Anti-quantum identity authentication method and system for novel power system terminal communication

By establishing a communication architecture in a new power system and adopting a quantum-resistant identity authentication method, and utilizing quantum keys and fuzzy hash calculations, the security threat of quantum attacks to the power system is solved, and reliable identity authentication and secure information transmission for terminal devices are achieved.

CN121125295APending Publication Date: 2025-12-12STATE GRID ANHUI ELECTRIC POWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511410652.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

New power systems face security threats from quantum computing technology. Traditional encryption methods are unable to effectively defend against quantum attacks, leading to serious security risks in power communication systems, especially vulnerabilities and unauthorized access issues in the identity authentication of terminal devices and cloud devices.

Method used

A new power system communication architecture is established, adopting a quantum-resistant identity authentication method. Identity authentication is performed through a quantum key distribution scheme, combined with fuzzy hash calculation of device behavior and biometric fingerprints, to achieve zero-trust information transmission control and monitoring, ensuring the security of information transmission.

Benefits of technology

Effectively resist quantum attacks, ensure the security of communication processes in new power systems, prevent unauthorized access and identity impersonation, and achieve reliable identity authentication and secure information transmission for terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125295A_ABST
    Figure CN121125295A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an anti-quantum identity authentication method and system for novel power system terminal communication, and belongs to the field of anti-quantum identity authentication. The anti-quantum identity authentication method comprises the following steps: establishing a novel power system communication architecture; information transmission of each end part in the novel power system communication architecture is carried out based on anti-quantum-attack identity authentication; and information transmission of each end part is controlled and monitored based on zero trust of the quantum key. According to the anti-quantum identity authentication method, the novel power system can be prevented from being attacked in the subsequent communication process based on anti-quantum identity authentication, and the security risk faced by a novel power communication access and transmission scene can be dealt with.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of anti-quantum identity authentication, in particular to an anti-quantum identity authentication method and system for terminal communication of a new power system. BACKGROUND

[0002] As the core support of the smart grid, the new power communication system shows unprecedented flexibility and inclusiveness, not only promoting the comprehensive Internet of Things and intelligent transformation of the power network, but also greatly improving the efficiency and reliability of power transmission and distribution. This trend brings convenience and efficiency, but also quietly introduces new security challenges. In recent years, the security incidents of power grids in various countries have occurred frequently, attracting the attention of the country and various industries, and the security problems faced by the power system have become increasingly prominent. For example, illegal access attempts are increasingly rampant, identity fraud incidents occur frequently, and the system itself may have vulnerabilities and defects, making the power communication system face unprecedented security risks. The power communication network is an important infrastructure that provides protection for the power system. Once attacked, it may cause significant losses, or even chaos in the entire country. More seriously, with the rapid development and continuous iteration of quantum computing technology, its powerful computing power has posed a substantial threat to traditional encryption methods, forming a so-called "quantum attack" risk, which poses a fundamental challenge to the cornerstone of power security communication.

[0003] Compared with the traditional power system, the uncertainty faced by the new power system will be greatly improved, and the operating mechanism will be more complex, so it is urgent to rely on advanced information communication technology to support the high-performance operation and efficient management and control needs of the power system, thereby improving the reliable acquisition, secure transmission and efficient processing capacity of information of the power system to support the safe and economic operation of the new power system. Therefore, it is necessary to establish a zero-trust anti-quantum identity authentication method for terminal devices and cloud devices in the new power system, so that the new power system can avoid attacks based on anti-quantum identity authentication in subsequent communication processes, and can cope with the security risks faced by the new power communication access and transmission scenario. SUMMARY

[0004] The purpose of the embodiment of the present application is to provide an anti-quantum identity authentication method and system for terminal communication of a new power system, which can avoid attacks in subsequent communication processes of the new power system based on anti-quantum identity authentication, and can cope with the security risks faced by the new power communication access and transmission scenario.

[0005] In order to achieve the above-mentioned purpose, the embodiment of the present application provides an anti-quantum identity authentication method for terminal communication of a new power system, which comprises: establishing a new power system communication architecture; Identity authentication based on quantum attack resistance is used for information transmission of each end in the new power system communication architecture; Quantum key-based zero trust is used for control and monitoring of information transmission of each end.

[0006] Optionally, the new power system communication architecture includes a backbone communication network and a terminal access communication network, wherein the backbone communication network includes an application layer and a platform layer, the application layer sets corresponding business applications, including power transmission business applications, power transformation business applications, power distribution business applications and new business applications, and the platform layer sets a cloud platform, an Internet of Things management platform and an enterprise middle platform; the terminal access communication network includes a network layer and a sensing layer, and the sensing layer includes data acquisition terminals corresponding to each business.

[0007] Optionally, identity authentication based on quantum attack resistance is used for information transmission of each component in the new power system communication architecture, including: Based on a quantum key distribution scheme, the initiator of identity authentication and the verifier of identity authentication jointly verify to obtain the same quantum key: The initiator generates an identity private key and securely stores it, and generates a corresponding public key and a companion public key according to system rules, and the verifier stores a public key matrix; The initiator generates a random number through a quantum random number generator, and simultaneously acquires a device behavior fingerprint or a biological feature fingerprint of itself; The initiator performs fuzzy hash calculation on the acquired device behavior fingerprint or biological feature fingerprint to obtain a fuzzy hash value: , Wherein, is a fuzzy hash function, is a fuzzy hash value, , are a device behavior fingerprint and a biological feature fingerprint, respectively; The stored identity private key is used for SM2 signature calculation on the current time, the random number and the fuzzy hash value of the device behavior fingerprint or the biological feature fingerprint to generate a signature; The initiator uses the same quantum key as the verifier to encrypt its identity ID, the companion public key, the fuzzy hash value and the generated signature, thereby obtaining a ciphertext; The initiator sends the ciphertext to the verifier; The verifier decrypts the ciphertext sent by the initiator and performs multiple verifications, and returns a corresponding verification result.

[0008] Optionally, the verifier decrypts the ciphertext sent by the initiator and performs multiple verifications, and returns a corresponding verification result, including: The verifier receives the ciphertext and decrypts the ciphertext using the same quantum secret key to obtain the corresponding identification ID, accompanying public key, fuzzy hash value and generated signature; The verifier performs fuzzy hash calculation according to the corresponding device behavior fingerprint or biometric fingerprint stored by the verifier to obtain the fuzzy hash value of the verifier side: , Among them, represents the hash value of the verification side, represents the corresponding device behavior fingerprint and biometric fingerprint stored by the verifier; According to the obtained fuzzy hash value of the initiator and the fuzzy hash value of the verifier, the similarity is calculated: , Among them, represents the similarity of the fuzzy hash value of the initiator and the fuzzy hash value of the verifier; Obtain the similarity and determine whether the similarity is within a set range; In the case where the similarity is within the set range, it is confirmed that the fuzzy hash value of the initiator is valid.

[0009] Optionally, the verifier receives the ciphertext sent by the initiator and performs multiple verifications to return the corresponding verification result, including: In the case where the similarity is not within the allowed range, it is confirmed that the fuzzy hash value of the initiator is invalid, and the device behavior fingerprint or biometric fingerprint is re-collected for fuzzy hash calculation and verification; In the case where the number of verification failures exceeds the preset threshold, the manual review or locking state is entered.

[0010] Optionally, the verifier receives the ciphertext sent by the initiator and performs multiple verifications to return the corresponding verification result, including: Obtain the valid fuzzy hash value of the initiator, and the identification ID, accompanying public key; According to the identification ID, accompanying public key and stored public key matrix, the identification public key of the initiator is solved; Obtain the solved identification public key of the initiator and the valid fuzzy hash value of the initiator to verify the signature of the initiator, and return the corresponding verification result.

[0011] Optionally, the verifier receives the ciphertext sent by the initiator and performs multiple verifications to return the corresponding verification result, including: According to the identification public key fuzzy hash value obtained by decryption, the corresponding verifier signature is generated in the same signature construction manner as the foregoing; verify the signature of the verifier and the decrypted signature of the initiator to determine whether they are consistent; In the case where the signature of the verifier and the decrypted signature of the initiator are consistent, it is confirmed that the initiator signature is valid, and it is determined that the authentication is successful. In the case where the signature of the verifier and the decrypted signature of the initiator are consistent, it is confirmed that the initiator signature is invalid, and it is entered into an artificial review or a locked state.

[0012] Optionally, the quantum key-based zero trust controls and monitors the information transmission of each end, including: Identity authentication is performed on all users and devices to ensure their true identities. Access control is performed on all users and devices to allow them to access only the resources they need. Real-time monitoring is performed on all users and devices to timely discover and prevent abnormal behaviors. Risk assessment is performed on all users and devices to dynamically authorize them according to their security states and access behaviors.

[0013] On the other hand, the present application also provides an anti-quantum identity authentication system for terminal communication of a new power system, including: A power system construction module is configured to establish a new power system communication architecture. An anti-quantum identity authentication module is configured to perform information transmission of each end in the new power system communication architecture based on anti-quantum attack-resistant identity authentication. A zero trust security architecture module is configured to control and monitor the information transmission of each end based on quantum key-based zero trust.

[0014] Through the above technical solutions, the anti-quantum identity authentication method and system for terminal communication of a new power system provided by the present application can establish a new power system communication architecture, and then perform information transmission of each end in the new power system communication architecture based on anti-quantum attack-resistant identity authentication. In the case where the identity authentication of each end is passed, the subsequent information transmission of each end can be performed, and in the process of identity authentication and information transmission, the information transmission of each end is controlled and monitored based on quantum key-based zero trust. The anti-quantum identity authentication method can be based on anti-quantum identity authentication to avoid attacks on the new power system in the subsequent communication process, and can cope with the security risks faced by the new power communication access and transmission scenario.

[0015] Other features and advantages of the embodiments of the present application will be described in detail in the following specific implementation part. BRIEF DESCRIPTION OF DRAWINGS

[0016] The accompanying drawings are included to provide a further understanding of embodiments of the application, and are incorporated in and constitute a part of this specification, illustrate embodiments of the application, and together with the description serve to explain embodiments of the application, but do not limit the application. In the drawings: Figure 1 is a flowchart of an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application; Figure 2 is a flowchart of anti-quantum identity authentication for an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application; Figure 3 is a flowchart of verifying a blurring hash value of an initiator for an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application; Figure 4 is a first flowchart of verifying a signature for an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application; Figure 5 is a second flowchart of verifying a signature for an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application; Figure 6 is a flowchart of zero-trust monitoring for an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application; Figure 7 is a schematic diagram of an anti-quantum identity authentication according to an embodiment of the application. DETAILED DESCRIPTION

[0017] The specific embodiments of the embodiments of the application will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the embodiments of the application, and are not used to limit the embodiments of the application.

[0018] In the embodiments of the present application, some software, components, models and the like in the industry may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the technical solutions in the embodiments of the application, but does not mean that the applicant has or will necessarily use the scheme.

[0019] Figure 1 is a flowchart of an anti-quantum identity authentication method for new-type power system terminal communication according to an embodiment of the application. In the present application, the flow of the anti-quantum identity authentication method can include: In step S1, a new-type power system communication architecture is established.

[0020] In step S2, information transmission of each end in the new power system communication architecture is carried out based on quantum attack-resistant identity authentication.

[0021] In step S3, information transmission of each end is controlled and monitored based on quantum key-based zero trust.

[0022] In the present application, a new power system communication architecture can be established, and then information transmission of each end in the new power system communication architecture can be carried out based on quantum attack-resistant identity authentication. In the case that identity authentication of each end is passed, subsequent information transmission of the end can be carried out, and in the process of identity authentication and information transmission, information transmission of each end is controlled and monitored based on quantum key-based zero trust. The quantum-resistant identity authentication method can avoid attacks on the new power system in subsequent communication processes based on quantum-resistant identity authentication, and can cope with security risks faced by new power communication access and transmission scenarios.

[0023] In an embodiment of the present application, the new power system communication architecture can include a backbone communication network and a terminal access communication network. The backbone communication network includes an application layer and a platform layer. The application layer sets up corresponding business applications, including power transmission business applications, power transformation business applications, power distribution business applications and new business applications, etc. The platform layer sets up at least a cloud platform, an Internet of Things management platform and an enterprise middle platform. The cloud platform provides technical support such as network, security, database and middleware for the Internet of Things management platform, so as to ensure that the Internet of Things management platform can realize functions such as connection management, device management, network management, application management and message processing. The Internet of Things management platform can directly interact with the business applications of the application layer, or can first interact through the enterprise middle platform, and then interact with the business applications through the enterprise middle platform.

[0024] The terminal access to the communication network includes two parts of a network layer and a perception layer. The perception layer includes data acquisition terminals corresponding to various services, such as power transmission service acquisition terminals, power transformation service acquisition terminals, power distribution service acquisition terminals, and new service acquisition terminals. The acquisition terminals transmit the acquired data to edge Internet of Things agent nodes, and the edge Internet of Things agent nodes transmit the data information to the cloud platform through power optical fibers, wireless private networks, or wireless public networks of the network layer. Specifically, in the power transmission scenario, the power transmission service acquisition terminals transmit the acquired data to a plurality of aggregation nodes through a wireless ad hoc network, and then the aggregation nodes transmit the aggregated data to the network access nodes of the power transmission scenario, that is, the edge Internet of Things agents. The power transmission service acquisition terminals can also directly transmit the data to the network through 4G or 5G networks. In the power transformation scenario, the power transformation service acquisition terminals can transmit the data to the network access nodes through intelligent APs or 4G, 5G, or optical fibers, and then the network access nodes transmit the data to the network. Meanwhile, the power transformation service acquisition terminals can also directly transmit the data to the network through 4G or 5G networks. In the power distribution scenario, the power distribution service acquisition terminals transmit the input to the fusion terminal through HPLC+HRF dual-mode communication, and the fusion terminal accesses the network layer as an edge Internet of Things agent. In the new service scenario, the new service scenario mainly comes from source network load storage applications such as virtual power plants and distributed new energy access. The new service acquisition terminals transmit the data to the edge Internet of Things agents such as energy controllers through wide and narrow low-power sensor networks, and the edge Internet of Things agents communicate with the network layer.

[0025] Although the platform layer and the application layer service interaction based on the backbone communication network can ensure safety, with the general terminalization of new power communication access, the interaction between the services at the platform layer and the application layer will bring new security risks. In addition, the sensors or acquisition terminals at the perception layer mainly realize data acquisition of small particle services through local communication networks, and the data is directly uploaded to the communication backbone network or uploaded through aggregation nodes. Most of the sensor or acquisition terminal devices have few running resources and single functions, and cannot realize security protection. Data transmission is mostly transparent, and data security communication cannot be guaranteed, which poses a security risk to the stable operation of the power system. At the same time, with the advancement of new power systems, source network load storage applications are increasingly frequent, and various new energy terminal devices accessing the power system lack effective security protection means and cannot guarantee the autonomous controllability of the power system to such terminal devices.

[0026] In one embodiment of the present application, as shown in Figure 2 The process of anti-quantum identity authentication can include: In step S4, based on the quantum key distribution scheme, the initiator of identity authentication and the verifier of identity authentication jointly verify to obtain the same quantum key.

[0027] In step S5, the initiator generates and securely stores an identifier private key, and generates a corresponding public key and accompanying public key according to system rules. The verifier stores the public key matrix.

[0028] In step S6, the initiator generates random numbers using a quantum random number generator and simultaneously collects its own device behavior fingerprint or biometric fingerprint.

[0029] In step S7, the initiator performs fuzzy hash calculation on the collected device behavior fingerprint or biometric fingerprint to obtain the hash value: , in, For fuzzy hash functions, For fuzzy hash values, , These are device behavior fingerprints and biometric fingerprints, respectively.

[0030] In step S8, the stored identifier private key is used to perform SM2 signature calculation on the current time, random number, and fuzzy hash value of device behavior fingerprint or biometric fingerprint to generate a signature.

[0031] In step S9, the initiator uses the same quantum key as the verifier to encrypt its identifier ID, accompanying public key, fuzzy hash value, and generated signature to obtain the ciphertext.

[0032] In step S10, the initiator sends the ciphertext to the verifier.

[0033] In step S11, the verifier receives the ciphertext sent by the initiator, decrypts it, performs multiple verifications, and returns the corresponding verification result.

[0034] In this invention, during quantum-resistant identity authentication, a quantum key distribution scheme can be used, where the initiator and verifier of the authentication jointly verify to obtain the same quantum key, such as... Figure 7 As shown, Figure 7 In this model, Alice can be represented as the initiator, and Bob as the verifier. After obtaining the keys, the initiator can generate and securely store an identifier private key, and generate a corresponding public key and accompanying public key according to system rules. The verifier can store the public key matrix. The initiator can generate random numbers using a quantum random number generator and can collect its own device behavior fingerprint or biometric fingerprint. When the authenticator is a device, the device's vibration frequency can be used. Data transmission frequency and equipment energy consumption information Device behavior fingerprints that make up terminal devices For human users, their fingerprints can be used. facial features and iris composing a biometric fingerprint . According to the obtained device behavior fingerprint or biometric fingerprint, a fuzzy hash calculation can be performed, so that a hash value can be obtained. After the fuzzy hash value is obtained, the initiator's stored identification private key can be used to perform an SM2 signature calculation on the current time, a random number, and the fuzzy hash value of the device behavior fingerprint or biometric fingerprint, so that the initiator's signature can be generated. The initiator can use the same quantum key as the verifier to encrypt the identification ID, the accompanying public key, the fuzzy hash value, and the generated signature, so that the ciphertext can be obtained. After the initiator generates the ciphertext, the initiator can send the ciphertext to the verifier. The verifier can receive the ciphertext sent by the initiator and decrypt it. After decryption is completed, the decrypted information can be verified multiple times, and the corresponding verification result can be returned. After successful verification, a verification success result can be returned. In the case of unsuccessful verification, a manual review or locking state can be entered.

[0035] In an embodiment of the present application, as shown in Figure 3 the flow of verifying the fuzzy hash value can include: In step S12, the verifier receives the ciphertext and decrypts the ciphertext using the same quantum key to obtain the corresponding identification ID, accompanying public key, fuzzy hash value, and generated signature.

[0036] In step S13, the verifier performs a fuzzy hash calculation according to the corresponding device behavior fingerprint or biometric fingerprint stored by the verifier to obtain the fuzzy hash value of the verifier side: , wherein, represents the hash value of the verifier side, represents the corresponding device behavior fingerprint and biometric fingerprint stored by the verifier.

[0037] In step S14, the similarity is calculated according to the obtained fuzzy hash value of the initiator and the fuzzy hash value of the verifier: , wherein, represents the similarity of the fuzzy hash value of the initiator and the fuzzy hash value of the verifier.

[0038] In step S15, the similarity is obtained and it is determined whether the similarity is within a set range.

[0039] In step S16, in the case where the similarity is within the set range, it is confirmed that the fuzzy hash value of the initiator is valid.

[0040] In the present application, when verifying the decrypted information, the verifier can receive the ciphertext sent by the initiator and decrypt the ciphertext using the same quantum key as the initiator, so as to obtain the corresponding identification ID, the accompanying public key, the fuzzy hash value and the generated signature. The verifier can perform fuzzy hash calculation according to the corresponding device behavior fingerprint or biometric fingerprint stored by itself, so as to obtain the fuzzy hash value of the verifier side. After obtaining the fuzzy hash value of the verifier side, the similarity verification can be performed with the real-time fuzzy hash value of the initiator. After obtaining the similarity, it can be judged whether the similarity is within the set range, and in the case that the similarity is within the set range, it can be determined that the real-time fuzzy hash value of the initiator is valid.

[0041] In one embodiment of the present application, as shown in Figure 3 The process of verifying the fuzzy hash value can include: In step S17, in the case that the similarity is not within the allowed range, it is confirmed that the fuzzy hash value of the initiator is invalid, and the device behavior fingerprint or biometric fingerprint is re-collected for fuzzy hash calculation and verification.

[0042] In step S18, in the case that the number of verification failures exceeds the preset threshold, the manual review or locking state is entered.

[0043] In the present application, when verifying the fuzzy hash value, in the case that the similarity is not within the allowed range, it can be indicated that the fuzzy hash value of the initiator is invalid, and the initiator can re-collect the device behavior fingerprint or biometric fingerprint and perform fuzzy hash calculation and verification. In the case that multiple verifications are not passed and the number of verification failures exceeds the preset threshold, the manual review or locking state can be entered.

[0044] In one embodiment of the present application, as shown in Figure 4 The first process of verifying the signature can include: In step S19, the valid fuzzy hash value of the initiator, and the identification ID and the accompanying public key are obtained.

[0045] In step S20, the identification public key of the initiator is solved according to the identification ID, the accompanying public key and the stored public key matrix.

[0046] In step S21, the solved identification public key of the initiator and the valid fuzzy hash value of the initiator are obtained to verify the signature of the initiator, and the corresponding verification result is returned.

[0047] In the present application, when verifying the signature of the initiator, the valid initiator's blurring hash value and the identification ID and the accompanying public key can be obtained. According to the identification ID, the accompanying public key and the public key matrix stored by the verifier, the identification public key of the initiator can be solved. According to the identification public key of the initiator solved and the aforementioned valid initiator's blurring hash value verified, the signature of the initiator can be verified, and the corresponding verification result can be returned. In the case of successful verification of the signature of the initiator, it can be confirmed that the verification is successful, and in the case of unsuccessful verification, it can be confirmed that the verification is unsuccessful.

[0048] In one embodiment of the present application, as shown in Figure 5 The second flow of verifying the signature can include: In step S22, the corresponding verifier's signature is generated according to the identification public key blurring hash value obtained by decryption, using the same signature construction method as before.

[0049] In step S23, it is verified whether the verifier's signature and the decrypted initiator's signature obtained are consistent.

[0050] In step S24, in the case where the verifier's signature and the decrypted initiator's signature obtained are consistent, it is confirmed that the initiator's signature is valid, and it is determined that the authentication is successful.

[0051] In step S25, in the case where the verifier's signature and the decrypted initiator's signature obtained are consistent, it is confirmed that the initiator's signature is invalid, and it enters the manual review or lock state.

[0052] In the present application, when verifying the signature of the verifier, it can be verified whether the verifier's signature and the decrypted initiator's signature obtained are consistent. In the case where the verifier's signature and the decrypted initiator's signature obtained are consistent, it can be confirmed that the initiator's signature is valid, so that it can be determined that the initiator's authentication is successful. In the case where the verifier's signature and the decrypted initiator's signature obtained are inconsistent, it can be confirmed that the initiator's signature is invalid, and it can enter the manual review or lock state.

[0053] In the present application, as shown in Figure 6 The flow of zero trust monitoring can include: In step S26, the identity of all users and devices is authenticated to ensure its true identity.

[0054] In step S27, access control is performed on all users and devices, and only allows them to access the resources they need.

[0055] In step S28, all users and devices are monitored in real time to timely discover and prevent abnormal behavior.

[0056] In step S29, a risk assessment is performed for all users and devices, and dynamic authorization is performed according to their security status and access behavior.

[0057] Zero Trust is a network security philosophy that emphasizes strict control and real-time monitoring of identity authentication in network environments, treating all users and devices as potential security threats regardless of whether they are inside or outside the enterprise network. In a Zero Trust system, any user or device connecting to enterprise resources must undergo a multi-level security policy review and identity verification process before accessing sensitive data or network resources. This invention establishes a trusted identity for power terminal devices based on identity keys, implements quantum-resistant identity authentication for SM2, and obtains authorization and access control for business. The core principle of the Zero Trust security model can be summarized as "never trust, always verify." The traditional security model is a border-based trust model, which establishes a secure boundary within the enterprise, and internal users and devices are trusted, while external users and devices are considered untrusted. However, with the advent of cloud computing and mobile office technologies, there is no clear boundary between the inside and outside of the enterprise, making it difficult for the traditional security model to ensure enterprise security. The Zero Trust model reduces the scope of trust to the minimum and no longer defaults to trust internal users and devices, but always authenticates and authorizes all users and devices. Therefore, in this application, during Zero Trust monitoring, identity authentication can be performed on all users and devices to ensure their true identity. Access control can be performed on all users and devices to allow them to access only the resources they need. Real-time monitoring can be performed on all users and devices to detect and prevent abnormal behavior in a timely manner. Risk assessment can be performed on all users and devices to dynamically authorize them based on their security status and access behavior. Its working principles: Principle of least privilege: only grant users and devices the minimum permissions to access the resources they need. Whether internal or external users and devices, they need to be authenticated and authorized to access enterprise resources. Real-time monitoring principle: real-time monitoring of all users and devices to detect and prevent abnormal behavior in a timely manner. Real-time monitoring of user and device access behavior is required to detect and prevent unauthorized access in a timely manner. Security verification principle: requires identity authentication and access control for all users and devices to ensure their true identity and only allow them to access the resources they need. The identity of users and devices needs to be verified and their access behavior needs to be authorized. Dynamic authorization principle: dynamically authorize users and devices based on their security status and access behavior to ensure that only qualified users and devices can access enterprise resources. Risk assessment principle: risk assessment of all users and devices based on their security status and access behavior for dynamic authorization. Enterprises need to assess the risk of users and devices based on their security status and access behavior for authorization.Based on the above zero trust concept, the zero trust concept is integrated into the established new power system communication architecture, and the zero trust principle is used for management and control in identity authentication, access control, etc. Specifically, for identity authentication, whether it is an internal or external user and device, before attempting to access the power business system resources, identity authentication through the zero trust control platform is required. Multi-factor authentication (MFA) is used to improve security, such as combining passwords, biometric identification (fingerprint, facial recognition), and hardware tokens. For access control, including role-based access control (RBAC): assign access permissions according to user roles to ensure that users can only access resources within their scope of responsibility; policy-based access control (ABAC): combine user attributes, environmental conditions, and resource attributes, etc. Dynamic factors for more granular access control; least privilege principle: each user and device is only granted the minimum permissions required to complete the task, reducing potential security risks.

[0058] On the other hand, the present application can also provide an anti-quantum identity authentication system for new power system terminal communication, comprising: A power system construction module for establishing a new power system communication architecture; An anti-quantum identity authentication module for information transmission of each end in the new power system communication architecture based on anti-quantum attack resistant identity authentication; A zero trust security architecture module for controlling and monitoring information transmission of each end based on quantum key zero trust.

[0059] Through the above technical solution, the anti-quantum identity authentication method and system for new power system terminal communication provided by the present application can establish a new power system communication architecture, and then perform information transmission of each end in the new power system communication architecture based on anti-quantum attack resistant identity authentication. In the case of passing the identity authentication of each end, the subsequent information transmission of the end can be performed, and in the process of identity authentication and information transmission, the information transmission of each end is controlled and monitored based on quantum key zero trust. The anti-quantum identity authentication method can be based on anti-quantum identity authentication to avoid attacks on the new power system in subsequent communication processes, and can cope with the security risks faced by new power communication access and transmission scenarios.

[0060] Those skilled in the art will appreciate that embodiments of the present application can be readily used as software, hardware, or a combination of software and hardware. In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0061] The present application is described in reference to the flowchart illustrations and / or block diagrams according to the embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing system, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0062] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0063] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0064] In one typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0065] The memory can include non-persistent memory, random access memory (RAM), and / or non-volatile memory, such as read only memory (ROM) or flash memory, among others. The memory is an example of computer-readable media.

[0066] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0067] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed, or further includes elements inherent in such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.

[0068] The above only is an embodiment of the present application, and is not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of claims of the present application.

Claims

1. A quantum-resistant authentication method for terminal communication in novel power systems, characterized in that, The quantum-resistant identity authentication method includes: Establish a new power system communication architecture; Information transmission at each end of the novel power system communication architecture is based on quantum-resistant authentication. Zero-trust quantum key distribution controls and monitors information transmission at each endpoint.

2. The quantum-resistant identity authentication method according to claim 1, characterized in that, The new power system communication architecture includes a backbone communication network and a terminal access communication network. The backbone communication network includes an application layer and a platform layer. The application layer is configured with corresponding business applications, including power transmission business applications, substation business applications, power distribution business applications, and new business applications. The platform layer is configured with a cloud platform, an IoT management platform, and an enterprise middleware. The terminal access communication network includes a network layer and a perception layer. The perception layer includes data acquisition terminals corresponding to various services.

3. The quantum-resistant identity authentication method according to claim 1, characterized in that, Information transmission in various components of the novel power system communication architecture based on quantum attack-resistant identity authentication includes: Based on the quantum key distribution scheme, the initiator and verifier of identity authentication jointly verify and obtain the same quantum key: The initiator generates and securely stores the identifier private key, and generates the corresponding public key and accompanying public key according to the system rules. The verifier stores the public key matrix. The initiator generates random numbers using a quantum random number generator and simultaneously collects its own device behavior fingerprint or biometric fingerprint. The initiator performs fuzzy hash calculations on the collected device behavior fingerprints or biometric fingerprints to obtain fuzzy hash values: , in, For fuzzy hash functions, For fuzzy hash values, , These are device behavior fingerprints and biometric fingerprints, respectively. The stored identifier private key is used to perform an SM2 signature calculation on the current time, a random number, and a fuzzy hash value of the device behavior fingerprint or biometric fingerprint to generate a signature; The initiator uses the same quantum key as the verifier to encrypt its identifier ID, accompanying public key, fuzzy hash value, and generated signature to obtain ciphertext; The initiator sends the ciphertext to the verifier; The verifier receives the ciphertext sent by the initiator, decrypts it, performs multiple verifications, and returns the corresponding verification result.

4. The quantum-resistant identity authentication method according to claim 3, characterized in that, The verifier receives the ciphertext sent by the initiator, decrypts it, performs multiple verifications, and returns the corresponding verification results, including: The verifier receives the ciphertext and decrypts it using the same quantum key to obtain the corresponding identifier ID, accompanying public key, fuzzy hash value, and generated signature; The verifier performs a fuzzy hash calculation based on its stored device behavior fingerprint or biometric fingerprint to obtain the verifier's fuzzy hash value: , in, This indicates that the hash value of this side is being verified. This indicates the corresponding device behavior fingerprint and biometric fingerprint stored by the verifier. Calculate the similarity based on the fuzzy hash values ​​of the initiator and the validator: , in, This indicates the similarity between the fuzzy hash values ​​of the initiator and the fuzzy hash values ​​of the verifier. Obtain the similarity score and determine whether the similarity score is within a set range; If the similarity is within a set range, the fuzzy hash value of the initiator is confirmed to be valid.

5. The quantum-resistant identity authentication method according to claim 4, characterized in that, The verifier receives the ciphertext sent by the initiator, performs multiple verifications, and returns the corresponding verification results, including: If the similarity is not within the allowed range, the fuzzy hash value of the initiator is confirmed to be invalid, and the device behavior fingerprint or biometric fingerprint is re-collected, fuzzy hash calculation is performed, and verification is performed. If the number of verification failures exceeds a preset threshold, the system will enter a manual review or lock out its status.

6. The quantum-resistant identity authentication method according to claim 4, characterized in that, The verifier receives the ciphertext sent by the initiator, performs multiple verifications, and returns the corresponding verification results, including: Obtain a valid fuzzy hash value of the initiator, as well as the identifier ID and accompanying public key; The initiator's identifier public key is calculated based on the identifier ID, the accompanying public key, and the stored public key matrix. Obtain the public key of the initiator obtained from the solution and the valid fuzzy hash value of the initiator to verify the signature of the initiator, and return the corresponding verification result.

7. The quantum-resistant identity authentication method according to claim 6, characterized in that, The verifier receives the ciphertext sent by the initiator, performs multiple verifications, and returns the corresponding verification results, including: Based on the fuzzy hash value of the identifier public key obtained through decryption, the corresponding verifier's signature is generated using the same signature construction method as described above; Verify whether the signature of the verifier matches the signature of the initiator obtained through decryption; If the verifier's signature matches the initiator's signature obtained through decryption, the initiator's signature is confirmed to be valid, and the authentication is confirmed to be successful. If the verifier's signature matches the initiator's signature obtained through decryption, the initiator's signature is deemed invalid, and the process enters a manual review or lockout state.

8. The quantum-resistant identity authentication method according to claim 1, characterized in that, Zero-trust quantum key distribution enables control and monitoring of information transmission at each endpoint, including: All users and devices are authenticated to ensure their true identities; Implement access control for all users and devices, allowing them to access only the resources they need; Real-time monitoring of all users and devices to promptly detect and prevent abnormal behavior; Conduct risk assessments on all users and devices, and dynamically authorize access based on their security status and access behavior.

9. A quantum-resistant identity authentication system for terminal communication in a novel power system, characterized in that, The quantum-resistant identity authentication system includes: Power system construction module, used to establish new power system communication architecture; A quantum-resistant identity authentication module is used for information transmission at each end of the novel power system communication architecture based on quantum-resistant identity authentication. The zero-trust security architecture module controls and monitors information transmission at each end based on quantum key distribution.