Electric power communication network quantum reinforcement method for coping with joint network attack
By constructing a quantum-secure cyber-physical power system framework and a three-layer DAD model, combining the QKD module with the symmetric encryption algorithm, and optimizing the deployment of defense resources, the problems of insufficient defense and rough modeling of existing power communication networks in joint network attacks are solved, achieving efficient security and resilience improvements.
Patent Information
- Application Number
- CN202510791713.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-23
AI Technical Summary
When facing joint network attacks, the existing power communication network's defense measures rely on physical layer resources, which are costly and inflexible. The attack scenario modeling is simple and cannot reflect the actual attack strategy. The risk assessment indicators are one-sided and lack comprehensive guidance.
A quantum-safe cyber-physical power system framework resistant to cyber attacks is constructed. A three-layer DAD model is adopted, combined with the QKD module and symmetric encryption algorithm, to optimize the deployment of defense resources, establish a two-layer risk assessment indicator for information exposure risk and load loss, and achieve a balance between quantum security and high throughput performance through a hybrid encryption mechanism that combines quantum key generation with traditional encryption.
It has significantly improved the security and resilience of the power communication system in complex attack scenarios, achieved flexible deployment and rapid response, and multi-dimensional risk assessment provided guidance for the optimal allocation of defense resources, improving the system's adaptability and security level.
Smart Images

Figure CN120692017A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power system communication security, and relates to a quantum reinforcement method for a power communication network to cope with joint network attacks. Background Art
[0002] As the coupling of information and physics in power systems intensifies, the requirements for communication security and attack resistance are increasing. However, current power communication networks primarily rely on traditional encryption technologies (such as symmetric encryption and public-key authentication) for security. These security challenges are increasingly being challenged by complex cyberattacks and efficient quantum algorithms, making it difficult to meet the system's requirements for long-term, stable, and secure communication. Therefore, the exploration of new, forward-looking reinforcement methods is urgently needed.
[0003] Quantum Key Distribution (QKD), a communication technology with unconditional security, has been recognized as a crucial security defense resource for next-generation power communication systems. Some research has attempted to apply QKD to the encryption of power service links to enhance communication confidentiality. However, existing solutions primarily rely on point-to-point encryption, lack a systematic deployment strategy for the overall topology of power communication networks, and fail to fully consider the practical characteristics of cyberattacks, such as path selection, resource constraints, and coordination.
[0004] From the perspective of attack modeling, existing research lacks accurate characterization of cyberattacks in power systems. On the one hand, most work focuses on a single attack mode, which fails to reflect the combined strategies of multi-point coordination, eavesdropping, and tampering employed by real-world attackers. On the other hand, there is a lack of modeling of the propagation of cyberattacks at the information layer and how they induce error responses at the physical layer. Current mainstream defense models often simplify attacks as direct disruptions to the availability of physical equipment, prioritizing the hardening of physical components as the primary defense measure. This ignores the dominant role of information interference in the attack chain.
[0005] Therefore, although QKD technology has preliminary engineering capabilities, how to conduct security modeling, deployment optimization and collaborative defense design in power communication networks, and build an active defense model that takes into account resource constraints, network attack uncertainty and the relationship between attack and defense, is still a gap and challenge in existing technologies.
[0006] The existing methods for reinforcing power communication networks against cyber attacks have the following major shortcomings:
[0007] 1. Defense measures rely on physical layer resources, resulting in high costs and poor flexibility. Current defenses primarily rely on the reinforcement or repair of physical equipment, making it difficult to quickly respond to information layer attacks. This results in delayed responses and high investment costs.
[0008] 2. Attack scenario modeling is simple and cannot reflect real-world attack strategies. Most models only consider a single attack behavior and fail to accurately depict complex attack methods such as joint attacks and path control.
[0009] 3. Risk assessment indicators are one-sided and lack comprehensive guidance. Existing assessments focus primarily on physical losses, ignoring the quantification of information-level risks and are insufficient to guide optimal resource allocation. Summary of the Invention
[0010] The present invention aims to propose a quantum reinforcement method for power communication networks against coordinated network attacks. The method of the present invention constructs a quantum-safe cyber-physical power system framework for network attacks and proposes a three-layer defender-attacker-defender (DAD) model to systematically characterize the attack and defense process in which attackers launch coordinated network attacks and planners deploy quantum defense resources in cyber-physical coupled power systems. The model takes the two-layer risk assessment indicators of information leakage and load loss as optimization targets, comprehensively considers defense resource constraints, attack strategy constraints, and the operating constraints of power and communication networks, and realizes quantum defense strategy optimization and risk collaborative assessment in uncertain network attack scenarios, effectively improving the security and resilience of power systems under complex network attacks.
[0011] The technical solution adopted by the present invention to solve the technical problem is: a quantum reinforcement method for power communication networks to cope with joint network attacks, comprising the following steps:
[0012] Step 1: Build a quantum-safe cyber-physical power system framework that is resistant to cyberattacks. The system framework deploys QKD modules on optical fiber communication links and uses wavelength division multiplexing to achieve co-fiber transmission with traditional communication systems. The system framework includes quantum channels for key generation and classical channels for transmitting encrypted data.
[0013] Step 2: Based on the system framework built in step 1, a three-layer DAD model is established to optimize the quantum hardening solution under uncertain attack scenarios; the three-layer DAD model includes: grid planners, malicious attackers, and grid operators;
[0014] Step 3: Establish an objective function, using information exposure risk as the network layer indicator and load shedding as the physical layer indicator, to jointly establish a comprehensive security indicator for the quantum security network-physical power system;
[0015] Step 4: Establish constraints, including defense resource constraints, attack strategy constraints, power network operation constraints, and communication network operation constraints.
[0016] Step 5, problem decomposition and solution, using the column and constraint generation algorithm to solve the proposed three-layer DAD model optimization model;
[0017] Step 6: Establish the main problem;
[0018] Step 7: Create sub-problems;
[0019] Step 8: Solve the problem as a whole.
[0020] Preferably, in step 1, the power communication network structure is divided into three layers: an access layer, a backbone layer, and a core layer; the access layer is used to directly collect data from associated power nodes, the backbone layer is used to aggregate access layer data and conduct intra-regional communication, and the core layer is used as a dispatching center to receive backbone layer data and issue system control instructions;
[0021] The quantum key generated by QKD is combined with the symmetric encryption algorithm to construct a hybrid encryption mechanism, achieving a balance between quantum security and high-throughput encryption performance.
[0022] Preferably, in step 2, the grid planner formulates a defense strategy by deciding whether to reinforce the communication link, and the malicious attacker launches a coordinated network attack by choosing which communication links to monitor and how much false data to inject into a specific node; the grid operator optimally dispatches the grid according to the attacker's strategy to minimize system losses.
[0023] Preferably, in step 3, the comprehensive security index of the quantum security network-physical power system is:
[0024]
[0025] In formula (1), x represents the planner's defense strategy, a represents the attacker's attack strategy, y represents the operator's response to the attack scenario, and f i Risk represents the information risk of power node i, P i S represents the load loss of power node i, w i represents the load importance of power node i; where the information risk f of power node i i Risk for:
[0026]
[0027] In formula (2), the routing state g i,l Indicates whether the information of power node i is transmitted through communication link l, f i D represents the communication data volume of power node i, a l represents the attacker's strategy to attack the communication link l, x l represents the planner's strategy for defending communication link l.
[0028] More preferably, in step 4, the quantum defense resource deployment strategy constraint is:
[0029]
[0030] In formula (3): n l N represents the number of QKD modules required for quantum reinforcement on the communication link l. max represents the planner's total budget for deploying defense resources;
[0031] The joint attack strategy constraints considering eavesdropping and false information injection are:
[0032]
[0033] -ηP i L ≤ΔP i ≤η i P i L (10)
[0034] η i =βf i Risk (11)
[0035] In formulas (8) to (11), a max represents the attacker's resource budget; ΔP i represents the amount of false data injected into node i, η i Indicates the FDI attack intensity, P i L represents the original load of node i, β represents the coefficient of the relationship between FDI attack intensity and information risk of node i;
[0036] The power network operation constraints are:
[0037]
[0038] P l F =B l (θ i -θ j ) (13)
[0039]
[0040] 0≤P i S ≤P i (16)
[0041] -θ max ≤θ i ≤θ max (17)
[0042] In formulas (12) to (17), P l represents the power flow on the power line l, P i represents the load of node i after being tampered by the attacker, P i S represents the load shedding amount of node i, P i G represents the output power of the power generation node g, K L , K D , K G They represent the connection relationship between lines and nodes, load nodes and system nodes, and generation nodes and system nodes, respectively. l represents the admittance of line l, θ i represents the voltage phase angle at node i, θ j represents the voltage phase angle at node j, θ max They represent the upper limits of line power, generated power and voltage phase angle respectively;
[0043] The communication network operation constraints are:
[0044]
[0045] In formulas (18) to (20), the binary variable vector g i,l and g i,m They represent the information flow status of power node i on communication link l and communication node m respectively.
[0046] Preferably, the step 8 specifically includes the following sub-steps:
[0047] Step 8-1: Input the physical layer parameters and network layer parameters, set the upper bound UB = ∞, the lower bound LB = -∞, initialize the attack strategy and load shedding amount to empty, set the number of iterations k to 0, and set the threshold ε = 0.01;
[0048] Step 8-2: Solve the main problem, obtain ξ1 and the defense strategy, and update the lower bound LB = ξ1;
[0049] Step 8-3: Solve the subproblem under the given defense strategy to obtain the optimal attack plan and the corresponding target value ξ2, update the upper bound UB = min{UB,ξ2}, and add the corresponding attack vector and load shedding strategy to the main problem as new constraints;
[0050] Step 8-4: If (UB-LB) / LB≤ε, stop the iteration and output the optimal solution; otherwise, set k=k+1 and return to step 8-2.
[0051] The beneficial effects of the present invention are:
[0052] 1. This invention effectively solves the core problems of existing power communication network reinforcement methods, such as slow response, insufficient protection, rough modeling, and one-sided evaluation. It has technical advantages and practical value, and provides a feasible path and theoretical support for building a new power communication system with quantum security capabilities, significantly improving the security of the power communication system in complex attack scenarios.
[0053] 2. This invention introduces QKD technology to construct an active defense framework for the information layer. Compared with the high cost and slow response of physical equipment reinforcement methods, the QKD system can achieve flexible deployment and rapid response, significantly improving the system's adaptability to unknown attacks and effectively meeting the long-term demand for high-intensity security protection in power communications.
[0054] 3. This paper constructs a three-layer DAD model, which systematically depicts the attack and defense evolution process under various strategy combinations such as attack paths, monitoring points, and signal misleading, significantly improving the authenticity of modeling and the targetedness of strategy optimization.
[0055] 4. This invention introduces an information leakage metric based on traditional physical loss metrics to quantify the interference and guidance effects of attacks on communication links, thereby more comprehensively assessing the security threats facing the system. This multi-dimensional risk assessment mechanism can provide a more guiding basis for the optimal allocation of defense resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 This is a schematic diagram of a QKD-based secure communication process for a quantum reinforcement method for power communication networks to counter joint network attacks according to the present invention;
[0057] Figure 2 is a schematic diagram of a three-layer DAD model of the present invention;
[0058] Figure 3 It is a schematic diagram of the method steps of the present invention. DETAILED DESCRIPTION
[0059] The following will provide a clear and complete description of the relevant technologies in the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0060] refer to Figures 1 to 3 The quantum reinforcement method for power communication networks against joint network attacks in this embodiment includes the following steps:
[0061] Step 1. Construct a quantum-secured cyber-physical power system (QCPPS) framework that is resistant to cyber attacks. Figure 1 This is a QKD-based secure communication process. A QKD secure communication system consists of two channels: a quantum channel for key generation and a classical channel for transmitting encrypted data. During the key generation process, any eavesdropping inevitably perturbs the quantum state, leading to abnormal fluctuations in the key bit error rate. By detecting these anomalies in real time, stolen keys can be promptly discarded, retaining only secure keys for subsequent communications, thereby ensuring data integrity and confidentiality. Given the trend toward highly coupled cyber-physical systems, QKD can serve as a new defense resource, significantly enhancing the system's anti-attack capabilities and improving the overall cybersecurity of modern power systems.
[0062] The present invention adopts a relay strategy to deploy the QKD module on the optical fiber communication link, and realizes co-fiber transmission with the traditional communication system through wavelength division multiplexing, which has good compatibility and scalability. The power communication network structure can be further divided into three layers: the access layer (AL) directly collects data from the associated power nodes, the backbone layer (BL) aggregates the access layer data and conducts intra-regional communication; the core layer (CL) serves as the dispatching center to receive the backbone layer data and issue system control instructions. In terms of information encryption methods, the quantum key generated by QKD is combined with the symmetric encryption algorithm to construct a hybrid encryption mechanism to achieve a balance between quantum security and high-throughput encryption performance. In the above manner, QKD can be effectively embedded in the existing cyber-physical coupled power system (CPPS) to form a QCPPS framework.
[0063] The proposed QCPPS framework effectively counters various cyberattacks. On the one hand, any interception of the quantum channel is detected in real time by both legitimate communicating parties, triggering a key update mechanism to prevent key leakage and disrupt further attacker penetration. On the other hand, when attackers are unable to access real system data, their ability to construct effective attack vectors is significantly weakened, making it difficult to launch harmful coordinated attacks.
[0064] Step 2. Based on the QCPPS architecture built in step 1, a three-layer DAD model is established to optimize the quantum hardening solution under uncertain attack scenarios. Figure 2 This is a schematic diagram of the three-layer DAD model. Grid planners develop defense strategies by deciding whether to reinforce communication links. Malicious attackers launch coordinated cyberattacks by selecting which communication links to monitor and how much false data to inject into specific nodes. Grid operators optimally dispatch the grid based on the attackers' strategies to minimize system losses. The specific optimization objective function and constraints are shown in Steps 3 and 4.
[0065] Step 3. Establish an objective function. This paper uses information exposure risk as a network layer indicator and load shedding as a physical layer indicator to jointly establish a comprehensive security indicator for the quantum security network-physical power system. Its specific form is:
[0066]
[0067] Where: x is the planner's defense strategy; a is the attacker's attack strategy; y is the operator's response to the attack scenario; f i Risk is the information risk of power node i. i S is the load loss of power node i, w i is the load importance of power node i.
[0068] For a power user node, the information exposure risk is the cumulative exposure risk of all data flowing from the node through the communication link to the control center. The exposure risk of each link depends on whether the link is reinforced by the planner and whether the attacker chooses to monitor it:
[0069]
[0070] Where: Routing state g i,l Indicates whether the information of power node i passes through communication link l; f i D is the communication data volume of power node i.
[0071] Step 4. Establishing Constraints: The constraints included in the proposed model are: defense resource constraints, attack strategy constraints, power network operation constraints, and communication network operation constraints.
[0072] 1) The quantum defense resource deployment strategy constraints are:
[0073]
[0074] Where: n l N is the number of QKD modules required to deploy quantum reinforcement on the communication link l. max Total budget for deploying defense resources for planners.
[0075] The number of QKD modules required for each link is determined by the selected protocol, key rate, data flow, and relay distance.
[0076]
[0077] L'=f -1 (γ′) (5)
[0078]
[0079] γ=f(L) (7)
[0080] Among them, L l is the length of the communication link l, and L' is the relay distance. Considering the large scale and relatively fixed structure of the power system, the relay distance is set to a fixed value in this invention. If the link length is less than the relay distance, QKD modules can be directly deployed at both ends of the link for encryption; otherwise, relay QKD modules need to be deployed at equal intervals in the middle of the link for encryption. γ is the quantum key rate that is inversely proportional to the communication distance, γ' is the minimum key rate threshold required for the link, and N e Indicates the number of keys required by the encryption algorithm, N I is the total data volume of link l.
[0081] After the QKD module generates the quantum key, it uses a symmetric encryption algorithm to encrypt the power communication data. To strike a balance between security and usability, the present invention adopts a key rotation strategy, which rotates the key every time a fixed amount of data (δ) is encrypted. This reduces the risk of key leakage and ensures continuous confidentiality during communication.
[0082] 2) The joint attack strategy constraints considering eavesdropping and false information injection (FDI) are:
[0083]
[0084] -ηP i L ≤ΔP i ≤η i P i L (10)
[0085] η i =βf i Risk (11)
[0086] Where: a max is the attacker's resource budget; ΔP is the amount of false data injected into node i; η i is the FDI attack intensity; P i L is the original load of node i; β is the coefficient of the relationship between FDI attack intensity and the information risk of node i.
[0087] Equation (8) shows that the attacker's behavior is limited by the resource budget. Equations (9)-(11) describe the false data injection (FDI) attack model: Equation (9) ensures that the sum of the false data injected by all nodes in the system is zero, maintaining system power balance; Equation (10) indicates that the value of the false data injected by the node is proportional to the attack intensity and the original load, while ensuring that the load fluctuation is within a certain fluctuation range, thereby circumventing the system detection mechanism; Equation (11) describes the coupling relationship between the two attack types.
[0088] In traditional FDI attack models, the attack intensity coefficient is typically treated as a constant. However, this invention considers a more realistic attack process, where the injection of false information depends on whether eavesdropping has been previously successfully conducted. Typically, eavesdropping involves monitoring or intrusion into physical communication links, such as optical fibers, requiring actual physical manipulation, which consumes attack resources and is subject to budget constraints. FDI attacks, on the other hand, are essentially manipulation actions based on acquired information. Their success depends primarily on whether the attacker possesses sufficient system perception information. Therefore, in joint attack modeling, resource constraints apply only to eavesdropping, while FDI attacks no longer impose separate resource constraints.
[0089] 3) Power network operation constraints are:
[0090]
[0091] P l F =B l (θ i -θ j ) (13)
[0092]
[0093] 0≤P i S ≤P i (16)
[0094] -θ max ≤θ i ≤θ max (17)
[0095] Where, is the power flow on the power line l; P i,t represents the load of node i after being tampered by the attacker, is the load shedding amount of node i; is the output power of the power generation node g; K L , K D , K G Respectively represent the connection relationship between lines and nodes, load nodes and system nodes, and generation nodes and system nodes; Bl is the admittance of line l; θ i is the voltage phase angle at node i; θ max They are the upper limits of line power, generated power and voltage phase angle respectively.
[0096] Equation (12) expresses the power balance condition of each node; Equation (13) describes the line power flow based on the phase angle difference; Equation (14) limits the output power of the generating unit to not exceed its capacity; Equation (15) ensures that the load shedding on each bus does not exceed its total load after tampering; Equation (16) limits the power flow on each transmission line to not exceed its capacity; Equation (17) imposes upper and lower limit constraints on the voltage phase angle of each node, and specifies the phase angle of the reference node to be 0.
[0097] 4) Communication network operation constraints are:
[0098] In the communication network, each power user node i communicates with the control center node in the core layer through the AL node and the BL node. i,l and g i,m Represent the information flow status of power node i on communication link l and communication node m, respectively. A value of 1 indicates a pass, and a value of 0 indicates a fail. AL nodes only transmit data, while BL nodes handle both data reception and transmission. Since the data flow is destined for the control center, the control center node needs to receive data from all nodes in the system, as shown in the following equation:
[0099]
[0100]
[0101] The bandwidth usage of a node and link is equal to the sum of the bandwidth consumed by all data passing through the node and link, and cannot exceed the bandwidth capacity limit of the corresponding device, as shown in the following formula:
[0102]
[0103] Where, f l,max and f i,max denote the bandwidth capacity of the communication link l and node i, respectively. Since the bandwidth occupied by the key generation phase is negligible compared to the total bandwidth of the power fiber, this bandwidth limitation is mainly for encrypted data.
[0104] The communication delay between the user node and the control center is equal to the sum of the forwarding delay of all relay nodes and the transmission delay of all links on its data flow path. This total delay must not exceed the preset upper limit, as shown below:
[0105]
[0106] Where, and They represent the forwarding delay of communication node m and the transmission delay of link l, d max is the upper limit of communication delay. Since quantum keys are used in the same way as ordinary keys after generation, the communication delay at the forwarding node is consistent with traditional communication.
[0107] Step 5: Problem decomposition and solution. The present invention adopts the Column-and-Constraint Generation (C&CG) algorithm to solve the proposed three-layer optimization model. The model can be decomposed into two parts: the main problem and the sub-problem. The main problem determines the optimal defense planning strategy under a given attack plan; under the determined defense strategy, the sub-problem optimizes the most serious collaborative network attack scenario, which corresponds to a two-layer optimization model. The two-layer model can be transformed into a single-layer optimization problem through duality theory. The specific main problem and sub-problem forms are shown in steps 6 and 7 respectively. The algorithm solution process is shown in step 8.
[0108] Step 6: Establish the master problem. In the kth iteration, the attacker’s attack strategy is known and the operator's load shedding plan After that, the main problem is to determine the defense decision x of the communication link l With information flow routing {g r,l ,g r,i} to minimize the overall risk of the system. Its mathematical expression is as follows:
[0109]
[0110] From the planner's perspective, although operators make decisions based on fabricated information injected by attackers, their load shedding actions will be implemented in the physical system. Therefore, when assessing the system's true operating state, it is necessary to recalculate power flows to identify further constraint violations (e.g., line overloads) that may have been caused by misleading actions. In this scenario, additional load shedding can be considered an indicator of cascading failures. Therefore, the planner's primary goal is to minimize the risk of information exposure by strengthening critical communication links and proactively planning data transmission paths.
[0111] Step 7: Create sub-problems. Given the main problem, determine the defense solution. After routing the information flow, the subproblem is to find the most destructive attack strategy under this defense strategy {a l ,ΔP i}, and determine the corresponding load shedding amount {P i MSIts mathematical expression is as follows:
[0112]
[0113] Planners aim to mitigate the effects of cyberattacks by reinforcing communication networks. However, since they cannot directly intervene in the attacker's injection of false data or reduce load shedding on protected links, their strategy favors active defense over passive response. Meanwhile, operators respond only to the physical layer, lacking the ability to identify cyberattacks or adjust data routing, and only perform load shedding based on misleading information. Attackers bridge the two layers, selectively eavesdropping on key communication links to maximize the exposure of critical power nodes and generate FDI attack vectors that induce operators to respond incorrectly. This interaction pattern highlights the deep coupling and asymmetric game-playing nature of the information and physical layers in power systems.
[0114] In this model, the objective function contains product terms of binary decision variables. To linearize these bilinear terms, auxiliary binary variables are introduced and the Big-M method is employed, transforming the original nonlinear model into a mixed-integer linear program. This standard linearization method ensures the solvability of the model and facilitates its use with commercial solvers.
[0115] Step 8: Overall solution of the problem. The overall C&CG solution process of the proposed model is as follows:
[0116] 1) Input the physical layer parameters and network layer parameters. Set the upper bound UB = ∞, the lower bound LB = -∞, initialize the attack strategy and load shedding to empty, set the number of iterations k to 0, and set the threshold ε = 0.01.
[0117] 2) Solve the main problem. Obtain ξ1 and the defense strategy, and update the lower bound LB = ξ1.
[0118] 3) Solve the subproblem under the given defense strategy to obtain the optimal attack plan and the corresponding target value ξ2, update the upper bound UB = min{UB,ξ2}, and add the corresponding attack vector and load shedding strategy to the main problem as new constraints.
[0119] 4) If (UB-LB) / LB≤ε, stop the iteration and output the optimal solution; otherwise, set k=k+1 and return to 2).
[0120] The solution of this embodiment can be completed by a commercial solver, and ultimately the optimal quantum hardening solution for coordinating network attacks is obtained.
[0121] In summary, the present invention effectively solves the core problems of slow response, insufficient protection, rough modeling and one-sided evaluation in existing power communication network reinforcement methods by constructing a quantum-safe cyber-physical power system framework and a three-layer DAD model. It has technical advantages and practical value, and provides a feasible path and theoretical support for the construction of a new power communication system with quantum security capabilities, significantly improving the security of the power communication system in complex attack scenarios.
[0122] It should be emphasized that the above are only preferred embodiments of the present invention and do not limit the present invention in any form. Any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention are still within the scope of the technical solution of the present invention.
Claims
1. A quantum reinforcement method for power communication networks to cope with joint network attacks, characterized in that: The following steps are involved: Step 1: Build a quantum-safe cyber-physical power system framework that is resistant to cyberattacks. The system framework deploys a QKD module on an optical fiber communication link and uses wavelength division multiplexing to achieve co-fiber transmission with traditional communication systems. The system framework includes a quantum channel for key generation and a classical channel for transmitting encrypted data. Step 2: Based on the system framework built in step 1, a three-layer DAD model is established to optimize the quantum hardening solution under uncertain attack scenarios; The three-layer DAD model includes: grid planners, malicious attackers, and grid operators; Step 3: Establish an objective function, using information exposure risk as the network layer indicator and load shedding as the physical layer indicator, to jointly establish a comprehensive security indicator for the quantum security network-physical power system; Step 4: Establish constraints, including defense resource constraints, attack strategy constraints, power network operation constraints, and communication network operation constraints. Step 5, problem decomposition and solution, using the column and constraint generation algorithm to solve the proposed three-layer DAD model optimization model; Step 6: Establish the main problem; Step 7: Create sub-problems; Step 8: Solve the problem as a whole.
2. The method for quantum reinforcement of power communication networks against joint network attacks according to claim 1 is characterized in that: In step 1, the power communication network structure is divided into three layers: an access layer, a backbone layer, and a core layer; the access layer is used to directly collect data from associated power nodes, the backbone layer is used to aggregate access layer data and conduct intra-regional communication, and the core layer is used as a dispatch center to receive backbone layer data and issue system control instructions; The quantum key generated by QKD is combined with a symmetric encryption algorithm to construct a hybrid encryption mechanism, achieving a balance between quantum security and high-throughput encryption performance.
3. The method for quantum reinforcement of power communication networks against joint network attacks according to claim 1 is characterized in that: In step 2, the grid planner formulates a defense strategy by deciding whether to reinforce communication links, and the malicious attacker launches a coordinated network attack by selecting which communication links to monitor and how much false data to inject into specific nodes; the grid operator optimally dispatches the grid according to the attacker's strategy to minimize system losses.
4. The method for quantum reinforcement of power communication networks against joint network attacks according to claim 1 is characterized in that: In step 3, the comprehensive security index of the quantum security network-physical power system is: In formula (1), x represents the planner's defense strategy, a represents the attacker's attack strategy, y represents the operator's response to the attack scenario, and f i Risk represents the information risk of power node i, P i S represents the load loss of power node i, w i represents the load importance of power node i; where the information risk f of power node i i Risk for: In formula (2), the routing state g i,l Indicates whether the information of power node i is transmitted through communication link l, f i D represents the communication data volume of power node i, a l represents the attacker's strategy to attack the communication link l, x l represents the planner's strategy for defending communication link l.
5. The method for quantum reinforcement of power communication networks against joint network attacks according to claim 4 is characterized in that: In step 4, the quantum defense resource deployment strategy constraints are: In formula (3): n l N represents the number of QKD modules required for quantum reinforcement on the communication link l. max represents the planner's total budget for deploying defense resources; The joint attack strategy constraints considering eavesdropping and false information injection are: -ηP i L ≤ΔP i ≤η i P i L (10) ηi=βf i Risk (11) In formulas (8) to (11), a max represents the attacker's resource budget; ΔP i represents the amount of false data injected into node i, η i Indicates the FDI attack intensity, P i L represents the original load of node i, β represents the coefficient of the relationship between FDI attack intensity and information risk of node i; The power network operation constraints are: P l F =B l (i i -θ j ) (13) 0≤P i S≤P i (16) -θ max ≤θ i ≤θ max (17) In formulas (12) to (17), P l F represents the power flow on the power line l, P i represents the load of node i after being tampered by the attacker, P i S represents the load shedding amount of node i, P i G represents the output power of the power generation node g, K L , K D , K G They represent the connection relationship between lines and nodes, load nodes and system nodes, and generation nodes and system nodes, respectively. l represents the admittance of line l, θ i represents the voltage phase angle at node i, θ j represents the voltage phase angle at node j, θ max They represent the upper limits of line power, generated power and voltage phase angle respectively; The communication network operation constraints are: In formulas (18) to (20), the binary variable vector g i,l and g i,m They represent the information flow status of power node i on communication link l and communication node m respectively.
6. The method for quantum reinforcement of power communication networks against joint network attacks according to claim 1 is characterized in that: The step 8 specifically includes the following sub-steps: Step 8-1: Input the physical layer parameters and network layer parameters, set the upper bound UB = ∞, the lower bound LB = -∞, initialize the attack strategy and load shedding amount to empty, set the number of iterations k to 0, and set the threshold ε = 0.01; Step 8-2: Solve the main problem, obtain ξ1 and the defense strategy, and update the lower bound LB = ξ1; Step 8-3: Solve the subproblem under the given defense strategy to obtain the optimal attack plan and the corresponding target value ξ2, update the upper bound UB = min{UB,ξ2}, and add the corresponding attack vector and load shedding strategy to the main problem as new constraints; Step 8-4: If (UB-LB) / LB≤ε, stop the iteration and output the optimal solution; Otherwise, set k=k+1 and return to step 8-2.