grids, which will not be repeated here. Those skilled in the art will recognize that the various modules and steps described in conjunction with the embodiments disclosed in this application can be implemented in hardware, software, or a combination of both. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0109] This invention provides a method for secure transmission of power grid data based on quantum cryptography. The method includes: determining the data transmission mode of the target response end based on a power grid data access request uploaded by the power grid data requesting end; extracting the identity identifiers of the power grid data requesting end and the target response end based on the data transmission mode; obtaining the original shared key pre-stored by both communicating parties based on the identity identifiers of the power grid data requesting end and the target response end, and generating a one-time session cipher using a quantum random number generator; generating a quantum key based on the one-time session cipher and the original shared key, and distributing the quantum key to the power grid data requesting end and the target response end through a quantum key distribution protocol; parsing the shared key information from the quantum key received by the target response end to obtain parsed shared key information, and matching and verifying the original shared key with the parsed shared key information to generate a communication security verification result; when the communication security verification result is successful, encrypting the power grid data to be transmitted using the one-time session cipher to generate encrypted power grid data, and transmitting the encrypted power grid data to the target response end. Compared with existing technologies, this method achieves full-process security protection for power grid data transmission through a collaborative mechanism of dynamic quantum key allocation, dual authentication, and quantum encrypted transmission. It ensures the confidentiality, integrity, and availability of power grid data during transmission, improves the security and reliability of power grid data communication, and meets the high requirements of smart grids for data security.
[0110] In one embodiment, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described method.
[0111] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., SSD), etc.
[0112] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed, it can include the processes of the embodiments of the above methods.
[0113] The embodiments described above are merely preferred embodiments of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various improvements and substitutions without departing from the technical principles of this invention, and these improvements and substitutions should also be considered within the scope of protection of this application. Therefore, the scope of protection of this patent application should be determined by the scope of the claims.
Claims
1. A power grid data secure transmission system based on quantum cryptography, characterized in that, The method comprises the following steps: The power grid data access module is used for determining the data transmission mode of the target response end according to the power grid data access application uploaded by the power grid data request end, and extracting the power grid data request end identity and the target response end identity according to the data transmission mode; The quantum key distribution module is used for obtaining the pre-stored original shared key of the communication parties according to the received power grid data request end identity and target response end identity, generating a one-time session password by using a quantum random number generator, and generating a quantum key according to the one-time session password and the original shared key, including: performing an exclusive OR operation on the original shared key and the one-time session password, and appending the power grid data request end identity to generate a quantum key, and distributing the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol; The communication security management module is used for parsing the shared key information from the quantum key received from the target response end to obtain parsed shared key information, and matching and verifying the original shared key and the parsed shared key information to generate a communication security verification result; The power grid secure communication module is used for encrypting the to-be-transmitted power grid data by using the one-time session password to generate power grid encrypted data when the communication security verification result is verified, and transmitting the power grid encrypted data to the target response end.
2. The quantum cryptography based power grid data secure transmission system of claim 1, wherein: The quantum key distribution module includes a shared key request unit, a shared key control unit, a session key generation unit, and a quantum key distribution unit; The shared key request unit is used for receiving the power grid data request end identity and the target response end identity sent by the power grid data access module, and generating a shared key request according to the power grid data request end identity and the target response end identity, and sending the shared key request to the shared key control unit; The shared key control unit is used for responding to the shared key request to retrieve the pre-stored original shared key of the power grid data request end and the target response end from the database, and feeding back the original shared key to the quantum key generation unit; The session key generation unit is used for generating a one-time session password by using a quantum random number generator; The quantum key distribution unit is used for distributing the quantum key to the power grid data request end and the target response end through a quantum key distribution protocol.
3. The quantum cryptography based power grid data secure transmission system of claim 1, wherein: The communication security management module includes a quantum key extraction unit, a shared key matching unit, and a verification decision unit; The quantum key extraction unit is used for parsing the shared key information from the quantum key received from the target response end to obtain parsed shared key information; The shared key matching unit is used for comparing the original shared key and the parsed shared key information to obtain a matching verification result; The verification decision unit is configured to verify the identities of the two communication parties according to the matching verification result, and determine that the identities of the two communication parties are verified successfully when the original shared key and the parsed shared key information are consistent, and allow the power grid data request end to communicate with the target response end; and determine that the identities of the two communication parties are verified unsuccessfully when the original shared key and the parsed shared key information are inconsistent, and refuse the power grid data request end to communicate with the target response end.
4. The quantum cryptography based power grid data secure transmission system of claim 3, wherein: The communication security management module further comprises a quantum transmission collection unit and a quantum encryption transmission unit. The quantum transmission collection unit is configured to collect, when the identities of the two communication parties are verified successfully, a quantum key generation statistical number, an identity verification statistical number, and quantum encryption transmission channel information in a current communication environment in a preset statistical period. The quantum encryption transmission unit is configured to calculate a quantum communication performance index according to the quantum key generation statistical number, the identity verification statistical number, and the quantum encryption transmission channel information in the current communication environment; wherein the quantum communication performance index comprises a key distribution success rate coefficient, a communication verification accuracy rate coefficient, a quantum channel performance coefficient, and a quantum encryption transmission stability coefficient.
5. The quantum cryptography based power grid data secure transmission system of claim 4, wherein: The communication security management module further comprises a power grid communication security evaluation module. The power grid communication security evaluation module is configured to calculate a power grid data communication security index according to the quantum communication performance index, and compare the power grid data communication security index with a preset power grid data communication security value; if the power grid data communication security index meets the preset power grid data communication security value, it is determined that the current power grid data communication is secure, and a communication security verification result is generated.
6. The quantum cryptography based power grid data secure transmission system of claim 5, wherein, The calculation process of the power grid data communication security index is as follows: Exponentially operate the square root of the quantum channel performance coefficient to obtain a quantum channel quality correction factor; Calculate the sum of squares of the key distribution success rate coefficient, the communication verification accuracy rate coefficient, and the quantum encryption transmission stability coefficient to obtain a comprehensive performance index; Multiply the comprehensive performance index and the quantum channel quality correction factor to obtain the power grid data communication security index.
7. The quantum cryptography based power grid data secure transmission system of claim 5, wherein: The key distribution success rate coefficient is the ratio of the number of successful quantum key generation to the number of quantum key generation attempts in a preset statistical period; The communication verification accuracy rate coefficient is the ratio of the number of correct identity verifications to the sum of the number of correct identity verifications and the number of incorrect identity verifications; The quantum channel performance coefficient is the ratio of the product of the channel capacity and the natural logarithm of the signal transmission path loss to the natural logarithm of the quantum error rate.
8. The quantum cryptography based power grid data secure transmission system of claim 5, wherein, The calculation process of the quantum encryption transmission stability coefficient is as follows: Accumulate and sum the ratio of the original data volume before quantum encryption successful transmission to the corresponding transmission time in a preset statistical period to obtain a total original transmission efficiency, and calculate a transmission efficiency factor according to the total original transmission efficiency and the number of quantum encryption transmissions in the preset statistical period; The data integrity sum is obtained by accumulating and summing the ratio of the data quantity after successful transmission of all quantum encryption to the original data quantity, and the data integrity factor is calculated according to the data integrity sum and the number of successful quantum encryption transmissions in a preset statistical period. The fault recovery efficiency sum is obtained by accumulating and summing the ratio of the recovered data quantity to the time length required for recovering the quantum encryption transmission that encounters a fault, and the fault recovery efficiency factor is calculated according to the fault recovery efficiency sum and the number of quantum encryption transmissions that encounter a fault in a preset statistical period. The transmission efficiency factor, the data integrity factor and the fault recovery efficiency factor are multiplied to obtain the quantum encryption transmission stability coefficient.
9. A power grid data secure transmission method based on quantum cryptography, characterized in that, The method comprises the following steps: According to the power grid data access application uploaded by the power grid data request end, the data transmission mode of the target response end is determined, and the power grid data request end identity and the target response end identity are extracted according to the data transmission mode; According to the power grid data access application uploaded by the power grid data request end, the data transmission mode of the target response end is determined, and the power grid data request end identity and the target response end identity are extracted according to the data transmission mode; The original shared key pre-stored by the communication parties is obtained according to the power grid data request end identity and the target response end identity, and a one-time session password is generated by using a quantum random number generator; The quantum key is generated according to the one-time session password and the original shared key, including: performing exclusive or operation on the original shared key and the one-time session password, and appending the power grid data request end identity to generate a quantum key, and the quantum key is distributed to the power grid data request end and the target response end through a quantum key distribution protocol; The shared key information is parsed from the quantum key received from the target response end to obtain parsed shared key information, and the original shared key is matched and verified with the parsed shared key information to generate a communication security verification result; 10. A computer-readable storage medium, characterized in that: When the communication security verification result is verified, the one-time session password is used to encrypt the power grid data to be transmitted to generate power grid encrypted data, and the power grid encrypted data is transmitted to the target response end. The computer readable storage medium stores a computer program, and when the device in which the computer readable storage medium is located executes the computer program, the method of claim 9 is realized. The computer readable storage medium stores a computer program, and when the device in which the computer readable storage medium is located executes the computer program, the method of claim 9 is realized.
Citation Information
Patent Citations
Bidirectional authentication method and system based on shared key, and terminal
CN110958209A
Data protection method fusing quantum key in TLS
CN119834967A