Power grid service-oriented end-to-end quantum key data security protection system and method

By combining a quantum key distribution and management module, hardware root trust encryption and decryption, and a transparent gateway, the reliability and compliance issues of key management in power grid operations are resolved, and efficient security protection of power grid business data is achieved.

CN121585356APending Publication Date: 2026-02-27ANHUI JIYUAN SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511859075.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-10
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

In power grid operations, traditional key management systems are difficult to reliably distribute and update. Existing solutions are insufficient in terms of offline key injection, protected secure media transportation, and controlled loading at terminals. Furthermore, they have limited support for automatic re-encryption of long-term stored ciphertexts, full lifecycle management of keys, and tamper-proof audit chains.

Method used

The system uses a quantum key distribution and key management module to generate and manage quantum keys. Combined with hardware root trust, it performs field-level encryption and decryption, achieves seamless and secure access through a transparent gateway, and builds an immutable audit chain, supporting automated re-encryption and key lifecycle management.

Benefits of technology

It effectively reduces the risk of keys being copied, replaced, or replayed, provides tamper-proof audit evidence, facilitates post-event evidence collection, and enables strategic and automated key lifecycle management, meeting the requirements of long-term storage, audit trails, and regulatory compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121585356A_ABST
    Figure CN121585356A_ABST
Patent Text Reader

Abstract

The invention discloses a power grid service-oriented end-to-end quantum key data security protection system and method. The system comprises a quantum key distribution and key management module which is responsible for quantum key generation and management; the injection and sealing module is used for carrying out signature packaging on the secret key and generating an offline injection packet and an audit abstract; the safety medium and loading module is used for bearing and transporting the injection package to a site; the terminal encryption and decryption module is used for realizing field-level data encryption and decryption based on hardware root trust; the transparent gateway and access module is used as a security agent to provide protocol adaptation and non-inductive access control; the rule triggering and re-encryption module is used for automatically executing a ciphertext re-encryption task according to a strategy; and the auditing chain management module is used for recording a whole-process operation log and forming a tamper-resistant auditing chain. The method can effectively resist secret key copying, replacing and replaying attacks, provide reliable auditing evidences, support postmortem evidence obtaining and safety tracking, and meet the power grid compliance requirement through automatic secret key life cycle management and manual intervention reduction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power technology, and more specifically, to an end-to-end quantum key data security protection system and method for power grid operations. Background Technology

[0002] The operation of power systems generates a large amount of confidential business data, covering real-time telemetry, protection and control, metering and settlement, and operation and maintenance logs. This data has stringent requirements for confidentiality, integrity, and availability. Highly sensitive data needs to be stored long-term to meet regulatory and dispute resolution needs, which places higher standards on encryption strength, key management, and auditability.

[0003] The widespread distribution of field devices in power grids, often in a state of weak connectivity or disconnection, makes it difficult for traditional online distribution-based key management systems to reliably distribute and update keys. At the same time, power systems are mostly heterogeneous and legacy environments, and directly modifying the application layer is extremely costly. Therefore, there is an urgent need for a transparent and secure solution that also considers "seamless access" to reduce the risk of modification and ensure compatibility.

[0004] However, existing solutions lack sufficient protection in offline key injection, secure media transport, and controlled loading on terminals, and offer limited support for automatic re-encryption of long-term stored ciphertext, full key lifecycle management, and tamper-proof audit chains. Therefore, an end-to-end protection system combining the high-entropy characteristics of quantum keys with engineered offline injection, secure carriers, transparent gateway access, and automated re-encryption mechanisms has significant practical value. It also provides verifiable guarantees in terms of operational feasibility, scalability, and compliance, meeting regulatory, auditing, and forensic requirements. Summary of the Invention

[0005] The purpose of this invention is to provide an end-to-end quantum key data security protection system and method for power grid services. It can effectively reduce the risk of keys being copied, replaced, or replayed, and provide tamper-proof audit evidence for key operations such as injection, loading, decryption, and re-encryption, facilitating post-event evidence collection and security incident tracking. At the same time, it realizes strategic and automated key lifecycle management and batch operation and maintenance, reducing manual intervention and error probability, and meeting the requirements of long-term storage, audit trails, and regulatory compliance.

[0006] To achieve the above objectives, embodiments of the present invention provide an end-to-end quantum key data security protection system for power grid services, the system comprising: The quantum key distribution and key management module is used to generate and manage quantum keys, and maintain key metadata and version control; The injection and signing module, connected to the quantum key distribution and key management module, is used to sign and authenticate the quantum key and metadata in a controlled environment, and generate an offline injection package and an immutable injection audit digest. A secure medium and loading module are used to carry and transport the offline injection package offline. The terminal encryption / decryption module, deployed in the field terminal or gateway, is used to load keys from the secure medium and loading module in a controlled manner, and perform field-level data encryption and decryption operations based on hardware root trust; The transparent gateway and access control module are connected to the terminal encryption and decryption module and act as a security proxy for protocol adaptation, policy evaluation and dynamic access control, providing a seamless data security access interface for upper-layer legacy applications. The rule triggering and re-encryption module is used to trigger and execute automated ciphertext re-encryption tasks based on a predefined rule base and key lifecycle policy. The audit chain management module is used to record and manage key operation logs throughout the entire process from key injection, loading, use to re-encryption, forming an immutable audit chain.

[0007] On the other hand, the present invention provides an end-to-end quantum key data security protection method for power grid services, which performs quantum key data security protection based on the above system, including: Quantum keys are generated and managed based on the quantum key distribution and key management module; The quantum key and metadata are signed and encapsulated at the controlled injection station to generate an offline injection package; The injection package is transported to the site via secure media, and verification is completed on the terminal device, loading the key into protected storage. In the terminal or gateway, the business data stream is encrypted or decrypted at the field level according to the encryption rule base. A transparent gateway enables protocol adaptation and access control, providing seamless and secure access to legacy systems. Automatic re-encryption and key lifecycle management are achieved based on rules and triggers; Generate audit logs for critical operations and build an immutable audit chain.

[0008] Preferably, generating and managing quantum keys based on the quantum key distribution and key management module includes: The system performs overall orchestration, filtering, error correction, and privacy amplification of quantum links, maintains key metadata and version control, provides a standardized key derivation interface, and supports session key generation and key updates. Furthermore, according to formula (1), the security of the high-entropy key at the central end is represented by the key rate. (1) in, For the final secure key rate, The available bit rate after filtering For The calculated binary entropy, For quantum bit error rate, Leakage amount is corrected for error.

[0009] Preferably, the generation and management of quantum keys based on the quantum key distribution and key management module also includes scoring the freshness based on formula (2), prioritizing keys that are about to expire, and formulating a distribution window and backup plan based on the key usage frequency and sensitivity. (2) in, For freshness, It is the attenuation constant. For time intervals.

[0010] Preferably, the process of signing and encapsulating the quantum key and metadata at the controlled injection station to generate an offline injection package includes: Within the controlled injection station, the key and injection metadata are encapsulated, signed, authenticated, and sealed using HSM and multi-factor authentication. Simultaneously, an immutable injection digest and handover log are recorded to support transportation and verification. The injection signature is defined according to formula (3). (3) in, For digital signatures, For the injection site's private key, For hash functions, For key materials, This is metadata.

[0011] Preferably, the injection package is transported to the field via a secure medium, and verification is completed on the terminal device, including loading the key into protected storage: A quantum-safe TF card or UKY bearer injection package is used, and signature verification, serial number verification, and multi-factor authentication are completed on-site. The key is bound to a specific terminal hardware, and the derived key is stored in protected storage to prevent cross-device abuse. Among them, the device-bound key is used according to formula (4). (4) in, Bind a key to the terminal. For key materials, For security media serial number, For equipment identification.

[0012] Preferably, in the terminal or gateway, the field-level encryption or decryption processing of the business data stream according to the encryption rule base includes: Within the terminal or gateway, field-level AEAD encryption and decryption, key desealing, and local auditing are performed based on hardware root trust. A transparent API is provided to the upper level, and the impact of concurrency and latency is evaluated through a performance model. Among them, according to formula (5), field-level encryption is performed in the form of AEAD. (5) in, It is a ciphertext. For certification labels, For plain text, For related data, To initialize the vector, This is the session key.

[0013] Preferably, providing seamless and secure access to legacy systems through a transparent gateway for protocol adaptation and access control includes: Using the transparent gateway and admission module as applications, the security proxy between the gateway and storage is responsible for protocol adaptation, policy evaluation, session key derivation, and dynamic credential verification, achieving seamless access and fine-grained admission control to legacy systems; simultaneously, after admission is granted, decryption or desensitization is performed automatically; wherein, the admission decision is formalized according to formula (6), (6) in, For the admission results, As the main body, For objects, For action, For a set of strategies, This is a single-strategy evaluation.

[0014] Preferably, automatic re-encryption and key lifecycle management based on rules and triggers includes: Based on rule base entries, key lifecycle, and compliance policies, ciphertext is scanned periodically or event-driven, and re-encryption tasks are distributed in batches. Simultaneously, batch concurrent processing and on-chain auditing are supported to ensure long-term data confidentiality and traceability. The re-encryption triggering conditions are formalized according to formula (7). (7) in, To trigger the judgment, For the current time, To encrypt the time, For the retention period, This refers to the key expiration time. For the window threshold, This is a policy trigger point.

[0015] Preferably, the injection package is transported to the site via a secure medium, verified on the terminal device, the key is loaded into protected storage, the offline secure medium is replaced with TEE and threshold key management, and a security protection system is established by combining consortium blockchain with chain hash auditing instead of chain hash auditing.

[0016] The above technical solution integrates QKD key generation and KMS management, controlled offline injection and protected secure media, terminal / gateway hardware encryption / decryption modules, rule-based data stream encryption and triggered re-encryption mechanisms, and an immutable audit chain and key lifecycle management. The system achieves strong authentication, integrity verification, and audit logging throughout the entire process of key generation, injection, loading, use, backup, re-encryption, and destruction. It enables seamless access to legacy applications through a transparent gateway, balancing engineering deployability with compliant forensic capabilities. This method leverages the high entropy of quantum keys to enhance key security and meets the requirements for long-term storage and refined access control of highly sensitive power grid business data through engineering measures such as injected signatures, multi-factor loading, policy-driven encryption, and automatic triggered re-encryption.

[0017] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0018] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings: Figure 1 This is a schematic diagram of the structure of an end-to-end quantum key data security protection system for power grid services provided by the present invention; Figure 2 This is a flowchart illustrating the end-to-end quantum key data security protection method for power grid services provided by the present invention. Detailed Implementation

[0019] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.

[0020] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application all comply with relevant laws and regulations. In the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.

[0021] See Figure 1 This invention provides an end-to-end quantum key data security protection system for power grid services, the system comprising: The quantum key distribution and key management module is used to generate and manage quantum keys, and maintain key metadata and version control; The injection and signing module, connected to the quantum key distribution and key management module, is used to sign and authenticate the quantum key and metadata in a controlled environment, and generate an offline injection package and an immutable injection audit digest. A secure medium and loading module are used to carry and transport the offline injection package offline. The terminal encryption / decryption module, deployed in the field terminal or gateway, is used to load keys from the secure medium and loading module in a controlled manner, and perform field-level data encryption and decryption operations based on hardware root trust; The transparent gateway and access control module are connected to the terminal encryption and decryption module and act as a security proxy for protocol adaptation, policy evaluation and dynamic access control, providing a seamless data security access interface for upper-layer legacy applications. The rule triggering and re-encryption module is used to trigger and execute automated ciphertext re-encryption tasks based on a predefined rule base and key lifecycle policy. The audit chain management module is used to record and manage key operation logs throughout the entire process from key injection, loading, use to re-encryption, forming an immutable audit chain.

[0022] In one specific implementation, the system includes a key center (QKD-KMS), an injection station (IS), a secure medium (SM), a field terminal (FT), an audit chain (AS), a ciphertext storage (DS), a re-encryption trigger (TS), and a transparent gateway (QG). These entities work collaboratively to achieve a secure quantum key distribution system. Specifically: The QKD-KMS management unit is responsible for the orchestration, filtering, error correction, and privacy amplification of quantum links. It maintains key metadata, versioning, and auditing, and publishes available keys and update notifications to support online and offline distribution. Simultaneously, this unit quantitatively assesses key freshness and risk, generating retrieval or key re-establishment policies to ensure that high-entropy keys at the central end are distributed to injection stations or gateways in a controllable and auditable manner. Furthermore, it can also score keys based on freshness. Prioritize keys that are about to expire, and formulate distribution windows and backup plans based on key usage frequency and sensitivity, thereby balancing key security, availability and operation and maintenance costs in engineering deployment.

[0023] The injection and encapsulation unit performs key and metadata integrity verification, signing, authentication, encryption, and encapsulation within the controlled injection station. It also generates an immutable injection digest according to a multi-factor approval process for verification by the transporter and receiver. The IS simultaneously records the operator, timestamp, and media serial number, and writes the encapsulated injection packet to a designated SM to ensure link traceability.

[0024]

[0025] in, For the injection site's private key, For hash functions, For key materials, For metadata, For serial numbers.

[0026] The injection unit provides auditable handover documents and status feedback interfaces, supporting signature verification and anomaly handling at each stage of transportation and on-site loading, ensuring the authenticity and integrity of the injected documents throughout the entire offline lifecycle.

[0027] The secure medium and loading unit are carried by quantum-safe TF cards or UKY cards. On-site, after card insertion, serial number verification and signature verification are performed first, followed by multi-factor authentication. The key is then bound to the device context and written to protected storage, preventing misuse or duplication of the key on unauthorized devices. The loading process simultaneously reports loading audits and triggers rollback and alarm mechanisms in case of failure to ensure operational control.

[0028]

[0029] in To bind the key, Master key For device ID, This is the media serial number.

[0030] Through device binding and protected area management, field terminals can still use keys in a controlled manner even in the absence of network or weak network conditions, and all loading events are logged in a chain for post-event evidence collection.

[0031] The terminal encryption / decryption unit implements field-level encryption, decryption, and authentication within a protected environment inside the terminal or gateway. It employs encryption-authentication separation or an AEAD process to balance concurrency performance and data integrity. This unit generates logs for each encryption / decryption operation and supports pipelined batch processing to improve throughput, while also providing real-time latency and throughput monitoring for dynamically adjusting concurrency.

[0032]

[0033] in, It is a ciphertext. For certification labels, For plain text, For related data, To initialize the vector, For encryption key, This is the authentication key.

[0034] Operations and maintenance personnel monitor encryption / decryption latency, queue length, and failure rate to adjust local caching, concurrent thread count, and rollback strategies, ensuring that security is met without affecting business availability in real-time control and massive metering scenarios.

[0035] The transparent gateway and admission unit act as security proxies between applications and storage, responsible for protocol adaptation, policy evaluation, and dynamic credential management. QG calculates admission scores based on subject attributes, roles, and environmental context, and decides whether to decrypt or return anonymized data. When admission is granted, short-term session keys are derived as needed to achieve the principle of least privilege.

[0036]

[0037] in, For the first The weight of the item attribute, For the first The rating value of the item attribute. To determine the overall admission score, This is the admission threshold (anything above this value is considered passed).

[0038] QG ensures that legacy applications can securely access data without modification, while also recording each access decision and session credential usage, supporting fine-grained tracing and temporary tightening strategies triggered by risks.

[0039] The rule-triggered and re-encryption unit periodically or event-drivenly scans ciphertext metadata based on the rule base, key lifecycle, and compliance requirements, and initiates re-encryption tasks. It adopts windowed batch processing and idempotent design to ensure rollback and consistency, and prioritizes and schedules re-encryption jobs to control system load and completion window.

[0040]

[0041] in, The number of ciphertexts to be processed. The throughput that can be processed per unit time. For each batch processing size, For the time consumed per batch, This is an additional fixed expense.

[0042] This unit simultaneously generates a complete re-encryption audit chain and associates it with audit records such as injection, loading, and usage, thereby enabling automated, controllable, and verifiable data key rotation and compliance management in long-term storage scenarios.

[0043] like Figure 2 As shown, another aspect of the present invention provides an end-to-end quantum key data security protection method for power grid services, which performs quantum key data security protection based on the above system, including: Quantum keys are generated and managed based on the quantum key distribution and key management module; The quantum key and metadata are signed and encapsulated at the controlled injection station to generate an offline injection package; The injection package is transported to the site via secure media, and verification is completed on the terminal device, loading the key into protected storage. In the terminal or gateway, the business data stream is encrypted or decrypted at the field level according to the encryption rule base. A transparent gateway enables protocol adaptation and access control, providing seamless and secure access to legacy systems. Automatic re-encryption and key lifecycle management are achieved based on rules and triggers; Generate audit logs for critical operations and build an immutable audit chain.

[0044] In this embodiment, the generation and management of quantum keys based on the quantum key distribution and key management module includes: overall orchestration, filtering, error correction, and privacy amplification of the quantum link; maintenance of key metadata and version control; provision of a standardized key derivation interface; support for session key generation and key updates; and ensuring that high-entropy keys at the central end can be securely distributed and audited. Its secure and usable key rate can be expressed as...

[0045] in, For the final secure key rate, The available bit rate after filtering For The calculated binary entropy, For quantum bit error rate, Leakage amount is corrected for error.

[0046] Furthermore, the above-mentioned generation and management of quantum keys based on the quantum key distribution and key management module also includes... Freshness scores are calculated, and keys that are about to expire are prioritized. Distribution windows and backup plans are formulated based on key usage frequency and sensitivity, thereby balancing key security, availability, and operational costs in engineering deployment.

[0047] In this embodiment, signing and encapsulating the quantum key and metadata at the controlled injection station to generate an offline injection package includes: within the controlled injection station, combining HSM and multi-factor authentication to encapsulate, sign, authenticate, and seal the key and injection metadata, while simultaneously recording an immutable injection digest and handover log to support transportation and verification; wherein, the injection signature can be defined as... ,in, For digital signatures, For the injection site's private key, For hash functions, For key materials, This is metadata.

[0048] In this embodiment, the injection package is transported to the site via a secure medium, and verification is completed on the terminal device. Loading the key into protected storage includes: using a quantum-safe TF card or UKY to carry the injection package and completing signature verification, serial number verification, and multi-factor authentication on-site; binding the key to specific terminal hardware; and storing the derived key in protected storage to prevent cross-device misuse. The device-bound key can be represented as... ,in, Bind a key to the terminal. For key materials, For security media serial number, For equipment identification.

[0049] Simultaneously, within the terminal or gateway, based on the encryption rule base, field-level encryption or decryption processing is performed on the business data stream. This includes: performing field-level AEAD encryption / decryption, key desealing, and local auditing within the terminal or gateway based on hardware root trust, providing a transparent API, and evaluating the concurrency and latency impact through a performance model; whereby field-level encryption is represented in AEAD format. ,in, It is a ciphertext. For certification labels, For plain text, For related data, To initialize the vector, This is the session key.

[0050] In this embodiment, protocol adaptation and access control are implemented through a transparent gateway to provide seamless and secure access to legacy systems, including: By using a transparent gateway and admission module as applications, a security proxy between the gateway and storage handles protocol adaptation, policy evaluation, session key derivation, and dynamic credential verification, enabling seamless access and fine-grained admission control over legacy systems. Simultaneously, after admission is granted, decryption or de-identification is performed manually. The admission decision can be formalized as follows: , among which, among which, For the admission results, As the main body, For objects, For action, For a set of strategies, This is a single-strategy evaluation.

[0051] In this implementation, automatic re-encryption and key lifecycle management based on rules and triggers includes: periodically or event-driven scanning of ciphertext and batch distribution of re-encryption tasks according to rule base entries, key lifecycle, and compliance policies. Simultaneously, it supports batch concurrent processing and on-chain auditing to ensure long-term data confidentiality and traceability. The re-encryption trigger condition can be formalized as follows:

[0052] in, To trigger the judgment, For the current time, To encrypt the time, For the retention period, This refers to the key expiration time. For the window threshold, This is a policy trigger point.

[0053] In addition, as an alternative to this implementation, the present invention also provides multiple redundancy and alternative implementation paths, including semi-offline distribution based on TEE and threshold key management, off-site HSM backup and threshold recovery, and consortium blockchain alternative chain hash storage, to ensure that the system can still switch smoothly and maintain data and key security when the device fails, the connection is interrupted or the compliance changes.

[0054] Therefore, the system provided by this invention constructs an overall architecture covering QKD-KMS, injection station, security medium, terminal encryption and decryption module, transparent gateway and storage trigger, realizes closed-loop management of key from generation to destruction and full-link encryption protection of data flow, ensures the security consistency and auditability of key distribution, use and re-keys at the system level, and supports both online and offline deployment modes to adapt to the heterogeneous terminal environment of the power grid.

[0055] Secondly, this invention performs hardware signing and authentication encryption encapsulation of quantum keys and metadata at a controlled injection station, generating an injection packet that can be transported offline on a medium and recording an immutable handover digest. This ensures the authenticity, integrity, and traceability of the injection credentials even in unpredictable or weak network scenarios, reducing the complexity of establishing trust on-site.

[0056] Furthermore, this invention uses quantum-safe TF cards / UKY and other media with hardware root trust to carry injection packages. On-site loading requires serial number verification, signature verification and multi-factor authentication. The key is bound to the terminal hardware context and written to protected storage to ensure that the key is only available on authorized devices and to prevent cross-device abuse and copying risks.

[0057] Meanwhile, this invention also constructs an encryption rule base based on source-field-sensitivity. Terminals or gateways implement field-level AEAD encryption and decryption according to the rules, supporting policy-driven key invocation and least privilege access, so as to achieve fine-grained confidentiality for different business flows and performance optimization for real-time requirements, taking into account both security and business availability.

[0058] Furthermore, this invention deploys a smart gateway as a proxy without altering the upper-layer application. This gateway is responsible for protocol adaptation, access policy evaluation, and temporary session key derivation. After access is granted, the gateway performs decryption or desensitization and return, thereby achieving seamless and secure access to legacy systems and providing fine-grained auditing and risk control at the access level.

[0059] Furthermore, this invention designs triggers to periodically or event-drivenly scan the ciphertext and key status, automatically batch-issue re-encryption tasks based on retention period, key expiration, or compliance trigger conditions, and supports idempotent rollback and priority scheduling. Combined with key versioning and backup strategies, it achieves secure and controllable operation and maintenance throughout the key lifecycle.

[0060] Finally, this invention generates signed audit records for key operations such as injection, loading, decryption, re-encryption, backup, and destruction, and uses chained digests or consortium ledgers for evidence storage, ensuring that the audit chain is immutable in the long term and supporting multi-role retrieval and legal evidence collection, thereby improving operational transparency and compliance proof capabilities.

[0061] In summary, the method provided by this invention combines high-entropy keys generated by QKD, controlled offline injection, media sealing, and terminal binding, along with AEAD encryption and chain auditing. This effectively reduces the risk of keys being copied, replaced, or replayed, and provides tamper-proof audit evidence for critical operations such as injection, loading, decryption, and re-encryption, facilitating post-incident evidence collection and security incident tracing. Furthermore, it enables seamless access to legacy systems through a transparent gateway, and with rule-driven field-level encryption and trigger-based automatic re-encryption, it achieves policy-based and automated key lifecycle management and batch maintenance, reducing manual intervention and error probability, and meeting long-term storage, audit trail, and regulatory compliance requirements.

[0062] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0063] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0064] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0065] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0066] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0067] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0068] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0069] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0070] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A power grid service oriented end-to-end quantum key data security protection system, characterized in that, The system comprises: A quantum key distribution and key management module for generating and managing quantum keys and maintaining key metadata and version control; An injection and sealing module connected to the quantum key distribution and key management module for signing and differentially encrypting quantum keys and metadata in a controlled environment, generating offline injection packages and tamper-proof injection audit summaries; A secure medium and loading module for carrying and offline transporting the offline injection packages; A terminal encryption and decryption module deployed in a field terminal or gateway for controlled loading of keys from the secure medium and loading module and performing field-level data encryption and decryption operations based on hardware root trust; A transparent gateway and access module connected to the terminal encryption and decryption module as a security agent for protocol adaptation, policy evaluation and dynamic access control, providing a non-intrusive data security access interface for upper-layer legacy applications; A rule triggering and re-encryption module for triggering and performing automatic ciphertext re-encryption tasks according to a predefined rule library and key life cycle policy; An audit chain management module for recording and managing key operation logs from key injection, loading, use to re-encryption, forming a tamper-proof audit chain.

2. A power grid service oriented end-to-end quantum key data security protection method, characterized in that, The system based on claim 1 for quantum key data security protection comprises: Generating and managing quantum keys based on the quantum key distribution and key management module; Signing and packaging quantum keys and metadata at a controlled injection station to generate offline injection packages; Transporting the injection packages to the field through a secure medium and completing verification on a terminal device to load the keys into protected storage; In a terminal or gateway, according to the encryption rule library, field-level encryption or decryption processing is performed on the business data stream; Protocol adaptation and access control are realized through a transparent gateway to provide non-intrusive security access for legacy systems; Automatic re-encryption and key life cycle management are realized based on rules and triggers; Audit records are generated for key operations, and a tamper-proof audit chain is constructed.

3. The grid service oriented end-to-end quantum key data security protection method according to claim 2, characterized in that, The quantum key distribution and key management module generates and manages quantum keys, comprising: Overall orchestration, screening, error correction and privacy amplification of quantum links, maintenance of key metadata and version control, provision of standardized key derivation interfaces to support session key generation and key update; and according to formula (1), the key rate is used to represent the security of the high-entropy key at the center end, ,(1) in, For the final secure key rate, The available bit rate after filtering For The calculated binary entropy, For quantum bit error rate, Leakage amount is corrected for error.

4. The grid service oriented end-to-end quantum key data security protection method according to claim 3, characterized in that, Also includes freshness scoring based on formula (2), and prioritizing keys that are about to expire, combined with key usage frequency and sensitivity to develop distribution windows and backup plans, ,(2) wherein, is the freshness, is the decay constant, is the time interval.

5. The grid service oriented end-to-end quantum key data security protection method according to claim 2, characterized in that, The quantum key distribution and key management module generates and manages quantum keys, comprising: In the controlled injection station, the key and injection metadata are packaged, signed and differentially encrypted in combination with HSM and multi-factor approval, and are stored, and tamper-proof injection summaries and handover logs are recorded to support transportation and verification; wherein the injection signature is defined according to formula (3), ,(3) wherein, is a digital signature, is an injection station private key, is a hash function, is key material, is metadata.

6. The grid service oriented end-to-end quantum key data security protection method according to claim 2, characterized in that, The quantum key distribution and key management module generates and manages quantum keys, comprising: Adopt quantum security TF card or UKY to carry injection package and complete signature verification, serial number check and multi-factor authentication on site, bind the key with specific terminal hardware and save the derived key in protected storage to prevent cross-device abuse; wherein, according to formula (4), the device binding key is used, ,(4) wherein, is a terminal binding key, is a key material, is a secure media serial number, is a device identification.

7. The grid service oriented end-to-end quantum key data security protection method according to claim 2, characterized in that, The field-level encryption or decryption processing of the service data flow in the terminal or the gateway according to the encryption rule library includes: The field-level AEAD encryption and decryption, key unsealing and local audit are performed in the terminal or the gateway based on hardware root trust, the transparent API is provided upwards, and the concurrent and delay effects are evaluated through the performance model; wherein, according to formula (5), the field-level encryption is performed in the form of AEAD, ,(5) wherein, is a ciphertext, is an authentication tag, is a plaintext, is associated data, is an initialization vector, is a session key.

8. The grid service oriented end-to-end quantum key data security protection method according to claim 2, characterized in that, The protocol adaptation and access control are realized through the transparent gateway, and the safe access of the legacy system is provided without feeling includes: The transparent gateway and the access module are used as the application between the storage and the security agent, which is responsible for protocol adaptation, policy evaluation, session key derivation and dynamic credential check, realizes the access of the legacy system without feeling and fine-grained access control; at the same time, after the access is passed, the decryption or desensitization is executed; wherein, according to formula (6), the access decision is formalized, ,(6) wherein, is an admission result, is a subject, is an object, is an action, is a policy set, is a single policy evaluation.

9. The grid service oriented end-to-end quantum key data security protection method according to claim 2, characterized in that, The automatic re-encryption and key life cycle management are realized based on rules and triggers includes: According to the rule library entry, the key life cycle and the compliance strategy, the ciphertext is scanned regularly or event-driven, and the re-encryption task is issued in batches, at the same time, the batch concurrent processing and audit chain are supported to ensure the long-term data confidentiality and traceability; wherein, according to formula (7), the re-encryption trigger condition is formalized, ,(7) wherein, is a trigger judgment, is a current time, is an encryption time, is a retention period, is a key expiration time, is a window threshold, is a policy trigger bit.

10. The grid service oriented end-to-end quantum key data security protection method according to claim 6, characterized in that, The injection package is transported to the site through the secure medium, and the verification is completed on the terminal device, the key is loaded into the protected storage, the offline security medium is replaced by TEE and threshold key management, and the security protection system is established in combination with the alliance chain instead of chain hash audit.