Information board quantum security protection system and method
By building a zero-trust virtual network and quantum encryption technology, the security risks problem during intelligence board information release is solved, the security and reliability of data transmission is achieved, and the global security situation display and refined management and control are provided.
Patent Information
- Application Number
- CN202510738404.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-08-15
AI Technical Summary
Existing intelligence boards cannot avoid security risks when information is released, and there is a possibility of information leakage and tampering.
The quantum security control module is used to build a zero-trust virtual network, and data encryption and decryption are carried out through quantum gateways and management terminals, and quantum security service modules are combined to ensure the security of data during transmission, and real-time monitoring and visual display are carried out through the quantum situational awareness module.
It realizes the security and integrity of information transmission on the intelligence board, prevents unauthorized access and tampering, provides global security situation display and refined control, and ensures the security and stability of the intelligence board release network.
Smart Images

Figure CN120498677A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an information board quantum security protection system and method. Background Art
[0002] With the development of science and technology and the acceleration of urbanization, intelligent transportation systems have become a new trend in urban traffic management. Traffic guidance screens (variable information boards) play a vital role in this system. By utilizing advanced LED (light-emitting diode) display technology, they can timely issue various traffic notices and related traffic information, effectively directing traffic flow, rationally controlling and balancing the distribution of road traffic flow, improving the utilization rate of existing roads, and providing excellent services for drivers and vehicles to travel safely and quickly.
[0003] Traffic guidance screens are typically installed at key locations such as busy intersections, highways, and urban roads. They reach a wide audience, requiring strict control over displayed content to prevent serious safety risks. Traffic guidance screens have been used repeatedly across the country to spread harmful information, resulting in extremely negative social impacts. Therefore, strict security management of traffic guidance screen transmission systems is essential, with meticulous control over display computers (management terminals), variable information boards, and display strategies to prevent safety risks.
[0004] In summary, existing information boards cannot avoid the occurrence of security risks when releasing information. Summary of the Invention
[0005] In view of this, it is necessary to provide a quantum security protection system and method for information boards to solve the technical problem that existing information boards cannot avoid security risks when releasing information.
[0006] In order to solve the above problems, in a first aspect, the present invention provides an information board quantum security protection system, comprising: A quantum security control module is configured to construct a zero-trust virtual network, assign identity registration files to communication nodes in the zero-trust virtual network, and connect the communication nodes to the zero-trust virtual network after the communication nodes complete identity registration based on the identity registration files. The communication nodes include a quantum gateway, a management terminal, and an intelligence board device. The quantum gateway is configured to decrypt encrypted data and forward it to the intelligence board device via the zero-trust virtual network. The management terminal is configured to send data to be transmitted to the zero-trust virtual network. The quantum security service module is used to perform quantum encryption on data to be transmitted in the zero-trust virtual network based on the quantum security key, obtain encrypted data, and transmit the encrypted data back to the zero-trust virtual network.
[0007] In one possible implementation, the intelligence board quantum security protection system further includes: The quantum security situation awareness module is used to receive data uploaded by the quantum gateway and visualize the data uploaded by the quantum gateway.
[0008] In one possible implementation, the data uploaded by the quantum gateway includes: operating status data of the communication node, threat alarm data generated by the zero-trust virtual network, quantum key consumption trend data, and security risk events.
[0009] In a possible implementation, the communication node further includes: a perception module; the perception module is configured to send an alarm message to the quantum security situation awareness module when detecting that an abnormal operating status of the intelligence board device exists.
[0010] In a possible implementation, the identification module is further configured to intercept decrypted data sent to the information board device when it is determined that the registered identity of the information board device has changed based on the identity registration file of the information board device.
[0011] In one possible implementation, the zero-trust virtual network operates at the network layer and the transport layer; The quantum security control module is further configured to set a virtual communication link policy for the network layer, so as to control data transmission of the zero-trust virtual network at the transport layer based on the virtual communication link policy.
[0012] In a possible implementation, the quantum security control module is further configured to receive an access control policy input by a user, and set access rights for the management terminal based on the access control policy.
[0013] In a possible implementation, the quantum gateway includes: an edge-side gateway and a center-side gateway; The management terminal is used to send encrypted data to the center-side gateway; The central gateway is configured to decrypt the encrypted data to obtain decrypted data, and forward the decrypted data with the authentication tag to the edge gateway if the decrypted data is authorized to pass based on the access control policy; The edge layer gateway is used to forward the corresponding decrypted data to the intelligence board device through the zero-trust virtual network after identifying the authentication tag.
[0014] In a possible implementation, the management terminal is configured to send encrypted data to the central-side gateway via a quantum secure tunnel.
[0015] In a second aspect, the present invention further provides a method for quantum security protection of an information board, which is applied to any of the above-mentioned systems, and includes: A zero-trust virtual network is constructed based on the quantum security control module, and identity registration files are allocated to communication nodes of the zero-trust virtual network. After the communication nodes complete identity registration based on the identity registration files, the communication nodes are connected to the zero-trust virtual network; the communication nodes include: a quantum gateway, a management terminal, and an intelligence board device; Sending the data to be transmitted to the zero-trust virtual network based on the management terminal; Based on the quantum security service module, the quantum security key is used to perform quantum encryption on the data to be transmitted in the zero-trust virtual network to obtain encrypted data; The encrypted data is decrypted based on the quantum gateway and then forwarded to the intelligence board device through the zero-trust virtual network.
[0016] The beneficial effects of the above implementation are as follows: the quantum security protection system for the information board provided by the present invention, including the quantum security control module, quantum gateway, management terminal, and information board device, all establish communication connections through a zero-trust virtual network. The management terminal sends the data to be transmitted, i.e., the data information to be displayed on the information board device. The quantum security service module performs quantum encryption to prevent information leakage and tampering. After the encrypted information is transmitted to the quantum gateway, it is decrypted by the quantum gateway and forwarded to the information board device through the zero-trust virtual network for display. When data is transmitted between the various communication nodes, it is first quantum encrypted and then decrypted by the quantum gateway. When quantum keys are used for encryption, because quantum states cannot be cloned, attackers cannot accurately copy or steal the quantum keys. At the same time, when quantum states are eavesdropped or interfered with, their states will change, so the attacker can detect the attack by detecting the changes in the quantum state. Therefore, quantum keys are theoretically considered to be unbreakable, thus ensuring the security of communication and solving the technical problem that existing information boards cannot avoid security risks when distributing information. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0018] Figure 1 A block diagram showing a principle of an embodiment of the information board quantum security protection system provided by the present invention; Figure 2This is an overall architecture diagram of another embodiment of the information board quantum security protection system provided by the present invention; Figure 3 A schematic diagram of the network architecture of an embodiment of the information board quantum security protection system provided by the present invention; Figure 4 This is a flowchart of an embodiment of the quantum security protection method for an information board provided by the present invention. DETAILED DESCRIPTION
[0019] The following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0020] In the description of the embodiments of the present application, unless otherwise specified, “a plurality of” means two or more.
[0021] The terms "including" and "having" and any variations thereof in the embodiments of the present invention are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product or device comprising a series of steps or modules is not necessarily limited to those steps or modules explicitly listed, but may include other steps or modules not explicitly listed or inherent to these processes, methods, products or devices.
[0022] The naming or numbering of the steps in the embodiments of the present invention does not mean that the steps in the method flow must be executed in the time / logical sequence indicated by the naming or numbering. The execution order of the named or numbered process steps can be changed according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved.
[0023] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0024] like Figure 1 As shown, the present invention provides an information board quantum security protection system, comprising: The quantum security control module 101 is used to build a zero-trust virtual network, allocate an identity registration file to a communication node 103 of the zero-trust virtual network, and connect the communication node 103 to the zero-trust virtual network after the communication node 103 completes identity registration based on the identity registration file. The communication node 103 includes: a quantum gateway, a management terminal, and an information board device; the quantum gateway is used to decrypt encrypted data and forward it to the information board device via the zero-trust virtual network; the management terminal is used to send the data to be transmitted to the zero-trust virtual network; The quantum security service module 102 is used to perform quantum encryption on the data to be transmitted in the zero-trust virtual network based on the quantum security key, obtain encrypted data, and transmit the encrypted data back to the zero-trust virtual network.
[0025] It's understandable that the key to zero-trust virtual networks lies in breaking the default "trust," which can be summarized in one sentence: "continuous verification, never trust." By default, no one, device, or system inside or outside the enterprise network is trusted. The trust foundation for access control is rebuilt based on identity authentication and authorization, ensuring trusted identities, devices, applications, and links. A virtual network is a computer network that includes at least some virtual network connections. A virtual network connection does not involve a physical connection between two computing devices, but is instead implemented through network virtualization. A management terminal can be a terminal device such as a mobile phone or computer.
[0026] The overall architecture of the intelligence board quantum security protection system is shown in Figure 2: The intelligence board's quantum security protection system consists of a quantum security control platform (i.e., quantum security control module 101), a quantum security situational awareness platform (i.e., quantum security situational awareness module 104), and a quantum security service platform (i.e., quantum security service module 102), all integrated with zero-trust virtual network technology. The zero-trust virtual network manages intelligence service communication data between all devices in the system. The quantum security service platform manages quantum security keys, providing them for data encryption during data transmission. The quantum security control platform manages access management, policy management, and quantum security capability allocation for the entire device environment. The quantum security situational awareness platform collects various operational and network security data uploaded by gateway devices within the network, visually displaying them, helping administrators understand the security status of the entire intelligence board's network.
[0027] The zero-trust virtual network is constructed using a quantum-safe control platform and a zero-trust virtual network communication router. The control platform is responsible for authentication, communication configuration, service, and policy management for all device access, while the communication router is responsible for the actual network data transmission. The platform provides clients as edge nodes, connecting gateway devices and management computers to the virtual network through the communication router for data transmission. The gateway device receives encrypted traffic from the virtual network, decrypts it, and forwards it to the intelligence board device, preventing unauthorized requests from directly accessing the intelligence board device.
[0028] The quantum security control platform operates at the application layer, assigning identity registration and authentication files to zero-trust virtual network communication nodes 103. The quantum security gateway uses the authentication files to connect to the quantum security management platform and complete identity registration. The quantum security gateway can also directly register itself through the quantum security management platform without requiring authentication files. After completing registration and access, the quantum security gateway participates as a node in the zero-trust virtual network.
[0029] Zero-trust virtual networks operate at the network and transport layers. The quantum security management platform establishes virtual communication link policies at the network layer, binding these policies to forwarding routes. Quantum security gateways can serve as both the starting and ending points of virtual communication links. Device terminals intercept requests at the transport layer through the starting gateway, encrypt them, and forward them to the virtual network. The virtual network then sends the traffic to the ending gateway at the network layer. The ending gateway decrypts the encrypted traffic and then forwards the request to the destination address at the transport layer according to the rules.
[0030] The quantum security service platform is a full life cycle management platform for quantum security keys. It provides quantum security keys for encrypted communications in zero-trust virtual networks and empowers quantum security capabilities. The quantum security gateway can connect to the quantum security service platform to obtain quantum security keys or obtain them from secure media filled with quantum security keys, providing encryption keys for the data transmission process of the quantum security gateway and improving the security of the data transmission process.
[0031] The quantum security situational awareness platform operates at the application layer. Quantum security gateways and virtual links jointly build a zero-trust virtual network. The situational awareness platform uses the quantum security gateway to collect real-time device and communication service data within the virtual network. This data is then stored in a database and visualized using custom rules, helping administrators understand the overall network security situation of the intelligence board's published network.
[0032] In some embodiments, the intelligence board quantum security protection system further includes: The quantum security situation awareness module 104 is used to receive the data uploaded by the quantum gateway and visualize the data uploaded by the quantum gateway.
[0033] It is understood that the quantum security situational awareness module 104, also known as the quantum security situational awareness platform, operates at the application layer. The quantum security gateway and virtual links together form a zero-trust virtual network. The situational awareness platform uses the quantum security gateway to collect real-time device and communication service data in the virtual network. This data is then stored in a database and visualized using custom rules, helping administrators understand the overall network security status of the intelligence board's published network.
[0034] In some embodiments, the data uploaded by the quantum gateway includes: operating status data of the communication node 103, threat alarm data generated by the zero-trust virtual network, quantum key consumption trend data, and security risk events.
[0035] The information board's quantum security protection system can display the security status of the information board's network on a large screen through a visualization platform. This allows managers to quickly grasp information such as the operating status of system devices, the information board, generated threat alerts, and quantum key consumption trends, allowing them to promptly address potential security risks and avoid security incidents.
[0036] In some embodiments, the communication node 103 further includes: a perception module; the perception module is used to send an alarm message to the quantum security situation perception module 104 when detecting that the information board device has an abnormal operating status.
[0037] It is understandable that the quantum security protection system of the intelligence board can regularly sense the operating status and identity information of the intelligence board controlled by the system. If the operating status of the intelligence board is abnormal, an alarm will be generated to the visualization platform, prompting the user to perform maintenance work on the intelligence board.
[0038] In some embodiments, the identification module is further configured to intercept decrypted data sent to the information board device when it is determined based on the identity registration file of the information board device that the registered identity of the information board device has changed.
[0039] It is understandable that if the identity of the person accessing the information board changes, the system will "blacklist" it, blocking the publishing terminal from publishing information to the untrusted information board, thereby avoiding security accidents.
[0040] In some embodiments, the zero-trust virtual network operates at the network layer and the transport layer; The quantum security control module 101 is further configured to set a virtual communication link policy for the network layer, so as to control data transmission of the zero-trust virtual network at the transport layer based on the virtual communication link policy.
[0041] As you can understand, zero-trust virtual networks operate at the network and transport layers. The quantum security management platform establishes virtual communication link policies at the network layer, binding these policies to forwarding routes. The quantum security gateway can serve as both the starting point and the endpoint of a virtual communication link. The starting gateway intercepts requests at the transport layer, encrypts them, and forwards them to the virtual network. The virtual network then sends the traffic to the endpoint gateway at the network layer. The endpoint gateway decrypts the encrypted traffic and then forwards the request to the destination address at the transport layer according to the rules.
[0042] In some embodiments, the quantum security control module 101 is further configured to receive an access control policy input by a user, and set access rights for the management terminal based on the access control policy.
[0043] Administrators can, understandably, issue global access control policies through the information board's quantum security protection system's control platform, finely controlling access to the information board from publishing terminals, blocking unauthorized traffic and ensuring the security of the information board's publishing network. All control policies can be implemented on the control platform, significantly improving administrators' work efficiency and reducing workload.
[0044] In some embodiments, the quantum gateway includes: an edge-side gateway and a center-side gateway; The management terminal is used to send encrypted data to the center-side gateway; The central gateway is configured to decrypt the encrypted data to obtain decrypted data, and forward the decrypted data with the authentication tag to the edge gateway if the decrypted data is authorized to pass based on the access control policy; The edge layer gateway is used to forward the corresponding decrypted data to the intelligence board device through the zero-trust virtual network after identifying the authentication tag.
[0045] It is understood that the intelligence board-related traffic sent by the publishing terminal (i.e., the management terminal) is encrypted by the security control software and transmitted through the quantum security tunnel to the central gateway. The central gateway decrypts the data and matches it with the access policy issued by the control console. If there is a policy that allows the traffic to pass, the traffic is encrypted and forwarded to the corresponding edge gateway. The edge gateway decrypts the data to check whether it has the authentication tag of the central gateway. If so, it forwards the traffic to the managed intelligence board, thus completing the forwarding of the entire data traffic. During operation, each gateway can also report network security information to the visualization platform for large-screen display of the visualized information. If threatening traffic can be detected within the network, the visualization platform can generate a prominent alarm and intercept the threatening traffic, prompting the administrator to take security risk measures to avoid security incidents.
[0046] In some embodiments, the management terminal is used to send encrypted data to the central-side gateway through a quantum secure tunnel.
[0047] The system provided by the present invention should have at least the following capabilities in terms of security management of the information board network: Threat traffic interception and alarm: Untrusted or unauthorized intelligence board-related traffic can be regarded as threat traffic. When such threat traffic exists in the network, an alarm should be generated and blocked quickly.
[0048] Terminal access control: The terminal used to publish information to the information board is called the publishing terminal. The access of the publishing terminal and the variable information information board should be confirmed by the administrator. Unconfirmed publishing terminals and information boards cannot access the information board publishing network.
[0049] Access policy control: In addition to the need to control terminal access, the communication between the publishing terminal and the variable information information board also needs to be controlled. Information publishing operations can only be performed between the publishing terminal and the information board that have established an access policy.
[0050] Global security situation display: The overall security status of the information board network should be displayed on a large visual screen, allowing administrators to easily grasp the security risks of the entire network and the operating status of equipment without having to conduct security inspections on all equipment one by one.
[0051] The system provided by the present invention has the following design principles: Confidentiality: Ensure the confidentiality of sensitive information and data transmission in the intelligence board. Use quantum encryption technology to ensure the security of data during transmission and prevent unauthorized access and eavesdropping.
[0052] Integrity principle: Protect the integrity of the information board's data and systems to prevent data tampering, destruction, or loss. Through mechanisms such as quantum encryption and identity verification, ensure that only authorized personnel can perform information release operations.
[0053] Availability principle: Ensure that the information board system can maintain availability and stability under any circumstances to cope with various network attacks and failures.
[0054] User-friendliness principle: Simplify system operation and management, provide user-friendly interfaces and tools, reduce user learning and operation difficulties, and improve work efficiency and user satisfaction.
[0055] The information board's quantum security protection system, based on quantum secure communication, provides high-strength encryption from the publishing terminal to the information board's information distribution network, encrypting the transmitted information. The management platform fine-grainedly manages access policies between the publishing terminals and the information board, providing comprehensive control over information distribution. The situational awareness platform displays the overall security situation on a large screen and provides real-time alerts on threatening traffic, helping administrators gain a global perspective on security risks within the information board's distribution network and address them promptly, ensuring network security.
[0056] The system provided by the present invention has the following advantages: Quantum secure communication capabilities: Quantum keys are generated using the principles of quantum mechanics. Their security is based on the uncertainty principle and the quantum no-cloning theorem. Because quantum states cannot be cloned, attackers cannot accurately copy or steal quantum keys. Furthermore, when quantum states are eavesdropped on or interfered with, their state changes, allowing attackers to detect attacks by detecting these changes. Therefore, quantum keys are theoretically considered unbreakable, thus ensuring the security of communications.
[0057] The data transmission of the information board publishing network mostly adopts plain text transmission. External attackers can intercept data packets through eavesdropping, directly intercept and tamper with the published content through plain text data packets, and publish information containing inappropriate remarks, thereby causing adverse effects.
[0058] The quantum security protection system of the intelligence board can leverage the uniqueness and high security of quantum keys to empower the security of the intelligence board transmission network. Quantum keys can be used to build quantum secure communication tunnels between gateway nodes for data encryption transmission. By combining quantum secure communication technology with traditional data transmission networks and encryption technology, we can get rid of traditional point-to-point quantum encryption communication and create a multi-point quantum encryption communication network that is more suitable for applications, so that the quantum security protection system of the intelligence board has quantum secure communication capabilities and ensures the security of data transmission.
[0059] Visual display capabilities: The information board's quantum security protection system displays the security status of the information board's network on a large screen through a visualization platform. This allows managers to quickly understand the operating status of system devices, the information board, generated threat alerts, and quantum key consumption trends, enabling them to promptly address potential security risks and prevent incidents.
[0060] Global policy delivery capability: Administrators can globally issue access control policies through the information board's quantum security protection system's control platform, finely controlling access to the information board from publishing terminals, blocking unauthorized traffic and ensuring the security of the information board's publishing network. All control policies can be implemented on the control platform, significantly improving administrators' work efficiency and reducing workload.
[0061] Refined terminal management and control capabilities: The information board's quantum security protection system allows for granular control of authorized terminal access. All terminals accessing the information board's publishing network must be authorized by management personnel. Only after formal authorization can access the network. To publish information to the information board, the administrator must issue an access policy for the corresponding terminal. Once the policy allows the terminal to publish information to the corresponding information board, this dual control mechanism of "authorization" and "policy" allows for granular control of terminal access to the information board.
[0062] Intelligence board status perception capabilities: The information board's quantum security protection system regularly monitors the operating status and identity of the information boards it manages. If an information board's operating status is abnormal, an alert is generated to the visualization platform, prompting users to perform information board maintenance. If the identity of the accessed information board changes, the system will blacklist it, preventing the publishing terminal from publishing information to the untrusted information board, thus preventing security incidents.
[0063] Real-time alert capability for threat traffic: Traffic from unauthorized terminals scanning or operating intelligence boards can be considered threat traffic. The intelligence board's quantum security protection system can perceive such threat traffic in real time. If the threat traffic can be captured, the system can quickly block it and generate an alarm on the visualization platform.
[0064] Implementation and deployment plan The intelligence board's quantum security protection system primarily consists of components such as security control software, a central gateway, an edge gateway, a control platform, and a visualization platform. The intelligence board-related traffic sent from the publishing terminal is encrypted by the security control software and transmitted through a quantum secure tunnel to the central gateway. The central gateway decrypts the data and matches it with the access policy issued by the control console. If there is a policy allowing the traffic to pass, the encrypted traffic is forwarded to the corresponding edge gateway. The edge gateway decrypts the data to check whether it has the authentication tag of the central gateway. If so, the traffic is forwarded to the managed intelligence board, thus completing the forwarding of the entire data traffic. During operation, each gateway can also report network security information to the visualization platform, completing a large-screen display of the visualized information. If threatening traffic can be detected within the network, the visualization platform can generate a prominent alarm and intercept the threatening traffic, prompting the administrator to address the security risk and avoid security incidents.
[0065] The network architecture of the intelligence board quantum security protection system is roughly as follows Figure 3 As shown: Operations Center, including: Quantum Security Control Platform: Administrators can use the quantum security console to manage terminal authorization, issue access policies, and handle threat alerts. All components of the intelligence board's quantum security management system can be managed from the control platform. Access policies issued by the control platform are synchronized to the quantum security center gateway and aggregation gateway. The center or aggregation gateway then determines whether traffic should be forwarded to the corresponding quantum security edge gateway based on the policy.
[0066] Quantum Security Situational Awareness Platform: The Quantum Security Situation Awareness Platform displays the network security status of the information board's distribution network on a large screen. This includes past security incidents, quantum key consumption trends, network topology diagrams, and the operational status of security protection system components and the information board. This helps administrators quickly understand the security status of the information board's distribution network and, if any, generates immediate alerts, alerting administrators to address the incident.
[0067] Quantum Security Center Gateway: The central gateway can be deployed alongside the core switch in the information board's distribution network, without changing the user-side network structure. The central gateway receives encrypted traffic from the security control software and verifies that the terminal has passed identity authentication and has an approved access control policy. If so, it forwards the traffic via a quantum secure tunnel to the corresponding edge gateway in front of the information board. The edge gateway decrypts the traffic and forwards it to the information board for distribution.
[0068] Regional Operations Center, including: Quantum Security Aggregation Gateway: The aggregation gateway can be deployed in parallel below the core switch in the regional operations center's computer room, without changing the user-side network structure. The aggregation gateway receives encrypted traffic from the quantum security center gateway and verifies that the terminal has passed identity authentication and has an approved access control policy. If so, it forwards the traffic through the quantum secure tunnel to the edge gateway in front of the corresponding information board. The edge gateway decrypts the traffic and forwards it to the information board for publication.
[0069] Regional center sub-platform: The regional center sub-platform directly manages the information boards within the regional operations center's management section, as well as the quantum-secure convergence gateway, quantum-secure edge gateway, and information boards within the network. The regional center sub-platform serves as a sub-node for various platforms within the operations center. Access and control permissions for each sub-platform are centrally assigned by the operations center administrator. Centralized management of relevant devices within the network is strictly based on permissions, preventing unauthorized access and the resulting security risks.
[0070] Security control software: The security control software needs to be installed on the publishing terminal that needs to access the information release platform of the information board. After completing the identity authentication of the publishing terminal, it can access the information board publishing network. The information board communication traffic sent by the publishing terminal will be taken over by the security control software, encrypted through the quantum secure tunnel, and transmitted to the central side gateway. The precise control of the security control software will not affect the publishing terminal's access to other services, thereby realizing precise traffic control.
[0071] Roadside equipment, including: Quantum Secure Edge Gateway: The edge gateway is transparently deployed in front of the information board, eliminating the need to modify the board's existing IP address. It receives encrypted traffic forwarded by the central gateway, verifies the traffic bears the central gateway's authentication tag, decrypts it, and forwards it to the information board, completing the release of the information. The gateway also regularly monitors the board's operating status and identity. If the board's operating status or identity is abnormal, it quickly generates an alert to the visualization platform, alerting management personnel to perform maintenance to prevent disruption to the board's normal operation.
[0072] Before implementing the system provided by the present invention, it should be confirmed whether the project site has the implementation environment, such as the network environment, power environment, installation environment, etc.
[0073] Network environment: Check whether the platform-side devices and gateway-side devices have been assigned IP addresses and whether the devices can communicate with each other.
[0074] Power supply environment: Check whether the installation locations of the platform-side hardware devices and gateway devices are equipped with power supplies, and whether the installation location of the edge-side gateway on the information board gantry can be normally connected to the power supply.
[0075] Installation environment: Check whether there is space for deployment of platform-side equipment and central-side and aggregation-side gateways in the corresponding offices, and whether there is space for installation of edge-side gateways on the information board gantry.
[0076] Equipment Installation and Deployment: Platform-side equipment, center-side gateways, and aggregation-side gateways can all be deployed in designated cabinets within the corresponding equipment rooms in each area. Since the edge-side gateways need to be connected in series in front of the protected information board, the quantum-secure edge-side gateways must be debugged in direct-through mode and deployed in front of the information board. They can then be remotely debugged through the quantum-secure control platform. Once the platform-side and gateway-side equipment are installed and deployed, the joint debugging phase can begin.
[0077] Device Joint Commissioning Test: Once all devices are deployed, joint commissioning testing can begin. First, test whether the quantum security control platform can communicate properly with all gateway devices in the network. Then, check whether the quantum security situational awareness platform can view data normally. Once this is confirmed, select a specific intelligence board and conduct joint commissioning testing with the quantum security edge gateway in front of it. Once this test is complete, the quantum security edge gateway can be debugged into control mode via the quantum security management and control platform to implement security protection for the intelligence board.
[0078] Global security policy issuance: After the equipment joint debugging test passes, the administrator can create a new operation and maintenance user account on the quantum security control platform and specify the access control policy. After the formulation is completed, the global security policy can be issued. After the global policy is issued, the operation and maintenance personnel can only access the information board equipment according to the assigned permissions, thereby improving the security of the information board publishing network.
[0079] The equipment list provided by the present invention is shown in Table 1: Table 1: Equipment list of the intelligence board quantum security protection system
[0080] The present invention also provides a method for quantum security protection of information boards, which is applied to the above-mentioned system, such as Figure 4 As shown, the method includes: S401: Build a zero-trust virtual network based on the quantum security control module 101, allocate an identity registration file to a communication node 103 of the zero-trust virtual network, and connect the communication node 103 to the zero-trust virtual network after the communication node 103 completes identity registration based on the identity registration file; the communication node 103 includes: a quantum gateway, a management terminal, and an information board device; S402: Sending the data to be transmitted to the zero-trust virtual network based on the management terminal; S403: quantum encrypt the data to be transmitted in the zero-trust virtual network using the quantum security key based on the quantum security service module 102 to obtain encrypted data; S404: Decrypt the encrypted data based on the quantum gateway and forward it to the intelligence board device through the zero-trust virtual network.
[0081] The above is a detailed introduction to the information board quantum security protection system and method provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method and core ideas of the present invention. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. An information board quantum security protection system, characterized in that: include: A quantum security control module is configured to construct a zero-trust virtual network, assign identity registration files to communication nodes in the zero-trust virtual network, and connect the communication nodes to the zero-trust virtual network after the communication nodes complete identity registration based on the identity registration files. The communication nodes include a quantum gateway, a management terminal, and an intelligence board device. The quantum gateway is configured to decrypt encrypted data and forward it to the intelligence board device via the zero-trust virtual network. The management terminal is configured to send data to be transmitted to the zero-trust virtual network. The quantum security service module is used to perform quantum encryption on data to be transmitted in the zero-trust virtual network based on the quantum security key, obtain encrypted data, and transmit the encrypted data back to the zero-trust virtual network.
2. The information board quantum security protection system according to claim 1, characterized in that: Also includes: The quantum security situation awareness module is used to receive data uploaded by the quantum gateway and visualize the data uploaded by the quantum gateway.
3. The information board quantum security protection system according to claim 2, characterized in that: The data uploaded by the quantum gateway includes: the operating status data of the communication node, the threat alarm data generated by the zero-trust virtual network, the quantum key consumption trend data and security risk events.
4. The information board quantum security protection system according to claim 2, characterized in that: The communication node also includes: a perception module; the perception module is used to send an alarm message to the quantum security situation perception module when it detects that the information board device has an abnormal operating status.
5. The information board quantum security protection system according to claim 4, characterized in that: The identification module is further configured to intercept decrypted data sent to the information board device when it is determined based on the identity registration file of the information board device that the registered identity of the information board device has changed.
6. The information board quantum security protection system according to claim 1, characterized in that: The zero-trust virtual network works at the network layer and the transport layer; The quantum security control module is further configured to set a virtual communication link policy for the network layer, so as to control data transmission of the zero-trust virtual network at the transport layer based on the virtual communication link policy.
7. The information board quantum security protection system according to claim 1, characterized in that: The quantum security control module is further configured to receive an access control policy input by a user and set access rights for the management terminal based on the access control policy.
8. The information board quantum security protection system according to claim 7, characterized in that: The quantum gateway includes: an edge-side gateway and a center-side gateway; The management terminal is used to send encrypted data to the center-side gateway; The central gateway is configured to decrypt the encrypted data to obtain decrypted data, and forward the decrypted data with the authentication tag to the edge gateway if the decrypted data is authorized to pass based on the access control policy; The edge layer gateway is used to forward the corresponding decrypted data to the intelligence board device through the zero-trust virtual network after identifying the authentication tag.
9. The information board quantum security protection system according to claim 8, characterized in that: The management terminal is used to send encrypted data to the central side gateway through the quantum secure tunnel.
10. A quantum security protection method for an information board, characterized in that: The method is applied to the system according to any one of claims 1 to 9, and the method includes: A zero-trust virtual network is constructed based on the quantum security control module, and identity registration files are allocated to communication nodes of the zero-trust virtual network. After the communication nodes complete identity registration based on the identity registration files, the communication nodes are connected to the zero-trust virtual network; the communication nodes include: a quantum gateway, a management terminal, and an intelligence board device; Sending the data to be transmitted to the zero-trust virtual network based on the management terminal; Based on the quantum security service module, the quantum security key is used to perform quantum encryption on the data to be transmitted in the zero-trust virtual network to obtain encrypted data; The encrypted data is decrypted based on the quantum gateway and then forwarded to the intelligence board device through the zero-trust virtual network.