Quantum encryption communication optimization method suitable for smart power grid
By real-time monitoring of link node status in smart grids, combined with quantum encryption communication optimization methods, and dynamic path selection, the problems of high path selection dependence and insufficient security in existing technologies are solved, and intelligent dynamic optimization of communication paths and security improvement are achieved.
Patent Information
- Application Number
- CN202510844404.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-06-23
AI Technical Summary
Existing encryption communication technologies have problems such as high dependence on path selection and real-time changes in complex communication networks, performance bottlenecks when handling complex environments, and limited security improvements.
By sniffing available communication paths in the communication network topology, monitoring the security of link node status in real time, identifying and screening the best and backup paths, combining the superposition and entanglement characteristics of quantum states, dynamically optimizing communication paths, using quantum characteristics to evaluate node status change trends, setting path offline and recovery mechanisms and jump command restrictions.
It realizes intelligent dynamic optimization of communication paths, improves the flexibility and scientificity of path selection, accurately evaluates node status in real time, resists quantum computing attacks, and ensures the security and stability of the communication process.
Smart Images

Figure CN120692018A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption communication technology, and in particular to a quantum encryption communication optimization method suitable for smart grids. Background Art
[0002] Quantum encryption communication in smart grids integrates quantum information technology with power grid communication systems, and utilizes the superposition and entanglement characteristics of quantum states to achieve unconditional security in key distribution, thereby resisting the risk of quantum computing cracking faced by traditional encryption. It can ensure the security of power dispatching, user data and other transmissions, enhance the anti-attack capabilities of power grid communications, and provide core technical support for building a more reliable smart grid security system.
[0003] The invention patent application with application number 202411173242.0 discloses an encryption optimization method for data communication, which includes the following steps: S1. Construction of an intelligent encryption algorithm library: Design an intelligent algorithm library containing multiple encryption algorithms, covering multiple types of symmetric encryption, asymmetric encryption and hybrid encryption: The intelligent algorithm library selects the encryption algorithm for the current data communication environment through analysis and learning of historical communication data; S2. Multi-level encryption strategy and chain optimization: S2.1. Layered processing of data according to sensitivity and priority, each layer uses different encryption algorithms and keys and uses a security architecture in which the upper-layer encrypted data depends on the lower-layer keys; S2.2. Through the design of a chain-dependent structure, the encryption results of each layer affect the encryption parameter selection and optimization of the next layer; S3. Adaptive key management and distribution optimization: S3.1. Based on the dynamic changes of the communication environment and data transmission requirements, an adaptive key generation and update strategy is designed, wherein the key The key generation process combines the hardware characteristics of the device with the real-time network status; S3.2, adopts an optimized distributed key distribution mechanism, combines the data traffic on the encryption link and the load of the network node, dynamically selects the distribution path, and synchronizes the key through the chain encryption result; S4, end-to-end encryption optimization and multi-channel transmission: S4.1, divides the data into multiple fragments, and encrypts and transmits them through different transmission channels; each channel uses an independent encryption algorithm and key, while ensuring the integrity and independence of each data fragment; S4.2, based on the adaptive key management strategy, dynamically optimizes the encryption path of each transmission channel; and during the data transmission process, selects the path and channel according to the real-time monitored network status, and adjusts and optimizes it based on the chain optimization results. This application aims to solve the problem that "the existing encryption technology has a high dependence, may have performance bottlenecks when dealing with complex communication environments, and has limited security improvements."
[0004] However, in the field of encrypted communication optimization technology, how to select and change communication paths in real time in complex communication networks to ensure the security of the communication process is also a topic worthy of in-depth research; To this end, a quantum encryption communication optimization method suitable for smart grids is proposed. Summary of the Invention
[0005] In response to the above-mentioned shortcomings of the prior art, the present invention provides a quantum encryption communication optimization method suitable for smart grids, which can effectively solve the problems of the prior art.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: The present invention discloses a quantum encryption communication optimization method applicable to smart grids, comprising: Acquire the communication network topology, sniff the available communication paths in the communication network topology, monitor the status security of each link node in the communication network in real time, and identify the security indicators of each available communication path based on the link node status security monitoring results; monitor the link nodes for obtaining communication requests and the link nodes targeted by the communication requests in the communication network topology, query the available communication paths that meet the communication conditions based on the monitored link nodes, and simultaneously set the available communication path screening threshold. Based on the available communication path screening threshold, select the best communication path and the backup communication path from the queried available communication paths; apply the best communication path to obtain the communication request The link node and the communication request target point to the link node, continuously monitor the status security of each link node in the optimal communication path, and decide whether to change the communication path based on the trend of the change in the status security of each link node; if the decision result is no, then the application of the optimal communication path is maintained; if the decision result is yes, then a backup communication path is selected from all backup communication paths as the communication path change target, and the backup communication path pointed to by the change result is re-recorded as the optimal communication path; execute the jump command, and jump to the execution stage of continuously monitoring the status security of each link node in the optimal communication path and deciding whether to change the communication path based on the trend of the change in the status security of each link node.
[0007] Furthermore, when sniffing available communication paths in the communication network topology, any two or more link nodes are selected in the communication network topology, the selected link nodes are used as sniffing targets, and all communication paths that can cover the selected link nodes are sniffed in the communication network topology; When selecting link nodes in the communication network topology, all combinations of any two or more link nodes are used as sniffing targets; Among them, after obtaining the communication request, each link node in the communication network synchronously obtains the link node pointed to by the communication request, and uses the link node of the communication request and the link node pointed to by the communication request as query targets, and queries all available communication paths that contain the link node of the communication request and the link node pointed to by the communication request.
[0008] Furthermore, the link node status security monitoring logic is expressed as: ; Where: The link node status security; is the total number of vulnerabilities on the link nodes; The score of the ith vulnerability on the node obtained by the CVSS (Critical Vulnerability Scoring System); is the weight of the i-th vulnerability; This is the score of the currently used encryption algorithm based on the NIST standard; QBER is the quantum channel bit error rate; is the attack frequency per unit time; is the proportion of malicious traffic; is the maximum attack frequency of the corresponding node in the network history; The maximum malicious traffic ratio corresponding to the node in the network history; Among them, the weight values of vulnerabilities are all positive and less than 1. And it obeys the setting logic that the more times the vulnerability appears in each link node, the larger the value is.
[0009] Furthermore, the security index of each available communication path is identified based on the security monitoring results of each link node status: ; Where: is the security indicator of the available communication path L; is the total number of link nodes on the available communication path L; is the corresponding state security of the j-th link node; is the scale factor; The corresponding state security of the link node between the j-th link node and the central link node of the network topology, which is closest to the j-th link node and directly connected to the j-th link node; is the calibration factor; Among them, the scale factor The value is 0.4 or 0.6. , scale factor The value is 0.6, otherwise the proportional factor The value is 0.4, the calibration factor The value range is between 0.5 and 1, and the more link nodes on the available communication path L, the greater the calibration factor The smaller the value, the smaller the calibration factor. The larger the value.
[0010] Furthermore, the available communication path screening threshold is customized by the user end based on the security index of the available communication path, and all available communication paths corresponding to security indexes greater than the available communication path screening threshold are used as screening results. The available communication paths are simultaneously sorted from largest to smallest according to the security indexes corresponding to the available communication paths included in the screening results. The available communication path at the top of the sorting results is selected as the optimal communication path, and the remaining available communication paths are selected as backup communication paths. Among them, after the backup communication path is determined, the number of link nodes in the intersection of the link nodes included in each backup communication path and the link nodes included in the optimal communication path is synchronously identified. For the intersection of the link nodes included in the backup communication path and the link nodes included in the optimal communication path, after the number of link nodes in the intersection of the link nodes included in the backup communication path and the link nodes included in the optimal communication path is subtracted from the number of link nodes for obtaining the communication request and the number of link nodes pointed to by the communication request target, the backup communication path whose number of link nodes in the intersection is still greater than 1 is regarded as the abandonment target, and the abandonment operation is performed.
[0011] Furthermore, after the optimal communication path is screened and determined, the optimal communication path only serves the link node currently receiving the communication request and the link node to which the communication request is directed. All backup communication paths will no longer be selected as backup communication paths when a new communication task occurs in the communication network while the link node currently receiving the communication request and the link node to which the communication request is directed have not yet completed communication. After the link node currently acquiring the communication request and the link node targeted by the communication request complete communication, the status of the optimal communication path and the backup communication path changes to available.
[0012] Furthermore, when deciding whether to change the communication path based on the security change trend of each link node status, the following conditions must be followed: Each node on the optimal communication path is marked as ; Then For example, The continuously monitored state safety is recorded as , Similarly; Logic 1: The security of the status of each node in the two latest monitorings is more than half, and both show a downward trend; Logic 2: On the optimal communication path, the security of the latest three monitoring states of at least two consecutive nodes shows a continuous downward trend; Among them, when any one or more of Logic1 and Logic2 is true, the decision result is to change the communication path. When neither Logic1 nor Logic2 is true, the decision result is to maintain the application of the optimal communication path.
[0013] Furthermore, when changing the communication path, the following conditions must be followed: ; Where: is the recommendation index for the alternative communication path; is the security indicator of the backup communication path; is the total number of link nodes on the backup communication path; is the value of the shortest straight-line distance between the vth link node and the best communication path last applied; When changing a communication path, the backup communication path with the highest recommendation index is used as the change target.
[0014] Furthermore, during the communication path changing operation phase, the best communication path last used is offline in the communication network. After the communication path is changed and the communication task is completed, the offline communication path is restored in the communication network.
[0015] Furthermore, after the jump command is executed more than three times in a row, the communication network ends the current communication request when the jump command is executed next time, and within a preset time threshold, no longer provides a communication path for the link node that obtains the communication request and the link node pointed to by the communication request target.
[0016] Compared with the prior art, the technical solution provided by the present invention has the following beneficial effects: The present invention provides a quantum encryption communication optimization method suitable for smart grids. During the execution of this method, fully available communication paths are obtained through sniffing of all combined link nodes. Combined with customized screening thresholds and security index ranking, the method can accurately select the best and backup paths, changing the traditional fixed path mode and improving the flexibility and scientificity of path selection. In terms of security assessment, the constructed link node status security monitoring model comprehensively considers multi-dimensional dynamic parameters such as the number of vulnerabilities, scores, encryption algorithms, bit error rates, and attack frequencies, breaking through the limitations of single indicator evaluation. It can accurately evaluate the node status in real time, and decide whether to change the path based on the node status change trend. The backup path is optimized through a recommendation index model. In addition, a path offline and recovery mechanism and a jump command execution time limit are set to fully realize the intelligent dynamic optimization of the communication path. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.
[0018] Figure 1Schematic diagram of a flow chart of a quantum encryption communication optimization method suitable for smart grids. DETAILED DESCRIPTION
[0019] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0020] The present invention will be further described below with reference to the embodiments.
[0021] Example:
[0022] A quantum encryption communication optimization method applicable to smart grids in this embodiment is as follows: Figure 1 As shown, including: Step 1: Obtain the communication network topology, sniff available communication paths in the communication network topology, monitor the security of each link node in the communication network in real time, and identify the security indicators of each available communication path based on the link node status security monitoring results; When sniffing available communication paths in a communication network topology, any two or more link nodes are selected in the communication network topology, the selected link nodes are used as sniffing targets, and all communication paths that can cover the selected link nodes are sniffed in the communication network topology; When selecting link nodes in the communication network topology, all combinations of any two or more link nodes are used as sniffing targets; wherein, after obtaining a communication request, each link node in the communication network synchronously obtains a link node to which the communication request is directed, takes the link node to which the communication request is obtained and the link node to which the communication request is directed as query targets, and queries all available communication paths including the link node to which the communication request is obtained and the link node to which the communication request is directed; The link node status security monitoring logic is expressed as: ; Where: The link node status security; is the total number of vulnerabilities on the link nodes; The score of the ith vulnerability on the node obtained by the CVSS (Critical Vulnerability Scoring System); is the weight of the i-th vulnerability; This is the score of the currently used encryption algorithm based on the NIST standard; QBER is the quantum channel bit error rate; is the attack frequency per unit time; is the proportion of malicious traffic; is the maximum attack frequency of the corresponding node in the network history; is the maximum malicious traffic ratio of the corresponding node in the network history. The weight of the vulnerability is always positive and less than 1. And it obeys the setting logic that the more times the vulnerability appears in each link node, the larger its value is; Through the above logical formula, the security of link node status is quantitatively monitored; The security indicators of each available communication path are identified based on the security monitoring results of each link node status: ; Where: is the security indicator of the available communication path L; is the total number of link nodes on the available communication path L; is the corresponding state security of the j-th link node; is the scale factor; The corresponding state security of the link node between the j-th link node and the central link node of the network topology, which is closest to the j-th link node and directly connected to the j-th link node; is the calibration factor; Among them, the scale factor The value is 0.4 or 0.6. , scale factor The value is 0.6, otherwise the proportional factor The value is 0.4, the calibration factor The value range is between 0.5 and 1, and the more link nodes on the available communication path L, the greater the calibration factor The smaller the value, the smaller the calibration factor. The larger the value; The above logical formula is used to quantitatively evaluate the security of each available communication path, providing support for the subsequent selection of the optimal communication path and backup communication paths in the method of this embodiment. Step 2: Monitor the communication network topology to obtain the link nodes of the communication request and the link nodes to which the communication request is directed, query the available communication paths that meet the communication conditions based on the monitored link nodes, and simultaneously set the available communication path screening threshold. Based on the available communication path screening threshold, select the best communication path and the backup communication path from the queried available communication paths; The available communication path screening threshold is customized by the user end based on the security index of the available communication path. All available communication paths with security indexes greater than the available communication path screening threshold are used as screening results. The available communication paths are sorted from largest to smallest according to the security indexes of the available communication paths included in the screening results. The available communication path with the highest position in the sorting result is selected as the optimal communication path, and the remaining available communication paths are selected as backup communication paths. After the backup communication paths are determined, the number of link nodes in the intersection of the link nodes included in each backup communication path and the link nodes included in the optimal communication path is synchronously identified. After the number of link nodes in the intersection of the link nodes included in the backup communication paths and the link nodes included in the optimal communication paths is subtracted from the number of link nodes for obtaining the communication request and the number of link nodes directed to the communication request target, the backup communication paths whose number of link nodes in the intersection is still greater than 1 are regarded as discarded targets and discarded. After the optimal communication path is screened and determined, it will only serve the link node that currently receives the communication request and the link node that the communication request is directed to. All backup communication paths will no longer be selected as backup communication paths when new communication tasks appear in the communication network while the link node that currently receives the communication request and the link node that the communication request is directed to have not yet completed communication. After the link node currently receiving the communication request and the link node targeted by the communication request complete communication, the status of the optimal communication path and the backup communication path changes to available; Step 3: Apply the optimal communication path to the link node that receives the communication request and the link node that the communication request is directed to. Continuously monitor the status security of each link node in the optimal communication path. Based on the trend of the status security of each link node, decide whether to change the communication path. Step 4: If the decision result is no, the application of the optimal communication path is maintained; if the decision result is yes, a backup communication path is selected from all backup communication paths as the communication path change target, and the backup communication path pointed to by the change result is re-recorded as the optimal communication path; When deciding whether to change the communication path based on the security trend of each link node status, the following must be followed: Each node on the optimal communication path is marked as ; Then For example, The continuously monitored state safety is recorded as , Similarly; Logic 1: The security of the status of each node in the two latest monitorings is more than half, and both show a downward trend; Logic 2: On the optimal communication path, the security of the latest three monitoring states of at least two consecutive nodes shows a continuous downward trend; When any one of Logic1 and Logic2 is true, the decision result is to change the communication path. When neither Logic1 nor Logic2 is true, the decision result is to maintain the application of the optimal communication path. When changing the communication path, obey: ; Where: is the recommendation index for the alternative communication path; is the security indicator of the backup communication path; is the total number of link nodes on the backup communication path; is the value of the shortest straight-line distance between the vth link node and the best communication path last applied; When changing the communication path, the backup communication path with the highest recommendation index is used as the change target; The above logic formula further improves the communication path change logic to ensure timely response and change to the optimal backup communication path when there is a need to change the communication path in the communication scenario; Step 5: Execute the jump command to jump to the execution phase of continuously monitoring the status security of each link node in the optimal communication path and deciding whether to change the communication path based on the trend of the status security change of each link node; During the communication path change operation phase, the previously used optimal communication path is offline in the communication network. After the communication path is changed and the communication task is completed, the offline communication path is restored in the communication network. After the jump command is executed more than three times in a row, the communication network ends the current communication request when the jump command is executed next time, and no longer provides a communication path for the link node that obtains the communication request and the link node pointed to by the communication request within the preset time threshold.
[0023] When the method in the above embodiment is applied to the quantum encryption communication scenario of the smart grid, it effectively realizes the full optimization and control of the communication link during the encryption communication process, ensuring the security and stability of the communication process.
[0024] In the smart grid quantum encryption communication process of this embodiment, the characteristics of quantum state superposition and quantum entanglement run through the entire process of communication path security assessment and data transmission: Security protection mechanism of quantum state superposition: When two communicating parties generate keys through the quantum key distribution (QKD) protocol, a single photon is in a superposition state (such as horizontal polarization With vertical polarization Information is transmitted through a superposition of states (e.g., quantum entanglement). For example, the sender prepares a sequence of photons in a superposition state, and the receiver randomly selects a basis vector (such as the orientation of a polarizer) to measure the photons. Both parties compare the basis vectors for consistency over a classical channel, eliminating bit errors and generating the final key. Due to the quantum no-cloning theorem, an eavesdropper cannot copy the superposition photons. The measurement inevitably perturbs the quantum state, causing both communicating parties to detect an abnormal bit error rate (e.g., a significant increase in the QBER), thus promptly detecting the eavesdropping attempt.
[0025] Real-time synchronization characteristics of quantum entanglement: For the communication nodes of the smart grid with wide distribution, entangled photon pairs (such as Bell states) are prepared in advance through quantum entanglement sources and distributed to different substations (link nodes). When a node measures the polarization of an entangled photon, its remote entangled photon will instantly collapse to a correlated state, realizing real-time synchronous update of the key. For example, if nodes S1 and S5 in path L4 share an entangled photon pair, when S1 measures the polarization of the photon, When the base is measured, the entangled photons of S5 will immediately show the corresponding or This feature ensures the instantaneity of key updates and path switching, and resists relay attacks.
[0026] Integration of quantum properties and path security indicators: The above quantum characteristics directly affect the quantitative assessment of the security of link node status: Encryption Algorithm Score (E_score): The security of quantum encryption algorithms (such as the BB84 protocol) relies on the characteristics of quantum states. Their scoring must combine indicators such as the quantum channel bit error rate (QBER) and entanglement fidelity, rather than the single computational complexity assessment of traditional encryption algorithms.
[0027] Attack frequency (AF) and malicious traffic (MTP): The unconditional security of quantum communication can resist traditional computing power attacks (such as RSA decomposition), but it requires additional monitoring of attack types unique to quantum channels (such as photon number splitting attacks and Trojan horse attacks). Therefore, the quantum attack event dimension needs to be independently divided in the statistics of AF and MTP.
[0028] The following is an example application of the method in the above embodiment: The xx regional smart grid requires establishing an encrypted communication link between the control center node A and the distributed energy storage cluster node B to transmit real-time grid operation data. The network topology includes seven link nodes and three potential communication paths (Path 1: ACB; Path 2: ADEB; Path 3: AFGB). Quantum characteristic indicators (quantum channel bit error rate (QBER), quantum optical interference, and photon detection count change rate) must be combined to dynamically optimize the paths and determine attack risks.
[0029] Step 1: Path Sniffing and Security Initialization Sniffing range: Targeting nodes A, B, and the topology center node C, traverse the paths of all covered nodes and identify three available paths.
[0030] Quantum property index collection: QBER: Monitoring by the quantum key distribution system shows that the QBER of the AC link in path 1 is 1.5% (normal threshold ≤ 2%), and the QBER of the DE link in path 2 suddenly increases to 2.9% (close to the attack warning value of 3%).
[0031] Quantum optical interference: Measured using a quantum interferometer, the interference of the FG link in path 3 is 86% (the ideal value is ≥95%, indicating abnormal photon state coherence).
[0032] Photon detection count change rate: The CB link change rate in path 1 is 4.5% / min (the normal threshold is ≤ 3%, indicating a possible photon interception attack).
[0033] Security calculation: The security of each node is calculated using the link node status security formula (link node status security is the sum of the product of the vulnerability scores and weights divided by the total number of link node vulnerabilities, multiplied by the current encryption algorithm score, and then multiplied by the product of (1 minus the ratio of the link bit error rate to the historical maximum bit error rate), (1 minus the ratio of the attack frequency to the historical maximum attack frequency), and (1 minus the ratio of the malicious traffic percentage to the historical maximum malicious traffic percentage). For example, the security value of node C is 0.9 (low QBER, few vulnerabilities), and the security value of node D is 0.7 (QBER exceeds the limit, high attack frequency).
[0034] Step 2: Path screening and threshold setting User-defined threshold: Set the security index threshold to 1.0 (the security index is equal to the average security of the node status of each link in the available communication path, plus the product of the scaling factor, the security of the adjacent node status, and the calibration factor; the scaling factor is 0.6 or 0.4 depending on the security level of the node and its adjacent nodes, and the calibration factor decreases as the number of path nodes increases).
[0035] Screening results: The safety index of path 1 is 1.2 (security of node A is 0.85, security of C is 0.9, security of B is 0.8, average value is 0.88, plus the proportional factor 0.6 × security of adjacent node C 0.9 × calibration factor 0.8 (3 nodes) to get 1.2), path 2 is 0.9 (below the threshold and eliminated), and path 3 is 1.1 (retained).
[0036] Sorting and backup paths: The best path is path 1, and the backup path is path 3. Eliminate backup paths that share more than one node with the best path (no qualified path exists, so path 3 is retained).
[0037] Steps 3-5: Dynamic monitoring and path switching Initial communication phase: Application path 1 (ACB), continuous monitoring of quantum indicators: After 15 minutes of operation, the QBER of node C rose to 2.8%, the quantum optical interference dropped to 82%, and the photon detection count change rate suddenly increased to 7% / min (all triggering attack warnings).
[0038] Status trend determination: Logic 1: The security of nodes A and C decreased in the two most recent monitoring results (A from 0.85 to 0.78, C from 0.9 to 0.75). More than half of the nodes (2 out of 3 nodes) meet the downward trend.
[0039] Logic 2: The AC link security index decreases continuously over three consecutive monitoring periods (0.85 → 0.8 → 0.75).
[0040] Decision result: Trigger path change.
[0041] Backup path selection: Based on the recommendation index formula (the recommendation index is equal to the backup path security index multiplied by (1 minus the ratio of the number of link nodes to the maximum number of nodes), divided by the shortest distance between the path and the original optimal path), the recommendation index of path 3 is calculated to be 0.35 (security index 1.1 × (1-3 / 5) ÷ 2 hops), making it the only backup path. Path 3 (AFGB) is switched to.
[0042] Path offline and recovery: The original path 1 goes offline and automatically recovers after the communication task is completed.
[0043] Anti-repeat attack mechanism: If the path jumps three times, the system automatically terminates the current communication and does not provide a path for nodes A and B within the preset 10 minutes. It also simultaneously starts quantum key redistribution and node vulnerability scanning, using the non-cloning nature of quantum encryption to block continuous attacks.
[0044] The value of quantum properties: Physical layer attack perception: Through quantum properties such as QBER mutation (unavoidable disturbance caused by the measurement of photon states) and interference deterioration (quantum channel eavesdropping), attacks can be detected earlier than traditional encryption (about 12 minutes earlier).
[0045] Dynamic anti-interference efficiency: It takes only 600 milliseconds from detecting anomalies to completing path switching, and the unconditional security of quantum communication (based on the principles of quantum mechanics) is used to ensure that data transmission cannot be intercepted.
[0046] Attack tracing support: Photon counting mutation mode combined with quantum state distribution records can locate the link where the attack occurs (such as the CB link), providing an accurate basis for power grid security protection.
[0047] In summary, during the execution of the method in the above embodiment, a fully available communication path is obtained through sniffing of the full combination of link nodes. Combined with the customized screening threshold and security index sorting, the best and backup paths can be accurately selected, which changes the traditional fixed path mode and improves the flexibility and scientificity of path selection. In terms of security assessment, the constructed link node status security monitoring model comprehensively considers multi-dimensional dynamic parameters such as the number of vulnerabilities, scores, encryption algorithms, bit error rates, and attack frequencies, breaking through the limitations of single indicator evaluation. It can accurately evaluate the node status in real time, and decide whether to change the path based on the trend of node status changes, and select the backup path through the recommendation index model. In addition, the path offline and recovery mechanism and the jump command execution time limit are set to fully realize the intelligent dynamic optimization of the communication path.
[0048] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A quantum encryption communication optimization method suitable for smart grid, characterized in that: include: Step 1: Obtain the communication network topology, sniff available communication paths in the communication network topology, monitor the security of each link node in the communication network in real time, and identify the security indicators of each available communication path based on the link node status security monitoring results; Step 2: Monitor the communication network topology to obtain the link nodes of the communication request and the link nodes to which the communication request is directed, query the available communication paths that meet the communication conditions based on the monitored link nodes, and simultaneously set the available communication path screening threshold. Based on the available communication path screening threshold, select the best communication path and the backup communication path from the queried available communication paths; Step 3: Apply the optimal communication path to the link node that receives the communication request and the link node that the communication request is directed to. Continuously monitor the status security of each link node in the optimal communication path. Based on the trend of the status security of each link node, decide whether to change the communication path. Step 4: If the decision result is no, the application of the optimal communication path is maintained; if the decision result is yes, a backup communication path is selected from all backup communication paths as the communication path change target, and the backup communication path pointed to by the change result is re-recorded as the optimal communication path; Step 5: Execute the jump command to jump to the execution stage of continuously monitoring the status security of each link node in the optimal communication path and deciding whether to change the communication path based on the changing trend of the status security of each link node.
2. A quantum encryption communication optimization method suitable for smart grid according to claim 1, characterized in that: When sniffing available communication paths in the communication network topology, any two or more link nodes are selected in the communication network topology, the selected link nodes are used as sniffing targets, and all communication paths that can cover the selected link nodes are sniffed in the communication network topology; When selecting link nodes in the communication network topology, all combinations of any two or more link nodes are used as sniffing targets; Among them, after obtaining the communication request, each link node in the communication network synchronously obtains the link node pointed to by the communication request, and uses the link node of the communication request and the link node pointed to by the communication request as query targets, and queries all available communication paths that contain the link node of the communication request and the link node pointed to by the communication request.
3. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: The link node status security monitoring logic is expressed as: ; Where: The link node status security; is the total number of vulnerabilities on the link nodes; The score of the ith vulnerability on the node obtained by the CVSS (Critical Vulnerability Scoring System); is the weight of the i-th vulnerability; This is the score of the currently used encryption algorithm based on the NIST standard; QBER is the quantum channel bit error rate; is the attack frequency per unit time; is the proportion of malicious traffic; is the maximum attack frequency of the corresponding node in the network history; The maximum malicious traffic ratio corresponding to the node in the network history; Among them, the weight values of vulnerabilities are all positive and less than 1. And it obeys the setting logic that the more times the vulnerability appears in each link node, the larger the value is.
4. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: The security indicators of each available communication path are identified based on the security monitoring results of each link node status: ; Where: is the security indicator of the available communication path L; is the total number of link nodes on the available communication path L; is the corresponding state security of the j-th link node; is the scale factor; The corresponding state security of the link node between the j-th link node and the central link node of the network topology, which is closest to the j-th link node and directly connected to the j-th link node; is the calibration factor; Among them, the scale factor The value is 0.4 or 0.
6. , scale factor The value is 0.6, otherwise the proportional factor The value is 0.4, the calibration factor The value range is between 0.5 and 1, and the more link nodes on the available communication path L, the greater the calibration factor The smaller the value, the smaller the calibration factor. The larger the value.
5. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: The available communication path screening threshold is customized by the user end based on the security index of the available communication path. All available communication paths corresponding to security indexes greater than the available communication path screening threshold are used as screening results. The available communication paths included in the screening results are sorted from largest to smallest according to the security indexes corresponding to the available communication paths. The available communication path at the top of the sorting results is selected as the optimal communication path, and the remaining available communication paths are selected as backup communication paths. Among them, after the backup communication path is determined, the number of link nodes in the intersection of the link nodes included in each backup communication path and the link nodes included in the optimal communication path is synchronously identified. For the intersection of the link nodes included in the backup communication path and the link nodes included in the optimal communication path, after the number of link nodes in the intersection of the link nodes included in the backup communication path and the link nodes included in the optimal communication path is subtracted from the number of link nodes for obtaining the communication request and the number of link nodes pointed to by the communication request target, the backup communication path whose number of link nodes in the intersection is still greater than 1 is regarded as the abandonment target, and the abandonment operation is performed.
6. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: After the optimal communication path is screened and determined, the optimal communication path only serves the link node currently receiving the communication request and the link node to which the communication request is directed. All backup communication paths will no longer be selected as backup communication paths when a new communication task occurs in the communication network while the link node currently receiving the communication request and the link node to which the communication request is directed have not yet completed communication. After the link node currently acquiring the communication request and the link node targeted by the communication request complete communication, the status of the optimal communication path and the backup communication path changes to available.
7. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: When deciding whether to change the communication path based on the security change trend of each link node status, the following is followed: Each node on the optimal communication path is marked as ; Then For example, The continuously monitored state safety is recorded as , Similarly; Logic 1: The security of the status of each node in the two latest monitorings is more than half, and both show a downward trend; Logic 2: On the optimal communication path, the security of the latest three monitoring states of at least two consecutive nodes shows a continuous downward trend; Among them, when any one or more of Logic1 and Logic2 is true, the decision result is to change the communication path. When neither Logic1 nor Logic2 is true, the decision result is to maintain the application of the optimal communication path.
8. The quantum encryption communication optimization method applicable to smart grid according to claim 1 is characterized in that: When changing the communication path, the following must be followed: ; Where: is the recommendation index for the alternative communication path; is the security indicator of the backup communication path; is the total number of link nodes on the backup communication path; is the value of the shortest straight-line distance between the vth link node and the last applied optimal communication path; when changing the communication path, the backup communication path with the highest recommendation index is used as the change target.
9. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: During the communication path changing operation phase, the best communication path last used is offline in the communication network. After the communication path is changed and the communication task is completed, the offline communication path is restored in the communication network.
10. The quantum encryption communication optimization method applicable to smart grid according to claim 1, characterized in that: After the jump command is executed more than three times in a row, the communication network ends the current communication request when the jump command is executed next time, and no longer provides a communication path for the link node that obtains the communication request and the link node that the communication request targets within a preset time threshold.
Citation Information
Patent Citations
Encryption optimization method for data communication
CN118944952B
Processing method and device based on block chain network, electronic equipment and medium
CN118368291A
Network security protection system based on GIS
CN119232641A
Multi-node secure communication method and system based on quantum key distribution
CN120128524A
Path selection for data traffic within a software-defined wide area network using traffic metrics
US20230059537A1