An Optimization Method for Quantum Encrypted Communication Applicable to Smart Grids

By monitoring the security of link node states in real time and dynamically selecting paths in smart grids, and combining the characteristics of quantum state superposition and entanglement, the problem of high path selection dependence in existing technologies is solved, and intelligent dynamic optimization and security improvement of communication paths are achieved.

CN120692018BActive Publication Date: 2026-01-06GUIYANG BUREAU OF CHINA SOUTHERN POWER GRID CO LTD EHV TRANSMISSION CO
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510844404.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2026-01-06
Estimated Expiration
2045-06-23

AI Technical Summary

Technical Problem

Existing encrypted communication technologies suffer from high dependence on path selection and real-time changes in complex communication networks, as well as performance bottlenecks and limited security improvements when handling complex environments.

Method used

By sniffing out available communication paths in the communication network topology, monitoring the security status of link nodes in real time, identifying security indicators of available communication paths, screening the best and backup paths, and deciding whether to change paths based on the trend of node status changes, dynamic optimization is achieved by combining the characteristics of quantum state superposition and entanglement.

Benefits of technology

It enables intelligent dynamic optimization of communication paths in smart grids, improving the flexibility and scientific nature of path selection, accurately assessing node status in real time, resisting quantum computing attacks, and ensuring the security and stability of the communication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692018B_ABST
    Figure CN120692018B_ABST
Patent Text Reader

Abstract

The application discloses a quantum encryption communication optimization method suitable for a smart grid, relates to the field of encryption communication, and comprises the following steps: acquiring a communication network topology, sniffing available communication paths in the communication network topology, monitoring the state security of each link node in the communication network in real time, identifying the security indexes of each available communication path based on the monitoring result of the state security of the link node, and acquiring comprehensive available communication paths through full-combination link node sniffing, and combining a self-defined filtering threshold and security index sorting, so that the best and backup paths can be accurately selected, the traditional fixed path mode is changed, and the flexibility and scientific nature of path selection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of encrypted communication technology, specifically to an optimized quantum encrypted communication method suitable for smart grids. Background Technology

[0002] Quantum-encrypted communication in smart grids integrates quantum information technology with power grid communication systems. By utilizing the superposition and entanglement properties of quantum states, it achieves unconditional security in key distribution, resists the risks of quantum computing cracking faced by traditional encryption, ensures the security of power dispatching and user data transmission, enhances the anti-attack capability of power grid communication, and provides core technical support for building a more reliable smart grid security system.

[0003] The invention patent application with application number 202411173242.0 discloses an encryption optimization method for data communication, including the following steps: S1, Intelligent encryption algorithm library construction: Design an intelligent algorithm library containing multiple encryption algorithms, covering symmetric encryption, asymmetric encryption, and hybrid encryption types; the intelligent algorithm library selects encryption algorithms for the current data communication environment through analysis and learning of historical communication data; S2, Multi-level encryption strategy and chain optimization: S2.1, Data is processed in layers according to sensitivity and priority, each layer uses different encryption algorithms and keys, and uses a security architecture where the encryption data of the upper layer depends on the key of the lower layer; S2.2, Through the design of a chain dependency structure, the encryption result of each layer affects the selection and optimization of encryption parameters of the next layer; S3, Adaptive key management and distribution optimization: S3.1, Based on the dynamic changes in the communication environment and data transmission requirements, an adaptive key generation and update strategy is designed, wherein the key... The key generation process combines the hardware characteristics of the device with the real-time network status; S3.2, an optimized distributed key distribution mechanism is adopted, which dynamically selects the distribution path based on the data traffic on the encrypted link and the load of network nodes, and synchronizes the key through chained encryption results; S4, end-to-end encryption optimization and multi-channel transmission: S4.1, the data is divided into multiple segments and encrypted and transmitted through different transmission channels; each channel uses an independent encryption algorithm and key, while ensuring the integrity and independence of each data segment; S4.2, based on an adaptive key management strategy, the encryption path of each transmission channel is dynamically optimized; and during data transmission, the path and channel are selected according to the real-time monitored network status, and adjustments and optimizations are made based on the chained optimization results. This application aims to solve the problems that "existing encryption technologies have high dependence, may have performance bottlenecks when dealing with complex communication environments, and have limited improvement in security."

[0004] However, in the field of encrypted communication optimization technology, how to select and change communication paths in real time in complex communication networks to ensure the security of the communication process is also a topic worthy of in-depth research.

[0005] To address this, an optimized method for quantum encrypted communication suitable for smart grids is proposed. Summary of the Invention

[0006] In view of the above-mentioned shortcomings of the existing technology, the present invention provides a quantum encrypted communication optimization method suitable for smart grids, which can effectively solve the problems of the existing technology.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions;

[0008] This invention discloses a quantum encrypted communication optimization method suitable for smart grids, comprising:

[0009] The system acquires the communication network topology, sniffs out available communication paths within it, and monitors the security status of each link node in the network in real time. Based on the monitoring results, it identifies the security indicators of each available communication path. It monitors the link nodes in the network topology that receive communication requests and the link nodes to which the communication requests are directed. Based on the monitored link nodes, it queries available communication paths that meet the communication conditions, simultaneously setting a filtering threshold for available communication paths. Based on this threshold, it selects the optimal and backup communication paths from the queried available paths. Finally, it applies the optimal communication path to receive the communication request. The system continuously monitors the state security of each link node in the optimal communication path and decides whether to change the communication path based on the trend of state security changes of each link node. If the decision is negative, the application of the optimal communication path is maintained. If the decision is positive, one of the backup communication paths is selected as the target for communication path change, and the backup communication path is re-recorded as the optimal communication path. A jump command is executed to jump to the execution phase of continuously monitoring the state security of each link node in the optimal communication path and deciding whether to change the communication path based on the trend of state security changes of each link node.

[0010] Furthermore, when sniffing available communication paths in the communication network topology, any two or more link nodes are selected in the communication network topology, and the selected link nodes are used as sniffing targets to sniff all communication paths in the communication network topology that can cover the selected link nodes.

[0011] When selecting link nodes in the communication network topology, all combinations of any two or more link nodes are used as sniffing targets.

[0012] In this process, after each link node in the communication network receives a communication request, it synchronously obtains the link node to which the communication request is directed. Using the link node that received the communication request and the link node to which the communication request is directed as query targets, it queries all available communication paths that contain the link node that received the communication request and the link node to which the communication request is directed.

[0013] Furthermore, the link node state security monitoring logic is represented as follows:

[0014] ;

[0015] In the formula: For the security of link node states; This represents the total number of vulnerabilities on the link node; The score obtained by the vulnerability scoring system (CVSS) for the i-th vulnerability on the node; Let be the weight of the i-th vulnerability; The current application encryption algorithm is scored according to the NIST standard; QBER is the quantum channel bit error rate. Attack frequency per unit time; This represents the percentage of malicious traffic. This represents the highest attack frequency for that node in the network's historical records. This represents the percentage of malicious traffic corresponding to that node in the network history record.

[0016] The weights of the vulnerabilities are all positive numbers and less than 1. Furthermore, it follows the logic that the more times a vulnerability appears in each link node, the larger its value becomes.

[0017] Furthermore, the security indicators of each available communication path are identified based on the security monitoring results of each link node's state:

[0018] ;

[0019] In the formula: The security index for the available communication path L; The total number of nodes on the available communication path L; For the state security of the j-th link node; It is a scaling factor; The state security of the link node that is closest to the j-th link node and directly connected to the j-th link node between the j-th link node and the network topology center link node. Calibration factor;

[0020] Among them, the scaling factor The value can be 0.4 or 0.6. , scaling factor The value is 0.6, otherwise the scaling factor is... The value is 0.4, calibration factor. The value ranges from 0.5 to 1, and the more uplink nodes there are on the available communication path L, the higher the calibration factor becomes. The smaller the value, the greater the calibration factor. The larger the value, the better.

[0021] Furthermore, the available communication path filtering threshold is defined by the user based on the security index of the available communication path. All available communication paths with security indices greater than the available communication path filtering threshold are used as filtering results. Simultaneously, based on the security indices of each available communication path in the filtering results, each available communication path is sorted from largest to smallest. The available communication path at the top of the sorted results is used as the best communication path, and the remaining available communication paths are used as backup communication paths.

[0022] Once the backup communication path is determined, the number of link nodes in the intersection of the link nodes included in each backup communication path and the link nodes included in the best communication path is identified synchronously. For the intersection of the link nodes included in the backup communication path and the link nodes included in the best communication path, the backup communication path whose number of link nodes is still greater than 1 after subtracting the number of link nodes that obtained the communication request and the number of link nodes that the communication request target points to is selected as the discard target and the discard operation is performed.

[0023] Furthermore, after the optimal communication path is determined, the optimal communication path only serves the link node that is currently receiving the communication request and the link node to which the communication request target points. All backup communication paths will not be selected as backup communication paths when a new communication task appears in the communication network while the link node that is currently receiving the communication request and the link node to which the communication request target points are still communicating.

[0024] In this context, after the link node currently receiving the communication request ends communication with the link node to which the communication request is directed, the status of the best communication path and the backup communication path changes to available.

[0025] Furthermore, when deciding whether to change the communication path based on the security change trend of each link node's state, the following applies:

[0026] The nodes on the optimal communication path are marked according to their node arrangement order. ;

[0027] Then For example, The state security of continuous monitoring is denoted as , Similarly;

[0028] Logic1: The security status of each node in the two most recent monitoring sessions is down for more than half of the nodes.

[0029] Logic2: On the optimal communication path, the security of the state of any two consecutive nodes shows a continuous decreasing trend in the three most recent monitoring checks.

[0030] If any one or more of Logic1 and Logic2 are true, the decision is to change the communication path; if neither Logic1 nor Logic2 is true, the decision is to maintain the application of the optimal communication path.

[0031] Furthermore, when changing the communication path, the following applies:

[0032] ;

[0033] In the formula: Recommendation index for backup communication paths; Security indicators for backup communication paths; This represents the total number of link nodes on the backup communication path. This is the value of the shortest straight-line distance between the v-th link node and the best communication path of the previous application;

[0034] When changing the communication path, the backup communication path with the highest recommendation index is used as the target for the change.

[0035] Furthermore, during the communication path change operation phase, the previously applied optimal communication path is taken offline in the communication network. After the communication path is changed and the communication task is completed, the offline communication path is restored in the communication network.

[0036] Furthermore, after the jump command is executed more than three times consecutively, the communication network terminates the current communication request when the jump command is executed again, and within a preset time threshold, it no longer provides a communication path for the link node that obtains the communication request and the link node to which the communication request target points.

[0037] Compared with the known prior art, the technical solution provided by this invention has the following beneficial effects:

[0038] This invention provides a quantum-encrypted communication optimization method suitable for smart grids. During execution, this method acquires all available communication paths through full-combination link node sniffing. Combined with a custom filtering threshold and security index ranking, it can accurately select the best and backup paths, changing the traditional fixed-path mode and improving the flexibility and scientific nature of path selection. In terms of security assessment, the constructed link node status security monitoring model comprehensively considers multiple dimensions of dynamic parameters such as the number of vulnerabilities, scores, encryption algorithms, bit error rate, and attack frequency, breaking through the limitations of single-indicator evaluation. It can accurately assess node status in real time and decide whether to change paths based on node status change trends. Furthermore, it optimizes backup paths through a recommendation index model. In addition, it sets path offline and recovery mechanisms and limits the number of jump command executions, comprehensively realizing intelligent dynamic optimization of communication paths. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.

[0040] Figure 1 This is a flowchart illustrating an optimized quantum encrypted communication method suitable for smart grids. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0042] The present invention will be further described below with reference to embodiments.

[0043] Example:

[0044] This embodiment presents an optimized quantum encrypted communication method suitable for smart grids, such as... Figure 1 As shown, it includes:

[0045] Step 1: Obtain the communication network topology, sniff out available communication paths in the communication network topology, monitor the security status of each link node in the communication network in real time, and identify the security indicators of each available communication path based on the link node security monitoring results.

[0046] When sniffing available communication paths in a communication network topology, select any two or more link nodes in the communication network topology, use the selected link nodes as sniffing targets, and sniff all communication paths in the communication network topology that can cover the selected link nodes.

[0047] When selecting link nodes in a communication network topology, all combinations of any two or more link nodes are used as sniffing targets.

[0048] In this process, after each link node in the communication network receives a communication request, it synchronously obtains the link node to which the communication request is directed. The link node that received the communication request and the link node to which the communication request is directed are used as query targets to query all available communication paths that contain the link node that received the communication request and the link node to which the communication request is directed.

[0049] The logic for monitoring the security status of link nodes is represented as follows:

[0050] ;

[0051] In the formula: For the security of link node states; This represents the total number of vulnerabilities on the link node; The score obtained by the vulnerability scoring system (CVSS) for the i-th vulnerability on the node; Let be the weight of the i-th vulnerability; The current application encryption algorithm is scored according to the NIST standard; QBER is the quantum channel bit error rate. Attack frequency per unit time; This represents the percentage of malicious traffic. This represents the highest attack frequency for that node in the network's historical records. This represents the percentage of malicious traffic corresponding to that node in the network history; the weights of the vulnerabilities are all positive numbers and less than 1. Furthermore, it follows the logic that the more times a vulnerability appears in each link node, the larger its value becomes;

[0052] The above logical formula is used to quantitatively monitor the security of link node status;

[0053] The security indicators for each available communication path are identified based on the security monitoring results of each link node's state:

[0054] ;

[0055] In the formula: The security index for the available communication path L; The total number of nodes on the available communication path L; For the state security of the j-th link node; It is a scaling factor; The state security of the link node that is closest to the j-th link node and directly connected to the j-th link node between the j-th link node and the network topology center link node. Calibration factor;

[0056] Among them, the scaling factor The value can be 0.4 or 0.6. , scaling factor The value is 0.6, otherwise the scaling factor is... The value is 0.4, calibration factor. The value ranges from 0.5 to 1, and the more uplink nodes there are on the available communication path L, the higher the calibration factor becomes. The smaller the value, the greater the calibration factor. The larger the value;

[0057] The security of each available communication path is quantitatively evaluated using the above logical formula, providing support for the subsequent screening of the best and backup communication paths in this embodiment.

[0058] Step 2: Monitor the link nodes that receive communication requests and the link nodes that the communication request targets in the communication network topology. Based on the monitored link nodes, query available communication paths that meet the communication conditions. Simultaneously set the available communication path filtering threshold. Based on the available communication path filtering threshold, filter the best communication path and backup communication path from the queried available communication paths.

[0059] The available communication path filtering threshold is defined by the user based on the security index of the available communication path. All available communication paths with security indices greater than the available communication path filtering threshold are used as the filtering results. Simultaneously, based on the security index of each available communication path in the filtering results, the available communication paths are sorted from largest to smallest. The available communication path at the top of the sorted results is used as the best communication path, and the remaining available communication paths are used as backup communication paths.

[0060] Among them, after the backup communication path is determined, the number of link nodes in the intersection of the link nodes contained in each backup communication path and the link nodes contained in the best communication path is identified synchronously. For the intersection of the link nodes contained in the backup communication path and the link nodes contained in the best communication path, the backup communication path whose number of link nodes is still greater than 1 after subtracting the number of link nodes that obtained the communication request and the number of link nodes that the communication request target points to is selected as the discard target and the discard operation is performed.

[0061] Once the optimal communication path is determined, it only serves the link node that is currently receiving the communication request and the link node to which the communication request is directed. All backup communication paths will not be selected as backup communication paths when a new communication task appears in the communication network while the link node that is currently receiving the communication request and the link node to which the communication request is directed are still in the communication state.

[0062] Among them, after the link node currently receiving the communication request and the link node to which the communication request target points end their communication, the status of the best communication path and the backup communication path changes to available.

[0063] Step 3: Apply the optimal communication path to the link node that receives the communication request and the link node to which the communication request target points. Continuously monitor the state security of each link node in the optimal communication path. Based on the trend of the state security of each link node, decide whether to change the communication path.

[0064] Step 4: If the decision result is negative, the application of the best communication path is maintained; if the decision result is positive, one of the backup communication paths is selected as the target for communication path change among all backup communication paths, and the change result indicates that the backup communication path is re-recorded as the best communication path.

[0065] When deciding whether to change the communication path based on the changing security trends of each link node's state, the following principle applies:

[0066] The nodes on the optimal communication path are marked according to their node arrangement order. ;

[0067] Then For example, The state security of continuous monitoring is denoted as , Similarly;

[0068] Logic1: The security status of each node in the two most recent monitoring sessions is down for more than half of the nodes.

[0069] Logic2: On the optimal communication path, the security of the state of any two consecutive nodes shows a continuous decreasing trend in the three most recent monitoring checks.

[0070] When any one or more of Logic1 and Logic2 are true, the decision is to change the communication path; when neither Logic1 nor Logic2 is true, the decision is to maintain the application of the optimal communication path.

[0071] When changing the communication path, the following rules apply:

[0072] ;

[0073] In the formula: Recommendation index for backup communication paths; Security indicators for backup communication paths; This represents the total number of link nodes on the backup communication path. This is the value of the shortest straight-line distance between the v-th link node and the best communication path of the previous application;

[0074] When changing the communication path, the backup communication path with the highest recommendation index is used as the target for the change.

[0075] The above logical formula further improves the communication path change logic, ensuring that when there is a need to change the communication path in a communication scenario, it responds in a timely manner and changes to the optimal backup communication path.

[0076] Step 5: Execute the jump command to jump to the execution stage of continuous monitoring of the status security of each link node in the optimal communication path and decision on whether to change the communication path based on the trend of status security changes of each link node;

[0077] During the communication path change operation phase, the best communication path of the previous application is taken offline in the communication network. After the communication path is changed and the communication task is completed, the offline communication path is restored in the communication network.

[0078] After a jump command is executed more than three times consecutively, the communication network will terminate the current communication request the next time the jump command is executed, and will no longer provide a communication path for the link node that obtained the communication request and the link node to which the communication request target is pointed within a preset time threshold.

[0079] When the method described in the above embodiments is applied to the quantum encrypted communication scenario of smart grids, it effectively achieves full-process optimized management and control of the communication link during the encrypted communication process, ensuring the security and stability of the communication process.

[0080] In the smart grid quantum encrypted communication process of this embodiment, the characteristics of quantum superposition and quantum entanglement are applied throughout the security assessment of the communication path and the entire data transmission process:

[0081] Security mechanisms for quantum superposition:

[0082] When the two communicating parties generate a key using a quantum key distribution (QKD) protocol, a single photon exists in a superposition state (such as horizontal polarization). With vertical polarization Information is transmitted via superposition. For example, the sender prepares a sequence of photons in a superposition state, and the receiver randomly selects a basis vector (such as the polarizer direction) to measure the photons. Both parties compare the basis vector consistency through a classical channel, filter out errors, and generate the final key. Due to the quantum no-cloning theorem, an eavesdropper cannot copy the superposition state photons. Their measurement behavior will inevitably perturb the quantum state, causing both parties to detect an abnormal bit error rate (such as a significant increase in QBER), thus promptly detecting the eavesdropping attempt.

[0083] Real-time synchronization characteristics of quantum entanglement:

[0084] For communication nodes widely distributed in smart grids, entangled photon pairs (such as Bell states) are pre-prepared using a quantum entanglement source and distributed to different substations (link nodes). When a node performs a polarization measurement on an entangled photon, its distant entangled photon instantly collapses into a correlated state, achieving real-time synchronization and updating of the key. For example, if nodes S1 and S5 in path L4 share an entangled photon pair, when S1 performs a polarization measurement on the photon... During the basis measurement, the entangled photons of S5 will immediately exhibit the corresponding... or This feature ensures instantaneous key updates and path switching, resisting relay attacks.

[0085] The integration of quantum properties and path security indicators:

[0086] The aforementioned quantum properties directly affect the quantitative assessment of the security of link node states:

[0087] Encryption Algorithm Score (E_score): The security of quantum encryption algorithms (such as the BB84 protocol) depends on the characteristics of quantum states. Its score needs to combine indicators such as quantum channel bit error rate (QBER) and entanglement fidelity, rather than the single computational complexity evaluation of traditional encryption algorithms.

[0088] Attack frequency (AF) and malicious traffic (MTP): The unconditional security of quantum communication can resist traditional computing power attacks (such as RSA decomposition), but it is necessary to monitor the attack types unique to quantum channels (such as photon number splitting attacks and Trojan horse attacks). Therefore, the quantum attack event dimension needs to be separately divided in the statistics of AF and MTP.

[0089] The following is an example application of the method described in the above embodiments:

[0090] The smart grid in region xx needs to establish an encrypted communication link between control center node A and distributed energy storage cluster node B to transmit real-time grid operation data. The network topology includes 7 link nodes and 3 potential communication paths (Path 1: ACB; Path 2: ADEB; Path 3: AFGB). The paths need to be dynamically optimized and attack risks assessed using quantum performance indicators (quantum channel bit error rate QBER, quantum optical interferometry, and photon detection count change rate).

[0091] Step 1: Path Sniffing and Security Initialization

[0092] Sniffing range: Targeting nodes A, B and the topology center node C, traverse the paths of all covered nodes and identify 3 usable paths.

[0093] Quantum property index collection:

[0094] QBER: According to the monitoring of the quantum key distribution system, the QBER of AC link in path 1 is 1.5% (normal threshold ≤2%), and the QBER of DE link in path 2 suddenly increases to 2.9% (close to the attack warning value of 3%).

[0095] Quantum optical interferometry: Measured using a quantum interferometer, the interferometry of the FG link in path 3 is 86% (ideal value ≥95%, indicating abnormal photonic state coherence).

[0096] Photon detection count change rate: The change rate of the CB link in path 1 is 4.5% / min (normal threshold ≤3%, indicating possible photon interception attack).

[0097] Security calculation:

[0098] The security of each node is calculated using the link node state security formula (link node state security equals the sum of the products of the total number of vulnerabilities in the link node and the product of the scores of each vulnerability and their weights, multiplied by the current encryption algorithm score, and then multiplied by the product of (1 minus the ratio of the link error rate to the historical maximum error rate), (1 minus the ratio of the attack frequency to the historical maximum attack frequency), and (1 minus the ratio of the proportion of malicious traffic to the historical maximum malicious traffic proportion)). For example, node C has a security value of 0.9 (low QBER, few vulnerabilities), and node D has a security value of 0.7 (QBER exceeds the limit, high attack frequency).

[0099] Step 2: Path Filtering and Threshold Setting

[0100] User-defined threshold: Set the security index threshold to 1.0 (the security index is equal to the average security status of each link node in the available communication path, plus the product of the scaling factor, the security status of adjacent nodes, and the calibration factor; the scaling factor is 0.6 or 0.4 depending on the security level of the node and its adjacent nodes, and the calibration factor decreases as the number of nodes in the path increases).

[0101] Screening results: The security index of path 1 is 1.2 (the security of node A is 0.85, the security of C is 0.9, the security of B is 0.8, the average value is 0.88, plus the scaling factor 0.6 × the security of adjacent node C is 0.9 × the calibration factor 0.8 (3 nodes) to get 1.2), path 2 is 0.9 (below the threshold and removed), and path 3 is 1.1 (retained).

[0102] Sorting and backup paths: The best path is path 1, and the backup path is path 3; remove backup paths that share more than one node with the best path (if no path meets the criteria, keep path 3).

[0103] Steps 3-5: Dynamic Monitoring and Path Switching

[0104] Initial communication phase: Application path 1 (ACB), continuous monitoring of quantum indicators:

[0105] After running for 15 minutes, the QBER of node C rose to 2.8%, the quantum light interferometry dropped to 82%, and the photon detection count change rate suddenly increased to 7% / min (all of which triggered attack warnings).

[0106] Status trend determination:

[0107] Logic1: The security of nodes A and C has decreased in the two most recent monitoring tests (A from 0.85 to 0.78, C from 0.9 to 0.75), and more than half of the nodes (2 out of 3 nodes) meet the downward trend.

[0108] Logic2: The security index of the AC link continued to decline in three consecutive monitoring tests (0.85→0.8→0.75).

[0109] Decision result: Triggering a path change.

[0110] Alternate path selection: According to the recommendation index formula (the recommendation index is equal to the safety index of the alternative path multiplied by (1 minus the ratio of the number of link nodes to the maximum number of nodes), and then divided by the shortest distance between the path and the original best path), the recommendation index of path 3 is calculated to be 0.35 (safety index 1.1 × (1-3 / 5) ÷ 2 hops), which is the only alternative path, and the path is switched to path 3 (AFGB).

[0111] Path offline and recovery: The original path 1 is offline and will be automatically recovered after the communication task ends.

[0112] Anti-repeated attack mechanism:

[0113] If the path hops three times, the system will automatically terminate the current communication and will not provide a path for nodes A and B for a preset 10 minutes. At the same time, it will start quantum key redistribution and node vulnerability scanning to block continuous attacks by taking advantage of the non-cloning property of quantum encryption.

[0114] The value of quantum properties is reflected in:

[0115] Physical layer attack detection: By utilizing quantum properties such as QBER mutation (unavoidable perturbation caused by the measurement of photon states) and interference degradation (eavesdropping on quantum channels), attacks can be detected earlier than traditional encryption (approximately 12 minutes earlier).

[0116] Dynamic anti-interference efficiency: It only takes 600 milliseconds from detecting an anomaly to completing the path switching. It utilizes the unconditional security of quantum communication (based on the principles of quantum mechanics) to ensure that data transmission cannot be intercepted.

[0117] Attack attribution support: The photon counting mutation mode combined with quantum state distribution records can pinpoint the attack chain (such as the CB link), providing accurate evidence for power grid security protection.

[0118] In summary, the method described in the above embodiments acquires all available communication paths through full-combination link node sniffing during execution. Combined with custom filtering thresholds and security index ranking, it can accurately select the best and backup paths, changing the traditional fixed path mode and improving the flexibility and scientific nature of path selection. In terms of security assessment, the constructed link node status security monitoring model comprehensively considers multiple dynamic parameters such as the number of vulnerabilities, scores, encryption algorithms, bit error rate, and attack frequency, breaking through the limitations of single index assessment. It can accurately assess the node status in real time and decide whether to change the path based on the trend of node status changes. It also optimizes backup paths through a recommendation index model. In addition, it sets path offline and recovery mechanisms and limits the number of jump command executions, fully realizing intelligent dynamic optimization of communication paths.

[0119] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A quantum encryption communication optimization method suitable for a smart grid, characterized in that, Comprise: Step 1: Obtain the communication network topology, sniff the available communication path in the communication network topology, monitor the link node state security in the communication network in real time, identify the security index of each available communication path based on the link node state security monitoring result; Step 2: Monitor the link node of the communication request in the communication network topology and the communication request target pointing link node, query the available communication path that meets the communication condition in the available communication path according to the monitored link node, set the available communication path filtering threshold value synchronously, filter the best communication path and standby communication path in the queried available communication path based on the available communication path filtering threshold value; Step 3: Apply the best communication path to the link node of the communication request and the communication request target pointing link node, continuously monitor the state security of each link node in the best communication path, and decide whether to change the communication path based on the change trend of the state security of each link node; Step 4: If the decision result is no, keep the application of the best communication path; if the decision result is yes, select a standby communication path as the communication path change target in all standby communication paths, and the change result points to the standby communication path as the best communication path; Step 5: Execute the jump command and jump to the execution stage of the continuous monitoring of the state security of each link node in the best communication path and the decision whether to change the communication path based on the change trend of the state security of each link node; The link node state security monitoring logic is represented as: ; In the formula: is the link node state security; is the total number of vulnerabilities on the link node; is the score of the i-th vulnerability on the node obtained by the vulnerability scoring system (CVSS); is the weight of the i-th vulnerability; is the score of the current application encryption algorithm reference NIST standard; QBER is the quantum channel error rate; is the attack frequency per unit time; is the malicious traffic proportion; is the maximum attack frequency corresponding to the node in the network history record; is the maximum malicious traffic proportion corresponding to the node in the network history record; Wherein, the weight of the vulnerability is positive and less than 1, And the compliance, the more the number of vulnerabilities in each link node, the greater the value of the set logic. The security index of each available communication path is identified based on the link node state security monitoring result: ; In the formula: is a security indicator of the available communication path L; is the total number of link nodes on the available communication path L; is the corresponding state security of the jth link node; is a proportionality factor; is the corresponding state security of the link node which is closest to the jth link node and directly connected to the jth link node between the jth link node and the network topology center link node; is a calibration factor; wherein the scaling factor takes the value 0.4 or 0.6, ≤ , the scaling factor takes the value 0.6, and vice versa, the scaling factor takes the value 0.4, the calibration factor takes a value in the range 0.5 to 1 and is subject to the condition that the more link nodes on the available communication path L, the smaller the calibration factor takes the value, and vice versa, the calibration factor takes the larger value. 2.The quantum encryption communication optimization method for smart grid according to claim 1, wherein, When sniffing the available communication path in the communication network topology, select any two or more link nodes in the communication network topology, and select the sniffing target as the selected link node, sniff all communication paths that can cover the selected link node in the communication network topology; When selecting link nodes in the communication network topology, make all combinations of any two or more link nodes be applied as the sniffing target; Wherein, after each link node in the communication network obtains the communication request, the communication request target pointing link node is obtained synchronously, and the link node obtaining the communication request and the communication request target pointing link node are taken as the query target to query all available communication paths containing the link node obtaining the communication request and the communication request target pointing link node. 3.The quantum encryption communication optimization method for smart grid of claim 1, wherein, The available communication path filtering threshold value is customized by the user terminal based on the security index of the available communication path, all available communication paths corresponding to the security index greater than the available communication path filtering threshold value are taken as the filtering result, and each available communication path corresponding to the security index is sorted from large to small according to the filtering result, the first available communication path in the sorting result is taken as the best communication path, and the remaining available communication paths are taken as standby communication paths; The backup communication path is determined, and the number of link nodes in the intersection of the backup communication path and the best communication path is identified. The backup communication path in which the number of link nodes in the intersection of the backup communication path and the best communication path is greater than 1 after the number of link nodes in the intersection is subtracted by the number of link nodes obtaining the communication request and the number of link nodes to which the communication request is directed is discarded as a discard target, and the discard operation is performed. 4.The quantum encryption communication optimization method for smart grid of claim 1, wherein, After the best communication path is determined, the best communication path only serves the link node obtaining the current communication request and the link node to which the communication request is directed. When a new communication task appears in the communication network, all backup communication paths are no longer selected as backup communication paths when the link node obtaining the current communication request and the link node to which the communication request is directed are not in a communication end state. After the link node obtaining the current communication request and the link node to which the communication request is directed end the communication, the state of the best communication path and the backup communication path is changed to available.

5. The quantum encryption communication optimization method for smart grid according to claim 1, wherein, When the decision whether to change the communication path is based on the state safety change trend of each link node, the following is followed: The nodes on the optimal communication path are marked based on the order of the nodes in the sequence ; Then, with For example, Continuously monitored state safety is denoted as , Similarly; Logic1: More than half of the latest two monitored state safety of each node shows a downward trend. Logic2: On the best communication path, the latest three monitored state safety of any continuous at least two nodes shows a continuous downward trend. When any one or more of Logic1 and Logic2 is true, the decision result is to change the communication path, and when neither Logic1 nor Logic2 is true, the decision result is to maintain the application of the best communication path.

6. The quantum encryption communication optimization method for smart grid according to claim 1, wherein, When the communication path is changed, the backup communication path with the highest recommendation index is selected as the change target. ; In the formula: is a recommended index of the backup communication path; is a security index of the backup communication path; is the total number of link nodes on the backup communication path; is the value of the shortest straight-line distance between the vth link node and the last applied optimal communication path. In the communication path change operation stage, the last applied best communication path is offline in the communication network, and after the communication path is changed and the communication task is ended, the offline communication path is restored in the communication network.

7. The quantum encryption communication optimization method for smart grid according to claim 1, wherein, After the jump command is executed continuously for more than three times, the communication network ends the current communication request, and does not provide a communication path for the link node obtaining the communication request and the link node to which the communication request is directed within a preset time threshold when the jump command is executed next time. 8.The quantum encryption communication optimization method for smart grid of claim 1, wherein, ​

Citation Information

Patent Citations

  • Encryption optimization method for data communication

    CN118944952B

  • Network security protection system based on GIS

    CN119232641A

  • Multi-node secure communication method and system based on quantum key distribution

    CN120128524A