A substation dispatching data network security communication method based on quantum tunnel encryption
By deploying quantum-secure communication terminals in the substation dispatch data network and using quantum key distribution and post-quantum cryptography technology to encrypt and sign remote control protocol data, the problem of separation between security mechanisms and business applications in existing systems is solved. This achieves end-to-end security protection and flexible network deployment, adapting to quantum computing threats and various network access methods.
Patent Information
- Application Number
- CN202511104210.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-07
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2045-08-07
AI Technical Summary
In the existing security protection system of substation dispatch data network, the security mechanism is separated from business applications, resulting in a lack of endpoint security, inability to resist quantum computing threats, and reliance on dedicated fiber optic networks, which limits deployment flexibility and economy.
A quantum-tunnel-based encryption method is adopted, and quantum-secure communication terminals are deployed in the dispatch master station and substation. Through quantum key distribution and post-quantum cryptography, the remote control protocol data is encapsulated, encrypted, and digitally signed at the application layer, thus constructing an end-to-end secure communication system that is compatible with multiple network media.
It achieves end-to-end security protection, resists quantum computing attacks, enhances networking flexibility, reduces deployment costs, supports a smooth transition between old and new systems, and ensures the stability and security of power grid dispatching services.
Smart Images

Figure CN120811596B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of large-scale power grid security technology, and more specifically, to a secure communication method for substation dispatch data networks based on quantum tunnel encryption. Background Technology
[0002] As a core component of the nation's critical information infrastructure, the safe and stable operation of the power grid system is directly related to the national economy, people's livelihood, and social order. Among these systems, the substation dispatch data network serves as a neural network connecting the main dispatch station with its subordinate substations. It is responsible for the real-time acquisition of massive amounts of telemetry and teleindication data, as well as the precise issuance of remote control and dispatch commands. It is the lifeline ensuring accurate perception, reliable control, and efficient decision-making for the entire power grid. Therefore, ensuring the confidentiality, integrity, and availability of information exchange within this data network remains a core issue in the fields of power system automation and information security technology.
[0003] For a considerable period, to address increasingly complex cybersecurity threats, the power industry generally followed a comprehensive protection strategy of "security zoning, dedicated networks, horizontal isolation, and vertical authentication." Under this strategy, the mainstream technical practice was to deploy dedicated vertical encryption and authentication devices for the power sector. Specifically, these devices were typically placed at the boundaries between different security zones, such as the dispatch master station and substations. Their core function was to establish a logically secure channel on the physical communication link using tunnel encryption technologies such as IPSec. All business data crossing the security zone boundary was encrypted before entering this channel and decrypted upon arrival at the other end, effectively ensuring the confidentiality of data during wide-area transmission and preventing the risk of eavesdropping or interception on public or untrusted network links. This boundary protection and channel encryption model, at a specific stage of development, played a crucial protective role against attacks originating from external networks, providing a fundamental guarantee for the stable operation of the dispatch data network.
[0004] However, with the deepening of power grid intelligence, the extension of the Internet of Things trend, and the increasing evolution of network attack methods, the inherent limitations of this traditional security architecture, which relies on perimeter protection and network layer encryption, are becoming increasingly apparent. The reason lies in the fact that the core design philosophy of this architecture is to solidify security capabilities at specific network gateways, forming a "robust outer shell, soft core" protection model. Its deeper technical contradiction lies in the separation of security mechanisms from business applications. For example, the IEC 104 and other telemetry protocols widely used in dispatch data networks did not fully consider security factors in their initial design, essentially exchanging data in plaintext. Although vertical encryption devices encrypt the transmission channel, data remains in plaintext within the internal network of its respective security zone before entering and after leaving the encryption device. This means that once an attacker penetrates the substation's internal network through other means, they can bypass the protection of the vertical encryption device and directly send forged remote control commands or tamper with transmitted telemetry data to terminal equipment within the station, thereby causing serious damage to the power grid. This security model protects the "channel" but fails to protect the "source" and "destination," meaning that security protection does not truly extend to the source of data generation and the final consumption endpoint.
[0005] Furthermore, the security of classical cryptography is rooted in the computational complexity of mathematical problems such as large number factorization and discrete logarithms. With the rapid development of quantum computing technology, its powerful parallel computing capabilities pose a disruptive threat to existing public-key cryptosystems. Once a practical quantum computer becomes available, encryption algorithms currently widely used for authentication and key negotiation could be easily cracked. At that point, the entire protection system based on vertical encryption and authentication devices would become ineffective, and power grid security would face a fundamental and severe challenge. In addition, at the practical deployment level, traditional solutions heavily rely on dedicated fiber optic networks to ensure the reliability and security of physical links. However, in remote, harsh environments, or substation scenarios requiring temporary deployment, the high cost and long deployment time of fiber optic cables severely limit the flexibility and response speed of network deployment. While 5G and other public wireless network technologies offer new solutions, their open access characteristics place far more stringent demands on the strength of communication encryption and end-to-end protection capabilities than ever before.
[0006] Therefore, how to build a system based on the existing power grid dispatch data network architecture that can extend security protection capabilities from the network boundary to the business application endpoint, withstand the disruptive impact of future quantum computing, be compatible with diverse network access methods, and ensure a smooth transition and seamless integration with existing business systems to achieve true end-to-end intrinsic security has become a key challenge and an urgent technical problem for those skilled in the art. Summary of the Invention
[0007] The technical problem this invention aims to solve is to overcome the shortcomings of existing substation dispatch data network security systems. These shortcomings stem from the separation of security mechanisms from business applications, resulting in a lack of endpoint security, rigid protection boundaries, and the inherent vulnerability of classical cryptography to quantum computing threats. Existing technologies rely on deploying vertical encryption and authentication devices at network boundaries. This approach only ensures the confidentiality of the transmission channel, failing to provide source-to-end protection for the transmitted content itself—i.e., remote communication data such as IEC 104 protocols existing in plaintext within the network. Once an attacker penetrates the secure area, they can bypass boundary protection and directly threaten business endpoints. Furthermore, the public-key cryptography algorithms relied upon by this system are vulnerable to future quantum computer attacks, posing a fundamental challenge to the long-term security of the power grid. Simultaneously, over-reliance on dedicated fiber optic networks limits their deployment flexibility and cost-effectiveness in complex geographical environments.
[0008] To address the aforementioned technical challenges, this invention provides a secure communication method for substation dispatch data networks based on quantum tunnel encryption. The method aims to construct a two-layer, end-to-end security architecture that deeply integrates quantum cryptography and post-quantum cryptography. By deploying quantum-secure communication terminals at the dispatch master station and substations, security capabilities are extended from the network boundary to the source of application data generation. The original telemetry protocol data undergoes application-layer encapsulation encryption and digital signature. Based on this, a quantum-key-based, encrypted logical tunnel is constructed for transmission. This approach not only compensates for the lack of security mechanisms inherent in telemetry protocols, achieving endpoint-level data protection, but also leverages the unconditional security of quantum key distribution and the computational attack resistance of post-quantum cryptography algorithms to construct a next-generation secure communication system resistant to both classical and quantum computing attacks. Furthermore, it is compatible with various physical network media, achieving the protection goals of security, flexibility, and smooth evolution.
[0009] To achieve the above-mentioned objectives, the present invention is implemented through the following technical solution:
[0010] This invention discloses a secure communication method for substation dispatch data networks based on quantum tunnel encryption. It establishes secure communication between a dispatch master station and one or more substations, where both the dispatch master station and the one or more substations are equipped with quantum-secure communication terminals. The method includes the following steps: a secure session establishment step, a data encapsulation and encryption step at the transmitting end, and a decryption and data restoration step at the receiving end.
[0011] The quantum-secure communication terminal is a dedicated hardware device that integrates a quantum key distribution module, a post-quantum cryptography module, a security protocol processing engine, a key management and synchronization unit, and a multi-network interface module.
[0012] The quantum key distribution module contains a phase-encoded BB84 decoy state quantum signal transmitter or receiver. The transmitter uses a narrow-linewidth distributed feedback laser with a center wavelength of 1550 nm as the light source, and the photons are phase-modulated using an asymmetric Mach-Zehnder interferometer. The receiver employs a superconducting nanowire single-photon detector array with a response wavelength range covering 1500 to 1600 nm, a dark count rate of less than 100 times per second, and a detection efficiency of more than 20%. This module is responsible for executing the quantum key distribution protocol between the quantum-secure communication terminals of the two communicating parties through an independent quantum channel, generating a shared original key with information-theoretic security.
[0013] The post-quantum cryptography module embeds a dedicated field-programmable gate array (FPGA) chip, which contains hardware acceleration logic for executing post-quantum cryptography algorithms based on modular lattice cryptography. Specifically, the module executes a key encapsulation mechanism algorithm based on learning a modular version with rounding problems to securely negotiate and share secrets during the initial authentication phase. Simultaneously, the module executes a digital signature algorithm based on learning a modular version with rounding problems to authenticate communicating entities and sign critical data messages to ensure their integrity and non-repudiation. The security strength of the algorithm executed by this module is designed to be equivalent to Level 3 security as defined in the post-quantum cryptography standardization process of the National Institute of Standards and Technology (NIST).
[0014] The security protocol processing engine employs a multi-core network processor with a built-in hardware encryption / decryption acceleration unit, and the processor core operates at a frequency of no less than 1.2 GHz. This engine is responsible for executing the encapsulation and decapsulation operations of a quantum-secure telemetry application protocol (QSTAP) and a quantum-secure tunneling protocol (QSTP) as defined in this invention. The engine performs in-depth processing on the original telemetry protocol messages originating from the local service terminal according to a preset security strategy.
[0015] The key management and synchronization unit includes a secure storage chip with physical tamper-proof features. This chip stores the original key generated by the quantum key distribution module, the post-processed session master key, and various working keys generated from the session master key using a key derivation function (KDF). The key derivation function employs the Extract-Expand Key Derivation Function (HKDF) based on Secure Hash Algorithm 3 (SHA-3). This unit is responsible for the entire lifecycle management of key generation, storage, distribution, updating, and destruction, and maintains state synchronization with the key management unit of the peer device.
[0016] The multi-network interface module physically integrates a single-mode fiber optic interface supporting the 1000BASE-LX standard for connecting the quantum channel and the primary data channel; and a wireless communication module supporting the 5G New Radio (NR) standard. This module includes an RF front-end and a baseband processor, supporting communication in the 3.5 GHz band and serving as a backup or primary data transmission channel. The module incorporates link aggregation and intelligent fault-to-connection logic to ensure redundancy and high availability of the communication links.
[0017] Furthermore, the specific process of establishing the secure session is as follows:
[0018] First, initial authentication and key negotiation based on post-quantum cryptography are performed. The initiating party's quantum-secure communication terminal generates a temporary post-quantum public-private key pair through its post-quantum cryptography module, and sends the public key along with a randomly generated challenge number to the responding party. Upon receiving this information, the responding party's quantum-secure communication terminal uses its pre-stored long-term post-quantum private key, representing its identity, to digitally sign the concatenation of the initiating party's public key and the challenge number. This signature, along with its own long-term post-quantum public key and a ciphertext package containing the shared secret generated by its post-quantum cryptography module, is returned to the initiating party. The ciphertext package is generated using the initiating party's temporary post-quantum public key, encrypted using the aforementioned key encapsulation mechanism algorithm. Upon receiving the response, the initiating party first verifies the validity of the signature using the responding party's pre-stored long-term post-quantum public key to authenticate the responding party's identity. After successful verification, it decrypts the ciphertext package using its temporary post-quantum private key to obtain the shared secret. Thus, both parties establish a bidirectionally authenticated initial shared secret resistant to quantum computing attacks.
[0019] Next, quantum key distribution and session master key generation are performed. After successful initial authentication, the quantum key distribution modules of both communicating parties initiate the quantum key distribution process through a quantum channel. Both parties execute the aforementioned decoy state BB84 protocol, ceasing quantum signal transmission and reception after a preset time (e.g., 300 seconds) or after generating a bit sequence of a predetermined length. Subsequently, both parties perform key negotiation post-processing steps, including basis vector comparison, bit error rate estimation, error bit removal, and parameter negotiation, through a public classical channel that has undergone initial shared secret encryption authentication. Specifically, error bit removal employs low-density parity-check codes (LDPC) for efficient error correction. After error correction, both parties use privacy amplification technology based on a dual-path universal hash function to compress and purify the corrected key, eliminating information that might be leaked to eavesdroppers during post-processing, ultimately generating a 256-bit session master key (MSK) with unconditional security.
[0020] Finally, working key derivation is performed. The key management and synchronization units of both parties use this session master key as input and feed it into the aforementioned extraction-expansion key derivation function based on secure hash algorithm 3. This function uses the session identifier, the identities of both communicating parties, and other information as salt and input information to derive at least four independent working keys: a 128-bit application layer encryption key (K_APP_ENC) used to encrypt the payload of the quantum-safe telemetry application protocol; a 128-bit application layer message authentication code key (K_APP_MAC) used to verify the integrity of application layer data; a 128-bit tunnel layer encryption key (K_TUN_ENC) used to encrypt the payload of the quantum-safe tunnel protocol; and a 128-bit tunnel layer message authentication code key (K_TUN_MAC) used to verify the integrity of tunnel layer data. After derivation, the secure session is established, and the system enters a standby state.
[0021] Furthermore, the specific process of the data encapsulation and encryption steps at the sending end is as follows:
[0022] This step is triggered when the security protocol processing engine of the quantum-safe communication terminal at the transmitting end listens through its internal port to an Application Protocol Data Unit (APDU) conforming to the IEC 104 specification format originating from a local scheduling application or substation terminal equipment.
[0023] The first step is to construct the Quantum Secure Telematics Application Protocol (QSTAP) message. The security protocol processing engine uses the captured complete IEC 104 APDU as the base payload. The engine then creates a QSTAP message header, which contains the following fields: a 4-byte version and compatibility flag field to identify the protocol version and backward compatibility mode; an 8-byte Session Identifier (SPI) to point to the currently effective session master key and associated working key; an 8-byte sequence number to prevent replay attacks, which strictly monotonically increments with each packet transmission; and a 2-byte payload length field.
[0024] The second step involves application-layer encryption and integrity protection. The security protocol processing engine invokes an authentication encryption algorithm module based on the Advanced Encryption Standard (AES) and operating in Galois / Counter mode (GCM). This module uses the previously derived application-layer encryption key (K_APP_ENC) and application-layer message authentication code key (K_APP_MAC) as parameters to encrypt and authenticate the payload of the QSTAP message, i.e., the original IEC 104 APDU. The QSTAP message header, as Associated Data (AAD) in the authentication encryption process, is protected in integrity but is not encrypted itself. The result of the encryption and authentication calculations is a ciphertext payload and a 128-bit message authentication code (MAC). This message authentication code is appended to the ciphertext payload.
[0025] The third step involves performing a post-quantum digital signature. To ensure non-repudiation, the security protocol processing engine treats the complete QSTAP message (including the header, ciphertext payload, and message authentication code) as a single data block and invokes the post-quantum cryptography module. This module uses the sender's long-term post-quantum private key to execute the aforementioned digital signature algorithm on this data block, generating a post-quantum digital signature. This signature is appended to the end of the QSTAP message.
[0026] The fourth step is to construct the Quantum Secure Tunneling Protocol (QSTP) message. The security protocol processing engine takes the complete QSTP message, which has been encrypted and signed by the application layer, as the payload of the Quantum Secure Tunneling Protocol. The engine creates a QSTP message header containing only an 8-byte Tunnel Session Identifier (T-SPI) to indicate which set of tunnel layer working keys the peer device uses.
[0027] The fifth step involves tunnel layer encryption and integrity protection. Similar to application layer encryption, the security protocol processing engine again calls the authentication encryption algorithm module, but this time uses the tunnel layer encryption key (K_TUN_ENC) and the tunnel layer message authentication code key (K_TUN_MAC). This module encrypts and authenticates the payload of the QSTP message, i.e., the aforementioned complete QSTAP message. The QSTP message header is used as associated data. The calculation result is a tunnel ciphertext payload and a tunnel message authentication code.
[0028] Step six, final encapsulation and transmission. The security protocol processing engine combines the QSTP header, tunnel ciphertext payload, and tunnel message authentication code into a complete QSTP message, which is then used as the payload of a new Internet Protocol (IP) datagram. The source and destination addresses of this IP datagram are the addresses of the quantum-secure communication terminals at the sending and receiving ends, respectively. Finally, this IP datagram is transmitted via the multi-network interface module through the currently selected physical link (dedicated fiber optic cable or 5G wireless network).
[0029] Furthermore, the specific process of the receiving end decryption and data restoration steps is as follows:
[0030] This step is triggered when the multi-network interface module of the quantum-safe communication terminal at the receiving end receives an IP datagram whose protocol field is identified as QSTP.
[0031] The first step is tunnel layer decapsulation and verification. The security protocol processing engine extracts the QSTP packet from the received IP datagram. Based on the tunnel session identifier in the QSTP packet header, it retrieves the corresponding tunnel layer encryption key (K_TUN_ENC) and tunnel layer message authentication code key (K_TUN_MAC) from the key management and synchronization unit. The engine calls the authentication encryption algorithm module to decrypt and verify the tunnel ciphertext payload and the tunnel message authentication code. If the message authentication code verification fails, it indicates that the data has been tampered with during transmission, and the packet is immediately discarded and a security event is recorded. If the verification is successful, the decrypted payload is obtained, which is a complete QSTAP packet with a post-quantum digital signature.
[0032] The second step is post-quantum digital signature verification. The security protocol processing engine calls the post-quantum cryptography module, using the pre-stored long-term post-quantum public key from the sender, to verify the post-quantum digital signature attached to the decrypted QSTAP message. If signature verification fails, it indicates that the message source is illegal or the content has been tampered with; the message is immediately discarded and the security event is recorded. This step ensures the authenticity and non-repudiation of the data source.
[0033] The third step is application-layer decapsulation and verification. After successful signature verification, the security protocol processing engine parses the QSTAP message header to obtain the Session Identifier (SPI) and sequence number. The engine first checks the sequence number to ensure it is greater than the sequence number of the previously successfully received message, preventing replay attacks. Then, based on the session identifier, it retrieves the corresponding application-layer encryption key (K_APP_ENC) and application-layer message authentication code key (K_APP_MAC) from the key management and synchronization unit. The engine calls the authentication encryption algorithm module to decrypt and verify the ciphertext payload and message authentication code in the QSTAP message. If the message authentication code verification fails, the message is discarded.
[0034] The fourth step is to restore and forward the original data. After successful verification of the application layer message authentication code, the engine obtains the decrypted plaintext payload, which is the original, unmodified Application Protocol Data Unit (APDU) of the IEC 104 standard. The security protocol processing engine forwards this APDU through its internal port to the local dispatch master station application system or substation monitoring backend it protects, completing a secure, end-to-end data communication process.
[0035] In a preferred embodiment of the present invention, to ensure a smooth transition and seamless integration with existing scheduling data network infrastructure, the security protocol processing engine of the quantum-safe communication terminal incorporates a set of compatibility policy control logic. This logic is based on a configurable peer device capability registry. When communicating with a legacy device that does not support the method described in this invention, the version and compatibility flag field is set to "legacy mode". In this mode, the security protocol processing engine of the quantum-safe communication terminal will not perform any QSTAP or QSTP encapsulation operations, but will instead forward the intercepted IEC 104 messages directly to the existing vertical encryption authentication device deployed serially with the quantum-safe communication terminal via a transparent bridge, which will then perform traditional network layer tunnel encryption. When communicating with a peer that has also deployed a quantum-safe communication terminal but whose quantum channel has not yet been established or is unavailable, the flag field is set to "hybrid mode". In this mode, the security protocol processing engine only performs application-layer QSTAP encapsulation, encryption, and signing, and then directly delivers the generated protected QSTAP message to the existing vertical encryption authentication device for transport layer encryption. Only when both communicating parties have completed deployment and the quantum channel is available is "full mode" enabled, executing all the steps described in this invention.
[0036] Compared with the prior art, the beneficial effects of the present invention are:
[0037] (1) Achieves true end-to-end security protection. This invention extends security protection capabilities from the network boundary to the source of data generation and the final consumption endpoint by encrypting and signing the data of remote control protocols such as IEC 104 at the application layer. This completely solves the inherent defects of the traditional boundary protection model of "strong outer shell and soft core". Even if an attacker penetrates into the substation intranet, he will not be able to parse or forge the protected dispatch instructions and data.
[0038] (2) A forward-looking security system capable of resisting quantum computing attacks has been constructed. This invention creatively integrates two key cryptographic technologies of the quantum era: utilizing the information-theoretical security of quantum key distribution (QKD) to ensure the absolute security of session key exchange, making it immune to any computational attacks; and using post-quantum cryptography (PQC) algorithms to solve the problem of resisting quantum attacks in the identity authentication and digital signature links, thus constructing a full-link, future-oriented defense-in-depth system.
[0039] (3) It provides dual encryption and defense-in-depth capabilities. This invention implements dual-layer encryption protection for business data through QSTAP encapsulation at the application layer and QSTP encapsulation at the tunnel layer. The application layer encryption protects the data content itself, while the tunnel layer encryption hides the protocol characteristics and traffic patterns of internal communication, effectively resisting complex traffic analysis attacks and significantly improving the overall protection strength.
[0040] (4) Enhanced network flexibility and reduced deployment costs. The quantum-secure communication terminal integrates support for multiple network media, including wired optical fiber and 5G wireless public network, and has intelligent link switching capabilities. This enables substations in remote areas, temporary scenarios, or those without the conditions for laying optical fibers to quickly and economically access the dispatch data network using the wireless public network. At the same time, the powerful encryption mechanism provided by this invention ensures communication security, greatly improving the flexibility and response speed of power grid construction.
[0041] (5) It ensures a smooth evolution between the old and new systems and seamless business operations. The compatibility mode designed in this invention enables the new quantum secure communication terminal to coexist and work together with existing vertical encryption and authentication devices, supporting gradual and regional upgrades and deployments. This avoids the huge risks and investment waste brought about by "one-size-fits-all" system transformations, and ensures that the continuity and stability of power grid dispatching services are not affected in any way during the security upgrade process.
[0042] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, embodiments of the present invention are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0043] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0044] Figure 1 This is a schematic diagram of the deployment architecture of the secure communication system in this invention.
[0045] Figure 2 This is a block diagram of the internal structure of the quantum-safe communication terminal in this invention.
[0046] Figure 3 This is a schematic diagram of the overall process of the secure communication method described in this invention. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments.
[0048] Reference Figure 1This invention demonstrates the system deployment architecture of a quantum tunnel encryption-based secure communication method for substation dispatch data networks. This architecture establishes secure communication links between a dispatch master station and one or more remote substations. Unlike the traditional approach of centrally deploying security equipment at the network boundary, the core of this invention lies in deploying a dedicated quantum secure communication terminal within the local area network of the dispatch master station and within the local area network of each substation requiring secure communication. The dispatch application server within the dispatch master station and the remote terminal units (RTUs) or monitoring backend systems within the substations are all connected to the quantum secure communication terminals in their respective areas via standard Ethernet interfaces. Between the dispatch master station and the substation, there are two logically separate channels: one is a quantum channel for executing the quantum key distribution protocol, which is typically a dedicated, low-loss single-mode optical fiber; the other is a data channel for transmitting encrypted service data. This data channel can reuse the optical fiber used by the quantum channel, achieving channel sharing through wavelength division multiplexing (WDM), or it can be a completely independent physical link, such as another optical fiber, a microwave link, or, as shown in this embodiment, a fifth-generation mobile communication (5G) wireless link based on a public network. Through this deployment method, the quantum-secure communication terminal becomes the essential gateway for dispatch service data before it enters or leaves the local network, thus constituting endpoint-level security protection for the original service data.
[0049] Next, refer to Figure 2 This document details the internal functional structure of the quantum-secure communication terminal, the core execution entity of the present invention. The terminal is designed as a highly integrated dedicated hardware device, containing five key functional modules that work together to implement the secure communication method described in this invention. These five modules are: a quantum key distribution module, a post-quantum cryptography module, a security protocol processing engine, a key management and synchronization unit, and a multi-network interface module.
[0050] Specifically, the quantum key distribution module is the foundation for information-theoretic secure key negotiation. In this embodiment, the module implements a complete quantum key distribution transceiver system based on the phase-encoded decoy state BB84 protocol. When the terminal acts as the transmitter, its core light source is a distributed feedback (DFB) laser with a center wavelength precisely stabilized at 1550.12 nm and a spectral linewidth of less than 100 kHz. The light pulses generated by this laser have a pulse width precisely controlled at 500 picoseconds and a repetition frequency of 100 MHz. After passing through an adjustable optical attenuator, the light pulses are injected into an asymmetric Mach-Zehnder interferometer composed of a lithium niobate (LiNbO3) waveguide. By applying precise driving voltages (0V, 1.57V, 3.14V, 4.71V, corresponding to phases of 0, π / 2, π, and 3π / 2, respectively) to the phase modulator of the interferometer, the four quantum states (|0>, |1>, |+>, |->) of each photon are encoded. Simultaneously, by randomly modulating the intensity of the light pulses, pulse sequences with three different average photon numbers—signal state, decoy state, and vacuum state—are generated to resist photon number separation attacks. When the terminal acts as a receiver, its core detection component is a superconducting nanowire single-photon detector (SNSPD) array. This array is encapsulated in a cryostat operating at 2.2 Kelvin, achieving a detection efficiency exceeding 90% in the 1550 nm band, with a dark count rate strictly controlled below 50 times per second and a time jitter of less than 50 picoseconds. Received photons undergo basis vector selection via an interferometer symmetrical to the transmitter structure and are then detected by the detector array. The overall function of this module is to collaborate with the quantum key distribution module at the other end on the quantum channel to transmit and receive quantum signals, generating shared raw key material for the upper layer.
[0051] The post-quantum cryptography module aims to address the security issues of authentication and digital signatures in the quantum computing era. At its core is a field-programmable gate array (FPGA) chip, specifically a Xilinx Virtex UltraScale+VU9P. On this FPGA, dedicated hardware acceleration logic for executing post-quantum cryptography algorithms based on modular lattice cryptography is embedded using a hardware description language. This embodiment integrates two algorithms, both conforming to Level 3 security as defined in the National Institute of Standards and Technology (NIST) post-quantum cryptography standardization process. The first is a Key Encapsulation Mechanism (KEM) algorithm, employing a variant of CRYSTALS-Kyber, used for quantum-resistant shared secret negotiation during the initial authentication phase. The second is a digital signature algorithm, employing a variant of CRYSTALS-Dilithium, used for authenticating the identity of communicating entities and signing critical data messages to ensure their integrity and non-repudiation. The hardware acceleration logic inside the FPGA mainly includes multiple parallel polynomial multiplication units based on number theory transformation (NTT), as well as a hardware pipeline designed specifically for core cryptographic operations such as sampling and rounding, which optimizes the latency of signature and verification operations to the sub-millisecond level.
[0052] The security protocol processing engine is the central hub for data encapsulation and processing in this invention. This engine employs a high-performance multi-core network processor, such as the NXP Layerscape LX2160A, which contains 16 ARM Cortex-A72 cores operating at 2.2 GHz. This processor integrates a powerful hardware encryption / decryption coprocessor, capable of line-speed processing of authentication encryption operations for the Advanced Encryption Standard (AES) in Galois / Counter Mode (GCM). The engine's primary responsibility is to execute the two core protocols defined in this invention: encapsulation and decapsulation of the Quantum Secure Telematics Application Protocol (QSTAP) and the Quantum Secure Tunneling Protocol (QSTP). Through its internal high-speed switching structure, the engine monitors original IEC 104 protocol messages from local service terminals (such as scheduling master station applications) and, based on preset security policies and the current session state, performs in-depth processing, encapsulation, and encryption on these messages, or decrypts, verifies, and restores received encrypted messages.
[0053] The key management and synchronization unit is the cornerstone of the entire security system, responsible for the secure lifecycle management of all keys. At its core is a secure storage chip with Physical Unclonable Function (PUF) characteristics, such as STMicroelectronics' STSAFE-A110. This chip provides a hardware-isolated secure execution environment for storing the original key generated by the quantum key distribution module, the post-processed session master key (MSK), and various working keys generated from the session master key using key derivation functions (KDF). Once stored, all sensitive key materials cannot be directly read externally. The unit also incorporates a hardware implementation of the Extract-Expand Key Derivation Function (HKDF) based on Secure Hash Algorithm 3 (SHA-3). It is responsible for deterministically deriving multiple independent and unrelated working keys from a high-entropy session master key, based on different contextual information (e.g., salt value and information tags), for different encryption and authentication tasks. Meanwhile, this unit synchronizes its status with the corresponding unit of the peer device through a secure internal channel, ensuring that both parties use the correct key set at all times, and is responsible for the timed updating and secure destruction of the key.
[0054] The multi-network interface module provides the terminal with flexible network access and link redundancy capabilities. This module physically integrates a series of interfaces. Firstly, it is a single-mode fiber SFP+ interface supporting the 1000BASE-LX standard, used to connect long-distance quantum channels and the primary data channel. Secondly, it is a wireless communication module supporting the 5G New Radio (NR) standard, which internally includes a Qualcomm Snapdragon X65 baseband processor and a complete RF front-end, supporting communication at 3.5 GHz (n78 band) and 4.9 GHz (n79 band, dedicated to the power grid). This 5G interface can serve as a preferred data transmission channel in areas with scarce fiber optic resources, or as a backup channel for the primary fiber optic link. The module incorporates intelligent fault switching logic based on real-time link quality monitoring. This logic continuously monitors the latency, jitter, and packet loss rate of the fiber optic link and the 5G link by periodically sending small probe packets. Once the performance metrics of the primary link deteriorate and continue to exceed preset thresholds (e.g., latency greater than 50 milliseconds or packet loss rate higher than 0.1% for more than 5 seconds), the module will automatically and seamlessly switch the data stream to the backup link and report the link switching event to the upper-layer security protocol processing engine. The entire process is transparent to the upper-layer services, ensuring high availability and business continuity of the communication link.
[0055] After a detailed explanation of the system's core hardware entities and their functional modules, the following will combine... Figure 3The flowchart shown systematically describes the specific steps of the secure communication method for substation dispatch data networks based on quantum tunnel encryption proposed in this invention. The entire method can be divided into three logically consecutive stages: a secure session establishment step, a data encapsulation and encryption step at the sending end, and a decryption and data restoration step at the receiving end.
[0056] First, a secure session establishment step is performed. The goal of this step is to establish a secure session context containing the full set of working keys between the two quantum-secure communication terminals, which is doubly authenticated and has forward security. This step consists of a series of precisely coordinated sub-steps.
[0057] The first sub-step is initial authentication and key negotiation based on post-quantum cryptography. The purpose of this process is to securely establish an initial shared secret without any pre-shared key, and to achieve strong authentication of both communicating parties, while also being resistant to quantum computer attacks. Assume the terminal on the master station side is the initiator, and the terminal on the substation side is the responder. The initiator generates a temporary, one-time post-quantum public-private key pair (PQC_ephem_pub, PQC_ephem_priv) using its post-quantum cryptography module, employing the aforementioned CRYSTALS-Kyber key algorithm. Simultaneously, the initiator generates a 256-bit random number as a challenge. Subsequently, the initiator encapsulates this temporary public key PQC_ephem_pub and the challenge number in an "authentication request" message and sends it to the responder via the data channel. Upon receiving the request, the responding terminal first retrieves a pre-set long-term post-quantum private key (PQC_longterm_priv) representing its legitimate identity from its key management and synchronization unit. This private key is the same as the private key used in the aforementioned CRYSTALS-Dilithium algorithm. Using this long-term private key, it digitally signs the concatenated byte string of the initiator's temporary public key (PQC_ephem_pub) and the challenge number (Challenge), generating a post-quantum signature. Next, the responding terminal invokes its post-quantum cryptography module, using the initiator's temporary public key (PQC_ephem_pub) as input, to execute the key encapsulation algorithm (Kyber.Encaps), generating a shared secret and its corresponding ciphertext. Finally, the responding terminal encapsulates its own long-term post-quantum public key (PQC_longterm_pub), the generated post-quantum signature (Signature), and the ciphertext in a single "authentication response" message and sends it back to the initiator. Upon receiving the response, the initiator performs two crucial verification actions: First, it verifies the signature in the response message using the responder's long-term post-quantum public key PQC_longterm_pub, which is pre-stored in a local trusted list. The verification data consists of the initiator's previously sent temporary public key and challenge number. If this step passes, the responder's identity is successfully authenticated. Second, after successful authentication, the initiator uses its own stored temporary post-quantum private key PQC_ephem_priv to perform a key decapsulation operation (Kyber.Decaps) on the ciphertext in the response message, thereby recovering the shared secret, which is completely identical to the responder's.Thus, without needing a pre-set symmetric key, both parties have completed a two-way authentication process capable of resisting both passive and active quantum attacks, and have securely negotiated an initial shared secret. This secret will then be used to protect subsequent key negotiation processes.
[0058] The second sub-step is quantum key distribution and session master key generation. After successful initial authentication and the establishment of a secure classical communication channel (all communication content uses the key derived from the shared secret for symmetric encryption and authentication), the quantum key distribution modules of both parties initiate the quantum key distribution process through the quantum channel. Both parties strictly adhere to the pre-configured decoy state BB84 protocol. In a typical embodiment, the quantum signal transmission and reception process lasts 300 seconds. During this period, the transmitter sends a sequence of light pulses containing signal, decoy, and vacuum states at a frequency of 100 MHz, while the receiver performs synchronous detection. After 300 seconds, assuming a 25 km fiber optic link with a total attenuation of 5 dB, the two parties have exchanged approximately 3 x 10^10 pulses, and the receiver has detected approximately 3 x 10^8 valid photon events. Subsequently, the two parties enter the post-processing stage of key negotiation. Communication in this stage is conducted through the data channel and is protected by the initial shared secret generated in the previous step. First, there's sifting, where both parties publish their respective basis vector sequences used for encoding and probing, filtering out events where the basis vectors match. After this process, the key string length is reduced to approximately 1.5 x 10^8 bits. Next is QBER estimation, where both parties randomly select a small subset of the filtered bits for comparison, calculating the bit error rate (BER) of the quantum channel. Simultaneously, using statistical information from decoy states, the gain and BER of the single-photon pulse are accurately estimated, thus determining potential perturbations introduced by an eavesdropper and calculating the upper bound of the final secure key length. In this example, the estimated QBER is assumed to be 1.2%. Then, error correction is performed using an efficient low-density parity-check (LDPC) code to correct errors in the filtered key. For example, using an LDPC code with a code rate of 0.9, all erroneous bits are corrected through 10 iterations. Finally, and most crucially, is privacy amplification. To eliminate any information that could be leaked to eavesdroppers during post-processing (especially the error correction phase), both parties employ privacy amplification technology based on a dual-path universal hash function. They use the error-corrected key as input, compressing and purifying it through a hash function based on SHA-256, ultimately generating one or more 256-bit, information-theoretically secure master keys (MSKs). After this process, the initially negotiated PQC shared secret is destroyed, and all subsequent communication security is based on this MSK.
[0059] The third sub-step is the derivation of the working key. The key management and synchronization units of both parties send the newly generated 256-bit session master key MSK as input key material (IKM) to the built-in SHA-3 based HKDF module. This function uses the unique identifier of the current session (e.g., a 64-bit session ID) as the salt and a predefined string (e.g., "QSTAP-AES128GCM-KEYS") as the info input. Through a two-stage extraction-expansion process, it derives at least four independent 128-bit working keys: an application-layer encryption key (K_APP_ENC) for AES-128-GCM encryption of the QSTAP payload; an application-layer message authentication code key (K_APP_MAC), which, although AES-GCM mode has built-in authentication, can be used for independent MAC calculation or as GCM key input in some high-security scenarios; a tunnel-layer encryption key (K_TUN_ENC) for AES-128-GCM encryption of the QSTP payload; and a tunnel-layer message authentication code key (K_TUN_MAC). After derivation, a complete secure session is established, all necessary key materials are ready and securely stored, and the system enters a standby state, ready to process business data.
[0060] Once the secure session is established, the system enters the normal communication phase. The data encapsulation and encryption steps performed by the quantum-secure communication terminal at the transmitting end will be described in detail below. This step is triggered when the security protocol processing engine detects an IEC 104 Application Protocol Data Unit (APDU) originating from a local service terminal it protects (e.g., the scheduling master application server).
[0061] The first step is to construct the Quantum Secure Telemetry Application Protocol (QSTAP) message. The security protocol processing engine treats all captured complete IEC 104 APDUs, whether telemetry, telesignaling, or remote control commands, as its basic payload. The engine then creates a QSTAP message header in memory. The header structure is precisely defined as follows: a 4-byte version and compatibility flag field, where the high byte represents the major version number, the second byte represents the minor version number, and the last 2 bytes are flag bits used for compatibility mode control; an 8-byte Session Identifier (SPI), which uniquely points to the currently effective session master key MSK and the complete set of working keys derived from it, ensuring that the receiver can correctly retrieve the key; an 8-byte sequence number, which is maintained by the sender within the current session and is strictly monotonically increasing, used to defend against replay attacks; and a 2-byte payload length field, indicating the length of the subsequent encrypted payload.
[0062] The second step involves application-layer encryption and integrity protection. The security protocol processing engine invokes its built-in hardware encryption / decryption coprocessor to execute the AES-128-GCM authentication encryption algorithm. It obtains the application-layer encryption key K_APP_ENC for the current session from the key management and synchronization unit. The inputs to the encryption operation include the original IEC 104 APDU as plaintext and K_APP_ENC as the key. To generate a unique initialization vector (IV) for each encryption, the engine concatenates an 8-byte sequence number with a 4-byte fixed value to form a 96-bit IV, which satisfies the GCM mode's requirement for IV uniqueness. Simultaneously, the engine uses the entire QSTAP header created in the first step as the associated data (AAD) in the authentication encryption process. This means that the integrity of the header is protected; any tampering with the header will be detected during decryption, but the header itself is transmitted in plaintext, facilitating possible policy processing by network intermediate devices. The result of the encryption calculation is a ciphertext payload of the same length as the original APDU, and a 128-bit (16-byte) Message Authentication Code (MAC), also known as an authentication tag. The MAC is appended to the encrypted payload, forming the protected QSTAP payload portion.
[0063] The third step involves performing a post-quantum digital signature to ensure non-repudiation. To provide the highest level of security, especially for critical remote control commands, it's crucial to ensure the absolute authenticity and irrefutability of their origin. The security protocol processing engine treats the complete QSTAP message generated in the first two steps (containing a plaintext header, ciphertext payload, and a 128-bit MAC) as a single data block. It invokes the post-quantum cryptography module, passing in the sender's own long-term post-quantum private key (PQC_longterm_priv). The post-quantum cryptography module uses the CRYSTALS-Dilithium signature algorithm to calculate the SHA3-512 hash of this data block, generating a post-quantum digital signature of approximately 2420 bytes. This signature is appended to the end of the entire QSTAP message.
[0064] The fourth step is to construct the Quantum Secure Tunneling Protocol (QSTP) message. The purpose of this step is to hide the details of the internal application-layer security protocol from the external network, providing an extra layer of protection against traffic analysis. The security protocol processing engine uses the complete QSTP message (header + ciphertext payload + MAC + signature), which has been encrypted and signed by the application layer, as the payload of the Quantum Secure Tunneling Protocol. The engine creates an extremely concise QSTP message header containing only an 8-byte Tunnel Session Identifier (T-SPI) to indicate to the peer device which set of tunnel layer working keys should be used for decryption.
[0065] The fifth step involves tunnel layer encryption and integrity protection. Similar to the application layer encryption process, the security protocol processing engine again invokes the hardware encryption / decryption coprocessor. This time, however, it obtains the tunnel layer encryption key K_TUN_ENC from the key management unit. It encrypts the entire QSTAP message, which served as the QSTP payload in step four, as plaintext. Similarly, the QSTP header (i.e., T-SPI) is used as the AAD, and a unique sequence number maintained by the tunnel layer is used to generate the IV. The result of the encryption operation is a tunnel ciphertext payload and a 128-bit tunnel message authentication code.
[0066] Step six, final encapsulation and transmission. The security protocol processing engine combines the QSTP header, tunnel ciphertext payload, and tunnel message authentication code into a complete QSTP message. This message is encapsulated as the payload within a standard Internet Protocol (IP) datagram. The protocol field of this IP datagram is set to a reserved custom value (e.g., 254) to identify that it carries the QSTP protocol. The source and destination addresses in the IP header are the IP addresses of the sending and receiving quantum-secure communication terminals, respectively. Finally, this constructed IP datagram is transmitted via a multi-network interface module through the currently selected physical link (e.g., a primary dedicated fiber optic cable or a backup 5G wireless network).
[0067] Accordingly, when the multi-network interface module of the quantum-safe communication terminal at the receiving end receives an IP datagram and parses its protocol field to find that it is a QSTP protocol, the receiving end's decryption and data restoration steps are triggered. This process is the exact reverse operation of the sending end's encapsulation and encryption process.
[0068] The first step is tunnel layer decapsulation and verification. The security protocol processing engine extracts the QSTP message from the IP datagram. It first parses the 8-byte Tunnel Session Identifier (T-SPI) in the QSTP message header and uses it as an index to quickly retrieve the corresponding tunnel layer encryption key K_TUN_ENC from the key management and synchronization unit. Subsequently, the engine calls the hardware encryption / decryption coprocessor to perform AES-128-GCM decryption and verification operations. It takes the QSTP message header as the AAD, the tunnel ciphertext payload, and the tunnel message authentication code as input. The coprocessor simultaneously recalculates and compares the decryption and authentication tags. If the calculated tag does not match the tag attached to the message, it indicates that the data has been tampered with or corrupted during transmission; the message is immediately discarded, and a high-priority security alarm log is generated. If verification is successful, the decrypted plaintext payload is output, which is a complete QSTAP message with a post-quantum digital signature.
[0069] The second step is post-quantum digital signature verification. The engine submits the decrypted QSTAP message and its attached post-quantum digital signature to the post-quantum cryptography module. Simultaneously, it retrieves the sender's long-term post-quantum public key (PQC_longterm_pub) from its local trusted list based on the IP source address or sender information in the QSTAP message header. The post-quantum cryptography module uses this public key and the CRYSTALS-Dilithium verification algorithm to verify the signature. If signature verification fails, it indicates that the message was not signed by the claimed sender, or that the message content (even if ciphertext) was tampered with after signing but before tunnel encryption. The message is immediately discarded and recorded as a signature forgery attack. This step is a crucial barrier to ensure the authenticity and non-repudiation of the data source.
[0070] The third step is application-layer decapsulation and verification. After successful signature verification, the security protocol processing engine begins processing the QSTAP message. It parses the QSTAP message header to obtain the 8-byte Session Identifier (SPI) and the 8-byte sequence number. First, the engine compares this sequence number with the last sequence number successfully received in the current session. If it is less than or equal to, it is considered a replay attack, and the message is discarded. If it is greater, the latest sequence number recorded locally is updated. Next, the corresponding application-layer encryption key K_APP_ENC is retrieved from the key management unit based on the SPI. The engine again calls the hardware encryption / decryption coprocessor to perform AES-128-GCM decryption and verification on the ciphertext payload and message authentication code in the QSTAP message. The QSTAP message header also participates in the verification as an AAD. If authentication fails, the message is discarded.
[0071] The fourth step is to restore and forward the original data. After successful verification of the application layer message authentication code, the engine finally obtains the decrypted plaintext payload. This payload is the original, unmodified Application Protocol Data Unit (APDU) of the IEC 104 standard. At this point, all security encapsulation layers have been stripped and verified. The security protocol processing engine forwards this clean APDU directly to the local dispatch master station application system or substation monitoring backend it protects through an internal physical port. For the local business system, it receives a standard, directly parseable IEC 104 message, as if there were no encryption steps in the communication process, thus achieving complete transparency to the existing business system.
[0072] As a preferred embodiment of the present invention, to ensure that this technical solution can adapt to the complex existing environment of the power grid dispatch data network and achieve a smooth transition and seamless integration of the old and new systems, the security protocol processing engine of the quantum secure communication terminal has a set of refined compatibility strategy control logic embedded within it. The core of this logic is a "peer device capability registry" that can be remotely configured by the network administrator. This registry records the security capability level of each peer device, indexed by its IP address or logical identifier. When communication is initiated, the engine queries this table and sets the corresponding mode flag in the "Version and Compatibility Flags" field of the QSTAP message header based on the query results. Specifically, there are three working modes:
[0073] First, Full Mode. This mode is enabled when the registry shows that the peer device has also deployed the full-featured quantum-secure communication terminal described in this invention, and the quantum channel between the two devices is normal and can continuously generate keys. In this mode, the terminal will fully execute all the aforementioned security steps, including QSTAP encapsulation encryption signature and QSTP tunnel encapsulation encryption, providing the highest level of security protection.
[0074] Secondly, Hybrid Mode. When the registry shows that the peer device is a quantum-safe communication terminal of the same model, but the quantum channel between the two is interrupted (e.g., fiber optic cable failure) or has not yet been initialized, the system automatically degrades to this mode. In this mode, the generation of the session key degenerates to relying entirely on the aforementioned post-quantum cryptography-based key encapsulation mechanism for negotiation. The terminal will only perform application-layer QSTAP encapsulation, encryption, and signing, completing the third step of the data encapsulation and encryption process to the sending end. Afterward, the generated protected QSTAP message will no longer undergo QSTP tunnel encapsulation, but will be directly delivered to the existing vertical encryption and authentication device deployed serially with the quantum-safe communication terminal, which will then use traditional protocols such as IPsec for transport-layer encryption. This mode ensures that even in the extreme case of quantum channel failure, the end-to-end security of core business data remains guaranteed.
[0075] Third, Legacy Mode. This mode is enabled when the registry shows that the peer device is a traditional terminal that does not support the method described in this invention and only deploys a traditional vertical encryption authentication device. In this mode, the security protocol processing engine of the quantum-secure communication terminal will not perform any QSTAP or QSTP encapsulation operations. It will treat the intercepted local IEC 104 messages as ordinary IP traffic and forward them directly and without modification to the serially deployed vertical encryption authentication device in a transparent bridge manner, whereby the device will complete the traditional network layer tunnel encryption. This mode enables the new terminal to seamlessly integrate with the large existing system, supporting the gradual, regional, and batch upgrade deployment of the power grid, avoiding the huge risks, investment waste, and impact on critical business continuity caused by "one-size-fits-all" system transformation.
[0076] To illustrate the technical advantages of this invention, we have compared the method of this invention with conventional methods.
[0077] 1. Implementation of the method of the present invention:
[0078] The scenario is as follows: A dispatching application located at a dispatching master station in Beijing needs to send a remote tripping command to a remote control terminal unit located at a 220 kV substation in Tianjin. The two locations are connected via a 140 km long G.652.D standard single-mode optical fiber with a total link attenuation of 28 dB. Since the distance exceeds the secure transmission limit of a single-span QKD (Quantum-Know-Domain) communication, two trusted relay nodes are deployed along the fiber optic route, dividing the entire link into three independent quantum channels. Both the dispatching master station and the substation deploy the quantum-secure communication terminal described in this invention.
[0079] Before operation, the quantum-safe communication terminals at both ends first perform the secure session establishment step.
[0080] Initial Authentication: The master terminal initiates an initial authentication process to the substation terminal based on CRYSTALS-Kyber768 and CRYSTALS-Dilithium2. On the terminal's built-in FPGA (Xilinx Virtex UltraScale+VU9P), the average latency for key generation, encapsulation, and decapsulation operations with Kyber768 is 45 microseconds, 55 microseconds, and 50 microseconds, respectively. The average latency for signature and verification operations with Dilithium2 is 120 microseconds and 60 microseconds, respectively. The total time for the entire interaction (request-response) to establish the initial shared secret is approximately 280 microseconds, plus network transmission latency.
[0081] Quantum key generation: Three quantum channels simultaneously initiate the BB84 protocol in a decoy state. The average attenuation of each channel is approximately 9.3 dB. The quantum key distribution module operates at a frequency of 100 MHz. Over a 300-second key generation cycle, considering the combined performance of the three links, the system can generate approximately 1.2 x 10^6 256-bit session master keys (MSKs), with an average key generation rate of approximately 4000 MSKs per second. These keys are stored in the key pool of the key management and synchronization unit.
[0082] Working key derivation: Take an MSK from the key pool and derive four 128-bit working keys, K_APP_ENC, K_APP_MAC, K_TUN_ENC, and K_TUN_MAC, using HKDF-SHA3. This process takes less than 5 microseconds on the network processor.
[0083] When the dispatcher issues a remote tripping command, an IEC 104 APDU (10 bytes in length) containing the command is generated and sent to the quantum-safe communication terminal on the master station side.
[0084] QSTAP encapsulation and encryption: The engine creates a QSTAP header (22 bytes) and uses K_APP_ENC to encrypt the 10-byte APDU using AES-128-GCM, generating a 10-byte ciphertext and a 16-byte MAC. This step takes approximately 1.5 microseconds on the hardware coprocessor.
[0085] PQC Signature: The QSTAP message (22+10+16=48 bytes) is submitted to the post-quantum cryptography module, which performs Dilithium2 signing using the long-term private key, generating a 2420-byte signature. This step takes 120 microseconds.
[0086] QSTP encapsulation and encryption: The signed QSTAP message (48 + 2420 = 2468 bytes) is used as the payload, a QSTP header (8 bytes) is added, and AES-128-GCM encryption is performed using K_TUN_ENC. Due to the large payload, this step takes approximately 8 microseconds.
[0087] Sending: The final generated IP datagram (approximately 2500 bytes in total length) is sent through the data channel.
[0088] After receiving the IP message, the quantum-safe communication terminal on the substation side performs the reverse operation.
[0089] QSTP decryption and verification: takes approximately 8 microseconds.
[0090] PQC signature verification: takes approximately 60 microseconds.
[0091] QSTAP decryption verification: takes approximately 1.5 microseconds.
[0092] Ultimately, the original 10-byte remote control command APDU was successfully restored and sent to the remote terminal unit. From the moment the APDU is received by the master terminal to the substation terminal forwarding the restored APDU, the total one-way processing delay introduced by the entire safety processing flow is approximately 1.5 + 120 + 8 + 8 + 60 + 1.5 = 199 microseconds. This delay is negligible for the real-time requirements of power grid dispatching operations.
[0093] 2. Implementation of traditional methods:
[0094] The same dispatching scenario from Beijing to Tianjin is used. However, security protection employs technologies commonly used in the current power grid: vertical encryption and authentication devices are deployed at the network egress points of the dispatching master station and substations. This device is based on a commercial firewall platform, uses the IPsec protocol to build a VPN tunnel, employs RSA-4096 certificates for authentication, AES-256-CBC encryption algorithm, and SHA-256 hash algorithm.
[0095] In this architecture, the IEC 104 remote control command APDU (10 bytes) generated by the master station application is transmitted in plaintext within the master station's intranet. Upon reaching the vertical encryption device at the network egress, the entire IP packet (including the plaintext APDU) is encapsulated and encrypted using the IPsec protocol before being transmitted via the fiber optic data channel. At the substation side, the vertical encryption device decrypts the IPsec packet, restoring the original IP packet. This IP packet is then transmitted in plaintext within the substation's intranet, ultimately reaching the remote terminal unit (RTU).
[0096] The one-way processing latency of this scheme is mainly contributed by IPsec encapsulation / decapsulation and encryption / decryption operations, and its latency is about 400 microseconds under the same hardware performance.
[0097] Performance and safety comparison between the method of this invention and traditional methods:
[0098] Table 1 provides a quantitative and qualitative comparison between the method of this invention and traditional methods across several key dimensions.
[0099] Table 1
[0100]
[0101] A comparison of data from the method of this invention and traditional methods clearly demonstrates that the quantum tunnel encryption-based secure communication method for substation dispatch data networks disclosed in this invention exhibits fundamental and obvious advantages over existing technologies in several aspects, including the depth of the security model, the ability to resist future threats, the granularity of protection for critical business data, the flexibility of deployment, and the smoothness of system evolution. It not only addresses the security shortcomings of current dispatch data networks but also constructs a solid, forward-looking, and feasible technical framework for the cybersecurity of next-generation power systems.
[0102] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A secure communication method for substation dispatch data network based on quantum tunneling encryption, applied between a dispatch master station and a substation, wherein both the dispatch master station and the substation are equipped with quantum secure communication terminals, characterized in that... The method includes the following steps: establishing a secure session, whereby a secure session context containing a session master key and a set of working keys derived from the session master key is established between the quantum-secure communication terminals of the two communicating parties; data encapsulation and encryption at the transmitting end, whereby the original telemetry protocol message originating from the local service terminal is encapsulated and encrypted at the application layer and at the tunnel layer to generate a double-encrypted datagram to be sent at the quantum-secure communication terminal of the transmitting end; and decryption and data restoration at the receiving end, whereby the received datagram to be sent is decrypted and verified at the tunnel layer and at the application layer to restore the original telemetry protocol message and forward it to the local service terminal. The quantum-safe communication terminal is internally integrated with: The quantum key distribution module is used to execute a quantum key distribution protocol between two communicating parties via a quantum channel to generate a shared original key; The post-quantum cryptography module is used to execute post-quantum cryptography algorithms for authentication and digital signatures. The security protocol processing engine is used to perform protocol encapsulation, decapsulation, encryption, and decryption operations at the application layer and tunnel layer. The key management and synchronization unit is used to manage and store the session master key and the working key throughout their entire lifecycle. A multi-network interface module is used to provide data channel access capabilities for at least two different physical media, and to perform link aggregation and fault switching between the data channels; The establishment of the secure session specifically includes: Initial authentication and key negotiation based on post-quantum cryptography: The quantum-secure communication terminal of the initiator generates a temporary post-quantum public-private key pair and sends the temporary public key and a random challenge number to the responder; the responder uses its long-term post-quantum private key to digitally sign the concatenation value of the received initiator's temporary public key and the challenge number, and uses the initiator's temporary public key to generate a ciphertext package of the shared secret through a key encapsulation mechanism algorithm, and returns the signature, its own long-term post-quantum public key, and the ciphertext package to the initiator; the initiator authenticates the responder's identity by verifying the signature, and uses its temporary post-quantum private key to decrypt the ciphertext package to obtain the shared secret, thereby establishing an initial shared secret with two-way authentication; Quantum key distribution and session master key generation: After successful initial authentication, the quantum key distribution modules of both parties execute the quantum key distribution protocol through the quantum channel; subsequently, the two parties perform basis vector comparison, bit error rate estimation, error bit removal using low-density parity-check codes, and privacy amplification technology based on dual-path universal hash functions through the classical channel protected by the initial shared secret, and finally generate a 256-bit session master key with unconditional security. Working key derivation: The key management and synchronization units of both parties take the session master key as input, use the extraction-expansion key derivation function based on the secure hash algorithm 3, and use the session identifier and the identity identifiers of both communicating parties as salt values and information inputs to derive at least four independent working keys, including: application layer encryption key, application layer message authentication code key, tunnel layer encryption key, and tunnel layer message authentication code key.
2. The method according to claim 1, characterized in that, The quantum key distribution module executes the phase-encoded decoy state BB84 protocol; When the quantum secure communication terminal is used as the transmitter, the quantum signal transmitter in the quantum key distribution module uses a narrow linewidth distributed feedback laser with a center wavelength of 1550 nanometers as the light source. The phase of the photons is modulated by an asymmetric Mach-Zehnder interferometer, and the intensity of the light pulse is randomly modulated to generate a pulse sequence of signal state, decoy state and vacuum state. When the quantum secure communication terminal is used as the receiving end, the quantum signal receiver in the quantum key distribution module uses a superconducting nanowire single-photon detector array with a response wavelength range covering 1500 to 1600 nanometers, a dark count rate of less than 100 times per second, and a detection efficiency of more than 20% for basis selection and photon detection.
3. The method according to claim 1, characterized in that, The post-quantum cryptography module has an embedded field-programmable gate array chip, on which hardware acceleration logic for executing post-quantum cryptography algorithms based on modular lattice cryptography is embedded. The post-quantum cryptography module specifically performs the following: A key encapsulation mechanism algorithm based on a modular version with rounding issues is used to securely negotiate and share secrets during the initial authentication phase of the secure session. A modular version of a digital signature algorithm with rounding issues is used to authenticate communication entities during the establishment of the secure session and to digitally sign key data packets during the data encapsulation and encryption at the sending end.
4. The method according to claim 1, characterized in that, The multi-network interface module physically integrates: A single-mode fiber optic interface supporting the 1000BASE-LX standard is used to connect the quantum channel to the fiber optic link that serves as the primary data channel. A wireless communication module that supports the fifth-generation mobile communication new radio standard. The module includes an RF front-end and a baseband processor, and supports communication in the 3.5 GHz band, serving as a backup or primary data transmission channel. The multi-network interface module has built-in link aggregation and intelligent fault switching logic. By periodically monitoring the latency, jitter and packet loss rate of each link, it automatically and seamlessly switches the data stream to the backup link when the performance indicators of the primary link deteriorate and continue to exceed the preset threshold.
5. The method according to claim 1, characterized in that, The data encapsulation and encryption at the sending end specifically includes: Constructing a quantum-safe telemetry application protocol message: The security protocol processing engine uses the captured complete IEC 104 protocol application protocol data unit as the basic payload and creates a quantum-safe telemetry application protocol message header containing version compatibility flags, session identifiers, sequence numbers, and payload length fields; Application layer encryption and integrity protection: The security protocol processing engine calls the authentication encryption algorithm module based on the Advanced Encryption Standard and operating in Galois / counter mode, uses the application layer encryption key to encrypt the basic payload, and uses the quantum-safe telemetry application protocol message header as associated data for authentication, generating ciphertext payload and application layer message authentication code; Post-quantum digital signature: The security protocol processing engine treats the quantum-safe telemetry application protocol message header, the ciphertext payload, and the application layer message authentication code as a whole data block, calls the post-quantum cryptographic operation module, uses the long-term post-quantum private key of the sending end to execute the digital signature algorithm on the data block, generates a post-quantum digital signature, and appends it to the end of the message; Constructing a quantum-safe tunnel protocol message: The security protocol processing engine takes the complete quantum-safe telemetry application protocol message, which has been encrypted and signed by the application layer, as the tunnel layer payload and creates a quantum-safe tunnel protocol message header containing only the tunnel session identifier; Tunnel layer encryption and integrity protection: The security protocol processing engine calls the authentication encryption algorithm module again, uses the tunnel layer encryption key to encrypt the tunnel layer payload, and uses the quantum secure tunnel protocol message header as associated data for authentication to generate tunnel ciphertext payload and tunnel message authentication code; Final encapsulation and transmission: The quantum secure tunnel protocol message header, the tunnel ciphertext payload, and the tunnel message authentication code are combined into a complete quantum secure tunnel protocol message, which is then encapsulated in the payload of an Internet Protocol datagram and sent out through the multi-network interface module.
6. The method according to claim 5, characterized in that, The receiving end decryption and data restoration specifically include: Tunnel layer decapsulation and verification: The security protocol processing engine extracts the quantum secure tunnel protocol message from the received Internet Protocol datagram, retrieves the corresponding tunnel layer encryption key according to the tunnel session identifier in the message header, and calls the authentication encryption algorithm module to decrypt and verify the tunnel ciphertext payload and tunnel message authentication code. If the verification fails, the message is discarded; if successful, the decrypted and complete quantum secure telemetry application protocol message is obtained. Post-quantum digital signature verification: The security protocol processing engine calls the post-quantum cryptographic operation module and uses the pre-stored long-term post-quantum public key of the sending end to verify the post-quantum digital signature attached to the decrypted quantum secure telemetry application protocol message. If the verification fails, the message is discarded. Application layer decapsulation and verification: After successful signature verification, the security protocol processing engine parses the header of the quantum secure telemetry application protocol message, checks the sequence number to prevent replay attacks, retrieves the corresponding application layer encryption key based on the session identifier, and calls the authentication encryption algorithm module to decrypt and verify the ciphertext payload and application layer message authentication code in the message. If the verification fails, the message is discarded. Restore and forward the original data: After successful verification at the application layer, the decrypted plaintext payload, i.e. the original IEC 104 protocol application protocol data unit, is obtained and forwarded to the local business terminal.
7. The method according to claim 6, characterized in that, The security protocol processing engine incorporates compatibility policy control logic based on a configurable registry of peer device capabilities. Based on the results of querying this registry, it sets different working mode flags in the version and compatibility flag fields of the quantum-safe telemetry application protocol header. The working modes include: Full mode: This mode is enabled when both communicating parties have deployed the quantum-safe communication terminal and the quantum channel between them is available, and all steps in claim 1 are performed. Hybrid mode: This mode is enabled when both communicating parties have deployed the quantum-safe communication terminal but the quantum channel between them is unavailable. In this mode, the generation of the session key degenerates to relying solely on the key encapsulation mechanism of post-quantum cryptography for negotiation. The terminal only performs application-layer encapsulation, encryption, and signing. After that, the protected message is delivered to the existing longitudinal encryption authentication device deployed in serial order for transport layer encryption. Traditional mode: When the peer device is a traditional device that does not support the method of this invention, the security protocol processing engine does not perform any encapsulation and encryption operations, but instead forwards the intercepted original telemetry protocol message directly to the existing serially deployed vertical encryption and authentication device in the form of a transparent bridge.
Citation Information
Patent Citations
5G quantum security differential protection communication system and communication method
CN118714556A
5G quantum encryption communication method and device based on RedCap
CN119277378A