Quantum key encryption communication system and method for gas station

By using a quantum key encryption communication system, symmetric session keys and protection keys are generated and dynamically managed, solving the problems of network attacks on gas stations and the security vulnerabilities of traditional encryption systems. This enables end-to-end high-strength encrypted communication and improves the security of gas automation systems.

CN121333760APending Publication Date: 2026-01-13NINGBO YOUPU INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511671799.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-14
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Data communication and remote control systems at gas stations face the risk of cyberattacks. Traditional encryption methods are easily leaked and tampered with, and there are security vulnerabilities in key generation, management and distribution, leading to the risk of information leakage and control command failure.

Method used

A quantum key encryption communication system is adopted. A symmetric session key is generated and invalidated through a key generation and management unit. A protection key is generated in combination with a quantum random number generator to achieve secure key distribution and dynamic scheduling. The true randomness and non-cloning properties of quantum keys ensure the security of the key throughout its entire life cycle.

Benefits of technology

It effectively prevents man-in-the-middle attacks and replay attacks, builds a high-strength encrypted communication channel, ensures end-to-end secure transmission of control commands and monitoring data at gas stations, and improves the level of communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333760A_ABST
    Figure CN121333760A_ABST
Patent Text Reader

Abstract

The invention provides a quantum key encryption communication system and method for a gas station, and the system comprises a main station side gateway, a station side CPE, and a key management system. The key management system comprises a key generation management unit, a random number generator group, a key service platform, two exchange cipher machines and two key charging modules. The key generation management unit is used for generating symmetric session keys, and the symmetric session keys are correspondingly stored in the two exchange cipher machines and are cancelled after being used; the random number generator group is used for generating two groups of protection keys carrying unique key identifiers, and the two groups of protection keys are correspondingly stored in the two exchange cipher machines; the two key charging modules are used for charging the two groups of protection keys to the gateway and the CPE respectively; and the key service platform is used for instructing the two exchange cipher machines to encrypt the session key through the protection key and respectively sending the encrypted session key to the gateway and the CPE. According to the system provided by the invention, the end-to-end communication security of the gas field station is ensured through secure key distribution and dynamic scheduling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to the field of interdisciplinary technology of smart gas and information security, and specifically to a quantum key encryption communication system and method for gas stations. Background Technology

[0002] Currently, the urban gas industry is accelerating its transformation towards automation, informatization, and intelligence. Remote control systems at the station level are being widely deployed, involving SCADA systems, RTU / PLC equipment, gas IoT platforms, and dispatch command systems. Gas stations, including gate stations, pressure regulating stations, LNG storage and distribution stations, and metering stations, are the core links in the production and operation of urban gas companies and are crucial to urban gas supply. They are numerous and diverse; any data transmission or communication anomalies or control command failures can severely impact urban gas supply and even lead to gas leaks, explosions, and other accidents. Various terminal devices at gas stations mainly connect to the power distribution automation system via fiber optics and wireless networks. With the increasing sophistication of network attack methods, security risks such as information leakage, tampering, and bypass control are rising, exposing the numerous and widely distributed urban gas systems to network attack risks from both public and private networks.

[0003] Current security measures primarily focus on the centralized hardware and software deployment of the main station system, while security measures for numerous, widely distributed, and open business terminals and communication terminals are relatively weak. Data communication and remote control at existing gas stations mainly rely on dedicated lines, 4G / 5G wireless networks, or VPNs. Information security protection generally uses encryption methods based on communication technology, with traditional encryption methods (such as asymmetric encryption algorithms and TLS / IPSec protocols) used for critical data. To enhance security, some systems employ hardware and software cryptographic machines and national cryptographic algorithms to strengthen key storage and command encryption. However, security vulnerabilities such as interception, tampering, replay, and brute-force attacks still exist throughout the entire lifecycle of key generation, management, distribution, and application. Summary of the Invention

[0004] In view of the above-mentioned defects or deficiencies in the prior art, it is desirable to provide a quantum key encryption communication system and method for gas stations to solve the above problems.

[0005] The first aspect of this application provides a quantum key encryption communication system for gas stations, including a master station-side gateway, a station-side CPE, and a key management system; the key management system includes a key generation management unit, a random number generator group, a key service platform, two cryptographic exchange machines, and two key filling modules; The key generation and management unit is used to generate symmetric session keys, which are stored in the two exchange cryptographic machines respectively and are invalidated after use. These symmetric session keys are used to encrypt and decrypt control commands and monitoring data. The random number generator group is used to generate two sets of protection keys carrying unique key identifiers, and the two sets of protection keys are stored in the two exchange cryptographic machines respectively. The two key injection modules are used to inject the two sets of protection keys into the gateway and CPE respectively; The key service platform is used to receive key requests from the gateway and CPE, and issue corresponding key identifiers accordingly, so that the two exchange cryptographic machines can encrypt the session key with the corresponding protection key and send it to the gateway and CPE respectively.

[0006] According to the technical solution provided in the embodiments of this application, the key generation management unit includes a key management module and a quantum key generation terminal. The quantum key generation terminal generates the symmetric session key based on BB84 or coherent state coding protocol. The key management module is used to assign an identifier to the session key, control the storage of the session key, mark the usage status of the session key, and invalidate the session key and trigger the generation of a new session key under predetermined conditions.

[0007] According to the technical solution provided in the embodiments of this application, the random number generator group includes a first quantum random number generator and a second quantum random number generator. The first quantum random number generator is connected to one of the exchange cryptographic machines and is used to generate a set of protection keys and store them in the corresponding exchange cryptographic machine. The second quantum random number generator is connected to another exchange cryptographic machine and is used to store another set of protection keys in the corresponding exchange cryptographic machine.

[0008] A second aspect of this application provides a quantum key encryption communication method for gas stations, applied to the system described above, the method comprising: The two sets of protection keys are stored in the two cryptographic exchange machines, and the two sets of protection keys are respectively fed into the gateway and the CPE; Generate the symmetric session key and store the symmetric session key in the two exchange cryptographic machines respectively; Receive key requests sent by the gateway and CPE; In response to the key request, a key identifier corresponding to the protection key is sent to the gateway, CPE and the corresponding cryptographic exchange machine; Perform a transmission operation; the transmission operation is to instruct the two exchange cryptographic machines to encrypt the paired session key using the protection key corresponding to the key identifier, and then forward the encrypted paired session key to the gateway and CPE respectively.

[0009] According to the technical solution provided in the embodiments of this application, the method further includes: Monitor the first signal fed back by the gateway and CPE, and trigger the invalidation of the current paired session key based on the first signal; the first signal is the session key usage completion signal.

[0010] According to the technical solution provided in the embodiments of this application, after issuing the key identifier corresponding to the protection key to the gateway, CPE and the corresponding cryptographic exchange machine, the method further includes: Monitor the second signal fed back by the gateway and CPE within the first set time period. The second signal is a key identification signal indicating successful reception. If the second signal is not received from either the gateway or the CPE, a first retransmission operation is performed, and the first retransmission count is accumulated. The first retransmission count is the number of times the first retransmission operation is performed, and the first retransmission operation is to resend the unreceived key identifier to the party that did not send back the first signal. If the first retransmission count is greater than or equal to the first preset threshold, then the transmission operation is performed; Monitor the third signal fed back by the gateway and CPE within the second set time period, the third signal being a session key reception success signal; If the third signal is received from both parties, a first fault signal is generated to indicate that the first signal has a fault.

[0011] According to the technical solution provided in the embodiments of this application, after monitoring the second signal fed back by the gateway and CPE within a first set time period, the method further includes: If the second signal is received from both parties, the transmission operation is executed directly. If the third signal is not received from either the gateway or the CPE within the second set time period, the current symmetric session key is invalidated and a new symmetric session key is generated, and a second retransmission operation is performed; the second retransmission operation is to resend the new key identifier corresponding to the protection key to the gateway, the CPE and the corresponding cryptographic exchange machine.

[0012] According to the technical solution provided in the embodiments of this application, after monitoring the third signal fed back by the gateway and CPE within the second set time period, the method further includes: If no third signal is received from either the gateway or the CPE, a second fault signal is generated to indicate a key identification transmission channel failure.

[0013] According to the technical solution provided in the embodiments of this application, the method further includes: The cumulative number of second retransmissions within the third set time period, where the second retransmission count is the number of times the second retransmission operation is executed; If the second retransmission count is greater than or equal to the second set threshold, the instruction is to recharge the protection key to the party that has not fed back the third signal.

[0014] According to the technical solution provided in the embodiments of this application, after storing the two sets of protection keys into the two cryptographic exchange machines and respectively filling the two sets of protection keys into the gateway and CPE, the method further includes... If the preset update cycle is reached, the instruction regenerates the two sets of protection keys and stores them in the two exchange cryptographic machines accordingly; The two newly generated protection keys are respectively fed into the gateway and the CPE.

[0015] Compared with existing technologies, the advantages of this application are as follows: A symmetric session key that expires after use is generated by a key generation management unit, and a protection key generated by a quantum random number generator is combined with the key to achieve secure distribution and dynamic scheduling of the key via a key service platform and a cryptographic exchange machine. This effectively solves the problems of easy leakage and tampering of keys in traditional encryption systems. The system utilizes the true randomness and non-cloning properties of quantum keys to ensure the security of the key throughout its entire lifecycle of generation, distribution, and application, preventing threats such as man-in-the-middle attacks and replay attacks. Simultaneously, through the collaborative work of the main station-side gateway and the station-side CPE, a high-strength encrypted communication channel is constructed, ensuring end-to-end secure transmission of gas station control commands and monitoring data, and improving the communication security level of the gas automation system. Attached Figure Description

[0016] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 A schematic diagram of the quantum key encryption communication system for gas stations provided in Example 1; Figure 2 The flowchart illustrates the steps of the quantum key encryption communication method for gas stations provided in Example 2.

[0017] Reference numerals: 100, Gateway; 200, CPE; 301, Key Management Module; 302, First Key Generation Terminal; 303, Second Key Generation Terminal; 304, First Quantum Random Number Generator; 305, Second Quantum Random Number Generator; 306, First Exchange Cryptography Machine; 307, Second Exchange Cryptography Machine; 308, First Filling Module; 309, Second Filling Module; 310, Key Service Platform. Detailed Implementation

[0018] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0019] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0020] Example 1 Please refer to Figure 1 This embodiment provides a quantum key encryption communication system for gas stations, including a master station gateway 100, a station-side CPE 200, and a key management system; the key management system includes a key generation management unit, a random number generator group, a key service platform 310, two cryptographic exchange machines, and two key filling modules; The key generation and management unit is used to generate symmetric session keys, which are stored in the two exchange cryptographic machines respectively and are invalidated after use. These symmetric session keys are used to encrypt and decrypt control commands and monitoring data. The random number generator group is used to generate two sets of protection keys carrying unique key identifiers, and the two sets of protection keys are stored in the two exchange cryptographic machines respectively. The two key filling modules are used to fill the two sets of protection keys into the gateway 100 and CPE200 respectively; The key service platform 310 is used to receive key requests from the gateway 100 and CPE200, and issue corresponding key identifiers accordingly, so that the two exchange cryptographic machines can encrypt the session key with the corresponding protection key and send it to the gateway 100 and CPE200 respectively.

[0021] The quantum key encryption communication system provided in this embodiment is applied to communication encryption between the gas station and gas yard sides. It is mainly divided into a key generation subsystem, a key management subsystem, and a key application subsystem. The key generation and key management subsystems are executed by the key management system. The key application subsystem includes a gateway 100 and a CPE 200, which establish a communication connection via an IP network. This connection is used for the master station to send control commands to the gas yard side, and for the gas yard side to send monitoring data back to the master station side. Gateway 100 is a quantum-secure gateway deployed at the network boundary of the master station, serving as the centralized security gateway for all business data entering and leaving the master station. CPE 200 is a quantum-secure CPE (Customer Premises Equipment) deployed at each gas yard site, serving as the access gateway for all terminal devices (such as RTUs, PLCs, sensors, etc.) at that gas yard. Gateway 100 and CPE 200 together constitute... As a core security infrastructure, the key management system typically has its components deployed in a secure computer room on the main station side. It is used to encrypt control commands and monitoring data used in communication between the main station and the field station. The system consists of a key generation management unit, a random number generator group, a key service platform 310, two cryptographic exchange machines, and two key filling modules.

[0022] Specifically, such as Figure 1 As shown, the two cryptographic exchange machines are the first cryptographic exchange machine 306 and the second cryptographic exchange machine 307, which serve as the core key operation and storage units of the system and are the core devices for performing key encapsulation. In this embodiment, the first cryptographic exchange machine 306 is configured to be associated with the gateway 100, and the second cryptographic exchange machine 307 is configured to be associated with the CPE 200. The two key filling modules are the first filling module 308 and the second filling module 309, which serve as the medium for key filling and are used for key initialization of offline or edge nodes. In this embodiment, the first filling module 308 is configured to be associated with the gateway 100, and the second filling module 309 is configured to be associated with the CPE 200. Optionally, the first filling module 308 and the second filling module 309 can be a USB key, a TF card, or a trusted chip.

[0023] Furthermore, the key generation management unit includes a key management module 301 and a quantum key generation terminal. The quantum key generation terminal generates the symmetric session key based on BB84 or coherent state coding protocol. The key management module 301 is used to assign an identifier to the session key, control the storage of the session key, mark the usage status of the session key, and invalidate the session key and trigger the generation of a new session key under predetermined conditions.

[0024] Specifically, such as Figure 1As shown, the quantum key generation terminal includes a first key generation terminal 302 and a second key generation terminal 303. Both generate truly random symmetric session keys with information-theoretic security based on the BB84 protocol or a coherent state coding protocol. It should be noted that the symmetric session keys are two identical keys: one is used by the gateway 100 to encrypt data using the national cryptographic algorithm SM4, and the other is used by the CPE200 to decrypt data using the same algorithm. After generation, the symmetric session keys are not directly sent to the gateway 100 and CPE200, but are securely and correspondingly stored in the first and second cryptographic exchange machines 306 and 307. In this embodiment, the first key generation terminal 302 is associated with the first cryptographic exchange machine 306, responsible for generating and providing the session key to it; the second key generation terminal 303 is associated with the second cryptographic exchange machine 307, responsible for generating and providing the same session key to it, thereby ensuring that the session keys held by the master station and the field station are completely consistent.

[0025] The key management module 301 is the core control center of the key generation management unit. It is communicatively connected to the first key generation terminal 302, the second key generation terminal 303, the first exchange cipher machine 306, and the second exchange cipher machine 307, and is responsible for the full lifecycle management of symmetric session keys. The key management module 301 includes several functions. Firstly, it is configured to assign a unique identifier to each newly generated symmetric session key, which is used to accurately index the corresponding session key during subsequent scheduling, distribution, and use. Secondly, the session keys generated by the instruction are securely and synchronously stored in designated storage areas of the first exchange cipher machine 306 and the second exchange cipher machine 307. Thirdly, it is configured to dynamically maintain and update the status of each session key, such as "unused," "used," or "invalid." Once a session key is successfully used in a communication, its status is updated immediately. The fourth aspect is configured so that when predetermined conditions are met (e.g., a communication session ends, the key expires, or the system detects a security risk), the key management module 301 will immediately mark the currently used session key as "invalid" and simultaneously trigger the first key generation terminal 302 and the second key generation terminal 303 to collaboratively generate a new pair of symmetric session keys to start a new round of key distribution process.

[0026] Furthermore, the random number generator group includes a first quantum random number generator 304 and a second quantum random number generator 305. The first quantum random number generator 304 is connected to one of the exchange cryptographic machines and is used to generate a set of protection keys and store them in the corresponding exchange cryptographic machine. The second quantum random number generator 305 is connected to another of the exchange cryptographic machines and is used to store another set of protection keys in the corresponding exchange cryptographic machine. Specifically, such as Figure 1 As shown, the random number generator group consists of two independent physical devices: a first quantum random number generator 304 and a second quantum random number generator 305. In this embodiment, the first quantum random number generator 304 establishes an independent connection with the first exchange cipher machine 306 via a secure communication link. Its core function is to generate several protection keys with true randomness and unpredictability using quantum physical processes. Each protection key carries a unique key identifier, and the several protection keys generated by the first quantum random number generator 304 form a first protection key group. After obtaining the first protection key group, the first protection key is transmitted and stored in the protected storage area inside the first exchange cipher machine 306.

[0027] Similarly, the second quantum random number generator 305 also establishes another independent connection with the second exchange cipher machine 307 through a separate secure communication link. It independently generates several protection keys that are completely unrelated to the first protection key set, and forms a second protection key set. After obtaining the second protection key set, it transmits and securely stores the second protection key set in the protected storage area inside the second exchange cipher machine 307.

[0028] It should be noted that each protection key in the first and second protection key sets has a different key identifier. These protection keys are used to encrypt and decrypt the session key transmission, thus ensuring the security of the session key transmission. By using two independent quantum random number generators, the statistical independence and uncorrelatedness of the two protection key sets are guaranteed. This ensures that even if one set is compromised, no information from the other set will be leaked, greatly enhancing the overall robustness of the system.

[0029] The key service platform 310, acting as the system's control and scheduling center, receives session key requests from gateway 100 and CPE200. Instead of directly distributing the key itself, it issues a key identifier for this session to both requesting parties and their corresponding cryptographic exchange machines. This key identifier instructs the exchange machines to encrypt the session key using a specific protection key, and also instructs gateway 100 and CPE200 to decrypt the session key using the same protection key.

[0030] According to the functional division, the key management module 301, the first key generation terminal 302, the second key generation terminal 303, the first quantum random number generator 304, and the second quantum random number generator 305 constitute the key generation subsystem; the first exchange cipher machine 306, the second exchange cipher machine 307, the first filling module 308, the second filling module 309, and the key service platform 310 constitute the key scheduling subsystem.

[0031] The system provided in this embodiment includes a preparation process and an application process. Preparation Process: Before the system starts running, initialization is required. First, a first protection key set is generated by the first quantum random number generator 304 and transmitted to the first cipher machine 306 for storage. Simultaneously, a second protection key set is generated by the second quantum random number generator 305 and transmitted to the second cipher machine 307 for storage. Next, the first protection key set is injected into the gateway 100 by the first injection module 308, so that both the gateway 100 and the first cipher machine 306 store the first protection key set. At the same time, the second protection key set is injected into the CPE 200 by the second injection module 309, so that both the CPE 200 and the second cipher machine 307 store the second protection key set.

[0032] Application Process: Gateway 100 and CPE 200 synchronously send key requests to the key service platform 310 at set time intervals. Upon receiving a key request, the key service platform 310 sends an identical key identifier to both the first cryptographic exchange 306 and gateway 100, and another identical key identifier to both the second cryptographic exchange 307 and CPE 200. Upon receiving the key identifier, the first cryptographic exchange 306 encrypts the session key using the corresponding protection key and transmits the encrypted session key to gateway 100. Simultaneously, the second cryptographic exchange 307, upon receiving the key identifier, encrypts the session key using the corresponding protection key and transmits the encrypted session key to CPE 200. When gateway 100 receives the encrypted session key, it decrypts the session key using the protection key with the same key identifier as the first cryptographic exchange 306, thus obtaining the session key. Simultaneously, CPE 200 decrypts the session key using the protection key with the same key identifier as the second cryptographic exchange 307, thus obtaining the same session key as gateway 100. After both Gateway 100 and CPE200 obtain the session key, encrypted communication can begin between them. For example, Gateway 100 encrypts control commands using the session key and the national cryptographic SM4 algorithm, and transmits the encrypted control commands to CPE200. CPE200 then decrypts the control commands using the session key and the national cryptographic SM4 algorithm. Alternatively, CPE200 encrypts monitoring data using the session key and the national cryptographic SM4 algorithm, and transmits the encrypted monitoring data to Gateway 100. Gateway 100 then decrypts the monitoring data using the session key and the national cryptographic SM4 algorithm, thereby achieving "one-time key" encrypted communication between the main station and the field station.

[0033] Example 2 Based on the above embodiment 1, and referring to Figure 2This embodiment provides a quantum key encryption communication method for gas stations, applied to the system described in Embodiment 1. The method includes: S1: Store the two sets of protection keys into the two exchange cryptographic machines, and charge the two sets of protection keys into the gateway 100 and CPE200 respectively; S2: Generate the symmetric session key and store the symmetric session key in the two exchange cryptographic machines respectively; S3: Receive the key request sent by the gateway 100 and CPE200; S4: In response to the key request, send the key identifier corresponding to the protection key to the gateway 100, CPE200 and the corresponding cryptographic exchange machine; S5: Execute a transmission operation; the transmission operation is to instruct the two exchange cryptographic machines to encrypt the paired session key using the protection key corresponding to the key identifier, and forward the encrypted paired session key to the gateway 100 and CPE200 respectively.

[0034] Specifically, the method provided in this embodiment is applied to the system described in Embodiment 1, and its complete process can be divided into a system initialization stage and a dynamic encrypted communication stage.

[0035] The first stage is the system initialization phase, which involves preparatory work before the system runs. This phase specifically includes steps S1 and S2: Step S1 corresponds to the collaborative operation of the random number generator group and the key filling module in Embodiment 1. Specifically, the first quantum random number generator 304 generates a first protection key set, which contains, for example, 100 independent protection keys, each carrying a unique key identifier (such as identifier 1 to 100), and securely stores the key set in the first exchange cipher machine 306; simultaneously, the second quantum random number generator 305 independently generates a second protection key set, which also contains, for example, 100 independent protection keys, each carrying a unique key identifier (such as identifier 101 to 200), and securely stores the key set in the second exchange cipher machine 307. Subsequently, the first filling module 308 completely fills the first protection key set (including identifiers 1-100) into the local security hardware of the main station-side gateway 100; the second filling module 309 completely fills the second protection key set (including identifiers 101-200) into the local security hardware of the site-side CPE 200. At this point, Gateway 100 and CPE200 physically possess the complete static root keystore used for decrypting session keys.

[0036] Step S2 corresponds to the function of the key generation management unit described in Embodiment 1. The first key generation terminal 302 and the second key generation terminal 303 generate symmetric session keys with information-theoretic security based on BB84 or coherent state coding protocols. The key management module 301 assigns a unique identifier (e.g., SK_001) to this session key and controls its synchronous and corresponding storage in the first and second exchange cryptographic machines 306 and 307, awaiting scheduling and use. This step ensures that the session key source used by both communicating parties in the future is consistent, preparing data for dynamic encrypted communication.

[0037] The second phase is the dynamic encrypted communication phase. After initialization, the system enters the dynamic encrypted communication phase, which can be triggered on demand, to achieve secure communication with "one-time key" encryption. This phase includes steps S3 to S5: In step S3, according to a set time interval or triggered by a service (when the master station needs to send control commands to the field station, or when the field station needs to upload monitoring data to the master station), the gateway 100 and CPE200 deployed at both ends of the communication will simultaneously send session key requests to the key service platform 310.

[0038] In step S4, the key service platform 310 responds to the key requests received from the gateway 100 and CPE 200. Instead of directly distributing the sensitive session key itself, it selects the protection key for this session from the pre-filled key set according to the scheduling policy. For example, the platform may decide to use the protection key identified as "15" in the first protection key set and the protection key identified as "115" in the second protection key set for this session. Subsequently, the platform sends the protection key identifier "15" to the gateway 100 and the protection key identifier "115" to the CPE 200, while simultaneously informing the corresponding first and second exchange cryptographic machines 306 and 307 of these two identifiers and the session key identifier to be used (SK_001), respectively.

[0039] Step S5 establishes the core of the secure channel, specifically executing the "one-time sealing" mechanism as described in Example 1. Upon receiving the instruction, the first cipher machine 306 uses its locally stored protection key, identified as "15," to encrypt the session key identified as "SK_001," and forwards the encrypted data packet to the gateway 100 via the key service platform 310. Simultaneously, the second cipher machine 307 uses its locally stored protection key, identified as "115," to encrypt the same "SK_001" session key, and forwards the encrypted data packet to the CPE 200 via the key service platform 310. The gateway 100 uses its locally pre-filled protection key, identified as "15," to decrypt the received encrypted data, recovering the session key "SK_001"; the CPE 200 uses its locally pre-filled protection key, identified as "115," to decrypt the received encrypted data, similarly recovering the session key "SK_001." Ultimately, both communicating parties use the same session key "SK_001" and encryption algorithms such as the national standard SM4 algorithm to establish a quantum-secure encrypted channel for the secure transmission of control commands and monitoring data. After this communication ends, the session key "SK_001" is marked as invalid by the key management module 301 and is no longer used.

[0040] It should be noted that in this embodiment, the session key is not invalidated after a session is completed, but rather remains valid within the set time interval between the key requests sent by the gateway 100 and CPE200. The used session key is invalidated only after each new key request is sent.

[0041] Furthermore, the method also includes: The system monitors the first signal fed back by the gateway 100 and CPE200, and triggers the invalidation of the current symmetric session key based on the first signal; the first signal is the session key usage completion signal.

[0042] Building upon the dynamic encrypted communication phase, a secure management mechanism for session keys is added after the communication ends. When gateway 100 and CPE200 complete this secure communication (e.g., continuously setting time intervals) using a session key (e.g., SK_001), the system initiates a key cleanup process.

[0043] Specifically, gateway 100 and CPE200 will locally generate and send a first signal to the upstream key service platform 310. This first signal is a clear signal indicating that the session key has been used up, and its content includes at least the identifier of the session key that has been used up and the identifier of the sender's device.

[0044] The key service platform 310 continuously monitors and receives this first signal from the gateway 100 and CPE 200. Once the key service platform 310 confirms that it has received a signal from both communicating parties indicating completion of use of the same session key, or even if it only receives a signal from one party but determines that the communication has timed out, it immediately issues an instruction to the key management module 301. Upon receiving the instruction, the key management module 301 triggers a key invalidation operation based on this first signal. The core of this operation is to mark the status of the recently used paired session key, identified as "SK_001," in the storage units of the first and second exchange cipher machines 306 as "invalidated." This operation ensures that the session key is immediately invalidated and cannot be reused or intercepted, thus strictly implementing the "one-time key" security principle and effectively preventing replay attacks.

[0045] Furthermore, after step S1, the following steps are also included: If the preset update cycle is reached, the instruction regenerates the two sets of protection keys and stores them in the two exchange cryptographic machines accordingly; The two newly generated protection keys are respectively fed into the gateway 100 and CPE200.

[0046] Specifically, the key service platform 310 or a separate timed management module continuously monitors the system uptime. When a preset update cycle is reached (e.g., every 30 days), the module sends an instruction to the random number generator group, triggering it to regenerate two new sets of protection keys. This process is consistent with the initial generation process of the protection keys in Embodiment 1: the first quantum random number generator 304 regenerates a new first protection key set (e.g., containing 100 new protection keys identified as 201-300) and stores it in the first exchange cipher machine 306; simultaneously, the second quantum random number generator 305 independently regenerates a new second protection key set (e.g., containing 100 new protection keys identified as 301-400) and stores it in the second exchange cipher machine 307.

[0047] After the new protection key set is generated and stored in the cryptographic exchange machine, the system immediately instructs the two key filling modules to perform a refill operation. The first filling module 308 fills the new first protection key set into the local security hardware of the gateway 100, overwriting the old key set. At the same time, the second filling module 309 fills the new second protection key set into the local security hardware of the CPE 200, also overwriting the old key set.

[0048] By periodically changing the root key used for encrypting session keys, even if a protection key has a potential risk of leakage during long-term use, its validity period is strictly limited to the update cycle, thereby greatly enhancing the system's ability to resist long-term latent attacks.

[0049] Example 3 In this embodiment, after step S4, a monitoring and retransmission mechanism is introduced to ensure reliable key distribution. This mechanism consists of the following steps S6-1 to S6-4: It should be noted that steps S6-1 to S6-4 are for illustrative purposes only and are not intended to limit the order of execution of the steps.

[0050] S6-1: Monitor the second signal fed back by the gateway 100 and CPE200 within the first set time period. The second signal is a key identification signal indicating successful reception.

[0051] Specifically, after the key service platform 310 completes step S4, it starts a first timer and begins monitoring the second signal fed back by the gateway 100 and CPE 200 within a first set duration; for example, the first set duration is 3 seconds. The second signal is a key identifier reception success signal, used to confirm that both ends of the communication have successfully received and processed the key identifier instruction issued by the platform.

[0052] S6-2: If the second signal is not received from either the gateway 100 or the CPE 200, a first retransmission operation is performed, and the first retransmission count is accumulated. The first retransmission count is the number of times the first retransmission operation is performed, and the first retransmission operation is to resend the unreceived key identifier to the party that did not send back the first signal. If the first number of retransmissions is greater than or equal to the first set threshold, then the transmission operation is performed.

[0053] Specifically, during the monitoring process in step S6-1, if the second signal is not received from either the gateway 100 or the CPE 200, the key service platform 310 performs a first retransmission operation. This operation refers to retransmitting the key identifier (e.g., protection key identifier "115") that was previously not successfully received to the party that did not respond (e.g., only the CPE 200 did not respond). Simultaneously, the key service platform 310 accumulates the number of first retransmissions.

[0054] The system will determine whether the first retransmission count has reached a first preset threshold, for example, two times. If not, S6-1 and S6-2 will be executed repeatedly until the first preset threshold is reached. If the first retransmission count is greater than or equal to the first preset threshold, it is considered that there may be a one-way failure in the key identification channel. However, to avoid service interruption, the key service platform 310 will no longer wait, but will directly instruct the system to continue executing the subsequent step S5 to attempt to complete the distribution of the session key.

[0055] S6-3: Monitor the third signal fed back by the gateway 100 and CPE200 within the second set time period. The third signal is a session key reception success signal.

[0056] Specifically, after executing step S5, the key service platform 310 starts a second timer and begins monitoring the third signal fed back by the gateway 100 and CPE 200 within a second set time period; for example, the second set time period is 5 seconds. The third signal is a session key reception success signal, used to confirm that both ends of the communication have successfully received and decrypted the session key used in this communication.

[0057] S6-4: If the third signal is received from both parties, a first fault signal is generated to indicate that the first signal has a fault.

[0058] Specifically, after the monitoring cycle in step S6-3 ends, the results are analyzed: If a third signal is received from both Gateway 100 and CPE200: This is a key anomaly criterion. It means that both ends of the communication have successfully obtained the session key, but in the previous steps S6-1 / S6-2, one party failed to confirm the key identifier in a timely manner. At this time, the key service platform 310 will generate a first fault signal. This signal indicates that the second signal feedback path has failed, for example, the confirmation message at one end may be lost, or there may be a delay in the processing unit, requiring maintenance and inspection, but it does not itself block the establishment of this encrypted channel.

[0059] This process significantly improves the robustness of the system in unreliable network environments by setting up acknowledgment and retransmission mechanisms at key nodes in key distribution, and can accurately locate and alarm specific types of faults.

[0060] Example 4 In this embodiment, after step S6-1, the processing sub-processes for two different cases are further refined, including steps S7-1 and S7-2: It should be noted that the steps S7-1 to S7-2 are for illustrative purposes only and are not intended to limit the order of execution.

[0061] S7-1: If the second signal is received from both parties, the transmission operation is executed directly.

[0062] Specifically, during the monitoring period of step S6-1, if the key service platform 310 receives the second signal from both the gateway 100 and the CPE 200, this indicates that the key identifier has been reliably delivered to both ends of the communication. At this time, the system determines that the key identifier distribution phase has been successfully completed, and no retransmission operation is required. The key service platform 310 will directly execute the subsequent step S5, instructing the first exchange cipher machine 306 and the second exchange cipher machine 307 to immediately begin encrypting the session key using the corresponding protection key and sending it respectively.

[0063] S7-2: If the third signal is not received from either the gateway 100 or the CPE200 within the second set time period, the current symmetric session key is invalidated and a new symmetric session key is generated, and a second retransmission operation is performed; the second retransmission operation is to resend the new key identifier corresponding to the protection key to the gateway 100, the CPE200 and the corresponding exchange cryptographic machine.

[0064] Specifically, after executing S7-1 (i.e., directly executing S5), the system enters the monitoring cycle of step S6-3, waiting for the third signal. If no third signal is received from either the gateway 100 or the CPE200 within the second set time period, it means that the encrypted session key may have been lost during transmission, intercepted by an attacker, or the receiver failed to decrypt it.

[0065] At this point, the system will initiate the security recovery process: The key service platform 310 immediately notifies the key management module 301 to mark the currently undelivered symmetric session key (e.g., SK_001) as "invalid" in the first and second exchange cryptographic machines 306 and 307 to prevent it from being exploited by potential attackers. Simultaneously, the key management module 301 triggers the first key generation terminal 302 and the second key generation terminal 303 to collaboratively generate a new pair of symmetric session keys (e.g., SK_002) and synchronously store them in the two exchange cryptographic machines. Finally, the system performs a second retransmission operation. This operation is not a simple retransmission, but rather a complete restart of the key distribution process: the key service platform 310 reissues new key identifiers corresponding to the protection key (e.g., this time selecting protection key identifiers "20" and "120") to the gateway 100, CPE 200, and the corresponding first and second exchange cryptographic machines 306 and 307. The system then re-enters the complete process from issuing the identifier in step S4 to transmitting the key in step S5.

[0066] This mechanism ensures that the system can automatically and securely recover in the event of a session key transmission failure by discarding any potentially leaked keys and enabling a completely new key pair, thus guaranteeing the secure continuity of the communication process.

[0067] Example 5 In this embodiment, after step S6-3, a diagnostic and alarm mechanism is provided for fundamental failures of the key identification transmission channel, including step S8-1: It should be noted that the following steps S8-1 are for illustrative purposes only and are not intended to limit the order of execution of the steps.

[0068] S8-1: If no third signal is received from either the gateway 100 or the CPE200, a second fault signal is generated to indicate a key identification transmission channel failure.

[0069] Specifically, step S8-1 follows step S6-3. Within the second set time period, the key service platform 310 monitors the third signal from the gateway 100 and CPE 200. If no third signal is received from either the gateway 100 or CPE 200: this specific situation needs to be understood in conjunction with the premise in embodiment 3. The premise is that the system has forcibly jumped to step S5 after failing to receive the second signal in step S6-1 and reaching the first retransmission threshold. Therefore, the current fault scenario is: the key service platform 310 has tried to issue the key identifier multiple times, but the gateway 100 or CPE 200 has not confirmed it. Subsequently, the system attempts to directly transmit the encrypted session key, but the recipient also does not confirm it.

[0070] This situation indicates that the failure is not a simple loss of confirmation signal, but rather a serious problem with the key identification transmission channel itself, causing a near-complete interruption of the command path from the key service platform 310 to the gateway 100 or CPE200. The receiving device may not have received the key identification command at all, and therefore will neither send back the second signal nor prepare the correct protection key to decrypt subsequently received session keys.

[0071] At this point, the key service platform 310 will generate a second fault signal. This signal clearly indicates a fault in the key identification transmission channel, prompting maintenance personnel to immediately check the network connection, device status, or interface protocol with the faulty party, because core scheduling commands can no longer be reliably delivered.

[0072] This mechanism complements the first fault signal in Example 3, enabling multi-level fault diagnosis from "abnormal confirmation signal feedback" to "interruption of core instruction transmission channel", providing a more accurate direction for system operation and maintenance.

[0073] Example 6 In this embodiment, based on step S7-2, a monitoring and ultimate recovery mechanism for persistent failures during the key negotiation process is added, including steps S9-1 and S9-2: It should be noted that the following steps S9-1 and S9-2 are for illustrative purposes only and are not intended to limit the order of execution.

[0074] S9-1: Accumulate the number of second retransmissions within the third set time period, where the number of second retransmissions is the number of times the second retransmission operation is executed.

[0075] Specifically, when the system enters step S7-2 and performs a second retransmission operation due to session key reception failure, the key service platform 310 will activate a monitoring mechanism. It will accumulate the number of second retransmissions for a specific faulty party (e.g., CPE 200 that has not continuously returned a third signal) within a third set time period; for example, the third set time period is 10 minutes.

[0076] S9-2: If the second retransmission count is greater than or equal to the second set threshold, the protection key is recharged to the party that has not fed back the third signal.

[0077] Specifically, the key service platform 310 will determine in real time whether the cumulative number of second retransmissions within a third set time period reaches or exceeds a second set threshold; for example, the second set threshold is 3 times. If the number of second retransmissions is less than the second set threshold: the system considers this to be an occasional communication fluctuation and continues to process according to the existing procedure; if the number of second retransmissions is greater than or equal to the second set threshold: this indicates that multiple attempts to negotiate a new key for this device (such as CPE 200) have failed. Based on this, the system determines that the root cause is likely not a temporary network problem, but rather that the device's local protection key has suffered irreparable damage, loss, or synchronization failure.

[0078] At this point, the system will perform an initial recovery operation: the key service platform 310 will generate a high-level instruction, commanding the second refill module 309 to re-obtain the second protection key set from the second exchange cipher machine 307 and refill the protection key to the party that has not fed back the third signal (i.e., CPE 200). This operation aims to fundamentally repair the persistent communication failure caused by abnormal key materials by completely resetting the root key of the device.

[0079] This mechanism provides the system with a complete solution from recovery from temporary failures to dealing with permanent device key failures, ensuring that the system can still restore secure communication capabilities through automated means when faced with complex failure scenarios.

[0080] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A quantum key encryption communication system for gas stations, characterized in that, It includes a main station-side gateway (100), a site-side CPE (200), and a key management system; the key management system includes a key generation management unit, a random number generator group, a key service platform (310), two cryptographic exchange machines, and two key filling modules; The key generation and management unit is used to generate symmetric session keys, which are stored in the two exchange cryptographic machines respectively and are invalidated after use. They are used to encrypt and decrypt control commands and monitoring data. The random number generator group is used to generate two sets of protection keys carrying unique key identifiers, and the two sets of protection keys are stored in the two exchange cryptographic machines respectively. The two key filling modules are used to fill the two sets of protection keys into the gateway (100) and CPE (200) respectively. The key service platform (310) is used to receive key requests from the gateway (100) and CPE (200), and issue corresponding key identifiers accordingly, so that the two exchange cryptographic machines can encrypt the session key with the corresponding protection key and send it to the gateway (100) and CPE (200) respectively.

2. The quantum key encryption communication system for gas stations according to claim 1, characterized in that, The key generation management unit includes a key management module (301) and a quantum key generation terminal. The quantum key generation terminal generates the symmetric session key based on BB84 or coherent state coding protocol. The key management module (301) is used to assign an identifier to the session key, control the storage of the session key, mark the usage status of the session key, and invalidate the session key and trigger the generation of a new session key under predetermined conditions.

3. The quantum key encryption communication method for gas stations according to claim 1, characterized in that, The random number generator group includes a first quantum random number generator (304) and a second quantum random number generator (305). The first quantum random number generator (304) is connected to one of the exchange cryptographic machines and is used to generate a set of protection keys and store them in the corresponding exchange cryptographic machine. The second quantum random number generator (305) is connected to another exchange cryptographic machine and is used to store another set of protection keys in the corresponding exchange cryptographic machine.

4. A quantum key encryption communication method for gas stations, characterized in that, Applied to the system as described in any one of claims 1-3, the method comprises: The two sets of protection keys are stored in the two exchange cryptographic machines respectively, and the two sets of protection keys are respectively fed into the gateway (100) and CPE (200). Generate the symmetric session key and store the symmetric session key pair in the two exchange cryptographic machines respectively; Receive key requests sent by the gateway (100) and CPE (200); In response to the key request, a key identifier corresponding to the protection key is sent to the gateway (100), CPE (200) and the corresponding cryptographic exchange machine; Perform a transmission operation; the transmission operation is to instruct the two exchange cryptographic machines to encrypt the paired session key with the protection key corresponding to the key identifier, and forward the encrypted paired session key to the gateway (100) and CPE (200) respectively.

5. The quantum key encryption communication method for gas stations according to claim 4, characterized in that, The method further includes: Monitor the first signal fed back by the gateway (100) and CPE (200), and trigger the invalidation of the current paired session key based on the first signal; the first signal is the session key usage completion signal.

6. The quantum key encryption communication method for gas stations according to claim 4, characterized in that, After the step of issuing the key identifier corresponding to the protection key to the gateway (100), CPE (200), and the corresponding cryptographic exchange machine, the method further includes: Monitor the second signal fed back by the gateway (100) and CPE (200) within the first set time period, the second signal being a key identification signal indicating successful reception; If the second signal is not received from either the gateway (100) or the CPE (200), a first retransmission operation is performed, and the first retransmission count is accumulated. The first retransmission count is the number of times the first retransmission operation is performed, and the first retransmission operation is to resend the unreceived key identifier to the party that did not send back the first signal. If the first retransmission count is greater than or equal to the first preset threshold, then the transmission operation is performed; Monitor the third signal fed back by the gateway (100) and CPE (200) within the second set time period, the third signal being a session key reception success signal; If the third signal is received from both parties, a first fault signal is generated to indicate that the first signal has a fault.

7. The quantum key encryption communication method for gas stations according to claim 6, characterized in that, After monitoring the second signal fed back by the gateway (100) and CPE (200) within the first set time period, the method further includes: If the second signal is received from both parties, the transmission operation is executed directly. If the third signal is not received from either the gateway (100) or the CPE (200) within the second set time period, the current symmetric session key is invalidated and a new symmetric session key is generated, and a second retransmission operation is performed; the second retransmission operation is to resend the new key identifier corresponding to the protection key to the gateway (100), the CPE (200) and the corresponding exchange cryptographic machine.

8. The quantum key encryption communication method for gas stations according to claim 6, characterized in that, After monitoring the third signal fed back by the gateway (100) and CPE (200) within the second set time period, the method further includes: If no third signal is received from either the gateway (100) or the CPE (200), a second fault signal is generated to indicate a key identification transmission channel failure.

9. The quantum key encryption communication method for gas stations according to claim 7, characterized in that, The method further includes: The cumulative number of second retransmissions within the third set time period, where the second retransmission count is the number of times the second retransmission operation is executed; If the second retransmission count is greater than or equal to the second set threshold, the instruction is to recharge the protection key to the party that has not fed back the third signal.

10. The quantum key encryption communication method for gas stations according to claim 4, characterized in that, After storing the two sets of protection keys into the two cryptographic exchange machines and respectively filling the two sets of protection keys into the gateway (100) and CPE (200), the method further includes: If the preset update cycle is reached, the instruction regenerates the two sets of protection keys and stores them in the two exchange cryptographic machines accordingly; The two newly generated protection keys are respectively fed into the gateway (100) and CPE (200).