TANG Pengyi,LI Guochun,YU Gang,ZHONG Jun,ZHANG Yinghua,XUE Lu,ZHAO Ziyan
In the future quantum computing era,there will be security risks in the authentication and key exchange links of constructing Virtual Private Network(VPN).Therefore,a VPN enhanced security architecture based on Quantum Secure Key Management Service(QS-KMS) is established to implement quantum security solutions based on quantum cryptography.A global unified backend QS-KMS service is used to provide authentication and session key for IPSec VPN to decouple VPN services from physical layer quantum devices.In view of the complex working conditions and strong environmental interference of power overhead fiber optic cables,the QS-KMS key pool dynamic key management technology and post-quantum cryptography technology are applied to keep the key pool sufficient to ensure the stable operation of VPN.On this basis,the effective quantum security VPN service in the power communication network is realized.Test results show that this method can meet the needs of power grid control communication.