Secret key negotiation method and device for quantum group authentication of smart power grid, storage medium and product
By employing a quantum group authentication key negotiation method for smart grids, and utilizing a hybrid strategy of group manager and smart meter two-factor authentication and quantum sequence, the problem of quantum algorithms weakening the security of classical public-key cryptosystems and high communication complexity in smart grids is solved. This method achieves efficient generation of group keys and authentication keys, meeting the security requirements of smart grids.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-03-10
AI Technical Summary
Existing technologies are insufficient to effectively defend against the weakening of classical public-key cryptosystems by quantum algorithms in smart grids. Furthermore, existing subgroup key negotiation schemes suffer from high communication complexity and insufficient scalability, failing to meet the security requirements of smart grids.
A quantum group authentication key negotiation method for smart grids is adopted. Through the registration, login, authentication and group key generation stages, a secure broadcast command and exclusive authentication key are generated by using the two-factor authentication of the group manager and smart meter and the quantum sequence hybrid strategy, which is adapted to resource-constrained smart meters.
It enables efficient generation of group keys and authentication keys, reduces resource overhead, improves communication efficiency and scalability, and adapts to the flexible management needs of smart grids.
Smart Images

Figure CN121644075A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum group authentication key negotiation technology, and in particular to a key negotiation method, apparatus, storage medium and product for quantum group authentication for smart grids. Background Technology
[0002] As a core infrastructure for energy transition, the Smart Grid (SG) deeply integrates with the traditional power grid through the Internet of Things (IoT), enabling real-time interaction and automated control. It not only significantly improves the reliability, flexibility, and efficiency of power grid operation but also plays a crucial role in ensuring the security of national energy infrastructure. However, SGs empowered by IoT technology face multiple security threats. Core nodes such as smart meters (SMs) and gateways are vulnerable to man-in-the-middle attacks, eavesdropping attacks, and replay attacks. The security of real-time bidirectional data communication between SMs and Neighborhood Area Network (NAN) gateways is particularly prominent. Simultaneously, the regionalized management of SGs has spurred the need for group-oriented communication, placing higher demands on existing security solutions.
[0003] Existing classical Authenticated Key Agreement (AKA) schemes have significant limitations: they struggle to address the security vulnerabilities of classical public-key cryptosystems posed by quantum algorithms, meaning they are defenseless against quantum adversary attacks. Furthermore, while research on Quantum Group Key Agreement (QGKA) exists, existing schemes still have shortcomings: some require all participants to possess full quantum capabilities, making them unsuitable for resource-constrained SMs in SG (Society of Keys) scenarios. Additionally, these schemes generally exhibit exponentially increasing communication complexity and insufficient scalability, failing to meet the communication efficiency requirements of group authentication under flexible regional management. Therefore, a secure, efficient, and SG-compatible quantum group key agreement scheme is urgently needed. Summary of the Invention
[0004] To address the aforementioned technical issues, this application proposes a key negotiation method, apparatus, storage medium, and product for quantum group authentication in smart grids.
[0005] The technical solution adopted in this application is: a key negotiation method for quantum group authentication in smart grids, comprising the following steps:
[0006] Registration phase: Multiple users and smart meters Through a secure channel to the gateway acting as the group manager Send a registration request to initially bind the user's identity and password, and generate a smart card. ;
[0007] Login phase: The user inserts the smart card into the smart meter, the smart meter sends a login request to the gateway, the gateway randomly prepares two sets of quantum sequences, obtains the final quantum sequence through a quantum sequence mixing strategy, and sends the final quantum sequence to the smart meter;
[0008] Authentication phase: The smart meter uses the quantum group key negotiation method to obtain the authentication key;
[0009] Group key generation phase: After authentication is completed by multiple smart meters that are operating in parallel, the group key is derived through a quantum system.
[0010] Furthermore, all smart meters Configured as a classic user using two-factor authentication.
[0011] Furthermore, the specific steps during the registration phase are as follows:
[0012] Sub-step 1: User Select and enter an identity code. and a password Then smart meters Generate a random value And calculate Finally, smart meters Register request ( Send to gateway ;in It is a hash function;
[0013] Sub-step 2: When received At that time, the gateway examine Is it unique? If If it exists, restart the registration phase; otherwise, the gateway... Generate a random value Then the gateway calculate And Store it in the registration list, and then Embedded smart card and securely place the smart card Awarded to smart meters ;
[0014] Sub-step 3: Upon receiving the smart card After that, smart meters calculate and Finally, smart meters Will and All stored in smart cards middle;
[0015] Sub-step 4: Smart meter and gateway Share a long-term key via a semi-quantum key distribution protocol. .
[0016] Furthermore, during the login phase, users smart card Insert smart meter In China, smart meters To the gateway Send login request, user enter and Smart meters calculate , , ,if Then smart card This login request has been denied.
[0017] Furthermore, during the login phase If the login request is received from the smart meter, then accept the login request. When a login request is received, the gateway Prepare indivual ,in It is a smart meter Quantity, It is a set of keys Length, yes dimension Particle state;
[0018] gateway Two sets of quantum sequences are prepared randomly. and ,in and , It is a computational basis. yes base; Record The state as a temporary key ,in Corresponding to Marked in the status , , Denotes the dimension of a high-dimensional Hilbert space;
[0019] The process of obtaining the final quantum sequence through a quantum sequence mixing strategy is as follows:
[0020] gateway Choose a random number And calculate , Depend on Control Insertion To obtain Gateway Choose a random number And calculate , Depend on Controlled insertion into quantum sequence To obtain quantum sequence ,in , It is the first indivual The One particle, and ;
[0021] Then the gateway To smart meters send ;
[0022] in , The control string for the quantum sequence mixing strategy. This is a hash function.
[0023] Furthermore, the certification phase specifically includes:
[0024] Sub-step 1: When the smart meter Received { At that time, smart meters calculate and ,based on and Smart meters Identification and ,Then exist China Measurement And derive temporary values from the measurement results. ;
[0025] Sub-step 2: Smart meter Choose a random number And calculate , Depend on Control Insertion To obtain ;
[0026] Sub-step 3: Smart meter Choose a random number And calculate ,as well as Smart meters To the gateway send ;
[0027] Sub-step 4: When received At that time, the gateway calculate Gateway according to Use the corresponding basis measurements with the initial state. The result is compared with the initial state; if the qubit error rate exceeds a predetermined threshold, the protocol is aborted and restarted; otherwise, the gateway... calculate as well as Gateway examine If unsuccessful, the process stops; otherwise, it proceeds to the next stage. It is a dynamic identity code. For temporary keys;
[0028] Sub-step 5: Gateway Choose a random number And calculate ,as well as Gateway To smart meters send ;
[0029] Sub-step 6: When received At that time, smart meters calculate ,as well as Then the smart meter examine If unsuccessful, the process will stop; otherwise, the smart meter will... Obtain authentication key .
[0030] Furthermore, in the group key generation stage of smart meters exist Measuring quantum sequences Obtain group key ,in Corresponding to Marked in the status .
[0031] A computer device includes a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method.
[0032] A computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implement the steps of the method.
[0033] A computer program product includes a computer program / instructions that, when executed by a processor, implement the steps of the method.
[0034] The advantages of this application over the prior art are as follows:
[0035] 1. The QGAKA scheme proposed in this application can generate a group key (secure broadcast command) and a dedicated authentication key (NAN-SM privacy exchange) in a single execution, which reduces the negotiation workload and improves efficiency.
[0036] 2. This application sets the smart meter as a classic user and adopts two-factor authentication, so that it can participate without full quantum capabilities, thus reducing resource consumption.
[0037] 3. The QGAKA scheme of this application has high quantum bit efficiency, and the participating nodes achieve linear complexity through parallel communication, which is better than the traditional scheme. Attached Figure Description
[0038] The following description, in conjunction with the accompanying drawings, further illustrates this application:
[0039] Figure 1 A schematic diagram illustrating the login and authentication process provided in an embodiment of this application;
[0040] Figure 2 This is a schematic diagram of the device structure provided in the embodiments of this application. Detailed Implementation
[0041] like Figure 1-2 As shown, this application provides a key negotiation method for quantum group authentication in smart grids, which can be called the Quantum Group Authentication Key Agreement (QGAKA). It mainly consists of four phases: registration, login, authentication, and group key generation. The parameters involved in this application include:
[0042] Computational basis: denoted as ;in Describes the dimension of a high-dimensional Hilbert space. It is a set of integers;
[0043] Base: Represented as ,in The quantum Fourier transform is defined as: ;in The summation index is an integer, and its value range is 1. ;
[0044] dimension Particle state is represented as ;
[0045] The meanings of other symbols involved are shown in Table 1.
[0046] Table 1. Symbols and their descriptions
[0047]
[0048] In the technical solution of this application, the group manager Possessing complete quantum capabilities, and smart meters For classic users only. During the registration phase, users... and smart meters Send to group manager via secure channel Registration. During the authentication phase, and They authenticate each other and establish an authentication key between them. Finally, all group members and... pass The group key is derived from the quantum entanglement system.
[0049] The technical solution of this application defines a quantum sequence mixing strategy: Let and Given two quantum sequences of equal length. If the control string's first... If the bit is 0, then The A quantum state is inserted into The Before a quantum state; otherwise, The A quantum state is inserted into The After a quantum state.
[0050] The following provides a detailed description of each stage of the technical solution in this application.
[0051] 1) Registration stage
[0052] The purpose of this stage is to allow users... and smart meters Through the safe passage Registration involves initial binding of identity and password, and generating a smart card to support subsequent two-factor authentication, specifically including:
[0053] Sub-step 1: Select and enter an identity code. and a password .Then Generate a random value And calculate .at last, Register request ( Send to .
[0054] Sub-step 2: When received hour, examine Is it unique? If If it exists, restart the registration phase. Otherwise, Generate a random value .Then calculate And Store it in the registration list, and then Embedded smart card and safely Awarded to users .
[0055] Sub-step 3: Upon receiving back, calculate and .at last, Will and All stored in smart cards middle.
[0056] Sub-step 4: and Share a long-term key via a semi-quantum key distribution protocol. .
[0057] 2) Login Phase
[0058] Will insert middle, Towards Send a request. enter and , calculate , , .if ,but This login request has been denied. The user's entered identity code, The password entered by the user is used to distinguish it from the correct identity code and password.
[0059] When received from When making a request, Prepare indivual ,in yes Quantity, It is a set of keys The length. Random preparation and ,in and . Record The state as ,in Corresponding to Marked in the status .after, Choose a random number And calculate . Depend on Control Insertion To obtain . Choose a random number And calculate . Depend on Control Insertion To obtain . , It is the first indivual The One particle, and .Then Towards send .
[0060] in , The control string for the quantum sequence mixing strategy. For hash functions, .
[0061] 3) The certification phase, which specifically includes:
[0062] Sub-step 1: When Received { hour, calculate and .based on and , Identification and .Then exist China Measurement And derive temporary values from the measurement results. .
[0063] Sub-step 2: Choose a random number And calculate . Depend on Control Insertion To obtain .
[0064] Sub-step 3: Choose a random number And calculate ,as well as . Towards send .
[0065] Sub-step 4: When received hour, calculate . according to Use the corresponding basis measurements with the initial state. And compare the result with the initial state. If the qubit error rate If the predetermined threshold is exceeded, the protocol will be suspended and restarted. Otherwise, calculate as well as . examine If unsuccessful, the process stops; otherwise, it proceeds to the next stage. It is a dynamic identity code.
[0066] Sub-step 5: Choose a random number And calculate ,as well as . Towards send .
[0067] Sub-step 6: When received hour, calculate ,as well as .Then examine If unsuccessful, the process will stop; otherwise... Obtain authentication key .
[0068] 4) Group Key Generation Stage
[0069] All those who have performed the above steps They can be executed in parallel. After authentication is complete, the group key is transmitted through a... dimension Particle system export. exist China Measurement To obtain ,in Corresponding to Dimension of the label in the state .
[0070] The QGAKA scheme proposed in this application has several advantages: First, it can generate two types of keys in a single execution: a group key for secure broadcast commands and a unique authentication key for private data exchange between the SM and NAN. Second, to enable resource-constrained SMs to participate in QGAKA, all SMs are configured as classical users using two-factor authentication, achieving robust authentication without requiring full quantum capabilities. Finally, QGAKA achieves high quantum bit efficiency, with the advantages becoming more significant as the number of participants increases. Furthermore, by replacing traditional exponentially complex serial communication with parallel communication, it successfully reduces communication complexity to a linear level, effectively improving communication efficiency and scalability.
[0071] Figure 2 A structural block diagram of a computer device according to a specific embodiment of this application is shown. Figure 2 As shown, the computer device includes a memory and a processor, the memory storing instructions executable on the processor. When the processor executes the instructions, it implements the methods described in the above embodiments. The number of memories and processors can be one or more. This computer device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The computer device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.
[0072] The computer device may also include a communication interface for communicating with external devices and exchanging data. The devices are interconnected using different buses and can be mounted on a common motherboard or otherwise as needed. The processor can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as a display device coupled to the interface). In other embodiments, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple electronic devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). The bus can be divided into address buses, data buses, control buses, etc. For ease of illustration, Figure 2 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0073] Optionally, in a specific implementation, if the memory, processor, and communication interface are integrated on a single chip, then the memory, processor, and communication interface can communicate with each other through an internal interface.
[0074] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting advanced RISC machines (ARM) architecture.
[0075] This application provides a computer-readable storage medium (such as the memory described above) storing computer instructions that, when executed by a processor, implement the method provided in this application.
[0076] Optionally, the memory may include a stored program area and a stored data area, wherein the stored program area may store the operating system and application programs required for at least one function; the stored data area may store data created based on the use of the computer device for mapping. Furthermore, the memory may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include memory remotely located relative to the processor, which can be connected to the computer device for mapping via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A key negotiation method for quantum group authentication in smart grids, characterized in that: The method comprises the following steps: Registration phase: multiple users and smart meters Through a secure channel to the gateway as a group manager Send a registration request, implement the initial binding of identity and password, and generate a smart card ; The login stage: the user inserts the smart card into the smart meter, the smart meter sends a login request to the gateway, the gateway randomly prepares two quantum sequences, obtains the final quantum sequence through a quantum sequence mixing strategy, and sends the final quantum sequence to the smart meter; The authentication stage: the smart meter obtains an authentication key through a quantum group key agreement method; The group key generation stage: after the authentication is completed, the multiple smart meters in parallel execute the group key through a quantum system. 2.The smart grid oriented quantum group authentication and key agreement method according to claim 1, characterized in that: All smart meters Classic users configured to employ two-factor authentication. 3.The smart grid oriented quantum group authentication and key agreement method of claim 1, wherein: The specific steps of the registration stage are as follows: Sub-step 1 : User selects and enters an identity code and a password The smart meter generates a random value and computes Finally, the smart meter sends a registration request to the gateway where is a hash function Sub-step 2: When received At that time, the gateway examine Is it unique? If If it exists, restart the registration phase; otherwise, the gateway... Generate a random value Then the gateway calculate And Store it in the registration list, and then Embedded smart card and securely place the smart card Awarded to smart meters ; Sub-step 3: upon receiving the smart card the smart meter computes and ; finally, the smart meter stores and both into the smart card ; Sub-step 4: Smart meter and a gateway Sharing a long-term key through a semi-quantum key distribution protocol .
4. The smart grid oriented quantum group authentication and key agreement method according to claim 3, characterized in that: login phase user inserting the smart card into the smart meter wherein the smart meter sends a login request to the gateway , the user inputs and , the smart meter computes , , if , the smart card rejects this login request.
5. The smart grid oriented quantum group authentication and key agreement method according to claim 4, characterized in that: In the login phase, when the login request is accepted, when receiving the login request from the smart meter , the gateway is prepared for , where is the number of smart meters , is the length of the group key , is dimensional particle state; Gateway Randomly prepare two sequences of qubits and where and , is a computational basis, is a basis; record the state as a temporary key where corresponds to the marked , , denotes the dimension of the high-dimensional Hilbert space; Then, the process of obtaining the final quantum sequence through the quantum sequence mixing strategy is as follows: gateway Choose a random number And calculate , Depend on Control Insertion To obtain Gateway Choose a random number And calculate , Depend on Controlled insertion into quantum sequence To obtain quantum sequence ,in , It is the first indivual The One particle, and ; Then the gateway sends to the smart meter a message ; wherein , is a control string for a quantum sequence hybrid strategy, is a hash function.
6. The smart grid oriented quantum group authentication and key agreement method according to claim 5, characterized in that: The authentication stage specifically comprises: Sub-step 1: When the smart meter Received { At that time, smart meters calculate and ,based on and Smart meters Identification and ,Then exist China Measurement And derive temporary values from the measurement results. ; Sub-step 2: Smart meter Choose a random number And calculate , Depend on Control Insertion To obtain ; Sub-step 3: smart meter select a random number and calculate and ; smart meter send to the gateway ; Sub-step 4: When received At that time, the gateway calculate Gateway according to Use the corresponding basis measurements with the initial state. The result is compared with the initial state; if the qubit error rate exceeds a predetermined threshold, the protocol is aborted and restarted; otherwise, the gateway... calculate as well as Gateway examine If unsuccessful, the process stops; otherwise, it proceeds to the next stage. It is a dynamic identity code. For temporary keys; Sub-step 5: Gateway selects a random number and calculates and , the gateway sends to the smart meter ; Sub-step 6: When receiving , the smart meter computes , and ; then the smart meter checks , aborts if unsuccessful, otherwise the smart meter obtains the authentication key .
7. The smart grid oriented quantum group authentication and key agreement method according to claim 6, characterized in that: Group key generation phase smart meter In Measuring quantum sequences To obtain group keys Wherein Corresponding to Marked in the state .
8. A computer apparatus comprising a memory, a processor, and a computer program stored on the memory, wherein: The processor executes the computer program to realize the steps of the method in any one of claims 1-7.
9. A computer readable storage medium having stored thereon computer programs / instructions, characterized in that: The computer program / instruction is executed by the processor to realize the steps of the method in any one of claims 1-7.
10. A computer program product comprising computer programs / instructions, characterized in that: The computer program / instruction is executed by the processor to realize the steps of the method in any one of claims 1-7.