A power distribution intelligent power distribution switch communication encryption method based on quantum security technology
By generating keys and dynamically encrypting them using quantum security technology, the reliability and versatility issues of communication encryption for smart power distribution switches are resolved, achieving end-to-end quantum-level secure communication and ensuring the confidentiality and integrity of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- WUXI DINGQUAN QUANTUM TECHNOLOGY CO LTD
- Filing Date
- 2025-07-07
- Publication Date
- 2026-05-08
AI Technical Summary
Existing intelligent power distribution switch communication encryption schemes suffer from poor reliability and diversity. Traditional encryption methods cannot effectively guarantee communication security, and fiber optic private network communication is costly while public network communication lacks security.
Quantum QKD keys and quantum random number keys are generated using quantum cryptography to power quantum CPE and quantum security gateways. Communication links are established through access authentication, and session keys are used for dynamic encrypted communication. IPsec tunnels and encryption algorithms are combined to ensure data transmission security.
It achieves end-to-end quantum-level secure communication, preventing eavesdropping and tampering, ensuring the confidentiality and integrity of data transmission, and improving the system's security, controllability, and anti-leakage capabilities.
Smart Images

Figure CN120639424B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication encryption technology, and specifically to a communication encryption method for intelligent power distribution switches based on quantum security technology. Background Technology
[0002] Currently, distribution automation emphasizes real-time two-way interaction, and the business only focuses on the security protection of the master station and the authentication of the terminal to the master station. Due to the large number of distribution automation terminals and the fact that the old terminals that have not been upgraded cannot support message encryption, the distribution automation system mainly adopts a one-way authentication compatibility mode. Effective security protection measures are urgently needed on the terminal side and the access network aggregation side.
[0003] Currently, smart switches mainly use fiber optic private networks or wireless public networks for communication, employing traditional encryption methods to improve communication security. However, this approach has the following drawbacks: using fiber optic private networks results in high communication costs and significant construction difficulties in certain scenarios; using public networks compromises communication security, limiting smart switches to only "remote control" functions; and traditional encryption technologies offer insufficient security. Summary of the Invention
[0004] The purpose of this invention is to provide a communication encryption method for intelligent power distribution switches based on quantum security technology, which solves the technical problems of poor reliability and versatility in the implementation of communication encryption for intelligent power distribution switches in existing solutions.
[0005] The objective of this invention can be achieved through the following technical solutions:
[0006] A communication encryption method for intelligent power distribution switches based on quantum security technology includes:
[0007] S1: Generate quantum QKD keys and quantum random number keys through a quantum key platform system, and use the quantum random number keys to charge the quantum CPE and quantum security gateway;
[0008] S2: Perform access authentication on the quantum CPE and the quantum security gateway, establish the communication link, and establish an IPsec tunnel;
[0009] S3: The quantum CPE requests to obtain the session key, which is transparently transmitted by the quantum security gateway. The quantum key platform system distributes the quantum key, including a one-time sealed package of the quantum random number key and the session key, and distributes it to the quantum security gateway and the quantum CPE.
[0010] S4: The quantum security gateway and quantum CPE deseal the received encapsulated session key, obtain and confirm the desealized session key, and communicate based on quantum security technology;
[0011] S5: The smart power distribution switch sends communication data to the quantum CPE via the network cable. After receiving the communication data sent by the smart power distribution switch, the quantum CPE uses the session key combined with the encryption algorithm to dynamically encrypt the communication data.
[0012] S6: The quantum security gateway decrypts the encrypted communication data according to the corresponding session key and encryption algorithm to obtain the original communication data sent by the smart power distribution switch, and then sends the original communication data to the master station.
[0013] Preferably, the specific implementation steps of S2 include: S21: connecting the smart power distribution switch to the quantum CPE, and the quantum security gateway identifying the smart power distribution switch based on the IP address and quantum CPE ID;
[0014] S22: Determine whether the connected smart power distribution switch is a legitimate terminal. If legitimate, proceed to the next step; if illegitimate, reject the connection.
[0015] S23: After determining that the connected smart power distribution switch is a legitimate terminal, the quantum CPE and the quantum security gateway establish an IPsec tunnel according to the IPsec protocol;
[0016] S24: After the IPsec tunnel is established, the quantum CPE communicates with the quantum security gateway to verify the availability of the channel using a three-way handshake.
[0017] S25: If it is confirmed to be feasible, conduct quantum secure communication network access verification for quantum CPE; if it is not feasible, conduct reconfirmation.
[0018] S26: After three failed confirmation attempts, the quantum CPE and the quantum security gateway release and re-establish the IPsec tunnel.
[0019] Preferably, the specific implementation steps of S3 include: S31: The quantum security gateway and the quantum CPE send a session key request to the key service platform; wherein the key length is agreed upon in advance in the key request;
[0020] S32: After receiving the session key request, the key service platform generates an encapsulation instruction and transmits the encapsulation instruction to the key generation system;
[0021] S33: After receiving the encapsulation instruction, the key generation system obtains the key length agreed upon in the key request, uses the protection key generated by the random number generator to encapsulate the session key generated by the QKD system in a one-time encapsulation, and after the encapsulation is completed, sends the session key to the quantum security gateway and the key service platform respectively, and then the key service platform forwards it to the quantum security gateway and the quantum security CPE.
[0022] S34: After receiving a sealed session key, the quantum security gateway and the quantum security CPE send a confirmation of key receipt to the key service platform; if only one party receives it, the original key is invalidated and steps S31 to S33 are repeated.
[0023] Preferably, the specific implementation steps of S4 include: S41: The quantum security gateway and the quantum CPE receive the encapsulated key and decrypt it using the injected key;
[0024] S42: After the quantum security gateway and quantum CPE have completed decryption, confirm whether the session key has been obtained, destroy the protection key using quantum random numbers, and notify and interact with the key service platform.
[0025] S43: After both the quantum security gateway and the quantum CPE confirm that they have obtained the session key, they will begin communication based on quantum security technology according to business needs;
[0026] S44: Update the session key according to the key service platform's distribution cycle and scheduling requirements.
[0027] Preferably, the specific implementation steps of S5 include: S51: When performing security quantization preprocessing on the session key, the information entropy of the key is calculated using an entropy value detection tool that complies with national cryptographic standards;
[0028] S52: Test and mark the session key's resistance to quantum attacks. If the session key is negotiated or distributed through a post-quantum cryptography algorithm, mark it as quantum-safe and set the corresponding capability value of the session key to a.
[0029] If the session key is negotiated using a traditional algorithm, it is marked as vulnerable to quantum attacks, and the capability value corresponding to the session key is set to b; both a and b are positive integers, and a > b;
[0030] S53: Through formula Calculate the security level value β of the obtained session key; where A and B are the information entropy and capability value of the session key, respectively; B is a or b; α is the weighting coefficient, which takes a value greater than or equal to 1; and C is the first standard security value.
[0031] Perform data analysis on the security level values, and associate the session key with low, medium, or high security levels based on the analysis results;
[0032] S54: When preprocessing communication data by sensitivity level and scenario classification, the corresponding sensitivity level is associated with the data type of the communication data. The sensitivity level includes high sensitivity level, medium sensitivity level or low sensitivity level.
[0033] S55: Obtain the security level associated with the session key and the sensitivity level associated with the communication data, and dynamically implement the first encryption scheme, the second encryption scheme, or the third encryption scheme.
[0034] Preferably, if the security level value is less than 1, the session key is associated with a lower security level;
[0035] If the security level value is greater than or equal to 1 and less than the second standard security value, then the security level in the session key will be associated with it.
[0036] If the security level value is greater than the second standard security value, then the session key will be associated with the higher security level.
[0037] Preferably, if a high security level and / or a high sensitivity level exists, the first encryption scheme is implemented;
[0038] If a medium security level and / or a medium sensitivity level exists, a second encryption scheme shall be implemented;
[0039] If a low security level and / or low sensitivity level exists, a third encryption scheme is implemented.
[0040] Preferably, the first encryption scheme adopts the AEAD mode;
[0041] The second encryption scheme adopts a single encryption + HMAC-SM3 authentication mode;
[0042] The third encryption scheme uses a single encryption mode.
[0043] Compared to existing solutions, the beneficial effects achieved by this invention are:
[0044] This invention generates QKD keys and quantum random number keys through a quantum key distribution platform and injects them into the quantum CPE and security gateway. This strengthens the initial security baseline of the devices, ensures anti-eavesdropping and anti-tampering throughout the communication link, and defends against potential threats such as quantum computing from the source, achieving end-to-end quantum-level secure communication. Access authentication ensures the trustworthiness of the quantum CPE and security gateway, eliminating the risk of unauthorized device access. Establishing an IPsec tunnel provides encryption protection for the communication link, ensuring the confidentiality and integrity of data transmission, and achieving reliable implementation of end-to-end secure communication.
[0045] This invention ensures consistency in key requirements between the quantum security gateway and the quantum CPE by pre-agreeing on key length, avoiding communication anomalies caused by length mismatch. Devices actively request session keys, supporting dynamic generation and on-demand distribution, improving key timeliness and anti-leakage capabilities. Simultaneously, the key service platform centrally responds to requests, enhancing system security and controllability. By desealing and confirming the session key, the integrity and accuracy of the key can be verified, preventing key invalidation due to transmission or encapsulation issues. The quantum CPE dynamically encrypts the communication data of the smart power distribution switch using the session key, effectively resisting eavesdropping and tampering risks during transmission. The dynamic encryption mechanism enhances data anti-decryption capabilities. The targeted use of the session key ensures encryption timeliness, building quantum-level security protection for the communication link of the smart power distribution system, ensuring the confidentiality and reliability of business data transmission. Attached Figure Description
[0046] The invention will now be further described with reference to the accompanying drawings.
[0047] Figure 1 This is a schematic diagram illustrating the principle of a communication encryption method for intelligent power distribution switches based on quantum security technology, according to the present invention.
[0048] Figure 2 This is a structural diagram of the quantum security gateway and the quantum CPE in this invention.
[0049] Figure 3 This is a structural diagram of the IPSec protocol system in this invention. Detailed Implementation
[0050] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0051] like Figure 1 As shown, this invention is a communication encryption method for intelligent power distribution switches based on quantum security technology, comprising:
[0052] like Figure 2 As shown, S1: The quantum QKD key and quantum random number key are generated through the quantum key platform system, and the quantum CPE and quantum security gateway are charged using the quantum random number key;
[0053] Among them, the quantum key generation system generates two quantum key sources: one is the quantum QKD key generated by the QKD system based on the BB84 protocol, and the other is the quantum random number key generated by the random number generator.
[0054] QKD system, short for Quantum Key Distribution system, is a technology that uses the principles of quantum mechanics to ensure communication security;
[0055] A random number generator (RNG) is a device or algorithm that can generate a series of unpredictable sequences of numbers. These sequences should statistically satisfy a uniform distribution, with each number having an equal probability of occurrence and no correlation between them.
[0056] In addition, the quantum QKD key generated by the QKD system is used as the session key, and the quantum random number key generated by the random number generator is used as the protection key;
[0057] After the quantum random machine generates a quantum random number key, it is stored in the exchange cryptographic machine. The quantum key filling system calls the quantum random number key through the exchange cryptographic machine and fills the U-shield and TF card with the key. The U-shield and TF card with the key filled are connected to the quantum security gateway and the quantum CPE respectively to ensure that the quantum key application system works normally.
[0058] In this embodiment of the invention, QKD keys and quantum random number keys are generated through a quantum key platform and injected into the quantum CPE and security gateway. This can strengthen the initial security baseline of the device, ensure anti-eavesdropping and anti-tampering throughout the communication link, resist potential threats such as quantum computing from the source, and achieve end-to-end quantum-level secure communication.
[0059] S2: Perform access authentication on the quantum CPE and the quantum security gateway, establish the communication link, and build an IPsec tunnel; specific steps include:
[0060] S21: Connect the smart power distribution switch to the quantum CPE. The quantum security gateway identifies the smart power distribution switch based on its IP address and the quantum CPE ID.
[0061] S22: Determine whether the connected smart power distribution switch is a legitimate terminal. If legitimate, proceed to the next step; if illegitimate, refuse access. Among them, the quantum security gateway checks whether the IP address and quantum CPE ID in the request message are consistent with the whitelist stored during the registration phase. If they are consistent, the connection is deemed legitimate; otherwise, the connection is deemed illegitimate.
[0062] S23: After determining that the connected smart power distribution switch is a legitimate terminal, the quantum CPE and the quantum security gateway establish an IPsec tunnel according to the IPsec protocol;
[0063] The IPSec protocol operates at the network layer. It deconstructs and encrypts network data at the IP layer of the protocol stack, then repackages the ciphertext into new IP layer data, thus providing encrypted protection for the original transparent IP data packets. The IPSec protocol architecture is as follows: Figure 3 As shown;
[0064] In addition, tunnel mode is the default mode for IPSec; in this mode, the IPSec protocol hides the entire original IP packet, encrypts the entire packet, adds a new IP header before the encrypted packet segment, and sends it to another gateway in the VPN tunnel; tunnel mode is typically used between gateways, or between an endpoint and a gateway, with the gateway acting as a proxy for its backend host; tunnel mode is used to encrypt data streams between two IPSec gateways.
[0065] S24: After the IPsec tunnel is established, the quantum CPE communicates with the quantum security gateway to verify the availability of the channel using a three-way handshake.
[0066] S25: If it is confirmed to be feasible, conduct quantum secure communication network access verification for quantum CPE; if it is not feasible, conduct reconfirmation.
[0067] S26: After three failed confirmation attempts, the quantum CPE and the quantum security gateway release and re-establish the IPsec tunnel;
[0068] The specific steps for verifying quantum secure communication using quantum CPE include:
[0069] S261: Quantum CPE initiates network access authentication to Quantum Security Gateway via IPsec tunnel;
[0070] S262: The quantum security gateway transmits the application information of the quantum CPE and the information of its connected U-shield and TF card to the key service platform.
[0071] S263: After receiving the network access authentication message 1, the key service platform queries the relevant information of the key being charged; message 1 is the network access authentication request message, which includes the terminal basic identification information, authentication type identification and optional extended information;
[0072] Among them, the basic identification information of the terminal includes: the unique ID of the quantum CPE (such as the device serial number and quantum communication module number) and the network access identifier (such as the IP address and MAC address).
[0073] Authentication type identifier: Indicates the purpose of this authentication, such as "first-time network access" or "key update";
[0074] Optional extended information: In some scenarios, it includes a list of encryption algorithms supported by the terminal, such as post-quantum cryptography algorithms, for negotiation authentication methods;
[0075] S264: The key service platform returns the relevant verification message2 to the quantum CPE, performs information comparison, and calculates the verification message3 required by the platform; message2 is the key service platform's verification response message, which includes the key-related parameters, authentication challenge value, and algorithm negotiation information;
[0076] Among them, the filling key associated parameters are as follows: if the filling key is a quantum key, such as a session key generated by QKD, it includes metadata such as key index and key length; if it is a traditional key, such as an AES key, it may include key version number or encryption salt value.
[0077] Authentication challenge value: A random number or timestamp generated by the platform to prevent replay attacks;
[0078] Algorithm negotiation information: Specifies the computation method to be used by the quantum CPE, such as hash algorithm SHA-3, signature algorithm EdDSA, etc.
[0079] message3 is the quantum CPE verification result message, which includes the calculation result value, timestamp or serial number and terminal identifier;
[0080] The calculated result values are: hash values (such as HMAC), signature values (such as EdDSA signatures), or encrypted challenge responses (such as encrypted random numbers using pre-stored keys) generated based on the charging key and message2 parameter.
[0081] Timestamp or serial number: Used to mark the validity of this authentication and avoid reuse;
[0082] Terminal identifier: The same quantum CPE ID as message1, ensuring correct message attribution;
[0083] S265: Send message 3 from the quantum CPE to the key service platform for verification and confirmation;
[0084] S266: The key service platform returns the verification result to the quantum CPE;
[0085] In this embodiment of the invention, access authentication ensures the trustworthiness of the quantum CPE and the security gateway, eliminating the risk of unauthorized device access; an IPsec tunnel is established to provide encryption protection for the communication link, ensuring the confidentiality and integrity of data transmission, and realizing the reliable implementation of end-to-end secure communication.
[0086] S3: The quantum CPE requests the session key, which is transparently transmitted by the quantum security gateway. The quantum key platform system distributes the quantum key, including a one-time sealed package of the quantum random number key and the session key, which is then distributed to the quantum security gateway and the quantum CPE; specifically including:
[0087] S31: The quantum security gateway and the quantum CPE send a session key request to the key service platform; the key length is agreed upon in advance in the key request;
[0088] S32: After receiving the session key request, the key service platform generates an encapsulation instruction and transmits the encapsulation instruction to the key generation system;
[0089] S33: After receiving the encapsulation instruction, the key generation system obtains the key length agreed upon in the key request, uses the protection key generated by the random number generator to encapsulate the session key generated by the QKD system in a one-time encapsulation, and after the encapsulation is completed, sends the session key to the quantum security gateway and the key service platform respectively, and then the key service platform forwards it to the quantum security gateway and the quantum security CPE.
[0090] S34: After receiving a sealed session key, the quantum security gateway and the quantum security CPE send an acknowledgment of key receipt to the key service platform; if only one party receives it, the original key is invalidated and steps S31 to S33 are repeated.
[0091] In this embodiment of the invention, by pre-agreeing on the key length, the consistency of key requirements between the quantum security gateway and the quantum CPE is ensured, avoiding communication anomalies caused by length mismatch; the device actively requests session keys to support dynamic generation and on-demand distribution, improving key timeliness and anti-leakage capability, while the key service platform centrally responds to requests, enhancing system security and controllability.
[0092] S4: The quantum-secure gateway and quantum CPE deseal the received encapsulated session key, obtain and confirm the desealable session key, and communicate based on quantum security technology; the specific steps include:
[0093] S41: The quantum security gateway and quantum CPE receive the encapsulated key and decrypt it using the injected key;
[0094] S42: After the quantum security gateway and quantum CPE have completed decryption, confirm whether the session key has been obtained, destroy the protection key using quantum random numbers, and notify and interact with the key service platform.
[0095] S43: After both the quantum security gateway and the quantum CPE confirm that they have obtained the session key, they will begin communication based on quantum security technology according to business needs;
[0096] S44: Update the session key according to the key service platform's distribution cycle and scheduling requirements;
[0097] In this embodiment of the invention, by unsealing and confirming the session key, the integrity and accuracy of the key can be verified, avoiding key failure due to transmission or encapsulation problems; combined with quantum secure communication technology, the anti-eavesdropping capability can be enhanced by utilizing the quantum non-cloning property, ensuring the confidentiality and security of data during communication, and realizing a reliable quantum-level secure communication link.
[0098] S5: The smart power distribution switch sends communication data to the quantum CPE via a network cable. After receiving the communication data sent by the smart power distribution switch, the quantum CPE dynamically encrypts the communication data using a session key combined with an encryption algorithm; the communication data can be plaintext data.
[0099] The specific steps for dynamic encryption include:
[0100] S51: When performing security quantization preprocessing on the session key, use a national cryptographically compliant entropy detection tool to calculate the information entropy of the key; wherein, the entropy detection tool is, for example, the NIST SP 800-90B method recommended by GM / T 0005-2012;
[0101] The higher the entropy value, the closer it is to the theoretical maximum value of 128 bits, the more secure the key.
[0102] For example: high entropy (≥120 bits), medium entropy (100-120 bits), low entropy (<100 bits);
[0103] S52: Test and mark the session key's resistance to quantum attacks. If the session key is negotiated or distributed using a post-quantum cryptography algorithm (such as SM9 identifier cryptography or Kyber lattice cryptography), mark it as quantum-safe and set the capability value corresponding to the session key to 'a'; post-quantum cryptography algorithms, such as SM9 identifier cryptography or Kyber lattice cryptography.
[0104] If the session key is negotiated using a traditional algorithm (such as RSA or Diffie-Hellman), it is marked as vulnerable to quantum attacks, and the capability value corresponding to the session key is set to b; both a and b are positive integers, and a > b;
[0105] S53: Through formula Calculate the security level value β of the obtained session key; where A and B are the information entropy and capability value of the session key, respectively; B is a or b; α is the weighting coefficient, which takes a value greater than or equal to 1; and C is the first standard security value.
[0106] If the security level value is less than 1, the session key will be associated with a lower security level.
[0107] If the security level value is greater than or equal to 1 and less than the second standard security value, then the security level in the session key will be associated with it.
[0108] If the security level value is greater than the second standard security value, then the session key will be associated with the higher security level.
[0109] The first standard safety value is less than the second standard safety value. The specific values are not limited and can be determined based on the big data of previous tests, or customized by professionals in the field according to the application requirements of the actual application scenario.
[0110] S54: When preprocessing communication data by sensitivity level and scenario classification, the corresponding sensitivity level is associated with the data type of the communication data. The sensitivity level includes high sensitivity level, medium sensitivity level or low sensitivity level.
[0111] Among them, the high sensitivity level requires confidentiality, integrity, and source authentication. For example, communication data may contain control commands, such as "circuit breaker trip"; identity authentication information may contain equipment certificates; and financial transaction data may contain sensitive information.
[0112] Medium Sensitivity Level: Requires confidentiality and basic integrity, such as communication data being status monitoring values, like voltage and current samples; configuration parameters, such as network addresses;
[0113] Low sensitivity level: Only confidentiality is required, such as communication data as log information, such as device startup time; non-sensitive metadata, such as software version number;
[0114] S55: Obtain the security level associated with the session key and the sensitivity level associated with the communication data, and dynamically implement the first encryption scheme, the second encryption scheme, or the third encryption scheme;
[0115] It is worth noting that, unlike existing technical solutions that use fixed encryption schemes, the embodiments of the present invention can effectively improve the targeting and flexibility of encryption for different communication data;
[0116] If a high security level and / or a high sensitivity level exists, the first encryption scheme shall be implemented.
[0117] If a medium security level and / or a medium sensitivity level exists, a second encryption scheme shall be implemented;
[0118] If a low security level and / or low sensitivity level exists, a third encryption scheme shall be implemented;
[0119] The first encryption scheme uses the AEAD mode;
[0120] The second encryption scheme uses a single encryption (such as CBC / CTR) + HMAC-SM3 authentication mode;
[0121] The third encryption scheme uses a single encryption mode, such as CTR stream mode;
[0122] In this embodiment of the invention, the communication data of the smart power distribution switch is dynamically encrypted using a session key via a quantum CPE, which can effectively resist the risks of eavesdropping and tampering during transmission. The dynamic encryption mechanism improves the data's anti-decryption capability. The targeted use of the session key ensures the timeliness of encryption, builds quantum-level security protection for the communication link of the smart power distribution system, and ensures the confidentiality and reliability of business data transmission.
[0123] S6: The quantum security gateway decrypts the encrypted communication data according to the corresponding session key and encryption algorithm to obtain the original communication data sent by the smart power distribution switch, and then sends the original communication data to the master station.
[0124] In this embodiment of the invention, the quantum security gateway accurately decrypts communication data using a session key and encryption algorithm, ensuring that only authorized devices can obtain the original information and effectively preventing the risk of data leakage. After decryption, the data is accurately transmitted to the master station, ensuring the information integrity and transmission reliability of the communication link of the intelligent power distribution system and supporting real-time and secure interaction of business data.
[0125] In the several embodiments provided by this invention, it should be understood that the disclosed system can be implemented in other ways. For example, the embodiments of the invention described above are merely illustrative; for example, the division of modules is only a logical functional division, and there may be other division methods in actual implementation.
[0126] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0127] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated module can be implemented in hardware or in the form of hardware plus software functional modules.
[0128] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the essential characteristics of the present invention.
[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A communication encryption method for intelligent power distribution switches based on quantum security technology, characterized in that, include: S1: Generate quantum QKD keys and quantum random number keys through a quantum key platform system, and use the quantum random number keys to charge the quantum CPE and quantum security gateway; S2: Perform access authentication on the quantum CPE and quantum security gateway, establish the communication link, and establish an IPsec tunnel; S3: The quantum CPE requests to obtain the session key, which is transparently transmitted by the quantum security gateway. The quantum key platform system distributes the quantum key, including a one-time sealed package of the quantum random number key and the session key, and distributes it to the quantum security gateway and the quantum CPE. S4: The quantum security gateway and quantum CPE deseal the received encapsulated session key, obtain and confirm the desealized session key, and communicate based on quantum security technology; S5: The smart power distribution switch sends communication data to the quantum CPE via the network cable. After receiving the communication data sent by the smart power distribution switch, the quantum CPE uses the session key combined with the encryption algorithm to dynamically encrypt the communication data. The specific implementation steps include: S51: When performing security quantization preprocessing on the session key, use a national cryptographically compliant entropy value detection tool to calculate the information entropy of the key; S52: Test and mark the session key's resistance to quantum attacks. If the session key is negotiated or distributed through a post-quantum cryptography algorithm, mark it as quantum-safe and set the corresponding capability value of the session key to a. If the session key is negotiated using a traditional algorithm, it is marked as vulnerable to quantum attacks, and the capability value corresponding to the session key is set to b; both a and b are positive integers, and a > b; S53: Through formula Calculate the security level value β of the obtained session key; where A and B are the information entropy and capability value of the session key, respectively; B is a or b; α is the weighting coefficient, which takes a value greater than or equal to 1; and C is the first standard security value. Perform data analysis on the security level values, and associate the session key with low, medium, or high security levels based on the analysis results; S54: When preprocessing communication data by sensitivity level and scenario classification, the corresponding sensitivity level is associated with the data type of the communication data. The sensitivity level includes high sensitivity level, medium sensitivity level or low sensitivity level. S55: Obtain the security level associated with the session key and the sensitivity level associated with the communication data, and dynamically implement the first encryption scheme, the second encryption scheme, or the third encryption scheme; S6: The quantum security gateway decrypts the encrypted communication data according to the corresponding session key and encryption algorithm to obtain the original communication data sent by the smart power distribution switch, and then sends the original communication data to the master station.
2. The method for encrypting communication between intelligent power distribution switches based on quantum security technology according to claim 1, characterized in that, The specific implementation steps of S2 include: S21: Connect the smart power distribution switch to the quantum CPE, and the quantum security gateway identifies the smart power distribution switch based on its IP address and the quantum CPE ID; S22: Determine whether the connected smart power distribution switch is a legitimate terminal. If legitimate, proceed to the next step; if illegitimate, reject the connection. S23: After determining that the connected smart power distribution switch is a legitimate terminal, the quantum CPE and the quantum security gateway establish an IPsec tunnel according to the IPsec protocol; S24: After the IPsec tunnel is established, the quantum CPE communicates with the quantum security gateway to verify the availability of the channel using a three-way handshake. S25: If it is confirmed to be feasible, conduct quantum secure communication network access verification for quantum CPE; if it is not feasible, conduct reconfirmation. S26: After three failed confirmation attempts, the quantum CPE and the quantum security gateway release and re-establish the IPsec tunnel.
3. The method for encrypting communication between intelligent power distribution switches based on quantum security technology according to claim 2, characterized in that, The specific implementation steps of S3 include: S31: The quantum security gateway and the quantum CPE send a session key request to the key service platform; wherein, the key length is agreed upon in advance in the key request; S32: After receiving the session key request, the key service platform generates an encapsulation instruction and transmits the encapsulation instruction to the key generation system; S33: After receiving the encapsulation instruction, the key generation system obtains the key length agreed upon in the key request, uses the protection key generated by the random number generator to encapsulate the session key generated by the QKD system in a one-time encapsulation, and after the encapsulation is completed, sends the session key to the quantum security gateway and the key service platform respectively, and then the key service platform forwards it to the quantum security gateway and the quantum security CPE. S34: After receiving a sealed session key, the quantum security gateway and the quantum security CPE send a confirmation of key receipt to the key service platform; if only one party receives it, the original key is invalidated and steps S31 to S33 are repeated.
4. The method for encrypting communication between intelligent power distribution switches based on quantum security technology according to claim 3, characterized in that, The specific implementation steps of S4 include: S41: The quantum security gateway and quantum CPE receive the encapsulated key and decrypt it using the injected key; S42: After the quantum security gateway and quantum CPE have completed decryption, confirm whether the session key has been obtained, destroy the protection key using quantum random numbers, and notify and interact with the key service platform. S43: After both the quantum security gateway and the quantum CPE confirm that they have obtained the session key, they will begin communication based on quantum security technology according to business needs; S44: Update the session key according to the key service platform's distribution cycle and scheduling requirements.
5. The method for encrypting communication between intelligent power distribution switches based on quantum security technology according to claim 1, characterized in that, If the security level value is less than 1, the session key will be associated with a lower security level. If the security level value is greater than or equal to 1 and less than the second standard security value, then the security level in the session key will be associated with it. If the security level value is greater than the second standard security value, then the session key will be associated with the higher security level.
6. The method for encrypting communication between intelligent power distribution switches based on quantum security technology according to claim 1, characterized in that, If a high security level and / or a high sensitivity level exists, the first encryption scheme shall be implemented; If a medium security level and / or a medium sensitivity level exists, a second encryption scheme shall be implemented; If a low security level and / or low sensitivity level exists, a third encryption scheme is implemented.
7. The method for encrypting communication between intelligent power distribution switches based on quantum security technology according to claim 6, characterized in that, The first encryption scheme uses the AEAD mode; The second encryption scheme adopts a single encryption + HMAC-SM3 authentication mode; The third encryption scheme uses a single encryption mode.
Citation Information
Patent Citations
Encryption communication method fusing quantum key and state secret CPE access device
CN117857026A
Quantum secret communication application security test method, system, device and medium
CN119696813A