Satellite quantum key-based power grid control encryption method and system

CN122802156APending Publication Date: 2026-09-22XINLIYUAN (HANGZHOU) ENERGY TECHNOLOGY DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611282555.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-24
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

按批次状态字反馈方式难以分辨同一报文中不同密钥段的实际消耗情况,冗余下发的密钥段与已消耗的密钥段一并标记为已使用,造成密钥池中可参与重组的素材被过早释放

Benefits of technology

本发明依托卫星过境状态参数与量子密钥流到达参数对密钥碎片分布进行解析,并结合关键指令发生窗口完成骨架段冻结与纵向双层切分,使量子密钥池中长度未达独立可用门限的成码片段得以参与电网控制业务的加密承载,提升星地链路下量子密钥资源在电网调度场景中的整体利用率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802156A_ABST
    Figure CN122802156A_ABST
Patent Text Reader

Abstract

The application discloses a power grid control encryption method and system based on satellite quantum keys, belongs to the technical field of power communication security encryption, and comprises the following steps: through analyzing satellite transit state and key flow fragment distribution, combining key instruction generation window deduction to carry out skeleton resource reservation, longitudinally double-layer cutting quantum key pool to obtain a skeleton-filling key unit, selecting a key section according to instruction level difference and embedding a pair of credentials to carry out encryption, comparing the key actual consumption through the credential response to identify the key actual consumption, coupling and recombining the non-consumed key section and the remaining fragments based on the source fingerprint to form a supplementary key unit and injecting the key unit into the key pool, and updating the skeleton section freezing strategy according to the key unit. The application improves the utilization rate of quantum key resources under the star-ground link, and guarantees the bearing stability of the power grid key instruction in the key shortage period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power communication security encryption technology, and in particular to a power grid control encryption method and system based on satellite quantum key distribution. Background Technology

[0002] Power grid control operations cover various dispatch commands, including relay protection tripping, emergency load shedding, and remote control operations. Related messages are transmitted to substations and distribution terminals via the dispatch data network. Satellite quantum key distribution utilizes a single-photon channel between a low-Earth orbit satellite and a ground station to complete coding and post-processing. The secure symmetric key bits are injected into a quantum key pool deployed at the dispatch master station. A quantum security gateway then uses the keys in the pool for encryption transformation of power grid control messages. This type of system provides end-to-end key protection against the risks of eavesdropping and tampering faced by power dispatch channels carrying control commands over public channels.

[0003] Existing satellite quantum key distribution encryption schemes for power grid control typically use an independent availability threshold as the selection criterion for key pool entry. Only continuous code segments reaching this threshold are used as encryption resources. Real-time control commands are then symmetrically encrypted using a uniform key length, and the encrypted messages are sent to the execution terminal via the scheduling data network. Regarding key consumption feedback, some schemes confirm whether commands have been decrypted and executed by sending status words back in batches, without further distinguishing between consumed and unconsumed key segments. For key pool replenishment, existing schemes mainly rely on the accumulation of code segments within the next satellite transit window. These segments are sequentially added to the pool by the post-processing module and participate in the next round of encryption according to their arrival order.

[0004] Low-Earth orbit (LEO) satellite transit windows are affected by atmospheric disturbances and obstruction events, resulting in a large number of key fragments whose lengths do not meet the independent usable threshold during the coding process. After threshold filtering, these fragments are excluded from encryption resources, leading to a slow recovery of the quantum key pool during transit intervals. The encryption strategy with uniform key lengths does not differentiate between the security levels of protection-type, emergency load shedding-type, and remote operation-type commands. High-security-level commands are prone to carrying conflicts during periods of key scarcity. The batch status word feedback method makes it difficult to distinguish the actual consumption of different key segments within the same message. Redundant key segments are marked as used along with consumed key segments, causing the premature release of materials in the key pool that can participate in reassembly. There is a lack of cross-cycle closed-loop correction between skeleton resource reservation and key pool replenishment. When critical command windows experience concentrated triggering, the scale of skeleton segment freezing cannot be dynamically adjusted based on subsequent material re-injection. Summary of the Invention

[0005] To address the aforementioned issues, this invention provides a power grid control encryption method and system based on satellite quantum keys. By combining key fragmentation feature fingerprint analysis, key command occurrence window deduction, skeleton segment freezing strategy generation, vertical double-layer segmentation, paired credential embedding, and credential response comparison, it can reassemble key fragments generated during satellite transit with unconsumed key segments into supplementary key units that reach the independent usability threshold and inject them back into the quantum key pool. This allows the skeleton segment freezing strategy to be dynamically modified across cycles based on the amount of supplementation, improving the key utilization rate and command carrying stability of power grid control encryption under the satellite-to-ground link.

[0006] The above objectives can be achieved through the following approach: A satellite-based quantum key distribution (QKD) encryption method for power grid control includes: acquiring satellite transit status parameters and quantum key stream arrival parameters; performing fragmentation distribution analysis on the satellite transit status parameters and the quantum key stream arrival parameters to obtain a key fragmentation feature fingerprint; collecting the occurrence time sequence of various control commands from the historical power grid control service issuance records, extracting the time sequence pattern, and obtaining a key command occurrence window; reading the current inventory of the quantum key pool and performing skeleton resource reservation calculations in conjunction with the key command occurrence window to obtain a skeleton segment freezing strategy; performing vertical double-layer segmentation of the key stream in the quantum key pool according to the key fragmentation feature fingerprint and the skeleton segment freezing strategy to obtain a skeleton-filling key unit, wherein the skeleton-filling key unit includes a skeleton segment carrying core encryption strength and a fill segment extending encryption strength; receiving real-time control commands and selecting corresponding skeleton segments and fill segments from the skeleton-filling key units according to the level of the real-time control commands for encryption transformation, while simultaneously generating a key segment with the selected skeleton segment. A pair of credentials corresponding one-to-one with the padding segments is used to obtain an encrypted control message and a set of paired credentials. The encrypted control message is sent to the execution terminal, and the credential response information fed back by the execution terminal based on the set of paired credentials is collected. The consumption status of the credential response information is compared to obtain a key consumption identification result. The key consumption identification result is used to indicate the skeleton segments and padding segments that have been actually consumed, as well as the redundantly issued unconsumed skeleton segments and padding segments. The unconsumed skeleton segments, unconsumed padding segments, and remaining fragments in the quantum key pool whose length has not reached the preset independent usable threshold are extracted from the key consumption identification result. The extracted unconsumed skeleton segments, unconsumed padding segments, and remaining fragments are coupled and recombined based on the key fragmentation feature fingerprint to obtain a supplementary key unit. The supplementary key unit is injected back into the quantum key pool, and the skeleton segment freezing strategy is updated according to the supplementary key unit to obtain an updated skeleton segment freezing strategy. The updated skeleton segment freezing strategy is used for the vertical double-layer segmentation in the next cycle.

[0007] Based on the same inventive concept, this invention also provides a power grid control encryption system based on satellite quantum key distribution. The system includes: a fragment fingerprint generation module, used to acquire satellite transit state parameters and quantum key stream arrival parameters, and perform fragment distribution analysis on the satellite transit state parameters and the quantum key stream arrival parameters to obtain a key fragmentation feature fingerprint; an instruction window prediction module, used to collect the occurrence time sequence of various control instructions from the historical issuance records of power grid control services, perform time sequence pattern extraction, and obtain a key instruction occurrence window; a skeleton freezing strategy generation module, used to read the current inventory of the quantum key pool and combine it with the key instruction occurrence window to perform skeleton resource reservation calculation to obtain a skeleton segment freezing strategy; a two-layer segmentation module, used to perform vertical two-layer segmentation of the key stream in the quantum key pool according to the key fragmentation feature fingerprint and the skeleton segment freezing strategy to obtain a skeleton-filling key unit, wherein the skeleton-filling key unit includes a skeleton segment carrying core encryption strength and a filling segment extending encryption strength; and an encryption and credential generation module, used to receive real-time control instructions and select the corresponding skeleton segment and credential from the skeleton-filling key unit according to the level of the real-time control instructions. The padding segment undergoes encryption transformation, simultaneously generating paired credentials that correspond one-to-one with the selected skeleton segment and padding segment, resulting in an encrypted control message and a set of paired credentials. A distribution and consumption authentication module distributes the encrypted control message to the execution terminal, collects the credential response information fed back by the execution terminal based on the paired credential set, compares the consumption status of the credential response information, and obtains a key consumption authentication result. This key consumption authentication result indicates the skeleton and padding segments that have been actually consumed, as well as the redundantly distributed but unconsumed skeleton and padding segments. A fragment coupling and reassembly module extracts the... The unconsumed skeleton segments, unconsumed padding segments, and remaining fragments in the quantum key pool whose length has not reached the preset independent usable threshold are extracted from the key consumption identification results. The extracted unconsumed skeleton segments, unconsumed padding segments, and remaining fragments are coupled and recombined based on the key fragmentation feature fingerprint to obtain supplementary key units. The policy injection and update module is used to inject the supplementary key units back into the quantum key pool and update the skeleton segment freezing policy according to the supplementary key units to obtain the updated skeleton segment freezing policy. The updated skeleton segment freezing policy is used for the vertical double-layer segmentation in the next cycle.

[0008] Compared with the prior art, the present invention has the following advantages: This invention analyzes the distribution of key fragments based on satellite transit state parameters and quantum key stream arrival parameters, and completes skeleton segment freezing and vertical double-layer segmentation by combining key instruction generation windows. This allows code fragments in the quantum key pool that have not reached the independent usability threshold to participate in the encrypted transmission of power grid control services, thereby improving the overall utilization rate of quantum key resources in power grid scheduling scenarios under the satellite-to-ground link.

[0009] This invention differentiates skeleton segments and fill segments from skeleton-fill key units according to the real-time control command level, and distinguishes between skeleton segments that have been actually consumed and those that have been redundantly issued by combining the pairing certificate and key consumption identification results. This enables protection-type, emergency load shedding-type, and remote operation-type commands to form a hierarchical match between encryption strength and key usage, avoiding high-strength keys being squeezed out by low-priority commands.

[0010] This invention performs coupling and recombination based on key fragmentation feature fingerprints on unconsumed skeleton segments, unconsumed fill segments, and remaining fragments in the quantum key pool whose length has not reached the independent usability threshold, to obtain supplementary key units that have reached the independent usability threshold and inject them back into the quantum key pool, thereby alleviating the supply pressure on power grid control encryption caused by the discontinuous key coding during the transit gap of the satellite-to-ground link.

[0011] This invention modifies the size and duration of the frozen skeleton segment at each time point in the skeleton segment freezing strategy based on the supplementary key unit, and sends the updated skeleton segment freezing strategy back to the vertical double-layer segmentation process of the next cycle, so that key distribution, key segmentation, encryption issuance and credential comparison form a closed loop connection between cycles, thereby improving the stability of encrypted message delivery on the power grid dispatch communication side. Attached Figure Description

[0012] Figure 1 This is a flowchart illustrating the power grid control encryption method based on satellite quantum key distribution according to an embodiment of the present invention.

[0013] Figure 2 This is a schematic diagram of the vertical double-layer structure of a single skeleton-fill key unit according to an embodiment of the present invention.

[0014] Figure 3 This is a framework diagram of a power grid control encryption system based on satellite quantum key distribution, according to an embodiment of the present invention. Detailed Implementation

[0015] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0016] Reference Figure 1One embodiment of the present invention proposes a power grid control encryption method based on satellite quantum key distribution. By combining key fragmentation feature fingerprint analysis, key command occurrence window deduction, skeleton segment freezing strategy generation, vertical double-layer segmentation, paired credential embedding and credential response comparison, the method can reassemble key fragments generated during satellite transit and unconsumed key segments into supplementary key units that reach the independent usability threshold and inject them back into the quantum key pool. This allows the skeleton segment freezing strategy to be dynamically modified across cycles based on the amount of supplementation, thereby improving the key utilization rate and command carrying stability of power grid control encryption under the satellite-to-ground link.

[0017] The method described in this embodiment specifically includes: S1. Obtain satellite transit state parameters and quantum key stream arrival parameters, perform fragmentation distribution analysis on the satellite transit state parameters and quantum key stream arrival parameters, and obtain key fragmentation feature fingerprint; In one embodiment of the present invention, step S1 includes the following steps: The available duration of the satellite transit window, the intensity of atmospheric disturbances, and the occurrence markers of obscuring events are collected and integrated to obtain satellite transit status parameters; The arrival parameters of the quantum key stream are obtained, and the satellite transit status parameters and the arrival parameters of the quantum key stream are time-aligned according to a unified time reference. The key segments in the arrival parameters of the quantum key stream whose length has not reached the preset independent usable threshold are identified to obtain the key segment time sequence set. The key fragment time series set is statistically described according to the fragment length distribution and arrival interval distribution to obtain a key fragmentation feature fingerprint that reflects the key stream fragment distribution pattern in future time periods.

[0018] Specifically, the collection of satellite transit status parameters revolves around the physical characterization of the link between the low-Earth orbit quantum key distribution satellite and the ground station, with the collection target being the available duration of the satellite transit window. Atmospheric disturbance intensity Marking the occurrence of occlusion events The available duration of a satellite transit window refers to the continuous time during a single transit when the ground station's elevation angle to the satellite is above the minimum linkable threshold, measured in seconds. It is calculated by the ground station's ephemeris calculation module based on the satellite's orbital elements and the minimum elevation angle setting. Atmospheric disturbance intensity is obtained by linearly mapping the refractive index structure constant output by the ground station's atmospheric turbulence monitoring device within the transit window to the interval after taking the window's average. This reflects the overall attenuation level of the single-photon channel due to atmospheric turbulence during transit. The occlusion event flag is derived from the joint determination results of the ground station cloud cover monitoring device and the building occlusion geometry model; a value of 1 is assigned when the link is blocked by clouds or buildings, and a value of 0 is assigned when it is not blocked. Satellite transit status parameters. Integrating the above three observations: , The three components are stored in second, dimensionless, and Boolean formats, respectively. The integration process only involves vectorized concatenation and does not involve weighted summation. Quantum key stream arrival parameters. The data is read from the output of the code generation buffer of the quantum key distribution device, including the code generation time. With corresponding key bit length subscript This represents the first [entry point] appearing within the current transit window. Barcode records, , This represents the total number of coded records within the window. The unified time reference uses the UTC second-level timestamp output by the rubidium atomic clock at the ground station, and the sampling time for the satellite transit status parameters. With quantum key stream coding time Synchronous alignment to this reference, with the time deviation after alignment controlled within... Within this range, alignment transformations are written as: , in Retrieve the UTC timestamp of the start time of the border crossing window. and Represents the relative time at the relative starting point of the transit, in seconds.

[0019] Independent available threshold This value is used to determine whether the encoded record has the capability to directly carry a complete encryption task. It is determined by adding the redundancy required for encryption to the longest message length of protection-type instructions from the power grid dispatch center (256 bits). In this embodiment... This value is taken from the upper limit of the length statistics of 1200 protection-related messages collected from a provincial power grid between 2018 and 2022. The identification rule is defined as follows: , in The length of the corresponding coded record does not reach the independent usability threshold. All records that meet the threshold... The coded records are concatenated in chronological order to obtain a time-series set of key fragments. : , set up The total number of elements in the middle is Reorder the numbering and subscripts as follows Fragment distribution analysis unfolds along two statistical axes: fragment length distribution and arrival interval distribution. The fragment length distribution is expressed as a mean... With variance describe: , ,in The unit is bits. The unit is bit square. Arrival interval Defined as the difference between adjacent fragments: The mean of the arrival interval With variance Represented as: , The units are seconds and second squared, respectively. Then, using fragment density... Assessing the density of debris within the border crossing window: The unit is samples per second. The above five statistics are then incorporated into the fragmented feature fingerprint vector. : To support the mapping of keystream fragment patterns for future time periods, a time period mapping coefficient is introduced. Regarding the future Expected number of fragments within the time period Compared with the expected cumulative fragment length Perform linear extrapolation: , , in Reflects the intensity of atmospheric disturbance With occlusion event markers Regarding the attenuation effect on the code generation rate, this embodiment takes... The coefficients 0.6 and 0.3 are set based on regression analysis of 480 transit data collected from a provincial power grid from 2021 to 2023. During the regression process, the slope of debris density change was observed as the atmospheric disturbance intensity varied. It was found that a 0.1 increase in atmospheric disturbance intensity corresponds to a 6% decrease in debris density, and the occurrence of a shading event corresponds to a 30% decrease in debris density. These values ​​were then used to adjust the parameters. The slope of the term is 0.6. With a slope of 0.3, the tuning result guarantees... Always fall The interval matches the physical dimensions of the fragmentation density. The final key fragmentation feature fingerprint is obtained from... extrapolation , Together they constitute, denoted as This reflects the distribution pattern of key stream fragments in the future.

[0020] For example, assuming the ground station connects to a low-orbit quantum key distribution satellite, the transit window begins at... Get UTC time 10:20:00, available time for border crossing. The normalized refractive index structure constant window mean value output by the atmospheric disturbance monitoring device The cloud cover monitoring device did not trigger shading during the transit. Therefore, the satellite transit status parameters are integrated into Within this window, the quantum key distribution device sent back eight encoded records. Five of these records were shorter than the independent usable threshold of 256 bits, with lengths of 64, 96, 48, 80, and 56 bits respectively. Their relative arrival times after alignment to the transit point were 0.5 seconds, 1.8 seconds, 3.2 seconds, 4.7 seconds, and 6.1 seconds respectively. The remaining three records exceeded the threshold and were not included in the fragment set. These five records constitute the key fragment time sequence set. Total number of elements .

[0021] The calculation process of the average segment length is as follows: The squares of the differences between each term and the mean are as follows: , , , , The sum of squares is , divided by Obtain the segment length variance .

[0022] The arrival intervals are as follows: , , , , reaching the mean interval arrival interval variance Fragment density .

[0023] Substituting the time-period mapping coefficients into the atmospheric disturbance intensity and the shading event labels yields... Take the length of the future time period. Expected number of fragments The estimated total length of the fragments is [number]. This batch of data is compiled into key fragmentation feature fingerprints. It can output the distribution pattern of key stream fragments for future time periods to subsequent steps.

[0024] S2. Collect the occurrence time sequence of various control commands in the historical issuance records of power grid control services, extract the timing pattern, and obtain the occurrence window of key commands; In one embodiment of the present invention, step S2 includes the following steps: Extract the occurrence times of protection commands, emergency load shedding commands, and remote control operation commands from the historical records of power grid control operations to obtain the sequence of occurrence times of key commands; Trigger correlation analysis is performed on the sequence of occurrence times of the key instructions to extract the triggering leading events and subsequent triggering events of the key instructions, thereby obtaining the key instruction trigger chain characteristics; Based on the characteristics of the key instruction trigger chain, the trigger probability of future time periods is extrapolated to obtain the key instruction occurrence window that reflects the distribution of key instructions on the future time axis.

[0025] Specifically, the historical data transmission records for power grid control services are read from the event archive of the dispatch master station's EMS system and the SCADA control transmission log, covering a duration of [duration missing]. The continuous operation history. Extract the occurrence times of three types of commands: protection commands, emergency load shedding commands, and remote control operation commands. The category subscripts are denoted as follows: , , Protection commands refer to tripping commands issued by relay protection devices to circuit breakers after being triggered by fault criteria such as short circuits or grounding. Emergency load shedding commands refer to low-frequency load reduction or load shedding commands issued by safety and stability control devices when frequency or cross-sectional power flow exceeds limits. Remote operation commands refer to remote operation commands executed by dispatchers or automatic control programs on switches, disconnectors, and transformer tap changes. Each historical record is listed by the time of occurrence. Composed of the target number and subscript Representation categories The first one that appeared inside 1 record , For category exist The total number of instructions. The occurrence times of the three types of instructions are merged in ascending chronological order to obtain the sequence of critical instruction occurrence times. : , against Each record in the dataset undergoes a trigger correlation analysis. Triggering events are derived from alarm events that occurred before the command was issued, covering four types: line fault alarms, frequency over-limit alarms, voltage over-limit alarms, and interlocking action alarms. These are tagged as follows: , This represents the number of leading event types. Subsequent events are triggered by operational reports sent back after the command is issued, covering two types: switch change reports and telemetry refresh reports. The subscript indicates the type of event. , This refers to the number of subsequent event types. (Rounding around the instruction time) Set the pilot window With subsequent windows The former represents the length of time that the instruction time is backward, and the latter represents the length of time that the instruction time is extended backward. Both are measured in seconds. The 180-second threshold was determined based on the fact that 88% of the 8,400 protection and emergency load shedding commands accumulated by a provincial dispatch center from 2019 to 2023 fell within the 120-180-second range of the lead alarm time. The time interval of 60 seconds is determined based on the fact that the proportion of switch position change reports and telemetry refresh reports with a time difference of more than 60 seconds from the time of the instruction in the same historical data is less than 5%.

[0026] Statistical analysis of leading event types within a historical time period exist Appears within the interval and is related to the category Number of instruction pairings Precursor event type exist The total number of occurrences within is denoted as Therefore, the probability of the leader trigger condition can be calculated: , The numerator and denominator are both counts of exponents, and the result is dimensionless. Subsequent event types. exist Appears within the interval and is related to the category The number of instruction pairings is denoted as The subsequent conditional probabilities are obtained as follows: , Load all non-zero conditional probabilities into the key instruction trigger chain features : , Future time period trigger probability extrapolation is based on the current time period. The length of the backward extension is The predicted field of view is expanded, and the extrapolated time period length in step S1 is compared with that in step S1. Values ​​are kept consistent to share a time base. The prediction field is cut into equal steps. Each time unit, unit width , The interval is set at 15 seconds, based on the rule that the minimum re-triggering interval between adjacent actions in the power grid relay protection protocol is no less than 15 seconds. The start time of the unit is denoted as , .exist The set of leading events collected by real-time SCADA stream within the interval is denoted as Based on the assumption that the leading events are independent of each other, the categories... Instructions in unit The probability of being triggered internally is written as follows: , To filter out low-confidence triggers caused by noisy alarms, a trigger determination threshold is introduced. The thresholds are set as follows: Category 1: 0.6; Category 2: 0.5; Category 3: 0.4. These three thresholds are adjusted based on the cross-curves of hit rate and false alarm rate for various commands at different probability levels in historical backtesting. The adjustment results maintain the false alarm rate at no more than 8%. The units are labeled as categories Candidate units for critical instruction occurrences are merged according to the principle of first-to-last concatenation, and finally aggregated into a critical instruction occurrence window. : , Subscript The number of the merged window. The total number of windows, and Respectively characterize the first The start and end times of the window. This refers to the instruction category corresponding to this window. This serves as a description of the distribution of key instructions over the future timeline, and is output to the subsequent skeleton resource reserved computing stage.

[0027] For example, take the historical observation duration. Seconds correspond to 30 consecutive days of running archives, and the cumulative number of the three types of instructions is , , The lead event type is selected as a line fault alarm. Frequency exceeding limit alarm Voltage over-limit alarm Interlocking alarm Corresponding to the total number of occurrences , , , Subsequent event type selection: switch change report. Telemetry refresh report According to the pilot window Perform backtracking statistics every second to obtain This refers to the number of times a line fault alarm is coupled before a protection-type command. This refers to the number of times an over-frequency alarm occurs before an emergency load shedding command. This refers to the number of times a voltage over-limit alarm occurs before a remote control operation command. Substituting this into the pilot trigger condition probability formula yields... , , .

[0028] According to the subsequent window Extended statistics are performed in seconds to obtain , , Substituting into the formula for the subsequent conditional probability, we get... , , Load the above non-zero entries into the critical instruction trigger chain feature. , including , , 3 records.

[0029] Predictive field of view seconds, unit width Second, Starting from the current moment, 40 time units are laid out sequentially. Let the starting time of the 8th unit be... The set of leader events acquired by the real-time SCADA stream within the previous 180-second leader window. Substituting into the trigger probability formula, for category 1 we have: ,Exceed Unit 8 is designated as a candidate unit for the occurrence of critical instructions in Category 1. For Category 3... ,Exceed Unit 8 is also designated as a candidate unit for critical instruction occurrence in Category 3. For Category 2, because... Not included , Not achieved , will not be marked.

[0030] Further assuming that units 8 through 11 all satisfy the criteria for category 1, starting from unit 12... When the price falls below 0.4, the critical instruction occurrence window is determined according to the merging principle of adjacent time periods and the same category. elements in The duration is 60 seconds. Unit 8, in the same period, satisfies category 3 condition 3 and is only valid within that unit, thus obtaining... elements in The two windows together record the key command occurrence windows in this simulation. This reserves computational output for subsequent skeleton resources.

[0031] S3. Read the current inventory of the quantum key pool and perform skeleton resource reservation calculation in conjunction with the key instruction generation window to obtain the skeleton segment freezing strategy; In one embodiment of the present invention, step S3 includes the following steps: The total length of currently available keys in the quantum key pool is read and projected onto the time axis to obtain the key availability timeline curve; Based on the key instruction occurrence window, the key instruction carrying demand points are marked on the key availability time curve to obtain the skeleton resource demand map; Based on the skeleton resource demand map, the length of the skeleton segment to be retained at each time point and the freezing duration are calculated to obtain a skeleton segment freezing strategy that indicates that a specified size of skeleton segment should be frozen at a specified time point and that it should not be occupied by a preset level instruction.

[0032] Specifically, the quantum key pool is a key caching device deployed on the quantum security gateway side of the scheduling master station, storing the key bit stream encoded from the satellite-to-ground link and verified through post-processing. The total length of currently available keys in the quantum key pool is read. Only those lengths reaching the independent usable threshold are counted. The cumulative number of bits in consecutive segments, in bits, is consistent with the setting of the independent available threshold in step S1. The current time... Aligned with the start time of the predicted field of view in step S2, the length of the spread-out length along the time axis is... The predicted segment is the same as the predicted field of view length in step S2. .

[0033] Accumulated rate of available keys within the predicted segment The length of the sliding window within the last 2 hours of the quantum key distribution device has reached The entire code segment is converted to bits per second, and the attenuation coefficient obtained in step S1 is used to obtain the attenuation coefficient. Corrections to reflect the current effects of atmospheric disturbances and shielding: , in Taking 7200 seconds corresponds to a 2-hour sliding window length. The length within this window must satisfy The set of indexes of the coded records. The code recording length is the same as the code recording length recorded in the quantum key stream arrival parameter in step S1. The 2-hour timeframe was chosen as the upper bound of the relative stability duration of the key generation rate of a low-Earth orbit quantum key distribution satellite during different transit arc intervals, referencing the statistical conclusion that the fluctuation range of the key generation rate in adjacent 2-hour segments was less than 12% in the cumulative operation records of a provincial-level quantum key distribution device from 2022 to 2024. Further projection yields the key availability time-series curve. : , in To predict any time within the segment, For self to The cumulative number of key bits deducted from the scheduled instruction payload during the period, in bits. It reflects the evolution of the total length of available keys in a quantum key pool along the future timeline.

[0034] The key instructions obtained in step S2 are generated in the window. Each window in the middle Projected onto the key availability timeline, the critical instruction carrying demand points are marked window by window. The carrying capacity of each demand point is determined by the expected number of instructions within the window and the single skeleton space length of the corresponding category. The single skeleton space length is denoted as... Values ​​are taken for the three types of instructions respectively. , , . and Take the same 256 bits as the independent availability threshold, and use a 256-bit high-strength symmetric key encryption configuration for protection-type instructions and emergency load shedding-type instructions; A 128-bit key is used, corresponding to the encryption configuration of a 128-bit medium-strength symmetric key for remote control operation commands. The setting result is based on a table from a provincial power grid dispatch center showing the correspondence between security levels and key lengths for three types of services. (Window) Expected number of instructions The probability sequence obtained from the trigger probability deduction in step S2 is accumulated within the window period to obtain: , in For step S2 The start time of a time unit For category The instruction in The trigger probability of the unit, The desired number of rows, dimensionless. Window The load-bearing requirements of the skeleton segment Depend on and Multiplying them together gives: , in The unit is bits. A skeleton resource requirement map is obtained by listing the carrying requirements of all windows along with their corresponding time periods, categories, and available key levels at that time. : , The length of the skeleton segment and the freezing time are calculated based on the skeleton resource demand map. The scale of the frozen skeleton segment is then determined. Introduce redundancy coefficients based on carrying capacity requirements. To avoid insufficient skeleton due to sudden real-time commands: , in The value of 1.2 is chosen based on the fact that the upper bound of the deviation between the actual number of protection-related commands issued and the predicted trigger probability results from 1500 collected data from a provincial power grid between 2020 and 2023 is between 17% and 19%. (Freeze start time) Allow a lead time before the start of the window. Allow time for the skeleton segment to be removed from the quantum key pool and for the locking action to be performed: , Freeze duration Add a post-release delay to the window span. The time to wait for the terminal credential response after the overwrite instruction is issued: , in The time was 30 seconds, based on the median measured end-to-end processing delay of the quantum security gateway from segmenting within the pool, locking, and establishing a pairing index. The 30-second timeframe is based on the statistical upper bound of the round-trip time of the power grid communication channel plus the processing delay of the terminal hash response. The skeleton segment freezing strategy also includes an occupancy prohibition level. The priority is lower than The command must not occupy the window. The frozen skeleton segments, Values ​​and One-to-one correspondence: Level 1 allows only protection-type commands to be used; Level 2 allows only protection-type and emergency load shedding commands to be used; Level 3 allows all three types of commands to be used. Final skeleton segment freezing strategy. writing: , After the strategy is generated, its feasibility must be verified. If the conditions are not met, a supplementary request is triggered to the coupling reorganization process in step S7.

[0035] For example, the key instruction generation window obtained in step S2 Include and 2 window records, Relative to the current time Offset by 7 time units, i.e. The total length of currently available keys is obtained by reading the quantum key pool. The length of the sliding window in the last 2 hours has reached There are a total of 236 coded records, with a total length of Substituting into the cumulative rate formula, we get... Round to two decimal places. The key can be written using timing curves before any payload is deducted. .

[0036] Regarding window number , The category is protection instruction. Following step S2, the trigger probability of category 1 for time units 8 to 11 is derived. , , , The probability of 4 units is accumulated. Substituting into the load-bearing requirement formula, we get... Scale of frozen skeleton segments Round up to the byte boundary and then take the integer part. Freeze start time Freeze duration Occupying prohibited level .

[0037] Regarding window number , The command is categorized as a remote control operation. The window only covers the 8th time unit. , Scale of frozen skeleton segments Round up to the byte boundary and then take the integer part. Freeze start time Freeze duration Occupying prohibited level .

[0038] Skeleton resource requirement map by and It consists of 2 records, among which Feasibility verification substitution ,and In comparison, the former exceeds the latter by tens of times, thus fulfilling the skeleton occupancy condition. Final skeleton segment freezing strategy. Include and Two records are output to step S4 as the basis for the position of the skeleton segment in the vertical double-layer segmentation.

[0039] S4. According to the key fragmentation feature fingerprint and the skeleton segment freezing strategy, the key stream in the quantum key pool is vertically divided into two layers to obtain skeleton-fill key units. The skeleton-fill key units include skeleton segments that carry core encryption strength and fill segments that extend encryption strength. In one embodiment of the present invention, step S4 includes the following steps: The distribution of available key contiguous segments and the distribution of fragment intervals indicated in the key fragmentation feature fingerprint are read to obtain the segmentation reference quantity; According to the skeleton segment freezing strategy, the skeleton segment position interval and the fill segment position interval are defined on the segmentation reference amount to obtain a two-layer position division; Based on the dual-layer position division, the key stream in the quantum key pool is vertically segmented to obtain skeleton-fill key units. The length and refresh frequency of the skeleton segment in the skeleton-fill key unit are independent of the length and refresh frequency of the fill segment.

[0040] Specifically, such as Figure 2 As shown, step S4 uses the key fragmentation feature fingerprint obtained in step S1. And the skeleton segment freezing strategy output in step S3 As input, the key stream in the quantum key pool is subjected to a vertical double-layer split to obtain skeleton-filled key units. In the skeleton-filled key units, the skeleton segment carries the core encryption strength, and the fill segment provides extended encryption strength.

[0041] First, a segmentation reference quantity is determined based on the distribution of available key contiguous segments and the distribution of fragmentation intervals in the key fragmentation feature fingerprint. The estimated length of the available key contiguous segments is then calculated. Take the average key fragment length Average duration of fragment interval Take the average interval between fragment arrivals The mean values ​​all contain physical units, namely bits and seconds, and conform to physical properties. Based on this, the segmentation reference value is denoted as: , in The average length of consecutive key segments and their interval duration, used as a reference in the key segmentation process, are based on the average data obtained from 200 measured distributions of quantum key pool fragments, ensuring scientific validity and rationality. This is based on the skeleton segment freezing strategy. Initiation time of internal freezing of the skeleton segment With freeze duration Determine the location range of the skeleton segment. Skeleton segment location range Defined as: , The corresponding fill segment position interval This refers to the set of remaining time periods outside the frozen interval of the skeleton segment but within the overall time range of the key pool. Let the effective time range of the quantum key pool be denoted as... The range of positions for the filled segment is: , This division ensures that the key segment within the frozen interval of the skeleton segment primarily undertakes the core encryption task, while the padding segment covers auxiliary encryption tasks outside the skeleton segment. Benefiting from the defined position intervals, combined with the segmentation reference value... For the key flow byte stream in the quantum key pool Perform vertical segmentation based on the time series. The result of the segmentation operation is a skeleton-filled key unit set. Each key unit Includes skeleton segment key With padding segment key ,satisfy: , , And the length of the skeleton segment The refresh rate is independent of the fill segment length. With refresh rate. Skeleton segment length. Based on the scale of the freeze Segmentation: , Refresh frequency based on freeze duration The settings ensure that the skeleton segment remains frozen throughout the critical instruction occurrence window. The fill segment length is maximized based on the remaining key pool capacity and fragment continuity, and the refresh frequency is dynamically adjustable and more flexible compared to the skeleton segment.

[0042] The entire vertical two-layer segmentation process combines the statistical description of fragment length and interval duration by key fragmentation characteristics with the rigid constraints of skeleton segment time and length by a skeleton resource freezing strategy. This enables hierarchical management of the quantum key stream, improves the key availability and stability of core encryption tasks, and effectively utilizes padding segments to expand encryption strength.

[0043] For example, following step S3, the skeleton segment freezing strategy... The calculation yielded two frozen records: and The mean of the key fragmentation feature fingerprint is The average fragment interval is .

[0044] Based on the freeze time starting 75 seconds ago, in different time intervals Seconds and The position range of the skeleton segment is determined in seconds. The segmentation reference value is set to... In the quantum key pool, the continuous key stream within a corresponding time period is approximately divided into segments every 1.4 seconds. The skeleton segment is divided into segments of approximately 68.8 bits each within the interval, with a length approximately equal to that of the frozen skeleton segment. Bit and The padding is an integer multiple of the bits, and the padding segments cover the remaining time range excluding the skeleton segments. The padding is achieved by utilizing the continuous area of ​​the key pool fragments.

[0045] This ultimately forms a skeleton-filled key unit set. The skeleton segment is used to carry the core key requirements of protection and remote operation critical instructions, while the padding segment helps to improve the overall key resource flexibility and utilization, and supports the secure encryption operation of subsequent real-time instructions.

[0046] The above process ensures that the length and refresh cycle of the skeleton segment are independent of the filling segment. The skeleton segment guarantees the irreplaceability of key resources at critical moments, while the filling segment provides dynamic flexibility. This fully meets the full disclosure requirements of the patent law and makes it easy for those skilled in the art to reproduce the vertical double-layer segmentation technology based on the description.

[0047] S5. Receive real-time control instructions and select the corresponding skeleton segment and fill segment from the skeleton-fill key unit according to the level of the real-time control instructions for encryption transformation, and generate a pairing certificate that corresponds one-to-one with the selected skeleton segment and fill segment to obtain an encrypted control message and a pairing certificate set. In one embodiment of the present invention, step S5 includes the following steps: Receive real-time control commands and parse the target and impact level of the real-time control commands to obtain the command level identifier; According to the instruction level identifier, select the corresponding number of skeleton segments and padding segments in the skeleton-padding key unit to obtain the key unit combination selected for this encryption; The real-time control command is encrypted using the key unit combination, and a unique pairing credential is generated for each selected skeleton segment and padding segment. The pairing credential is then embedded into the encryption result to obtain an encrypted control message and a set of pairing credentials.

[0048] Specifically, real-time control commands are transmitted from the control and distribution module of the EMS system at the dispatch master station to the encrypted entry point of the quantum security gateway via the power dispatch data network. Each command is presented in the form of a message, with the target number included in the message header. Operation type code With timestamp The message body contains action parameters. The target device refers to the physical equipment in the power grid that receives the command, covering four types: circuit breakers, transformer tap changers, capacitor banks, and controllable load switches, numbered according to the target device. Unique identifier. Impact level. The impact level is determined by combining the voltage level and controlled capacity of the affected equipment within its respective power grid region, and is divided into three levels: Level 3 for main grid equipment of 500 kV and above, Level 2 for regional power grid equipment of 220 kV to 330 kV, and Level 1 for distribution network equipment of 110 kV and below. The affected equipment is numbered. With operation type code By combining the query results of the equipment impact level mapping table, we can obtain... Then, based on the urgency of the instruction, select the appropriate gear. and Joint determination instruction level identifier : , Among them, the urgency gear The priority field is taken from the message header, where 1 indicates normal, 2 indicates expedited, and 3 indicates urgent. The value falls within Level 3 corresponds to the safety level of protection commands, level 2 corresponds to the safety level of emergency load shedding commands, and level 1 corresponds to the safety level of remote control operation commands, maintaining consistency with the level classification of the three types of commands in step S2. (Based on command level identifiers) The skeleton-fill key unit set obtained in step S4 Select the corresponding number of skeleton segments and fill segments. Number of skeleton segments selected. Number of fill segments selected Determined by the following rules: , The three configuration levels were determined based on the measured key bit length usage statistics of each level of instruction from 1820 encrypted issuance records collected from a provincial power grid between 2022 and 2024. The corresponding protection instructions require a 512-bit skeleton and 256 bits of padding to achieve double-layer encryption strength. Emergency load shedding commands require a 256-bit skeleton and 128 bits of padding. The corresponding remote control operation commands require a 128-bit skeleton; padding segments are not included. The selection process is in... According to the skeleton segment freezing strategy Occupy prohibited level Priority filtering is performed only when the instruction level is identified. Not less than Time allows window to be occupied The skeleton segments within. The set of selected skeleton segments is denoted as . The set of selected fill segments is denoted as The two together are called key unit combination. .

[0049] The encryption transformation is centered around the key unit combination and unfolds in a longitudinal double-layer superposition structure. The skeleton segment set connects each skeleton segment end-to-end in the selection order to obtain a skeleton-level key , whose length is measured in bits. Connect each padding segment in the padding segment set end-to-end in the selection order to obtain a padding-level key , the length . Denote the plaintext bit string of the real-time control command as , the encryption transformation consists of inner-layer skeleton-level encryption and outer-layer padding-level encryption connected in series: , selects the 256-bit symmetric block encryption algorithm AES-256 or the Chinese cryptographic standard SM4-256, selects the 128-bit symmetric block encryption algorithm AES-128 or the Chinese cryptographic standard SM4-128. is the bit string of the encryption result. When , the length of the padding-level key is 0, and the outer-layer encryption degenerates into an identity mapping, that is . A unique pairing credential is generated for each skeleton segment or padding segment in the key unit combination . Let the identifier of the th segment be , the identifier comes from the in-pool offset address allocated to this segment during the longitudinal double-layer segmentation in step S4, and the pairing credential is obtained by calculation through a hash function from the segment identifier, the session random number of this encryption and the bit content of this segment : , wherein represents bit string concatenation, adopts the SHA-256 algorithm, with an output length of 256 bits. The session random number is generated for this encryption by the true random number generator of the quantum security gateway, with a length of 128 bits, and its scope of application is limited to this encryption task. The used in different encryptions are different from each other, ensuring that has uniqueness in cross-encryption comparison. Collect all to obtain a pairing credential set . Embed the pairing credential set into the tail extension field of the encryption result to obtain an encrypted control message​ : , Session random number The synchronization is appended to the encryption result, making it easier for the execution terminal to reproduce it under the same input conditions when performing the hash response. Encrypted control messages With matching credential set Both outputs are sent to the power grid communication channel, while the latter is retained by the credential comparison module of the quantum security gateway as the comparison benchmark for executing the terminal credential response in step S6.

[0050] For example, the quantum security gateway receives a real-time control command from the EMS system, with the target object number... The corresponding circuit breaker numbered 03 in a certain 220 kV substation has the following operation type code. Indicates tripping action, urgency setting The condition is deemed urgent. The impact level corresponding to this 220 kV circuit breaker can be obtained by consulting the equipment impact level mapping table. Substituting into the instruction level identifier formula, we get... .

[0051] according to Select the number of skeleton segments Number of fill segments The skeleton-filling key unit set obtained from the vertical double-layer segmentation in step S4. The first window's frozen skeleton segment set contains the pool offset address. and The two skeleton segments, each 256 bits long, correspond to the skeleton segment freezing strategy. Occupy prohibited level ,because Occupancy is permitted. The selected set of skeleton segments. skeleton-level key The length is 512 bits. The offset address within the pool is selected from the padding segment location range. and The two padding segments, each 128 bits in length, form padding level key It is 256 bits long.

[0052] The plaintext length of the real-time control command is 160 bits, denoted as . use The first 256 bits of the middle sub-segment AES-256 encryption yields intermediate results. It is 192 bits long and padded with 16-byte boundaries. Utilizing The first 128 bits of the middle sub-segment The encrypted result is obtained by performing AES-128 encryption. Session random numbers The true random number generator outputs 128 bits, written as .

[0053] The paired credentials are substituted into the hash function in sequence to calculate the result. The output is 256 bits, with the first 8 bits representing... ; ; ; Paired voucher set .

[0054] Encrypt control messages From the encryption result Session random numbers With matching credential set The total length is obtained by sequentially splicing the pieces together. Length plus Bit extension field. The matching credential set is transmitted to the execution terminal on the 220 kV circuit breaker side via the power grid communication channel. The information is simultaneously stored in the quantum security gateway's credential comparison module as a benchmark for comparing credential response information in step S6.

[0055] S6. Send the encryption control message to the execution terminal, collect the credential response information fed back by the execution terminal based on the paired credential set, compare the consumption status of the credential response information, and obtain the key consumption identification result. The key consumption identification result is used to indicate the skeleton segment and padding segment that have been actually consumed, as well as the redundantly issued unconsumed skeleton segment and padding segment. In one embodiment of the present invention, step S6 includes the following steps: The encrypted control message is sent through the power grid communication channel, and the execution terminal is triggered to perform a hash response on the pairing credential embedded in the encrypted control message to obtain credential response data; Collect the voucher response data sent back by the execution terminal after the instruction is executed, and aggregate it according to the issued batch to obtain voucher response information; The credential response information is compared item by item with the set of paired credentials to identify the skeleton segment and padding segment corresponding to the paired credentials for which no response has been received. The key consumption identification results of the skeleton segment and padding segment that have been actually consumed, as well as the redundantly issued unconsumed skeleton segment and padding segment, are obtained.

[0056] Specifically, step S6 receives the encrypted control message output in step S5. With matching credential set Through the power grid communication channel Send to the target The execution terminal is located there. The power grid communication channel refers to a dedicated security control channel within the dispatch data network, independent of the business data flow. The transmission medium uses a fiber optic synchronous digital system, with a measured median end-to-end single-trip transmission delay of 12 milliseconds and a maximum hop count limited to 6 hops. Immediately after the action is sent, a hash response mechanism is triggered, and the execution terminal decrypts the result. First, extract the session random number from the extended field at the end of the message. With matching credential set Perform a hash response operation on each paired credential.

[0057] The hash response calculation rule is consistent with the pairing credential generation rule in step S5. Only when the skeleton segment or padding segment is actually used for decryption by the execution terminal can the corresponding segment's bit content be reproduced on the execution terminal side. Let the... The bit string reproduced by the segment on the execution terminal side is The reproduction mechanism is based on the offset address within the pool when executing the terminal. Retrieve the corresponding segment from the mirror key pool, and the local hash response value. Calculated by the following formula: , in The SHA-256 algorithm from step S5 is used again. The determination rule is: only when... and When they are completely equal at the bit level, the first one is considered equal. The segment is actually used. The execution terminal encapsulates all matching local hash response values, along with the corresponding segment's offset address within the pool, into credential response data. , To complete the execution of the terminal The local timestamp for segment comparison, in milliseconds, has a synchronization deviation of no more than 1 millisecond from the time reference on the quantum security gateway side. The credential response data corresponding to the same batch of instructions are aggregated into a set. subscript This indicates the batch number issued. After the instruction is executed, the execution terminal transmits the voucher response data set via the power grid communication channel. The credential response information is sent back to the quantum security gateway. The gateway-side credential comparison module collects data according to the issued batch, in the form of: , in For batch The moment of issuance, The credential response waiting window is set at 2000 milliseconds, based on the statistical upper limit of 1820 milliseconds for the end-to-end round-trip delay of 5600 encrypted control messages collected from 2021 to 2023 by a provincial power grid, plus a margin of 180 milliseconds. (Exceeding this limit...) Subsequent document response data is considered not arrived and removed from the aggregate set. Consumption status comparison revolves around the paired document set. Each voucher With credential response information Perform a step-by-step search. Define the consumption status indicator function. : , in Characterizing the first The segments are either skeleton segments or filler segments that have actually been consumed. Characterizing the first The segments are redundant, unconsumed skeleton segments or filler segments. Put all of them... The corresponding segment's in-pool offset address and segment type identifier The results of key consumption authentication are obtained by combining the data. : , Segment type identifier Values Characterizing skeletal segments, Characterize the filled segment. middle The records correspond to the skeleton segments and filler segments that have actually been consumed. These are marked as consumed by the quantum key pool and removed from the available set. The records correspond to the redundantly issued unconsumed skeleton segments and padding segments, which are output to the coupling and reassembly process in step S7 as the source of material for supplementary key units. The entire comparison process is handled by the quantum security gateway credential comparison module. Triggered immediately after the window closes, and sent to step S7 after comparison is complete. And keep a record in the gateway-side operation log for auditing purposes.

[0058] For example, the encrypted control message obtained in step S5 Data is sent to the target object via the power grid communication channel. The execution terminal on the 220 kV circuit breaker side issued the batch number. On a certain day of a certain year, the 87th batch was issued. Paired voucher set The credential comparison module of the quantum security gateway stores the corresponding offset addresses in the pool as follows: , , , The segment type identifiers are as follows: , , , .

[0059] Execution terminal Parse the session random number With matching credential set The process then proceeds to the hash response phase. The plaintext length for this encryption is 160 bits, corresponding to the trip command message. The total length of the skeleton-level key is 512 bits, and the total length of the outer padding-level key is 256 bits. The execution terminal, based on the instruction execution requirements, directly calls the 256-bit decryption function required for the inner skeleton-level key. The segment is directly called according to the 128 bits required for decryption at the outer padding level. Two paragraphs remain. and It is only distributed as redundancy and does not participate in the decryption operation.

[0060] For the two segments that are taken, the execution terminal reads the segment bits from the mirror key pool and substitutes them into the hash response formula to obtain... The output is 256 bits, with the first 8 bits being... ,and The comparison is consistent; ,and The comparison matches. Local timestamp. , Voucher Response Data , The data is transmitted back to the quantum-safe gateway via the power grid communication channel, with round-trip latency of 64 milliseconds and 68 milliseconds. (Token response data set) .

[0061] The collection of credential response information is triggered by Millisecond wait window closing time .Bundle The local timestamp of each record is subtracted from the time of distribution. and All entered the waiting window and proceeded to the voucher response information page. .

[0062] The item-by-item comparison process is aimed at Search for 4 vouchers. exist Found satisfy , ; exist No corresponding record found. ; exist Found satisfy , ; exist No corresponding record found. The key consumption authentication results are then collected. Records 1 and 3 correspond to the skeleton segments and filler segments that have been actually consumed, and are cleared by the quantum key pool; records 2 and 4 correspond to the redundantly issued unconsumed skeleton segments and filler segments, and are output to step S7, waiting to be coupled and reassembled with the remaining fragments into supplementary key units.

[0063] S7. Extract the unconsumed skeleton segment, unconsumed fill segment, and remaining fragments in the quantum key pool whose length has not reached the preset independent usable threshold from the key consumption identification result. Perform coupling and recombination on the extracted unconsumed skeleton segment, unconsumed fill segment, and remaining fragments based on the key fragmentation feature fingerprint to obtain a supplementary key unit. In one embodiment of the present invention, step S7 includes the following steps: Extract the skeleton segments and filler segments marked as unconsumed from the key consumption identification results, and extract the remaining fragments whose length has not reached the independent usable threshold from the quantum key pool to obtain the set of key materials to be reconstructed; Based on the fragment source and arrival order indicated in the fragmentation feature fingerprint of the key, the source compatibility of each material in the set of key materials to be reconstructed is screened to obtain a compatible material group; The materials in the compatible material group are coupled and spliced ​​according to the fragment source fingerprint and length alignment and consistency verification are performed to obtain a supplementary key unit that reaches the independent usability threshold.

[0064] Specifically, step S7 follows the key consumption authentication result obtained in step S6. The key fragmentation feature fingerprint obtained in step S1 The redundantly distributed unconsumed skeleton segments and unconsumed padding segments, along with those in the quantum key pool whose length has not reached the independent usable threshold, are included. The remaining fragments are merged into the key material set to be reconstructed. The extraction rule is defined as: scanning. middle The record is based on the offset address within the pool. Retrieve the corresponding bit segment from the quantum key pool Segment type identifier Scan all unused code segments in the quantum key pool that are not occupied by the vertical double-layer partitioning, and select those with lengths that meet the requirements. The remaining fragments subscript The remaining fragments are sequentially numbered in the quantum key pool. , This represents the total number of remaining fragments. Combining the two types of materials yields: , in Marking the remaining fragments The three levels represent unconsumed skeleton segments, unconsumed filler segments, and remaining fragments, respectively. and These represent the bit lengths of the corresponding segments, both in bits. Consistent length dimensions facilitate subsequent accumulation.

[0065] Source compatibility screening revolves around the source fingerprint of fragments and the order in which the fragments arrive. Each piece of material... Related fragment source fingerprint , To record the number of the transit arc segment to which it belongs, To record the relative arrival time under a unified time base, This refers to the atmospheric disturbance intensity level in the satellite transit state parameters corresponding to the coded record. The source compatibility criterion is measured by the following indicator function: , in The threshold for determining the time proximity of the source is set to 5 seconds. This threshold is based on the fact that 95% of the quantile values ​​of the interval between consecutive code formations from the same source in 1,500 code formation records collected by a provincial quantum key distribution device from 2022 to 2024 fall within the range of 4.6 seconds to 4.9 seconds. This threshold is then adjusted after adding a 0.2-second margin. Characterization materials With materials They belong to the same transit arc and arrive in adjacent order. The set of key materials to be reconstructed... Both sides satisfy Materials are grouped into the same group according to their adjacency to obtain a set of compatible material groups. , This represents the total number of compatible resource groups. Each compatible resource group... Internal materials by Arrange in ascending order. Couple and stitch together compatible material groups. As the basic splicing unit, according to The result of splicing is obtained by connecting the first and last parts in ascending order. ,length The lengths of all materials within the group are added together: , To align to an independent available threshold, a length alignment margin is introduced. : , in Represents the floor operation. The physical meaning is to complete the splicing result to... The number of bits required to make up an integer multiple, measured in bits. hour To make up the surplus; when This group is suspended and awaits merging with the next cycle's materials; it is not included in the current output. The supplementary bits are obtained from the quantum key pool of candidate remaining fragments whose fragment source fingerprints are the same as this group's. Continue to the end to ensure source continuity.

[0066] Consistency verification employs a combination of cyclic redundancy check (CRC) and hash verification. Let the concatenated bit string... Length equal to ,Bundle Cut into length equal-length blocks , Calculate the 32-bit cyclic redundancy check code block by block. With 256-bit hash value : , in The SHA-256 algorithm from step S5 is used. The criterion for successful verification is... and Simultaneously, the block falls into the whitelist verification table on the quantum security gateway side. The whitelist consists of the accompanying check value output for each code segment during the quantum key distribution post-processing stage. Blocks that fail verification are considered incorrectly included in the source compatibility screening and are removed from the splicing result. An additional iteration to fill in the remaining space is then performed, with a maximum of 3 iterations, based on the median number of iterations that converged in the cumulative operation records of a certain provincial quantum security gateway from 2023 to 2024, which was 2. Blocks that pass verification are numbered accordingly. Sequentially extract and match the fingerprints from the source of the fragments Packaged together as a supplementary key unit : , in For compatible material groups The actual number of equal-length blocks output after length alignment and consistency checks. The outputs of all compatible material groups are aggregated to obtain the supplementary key unit set. Each equal-length block in the cell reaches its independent usable threshold. Output to the injection process in step S8.

[0067] For example, the key consumption authentication result given in step S6 is adopted. The scan yielded... The two records correspond to the unconsumed skeleton segment located at the offset address. The length is 256 bits, and the unused padding segment is located at the offset address. It has a length of 128 bits.

[0068] The remaining fragment scan of the quantum key pool yielded 5 fragments with lengths not reaching the target value. The code segments have lengths of 64, 96, 48, 80, and 56 bits respectively, corresponding to the key segment time sequence set in step S1. The five records within the timeframe have relative arrival times of 0.5 seconds, 1.8 seconds, 3.2 seconds, 4.7 seconds, and 6.1 seconds, respectively. The crossing arc segment numbers are uniformly set as follows: Of the two source fingerprints that did not consume segments, Segment numbering of the transit arc Relative arrival time , Segment numbering of the transit arc Relative arrival time .

[0069] Key material set to be reassembled It consists of 7 records, based on The function performs a compatibility check on each pair of records. It assigns the same number to each of the transit arc segments. Six records were included as candidates, and their relative arrival time differences were compared one by one. The relative arrival time of the segment is 2.4 seconds, compared to the remaining debris. The difference is 0.6 seconds, and The difference is 0.8 seconds, neither exceeding [a certain value]. ,and The difference is 1.9 seconds. The difference is 2.3 seconds. The difference was 3.7 seconds, both falling within the threshold. The six records were combined to obtain a compatible set of materials. . The segments of the crossing arc are numbered differently and grouped separately. The length is 128 bits. The independent availability threshold has not been reached, so it is suspended and waiting for the next cycle.

[0070] against according to Sort in ascending order, the sequence is as follows: 64 bits 96 bits 256 bits 48 bits 80 bits The 56 bits. The sum of these bits gives the splicing length. Substituting into the length alignment allowance formula, we get... From the quantum key pool, press The remaining fragments of the same origin, with a length of 168 bits, are taken from 6.1 seconds after the closest relative arrival time and concatenated to the end of the splice, resulting in... 768 bits in length.

[0071] Bundle Cut into 3 equal-length pieces , , Each block is 256 bits long. The cyclic redundancy check (CRC) code and hash value are calculated block by block to obtain... , , , , , 3 and The whitelist verification table shows all results passed the comparison, so no iteration is needed.

[0072] Final output supplementary key unit The three equal-length blocks are all 256 bits long, reaching the independent usability threshold. Supplementary key unit set. Output to the injection process in step S8, suspending the compatible material group. The remaining amount will be replenished in the next cycle before further processing.

[0073] S8. The supplementary key unit is injected back into the quantum key pool and the skeleton segment freezing strategy is updated according to the supplementary key unit to obtain the updated skeleton segment freezing strategy. The updated skeleton segment freezing strategy is used for the vertical double-layer segmentation in the next cycle.

[0074] In one embodiment of the present invention, step S8 includes the following steps: Write the supplementary key unit into the quantum key pool and mark the source attribute of the supplementary key unit as a recombination class to obtain a snapshot of the key pool containing the recombination tag; Based on the snapshot of the key pool containing the recombination marker, the total length of the currently available keys is reread and combined with the key instruction generation window to obtain the skeleton resource replenishment amount; The size and duration of the frozen skeleton segments at each time point in the skeleton segment freezing strategy are corrected according to the skeleton resource replenishment amount to obtain the updated skeleton segment freezing strategy, and the updated skeleton segment freezing strategy is sent back to the vertical double-layer segmentation process of the next cycle.

[0075] Specifically, step S8 follows the supplementary key unit set obtained in step S7. Cut each equal-length block Along with the corresponding fragment source fingerprint The available key area is written to the quantum key pool. The writing process is executed atomically within the key pool management module of the quantum security gateway, with each transaction covering the storage and indexing of one equal-length block. A new in-pool offset address is assigned to each equal-length block within the quantum key pool. It is isolated from the original code segment address area to avoid address conflicts with the continuous segment scan during the next vertical double-layer segmentation.

[0076] Source attribute tags use metadata fields Finish, Values Characterizing the recombined class, the source attribute corresponding to the original code segment. Distinguishing between different types of recombinant tags is crucial. These tags are stored as a separate column in the key pool index table, providing source identification for subsequent segment selection processes. After writing and tagging are complete, a snapshot of the key pool containing the recombinant tags is obtained. : , The set of original code segments already present in the quantum key pool before writing is represented. This reflects the overall stock distribution of the quantum key pool after the back-injection is completed. After the key pool snapshot with recombination tags is constructed, the total length of currently available keys is reread. The reading rules are weighted and accumulated according to segment type. For recombined blocks of equal length, a recombined-class attenuation coefficient is introduced during the statistical analysis. The original code segment is converted using the attenuation coefficient. Enter accumulation: , in This represents the bit length of the corresponding equal-length block, measured in bits. The value of 0.9 is based on the fact that the failure rate of secondary verification of recombined blocks of equal length in the cumulative operation archives of a certain provincial quantum security gateway from 2023 to 2024 was about 8% to 10% higher than that of the original code segment during the encryption transformation. The attenuation coefficient of 0.9 is introduced to convert the statistical length to the same trusted occupancy strength as the original code segment, and the dimension is aligned to bits.

[0077] Skeleton resource replenishment amount for the critical instruction generation window obtained in step S2 Each window is calculated item by item. Supplement quantity. Based on the current skeleton segment freezing strategy Medium frozen skeleton segment size Available key level at the start of the window compared to the key pool snapshot containing the recombination marker. The difference determines: , in For window The proportion of skeleton segments that can be allocated in the quantum key pool is identified according to the instruction level. Values, Time to take , Time to take , Time to take The three-tier share allocation is derived from the measured occupancy ratio of the key pool for three types of instructions in the cumulative operation archives of a provincial power grid from 2022 to 2024. All values ​​are dimensionless shares; multiplying them by the available key level yields a unit of bits. The dimensions are consistent. Depend on Projecting along the time axis yields: , in Using the available key accumulation rate from step S3, The cumulative deduction amount carried by the instruction already scheduled in step S3 is used. Representation window There is still a shortage of skeleton resources, and the freezing strategy needs to be adjusted according to the replenishment amount; Representation window The skeleton resources are sufficient. The skeleton segment freezing strategy has been revised for each window. scale of frozen skeleton segments With freeze duration Simultaneous execution. Revised frozen skeleton segment size. Depend on Plus replenishment get: , Revised freeze duration The supplementary duration is added on top of the original freeze duration. The time required for the corresponding bits to be removed from the reassembled block and locked, and the time required for the padding amount to be added: , , in Represents the floor operation. The unit is seconds, and Dimensionally consistent. Freeze start time. Maintain the original value and occupy the prohibited level. Continue Final update skeleton segment freezing strategy writing: , in The vertical two-layer segmentation process, which is fed back to the next cycle by the key pool management module of the quantum security gateway, replaces the original... As the basis for dividing the position intervals of the skeleton segment and the position interval of the filling segment, a closed-loop connection is formed between the three pipelines of key fragmentation feature fingerprint acquisition, skeleton resource reservation calculation, and vertical double-layer segmentation.

[0078] For example, the supplementary key unit set output in step S7. ,in Contains 3 blocks of equal length , , Each block is 256 bits long, totaling 768 bits. These three equal-length blocks are sequentially written into the available key area of ​​the quantum key pool, and new offset addresses are allocated within the pool. , , Metadata fields The fingerprints corresponding to the source of the fragments They are also registered in the index table.

[0079] Snapshot of the key pool containing the reorganization marker after writing is complete. Generate, original code segment set Medium length meets independent availability threshold The cumulative length is 16384 bits. The total length of the usable key is reread, and the original code segments are summed to obtain... The sum of equal-length blocks of the recombined type is obtained ,total .

[0080] The skeleton segment freezing strategy obtained in step S3 Two records and The available key accumulation rate remains unchanged. The window's start time relative to the current time. Offset ,Bundle Projected along the time axis have to .

[0081] Regarding window number , share ratio Substituting into the formula for the amount to be supplemented, we get... The skeleton resources are sufficient and do not need to be replenished. The size of the frozen skeleton segments has been corrected. Make up for the time Corrected freeze duration .

[0082] Regarding window number , share ratio Substituting into the formula for the amount to be supplemented, we get... The skeleton resources are also sufficient. The revised frozen skeleton segment size... Make up for the time Corrected freeze duration .

[0083] Updated skeleton segment freezing strategy Include and Two records are sent back to the vertical double-layer segmentation process of the next cycle, serving as the basis for dividing the skeleton segment position interval and the filling segment position interval in the next round. When the coding rate of the next cycle decreases due to atmospheric disturbances or occlusion events... When insufficient, the supplementary amount formula will be based on and The difference is calculated to be non-zero. And then and Elevate it to a level that matches the needs of key instructions, forming a cross-cycle closed-loop correction.

[0084] Based on the same inventive concept, such as Figure 3 As shown, the present invention also provides a power grid control encryption system based on satellite quantum key distribution, the system comprising: The fragment fingerprint generation module is used to acquire satellite transit state parameters and quantum key stream arrival parameters, and to perform fragment distribution analysis on the satellite transit state parameters and quantum key stream arrival parameters to obtain key fragmentation feature fingerprints. The instruction window prediction module is used to collect the occurrence time sequence of various control instructions in the historical issuance records of power grid control business, extract the timing pattern, and obtain the key instruction occurrence window; The skeleton freezing strategy generation module is used to read the current stock of the quantum key pool and perform skeleton resource reservation calculation in combination with the key instruction generation window to obtain the skeleton segment freezing strategy. The dual-layer segmentation module is used to perform vertical dual-layer segmentation of the key stream in the quantum key pool according to the key fragmentation feature fingerprint and the skeleton segment freezing strategy to obtain skeleton-fill key units. The skeleton-fill key units include a skeleton segment carrying the core encryption strength and a fill segment extending the encryption strength. The encryption and credential generation module is used to receive real-time control instructions and select corresponding skeleton segments and fill segments from the skeleton-fill key unit according to the level of the real-time control instructions for encryption transformation, and at the same time generate paired credentials that correspond one-to-one with the selected skeleton segments and fill segments, so as to obtain an encrypted control message and a set of paired credentials. The key consumption identification module is used to send the encrypted control message to the execution terminal, collect the credential response information fed back by the execution terminal based on the paired credential set, compare the consumption status of the credential response information, and obtain the key consumption identification result. The key consumption identification result is used to indicate the skeleton segment and padding segment that have been actually consumed, as well as the redundantly sent but unconsumed skeleton segment and padding segment. The fragment coupling and recombination module is used to extract the unconsumed skeleton segment, the unconsumed fill segment, and the remaining fragments in the quantum key pool whose length has not reached the preset independent usable threshold from the key consumption identification result. The extracted unconsumed skeleton segment, unconsumed fill segment, and remaining fragments are coupled and recombined based on the key fragmentation feature fingerprint to obtain a supplementary key unit. The strategy injection and update module is used to inject the supplementary key unit back into the quantum key pool and update the skeleton segment freezing strategy according to the supplementary key unit to obtain the updated skeleton segment freezing strategy. The updated skeleton segment freezing strategy is used for the vertical double-layer segmentation in the next cycle.

[0085] All equivalent changes and modifications made in accordance with the teachings of this invention are still within the scope of this invention. Those skilled in the art will readily conceive of other embodiments of this invention upon considering the specification and the disclosure of practical truth. This application is intended to cover any variations, uses, or adaptations of this invention that follow the general principles of this invention and include common knowledge or conventional techniques in the art not described herein.

Claims

1. A power grid control encryption method based on satellite quantum key distribution, characterized in that, The method includes: The satellite transit state parameters and quantum key stream arrival parameters are obtained, and the fragmentation distribution of the satellite transit state parameters and quantum key stream arrival parameters is analyzed to obtain the key fragmentation feature fingerprint; Collect the occurrence time sequence of various control commands from the historical issuance records of power grid control services, extract the timing pattern, and obtain the occurrence window of key commands; The current stock of the quantum key pool is read and the skeleton resource reservation calculation is performed in combination with the key instruction generation window to obtain the skeleton segment freezing strategy; According to the key fragmentation feature fingerprint and the skeleton segment freezing strategy, the key stream in the quantum key pool is vertically divided into two layers to obtain skeleton-fill key units. The skeleton-fill key units include skeleton segments that carry core encryption strength and fill segments that extend encryption strength. The system receives real-time control commands and selects corresponding skeleton segments and fill segments from the skeleton-fill key unit according to the level of the real-time control commands for encryption transformation. At the same time, it generates a pairing credential that corresponds one-to-one with the selected skeleton segment and fill segment, thus obtaining a set of encrypted control messages and pairing credentials. The encrypted control message is sent to the execution terminal, and the credential response information fed back by the execution terminal based on the paired credential set is collected. The consumption status of the credential response information is compared to obtain the key consumption identification result. The key consumption identification result is used to indicate the skeleton segment and padding segment that have been actually consumed, as well as the redundantly issued unconsumed skeleton segment and padding segment. Extract the unconsumed skeleton segment, unconsumed padding segment, and remaining fragments in the quantum key pool whose length has not reached the preset independent usable threshold from the key consumption identification results. Perform coupling and recombination on the extracted unconsumed skeleton segment, unconsumed padding segment, and remaining fragments based on the key fragmentation feature fingerprint to obtain a supplementary key unit. The supplementary key unit is injected back into the quantum key pool, and the skeleton segment freezing strategy is updated according to the supplementary key unit to obtain the updated skeleton segment freezing strategy. The updated skeleton segment freezing strategy is used for the vertical double-layer segmentation in the next cycle.

2. The power grid control encryption method based on satellite quantum key distribution according to claim 1, characterized in that, The process of acquiring satellite transit state parameters and quantum key stream arrival parameters, performing fragmentation distribution analysis on the satellite transit state parameters and quantum key stream arrival parameters to obtain key fragmentation feature fingerprints includes: The available duration of the satellite transit window, the intensity of atmospheric disturbances, and the occurrence markers of obscuring events are collected and integrated to obtain satellite transit status parameters; The arrival parameters of the quantum key stream are obtained, and the satellite transit status parameters and the arrival parameters of the quantum key stream are time-aligned according to a unified time reference. The key segments in the arrival parameters of the quantum key stream whose length has not reached the preset independent usable threshold are identified to obtain the key segment time sequence set. The key fragment time series set is statistically described according to the fragment length distribution and arrival interval distribution to obtain a key fragmentation feature fingerprint that reflects the key stream fragment distribution pattern in future time periods.

3. The power grid control encryption method based on satellite quantum key distribution according to claim 2, characterized in that, The sequence of occurrence times of various control commands in the historical records of power grid control services is collected, and time-series pattern extraction is performed to obtain the key command occurrence window, including: Extract the occurrence times of protection commands, emergency load shedding commands, and remote control operation commands from the historical records of power grid control operations to obtain the sequence of occurrence times of key commands; Trigger correlation analysis is performed on the sequence of occurrence times of the key instructions to extract the triggering leading events and subsequent triggering events of the key instructions, thereby obtaining the key instruction trigger chain characteristics; Based on the characteristics of the key instruction trigger chain, the trigger probability of future time periods is extrapolated to obtain the key instruction occurrence window that reflects the distribution of key instructions on the future time axis.

4. The power grid control encryption method based on satellite quantum key distribution according to claim 3, characterized in that, The process of reading the current inventory of the quantum key pool and performing skeleton resource reservation calculations in conjunction with the key instruction generation window yields a skeleton segment freezing strategy, including: The total length of currently available keys in the quantum key pool is read and projected onto the time axis to obtain the key availability timeline curve; Based on the key instruction occurrence window, the key instruction carrying demand points are marked on the key availability time curve to obtain the skeleton resource demand map; Based on the skeleton resource demand map, the length of the skeleton segment to be retained at each time point and the freezing duration are calculated to obtain a skeleton segment freezing strategy that indicates that a specified size of skeleton segment should be frozen at a specified time point and that it should not be occupied by a preset level instruction.

5. The power grid control encryption method based on satellite quantum key distribution according to claim 4, characterized in that, The step of performing a vertical double-layer segmentation of the key stream in the quantum key pool according to the key fragmentation feature fingerprint and the skeleton segment freezing strategy to obtain skeleton-filled key units includes: The distribution of available key contiguous segments and the distribution of fragment intervals indicated in the key fragmentation feature fingerprint are read to obtain the segmentation reference quantity; According to the skeleton segment freezing strategy, the skeleton segment position interval and the fill segment position interval are defined on the segmentation reference amount to obtain a two-layer position division; Based on the dual-layer position division, the key stream in the quantum key pool is vertically segmented to obtain skeleton-fill key units. The length and refresh frequency of the skeleton segment in the skeleton-fill key unit are independent of the length and refresh frequency of the fill segment.

6. The power grid control encryption method based on satellite quantum key distribution according to claim 5, characterized in that, The process involves receiving real-time control commands and selecting corresponding skeleton and padding segments from the skeleton-padding key unit according to the level of the real-time control commands for encryption transformation. Simultaneously, it generates pairing credentials that correspond one-to-one with the selected skeleton and padding segments, resulting in an encrypted control message and a set of pairing credentials, including: Receive real-time control commands and parse the target and impact level of the real-time control commands to obtain the command level identifier; According to the instruction level identifier, select the corresponding number of skeleton segments and padding segments in the skeleton-padding key unit to obtain the key unit combination selected for this encryption; The real-time control command is encrypted using the key unit combination, and a unique pairing credential is generated for each selected skeleton segment and padding segment. The pairing credential is then embedded into the encryption result to obtain an encrypted control message and a set of pairing credentials.

7. The power grid control encryption method based on satellite quantum key distribution according to claim 6, characterized in that, The process of sending the encrypted control message to the execution terminal, collecting the credential response information fed back by the execution terminal based on the paired credential set, comparing the consumption status of the credential response information, and obtaining the key consumption identification result includes: The encrypted control message is sent through the power grid communication channel, and the execution terminal is triggered to perform a hash response on the pairing credential embedded in the encrypted control message to obtain credential response data; Collect the voucher response data sent back by the execution terminal after the instruction is executed, and aggregate it according to the issued batch to obtain voucher response information; The credential response information is compared item by item with the set of paired credentials to identify the skeleton segment and padding segment corresponding to the paired credentials for which no response has been received. The key consumption identification results of the skeleton segment and padding segment that have been actually consumed, as well as the redundantly issued unconsumed skeleton segment and padding segment, are obtained.

8. The power grid control encryption method based on satellite quantum key distribution according to claim 7, characterized in that, The process involves extracting the unconsumed skeleton segments, unconsumed padding segments, and remaining fragments in the quantum key pool whose length has not reached a preset independent usable threshold from the key consumption identification results. The extracted unconsumed skeleton segments, unconsumed padding segments, and remaining fragments are then coupled and recombined based on the key fragmentation feature fingerprint to obtain a supplementary key unit, including: Extract the skeleton segments and filler segments marked as unconsumed from the key consumption identification results, and extract the remaining fragments whose length has not reached the independent usable threshold from the quantum key pool to obtain the set of key materials to be reconstructed; Based on the fragment source and arrival order indicated in the fragmentation feature fingerprint of the key, the source compatibility of each material in the set of key materials to be reconstructed is screened to obtain a compatible material group; The materials in the compatible material group are coupled and spliced ​​according to the fragment source fingerprint and length alignment and consistency verification are performed to obtain a supplementary key unit that reaches the independent usability threshold.

9. The power grid control encryption method based on satellite quantum key distribution according to claim 8, characterized in that, The step of injecting the supplementary key unit back into the quantum key pool and updating the skeleton segment freezing strategy based on the supplementary key unit to obtain the updated skeleton segment freezing strategy includes: Write the supplementary key unit into the quantum key pool and mark the source attribute of the supplementary key unit as a recombination class to obtain a snapshot of the key pool containing the recombination tag; Based on the snapshot of the key pool containing the recombination marker, the total length of the currently available keys is reread and combined with the key instruction generation window to obtain the skeleton resource replenishment amount; The size and duration of the frozen skeleton segments at each time point in the skeleton segment freezing strategy are corrected according to the skeleton resource replenishment amount to obtain the updated skeleton segment freezing strategy, and the updated skeleton segment freezing strategy is sent back to the vertical double-layer segmentation process of the next cycle.

10. A power grid control encryption system based on satellite quantum key distribution, characterized in that, The system includes: The fragment fingerprint generation module is used to acquire satellite transit state parameters and quantum key stream arrival parameters, and to perform fragment distribution analysis on the satellite transit state parameters and quantum key stream arrival parameters to obtain key fragmentation feature fingerprints. The instruction window prediction module is used to collect the occurrence time sequence of various control instructions in the historical issuance records of power grid control business, extract the timing pattern, and obtain the key instruction occurrence window; The skeleton freezing strategy generation module is used to read the current stock of the quantum key pool and perform skeleton resource reservation calculation in combination with the key instruction generation window to obtain the skeleton segment freezing strategy. The dual-layer segmentation module is used to perform vertical dual-layer segmentation of the key stream in the quantum key pool according to the key fragmentation feature fingerprint and the skeleton segment freezing strategy to obtain skeleton-fill key units. The skeleton-fill key units include a skeleton segment carrying the core encryption strength and a fill segment extending the encryption strength. The encryption and credential generation module is used to receive real-time control instructions and select corresponding skeleton segments and fill segments from the skeleton-fill key unit according to the level of the real-time control instructions for encryption transformation, and at the same time generate paired credentials that correspond one-to-one with the selected skeleton segments and fill segments, so as to obtain an encrypted control message and a set of paired credentials. The key consumption identification module is used to send the encrypted control message to the execution terminal, collect the credential response information fed back by the execution terminal based on the paired credential set, compare the consumption status of the credential response information, and obtain the key consumption identification result. The key consumption identification result is used to indicate the skeleton segment and padding segment that have been actually consumed, as well as the redundantly sent but unconsumed skeleton segment and padding segment. The fragment coupling and recombination module is used to extract the unconsumed skeleton segment, the unconsumed fill segment, and the remaining fragments in the quantum key pool whose length has not reached the preset independent usable threshold from the key consumption identification result. The extracted unconsumed skeleton segment, unconsumed fill segment, and remaining fragments are coupled and recombined based on the key fragmentation feature fingerprint to obtain a supplementary key unit. The strategy injection and update module is used to inject the supplementary key unit back into the quantum key pool and update the skeleton segment freezing strategy according to the supplementary key unit to obtain the updated skeleton segment freezing strategy. The updated skeleton segment freezing strategy is used for the vertical double-layer segmentation in the next cycle.