Power distributed terminal secure communication method and system based on post-quantum cryptography

By adopting a post-quantum cryptography key encapsulation mechanism in the power distributed terminal secure communication system, the security problem under the threat of quantum computing is solved, the quantum security upgrade of the power communication system is realized, the long-term security and concurrent processing capability of the system are improved, and it is adapted to the mass production and operation and maintenance needs of power terminals.

CN122293324APending Publication Date: 2026-06-26STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610739851.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-27
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing secure communication systems for distributed power terminals face challenges when confronted with quantum computing threats, including long-term static risks to session keys, inability to withstand long-term quantum threats, and a lack of forward security. In particular, the security of communication data cannot be guaranteed once the key negotiation phase is compromised.

Method used

A key encapsulation mechanism based on post-quantum cryptography is adopted. Encryption keys are generated by terminal devices and pre-registered to the cloud-side key management system. Key exchange and shared session key generation are carried out in conjunction with a secure access gateway. A lattice-based post-quantum cryptography algorithm is used to replace the SM2 algorithm for session key negotiation. The key length of the SM4 algorithm used for symmetric encryption services is doubled to achieve continuous key evolution and periodic reconstruction.

Benefits of technology

In a quantum computing environment, a quantum security upgrade of the power distributed terminal communication system was achieved, avoiding infrastructure modifications, adapting to the needs of mass production and unattended operation and maintenance of power terminals, significantly improving the concurrent processing capability of the gateway, and possessing forward security and key leakage self-repair capability to resist long-term quantum threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122293324A_ABST
    Figure CN122293324A_ABST
Patent Text Reader

Abstract

This invention discloses a secure communication method and system for power distributed terminals based on post-quantum cryptography. With the development of quantum computing technology, traditional secure communication mechanisms based on elliptic curve cryptography face potential vulnerabilities. In existing secure communication systems for power distributed terminals, the terminal device and the secure access gateway typically use the SM2 elliptic curve cryptography algorithm for session key negotiation, which poses security risks in a quantum computing environment. This invention replaces the SM2 algorithm with a lattice-based post-quantum cryptography algorithm for session key negotiation and doubles the key length of the SM4 algorithm used for symmetric encryption services. While maintaining the original power communication system architecture and business processes, this invention achieves a quantum security upgrade for the power distributed terminal communication system, improving the system's long-term security in future quantum computing environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a secure communication method and system for power distributed terminals based on post-quantum cryptography, belonging to the fields of information security and power communication technology. Background Technology

[0002] Power distributed terminals are crucial devices in power systems that perform data acquisition, status monitoring, and control command issuance. Examples include distribution automation terminals (DTUs), feeder terminals (FTUs), and smart meters. To ensure the safety and stability of the power grid, a secure communication mechanism needs to be established between the terminal devices and the master station system to guarantee the confidentiality, integrity, and authenticity of communication data. Currently, secure communication systems for power distributed terminals typically employ security mechanisms based on commercial cryptographic algorithms. In existing systems, both communicating parties usually use the SM2 elliptic curve cryptography algorithm for authentication and key negotiation, the SM3 algorithm for message digest calculation, and the SM4 block cipher algorithm for encryption of business data, thus forming a complete secure communication system.

[0003] However, with the development of quantum computing technology, public-key cryptography algorithms based on integer factorization and elliptic curve discrete logarithm problems will face potential threats. Quantum computers can use Shor's algorithm to solve the elliptic curve discrete logarithm problem in polynomial time, thus putting existing security systems built on elliptic curve algorithms such as SM2 at risk of being cracked. Once the key negotiation phase is compromised, data subsequently protected by symmetric encryption algorithms will also lose its security.

[0004] Most existing power grid quantum security upgrade schemes only focus on quantum security protection during the initial key negotiation phase, without fully considering the long-term continuity of power system communication and the characteristics of terminals, which leads to the following problems:

[0005] 1. Long-term static risk of session keys: Most schemes use session keys generated by a single quantum key negotiation for long-term use. Once the key is leaked due to side-channel attacks, device vulnerabilities, or other reasons, attackers can decrypt all communication data within the validity period of the key. Moreover, power terminals are often deployed in unattended environments, making it difficult to detect key leaks in a timely manner.

[0006] 2. Unable to defend against the long-term quantum threat of "collect first, then decrypt": Even if the initial key negotiation adopts a post-quantum algorithm, if the session key remains unchanged for a long time, attackers can still intercept and store encrypted business data, and decrypt all data by cracking the historical session key when quantum computer technology matures in the future.

[0007] 3. Lack of forward security: The existing solution does not achieve message-level key isolation. If the session key is cracked at a certain moment, the attacker can reverse the encryption key of all previous messages and decrypt historical communication data.

[0008] Therefore, introducing post-quantum cryptographic algorithms that can resist quantum computing attacks into the existing power communication system and constructing new secure communication methods has become an important research direction in the field of power information security. Summary of the Invention

[0009] Objective: To overcome the shortcomings of the existing key negotiation mechanism based on the SM2 algorithm in the existing power distributed terminal secure communication architecture, this invention provides a power distributed terminal secure communication method and system based on post-quantum cryptography, which achieves quantum security upgrade of the communication system while maintaining the functional consistency and service seamlessness of the existing communication architecture.

[0010] Technical solution: To solve the above technical problems, the technical solution adopted by the present invention is as follows:

[0011] Firstly, a secure communication method for distributed power terminals based on post-quantum cryptography, specifically including:

[0012] Step 1: The terminal device generates an encryption key and a decryption key, binds the device identifier to the encryption key, and submits it to the cloud-based power system key management system through the encryption debugging channel to complete the pre-registration.

[0013] Step 2: The terminal device establishes a TCP connection with the security access gateway, and the security access gateway completes the encryption key exchange through the cloud-based power system key management system.

[0014] Step 3: The secure access gateway generates ciphertext and a shared session key based on the encryption key, and sends the ciphertext to the terminal device.

[0015] Step 4: The terminal device generates a shared session key based on the decryption key and the ciphertext.

[0016] Step 5: The terminal device and the secure access gateway use the shared session key as the session root key for encrypted message communication and update the session root key, respectively. The updated session root key is used for subsequent encrypted message communication.

[0017] In a second aspect, a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for secure communication of distributed power terminals based on post-quantum cryptography as described in any of the first aspects.

[0018] Thirdly, a computer device comprising:

[0019] Memory is used to store instructions.

[0020] A processor for executing the instructions, causing the computer device to perform operations of a post-quantum cryptography-based secure communication method for distributed power terminals as described in any of the first aspects.

[0021] Beneficial Effects: The power distributed terminal secure communication method and system based on post-quantum cryptography provided by this invention addresses the potential vulnerability of traditional elliptic curve cryptography-based secure communication mechanisms to the threat of attack posed by the development of quantum computing technology. In existing power distributed terminal secure communication systems, the session key negotiation between terminal devices and secure access gateways typically uses the SM2 elliptic curve cryptography algorithm, which poses a security risk in a quantum computing environment. This invention analyzes the quantum security risks of existing power distributed terminal communication architectures, identifying the SM2-based key negotiation process in cloud-edge wireless public network communication as the main security risk point, and proposes a secure communication method based on a post-quantum cryptography key encapsulation mechanism. This method replaces the SM2 algorithm with a lattice-based post-quantum cryptography algorithm for session key negotiation and doubles the key length of the SM4 algorithm used for symmetric encryption services. While maintaining the original power communication system architecture and business processes, this method achieves a quantum security upgrade of the power distributed terminal communication system, improving the long-term security of the system in future quantum computing environments. Compared to existing technologies, this invention has the following advantages:

[0022] 1. Reuse the existing power key management system to avoid infrastructure modifications: Change the standard process of "terminal actively uploading public key to gateway" in the general post-quantum algorithm to the gateway obtaining the pre-registered post-quantum public key of the terminal from the KMS through a dedicated power encryption backend channel. This design avoids the risk of public key tampering during transmission over the public network and is fully compatible with the existing power KMS operation and maintenance process, interface specifications, and security policies. No modifications are required to the existing key management infrastructure, achieving seamless integration with the existing system.

[0023] 2. Adapting to the needs of mass production and unattended operation and maintenance of power terminals: The "key generation during field deployment" mode of the general post-quantum algorithm is optimized to a "key generation during factory initialization + centralized pre-registration via KMS" mode. During the factory initialization phase of the production process (power-on in a secure production environment), the terminal's post-quantum key is generated by the key generation algorithm in step 1 executed internally by the security chip. The private key is permanently locked in a one-time programmable (OTP) encrypted partition and cannot be exported. The public key is bound to the terminal's unique asset number and pre-registered to the unified key management system (KMS) of the power system through an encrypted debugging channel in the production environment. After the terminal is deployed and powered on in the field, there is no need to regenerate the key or configure key information on-site, fully meeting the requirements of mass production deployment and unattended operation and maintenance of millions of power terminals nationwide.

[0024] 3. Significantly enhances the gateway's ability to handle massive concurrent terminals: Addressing the core requirement of power security access gateways to simultaneously support thousands of concurrent terminals, a public key matrix pre-computation and caching mechanism is added. The gateway obtains the complete encryption key ek_PKE (including seed ρ and vector) from KMS for each terminal. After that, a 3×3 public key matrix Â, uniquely determined by the seed ρ, is pre-calculated and cached. When the same terminal initiates a connection again, there is no need to recalculate the public key matrix Â. The cached result is used directly to perform key encapsulation operation, which can reduce the core operation time of key encapsulation per operation, improve the concurrent processing capability of a single gateway, and meet the business requirements of large-scale terminal access in the power distribution Internet of Things.

[0025] 4. Achieve full lifecycle quantum security protection: Through a two-layer key update mechanism of continuous key evolution and periodic key reconstruction, the quantum security problem of initial key negotiation is solved, and quantum security protection of continuous communication process is achieved, which can completely resist the long-term quantum threat of "collect first, then decrypt".

[0026] 5. Possesses forward security and key leakage self-repair capability: Message-level key evolution ensures that different messages use independent encryption keys, so even if the key of a message is leaked, historical messages cannot be decrypted; periodic post-quantum key reconstruction introduces a brand-new true random entropy, so even if the session root key is leaked, the system will automatically restore the secure state during the next reconstruction. Attached Figure Description

[0027] Figure 1 This is a schematic diagram of the architecture of an existing power distributed terminal security communication system.

[0028] Figure 2 This is a flowchart illustrating a secure communication method for distributed power terminals based on post-quantum cryptography according to the present invention. Detailed Implementation

[0029] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present invention.

[0030] The present invention will be further described below with reference to specific embodiments.

[0031] Example 1:

[0032] This embodiment introduces a secure communication method for distributed power terminals based on post-quantum cryptography. This method is built upon the existing "cloud-pipe-edge-terminal" communication architecture of the power system. Figure 1 As shown, the communication system includes: a cloud-side master station system, a communication transmission network, a secure access gateway, and edge-side power distributed terminal equipment.

[0033] The cloud-side master station system is used to realize power equipment management, data processing and business control functions, including the cloud-side power system key management system (KMS).

[0034] Communication transmission networks, including fiber optics, public wireless networks, or private power grids.

[0035] A secure access gateway is used to implement terminal device access authentication, secure communication control, and data forwarding.

[0036] Side-side distributed power terminal equipment, including distribution automation terminals, feeder terminals, and smart meters, is used to collect power equipment operation data and communicate with the master station system.

[0037] By conducting a quantum security risk analysis of the existing communication system, it was determined that when the cloud-side secure access gateway and the edge-side terminal device communicate through the public wireless network, the session key negotiation process based on the SM2 algorithm is at risk of quantum computing attacks.

[0038] Therefore, this invention uses a post-quantum cryptography key encapsulation mechanism to replace the original SM2 key negotiation mechanism, and achieves secure communication by establishing a quantum-resistant session key negotiation process, such as... Figure 2 As shown, it specifically includes:

[0039] Step 1: Terminal device executes key generation algorithm: This step is executed by the security encryption chip of the side-side power distributed terminal device (hereinafter referred to as: terminal device). The input is a 32-byte true random seed generated by the terminal true random number generator (TRNG), and the output is a 1184-byte encryption key ek_PKE (which can be publicly transmitted) and a 1152-byte decryption key dk_PKE (which is permanently stored in the encrypted partition of the security chip and cannot be exported or read). The specific steps of the algorithm execution are as follows:

[0040] Step 1.1: When the terminal device is powered on and initialized, the terminal true random number generator (TRNG) conforming to the national cryptographic standard is called to generate two 32-byte true random seeds d and z.

[0041] Step 1.2: Call the SHA3-512 hash function, input a 32-byte random seed d concatenated with a 1-byte parameter set identifier (k=0x03), output a 64-byte hash value, and split the hash value into the first 32 bytes seed ρ and the last 32 bytes seed σ.

[0042] Step 1.3: Initialize counter N=0 for subsequent pseudo-random number generation field separation. The counter increments independently inside the security chip to prevent replay attacks.

[0043] Step 1.4: Generate a 3×3 public key matrix Â: Set the positional parameters (i,j) of the 3×3 matrix, i,j∈[0,2]. Perform a rejection sampling algorithm on ρ||j||i (32 bytes + 1 byte + 1 byte) to output a uniformly distributed polynomial Â[i,j] in the NTT field. Each polynomial contains 256 integers modulo 3329. || is a concatenation operation. All polynomials Â[i,j] are used as the matrix Â. The matrix  is uniquely determined only by the seed ρ and does not need to be transmitted over the network. The NTT field represents the number theory transformation domain.

[0044] Step 1.5: Generate secret vector s: Perform a pseudo-random function PRF_η1(σ, N) on σ || N (32 bytes + 1 byte) to output polynomial s[0]. Then, increment N and repeat the calculation of polynomial s[i], i∈[0,2], to obtain polynomials s[1] and s[2] respectively. Use polynomials s[0], s[1], and s[2] as secret vector s. Among them, polynomial s[i] follows a central binomial distribution (η1=3) with 256 small coefficient integers. After each component of secret vector s is generated, the counter N increments by 1. Secret vector s is the core private key material. After generation, it is immediately transferred to the dedicated key register of the security chip and cannot be read externally.

[0045] Step 1.6: Generate noise vector e: The process is exactly the same as generating secret vector s. σ || N (32 bytes + 1 byte) is processed using the pseudo-random function PRF_η2(σ, N), and the output polynomial e[0] is obtained. Then, N+1 is used to repeatedly calculate polynomial e[i], i∈[0,2], to obtain polynomials e[1] and e[2] respectively. Polynomials e[0], e[1], and e[2] are used as noise vector e. Polynomial e[i] follows a central binomial distribution (η2=2) with 256 small coefficient integers. The noise vector is used to ensure the computational security of the algorithm and prevent lattice basis reduction attacks.

[0046] Step 1.7: Perform a number-theoretic transformation (NTT) on each component of the secret vector s to transform the polynomial from the time domain to the NTT domain, thus obtaining the NTT domain secret vector. Perform an NTT transformation on each component of the noise vector e to obtain the NTT domain noise vector ê. The NTT transformation is the core acceleration operator of this algorithm, which reduces the time complexity of polynomial multiplication from O(n²) to O(n log n), adapting to the low computing power characteristics of power terminals. Here, O() represents the time complexity function, and n represents the dimension of the polynomial.

[0047] Step 1.8: For the secret vector Perform matrix-vector multiplication and vector addition operations on the noise vector ê in the NTT domain to obtain the NTT domain vector. All operations are performed modulo 3329 and do not involve any floating-point operations. This represents matrix-vector multiplication.

[0048] Step 1.9: For vectors Each component is encoded using ByteEncode_12, converting each 12-bit integer into byte format, resulting in 1152 bytes of data. A 32-byte seed ρ is then concatenated to generate a 1184-byte encryption key, ek_PKE. ek_PKE can be transmitted to a secure access gateway via existing power communication protocols for subsequent key encapsulation operations.

[0049] Step 1.10: For the NTT domain secret vector Each component is encoded using ByteEncode_12 to obtain a 1152-byte decryption key, dk_PKE. dk_PKE is written to the one-time programmable (OTP) encryption area of ​​the security chip, which can only be accessed by the internal cryptographic algorithm and cannot be read by any external instruction.

[0050] Step 1.11: The terminal device binds its unique device identifier (asset number / device ID) with the generated 1184-byte encryption key ek_PKE and submits it to the cloud-side power system key management system (KMS) through the encrypted debugging channel to complete pre-registration. After verifying the legitimacy of the terminal's identity, KMS stores the mapping relationship between the terminal device identifier and the encryption key ek_PKE in the encrypted database, and simultaneously writes the root certificate of the secure access gateway and the post-quantum cryptography parameter set list configuration into the terminal device's security chip.

[0051] Step 1.12: After the algorithm completes execution, immediately clear and destroy all intermediate variables (including ρ, σ, Â, s, e, ...). ,ê, (etc.) to prevent side-channel attacks from leaking key information.

[0052] Step 2: TCP connection establishment and encryption key transmission.

[0053] This step fully reuses the existing power communication protocol stack, without changing the original protocol frame structure and service message format, achieving seamless compatibility with the existing power system. The execution entities are the edge-side power distributed terminal and the cloud-side secure access gateway, confirming the terminal device identifier, protocol version information, and post-quantum cryptography parameter set. The execution steps are as follows:

[0054] Step 2.1: The terminal device initiates a TCP connection request, completes a standard TCP three-way handshake with the secure access gateway, and establishes a reliable transport layer connection.

[0055] Step 2.2: The terminal device sends a session establishment request message to the secure access gateway. The request message contains the terminal's unique device identifier (asset number / device ID), the supported power communication protocol version number, and a list of supported post-quantum cryptography parameter sets.

[0056] Step 2.3: After receiving the request message, the secure access gateway first verifies the legality of the terminal device identifier and confirms that the terminal device has been registered in the power system key management system (KMS). After successful verification, it obtains the currently valid encryption key ek_PKE of the terminal device from the KMS.

[0057] Step 2.4: The secure access gateway returns a session response message to the terminal device. The response message contains the device identifier of the secure access gateway itself.

[0058] Step 2.5: After receiving the response message, the terminal confirms the selected post-quantum cryptography parameter set based on the device identifier of the secure access gateway and sends an acknowledgment message to the secure access gateway; both parties complete the TCP connection establishment and encapsulation key exchange, and prepare to enter the encryption key encapsulation stage.

[0059] Step 3: The secure access gateway performs key encapsulation operations:

[0060] This step is executed by the post-quantum cryptography service module of the cloud-side secure access gateway. The inputs are a 1184-byte encryption key ek_PKE uploaded by the terminal device, 32 bytes of plaintext m generated by the secure access gateway TRNG, and a 32-byte random number r. The outputs are a 1088-byte ciphertext c and a 32-byte shared session key ssk. The algorithm execution steps are as follows:

[0061] Step 3.1: The secure access gateway verifies the validity of the encryption key ek_PKE obtained from the terminal device: it verifies whether the encryption key length is 1184 bytes (as required by the parameter set of security level 3); it performs ByteDecode_12 decoding on the first 1152 bytes of the encryption key to verify that the value range of all integers is within [0, 3328], thus preventing maliciously constructed public key attacks.

[0062] Step 3.2: The secure access gateway calls the hardware TRNG to generate a 32-byte plaintext m, which is the core seed for generating the shared session key.

[0063] Step 3.3: Call the SHA3-512 hash function, with input m || SHA3-256(ek_PKE), and output a 64-byte hash value. Split the hash value into the first 32 bytes of the shared session key ssk and the last 32 bytes of the encrypted random number r.

[0064] Step 3.4: Initialize the counter N=0, which is independent of the terminal-side counter to ensure the uniqueness of the pseudo-random number.

[0065] Step 3.5: Perform ByteDecode_12 decoding on the first 1152 bytes of the encryption key ek_PKE to recover the NTT field vector. The decoding process also verifies that the values ​​of all integers are within the range of [0, 3328] to prevent maliciously constructed public key attacks.

[0066] Step 3.6: Extract the seed ρ from the last 32 bytes of the encryption key ek_PKE. This seed ρ is completely consistent with the seed generated on the terminal device side, ensuring that the secure access gateway side can generate the same NTT domain public key matrix  as the terminal device side.

[0067] Step 3.7: Regenerate the 3×3 public key matrix Â: Set the positional parameters (i,j) of the 3×3 matrix, i,j∈[0,2]. Perform a rejection sampling algorithm on ρ ||j ||i (32 bytes + 1 byte + 1 byte), outputting a uniformly distributed polynomial Â[i,j] over the NTT field. Each polynomial contains 256 integers modulo 3329. || is the concatenation operation. All polynomials Â[i,j] are used as the matrix Â. The process is exactly the same as on the terminal side, calling the rejection sampling algorithm to generate the matrix  based on the seed ρ. The matrix  can be pre-computed and cached on the gateway side, significantly improving the gateway's concurrent processing capability for massive numbers of terminals.

[0068] Step 3.8: Generate a random vector y: Process r || N (32 bytes + 1 byte) using the pseudo-random function PRF_η1(r, N) to output the polynomial y[0]. Increment N by 1 and repeat the calculation of polynomial y[i], i∈[0,2], to obtain polynomials y[1] and y[2] respectively. Use polynomials y[0], y[1], and y[2] as the random vector y, η1=3. The counter N increments by 1 after each component is generated.

[0069] Step 3.9: Generate noise vector e1: Perform a pseudo-random function PRF_η2(r, N) on r || N (32 bytes + 1 byte) to output polynomial e1[0]. Increment N by 1 and repeat the calculation of polynomial e1[i], i∈[0,2], to obtain polynomial e1[1] and polynomial e1[2] respectively. Use polynomial e1[0], polynomial e1[1] and polynomial e1[2] as noise vector e1, η2=2. The counter N increments by 1 after each component is generated. Here, the noise parameter η2=2 is used to further improve the operation speed while ensuring safety, and the same method is used to repeat step 3.9 to generate noise vector e2.

[0070] Step 3.10: Perform an NTT transformation on each component of the random vector y to obtain an NTT domain random vector. In the NTT domain, for  and Perform the matrix transpose-vector multiplication operation to obtain the result. The result is transformed using inverse number theory transformation (INTT). Transforming back to the time domain and adding the noise vector e1, we obtain the time-domain vector u. The INTT operation is also accelerated by hardware and takes about the same time as the NTT operation.

[0071] Step 3.11: Execute ByteDecode_1 to decode the 32-byte plaintext m, and then execute Decompress_1 to decompress it, converting the plaintext m into a plaintext polynomial μ. The plaintext m is the core seed for generating the shared session key.

[0072] Step 3.12: In the NTT domain... and Perform the matrix transpose-vector multiplication operation to obtain the result. Calling INTT will return the result. Transform back to the time domain, add the noise vector e2 and the plaintext polynomial μ to obtain the time domain vector v.

[0073] Step 3.13: Perform Compress_10 compression on each component of the time-domain vector u, compressing each 12-bit integer into 10 bits, and then perform ByteEncode_10 encoding to obtain a 960-byte ciphertext component c1. Perform Compress_4 compression and ByteEncode_4 encoding on the time-domain vector v to obtain a 128-byte ciphertext component c2. The compression operation effectively reduces the transmission overhead of the ciphertext and adapts to the narrow bandwidth characteristics of power line wireless public networks.

[0074] Step 3.14: Concatenate ciphertext components c1 and c2 to generate the final 1088-byte ciphertext c. The secure access gateway locally caches the mapping relationship between the terminal device identifier and the shared session key ssk, sets the session key validity period, and sends the ciphertext c to the corresponding terminal device.

[0075] Step 4: The terminal device performs the key decapsulation operation:

[0076] This step is executed by the security encryption chip of the edge-side power distributed terminal. The inputs are the 1152-byte decryption key dk_PKE stored internally in the security chip and the 1088-byte ciphertext c issued by the security access gateway. The output is a 32-byte plaintext m (completely identical to the plaintext generated by the security access gateway), used to finally generate the shared session key ssk, which serves as the session root key for subsequent encrypted communication of power business data. The algorithm execution steps are as follows:

[0077] Step 4.1: The terminal device receives the ciphertext c sent by the secure access gateway. First, it verifies whether the length of the ciphertext is 1088 bytes (as required by the security level 3 parameter set). If the length does not meet the requirement, it is discarded and the process is terminated.

[0078] Step 4.2: Split the ciphertext c, extract the first 960 bytes as ciphertext component c1, and extract the last 128 bytes as ciphertext component c2. Perform ByteDecode_10 decoding on ciphertext component c1, and then perform Decompress_10 decompression to recover the time-domain vector u'. Perform ByteDecode_4 decoding and Decompress_4 decompression on ciphertext component c2 to recover the time-domain vector v'.

[0079] Step 4.3: Read the decryption key dk_PKE from the encrypted partition of the security chip, perform ByteDecode_12 decoding, and recover the NTT field secret vector. .

[0080] Step 4.4: Perform the core decryption operation: First, perform an NTT transformation on the time-domain vector u' to obtain the NTT-domain vector û'; then, perform a matrix transpose-vector multiplication operation in the NTT domain. Calling INTT will return the result. Convert back to the time domain result; finally, subtract the time domain result from v' using the time domain result to obtain the polynomial w.

[0081] Step 4.5: Perform Compress_1 compression on the polynomial w to eliminate noise, and then perform ByteEncode_1 encoding to obtain 32 bytes of plaintext m'. This plaintext is completely consistent with the plaintext generated by the gateway.

[0082] Step 4.6: The terminal device derives the shared session key in the same way as the gateway: it calls the SHA3-512 hash function, with the input being m' || SHA3-256(ek_PKE), and outputs a 64-byte hash value. The first 32 bytes of the hash value are taken as the shared session key ssk'.

[0083] Step 4.7: The terminal device sends a key negotiation confirmation message to the secure access gateway. The key negotiation confirmation message contains a random challenge value encrypted using the shared session key ssk'. The secure access gateway uses the locally cached shared session key ssk to decrypt the challenge value and returns an encrypted response. The terminal device uses the shared session key ssk' to decrypt the encrypted response and verify its correctness, thus completing two-way authentication and session key synchronization.

[0084] Step 4.8: Both parties immediately clear and destroy all intermediate variables (m, r, m', ciphertext components, polynomial intermediate results, etc.).

[0085] The session key ssk does not directly participate in the encryption of business data, but serves as the session root key for the derivation of subsequent message encryption keys. Both communicating parties generate message-level encryption keys based on the key derivation function KDF, and use the SM4-256 algorithm with doubled key length to encrypt and transmit business data.

[0086] Step 5: Perform continuous evolution and reconstruction of session keys:

[0087] This step is executed collaboratively by the security encryption chip of the edge-side power distributed terminal and the post-quantum cryptography service module of the cloud-side security access gateway. The inputs are the shared session key 'ssk' generated in step four, the service message sequence, and the terminal device identifier. The output is the session key status, which is dynamically updated during the communication process. The specific execution process is as follows:

[0088] Step 5.1: After the shared session key ssk is established in Step 4, the terminal device and the secure access gateway use the shared session key ssk as the session root key to enter the continuous secure communication phase. The session root key ssk is not directly used for encrypting service data, but is used to derive the encryption keys for each service message and is continuously updated during the communication process.

[0089] Step 5.2: During the data transmission of the service, both communicating parties perform the following operations for the i-th power service message: call the key derivation function KDF, take the current session root key ssk and the message sequence number i as input, and generate the corresponding message encryption key mk_i; use mk_i to perform symmetric encryption on the service message; destroy mk_i immediately after the message processing is completed to avoid key reuse and reduce the risk of key leakage.

[0090] Step 5.3: After message encryption is completed, both communicating parties perform an update operation on the current session root key ssk to obtain a new session root key ssk ← KDF(ssk). This new key is used for subsequent encryption and decryption of service messages and for key derivation of the session root key, allowing the session root key to evolve gradually throughout the communication process. This update process is deterministic and does not introduce new randomness. Its purpose is to ensure that different messages use different encryption keys and to prevent historical keys from being derived in reverse, thereby improving the forward security of the system.

[0091] Furthermore, it also includes: Step 5.4: During continuous communication, both communicating parties maintain key reconstruction trigger conditions, and a new round of session key reconstruction process is triggered when preset conditions are met. The trigger conditions include: the number of service message transmissions reaches a preset threshold, the communication duration exceeds a set duration, or abnormal communication behavior is detected.

[0092] Step 5.4.1: After key reconstruction is triggered, similar to steps three and four, the secure access gateway calls the post-quantum cryptography key encapsulation mechanism to generate a new ciphertext c_new and a temporary shared key ssk_tmp based on the encapsulation key ek_PKE corresponding to the terminal device, and sends the ciphertext c_new to the terminal device; the terminal device uses the decryption key dk_PKE stored in its local security chip to perform decapsulation operation and recover the corresponding shared key ssk_tmp.

[0093] Step 5.4.2: Since the ssk_tmp is generated by the post-quantum cryptography mechanism and contains new randomness, the two communicating parties merge it with the current session root key ssk: call the key derivation function KDF, take the combination of ssk and ssk_tmp as input, generate the updated session root key ssk_new, and use ssk_new to replace the current session root key.

[0094] Step 5.4.3: After completing the key update, both communicating parties immediately clear and destroy the old session key and intermediate variables, including ssk_tmp, ciphertext cache and related intermediate calculation results, thereby completing the session key reconstruction process.

[0095] Through the aforementioned continuous evolution of session keys and the periodic reconstruction mechanism based on post-quantum cryptography, the system can avoid key reuse and achieve forward security during communication by evolving keys, and reconstruct the key state by introducing new randomness. Even if the session key is leaked at a certain moment in extreme cases, attackers will not be able to deduce the subsequent session key, thereby limiting the scope of security risk propagation and restoring communication security.

[0096] Example 2:

[0097] This embodiment describes a computer-readable storage medium storing a computer program that, when executed by a processor, implements a power distributed terminal secure communication method based on post-quantum cryptography as described in any of Embodiment 1.

[0098] Example 3:

[0099] This embodiment describes a computer device, including:

[0100] Memory is used to store instructions.

[0101] A processor is configured to execute the instructions, causing the computer device to perform operations as described in any of Embodiment 1, of a post-quantum cryptography-based secure communication method for distributed power terminals.

[0102] Example 4:

[0103] This embodiment is a simulation application example of a secure communication method for power distributed terminals based on post-quantum cryptography. The simulation scenario is set as secure communication between the distribution automation terminal (DTU) of a 10kV distribution transformer area in a city power grid and the cloud-side secure access gateway. It is used to verify the feasibility, technical characteristics, and quantum security advantages of the method in a real power business scenario. This embodiment uses typical hardware configurations that conform to the technological development roadmap of the power industry for simulation. All hardware capabilities are set based on the current technological evolution direction of national cryptographic chips, and this method is backward compatible with existing power terminal hardware platforms.

[0104] The simulation environment hardware configuration is as follows: The edge terminal simulates an industrial-grade power distribution automation terminal, equipped with an ARM Cortex-M7 core (216MHz), a built-in new-generation national cryptographic security encryption chip supporting post-quantum cryptography (compatible with national cryptographic SM2 / SM3 / SM4 algorithms, with SHA3 and NTT computation acceleration capabilities), 256KB RAM, and 2MB Flash, conforming to the power industry's industrial-grade standards; the cloud-side gateway simulates a power security access gateway, equipped with an 8-core Xeon processor (2.4GHz), 32GB memory, and a hardware acceleration module supporting post-quantum cryptography parallel computation, supporting concurrent access of 1000 terminals; the key management system (KMS) is independently deployed in the cloud business main station domain, equipped with a dedicated hardware cryptographic machine, storing all pre-registered keys for terminals; the communication network simulates a power wireless public network (4G), with a bandwidth of 10Mbps, an average network latency of 50ms, and a packet loss rate of 1%. In terms of software environment, the terminal side adopts the FreeRTOS real-time operating system, and the gateway side adopts the Linux operating system. The cryptographic algorithm library implements the post-quantum cryptography key encapsulation mechanism algorithm based on the NIST FIPS 203 standard, integrates the national cryptographic SM3 and SM4-256 algorithms, and sets up the original power system's common SM2 key negotiation + SM4-128 encryption scheme as a comparison group.

[0105] The simulation execution process first simulates the terminal's factory initialization and key pre-registration process in a production environment:

[0106] After the terminal security chip powers on, it calls a true random number generator (TRNG) conforming to the national cryptographic standard GM / T 0005 to generate two 32-byte true random seeds d=0x5A7F...9C2D and z=0x3B8E...7D1F. Internally, the security chip executes the post-quantum key encapsulation mechanism key generation algorithm, calling the SHA3-512 hash function. It inputs d, concatenates a 1-byte post-quantum key encapsulation mechanism default parameter set identifier 0x03, and outputs a 64-byte hash value, splitting it into a first 32-byte seed ρ and a last 32-byte seed σ. It initializes the counter N=0 and generates a 3×3 public key matrix  through a double loop, where each matrix element is a uniformly distributed polynomial in the NTT field. It then sequentially generates a secret vector s and a noise vector e following a central binomial distribution (η=3). After performing NTT transformations on s and e respectively, the vector is calculated in the NTT field. The final process generates a 1184-byte encapsulation key ek_PKE and a 1152-byte decapsulation key dk_PKE. The terminal binds its unique device identifier DTU-10kV-00127 with ek_PKE and submits it to KMS via an encrypted debugging channel to complete pre-registration. After verifying the terminal's legitimacy, KMS stores the mapping between the device identifier and ek_PKE in an encrypted database and writes the KMS root certificate and default post-quantum key encapsulation mechanism parameter set configuration into the terminal security chip. The terminal security chip writes dk_PKE into a one-time programmable (OTP) encrypted partition, sets it to non-exportable permissions, and then clears all intermediate variables. This step can be completed within the terminal's factory initialization timeframe. The NTT computation acceleration capability of the security chip significantly reduces computational overhead, meeting the requirements for mass production deployment.

[0107] Subsequently, the TCP connection establishment and post-quantum parameter negotiation process after the terminal was powered on was simulated in the field: After the terminal powered on and completed its hardware self-test, it initiated a TCP connection request to the secure access gateway with IP address 10.128.1.25 and port 8080, completing the standard three-way handshake to establish a reliable transport layer connection; the terminal sent a session establishment request message to the gateway, which contained the terminal's unique device identifier DTU-10kV-00127, the power communication protocol version number V2.0, and a list of supported post-quantum cryptographic parameter sets [security level 1, security level 3, security level 5], with a total message length of 128 bytes; after receiving the request message, the gateway sent the device identifier to the independently deployed KMS for legality verification. The KMS queried the encryption database to confirm that the terminal had completed pre-registration and was in normal status, and returned 1184 bytes of ek_PKE pre-registered data for the terminal; according to the unified security policy of the power system, the gateway selected security level 3 as the default parameter set for this communication and returned a message to the terminal containing the gateway identifier GW-POWER-003. The terminal sends a session response message with the selected parameter set, with a total message length of 64 bytes. Upon confirming that the selected parameter set is within its supported list, the terminal sends an acknowledgment message to the gateway, completing the TCP connection establishment and parameter negotiation process. This step is completely consistent with the connection establishment process of the original SM2 system, with roughly the same time consumption, achieving a seamless upgrade of services.

[0108] The subsequent post-quantum key encapsulation process on the secure access gateway side is executed: The gateway first verifies the legality of the acquired terminal ek_PKE, confirming its length as 1184 bytes. It then performs ByteDecode_12 decoding on the first 1152 bytes and verifies that all integer values ​​are within the range [0, 3328]. After successful verification, it calls the hardware TRNG to generate a 32-byte true random plaintext m=0x7C2D...5A8F as the core seed for generating the shared session key. It then calls the SHA3-512 hash function, taking m as input and concatenating it with the SHA3-256 hash value of ek_PKE, outputting a 64-byte hash value which is split into the first 32 bytes of the shared session key ssk=0x9E4B...3D7C and the last 32 bytes of encrypted random number r=0x2F6A...8E1B. Finally, it executes the post-quantum key encapsulation mechanism, initializes the counter N=0, extracts the seed ρ from ek_PKE, and regenerates a 3×3 key identical to the one on the terminal side. The public key matrix  is used to generate a random vector y, a noise vector e1, and a scalar noise polynomial e2. After performing an NTT transformation on y, a time-domain vector u and a polynomial v are calculated. u is compressed using Compress_10 and encoded using ByteEncode_10 to obtain a 960-byte ciphertext component c1. v is compressed using Compress_4 and encoded using ByteEncode_4 to obtain a 128-byte ciphertext component c2. c1 and c2 are concatenated to generate the final 1088-byte ciphertext c. The gateway locally caches the mapping between the device identifier and the SSK, sets the session key validity period to 1 hour, and sends the ciphertext c to the terminal. This step's computational efficiency can support the concurrent key negotiation needs of a massive number of power terminals, meeting the business requirements of large-scale terminal access in the power grid.

[0109] After receiving the ciphertext 'c' from the gateway, the terminal first verifies that its length is 1088 bytes, which meets the requirements of the post-quantum key encapsulation mechanism security level 3 parameter set. Then, the terminal's security chip internally executes the post-quantum key encapsulation mechanism decryption algorithm: splitting the ciphertext into 960 bytes c1 and 128 bytes c2, performing ByteDecode decoding and Decompress respectively to recover the time-domain vector u' and polynomial v'; reading dk_PKE from the security chip's OTP partition, and performing ByteDecode_12 decoding to recover the NTT domain secret vector. The core decryption operation yields a polynomial w, which is compressed using Compress_1 and encoded using ByteEncode_1 to obtain 32 bytes of plaintext m'=0x7C2D...5A8F, completely identical to the m generated by the gateway. The terminal derives a shared session key in the same way as the gateway, calling the SHA3-512 hash function with the input being m' concatenated with the SHA3-256 hash value of ek_PKE, resulting in a 32-byte shared session key ssk'=0x9E4B...3D7C, completely identical to the ssk on the gateway. The terminal sends a key negotiation confirmation message to the gateway, containing a 32-byte random challenge value 0x1A3B...7C9D encrypted using ssk'. The gateway uses its locally cached ssk to decrypt the challenge value and generates an encrypted response, returning it to the terminal. After verifying the response is correct, the terminal completes two-way authentication and session key synchronization. All private key operations in this step are performed in a closed loop within the security chip, with intermediate results not leaked outside the chip, meeting the security protection requirements for power terminals.

[0110] After the session key is established, both parties use ssk as the session root key to enter the continuous secure communication phase. For the first remote closing command message with a length of 64 bytes, the key derivation function KDF based on SM3 is called. The input is ssk and the sequence number of the concatenated message 0x00000001. The message encryption key mk_1 is generated and the command is encrypted and transmitted using SM4-256 using mk_1. mk_1 is destroyed immediately after the message is processed. After the message encryption is completed, both parties perform a one-way update operation on the current session root key, updating ssk to KDF (ssk), which is used for key derivation of subsequent messages. When the communication duration reaches 1 hour, a preset session key reconstruction process is triggered: the gateway re-executes the quantum key encapsulation mechanism algorithm to generate a new ciphertext c_new and a temporary shared key ssk_tmp, which is then sent to the terminal. After the terminal decapsulates and obtains ssk_tmp, both parties merge the current ssk and ssk_tmp to generate a new session root key ssk_new, and then destroy the old key and all intermediate variables, completing the key reconstruction. During the simulation, 1000 telemetry data packets, each 128 bytes, and 10 remote control command packets were continuously transmitted. All packets were successfully decrypted without data loss or errors. The encryption and decryption processing of a single service packet fully meets the real-time requirements of power control commands.

[0111] This embodiment compares and analyzes the core performance of the method of the present invention with that of the original SM2 scheme. The results show that: compared with the original SM2 scheme, the method of the present invention maintains a similar level in terms of business process, communication latency, and terminal resource consumption, and is fully compatible with the hardware capabilities and communication environment of existing power terminals; in terms of security performance, the present invention achieves NIST security level 3 and can effectively resist quantum computing attacks, while the original scheme can only resist classical computing attacks; the present invention supports message-level key evolution and periodic post-quantum key reconstruction, and has forward security and key leakage self-repair capability, while the original scheme does not have the above security features.

[0112] This embodiment fully verifies the practical application value of the method of the present invention, and its beneficial effects are mainly reflected in four aspects: First, it achieves quantum security protection. By adopting a post-quantum cryptographic key encapsulation mechanism to replace the SM2 algorithm for key negotiation, it can effectively resist Shor's algorithm attack of quantum computers, fundamentally solving the long-term security threat of "collecting first and then decrypting" faced by the power system; Second, it achieves seamless service upgrade. It fully reuses the existing power communication protocol stack and key management system, and the key negotiation process is the same as the original SM2. The solutions are basically the same and have no significant impact on the real-time performance of power services; thirdly, they have a high security design, achieving forward security and self-repair capability for key leakage through message-level key evolution and periodic post-quantum key reconstruction mechanisms. Even if the session key is leaked at a certain moment, attackers cannot decrypt historical and future data; fourthly, they have good hardware compatibility and smooth upgrade capability. This method can be implemented in pure software on existing national cryptographic security chips that have been deployed on a large scale. Quantum security transformation can be completed by upgrading the terminal firmware. At the same time, it can be smoothly adapted to the next generation of power terminals with post-quantum cryptography hardware acceleration capabilities in the future, making full use of hardware acceleration to further improve computing performance. Quantum security protection throughout the entire life cycle can be achieved without large-scale replacement of hardware devices.

[0113] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0114] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0115] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0116] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0117] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for secure communication of power distribution terminal based on post-quantum cryptography, characterized in that: Specifically, it includes: Step 1: The terminal device generates an encryption key and a decryption key, binds the device identifier to the encryption key, and submits it to the cloud-based power system key management system through the encryption debugging channel to complete the pre-registration. Step 2: The terminal device establishes a TCP connection with the security access gateway, and the security access gateway completes the encryption key exchange through the cloud-based power system key management system; Step 3: The secure access gateway generates ciphertext and a shared session key based on the encryption key, and sends the ciphertext to the terminal device; Step 4: The terminal device generates a shared session key based on the decryption key and the ciphertext; Step 5: The terminal device and the secure access gateway use the shared session key as the session root key for encrypted message communication and update the session root key, respectively. The updated session root key is used for subsequent encrypted message communication. 2.The power distributed terminal secure communication method based on post-quantum cryptography according to claim 1, wherein: Step 1 specifically includes: Step 1.1: When the terminal device is powered on and initialized, the true random number generator generates random seed d and random seed z respectively; Step 1.2: After concatenating the random seed d with the parameter set identifier, input it into the hash function, output the hash value, and split the hash value into seed ρ and seed σ; Step 1.3: Initialize counter N=0; Step 1.4: Set the position parameter (i,j), i,j∈[0,2], input ρ ||j ||i into the rejection sampling algorithm, and output the polynomial Â[i,j] in the NTT field. || is the concatenation operation. All polynomials Â[i,j] are used as matrix Â. The NTT field represents the number theory transformation field. Step 1.5: Input σ || N into the pseudo-random function PRF_η1(σ, N), output polynomial s[0], add N+1, and repeat the calculation of polynomial s[i], i∈[0,2], until N=2, to obtain polynomial s[1] and polynomial s[2] respectively, and use polynomial s[0], polynomial s[1] and polynomial s[2] as secret vector s; Step 1.6: Input σ || N into the pseudo-random function PRF_η2(σ, N) and output polynomial e[0]. Then, increase N by 1 and repeat the calculation of polynomial e[i], i∈[0,2], until N=2, to obtain polynomial e[1] and polynomial e[2] respectively. Use polynomial e[0], polynomial e[1] and polynomial e[2] as noise vector e; Step 1.7: Perform a number theoretic transform on each component of the secret vector s, resulting in an NTT domain secret vector s ; perform an NTT transform on each component of the noise vector e, resulting in an NTT domain noise vector e; Step 1.8: Compute the NTT domain vector from the secret vector s and the noise vector e , , denotes the matrix-vector multiplication; Step 1.9: Perform encoding on each component of the vector , get byte data, splice the byte data with the seed p, and generate the encryption key ek_PKE. Step 1.10: For the secret vector Each component is encoded to obtain the decryption key dk_PKE; Step 1.11: The terminal device binds the device identifier with the generated encryption key ek_PKE and submits it to the cloud-side power system key management system through the encryption debugging channel. After the power system key management system verifies the legitimacy of the terminal device's identity, it stores the mapping relationship between the device identifier and the encryption key ek_PKE in the encryption database, and at the same time writes the root certificate of the secure access gateway and the post-quantum cryptography parameter set list configuration into the terminal device. Step 1.12: Once the algorithm is complete, immediately clear and destroy all intermediate variables.

3. The secure communication method for power distributed terminals based on post-quantum cryptography according to claim 1, characterized in that: Step 2 specifically includes: Step 2.1: The terminal device initiates a TCP connection request, completes a standard TCP three-way handshake with the security access gateway, and establishes a transport layer connection; Step 2.2: The terminal device sends a session establishment request message to the secure access gateway. The request message contains the device identifier, the supported power communication protocol version number, and the list of supported post-quantum cryptography parameter sets. Step 2.3: After receiving the request message, the secure access gateway verifies the legality of the device identifier and confirms that the terminal device has been registered in the power system key management system. After successful verification, it obtains the currently valid encryption key ek_PKE of the terminal device from the power system key management system. Step 2.4: The secure access gateway returns a session response message to the terminal device, which contains the device identifier of the secure access gateway; Step 2.5: After receiving the response message, the terminal confirms the selected post-quantum cryptography parameter set based on the device identifier of the secure access gateway and sends an confirmation message to the secure access gateway.

4. The secure communication method for power distributed terminals based on post-quantum cryptography according to claim 1, characterized in that: Step 3 specifically includes: Step 3.1: The secure access gateway verifies the validity of the encryption key ek_PKE obtained from the terminal device; Step 3.2: The secure access gateway calls the true random number generator to generate plaintext m; Step 3.3: Input the encryption key ek_PKE into the hash function, concatenate the output hash value with m, and split the concatenated value into the shared session key ssk and the encrypted random number r; Step 3.4: Initialize counter N=0; Step 3.5: Perform decoding on the encryption key ek_PKE, recovering the NTT domain vector ; while verifying the NTT domain vector in the set range; Step 3.6: Extract the seed ρ from the encryption key ek_PKE; Step 3.7: Set the position parameters (i,j), i,j∈[0,2], input ρ ||j ||i into the rejection sampling algorithm, and output the polynomial Â[i,j] in the NTT field. || is the concatenation operation. All polynomials Â[i,j] are used as matrix Â. The NTT field represents the number theory transformation field. Step 3.8: Input r || N into the pseudo-random function PRF_η1(r, N) and output polynomial y[0]. Then, increase N by 1 and repeat the calculation of polynomial y[i], i∈[0,2], until N=2, to obtain polynomial y[1] and polynomial y[2] respectively. Use polynomial y[0], polynomial y[1] and polynomial y[2] as random vector y; Step 3.9: Input r || N into the pseudo-random function PRF_η2(r, N) and output polynomial e1[0]. Then, add N+1 and repeat the calculation of polynomial e1[i], i∈[0,2], until N=2, to obtain polynomial e1[1] and polynomial e1[2] respectively. Use polynomial e1[0], polynomial e1[1] and polynomial e1[2] as noise vector e1; Input r || N into the pseudo-random function PRF_η2(r, N) and output polynomial e2[0]. Then, add N+1 and repeat the calculation of polynomial e2[i], i∈[0,2], until N=2, to obtain polynomial e2[1] and polynomial e2[2] respectively. Use polynomial e2[0], polynomial e2[1] and polynomial e2[2] as noise vector e2; Step 3.10: Perform NTT transformation on each component of the random vector y, resulting in an NTT domain random vector ; Perform matrix transpose - vector multiplication operation on the NTT domain vectors , resulting in the result ; Convert the result back to time domain using inverse number theory transform, add the noise vector e1, resulting in the time domain vector u; Step 3.11: Decode the plaintext m, then decompress it to convert the plaintext m into a plaintext polynomial μ; Step 3.12: In the NTT domain... and Perform the matrix transpose-vector multiplication operation to obtain the result. Use inverse number theory transformation to transform the result Transform back to the time domain, add the noise vector e2 and the plaintext polynomial μ to obtain the time domain vector v; Step 3.13: Perform compression and encoding on each component of the time-domain vector u to obtain the ciphertext component c1; perform compression and encoding on the time-domain vector v to obtain the ciphertext component c2; Step 3.14: Concatenate ciphertext components c1 and c2 to generate ciphertext c; the secure access gateway caches the mapping relationship between the terminal device identifier and the shared session key ssk locally, and sets the session key validity period; send ciphertext c to the corresponding terminal device. 5.The power distributed terminal secure communication method based on post-quantum cryptography according to claim 1, wherein: Step 4 specifically includes: Step 4.1: The terminal device receives the encrypted message c sent by the secure access gateway; Step 4.2: Split the ciphertext c, extract ciphertext component c1 and ciphertext component c2; decode ciphertext component c1 and then decompress it to recover the time domain vector u'; decode and decompress ciphertext component c2 to recover the time domain vector v'. Step 4.3: Read the decryption key dk_PKE from the encrypted partition of the terminal device, perform decoding, and recover the NTT field secret vector. ; Step 4.4: Perform an NTT transform on the time-domain vector u' to obtain the NTT-domain vector û'; then perform a matrix transpose-vector multiplication operation in the NTT domain to obtain the result. Calling INTT will return the result. Convert back to the time domain result; subtract the time domain result from the time domain vector v' to obtain the polynomial w; Step 4.5: Compress the polynomial w, then encode it to obtain the plaintext m'; Step 4.6: Input the encryption key ek_PKE into the hash function, output the hash value, concatenate the hash value with the plaintext m', and extract the shared session key ssk' from the concatenated value; Step 4.7: The terminal device sends a key negotiation confirmation message to the secure access gateway. The key negotiation confirmation message contains a random challenge value encrypted using the shared session key ssk'. The secure access gateway uses the locally cached shared session key ssk to decrypt the challenge value and returns an encrypted response. The terminal device uses the shared session key ssk' to decrypt the encrypted response and verify its correctness, thus completing two-way authentication and session key synchronization. Step 4.8: The terminal device and the security access gateway immediately clear and destroy all intermediate variables.

6. The secure communication method for distributed power terminals based on post-quantum cryptography according to claim 1, characterized in that: Step 5 specifically includes: Step 5.1: The terminal device and the security access gateway share the session key as the session root key; Step 5.2: During the data transmission of the service message, perform the following operations for the i-th power service message: input the current session root key and message sequence number i into the key derivation function to generate the corresponding message encryption key mk_i; use mk_i to perform symmetric encryption on the service message for transmission; destroy the message encryption key mk_i immediately after message processing is completed; Step 5.3: After the message encryption is completed, the terminal device and the secure access gateway perform an update operation on the current session root key. The current session root key is input into the key derivation function to obtain a new session root key, which is used for subsequent encryption and decryption of service messages and key derivation of the session root key.

7. The secure communication method for power distributed terminals based on post-quantum cryptography according to claim 6, characterized in that: Step 5 further includes: Step 5.4: During continuous communication, when preset conditions are met, a new round of shared session key reconstruction process is triggered, specifically including: Step 5.4.1: After the shared session key reconstruction is triggered, the secure access gateway generates a new ciphertext c_new and a temporary shared key ssk_tmp based on the encapsulation key ek_PKE corresponding to the terminal device, and sends the ciphertext c_new to the terminal device; the terminal device uses the decryption key dk_PKE stored locally to perform the decapsulation operation and recover the corresponding temporary shared key ssk_tmp; Step 5.4.2: The terminal device and the security access gateway combine the current session root key and the temporary shared key ssk_tmp respectively and input them into the key derivation function to generate the updated session root key ssk_new, and use ssk_new to replace the current session root key; Step 5.4.3: After the terminal device and the security access gateway complete the shared session key update, they immediately clear and destroy the old session root key and intermediate variables.

8. The secure communication method for power distributed terminals based on post-quantum cryptography according to claim 7, characterized in that: The preset conditions include: the number of service message transmissions reaches a preset threshold, the communication duration exceeds a set duration, or abnormal communication behavior is detected.

9. A computer-readable storage medium, characterized in that: It stores a computer program, which, when executed by a processor, implements a power distributed terminal secure communication method based on post-quantum cryptography as described in any one of claims 1-8.

10. A computer device, comprising: include: Memory, used to store instructions; A processor for executing the instructions, causing the computer device to perform the operation of a post-quantum cryptography-based power distributed terminal secure communication method as described in any one of claims 1-8.