WO2019137014A1 - 基于量子密钥融合的虚拟电厂安全通信方法及装置、介质 - Google Patents

基于量子密钥融合的虚拟电厂安全通信方法及装置、介质 Download PDF

Info

Publication number
WO2019137014A1
WO2019137014A1 PCT/CN2018/102358 CN2018102358W WO2019137014A1 WO 2019137014 A1 WO2019137014 A1 WO 2019137014A1 CN 2018102358 W CN2018102358 W CN 2018102358W WO 2019137014 A1 WO2019137014 A1 WO 2019137014A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
client
server
quantum
authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/102358
Other languages
English (en)
French (fr)
Inventor
邓伟
吴文炤
于卓智
张叶峰
韩冰洋
冷曼
马永红
张京伦
吴润泽
陈文伟
李楠翔
朱玉坤
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Guodian Tong Network Technology Co Ltd
North China Electric Power University
State Grid Corp of China SGCC
Original Assignee
Beijing Guodian Tong Network Technology Co Ltd
North China Electric Power University
State Grid Corp of China SGCC
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Guodian Tong Network Technology Co Ltd, North China Electric Power University, State Grid Corp of China SGCC filed Critical Beijing Guodian Tong Network Technology Co Ltd
Priority to US16/481,215 priority Critical patent/US11233639B2/en
Publication of WO2019137014A1 publication Critical patent/WO2019137014A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0643Hash functions, e.g. MD5, SHA, HMAC or f9 MAC
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • H04L9/0841Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
    • H04L9/0844Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0866Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • H04L9/3239Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/50Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y04INFORMATION OR COMMUNICATION TECHNOLOGIES HAVING AN IMPACT ON OTHER TECHNOLOGY AREAS
    • Y04SSYSTEMS INTEGRATING TECHNOLOGIES RELATED TO POWER NETWORK OPERATION, COMMUNICATION OR INFORMATION TECHNOLOGIES FOR IMPROVING THE ELECTRICAL POWER GENERATION, TRANSMISSION, DISTRIBUTION, MANAGEMENT OR USAGE, i.e. SMART GRIDS
    • Y04S40/00Systems for electrical power generation, transmission, distribution or end-user application management characterised by the use of communication or information technologies, or communication or information technology specific aspects supporting them
    • Y04S40/20Information technology specific aspects, e.g. CAD, simulation, modelling, system security

Definitions

  • the present application relates to the field of power technology, but is not limited to the field of power technology, and particularly relates to a virtual power plant secure communication method and apparatus based on quantum key fusion, and a computer storage medium.
  • the virtual power plant is an effective form to rationally integrate and optimize the use of distributed new energy, and it can also effectively participate in the energy trading process of the electricity market.
  • the current research on virtual power plants mainly discusses the problems from the perspective of economic and reliable operation of power systems.
  • the specific work includes energy management, system operation, optimal scheduling, predictive modeling, etc., and how to rely on advanced passwords, identity authentication, and encryption. Technologies such as communication to ensure the security of information communication and ensure the reliable operation of the energy Internet have not yet been studied with highly relevant content.
  • Quantum cryptography is based on quantum.
  • the uncertainty principle, the quantum state measurement collapse and the physics of the unknown quantum state can not be cloned, can guarantee the long-term and absolute security of information transmission.
  • quantum key distribution technology into power systems.
  • the existing work is either discussed solely from the perspective of quantum key technology, or simply applying quantum technology in the power system, and the combination of results and power specific business systems is insufficient. It is difficult to implement efficient and secure means of communication, especially for communication safety related to virtual power plants.
  • the purpose of the present application is to provide a virtual power plant security communication method and apparatus based on quantum key fusion, and a computer storage medium.
  • the embodiment of the present application provides a virtual power plant security communication method based on quantum key fusion, including:
  • Identity authentication Based on the communication requirements, the identity between the client and the server in the virtual power plant is authenticated and the root key is obtained; wherein the server includes a commercial virtual power plant, a power market business system or a technical virtual power plant.
  • the client corresponds to a distributed power source, a commercial virtual power plant or a technical virtual power plant;
  • Key distribution based on the obtained root key, correspondingly generate a key encryption key and a message authentication key, thereby implementing data encryption key negotiation to obtain a data encryption key;
  • Data encryption encrypting the data to be encrypted with a data encryption key and implementing data communication accordingly;
  • the quantum key server is used to implement quantum key negotiation, and the negotiated quantum key implements corresponding identity authentication or as a data encryption key.
  • the embodiment of the present application further provides a virtual power plant security communication device based on quantum key fusion, including:
  • the identity authentication module is configured as an identity authentication: based on the communication requirement, authenticating the identity between the client and the server in the virtual power plant and obtaining the root key; wherein the server includes a commercial virtual power plant and a power market service a system or technology type virtual power plant; the client corresponds to a distributed power source, a commercial virtual power plant or a technical virtual power plant;
  • the distribution module is configured as a key distribution: based on the obtained root key, a key encryption key and a message authentication key are generated correspondingly, thereby implementing data encryption key negotiation to obtain a data encryption key;
  • the encryption module is configured as data encryption: the data to be encrypted is encrypted by the data encryption key and the data communication is implemented accordingly;
  • the quantum key server is used to implement quantum key negotiation, and the negotiated quantum key implements corresponding identity authentication or as a data encryption key.
  • the embodiment of the present application further provides a computer storage medium storing computer executable instructions. After the computer executable instructions are executed, the foregoing virtual power plant secure communication method based on quantum key fusion can be implemented.
  • the virtual power plant security communication method based on quantum key fusion realizes the secure communication of the virtual power plant by combining the quantum key with the classical encryption method, that is, the cost is not excessively increased, and Improve data security during communication. Therefore, the present application can provide a safe, reliable, and cost-effective method of secure communication, improving communication safety and reliability of virtual power plants.
  • FIG. 1 is a schematic structural diagram of a virtual power plant communication network according to an embodiment of the present application.
  • FIG. 2 is a schematic diagram of relationship between an encryption key and a history key hash value according to an embodiment of the present application
  • FIG. 3 is a schematic diagram of a relationship between obtaining a related key by using a root key according to an embodiment of the present disclosure
  • FIG. 4 is a schematic diagram of a unicast or multicast communication process of a virtual power plant according to an embodiment of the present application
  • FIG. 5 is a schematic flowchart of a method for secure communication of a virtual power plant based on quantum key fusion according to an embodiment of the present application.
  • This application is aimed at the current status of encrypted communication. Considering the high price of quantum products, the common classical and quantum key fusion can be utilized, and a virtual power plant security communication method based on quantum key fusion is proposed, which has a good application prospect. .
  • the communication in the virtual power plant usually includes between commercial virtual power plant (CVPP) and distributed power (DER), CVPP and power market business system.
  • CVPP commercial virtual power plant
  • DER distributed power
  • TVPP technical virtual power plant
  • TVPP multicast communication between power market service system and CVPP; as shown in Figure 1, the virtual provided for this application Schematic diagram of the power plant communication network structure.
  • the power market business system is usually connected to a plurality of commercial virtual power plants (CVPP) and conventional power plants, and each commercial virtual power plant (CVPP) is connected to a different technical virtual power plant (TVPP).
  • quantum communication requires the following equipment as support: quantum channel for quantum information transmission; quantum trusted relay device for trusted relay relay of quantum key; quantum key server for quantum key Generating and managing; classical channel for transmitting classical information outside the quantum key; quantum random number generator for generating quantum random numbers as keys for transmission to quantum key servers and quantum key management devices, belonging to quantum A key server; a client-side quantum key management device for generating an associated service key.
  • the method for secure communication of a virtual power plant based on quantum key fusion includes the following steps:
  • Identity authentication based on communication requirements, identity authentication between the client and the server in the virtual power plant and obtaining the root key; wherein the server includes a commercial virtual power plant, a power market business system or technology The virtual power plant; the client corresponds to a distributed power source, a commercial virtual power plant or a technical virtual power plant; for example, the server is a commercial virtual power plant (CVPP), and the client is a distributed power source (DER).
  • CVPP commercial virtual power plant
  • DER distributed power source
  • the identity authentication process includes performing a certificate authentication manner; wherein, when the certificate authentication is used, a trusted third party is required to issue a corresponding certificate to the client and the server respectively;
  • the certificate authentication process includes the following steps:
  • the client sends the corresponding identity information ID_C1, client certificate, such as X.509, client hash value, and random number Nh to the corresponding server;
  • the server receives the information sent by the client and verifies the information. If the verification information is consistent, the root key, that is, the authorization key AK, is given, and the root key is encrypted by using the public key in the certificate and sent to the client;
  • the client decrypts the corresponding root key with the corresponding private key to complete the identity authentication.
  • the identity authentication process includes performing a fast authentication method, where the client and the server respectively have a historical data index table, where the historical data index table includes time, identity information, and respective Historical key and historical hash value; the client and server generate an encryption key k for each session, denoted as k 0 , k 1 , k 2 ... k n , the historical key hash value generated each time It is denoted as h 1 , h 2 , h 3 ... h n , and the hash value of k and the hash value of h are XORed to obtain a new historical key hash value; referring to FIG. 2, h n is calculated by the following formula:
  • n is a natural number greater than 1, and SHA1 is a hash algorithm
  • the client and the server authenticate according to the historical data index table
  • the root key is granted after the authentication is successful.
  • the step of authenticating the client and the server according to the historical data index table further includes:
  • the client extracts the last key value k, the last time Ti, and the index value ind in the index table in the corresponding historical data index table;
  • the client uses the last key value, the last time, and the index value to calculate the hash value, and the identity information and the random number of the client are sent to the server as a message; wherein the message is encrypted using the last key value. And attach an index value;
  • the message is expressed as: ESM4[SHA1(k
  • ESM4 is a secret algorithm
  • k is an encryption key
  • Ti is the last time
  • Ni is a random number
  • ind is an index value
  • ID_DER is the identity information of the client
  • the server After receiving the message information, the server retrieves the historical data index table in the server according to the index value in the message information and extracts related information in the index table, decrypts the message information by using the encryption key, and compares and decrypts the message first.
  • the server generates a new random number Nj, and returns the confirmation information and the new time T to the client through the message; the message is encrypted with k, and the encryption formula is as follows: Encrypt(Nj
  • the client After receiving the message information, the client decrypts and obtains a new random number Nj and a new time T;
  • the server and the client calculate the random number Ni, Nj, the new time T, and the new historical hash value h to obtain a new root key AK.
  • the calculation formula of the root key AK is:
  • AK Truncate_128[SHA1(Ni
  • the identity authentication process may further implement quantum key negotiation by using a quantum key server; wherein both the client and the server have a quantum key server, and the client is provided with a quantum key management device.
  • the client's quantum key management device performs binding registration at the quantum key server in advance, and the quantum key server requires the quantum random number generator to generate a large number of random numbers for use as a key to be stored in the quantum.
  • the client sends a data transmission request to the server
  • the server After receiving the request, the server generates a random number Nb, and sends the random number Nb to the client together with the quantum identity authentication request;
  • the client After receiving the quantum identity authentication request, the client sends the service information to the bound quantum key server L2 through the quantum key management device QC of the client, and the information content is that the server requests the quantum identity authentication of the client;
  • the quantum key server L1 of the server After the quantum key server L2 receives the service information of the client, the quantum key server L1 of the server performs quantum key negotiation with the quantum key server L2 of the client, and the client and the server obtain the agreed secret after the quantum key negotiation is completed.
  • the server generates a random number as the root key AK, and calculates the signal. And sent to the quantum key server L2 through the classic channel;
  • the quantum key server L2 After the quantum key server L2 receives the signal E, it calculates And select the quantum random number Ni pre-stored between the client and the quantum key server L2, and calculate Subsequently, the quantum key server L2 sends the ST, the random number Ni pointer ptr, the length long, and the hash (AK') to the client together;
  • the client After receiving the message, the client extracts the random number Ni using the random number pointer ptr and the length long, and calculates Sending a message digest HMAC(AK") Nb to the server;
  • wireless communication devices can be used to transceive data in response to communication routing difficulties caused by widespread client distribution.
  • the client's quantum key management device can obtain the quantum random number by periodically using the USB copy method to the key management server.
  • the application layer data can be encrypted with an application key and can assist in encrypting low-level data using the 802.16 protocol.
  • the key distribution process includes:
  • the client sends a key request to the server; wherein the key application includes a random number Nh;
  • the server After receiving the key application, the server generates a key encryption key KEK, an uplink message authentication key HMAC_key1, and a downlink message authentication key HMAC_key2 according to the root key Ak and the random number Nh; the key encryption key KEK is as follows Formula calculation:
  • 0 ⁇ 44 represents 44 zeros
  • Nh is a 64-bit random number
  • the uplink message authentication key is calculated by the following formula:
  • the downlink message authentication key is calculated by the following formula:
  • 36 44 indicates that 44 0x36 are connected after the 128-bit root key AK, and a 352-bit bit string is formed, then the 480-bit string is hashed, and finally the XOR is performed with the random number Nh;
  • the client and the server perform negotiation of the data encryption key TEK; wherein, the client sends a negotiation application to the server, the application message is encrypted by using KEK, and the key of the message digest uses HMAC_key1;
  • the server After receiving the request, the server encrypts the TEK parameter list and sends it to the client using the KEK.
  • the key for sending the message digest uses HMAC_key2.
  • Data encryption encrypting the data to be encrypted by using the data encryption key and correspondingly implementing data communication; wherein the data to be encrypted includes equipment and operating state parameters sent by the client to the server, real-time power generation data, margin Cost, real-time power consumption data, energy storage capacity, and energy storage equipment status parameters.
  • the data encryption process encrypts application layer service data by using one or more combination algorithms of SM4-CBC, DES, AES, and SM1; wherein all data passes the message authentication key.
  • the hash operation is performed and attached to the data tail, and the hash key in the uplink direction is the uplink message authentication key HMAC_key1, and the hash key in the downlink direction is the downlink message authentication key HMAC_key2.
  • CBC is a cipher packet linking mode, the purpose is to make repeated plaintext packets generate different ciphertext packets.
  • the virtual power plant secure communication method based on quantum key fusion realizes the secure communication of the virtual power plant by combining the quantum key with the classical encryption method, that is, the cost is not excessively increased. , can greatly improve the data security in the communication process. Therefore, the present application can provide a safe, reliable, and cost-effective method of secure communication, improving communication safety and reliability of virtual power plants.
  • the foregoing identity authentication process and key distribution process utilize quantum key servers to implement quantum key negotiation
  • the identity authentication process includes the following steps:
  • the client sends an identity authentication request to the server through the classic channel;
  • the server After receiving the identity authentication request, the server generates a set of random numbers as the root key AK through the quantum random number generator, and requests the quantum key servers L2 and L1 to perform quantum key negotiation;
  • the quantum key servers L1 and L2 perform quantum key negotiation according to a predetermined protocol, and obtain a key K_QU2;
  • the server obtains the key K_QU2 and calculates And send E to the client;
  • the server determines whether the hash (AK') is equal to the hash (AK). If they are equal, the identity authentication for the client is completed; if not, the authentication fails and the communication is interrupted;
  • the key distribution process includes:
  • the client and the server use the AK as the root key to generate a corresponding message authentication key and a key encryption key KEK;
  • the client requests the quantum key servers L1 and L2 to perform quantum key negotiation;
  • the quantum key servers L1 and L2 perform quantum key negotiation according to a predetermined protocol to obtain a key K_QU3;
  • the client and server obtain the key K_QU3 and use the key K_QU3 as the data encryption key.
  • encryption with encrypted data is implemented according to the same data encryption process.
  • the secure distribution of the two parties may also be performed in a quantum one-time secret manner in a key distribution process, the key distribution process including:
  • Both the client and the server use AK as the root key, and then derive the message authentication key;
  • the quantum key server L1 and L2 are required to perform quantum key negotiation each time the client and the server communicate;
  • the quantum key servers L1 and L2 perform quantum key negotiation according to the BB84 protocol to obtain a key K_QU4;
  • the client and server get K_QU4 and use it as a data encryption key.
  • multicast mainly includes multicast information from each service system of the power market to each CVPP, including various energy prices in the current period, energy demand in the future period, and other information; and also includes various power-assisted market demand information, such as Business information such as frequency modulation, automatic power generation control, peak shaving, reactive power regulation, rotating standby, and black start.
  • a power market business system includes five CVPPs, and the power market multicasts energy demand bidding scheme messages to five clients, wherein the multicast center is a power market business system, and the intra-group client is each CVPP.
  • the communication is multicast communication
  • one server corresponds to multiple clients for multicast communication; referring to FIG. 4, the unicast or multicast communication process is provided for the virtual power plant provided by the present application.
  • schematic diagram. The virtual power plant communication method further includes the following steps:
  • the group key is initialized.
  • the implementation process is as follows:
  • each client Before initialization, each client first registers with the server and obtains the registration value
  • Each client sends the registration value and the selected random number B1 to Bn to the server; where n is the number of clients.
  • Bn is a random number selected by the client n;
  • the server After receiving the random number, the server calculates B1*B2*...*Bn[G] as the group key; where G is the base point corresponding to the ellipse encryption algorithm; based on the scheme, the elliptic encryption algorithm is used, and the elliptic curve used is E(a,b), the base point is G(xG,yG);
  • the server sends the group key to the client
  • each client After receiving the relevant data, each client calculates the group key by using the relevant data and the respective random numbers; for example, the client 1 calculates C1*B1 as the group key.
  • the key process includes the steps:
  • the application includes the random number Nm, the identity information ID_M1 of the new client M1, and the new client.
  • Public key PM and h(1); SM3 is a hash algorithm, and the application message is encrypted using the server public key P, and the encryption formula is: SM2[Nm
  • the server D1 After receiving the application message, the server D1 decrypts with the private key and replies to the new client M1, requesting the new client M1 to send the identity verification material;
  • the server D1 first performs message authentication according to the hash value h2, and verifies the registration value or certificate; if the verification is passed, the server D1 generates a key encryption key KEK, and sends the public key PM using the new client to the new client M1.
  • the encrypted key is encrypted with the key KEK and assigned a new registration value KM2; if the verification fails, the authentication is recognized and the communication is interrupted;
  • Server D1 calculates the following values:
  • KE_down T1+s* ⁇ hash(KM2)+hash(x) ⁇ [G];
  • X ⁇ s*hash(x) ⁇ [G]; where x is the group key being used, t1 is the current time, and s is the private key of server D1;
  • X Whether it is equal to h(3); if the verification is passed, the new client M1 generates KE_up, and sends KE_up encrypted with KEK to the server D1, with a hash value h(4) SM3(KE_up), the server After receiving the message, D1 calculates (KE_up*KE_down')[G] as the new group key; if the verification fails, the communication is interrupted;
  • the identity authentication of the server D1 can be realized without significantly increasing the calculation amount, that is, the two-way identity authentication is realized.
  • the new client authentication process may also be implemented by using quantum key negotiation; wherein the new client M1 is connected to the quantum key server L2; the server is connected to the quantum key server L1;
  • the new client authentication process includes:
  • the new client M1 initiates an authentication application to the server D1;
  • the server D1 After receiving the authentication application message, the server D1 requires a quantum method for identity authentication.
  • the new client M1 requests the quantum key servers L2 and L1 to perform quantum key negotiation according to a predetermined protocol to obtain a quantum key K_QU5, and both parties calculate (K_QU5*KE_down') [G] as a new group key.
  • this method guarantees the absolute security of KE_up, improves the security of the group key, and does not require other group clients other than the new client M1 to have a quantum key server.
  • the new client M1 has a quantum key management device QC, and the quantum key management device is bound to the quantum key server L2, QC and L2 have shared quantum random numbers; the server D1 is directly connected to the quantum key server L1;
  • the new client authentication process includes:
  • the new client M1 sends an authentication request to the server D1;
  • the server D1 After receiving the authentication application, the server D1 verifies the identity of the new client M1 in the same manner as in the above embodiment.
  • the quantum key servers L1 and L2 perform quantum key negotiation to obtain a quantum key K_QU6;
  • the encryption formula is:
  • KE_down t1[G]+[SM3(KM1)]P+SM3(x) according to KE_up, t1, SM3(KM1), combined with known P and x.
  • the server sends a random number Nj and its hash value SM3 (Nj) to all the clients in the group, and uses the original multicast key when sending. Encrypt data
  • the present application has at least the following advantages compared with the prior art: 1. Providing a secure communication scheme considering a specific application scenario for a virtual power plant service. 2. The use of traditional classic keys and unconditionally secure quantum keys to ensure the feasibility and gradual evolution of virtual power plant security communication solutions. 3. Provides a complete set of full-classical and quantum-fused secure communication solutions for unicast and multicast communication of virtual power plant services.
  • the embodiment further provides a virtual power plant security communication device based on quantum key fusion, comprising:
  • the identity authentication module is configured as an identity authentication: based on the communication requirement, authenticating the identity between the client and the server in the virtual power plant and obtaining the root key; wherein the server includes a commercial virtual power plant and a power market service a system or technology type virtual power plant; the client corresponds to a distributed power source, a commercial virtual power plant or a technical virtual power plant;
  • the distribution module is configured as a key distribution: based on the obtained root key, a key encryption key and a message authentication key are generated correspondingly, thereby implementing data encryption key negotiation to obtain a data encryption key;
  • the encryption module is configured as data encryption: the data to be encrypted is encrypted by the data encryption key and the data communication is implemented accordingly;
  • the quantum key server is used to implement quantum key negotiation, and the negotiated quantum key implements corresponding identity authentication or as a data encryption key.
  • the authentication module is configured to send, by the client, corresponding identity information, a client certificate, a client hash value, and a random number to the corresponding server;
  • the device also includes:
  • the receiving module is configured to receive the information sent by the client and verify the information, and if the verification information is met, the root key is given, and the root key is encrypted by using the public key in the certificate, and then sent to the client;
  • the authentication module is further configured to decrypt the same root key by using the corresponding private key, and complete the identity authentication.
  • the identity authentication process includes performing authentication by using a fast authentication method.
  • the client and the server respectively have a historical data index table, where the historical data index table includes time, identity information, and respective historical secrets.
  • the key and the historical hash value; the client and the server generate a key k for each session, denoted as k 0 , k 1 , k 2 ... k n , and the historical key hash value generated each time is recorded as h 1 , h 2 , h 3 ... h n , XOR the hash value of k and the hash value of h to obtain a new historical key hash value; h n is calculated by the following formula:
  • n is a natural number greater than 1, and SHA1 is a hash algorithm
  • the client and the server authenticate according to the historical data index table
  • the root key is granted after the authentication is successful.
  • the authentication module is further configured to: the client extracts the last key value k, the last time Ti, and the index value ind in the index table in the corresponding historical data index table;
  • the client uses the last key value, the last time, and the index value to calculate the hash value, and the identity information and the random number of the client are sent to the server as a message; wherein the message is encrypted using the last key value. And attaching an index value; the message is expressed as: ESM4[SHA1(k
  • the server After receiving the message information, the server retrieves the historical data index table in the server according to the index value in the message information and extracts related information in the index table, decrypts the message information by using the encryption key, and compares and decrypts the message first.
  • the server generates a new random number Nj, and returns the confirmation information and the new time T to the client through the message; the message is encrypted with k, and the encryption formula is as follows: Encrypt(Nj
  • the client After receiving the message information, the client decrypts and obtains a new random number Nj and a new time T;
  • the server and the client calculate by using the random number Ni, Nj, the new time T, and the new historical hash value h to obtain a new root key AK; wherein the calculation formula of the root key AK is:
  • AK Truncate_128[SHA1(Ni
  • the distribution module is further configured to send a key request to the server by the client; wherein the key application includes a random number Nh;
  • the server After receiving the key application, the server generates a key encryption key KEK, an uplink message authentication key HMAC_key1, and a downlink message authentication key HMAC_key2 according to the root key Ak and the random number Nh; the key encryption key KEK is as follows Formula calculation:
  • 0 ⁇ 44 represents 44 zeros
  • Nh is a 64-bit random number
  • the uplink message authentication key is calculated by the following formula:
  • the downlink message authentication key is calculated by the following formula:
  • 36 44 denotes that 44 0X36 are connected after the 128-bit root key AK, a 352-bit bit string is formed, then the 480-bit string is hashed, and finally the XOR is performed with the random number Nh;
  • the client and the server perform negotiation of the data encryption key TEK; wherein the client sends a negotiation application to the server, the application message is encrypted by using KEK, and the key of the message digest uses HMAC_key1;
  • the server After receiving the request, the server encrypts the TEK parameter list and sends it to the client using the KEK.
  • the key for sending the message digest uses HMAC_key2.
  • the data encryption process encrypts application layer service data by using one or more combination algorithms of SM4-CBC, DES, AES, and SM1; wherein all data is performed by using a message authentication key.
  • the hash operation is attached to the data tail, and the hash key in the uplink direction is the uplink message authentication key HMAC_key1, and the hash key in the downlink direction is the downlink message authentication key HMAC_key2.
  • the identity authentication process utilizes a quantum key server to implement quantum key negotiation; wherein both the client and the server have a quantum key server, and the client is provided with a quantum key management device at the client Before the end communicates with the server, the client's quantum key management device performs binding registration at the quantum key server in advance, and the quantum key server requires the quantum random number generator to generate a large number of random numbers for use as keys to be stored in the quantum key.
  • the authentication module is configured to send a data transmission request to the server by the client;
  • the server After receiving the request, the server generates a random number Nb, and sends the random number Nb to the client together with the quantum identity authentication request;
  • the client After receiving the quantum identity authentication request, the client sends the service information to the bound quantum key server L2 through the quantum key management device QC of the client, and the information content is that the server requests the quantum identity authentication of the client;
  • the quantum key server L1 of the server After the quantum key server L2 receives the service information of the client, the quantum key server L1 of the server performs quantum key negotiation with the quantum key server L2 of the client, and the client and the server obtain the agreed secret after the quantum key negotiation is completed.
  • the server generates a random number as the root key AK, and calculates the signal. And sent to the quantum key server L2 through the classic channel;
  • the quantum key server L2 After the quantum key server L2 receives the signal E, it calculates And select the quantum random number Ni pre-stored between the client and the quantum key server L2, and calculate Subsequently, the quantum key server L2 sends the ST, the random number Ni pointer ptr, the length long, and the hash (AK') to the client together;
  • the client After receiving the message, the client extracts the random number Ni using the random number pointer ptr and the length long, and calculates Sending a message digest HMAC(AK") Nb to the server;
  • both the identity authentication process and the key distribution process utilize a quantum key server to implement quantum key negotiation
  • the authentication module is further configured to: the client sends an identity authentication request to the server through the classic channel; after receiving the identity authentication request, the server generates a set of random numbers as the root key AK through the quantum random number generator, and requests the quantum
  • the key servers L2 and L1 perform quantum key negotiation; the quantum key servers L1 and L2 perform quantum key negotiation according to a predetermined protocol to obtain a key K_QU2; the server obtains the key K_QU2, and calculates And send E to the client; client computing And hash (AK'), and sent to the server; the server determines whether the hash (AK') is equal to the hash (AK), if equal, the identity authentication for the client is completed; if not, the authentication fails, the communication is interrupted ;
  • the distribution module is configured to: the client and the server use AK as a root key to generate a corresponding message authentication key and a key encryption key KEK; and the client requests the quantum key servers L1 and L2 to perform quantum key negotiation;
  • the quantum key servers L1 and L2 perform quantum key negotiation according to a predetermined protocol to obtain a key K_QU3; the client and the server obtain the key K_QU3, and use the key K_QU3 as a data encryption key.
  • one server corresponds to multiple clients for multicast communication
  • the device also includes:
  • a group key initial module configured to register each client first at the server and obtain a registration value
  • Each client sends a registration value to the server and the selected random number B1 ⁇ Bn;
  • the server After receiving the random number, the server calculates B1*B2*...*Bn[G] as the group key; where G is the base point corresponding to the ellipse encryption algorithm;
  • the server sends the group key to the client
  • each client After receiving the relevant data, each client calculates the group key by using the relevant data and the respective random numbers;
  • the certificate cert is sent to the server; the server D1 is first based on the The hash value h2 is used for message authentication, and the registration value or certificate is verified; if the verification is passed, the server D1 generates a key encryption key KEK, and transmits a key encryption key encrypted by the public key PM of the new client to the new client M1. Key KEK, and assign a new registration value KM2; if the verification fails, the authentication is recognized and the communication is interrupted;
  • Server D1 calculates the following values:
  • KE_down T1+s* ⁇ hash(KM2)+hash(x) ⁇ [G];
  • X ⁇ s*hash(x) ⁇ [G]; where x is the group key being used, t1 is the current time, and s is the private key of server D1;
  • X Whether it is equal to h(3); if the verification is passed, the new client M1 generates KE_up, and sends KE_up encrypted with KEK to the server D1, with a hash value h(4) SM3(KE_up), the server After receiving the message, D1 calculates (KE_up*KE_down')[G] as the new group key; if the verification fails, the communication is interrupted;
  • the encryption formula is:
  • KE_down t1[G]+[SM3(KM1)]P+SM3(x) according to KE_up, t1, SM3(KM1), combined with known P and x.
  • the server sends a random number Nj and its hash value SM3 (Nj) to all the clients in the group, and uses the original multicast key when sending. Encrypt data
  • the new client authentication process may also be implemented by using quantum key negotiation; wherein the new client M1 is connected to the quantum key server L2; the server is connected to the quantum key server L1;
  • the authentication module is configured as a new client authentication, and may include:
  • the new client M1 initiates an authentication application to the server D1;
  • the server D1 After receiving the authentication application message, the server D1 requires a quantum method for identity authentication.
  • the new client M1 requests the quantum key servers L2 and L1 to perform quantum key negotiation according to a predetermined protocol to obtain a quantum key K_QU5, and both parties calculate (K_QU5*KE_down')[G] as a new group key;
  • the new client M1 has a quantum key management device QC, and the quantum key management device is bound to the quantum key server L2, QC and L2 have shared quantum random numbers; the server D1 is directly connected to the quantum key server L1;
  • the new client authentication process includes:
  • the new client M1 sends an authentication request to the server D1;
  • the server D1 After receiving the authentication application, the server D1 verifies the identity of the new client M1 by means of the method of claim 9;
  • the quantum key servers L1 and L2 perform quantum key negotiation to obtain a quantum key K_QU6;
  • the embodiment of the present invention further provides a computer storage medium storing computer executable instructions; after the computer executable instructions are executed, the quantum key fusion provided by the one or more embodiments can be implemented.
  • a virtual power plant secure communication method for example, the method shown in FIG. 3 and/or FIG.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Electromagnetism (AREA)
  • Physics & Mathematics (AREA)
  • Power Engineering (AREA)
  • Storage Device Security (AREA)
  • Computer And Data Communications (AREA)

Abstract

本申请公开了一种基于量子密钥融合的虚拟电厂安全通信方法,包括:身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;上述进行身份认证或者密钥分发的过程中,利用量子密钥服务器实现量子密钥协商,并且将协商得到的量子密钥实现相应的身份认证或者作为数据加密密钥。本申请实施例还公开了一种基于量子密钥融合的虚拟电厂安全通信装置及计算机存储介质。

Description

基于量子密钥融合的虚拟电厂安全通信方法及装置、介质 技术领域
本申请涉及电力技术领域但不限于电力技术领域,特别是指一种基于量子密钥融合的虚拟电厂安全通信方法及装置、计算机存储介质。
背景技术
当前,随着大量不同种类的新能源和分布式发电设备的并网发电,对电网调度和安全运行带来了新的严峻挑战。虚拟电厂是一种合理整合和优化利用分布式新能源的有效形式,同时也能有效参与电力市场的能源交易过程。但目前对于虚拟电厂的研究主要是从电力系统经济可靠运行的角度讨论问题,具体工作主要包括能源管理、系统运行、优化调度、预测建模等方面,而对如何依托先进密码、身份认证、加密通信等技术来保障信息通信安全,确保能源互联网的可靠运行尚未有高相关性内容的研究。
传统的信息安全措施基于数学问题的计算复杂性,在分布式计算、云计算和量子计算等数值计算能力日益发展的今天,传统密码学并不能保障数据传输的绝对安全,而量子密码学基于量子测不准原理,量子态测量塌缩和未知量子态不可克隆等物理定理,可以很好地保障信息传输的长期和绝对安全。近年来,虽然电力系统的信息安全受到人们的广泛关注,也有一些将量子密钥分配技术引入电力系统的研究。但纵观现有相关成果可以看出:现有工作要么单纯从量子密钥技术的角度进行讨论,要么只是简单的在电力系统中提出应用量子技术,成果与电力具体业务系统的结合深度不足,难以实现高效安全的通信手段,尤其是针对于虚拟电厂相关的通信安全。
发明内容
本申请的目的在于提出一种基于量子密钥融合的虚拟电厂安全通信方法及装置、计算机存储介质。
本申请实施例提供了一种基于量子密钥融合的虚拟电厂安全通信方法,包括:
身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;其中,所述服务端包括商业型虚拟电厂、电力市场业务系统或技术型虚拟电厂;所述客户端对应包括分布式电源、商业型虚拟电厂或技术型虚拟电厂;
密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;
数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;
其中,上述进行身份认证或者密钥分发的过程中,利用量子密钥服务器实现量子密钥协商,并且将协商得到的量子密钥实现相应的身份认证或者作为数据加密密钥。
本申请实施例还提供一种基于量子密钥融合的虚拟电厂安全通信装置,包括:
身份认证模块,配置为身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;其中,所述服务端包括商业型虚拟电厂、电力市场业务系统或技术型虚拟电厂;所述客户端对应包括分布式电源、商业型虚拟电厂或技术型虚拟电厂;
分发模块,配置为密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;
加密模块,配置为数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;
其中,上述进行身份认证或者密钥分发的过程中,利用量子密钥服务器实现量子密钥协商,并且将协商得到的量子密钥实现相应的身份认证或者作为数据加密密钥。
本申请实施例还提供一种计算机存储介质,所述计算机存储介质存储有计算机可执行指令;所述计算机可执行指令被执行后,能够实现前述的基于量子密钥融合的虚拟电厂安全通信方法。
本申请实施例提供的基于量子密钥融合的虚拟电厂安全通信方法,通过将量子密钥与经典加密方式进行融合的方式实现虚拟电厂的安全通信,即不会过多的增加成本,又能大大提高通信过程中的数据安全性。因此,本申请能够提供一种安全、可靠并且经济有效的安全通信方法,提高虚拟电厂通信安全性和可靠性。
附图说明
图1为本申请实施例提供的虚拟电厂通信网络结构示意图;
图2为本申请实施例提供的加密密钥与历史密钥哈希值关系示意图;
图3为本申请实施例提供的通过根密钥获得相关密钥的关系示意图;
图4为本申请实施例提供的虚拟电厂进行单播或者组播通信流程示意图;
图5为本申请实施例提供的基于量子密钥融合的虚拟电厂安全通信方法的流程示意图。
具体实施方式
为使本申请的目的、技术方案和优点更加清楚明白,以下结合具体实施例,并参照附图,对本申请进一步详细说明。
需要说明的是,本申请实施例中所有使用“第一”和“第二”的表述均是为了区分两个相同名称非相同的实体或者非相同的参量,可见“第一”“第二”仅为了表述的方便,不应理解为对本申请实施例的限定,后续实施例对此不再一一说明。
本申请针对于当前加密通信现状,考虑到量子产品的价格较高,可利用常用经典和量子密钥融合,进而提出了一种基于量子密钥融合的虚拟电厂安全通信方法,具有良好的应用前景。
为了更加清楚的理解本申请方案,首先对虚拟电厂相关信息作出解释,如下:虚拟电厂中的通信通常包含商业型虚拟电厂(CVPP)和分布式电源(DER)之间、CVPP和电力市场业务系统之间、CVPP和技术型虚拟电厂(TVPP)之间、TVPP和DER之间的单播通信以及电力市场业务系统与CVPP之间的组播通信;参照图1所示,为本申请提供的虚拟电厂通信网络结构示意图。由图1可知,通常电力市场业务系统与多个商业型虚拟电厂(CVPP)以及传统电厂连接,而每个商业型虚拟电厂(CVPP)分别与不同的技术型虚拟电厂(TVPP)连接。其中,量子通信需要以下设备作为支撑:量子信道,用于量子信息的传输;量子可信中继设备,用于量子密钥的可信中继接力;量子密钥服务器,用于量子密钥的生成与管理;经典信道,用于传输量子密钥外的经典信息;量子随机数发生器,用于产生量子随机数作为密钥发送给量子密钥服务器和量子密钥管理装置,其隶属于量子密钥服务器;用户端量子密钥管理装置,用于产生相关的业务密钥。
在本申请一些实施例中,参照图5所示,所述基于量子密钥融合的虚拟电厂安全通信方法包括如下步骤:
(1)身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;其中,所述服务端包括商业型虚拟电厂、电力市场业务系统或技术型虚拟电厂;所述客户端对应包括分布式电源、商业型虚拟电厂或技术型虚拟电厂;例如:服务端为商业型虚拟电厂(CVPP),客户端为分布式电源(DER)。
在本申请一些实施例中,所述身份认证过程包括采用证书认证方式进行认证;其中,采用证书认证时需要可信的第三方分别给客户端和服务端签发相应证书;
采用证书认证过程包括如下步骤:
客户端将对应的身份信息ID_C1、客户端证书,例如X.509、客户端哈希值以及随机数Nh发送给相应的服务端;
服务端接收客户端发送的信息并且对信息进行验证,若验证信息符合,则给出根密钥,即授权密钥AK,并且将根密钥利用证书中的公钥加密后发送给客户端;
客户端用对应的私钥解密得到同样的根密钥,完成身份认证。
在本申请另一些实施例中,所述身份认证过程包括采用快速认证方法进行认证;其中,客户端和服务端分别拥有历史数据索引表,所述历史数据索引表中包含时间、身份信息、各自的历史密钥与历史哈希值;客户端和服务端每次会话会产生加密密钥k,记为k 0,k 1,k 2……k n,每次产生的历史密钥哈希值记为h 1,h 2,h 3……h n,将k的哈希值和h的哈希值进行异或运算,得到了新的历史密钥哈希值;参照图2所示,h n通过如下公式计算:
Figure PCTCN2018102358-appb-000001
Figure PCTCN2018102358-appb-000002
其中,n为大于1的自然数,SHA1为哈希算法;
客户端和服务端根据历史数据索引表进行认证;
认证成功后授予根密钥。
在一些实施例中,所述客户端和服务端根据历史数据索引表进行认证的步骤还包括:
客户端在对应的历史数据索引表中提取得到索引表内的上次密钥值k、上次时间Ti和索引值ind;
客户端利用上次密钥值、上次时间和索引值计算哈希值,连带客户端的身份信息和随机数,作为报文发送给服务端;其中,该报文使用上次密钥值加密,并附上索引值;
所述报文表示为:ESM4[SHA1(k|Ti|Ni|ind)|ID_DER|Ni] k|ind;
其中,ESM4为商密算法;k为加密密钥;Ti为上次时间;Ni为随机数;ind为索引值;ID_DER为客户端的身份信息;
服务端接收到上述报文信息后,根据报文信息中的索引值检索服务端内的历史数据索引表并提取索引表中的相关信息,用加密密钥对报文信息进行解密,先对比解密得到的客户端身份信息以获取客户端的身份,然后利用索引表中对应的上次时间,加密密钥,索引值和随机数计算哈希值,与客户端发送的哈希值进行比对;若两者相等,则确认客户端的身份信息真实有效,接纳该客户端的认证,并更新历史数据索引表内的历史哈希值、历史密钥、时间相关信息;若哈希值不相等,则身份认证失败,中断通信;至此,服务端对于客户端的身份认证结束,认证成功后,随后进行根密钥 的生成,为密钥分发做准备。
服务端产生新的随机数Nj,并将确认信息和新的时间T通过报文一起返回给客户端;报文用k加密,加密公式如下:Encrypt(Nj|T) k
客户端收到报文信息后进行解密,获得新随机数Nj和新时间T;
服务端和客户端通过随机数Ni、Nj、新时间T以及新历史哈希值h进行计算,得到新的根密钥AK;其中,根密钥AK的计算公式为:
AK=Truncate_128[SHA1(Ni|Nj|T|h)];其中,Truncate_128表示取前128位。
这样,即使攻击方破解了密钥k,但由于没有历史哈希值,所以也无法获得新的根密钥AK。
在本申请一些实施例中,所述身份认证过程还可以利用量子密钥服务器实现量子密钥协商;其中,客户端和服务端均具有量子密钥服务器,客户端设置有量子密钥管理装置,在客户端和服务端进行通信之前,客户端的量子密钥管理装置预先在量子密钥服务器处进行绑定注册,量子密钥服务器要求量子随机数发生器产生大量随机数用作密钥存储在量子密钥服务器和客户端的量子密钥管理装置中;客户端的量子密钥管理装置与量子密钥服务器L2共享量子随机数密钥,服务端直接连接量子密钥服务器L1;
利用量子密钥实现所述身份认证过程包括如下步骤:
客户端向服务端发送数据传输请求;
服务端收到请求后,产生随机数Nb,并将所述随机数Nb与量子身份认证要求一起发送给客户端;
客户端收到量子身份认证要求后,通过客户端的量子密钥管理装置QC向绑定的量子密钥服务器L2发出服务信息,信息内容为服务端要求对客户端进行量子身份认证;
量子密钥服务器L2收到客户端的服务信息后,服务端的量子密钥服务器L1与客户端的量子密钥服务器L2进行量子密钥协商,量子密钥协商完成之后客户端和服务端得到达成一致的密钥K_QU1;
服务端产生随机数作为根密钥AK,计算信号
Figure PCTCN2018102358-appb-000003
并通过经典信道发送给量子密钥服务器L2;
量子密钥服务器L2接收到信号E后,计算
Figure PCTCN2018102358-appb-000004
并选择 客户端和量子密钥服务器L2之间预存的量子随机数Ni,计算
Figure PCTCN2018102358-appb-000005
随后,量子密钥服务器L2将ST、随机数Ni指针ptr、长度long以及hash(AK’)一起发送给客户端;
客户端收到消息之后,使用随机数指针ptr及长度long提取随机数Ni,并计算
Figure PCTCN2018102358-appb-000006
将消息摘要HMAC(AK”) Nb发送给服务端;
服务端收到上述消息摘要后,计算HMAC(AK) Nb是否与HMAC(AK”) Nb一致,若一致,则确认客户端的身份,并使用AK作为根密钥;若不一致则认证失败,结束通信。
在一些实施例中,可采用无线通信设备收发数据,以应对客户端广分布所带来的通信布线困难问题。在无线通信情况下,客户端的量子密钥管理装置可通过定期到密钥管理服务器利用USB拷贝方式获得量子随机数。此后,可应用密钥对应用层数据加密,并可辅助采用802.16协议对低层数据加密。
(2)密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;参照图3所示,基于根密钥可以相应的衍生得到消息认证密钥、密钥加密密钥,进而利用密钥加密密钥得到业务加密密钥,也即数据加密密钥。
在本申请一些实施例中,所述密钥分发过程包括:
客户端向服务端发送密钥申请;其中,密钥申请中包含随机数Nh;
服务端接收到密钥申请后,根据根密钥Ak和随机数Nh生成密钥加密密钥KEK、上行消息认证密钥HMAC_key1及下行消息认证密钥HMAC_key2;所述密钥加密密钥KEK通过如下公式计算:
Figure PCTCN2018102358-appb-000007
其中,0^44表示44个0,Nh为64位随机数;
所述上行消息认证密钥通过如下公式计算:
Figure PCTCN2018102358-appb-000008
所述下行消息认证密钥通过如下公式计算:
Figure PCTCN2018102358-appb-000009
其中,36 44表示对在128位根密钥AK后面连接44个0X36,形成352位比特串,然后对这480位比特串进行哈希运算,最后和随机数Nh进行异 或运算;
客户端和服务端进行数据加密密钥TEK的协商;其中,客户端向服务端发送协商申请,该申请消息使用KEK加密,消息摘要的密钥使用HMAC_key1;
服务端收到请求后将TEK参数列表使用KEK加密并发送给客户端,发送消息摘要的密钥使用HMAC_key2。
(3)数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;其中,所述待加密的数据包括客户端发送给服务端的设备与运行状态参数、实时发电数据、边际成本、实时用电数据、储能容量和储能设备状态参数等。
在本申请一些实施例中,所述数据加密过程采用SM4-CBC、DES、AES、SM1中的一种或者多种组合算法对各应用层业务数据进行加密;其中,所有数据通过消息认证密钥进行哈希运算并附在数据尾部,且上行方向的哈希密钥采用上行消息认证密钥HMAC_key1,下行方向的哈希密钥采用下行消息认证密钥HMAC_key2。其中,CBC是密码分组链接模式,目的是让重复的明文分组产生不同的密文分组。
由上述实施例可知,本申请提供的基于量子密钥融合的虚拟电厂安全通信方法,通过将量子密钥与经典加密方式进行融合的方式实现虚拟电厂的安全通信,即不会过多的增加成本,又能大大提高通信过程中的数据安全性。因此,本申请能够提供一种安全、可靠并且经济有效的安全通信方法,提高虚拟电厂通信安全性和可靠性。
在本申请一些实施例中,上述身份认证过程和密钥分发过程均利用量子密钥服务器实现量子密钥协商;
所述身份认证过程包括如下步骤:
客户端通过经典信道向服务端发送身份认证请求;
服务端收到身份认证请求后,通过量子随机数发生器产生一组随机数作为根密钥AK,并要求量子密钥服务器L2和L1进行量子密钥协商;
量子密钥服务器L1和L2依据预定协议进行量子密钥协商后,得到密钥K_QU2;
服务端获取密钥K_QU2,计算
Figure PCTCN2018102358-appb-000010
并将E发送给客户端;
客户端计算
Figure PCTCN2018102358-appb-000011
和hash(AK’),并发送给服务端;
服务端判断hash(AK’)是否等于hash(AK),若相等,则完成了对于客户端的身份认证;若不等,则认证失败,中断通信;
所述密钥分发过程包括:
客户端和服务端以AK作为根密钥,产生对应的消息认证密钥和密钥加密密钥KEK;
客户端要求量子密钥服务器L1和L2进行量子密钥协商;
量子密钥服务器L1和L2依据预定协议进行量子密钥协商,得到密钥K_QU3;
客户端和服务端获得密钥K_QU3,并将密钥K_QU3作为数据加密密钥。
最后按照同样的数据加密过程实现带加密数据的加密。
在一些实施例中,还可以在密钥分发过程采用量子一次一密方式进行双方安全通信,所述密钥分发过程包括:
客户端和服务端均以AK作为根密钥,然后衍生得到消息认证密钥;
客户端与服务端每次通信时,都要求量子密钥服务器L1和L2进行量子密钥协商;
量子密钥服务器L1和L2依据BB84协议进行量子密钥协商,得到密钥K_QU4;
客户端和服务端获得K_QU4,并将其作为数据加密密钥。
上述方式虽然对于量子密钥的消耗量较大,但可以保证数据的绝对安全。
在本申请一些实施例中,针对于组播情形,除了需要考虑上述通讯安全,而且需要考虑到新客户端的加入与退出引起的认证以及组密钥更新过程。首先,通常来说,组播主要包括电力市场各业务系统向各CVPP的组播信息,包括当前时段各种能源电价,未来时段能量需求等信息;还包括各种电力辅助市场需求信息,如一次调频、自动发电控制、调峰、无功调节、旋转备用、黑启动等业务信息。例如:设某电力市场业务系统包含5个CVPP,该电力市场向5个客户端组播能量需求竞价方案消息,其中,组播中心为电力市场业务系统,组内客户端为各CVPP。
因此基于本申请提出的方案,若通信为组播通信时,一个服务端对应多个客户端进行组播通信;参照图4所示,为本申请提供的虚拟电厂进行单播或者组播通信流程示意图。所述虚拟电厂通信方法还包括如下步骤:
1、组密钥初始化,实现过程如下:
初始化之前,各客户端首先在服务端处注册,并获得注册值;
各客户端向服务端发送注册值以及选择的随机数B1~Bn;其中,n为客户端的数量。Bn为客户端n选择的随机数;
服务端收到随机数后,计算B1*B2*…*Bn[G]作为组密钥;其中,G为椭圆加密算法对应的基点;基于本方案使用椭圆加密算法实现,所使用的椭圆曲线为E(a,b),基点为G(xG,yG);
服务端向客户端发送组密钥时,将除当前客户端外其余客户端的随机数与基点乘积计算结果以及椭圆加密算法对应的椭圆曲线参数发给当前客户端,公式如下:Ci=B1*…*Bi-1*Bi+1*…*Bn[G];其中,Ci为当前第i个客户端对应的相关数据;
各客户端收到相关数据后,利用该相关数据与各自随机数计算得到组密钥;例如客户端1计算C1*B1作为组密钥。
这样,即使传输的密钥Ci被攻击,由于攻击者不具有客户端自身的随机数Bi,因此,也无法获得组密钥。
2、新客户端认证:
当服务端中有新的客户端M1希望加入服务端D1的组播群组,且客户端已知组播加密所用的椭圆曲线、基点G以及服务端公钥P;则新客户端获得组密钥的过程包括步骤:
新客户端计算h(1)=SM3(Nm|ID_M1),并向服务端发送加入组播群组的申请;其中,申请中包含随机数Nm、新客户端M1的身份信息ID_M1、新客户端的公钥PM和h(1);SM3为哈希算法,且申请消息使用服务端公钥P加密,加密公式为:SM2[Nm|ID_M1|PM|h(1)] p;其中,SM2为椭圆曲线加密算法;
服务端D1收到申请消息后,用私钥解密并向新客户端M1回复信息,要求新客户端M1发送身份证明材料;
新客户端M1收到服务端发送的消息后,若新客户端具有注册值,则向 服务端发送新客户端的注册值KM1,并附带哈希值h2=SM3(KM1),若新客户端M1没有注册值,则向服务端发送证书cert;
服务端D1首先根据哈希值h2进行消息认证,并验证该注册值或证书;若验证通过,则服务端D1生成密钥加密密钥KEK,向新客户端M1发送使用新客户端的公钥PM加密的密钥加密密钥KEK,并分配一个新的注册值KM2;若验证不通过,则认证识别,中断通信;
服务端D1计算如下值:
T1=t1[G];
KE_down=T1+s*{hash(KM2)+hash(x)}[G];
X={s*hash(x)}[G];其中,x为正在使用的组密钥,t1为当前时间,s为服务端D1的私钥;
服务端D1计算哈希值h(3)=SM3(KM2|T1|KE_down|X),向新客户端M1发送T1和X,并附上h(3)用作消息认证;
新客户端M1接收消息T1和X,利用已知的公钥P和其注册值KM2,计算KE_down’=T1+[hash(KM2)]P+X,并验证hash(KM2|T1|KE_down’|X)是否与h(3)相等;若验证通过,则新客户端M1生成KE_up,并向服务端D1发送使用KEK加密的KE_up,且附带哈希值h(4)=SM3(KE_up),服务端D1收到消息后,计算(KE_up*KE_down’)[G]作为新的组密钥;若验证失败,则中断通信;
这样,能够在不明显增加计算量的情况下实现了对服务端D1的身份认证,即实现了双向身份认证。
在本申请一些实施例中,所述新客户端认证过程还可以通过采用量子密钥协商的方式实现;其中,新客户端M1连接量子密钥服务器L2;服务端连接量子密钥服务器L1;
所述新客户端认证过程包括:
新客户端M1向服务端D1发起认证申请;
服务端D1收到认证申请消息后要求采用量子方式进行身份认证;
采用如上述实施例中同样的认证方式实现新客户端认证;
认证完成后,新客户端M1请求量子密钥服务器L2和L1依据预定协议进行量子密钥协商,得到量子密钥K_QU5,双方计算(K_QU5*KE_down’) [G]作为新的组密钥。这一方式一方面保证了KE_up的绝对安全,提高了组密钥的安全性,另外并不要求出新客户端M1之外的其他组内客户端拥有量子密钥服务器。
或者,
新客户端M1拥有量子密钥管理装置QC,且量子密钥管理装置绑定量子密钥服务器L2,QC和L2拥有共享的量子随机数;服务端D1直接连接量子密钥服务器L1;
所述新客户端认证过程包括:
新客户端M1向服务端D1发送认证申请;
服务端D1收到认证申请后,通过如上述实施例中同样的方式验证新客户端M1身份;
量子密钥服务器L1和L2进行量子密钥协商后得到量子密钥K_QU6;
选择QC和L2之间预存的某段量子随机数为Nc,L2计算
Figure PCTCN2018102358-appb-000012
Figure PCTCN2018102358-appb-000013
并发送给新客户端M1;
新客户端M1通过计算
Figure PCTCN2018102358-appb-000014
得到K_QU6,用K_QU6来加密KE_up进而实现身份认证。
3、组密钥更新:
对于以下两种情况,需要进行组密钥更新;
一、若有新加入客户端,新客户端的与服务端双向身份认证后,新客户端直接采用K_group=(KE_up*KE_down)[G]作为新组播密钥;
对组内其它客户端,服务端D1将{KE_up,t1,SM3(KM1)}用原组播密钥加密,并附上哈希值h(5)=SM3(KE_down)发给其它客户端,加密公式为:
SM4[KE_up|t1|SM3(KM1)] x
组内其它客户端收到消息后,根据KE_up,t1,SM3(KM1),结合已知的P和x,计算得到KE_down”=t1[G]+[SM3(KM1)]P+SM3(x)P,验证SM3(KE_down”)是否与h(5)一致;若一致,则计算得到K_group=(KE_up*KE_down”)[G]作为新的组播密钥;
二、若有客户端离开或者是密钥更新时间到,则服务端将选择的一个随机数Nj和其哈希值SM3(Nj)发送给所有组内客户端,发送时用原组播密 钥加密数据;
组内客户端收到该消息后计算K_group=Nj[G]+SM3(Nj)]P+SM3(x)P作为新的组播密钥。
由上述实施例可知,本申请与现有技术相比,至少具有以下优点:1、针对虚拟电厂业务,提供考虑具体应用场景的安全通信方案。2、融合使用传统的经典密钥和无条件安全的量子密钥,保证虚拟电厂安全通信方案的可行性和逐步演进。3、针对虚拟电厂业务的单播和组播通信,提供了一整套包括全经典和量子融合安全通信方案。
本实施例还提供一种基于量子密钥融合的虚拟电厂安全通信装置,包括:
身份认证模块,配置为身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;其中,所述服务端包括商业型虚拟电厂、电力市场业务系统或技术型虚拟电厂;所述客户端对应包括分布式电源、商业型虚拟电厂或技术型虚拟电厂;
分发模块,配置为密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;
加密模块,配置为数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;
其中,上述进行身份认证或者密钥分发的过程中,利用量子密钥服务器实现量子密钥协商,并且将协商得到的量子密钥实现相应的身份认证或者作为数据加密密钥。
在一些实施例中,所述认证模块,配置为客户端将对应的身份信息、客户端证书、客户端哈希值以及随机数发送给相应的服务端;
所述装置还包括:
接收模块,配置为服务端接收客户端发送的信息并且对信息进行验证,若验证信息符合,则给出根密钥,并且将根密钥利用证书中的公钥加密后发送给客户端;
所述认证模块,还配置为客户端用对应的私钥解密得到同样的根密钥,完成身份认证。
在一些实施例中,所述身份认证过程包括采用快速认证方法进行认证; 其中,客户端和服务端分别拥有历史数据索引表,所述历史数据索引表中包含时间、身份信息、各自的历史密钥与历史哈希值;客户端和服务端每次会话会产生密钥k,记为k 0,k 1,k 2……k n,每次产生的历史密钥哈希值记为h 1,h 2,h 3……h n,将k的哈希值和h的哈希值进行异或运算,得到了新的历史密钥哈希值;h n通过如下公式计算:
Figure PCTCN2018102358-appb-000015
Figure PCTCN2018102358-appb-000016
其中,n为大于1的自然数,SHA1为哈希算法;
客户端和服务端根据历史数据索引表进行认证;
认证成功后授予根密钥。
在一些实施例中,所述认证模块,还配置为客户端在对应的历史数据索引表中提取得到索引表内的上次密钥值k、上次时间Ti和索引值ind;
客户端利用上次密钥值、上次时间和索引值计算哈希值,连带客户端的身份信息和随机数,作为报文发送给服务端;其中,该报文使用上次密钥值加密,并附上索引值;所述报文表示为:ESM4[SHA1(k|Ti|Ni|ind)|ID_DER|Ni] k|ind;其中,ESM4为商密算法;k为加密密钥;Ti为上次时间;Ni为随机数;ind为索引值;ID_DER为客户端的身份信息;
服务端接收到上述报文信息后,根据报文信息中的索引值检索服务端内的历史数据索引表并提取索引表中的相关信息,用加密密钥对报文信息进行解密,先对比解密得到的客户端身份信息以获取客户端的身份,然后利用索引表中对应的上次时间,加密密钥,索引值和随机数计算哈希值,与客户端发送的哈希值进行比对;若两者相等,则确认客户端的身份信息真实有效,接纳该客户端的认证,并更新历史数据索引表内的历史哈希值、历史密钥、时间相关信息;若哈希值不相等,则身份认证失败,中断通信;
服务端产生新的随机数Nj,并将确认信息和新的时间T通过报文一起返回给客户端;报文用k加密,加密公式如下:Encrypt(Nj|T) k
客户端收到报文信息后进行解密,获得新随机数Nj和新时间T;
服务端和客户端通过随机数Ni、Nj、新时间T以及新历史哈希值h进行计算,得到新的根密钥AK;其中根密钥AK的计算公式为:
AK=Truncate_128[SHA1(Ni|Nj|T|h)];其中,Truncate_128表示取前128位。
在一些实施例中,所述分发模块,还配置为客户端向服务端发送密钥申请;其中,密钥申请中包含随机数Nh;
服务端接收到密钥申请后,根据根密钥Ak和随机数Nh生成密钥加密密钥KEK、上行消息认证密钥HMAC_key1及下行消息认证密钥HMAC_key2;所述密钥加密密钥KEK通过如下公式计算:
Figure PCTCN2018102358-appb-000017
其中,0^44表示44个0,Nh为64位随机数;
所述上行消息认证密钥通过如下公式计算:
Figure PCTCN2018102358-appb-000018
所述下行消息认证密钥通过如下公式计算:
Figure PCTCN2018102358-appb-000019
36 44表示对在128位根密钥AK后面连接44个0X36,形成352位比特串,然后对这480位比特串进行哈希运算,最后和随机数Nh进行异或运算;
客户端和服务端进行数据加密密钥TEK的协商;其中客户端向服务端发送协商申请,该申请消息使用KEK加密,消息摘要的密钥使用HMAC_key1;
服务端收到请求后将TEK参数列表使用KEK加密并发送给客户端,发送消息摘要的密钥使用HMAC_key2。
在一些实施例中,所述数据加密过程采用SM4-CBC、DES、AES、SM1中的一种或者多种组合算法对各应用层业务数据进行加密;其中,所有数据通过消息认证密钥进行哈希运算并附在数据尾部,且上行方向的哈希密钥采用上行消息认证密钥HMAC_key1,下行方向的哈希密钥采用下行消息认证密钥HMAC_key2。
在还有一些实施例中,所述身份认证过程利用量子密钥服务器实现量子密钥协商;其中,客户端和服务端均具有量子密钥服务器,客户端设置有量子密钥管理装置,在客户端和服务端进行通信之前,客户端的量子密钥管理装置预先在量子密钥服务器处进行绑定注册,量子密钥服务器要求量子随机数发生器产生大量随机数用作密钥存储在量子密钥服务器和客户 端的量子密钥管理装置中;客户端的量子密钥管理装置与量子密钥服务器L2共享量子随机数密钥,服务端直接连接量子密钥服务器L1;
所述认证模块,配置为客户端向服务端发送数据传输请求;
服务端收到请求后,产生随机数Nb,并将所述随机数Nb与量子身份认证要求一起发送给客户端;
客户端收到量子身份认证要求后,通过客户端的量子密钥管理装置QC向绑定的量子密钥服务器L2发出服务信息,信息内容为服务端要求对客户端进行量子身份认证;
量子密钥服务器L2收到客户端的服务信息后,服务端的量子密钥服务器L1与客户端的量子密钥服务器L2进行量子密钥协商,量子密钥协商完成之后客户端和服务端得到达成一致的密钥K_QU1;
服务端产生随机数作为根密钥AK,计算信号
Figure PCTCN2018102358-appb-000020
并通过经典信道发送给量子密钥服务器L2;
量子密钥服务器L2接收到信号E后,计算
Figure PCTCN2018102358-appb-000021
并选择客户端和量子密钥服务器L2之间预存的量子随机数Ni,计算
Figure PCTCN2018102358-appb-000022
随后,量子密钥服务器L2将ST、随机数Ni指针ptr、长度long以及hash(AK’)一起发送给客户端;
客户端收到消息之后,使用随机数指针ptr及长度long提取随机数Ni,并计算
Figure PCTCN2018102358-appb-000023
将消息摘要HMAC(AK”) Nb发送给服务端;
服务端收到上述消息摘要后,计算HMAC(AK) Nb是否与HMAC(AK”) Nb一致,若一致,则确认客户端的身份,并使用AK作为根密钥;若不一致则认证失败,结束通信。
在一些实施例中,所述身份认证过程和密钥分发过程均利用量子密钥服务器实现量子密钥协商;
所述认证模块,还配置为客户端通过经典信道向服务端发送身份认证请求;服务端收到身份认证请求后,通过量子随机数发生器产生一组随机数作为根密钥AK,并要求量子密钥服务器L2和L1进行量子密钥协商;量子密钥服务器L1和L2依据预定协议进行量子密钥协商后,得到密钥K_QU2;服务端获取密钥K_QU2,计算
Figure PCTCN2018102358-appb-000024
并将E发送给客户端;客户端计算
Figure PCTCN2018102358-appb-000025
和hash(AK’),并发送给服务端;服 务端判断hash(AK’)是否等于hash(AK),若相等,则完成了对于客户端的身份认证;若不等,则认证失败,中断通信;
所述分发模块,配置为客户端和服务端以AK作为根密钥,产生对应的消息认证密钥和密钥加密密钥KEK;客户端要求量子密钥服务器L1和L2进行量子密钥协商;量子密钥服务器L1和L2依据预定协议进行量子密钥协商,得到密钥K_QU3;客户端和服务端获得密钥K_QU3,并将密钥K_QU3作为数据加密密钥。
在一些实施例中,若通信为组播通信时,一个服务端对应多个客户端进行组播通信;
该装置还包括:
组密钥初始模块,配置为各客户端首先在服务端处注册,并获得注册值;
各客户端向服务端发送注册值以及选择的随机数B1~Bn;
服务端收到随机数后,计算B1*B2*…*Bn[G]作为组密钥;其中,G为椭圆加密算法对应的基点;
服务端向客户端发送组密钥时,将除当前客户端外其余客户端的随机数与基点乘积计算结果以及椭圆加密算法对应的椭圆曲线参数发给当前客户端,公式如下:Ci=B1*…*Bi-1*Bi+1*…*Bn[G];其中,Ci为当前第i个客户端对应的相关数据;
各客户端收到相关数据后,利用该相关数据与各自随机数计算得到组密钥;
所述认证模块,还配置为新客户端认证:当服务端中有新的客户端希望加入服务端的组播群组,且客户端已知组播加密所用的椭圆曲线、基点G以及服务端公钥P;则新客户端获得组密钥的过程包括步骤:新客户端计算h(1)=SM3(Nm|ID_M1),并向服务端发送加入组播群组的申请;其中,申请中包含随机数Nm、新客户端M1的身份信息ID_M1、新客户端的公钥PM和h(1);SM3为哈希算法,且申请消息使用服务端公钥P加密,加密公式为:SM2[Nm|ID_M1|PM|h(1)] p;其中,SM2为椭圆曲线加密算法;
服务端D1收到申请消息后,用私钥解密并向新客户端M1回复信息,要求新客户端M1发送身份证明材料;新客户端M1收到服务端发送的消息 后,若新客户端具有注册值,则向服务端发送新客户端的注册值KM1,并附带哈希值h2=SM3(KM1),若新客户端M1没有注册值,则向服务端发送证书cert;服务端D1首先根据哈希值h2进行消息认证,并验证该注册值或证书;若验证通过,则服务端D1生成密钥加密密钥KEK,向新客户端M1发送使用新客户端的公钥PM加密的密钥加密密钥KEK,并分配一个新的注册值KM2;若验证不通过,则认证识别,中断通信;
服务端D1计算如下值:
T1=t1[G];
KE_down=T1+s*{hash(KM2)+hash(x)}[G];
X={s*hash(x)}[G];其中,x为正在使用的组密钥,t1为当前时间,s为服务端D1的私钥;
服务端D1计算哈希值h(3)=SM3(KM2|T1|KE_down|X),向新客户端M1发送T1和X,并附上h(3)用作消息认证;
新客户端M1接收消息T1和X,利用已知的公钥P和其注册值KM2,计算KE_down’=T1+[hash(KM2)]P+X,并验证hash(KM2|T1|KE_down’|X)是否与h(3)相等;若验证通过,则新客户端M1生成KE_up,并向服务端D1发送使用KEK加密的KE_up,且附带哈希值h(4)=SM3(KE_up),服务端D1收到消息后,计算(KE_up*KE_down’)[G]作为新的组密钥;若验证失败,则中断通信;
组密钥更新:
对于以下两种情况,需要进行组密钥更新;
一、若有新加入客户端,新客户端的与服务端双向身份认证后,新客户端直接采用K_group=(KE_up*KE_down)[G]作为新组播密钥;
对组内其它客户端,服务端D1将{KE_up,t1,SM3(KM1)}用原组播密钥加密,并附上哈希值h(5)=SM3(KE_down)发给其它客户端,加密公式为:
SM4[KE_up|t1|SM3(KM1)] x
组内其它客户端收到消息后,根据KE_up,t1,SM3(KM1),结合已知的P和x,计算得到KE_down”=t1[G]+[SM3(KM1)]P+SM3(x)P,验证SM3(KE_down”)是否与h(5)一致;若一致,则计算得到 K_group=(KE_up*KE_down”)[G]作为新的组播密钥;
二、若有客户端离开或者是密钥更新时间到,则服务端将选择的一个随机数Nj和其哈希值SM3(Nj)发送给所有组内客户端,发送时用原组播密钥加密数据;
组内客户端收到该消息后计算K_group=Nj[G]+SM3(Nj)]P+SM3(x)P作为新的组播密钥。
在一些实施例中,所述新客户端认证过程还可以通过采用量子密钥协商的方式实现;其中,新客户端M1连接量子密钥服务器L2;服务端连接量子密钥服务器L1;
所述认证模块,配置为新客户端认证,可包括:
新客户端M1向服务端D1发起认证申请;
服务端D1收到认证申请消息后要求采用量子方式进行身份认证;
采用如权利要求9中同样的认证方式实现新客户端认证;
认证完成后,新客户端M1请求量子密钥服务器L2和L1依据预定协议进行量子密钥协商,得到量子密钥K_QU5,双方计算(K_QU5*KE_down’)[G]作为新的组密钥;
或者,
新客户端M1拥有量子密钥管理装置QC,且量子密钥管理装置绑定量子密钥服务器L2,QC和L2拥有共享的量子随机数;服务端D1直接连接量子密钥服务器L1;
所述新客户端认证过程包括:
新客户端M1向服务端D1发送认证申请;
服务端D1收到认证申请后,通过如权利要求9中方式验证新客户端M1身份;
量子密钥服务器L1和L2进行量子密钥协商后得到量子密钥K_QU6;
选择QC和L2之间预存的某段量子随机数为Nc,L2计算
Figure PCTCN2018102358-appb-000026
Figure PCTCN2018102358-appb-000027
并发送给新客户端M1;
新客户端M1通过计算
Figure PCTCN2018102358-appb-000028
得到K_QU6,用K_QU6来加密KE_up进而实现身份认证。
本发明实施例还提供一种计算机存储介质,所述计算机存储介质存储 有计算机可执行指令;所述计算机可执行指令被执行后,能够实现前述一个或多个实施例提供的基于量子密钥融合的虚拟电厂安全通信方法;例如,如图3和/或图4所示的方法。
所属领域的普通技术人员应当理解:以上任何实施例的讨论仅为示例性的,并非旨在暗示本公开的范围(包括权利要求)被限于这些例子;在本申请的思路下,以上实施例或者不同实施例中的技术特征之间也可以进行组合,步骤可以以任意顺序实现,并存在如上所述的本申请的不同方面的许多其它变化,为了简明它们没有在细节中提供。
本申请的实施例旨在涵盖落入所附权利要求的宽泛范围之内的所有这样的替换、修改和变型。因此,凡在本申请的精神和原则之内,所做的任何省略、修改、等同替换、改进等,均应包含在本申请的保护范围之内。

Claims (13)

  1. 一种基于量子密钥融合的虚拟电厂安全通信方法,包括:
    身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;其中,所述服务端包括商业型虚拟电厂、电力市场业务系统或技术型虚拟电厂;所述客户端对应包括分布式电源、商业型虚拟电厂或技术型虚拟电厂;
    密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;
    数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;
    其中,上述进行身份认证或者密钥分发的过程中,利用量子密钥服务器实现量子密钥协商,并且将协商得到的量子密钥实现相应的身份认证或者作为数据加密密钥。
  2. 根据权利要求1所述的方法,其中,所述身份认证过程包括采用证书认证方式进行认证;其中,采用证书认证时需要可信的第三方分别给客户端和服务端签发相应证书;
    认证过程包括:
    客户端将对应的身份信息、客户端证书、客户端哈希值以及随机数发送给相应的服务端;
    服务端接收客户端发送的信息并且对信息进行验证,若验证信息符合,则给出根密钥,并且将根密钥利用证书中的公钥加密后发送给客户端;
    客户端用对应的私钥解密得到同样的根密钥,完成身份认证。
  3. 根据权利要求1所述的方法,其中,所述身份认证过程包括采用快速认证方法进行认证;其中,客户端和服务端分别拥有历史数据索引表,所述历史数据索引表中包含时间、身份信息、各自的历史密钥与历史哈希值;客户端和服务端每次会话会产生密钥k,记为k 0,k 1,k 2……k n,每次产生的历史密钥哈希值记为h 1,h 2,h 3……h n,将k的哈希值和h的哈希值进行异或运算,得到了新的历史密钥哈希值;h n通过如下公式计算:
    Figure PCTCN2018102358-appb-100001
    Figure PCTCN2018102358-appb-100002
    其中,n为大于1的自然数,SHA1为哈希算法;
    客户端和服务端根据历史数据索引表进行认证;
    认证成功后授予根密钥。
  4. 根据权利要求3所述的方法,其中,所述客户端和服务端根据历史数据索引表进行认证的步骤还包括:
    客户端在对应的历史数据索引表中提取得到索引表内的上次密钥值k、上次时间Ti和索引值ind;
    客户端利用上次密钥值、上次时间和索引值计算哈希值,连带客户端的身份信息和随机数,作为报文发送给服务端;其中,该报文使用上次密钥值加密,并附上索引值;所述报文表示为:ESM4[SHA1(k|Ti|Ni|ind)|ID_DER|Ni] k|ind;其中,ESM4为商密算法;k为加密密钥;Ti为上次时间;Ni为随机数;ind为索引值;ID_DER为客户端的身份信息;
    服务端接收到上述报文信息后,根据报文信息中的索引值检索服务端内的历史数据索引表并提取索引表中的相关信息,用加密密钥对报文信息进行解密,先对比解密得到的客户端身份信息以获取客户端的身份,然后利用索引表中对应的上次时间,加密密钥,索引值和随机数计算哈希值,与客户端发送的哈希值进行比对;若两者相等,则确认客户端的身份信息真实有效,接纳该客户端的认证,并更新历史数据索引表内的历史哈希值、历史密钥、时间相关信息;若哈希值不相等,则身份认证失败,中断通信;
    服务端产生新的随机数Nj,并将确认信息和新的时间T通过报文一起返回给客户端;报文用k加密,加密公式如下:Encrypt(Nj|T) k
    客户端收到报文信息后进行解密,获得新随机数Nj和新时间T;
    服务端和客户端通过随机数Ni、Nj、新时间T以及新历史哈希值h进行计算,得到新的根密钥AK;其中根密钥AK的计算公式为:
    AK=Truncate_128[SHA1(Ni|Nj|T|h)];其中,Truncate_128表示取前128位。
  5. 根据权利要求1所述的方法,其中,所述密钥分发过程包括:
    客户端向服务端发送密钥申请;其中,密钥申请中包含随机数Nh;
    服务端接收到密钥申请后,根据根密钥Ak和随机数Nh生成密钥加密密钥KEK、上行消息认证密钥HMAC_key1及下行消息认证密钥HMAC_key2;所述密钥加密密钥KEK通过如下公式计算:
    Figure PCTCN2018102358-appb-100003
    其中,0^44表示44个0,Nh为64位随机数;
    所述上行消息认证密钥通过如下公式计算:
    Figure PCTCN2018102358-appb-100004
    所述下行消息认证密钥通过如下公式计算:
    Figure PCTCN2018102358-appb-100005
    36 44表示对在128位根密钥AK后面连接44个0X36,形成352位比特串,然后对这480位比特串进行哈希运算,最后和随机数Nh进行异或运算;
    客户端和服务端进行数据加密密钥TEK的协商;其中客户端向服务端发送协商申请,该申请消息使用KEK加密,消息摘要的密钥使用HMAC_key1;
    服务端收到请求后将TEK参数列表使用KEK加密并发送给客户端,发送消息摘要的密钥使用HMAC_key2。
  6. 根据权利要求1所述的方法,其中,所述数据加密过程采用SM4-CBC、DES、AES、SM1中的一种或者多种组合算法对各应用层业务数据进行加密;其中,所有数据通过消息认证密钥进行哈希运算并附在数据尾部,且上行方向的哈希密钥采用上行消息认证密钥HMAC_key1,下行方向的哈希密钥采用下行消息认证密钥HMAC_key2。
  7. 根据权利要求1所述的方法,其中,所述身份认证过程利用量子密钥服务器实现量子密钥协商;其中,客户端和服务端均具有量子密钥服务器,客户端设置有量子密钥管理装置,在客户端和服务端进行通信之前,客户端的量子密钥管理装置预先在量子密钥服务器处进行绑定注册,量子密钥服务器要求量子随机数发生器产生大量随机数用作密钥存储在量子密钥服务器和客户端的量子密钥管理装置中;客户端的量子密钥管理装置与量子密钥服务器L2共享量子随机数密钥,服务端直接连接量子密钥服务器L1;
    所述身份认证过程包括:
    客户端向服务端发送数据传输请求;
    服务端收到请求后,产生随机数Nb,并将所述随机数Nb与量子身份认证要求一起发送给客户端;
    客户端收到量子身份认证要求后,通过客户端的量子密钥管理装置QC向绑定的量子密钥服务器L2发出服务信息,信息内容为服务端要求对客户端进行量子身份认证;
    量子密钥服务器L2收到客户端的服务信息后,服务端的量子密钥服务器L1与客户端的量子密钥服务器L2进行量子密钥协商,量子密钥协商完成之后客户端和服务端得到达成一致的密钥K_QU1;
    服务端产生随机数作为根密钥AK,计算信号
    Figure PCTCN2018102358-appb-100006
    并通过经典信道发送给量子密钥服务器L2;
    量子密钥服务器L2接收到信号E后,计算
    Figure PCTCN2018102358-appb-100007
    并选择客户端和量子密钥服务器L2之间预存的量子随机数Ni,计算
    Figure PCTCN2018102358-appb-100008
    随后,量子密钥服务器L2将ST、随机数Ni指针ptr、长度long以及hash(AK’)一起发送给客户端;
    客户端收到消息之后,使用随机数指针ptr及长度long提取随机数Ni,并计算
    Figure PCTCN2018102358-appb-100009
    将消息摘要HMAC(AK”) Nb发送给服务端;
    服务端收到上述消息摘要后,计算HMAC(AK) Nb是否与HMAC(AK”) Nb一致,若一致,则确认客户端的身份,并使用AK作为根密钥;若不一致则认证失败,结束通信。
  8. 根据权利要求1所述的方法,其中,所述身份认证过程和密钥分发过程均利用量子密钥服务器实现量子密钥协商;
    所述身份认证过程包括:
    客户端通过经典信道向服务端发送身份认证请求;
    服务端收到身份认证请求后,通过量子随机数发生器产生一组随机数作为根密钥AK,并要求量子密钥服务器L2和L1进行量子密钥协商;
    量子密钥服务器L1和L2依据预定协议进行量子密钥协商后,得到密钥K_QU2;
    服务端获取密钥K_QU2,计算
    Figure PCTCN2018102358-appb-100010
    并将E发送给客户端;
    客户端计算
    Figure PCTCN2018102358-appb-100011
    和hash(AK’),并发送给服务端;
    服务端判断hash(AK’)是否等于hash(AK),若相等,则完成了对于客户端的身份认证;若不等,则认证失败,中断通信;
    所述密钥分发过程包括:
    客户端和服务端以AK作为根密钥,产生对应的消息认证密钥和密钥加密密钥KEK;
    客户端要求量子密钥服务器L1和L2进行量子密钥协商;
    量子密钥服务器L1和L2依据预定协议进行量子密钥协商,得到密钥K_QU3;
    客户端和服务端获得密钥K_QU3,并将密钥K_QU3作为数据加密密钥。
  9. 根据权利要求1所述的方法,其中,若通信为组播通信时,一个服务端对应多个客户端进行组播通信;
    该方法还包括:
    组密钥初始化,包括:
    各客户端首先在服务端处注册,并获得注册值;
    各客户端向服务端发送注册值以及选择的随机数B1~Bn;
    服务端收到随机数后,计算B1*B2*…*Bn[G]作为组密钥;其中,G为椭圆加密算法对应的基点;
    服务端向客户端发送组密钥时,将除当前客户端外其余客户端的随机数与基点乘积计算结果以及椭圆加密算法对应的椭圆曲线参数发给当前客户端,公式如下:Ci=B1*…*Bi-1*Bi+1*…*Bn[G];其中,Ci为当前第i个客户端对应的相关数据;
    各客户端收到相关数据后,利用该相关数据与各自随机数计算得到组密钥;
    新客户端认证:
    当服务端中有新的客户端希望加入服务端的组播群组,且客户端已知组播加密所用的椭圆曲线、基点G以及服务端公钥P;则新客户端获得组密钥的过程包括步骤:
    新客户端计算h(1)=SM3(Nm|ID_M1),并向服务端发送加入组播群组的申请;其中,申请中包含随机数Nm、新客户端M1的身份信息ID_M1、新 客户端的公钥PM和h(1);SM3为哈希算法,且申请消息使用服务端公钥P加密,加密公式为:SM2[Nm|ID_M1|PM|h(1)] p;其中,SM2为椭圆曲线加密算法;
    服务端D1收到申请消息后,用私钥解密并向新客户端M1回复信息,要求新客户端M1发送身份证明材料;
    新客户端M1收到服务端发送的消息后,若新客户端具有注册值,则向服务端发送新客户端的注册值KM1,并附带哈希值h2=SM3(KM1),若新客户端M1没有注册值,则向服务端发送证书cert;
    服务端D1首先根据哈希值h2进行消息认证,并验证该注册值或证书;若验证通过,则服务端D1生成密钥加密密钥KEK,向新客户端M1发送使用新客户端的公钥PM加密的密钥加密密钥KEK,并分配一个新的注册值KM2;若验证不通过,则认证识别,中断通信;
    服务端D1计算如下值:
    T1=t1[G];
    KE_down=T1+s*{hash(KM2)+hash(x)}[G];
    X={s*hash(x)}[G];其中,x为正在使用的组密钥,t1为当前时间,s为服务端D1的私钥;
    服务端D1计算哈希值h(3)=SM3(KM2|T1|KE_down|X),向新客户端M1发送T1和X,并附上h(3)用作消息认证;
    新客户端M1接收消息T1和X,利用已知的公钥P和其注册值KM2,计算KE_down’=T1+[hash(KM2)]P+X,并验证hash(KM2|T1|KE_down’|X)是否与h(3)相等;若验证通过,则新客户端M1生成KE_up,并向服务端D1发送使用KEK加密的KE_up,且附带哈希值h(4)=SM3(KE_up),服务端D1收到消息后,计算(KE_up*KE_down’)[G]作为新的组密钥;若验证失败,则中断通信;
    组密钥更新:
    对于以下两种情况,需要进行组密钥更新;
    一、若有新加入客户端,新客户端的与服务端双向身份认证后,新客户端直接采用K_group=(KE_up*KE_down)[G]作为新组播密钥;
    对组内其它客户端,服务端D1将{KE_up,t1,SM3(KM1)}用原组播 密钥加密,并附上哈希值h(5)=SM3(KE_down)发给其它客户端,加密公式为:
    SM4[KE_up|t1|SM3(KM1)] x
    组内其它客户端收到消息后,根据KE_up,t1,SM3(KM1),结合已知的P和x,计算得到KE_down”=t1[G]+[SM3(KM1)]P+SM3(x)P,验证SM3(KE_down”)是否与h(5)一致;若一致,则计算得到K_group=(KE_up*KE_down”)[G]作为新的组播密钥;
    二、若有客户端离开或者是密钥更新时间到,则服务端将选择的一个随机数Nj和其哈希值SM3(Nj)发送给所有组内客户端,发送时用原组播密钥加密数据;
    组内客户端收到该消息后计算K_group=Nj[G]+SM3(Nj)]P+SM3(x)P作为新的组播密钥。
  10. 根据权利要求9所述的方法,其中,所述新客户端认证过程还可以通过采用量子密钥协商的方式实现;其中,新客户端M1连接量子密钥服务器L2;服务端连接量子密钥服务器L1;
    所述新客户端认证过程包括:
    新客户端M1向服务端D1发起认证申请;
    服务端D1收到认证申请消息后要求采用量子方式进行身份认证;
    采用如权利要求9中同样的认证方式实现新客户端认证;
    认证完成后,新客户端M1请求量子密钥服务器L2和L1依据预定协议进行量子密钥协商,得到量子密钥K_QU5,双方计算(K_QU5*KE_down’)[G]作为新的组密钥;
    或者,
    新客户端M1拥有量子密钥管理装置QC,且量子密钥管理装置绑定量子密钥服务器L2,QC和L2拥有共享的量子随机数;服务端D1直接连接量子密钥服务器L1;
    所述新客户端认证过程包括:
    新客户端M1向服务端D1发送认证申请;
    服务端D1收到认证申请后,通过如权利要求9中方式验证新客户端M1身份;
    量子密钥服务器L1和L2进行量子密钥协商后得到量子密钥K_QU6;
    选择QC和L2之间预存的某段量子随机数为Nc,L2计算
    Figure PCTCN2018102358-appb-100012
    Figure PCTCN2018102358-appb-100013
    并发送给新客户端M1;
    新客户端M1通过计算
    Figure PCTCN2018102358-appb-100014
    得到K_QU6,用K_QU6来加密KE_up进而实现身份认证。
  11. 一种基于量子密钥融合的虚拟电厂安全通信装置,包括:
    身份认证模块,配置为身份认证:基于通信需求,对虚拟电厂中的客户端与服务端之间进行身份认证并获取得到根密钥;其中,所述服务端包括商业型虚拟电厂、电力市场业务系统或技术型虚拟电厂;所述客户端对应包括分布式电源、商业型虚拟电厂或技术型虚拟电厂;
    分发模块,配置为密钥分发:基于获取的根密钥,相应生成密钥加密密钥、消息认证密钥,进而实现数据加密密钥协商,得到数据加密密钥;
    加密模块,配置为数据加密:采用数据加密密钥对待加密的数据进行加密处理并且相应实现数据通信;
    其中,上述进行身份认证或者密钥分发的过程中,利用量子密钥服务器实现量子密钥协商,并且将协商得到的量子密钥实现相应的身份认证或者作为数据加密密钥。
  12. 根据权利要求11所述的装置,其中,
    所述认证模块,配置为客户端将对应的身份信息、客户端证书、客户端哈希值以及随机数发送给相应的服务端;
    所述装置还包括:
    接收模块,用于服务端接收客户端发送的信息并且对信息进行验证,若验证信息符合,则给出根密钥,并且将根密钥利用证书中的公钥加密后发送给客户端;
    所述认证模块,还用于客户端用对应的私钥解密得到同样的根密钥,完成身份认证。
  13. 一种计算机存储介质,所述计算机存储介质存储有计算机可执行指令;所述计算机可执行指令被执行后,能够实现权利要求1至10任一项提供的基于量子密钥融合的虚拟电厂安全通信方法。
PCT/CN2018/102358 2018-01-11 2018-08-24 基于量子密钥融合的虚拟电厂安全通信方法及装置、介质 Ceased WO2019137014A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US16/481,215 US11233639B2 (en) 2018-01-11 2018-08-24 Method and device for quantum key fusion-based virtual power plant security communication and medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201810025965.4 2018-01-11
CN201810025965.4A CN108234501B (zh) 2018-01-11 2018-01-11 一种基于量子密钥融合的虚拟电厂安全通信方法

Publications (1)

Publication Number Publication Date
WO2019137014A1 true WO2019137014A1 (zh) 2019-07-18

Family

ID=62640973

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/102358 Ceased WO2019137014A1 (zh) 2018-01-11 2018-08-24 基于量子密钥融合的虚拟电厂安全通信方法及装置、介质

Country Status (3)

Country Link
US (1) US11233639B2 (zh)
CN (1) CN108234501B (zh)
WO (1) WO2019137014A1 (zh)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112564904A (zh) * 2020-12-11 2021-03-26 山东极光智能科技有限公司 一种基于量子通信的数据加密系统及其使用方法
CN113014379A (zh) * 2021-02-05 2021-06-22 南阳理工学院 支持跨云域数据分享的三方认证和密钥协商方法、系统和计算机存储介质
CN114175574A (zh) * 2020-07-10 2022-03-11 西部数据技术公司 无线安全协议
CN114172641A (zh) * 2020-09-11 2022-03-11 军事科学院系统工程研究院网络信息研究所 探测驱动的双工双向量子加密通信方法
CN114553419A (zh) * 2022-03-24 2022-05-27 上海循态量子科技有限公司 基于连续变量量子密钥分发的量子身份认证方法及系统
CN115473638A (zh) * 2022-09-09 2022-12-13 国开启科量子技术(北京)有限公司 量子密钥加密、解密方法及系统
CN116074839A (zh) * 2023-01-30 2023-05-05 矩阵时光数字科技有限公司 一种量子安全终端接入量子安全网络的认证方法
CN119135456A (zh) * 2024-11-15 2024-12-13 齐鲁工业大学(山东省科学院) 基于国密算法的轻量级密钥管理方法及系统
CN119834967A (zh) * 2024-12-27 2025-04-15 中国科学技术大学 一种在tls中融合量子密钥的数据保护方法

Families Citing this family (71)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9953168B1 (en) * 2017-06-26 2018-04-24 Bracket Computing, Inc. Secure boot of virtualized computing instances
CN108234501B (zh) * 2018-01-11 2020-12-11 北京中电普华信息技术有限公司 一种基于量子密钥融合的虚拟电厂安全通信方法
CN109818749B (zh) * 2019-01-11 2021-11-16 如般量子科技有限公司 基于对称密钥池的抗量子计算点对点消息传输方法和系统
US12127002B2 (en) * 2019-03-26 2024-10-22 Apple Inc. Integrity protection of uplink data
US11374764B2 (en) 2019-08-02 2022-06-28 Salesforce.Com, Inc. Clock-synced transient encryption
US11228431B2 (en) * 2019-09-20 2022-01-18 General Electric Company Communication systems and methods for authenticating data packets within network flow
CN111143870B (zh) * 2019-12-30 2022-05-13 兴唐通信科技有限公司 一种分布式加密存储装置、系统及加解密方法
CN113098679A (zh) * 2020-01-09 2021-07-09 杭州海康威视数字技术股份有限公司 一种根密钥生成方法、装置、电子设备
CN113300832B (zh) * 2020-02-21 2023-05-05 阿里巴巴集团控股有限公司 通信链接的建立方法、装置、存储介质、处理器及系统
US20230177339A1 (en) * 2020-03-30 2023-06-08 British Telecommunications Public Limited Company Improvements to satellite-based qkd
US11563725B2 (en) * 2020-05-08 2023-01-24 Brian Wane Using keyboard app to encrypt e-mail and other digital data
CN111654378B (zh) * 2020-05-28 2021-01-05 广东纬德信息科技股份有限公司 一种基于电力安全网关的数据安全自检方法
US11646871B2 (en) * 2020-08-12 2023-05-09 Intuit Inc. System and method for multitenant key derivation
CN111953487B (zh) * 2020-08-14 2022-04-22 苏州浪潮智能科技有限公司 一种密钥管理系统
CN112055071B (zh) * 2020-08-31 2022-02-22 郑州信大捷安信息技术股份有限公司 一种基于5g的工业控制安全通信系统及方法
WO2022069056A1 (en) * 2020-10-02 2022-04-07 Huawei Technologies Co., Ltd. Protection of sensitive user data in communication networks
CN114362927B (zh) * 2020-10-14 2025-01-24 中国移动通信有限公司研究院 密钥协商方法、装置、设备及存储介质
CN114430328B (zh) * 2020-10-14 2024-08-30 中国移动通信有限公司研究院 密钥协商方法、装置、设备及存储介质
CN112383917B (zh) * 2020-10-21 2024-07-02 华北电力大学 一种基于商密算法的北斗安全通信方法和系统
CN112713997B (zh) * 2020-12-28 2022-04-22 北京握奇数据股份有限公司 密钥协商方法和系统
CN114765541B (zh) * 2020-12-31 2024-02-23 科大国盾量子技术股份有限公司 一种量子密钥卡的密钥分发方法及系统
CN114765542B (zh) * 2020-12-31 2024-07-19 科大国盾量子技术股份有限公司 基于量子密钥卡的量子密码网络加密通信方法
CN114697039B (zh) * 2020-12-31 2024-08-30 科大国盾量子技术股份有限公司 量子密码网络扩展网络设备的身份认证方法和系统
CN112994874B (zh) * 2021-04-19 2021-07-27 工业信息安全(四川)创新中心有限公司 一种基于消息鉴别码算法的保留格式加密方法及解密方法
CN113127911B (zh) * 2021-05-06 2022-05-20 国网河北省电力有限公司信息通信分公司 电力数据加密方法、装置及终端
CN113193957B (zh) * 2021-05-10 2023-03-31 成都量安区块链科技有限公司 一种与量子网络分离的量子密钥服务方法与系统
CN113242238B (zh) * 2021-05-10 2022-05-27 中国建设银行股份有限公司 安全通信方法、装置及系统
CN113542212B (zh) * 2021-05-21 2023-06-30 国网辽宁省电力有限公司鞍山供电公司 一种虚拟电厂调峰指令安全认证方法
CN113300845B (zh) * 2021-07-20 2022-07-05 国能信控互联技术有限公司 一种智慧热网数据传输安全防护系统和方法
US12432049B2 (en) 2021-07-24 2025-09-30 Zeroproof, Llc Systems, apparatus, and methods for generation, packaging, and secure distribution of symmetric quantum cypher keys
CN113595725B (zh) * 2021-07-29 2023-08-11 如般量子科技有限公司 基于量子密钥卡排列的通信系统及通信方法
CN113612608B (zh) * 2021-08-13 2024-04-19 中电信量子科技有限公司 一种双模对讲机基于公网实现集群加密的方法及系统
CN113992702B (zh) * 2021-09-16 2023-11-03 深圳市证通电子股份有限公司 一种ceph分布式文件系统存储国密加固方法及系统
CN114040356B (zh) * 2021-10-20 2024-07-30 合肥炀熵量子科技有限责任公司 一种融合量子安全的智能网联汽车数据安全保护方法
CN113765664B (zh) * 2021-11-10 2022-02-08 济南量子技术研究院 基于量子密钥的区块链网络安全通信方法
CN114040390B (zh) * 2021-11-17 2023-05-09 国网福建省电力有限公司 一种基于量子安全的5g虚商密钥库分发方法
CN113992432A (zh) * 2021-12-24 2022-01-28 南京中孚信息技术有限公司 消息处理方法、消息总线系统、计算机设备及存储介质
CN114398688B (zh) * 2021-12-29 2024-11-08 江苏亨通问天量子信息研究院有限公司 一种基于量子加密盒子的通信系统
CN114339741B (zh) * 2021-12-30 2024-11-01 江苏亨通问天量子信息研究院有限公司 一种基于量子存储卡的移动加密通信方法、系统
CN114363838A (zh) * 2021-12-30 2022-04-15 中国电信股份有限公司卫星通信分公司 一种通过短信通道实现卫星通信量子秘钥分发的方法
CN114244513B (zh) * 2021-12-31 2024-02-09 日晷科技(上海)有限公司 密钥协商方法、设备及存储介质
GB2616047A (en) * 2022-02-25 2023-08-30 Toshiba Kk A quantum network and a quantum authentication server
CN114285573B (zh) * 2022-03-06 2022-05-27 浙江九州量子信息技术股份有限公司 一种用于抗量子攻击的对称密钥分配方法
CN114531237B (zh) * 2022-04-21 2022-07-19 八维通科技有限公司 基于嵌入式平台的集成网关的根密钥升级方法
CN114785421B (zh) * 2022-04-24 2024-04-26 矩阵时光数字科技有限公司 一种基于量子加密的im离线消息处理方法
CN114915399B (zh) * 2022-05-11 2024-08-30 国网福建省电力有限公司 基于同态加密的能源大数据安全系统
CN117118597A (zh) * 2022-05-16 2023-11-24 中国移动通信有限公司研究院 量子保密通信方法和设备、量子密码服务网络和通信系统
CN115277194B (zh) * 2022-07-27 2024-07-02 歌尔科技有限公司 产品认证方法、穿戴设备、表带及存储介质
CN115189971B (zh) * 2022-09-13 2022-12-20 中科物栖(北京)科技有限责任公司 数据传输加密方法
CN115829236A (zh) * 2022-11-15 2023-03-21 武汉跨克信息技术有限公司 一种虚拟电厂参与电力市场的技术支持系统
CN115529193B (zh) * 2022-11-25 2023-04-28 深圳市亲邻科技有限公司 一种云边协同隧道的安全通信方法
CN116055042A (zh) * 2023-01-16 2023-05-02 国网浙江省电力有限公司信息通信分公司 一种量子密钥加密方法、装置、设备及存储介质
CN116032473B (zh) * 2023-01-17 2025-08-12 矩阵时光数字科技有限公司 输出量子安全密钥及认证参数方法、装置和根密钥中心
CN116405302B (zh) * 2023-04-19 2023-09-01 合肥工业大学 一种用于车内安全通信的系统及方法
CN116938445A (zh) * 2023-06-12 2023-10-24 上海电力大学 一种基于sm3算法的智能配电终端密钥协商方法及系统
US12362942B2 (en) * 2023-07-07 2025-07-15 Jpmorgan Chase Bank, N.A. Systems and methods for secure client-server authentication with key recycling
CN116774970B (zh) * 2023-08-22 2024-06-25 北京启源问天量子科技有限公司 基于量子随机数的id生成方法及装置
CN117254954B (zh) * 2023-09-21 2024-04-05 广州怡水水务科技有限公司 用于调度管理的直饮水云平台安全接入方法
CN117098123B (zh) * 2023-10-17 2024-02-02 西北大学 一种基于量子密钥的北斗短报文加密通信系统
CN117459325B (zh) * 2023-12-22 2024-02-27 北京邮电大学 一种量子通信与常规通信结合的三方数据通信方法
CN117857032A (zh) * 2024-01-09 2024-04-09 南方电网科学研究院有限责任公司 一种虚拟电厂终端设备的数据加密方法
CN117579276B (zh) * 2024-01-16 2024-03-29 浙江国盾量子电力科技有限公司 用于馈线终端的量子加密方法及量子板卡模组
CN118317299B (zh) * 2024-06-11 2024-09-06 南方电网科学研究院有限责任公司 5g加密通信方法、装置、电子设备及存储介质
CN118449786B (zh) * 2024-07-08 2024-09-03 国网浙江省电力有限公司杭州供电公司 电力终端的本地通信轻量级认证方法、系统、设备及介质
CN119109570A (zh) * 2024-07-15 2024-12-10 贵州电网有限责任公司 一种增强电网安全的量子中继方法及系统
CN119182523B (zh) * 2024-09-10 2025-03-11 矩阵时光数字科技有限公司 一种基于量子密钥关联的虚拟通信网络构建方法
CN119277370B (zh) * 2024-11-04 2025-09-19 中电信量子科技有限公司 用户漫游方法、装置、系统、电子设备和计算机存储介质
CN119155110A (zh) * 2024-11-13 2024-12-17 易迅通科技有限公司 虚拟云桌面身份认证量子安全增强方法
CN119232377B (zh) * 2024-11-29 2025-03-21 国网浙江省电力有限公司金华供电公司 面向智能电网场景下的网络节点认证及密钥交换协议方法
CN119254531B (zh) * 2024-12-02 2025-04-04 安徽数安系统集成有限公司 基于量子加密的新能源汽车运行数据点对点传输方法
CN120856331B (zh) * 2025-09-17 2025-11-25 上海图灵智算量子科技有限公司 会话密钥生成方法、装置、电子设备和存储介质

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107480847A (zh) * 2017-06-20 2017-12-15 郑州大学 能源区块链网络和基于该网络的虚拟电厂运行与调度方法
CN108234501A (zh) * 2018-01-11 2018-06-29 北京国电通网络技术有限公司 一种基于量子密钥融合的虚拟电厂安全通信方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2017200791A1 (en) * 2016-05-19 2017-11-23 Alibaba Group Holding Limited Method and system for secure data transmission
CN107404461B (zh) * 2016-05-19 2021-01-26 阿里巴巴集团控股有限公司 数据安全传输方法、客户端及服务端方法、装置及系统
CN107493169A (zh) * 2017-09-26 2017-12-19 安徽皖通邮电股份有限公司 一种基于量子密钥和国密算法的身份鉴别方法

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107480847A (zh) * 2017-06-20 2017-12-15 郑州大学 能源区块链网络和基于该网络的虚拟电厂运行与调度方法
CN108234501A (zh) * 2018-01-11 2018-06-29 北京国电通网络技术有限公司 一种基于量子密钥融合的虚拟电厂安全通信方法

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
FANG, YANQIONG ET AL.: "A Review on Virtual Power Plant", CHIN. SOC. FOR ELEC. ENG., 30 April 2016 (2016-04-30) *
LI, . ZHI: "The . Research of Key Technique on . the . Network Security for Power System", SCIENCE -ENGINEERING (B), CHINESE SELECTED DOCTORAL DISSERTATIONS AND MASTER'S THESES FULL- TEXT DATABASES (MASTER, 15 December 2004 (2004-12-15) *
SHABANZADEH, M. ET AL.: "An Interactive Cooperation Model for Neighboring Virtual Power Plant", APPLIED ENERGY, vol. 200, 18 May 2017 (2017-05-18), XP085041698 *

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114175574A (zh) * 2020-07-10 2022-03-11 西部数据技术公司 无线安全协议
CN114172641A (zh) * 2020-09-11 2022-03-11 军事科学院系统工程研究院网络信息研究所 探测驱动的双工双向量子加密通信方法
CN114172641B (zh) * 2020-09-11 2023-06-27 军事科学院系统工程研究院网络信息研究所 探测驱动的双工双向量子加密通信方法
CN112564904A (zh) * 2020-12-11 2021-03-26 山东极光智能科技有限公司 一种基于量子通信的数据加密系统及其使用方法
CN113014379A (zh) * 2021-02-05 2021-06-22 南阳理工学院 支持跨云域数据分享的三方认证和密钥协商方法、系统和计算机存储介质
CN113014379B (zh) * 2021-02-05 2022-05-17 南阳理工学院 支持跨云域数据分享的三方认证和密钥协商方法、系统和计算机存储介质
CN114553419A (zh) * 2022-03-24 2022-05-27 上海循态量子科技有限公司 基于连续变量量子密钥分发的量子身份认证方法及系统
CN114553419B (zh) * 2022-03-24 2024-05-17 上海循态量子科技有限公司 基于连续变量量子密钥分发的量子身份认证方法及系统
CN115473638A (zh) * 2022-09-09 2022-12-13 国开启科量子技术(北京)有限公司 量子密钥加密、解密方法及系统
CN116074839A (zh) * 2023-01-30 2023-05-05 矩阵时光数字科技有限公司 一种量子安全终端接入量子安全网络的认证方法
CN119135456A (zh) * 2024-11-15 2024-12-13 齐鲁工业大学(山东省科学院) 基于国密算法的轻量级密钥管理方法及系统
CN119834967A (zh) * 2024-12-27 2025-04-15 中国科学技术大学 一种在tls中融合量子密钥的数据保护方法

Also Published As

Publication number Publication date
CN108234501B (zh) 2020-12-11
US11233639B2 (en) 2022-01-25
CN108234501A (zh) 2018-06-29
US20190394031A1 (en) 2019-12-26

Similar Documents

Publication Publication Date Title
CN108234501B (zh) 一种基于量子密钥融合的虚拟电厂安全通信方法
CN114730420B (zh) 用于生成签名的系统和方法
CN103354498B (zh) 一种基于身份的文件加密传输方法
CN112104453B (zh) 一种基于数字证书的抗量子计算数字签名系统及签名方法
CN103795534B (zh) 基于口令的认证方法及用于执行该方法的装置
CN110601838A (zh) 一种基于量子密钥的身份认证方法、装置及系统
CN105245326B (zh) 一种基于组合密码的智能电网安全通信方法
CN106789042B (zh) Ibc域内的用户访问pki域内的资源的认证密钥协商方法
CN110999202B (zh) 用于对数据进行高度安全、高速加密和传输的计算机实现的系统和方法
CN113630248B (zh) 一种会话密钥协商方法
CN105933345B (zh) 一种基于线性秘密共享的可验证外包属性基加密方法
CN113704736A (zh) 基于ibc体系的电力物联网设备轻量级接入认证方法及系统
CN106301788A (zh) 一种支持用户身份认证的群组密钥管理方法
CN102970144B (zh) 基于身份的认证方法
CN101640590A (zh) 一种获取标识密码算法私钥的方法和密码中心
CN118573408B (zh) 一种端到端的数据加密处理方法
CN114244502B (zh) 基于sm9算法的签名密钥生成方法、装置和计算机设备
CN114513327B (zh) 一种基于区块链的物联网隐私数据快速共享方法
CN113364803B (zh) 基于区块链的配电物联网的安全认证方法
CN111277412A (zh) 基于区块链密钥分发的数据安全共享系统及方法
CN114978481B (zh) 基于后量子密码ca的抗量子计算通信系统
CN105812349A (zh) 一种基于身份信息的非对称密钥分发及消息加密方法
CN114785487A (zh) 基于ca和国密算法的抗量子计算https通信方法及系统
CN114189338A (zh) 基于同态加密技术的sm9密钥安全分发和管理系统及方法
CN114386020A (zh) 基于量子安全的快速二次身份认证方法及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18899795

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18899795

Country of ref document: EP

Kind code of ref document: A1