Abstract
Offshore wind farms are representative unmanned energy systems whose operation relies heavily on remote information exchange between offshore substations and onshore centralized control centers. However, the cross-sea communication link is vulnerable to cyberattacks, including impersonation and message tampering, and these threats persist in the quantum computing era, potentially compromising operational decision-making and control. To address this problem, this paper proposes a privacy-preserving key agreement method based on the Ring Learning With Errors (RLWE) problem. First, identity privacy protection is integrated with post-quantum cryptography. An identity commitment function conceals the true identities of the communicating entities, while a pre-shared authentication factor and fresh random parameters enable mutual authentication and session key establishment. This design prevents identity disclosure and secures information exchange in offshore wind farms against quantum-capable adversaries. Second, confidentiality and unforgeability are formally established under the decisional and search RLWE assumptions. Finally, experiments validate the effectiveness of the proposed method. Compared with existing schemes, it reduces communication overhead by up to 43.75%, making it particularly suitable for resource-constrained offshore wind farm environments.
1. Introduction
With the global transition toward a low-carbon economy and China’s carbon-peaking and carbon neutrality goals, wind energy is developing rapidly as a clean and sustainable energy source [1]. Owing to their autonomous, intelligent, and remotely operated characteristics, unmanned systems have become essential to offshore energy development, data acquisition, and operation and maintenance; offshore wind farms are a representative application in which remote monitoring and centralized dispatch are implemented through such systems. Compared to onshore wind power, offshore wind power offers substantial advantages in resource availability and stability, annual utilization hours, and conditions for large-scale development, and has therefore become a major source of growth in the wind industry [2]. As offshore wind farms continue to expand in scale and adopt clustered deployment, centralized modeling, monitoring, and operational management have become increasingly important [3]. In practical deployments, turbine-side data are aggregated at the offshore substation and ultimately transmitted to the onshore centralized control center, which serves as a core node of the monitoring and management platform. The cross-sea link between the offshore substation and the onshore centralized control center is a critical channel for telemetry upload and control-command delivery [4]. Securing this link is therefore a central challenge in offshore wind farm communications and is essential to safe and stable system operation.
Compared with onshore wind farms, offshore wind farms face more challenging security requirements due to their geographically dispersed deployment and cross-sea communication characteristics [5]. Long-distance transmission between offshore substations and onshore control centers increases the exposure of communication links to potential cyber threats, while the limited accessibility of offshore facilities makes security maintenance more difficult [6]. Therefore, ensuring reliable identity authentication, data integrity, and secure key establishment is essential for protecting offshore wind farm communications.
Research on secure data transmission over cross-sea links in offshore wind farms is progressing from conventional engineering protection toward active defense. To establish a logical security boundary, researchers have increasingly introduced cryptographic mechanisms. Shang et al. [7] and Amiya et al. [8] designed lightweight authentication protocols for Internet of Things healthcare networks using elliptic-curve cryptography (ECC) and identity-based cryptography combined with hashing, respectively. Abbasinezhad-Mood et al. [9] proposed an anonymous self-certified key-distribution scheme for smart grids based on ECC. Zhang et al. [10] developed an ECC-based lightweight authentication protocol for unmanned aerial vehicles that provides backward security for session keys while improving protocol flexibility. To address the wireless communication security requirements of offshore wind power collection lines, Chen et al. [11] designed a secure encryption scheme suitable for relay protection services, thereby ensuring the confidentiality of data transmission for multi-terminal wireless differential protection in complex marine environments. Arjun et al. [12] proposed an ECC-based lightweight authentication scheme for resource-constrained devices in energy and power systems.
With rapid advances in quantum computing and quantum algorithms, authentication methods based on conventional cryptography may be efficiently compromised by quantum adversaries [13]. Post-quantum cryptography has therefore emerged as a means of resisting quantum attacks [14]. Schemes based on the Ring Learning With Errors (RLWE) problem [15] have become a major research focus in lattice-based cryptography because they combine strong security with high computational efficiency. Zhao et al. [16] enhanced core security properties by achieving forward security in an RLWE-based identity-based protocol. Shen et al. [17] designed an RLWE-based two-factor three-party authentication protocol. Ni et al. [18] proposed an anonymous authenticated key agreement protocol for smart healthcare. Hong et al. [19] presented a parameter analysis method for an RLWE-based group key exchange protocol. Although recent studies have strengthened the core security properties of RLWE protocols and extended them to selected critical infrastructures, existing schemes have paid limited attention to the privacy and security requirements of offshore wind farms. Moreover, they generally lack comprehensive formal security arguments covering key operational threats such as tampering, man-in-the-middle attacks, and impersonation [8,9,11,12,19].
The key security challenge in offshore wind farms is to protect long-distance, geographically distributed, and remotely operated communication between offshore substations and onshore centralized control centers, which places stringent requirements on identity authentication, message integrity, secure key establishment, and communication efficiency. RLWE is not inherently specific to offshore communication; rather, its suitability in this work arises from its post-quantum security foundation and efficient polynomial-ring arithmetic [20]. These characteristics enable the proposed method to support mutual authentication and secure key establishment while satisfying the security and efficiency requirements of offshore wind farm communication systems. Compared with MLWE, which relies on module-based vector and matrix operations [21], RLWE enables a simpler single-ring construction. Therefore, RLWE is adopted to support a lightweight key agreement design in this work.
To address these limitations, this paper proposes an RLWE-based privacy-preserving key agreement method for offshore wind farms. Its main contributions are as follows: (1) an RLWE-based identity privacy and secure-authentication mechanism is designed to ensure the integrity and trustworthiness of cross-sea information transmission between the offshore substation and the onshore centralized control center in a quantum computing environment; and (2) the confidentiality and unforgeability of the proposed method are established under the hardness assumptions of RLWE, thereby providing a theoretical security foundation.
The remainder of this paper is organized as follows. Section 2 introduces the relevant preliminaries. Section 3 analyzes the vulnerabilities and security requirements of the cross-sea communication link in offshore wind farms. Section 4 presents the RLWE-based mutual-authentication key agreement method. Section 5 provides a theoretical security analysis. Section 6 reports the experimental evaluation. Finally, Section 7 concludes the paper and outlines directions for future work. The parameters used throughout the paper are summarized in Table 1.
Table 1.
Notation, system parameters, and variable visibility.
2. Preliminaries
2.1. Lattices and Related Hard Problems
A lattice is a discrete additive subgroup generated by linearly independent vectors in a real vector space. Let (where m is the dimension of the real vector space ) denote n linearly independent vectors, and let the basis matrix be [22]. The lattice generated by B is defined as
where is a basis of lattice . Every element of the lattice can be expressed as an integer linear combination of these basis vectors.
2.2. System Entities and Roles
The proposed RLWE-based privacy-preserving key agreement method involves three main entities: the key generation center (KGC), the offshore substation SDH device , and the onshore centralized control center SDH device . The KGC is responsible for system initialization and long-term key generation. The offshore substation SDH device and the onshore centralized control center SDH device are the two communicating entities responsible for mutual authentication and session key establishment.
In the identity commitment mechanism, the committer and verifier are functional roles assumed by the two communicating entities rather than additional system entities. Depending on the direction of authentication, and may act as the committer or the verifier, respectively. The KGC is responsible for key-related initialization and does not serve as a committer or verifier in the identity commitment process.
2.3. Class-C Commitment Scheme
Let G be a cyclic group of order q, where q is prime and N is a generator of group G. For any element in the message space, define the Class-C commitment function as . The scheme comprises a commitment phase and a verification phase. During commitment, the committer applies the scheme to the message a to be concealed, computes commitment , and sends it to the verifier. During verification, the committer reveals message a, and the verifier checks whether the received commitment satisfies . Verification succeeds if the equality holds; otherwise, it fails.
2.4. Sig and Extr Functions
To enable the communicating parties to recover identical shared bits in the presence of small errors, we introduce the signal function and the extraction function . Let q be a prime greater than 2. Define
Definition 1
(Sig function [23]). The signal function, , is defined as
This function generates auxiliary bit information according to the interval containing input x.
Definition 2
(Extr function). When q is an odd integer greater than 8, the extraction function is defined as
where δ is the auxiliary bit output by . The function extracts shared binary information from elements in the space modulo q. For any satisfying , , where ε is the small error term in the computed difference, the and functions extract the same bit value from x and y. Thus, the two communicating parties can recover identical shared information in the presence of bounded errors.
3. Problem Formulation
An offshore wind farm is a representative sea-land collaborative operating system [24]. Its communication network encompasses turbine-side data acquisition, service aggregation at the offshore substation, and monitoring and dispatch at the onshore centralized control center. The long communication span, geographically dispersed nodes, and prolonged operation in open or semi-open environments expose the system to cyber threats such as message tampering, man-in-the-middle attacks, and identity impersonation [25]. Figure 1 illustrates a typical offshore wind farm. Turbine-side measurements, including blade pitch angle, real-time wind speed, and rotor speed, are aggregated through tower-base switches and the internal aggregation switch of the offshore substation. The data are then transmitted through the submarine cable fiber link from the synchronous digital hierarchy (SDH) equipment at the offshore substation to the SDH equipment at the onshore centralized control center [3], after which they enter the onshore core data-switching network. In general, an offshore wind farm has one offshore substation and one onshore centralized control center. The offshore substation monitoring system is incorporated as a subsystem of the computerized monitoring system at the onshore center. The two sites exchange information over the transmission link network using TCP/IP. This link carries both telemetry uploads and remote control commands; it is therefore the core channel for sea–land information exchange and the most critical security boundary of the offshore wind farm.
Figure 1.
Offshore wind farm communication architecture. This figure illustrates the turbine-side data acquisition, data aggregation at the offshore substation, cross-sea transmission to the onshore centralized control center, and potential attack links.
Although the physical layer of this link relies on SDH equipment and fiber-optic channels, the underlying TCP/IP suite prioritizes open interconnection and transmission efficiency and does not provide intrinsic protection tailored to critical infrastructure. Its limitations are twofold. First, the protocol layer cannot directly authenticate communication entities in the offshore wind farm, allowing an adversary to impersonate a legitimate node through session or address spoofing. Second, the protocol itself provides no end-to-end integrity protection for operational messages, which may therefore be intercepted, tampered with [26], or injected during cross-sea transmission. We consider a network-level adversary who does not require direct physical access to the submarine fiber-optic link. By compromising an intermediate network node, communication interface, or legitimate endpoint, the adversary may gain logical access to the communication process and subsequently modify, inject, or replay protocol messages, or impersonate a legitimate communicating entity. Such capabilities may enable message tampering, identity impersonation, and man-in-the-middle attacks during authentication and key establishment.
These limitations directly affect the security of information transmitted between the offshore substation and the onshore centralized control center. If an adversary attacks this link, the information received by the onshore center may no longer reflect the true operating state of offshore equipment, thereby compromising state assessment, monitoring analysis, and dispatch decisions. Conventional TCP/IP transmission mechanisms cannot satisfy the secure communication requirements of this critical offshore wind power link. A key agreement method supporting mutual authentication is therefore urgently needed for offshore wind farm environments.
4. Proposed Method
The proposed RLWE-based privacy-preserving key agreement method involves three types of entities: a key generation center (KGC), with identity ; an SDH device at the offshore substation, with identity ; and an SDH device at the onshore centralized control center, with identity . The method comprises system initialization, long-term key generation, and session key agreement, as described below.
4.1. System Initialization
The system first initializes the public parameters required for the offshore wind farm communication environment.The key generation center first generates the system root key . It uniformly samples a public polynomial and independently samples the master secret polynomial and the error polynomial over , where . The coefficients of a, s, and e are defined modulo q. The system master public key is then computed as
It then distributes the system parameters
Here, denotes the polynomial ring, a is the public polynomial, is the system master public key, and H denotes the one-way hash function, whose detailed definition is given in Equation (9). These system parameters are distributed to all entities. Additional parameters are generated according to the security requirements: n is the lattice dimension and a power of 2; q is a prime satisfying , The modulus q is selected as a prime of the form , where t is a positive integer. This construction directly ensures . and G is a group of order q. The prime q satisfies the stated constraint. Moreover,
is a polynomial ring with modulus q, and is a discrete Gaussian distribution defined over , with standard deviation [27]. Parameter g is shared by the offshore substation and the onshore centralized control center.
Parameter g is shared by the offshore substation and the onshore centralized control center.
The pre-shared authentication factor is securely provisioned to and during system initialization or device registration through a protected management channel. During long-term operation, can be periodically refreshed according to the security policy. If compromise or suspected leakage is detected, the current factor is revoked and replaced with a newly generated value before authentication is resumed. The parties then select a hash function
SHA-256 is used in this work and outputs a 256-bit message digest. To protect the identities of both parties, the commitment function is defined as
4.2. Long-Term Key Generation
This phase describes how interacts with , , and to generate and distribute the long-term identity-based public/private key pairs of the entities. The key generation procedure for is used as an example. To avoid placing full control of the private key with , the key is generated in the following three steps.
Step 1: randomly selects and and computes the blinded public key
It then sends to .
Step 2: receives the request. Sample and . Compute the public value
With the master secret key s, obtain the partial private key
Step 3: Entity combines the value received from , namely , with its locally retained value . Its final long-term private key is , and its long-term public key is .
Entity analogously obtains the long-term private key and public key . For clarity, the main variables involved in the long-term key generation phase, together with their meanings and visibility, are summarized in Table 1.
4.3. Key Agreement
The key agreement procedure between the offshore substation SDH device and the onshore centralized control center SDH device is shown in Figure 2 and proceeds as follows.
Figure 2.
Detailed key agreement procedure.
4.3.1. Offshore-Side Authentication Request
Before initiating an authentication request, conceals its identity by applying an identity commitment to identifier , thereby obtaining commitment . Entity then randomly selects and constructs the identity-hiding parameter . From the discrete Gaussian distribution , it samples parameter , and uses to compute the offshore-side ephemeral session public key . The commitment , pre-shared authentication factor , and nonce are jointly hashed to obtain the offshore-side authentication digest . Entity then packs the authentication data into plaintext , encodes it as polynomial , and encrypts it using the long-term public key of , namely . It randomly samples and performs the computations , , then sets the identity authentication ciphertext to . Finally, it constructs the first-round authentication request and sends it to .
4.3.2. Onshore-Side Authentication and Response
Entity receives the first-round authentication request sent by and first checks the integrity of the identity-related information.
(1) Entity uses the received and to recover and computes . It then verifies whether holds. If the equality holds, the offshore-side identity information has not been altered in transit and the message passes the integrity check. Otherwise, the request may have been tampered with or forged, and immediately terminates the protocol.
(2) After the first-round request passes the integrity check, uses its private key to decrypt , thereby recovering the offshore-side authentication digest , , and . Entity then uses the received offshore-side ephemeral public key P, identity commitment , pre-shared authentication factor , and nonce to reconstruct the local authentication digest . If holds, possesses the correct pre-shared authentication factor in the current session, and its transmitted identity commitment, session nonce, and ephemeral public key are mutually consistent; thus, the identity of is authenticated. Otherwise, the received authentication data do not match the local computation, and terminates the protocol. Upon successful authentication, samples from the discrete Gaussian distribution to obtain parameter , and computes the onshore-side ephemeral session public key and the key agreement intermediate . Functions and are then used to compute and , respectively.
(3) The identity of is mapped by the commitment function to the onshore-side identity commitment . A fresh value is sampled to construct the identity-hiding parameter . Based on the onshore-side ephemeral public key Q, identity commitment , pre-shared authentication factor , reconciliation hint w, and nonce , entity computes the authentication value . It then constructs the second-round response and sends it to . Meanwhile, it derives the shared session key from its local extraction result.
4.3.3. Offshore-Side Verification and Key Establishment
After receives the second-round response returned by , it performs the following operations.
(1) Entity uses the received and to recover the integrity nonce and computes . It then verifies whether holds. If it does, the onshore-side identity information has not been altered in transit and the response passes the integrity check. Otherwise, verification fails and immediately aborts the protocol.
(2) After the integrity check succeeds, uses the received onshore-side session value and substitutes into the computation to reconstruct authentication value . If holds, the onshore-side entity is authenticated; otherwise, aborts the protocol. Following successful authentication, enters the local key-recovery phase. From distribution , it samples parameter and combines its ephemeral private parameter with the received onshore-side ephemeral public key Q to compute the offshore-side key agreement intermediate . Function then yields . The shared session key is computed from the local extraction result. By the key-reconciliation mechanism, the parties’ extraction results satisfy , namely, . Consequently, and achieve mutual authentication and establish a common session key without revealing their device identities.
Remark 1.
Representative studies have demonstrated that post-quantum security mechanisms can be integrated into existing industrial communication systems through protocol security layers, security proxies, or plug-and-play security modules [28,29,30]. Following these deployment patterns, the proposed method does not alter the existing communication architecture or industrial communication protocols of offshore wind farms. Instead, the RLWE-based mutual authentication and key agreement procedure is introduced before operational data transmission over the existing TCP/IP link. After successful authentication and session key establishment, the established key can be used to protect the subsequent data transmission, while the original communication protocol and application-layer message format remain unchanged.
5. Security Analysis
5.1. Security Model
The security model considers the same three entities introduced in Section 2.1: the key generation center (KGC), the offshore substation SDH device , and the onshore centralized control center SDH device .
With appropriate security parameters, a malicious adversary cannot solve the search RLWE or decisional RLWE problem in polynomial time. The security of the proposed method is therefore founded on the hardness of RLWE. The relevant definitions are given below.
Definition 3
(Search RLWE problem). Let , where n is a power of 2 and modulus q satisfies . Given secret polynomial , choose uniformly at random, and, from error distribution , sample . The resulting sample pair follows the RLWE distribution, denoted by . Given multiple independent samples drawn from RLWE distribution , the search problem is to recover the corresponding secret polynomial s. If no probabilistic polynomial-time algorithm can recover s with non-negligible probability, the search RLWE problem is said to be hard.
Definition 4
(Decisional RLWE problem). Under the conditions above, given multiple independent samples , determine whether they were drawn from the RLWE distribution or from the uniform distribution over . If no probabilistic polynomial-time algorithm can distinguish the two distributions with non-negligible advantage, the decisional RLWE problem is said to be hard.
5.2. Security Proofs
5.2.1. Adversary Models
The proposed method considers the following two types of potential adversaries.
- Type- Adversary. This adversary does not know the system master key but can replace the public key of any legitimate device and obtain ephemeral keys from the public channel.
- Type- Adversary. This adversary knows the system master key but cannot replace the public key of a legitimate device.
5.2.2. Security Properties
- Confidentiality.
Theorem 1.
Given parameters , the proposed authentication method is indistinguishable under chosen plaintext attack under the decisional assumption.
Proof.
Consider the given parameters and . If , then a value is drawn uniformly from to obtain . If , uniformly sample , , and , and compute . Thus, given and , solving the decisional RLWE instance amounts to guessing . □
Assume that, in the proposed authentication method, the indistinguishability of can be broken with non-negligible advantage by a polynomial-time adversary . Then challenger can solve the decisional RLWE problem with non-negligible advantage, using as a subroutine of and answering its queries .
Finally, receives and outputs as its guess for . If , then guesses . Clearly, when , is a valid ciphertext, and the probability that adversary correctly guesses is . Therefore,
where is a non-negligible advantage. When , because is sampled uniformly, is independent of , and hence
Combining the two cases yields
This result contradicts the decisional RLWE assumption. Therefore, by contradiction, the proposed authentication method is indistinguishable under chosen plaintext attack.
- Unforgeability.
Theorem 2.
Given parameters , if a malicious adversary can break the proposed authentication algorithm with non-negligible advantage , then a probabilistic polynomial-time challenger can solve the search RLWE problem with non-negligible advantage .
Proof.
Challenger generates the system parameters according to the proposed algorithm. Assume that adversary , in a fresh session, can distinguish the session key from a random value with non-negligible advantage. The session key is computed as
where . If can correctly compute , this is equivalent to solving the RLWE problem for the given parameters . □
Suppose simulates protocol sessions in total, among which are matching sessions . The probability that a successful forgery by adversary occurs precisely in a matching session is
If the forgery advantage of adversary in an arbitrary session is , then its advantage in a matching session is at least . A successful forgery in a matching session implies that has correctly computed ; consequently, can recover the solution to the search RLWE instance from . Therefore, the probability that solves the search RLWE problem is
Lattice-based cryptography theory indicates that the search RLWE problem remains hard against quantum computation; no probabilistic polynomial-time algorithm is known to solve it with non-negligible advantage. By contradiction, no polynomial-time adversary can forge a valid authentication value with non-negligible advantage. Hence, the proposed method is unforgeable.
6. Experimental Results and Analysis
The experimental evaluation emulates the three protocol entities in the offshore wind farm communication environment, namely , , and . The experiments focus on evaluating the computational and communication overhead of the proposed key agreement protocol rather than simulating the physical operation of the offshore wind farm. To provide adequate computing resources and eliminate interference caused by hardware differences, the experiments were conducted on a computer equipped with an Intel Core i7-12650H CPU, 16 GB of RAM, and a 64-bit Windows 10 operating system. The algorithmic logic and communication procedure were implemented in Java. The performance of the proposed privacy-preserving key agreement method is evaluated quantitatively below in terms of computational and communication overhead.
6.1. Computational Overhead
Computational overhead analysis considers the costs of hashing, polynomial scalar multiplication, polynomial multiplication, polynomial addition, and exponentiation, denoted by , , , , and , respectively; the negligible cost of integer addition and subtraction is ignored. The execution costs of and are analyzed theoretically. The offshore side incurs a cost of , the onshore side incurs a cost of , and the total cost is . For comparison, the theoretical computational costs of the schemes in [16,17,18] are , , and , respectively.
Implementation-based benchmark experiments were conducted to measure the execution time of the five basic cryptographic operations involved in the protocol, namely hashing, polynomial scalar multiplication, polynomial multiplication, polynomial addition, and exponentiation, as reported in Table 2. Based on these measured operation times and the corresponding operation counts required by each scheme, the overall computational overhead was calculated. Specifically, the total execution time is given by , where , , , , and denote the numbers of hashing, polynomial scalar multiplication, polynomial multiplication, polynomial addition, and exponentiation operations, respectively.
Table 2.
Execution time of cryptographic operations.
According to Table 2, the computational cost of the proposed method is ms, whereas the costs of the schemes in [16,17,18] are ms, ms, and ms, respectively, as summarized in Table 3. Compared with [16] and [17], the proposed method reduces the computational cost by approximately and , respectively. Although the proposed method incurs approximately higher computational cost than [18], this moderate increase is acceptable considering its enhanced post-quantum security and functional completeness. Moreover, the proposed method requires only 10 hash operations, compared with 12 in [16] and 20 in [17], achieving a better balance between computational efficiency and security.
Table 3.
Comparison of computational overhead.
6.2. Communication Overhead
In addition to computational overhead, the communication overhead of the proposed method is evaluated quantitatively and compared with the schemes in [16,17,18]. For a fair comparison, only the payload introduced by the security mechanisms is counted; the fixed headers of TCP/IP and the SDH bearer layer, such as IP/TCP headers, Ethernet headers, and SDH mapping overhead, are excluded. To establish a common metric, let denote the identity length ( bits); denote the length of an element modulo q, where the bit length of the modulus q is set to bits ( bits); denote the ring-output length, where n is set to 1024 ( bits); denote the hash-output length, which is 256 bits ( bits) for SHA-256; and denote the auxiliary-parameter length ( bits). The total communication overhead is the sum of the bit lengths of all transmitted messages across all rounds, namely, , where r is the number of protocol rounds and is the sum of the field lengths in the message sent during round i. The scheme in [16] uses three rounds and incurs total overhead ; the scheme in [17] uses four rounds and incurs ; and the scheme in [18] uses two rounds and incurs . The proposed protocol uses two rounds: the first-round request from the offshore side incurs , and the second-round response from the onshore side incurs , yielding a total communication overhead of . Table 4 compares the resulting communication payloads in bits.
Table 4.
Communication overhead.
Taken together, the results in Table 3 and Table 4 show that the proposed method does not optimize a single metric in isolation; rather, it achieves a more practical balance among security, functional completeness, and performance overhead. Its communication overhead is 4608 bits. Compared with the schemes in [17] (8192 bits) and [18] (4864 bits), this represents reductions of approximately and , respectively. Compared with [16] (6144 bits), the proposed method incurs a modest increase in computation but reduces communication overhead by . In bandwidth-constrained SDH bearer networks, this reduction can substantially decrease link occupancy and handshake latency. Trading a moderate amount of local computation for lower transmission overhead is therefore well aligned with practical network requirements. Overall, the proposed method combines post-quantum security with more compact message exchange and lower critical-operation overhead.
Remark 2.
The performance results reported in this section correspond to the normal case in which mutual authentication is successfully completed. If an integrity check or authentication value verification fails, the corresponding entity immediately terminates the current protocol execution. In practical industrial communication systems, additional mechanisms can be employed to handle such failures. For example, an authentication-failure threshold can be introduced to restrict repeated invalid authentication attempts [31], while secure retransmission and data recovery mechanisms can be employed after anomaly detection [32]. These mechanisms may introduce additional recovery or re-authentication latency and communication overhead, which should be evaluated separately from the normal authentication delay in future work.
6.3. Cross-Paradigm Comparison of Post-Quantum Schemes
The above performance evaluation mainly compares the proposed method with existing lattice-based authentication and key agreement schemes. To further clarify the applicability of different post-quantum approaches to critical industrial infrastructure, this subsection provides a cross-paradigm comparison with representative code-based and hash-based schemes. Since these schemes are designed for different cryptographic functionalities, a direct comparison based solely on execution time is not always meaningful. Therefore, the comparison focuses on their main functionality, computational characteristics, communication and storage overhead, and suitability for industrial communication environments.
6.4. Cross-Paradigm Comparison with Post-Quantum Schemes
To further evaluate the suitability of different post-quantum paradigms for critical industrial communication, representative code-based, hash-based, and lattice-based schemes are compared with the proposed method. The comparison considers not only security functionality but also key/signature size, computational cost, and communication efficiency, thereby highlighting the different trade-offs of these post-quantum approaches.
As shown in Table 5, different post-quantum paradigms exhibit distinct trade-offs in terms of security functionality and implementation efficiency. Representative code-based schemes can provide post-quantum security but may involve relatively large key sizes, while hash-based schemes generally incur larger signature overhead and may require an additional mechanism for session key establishment. Lattice-based alternatives can provide both authentication and key-establishment capabilities, but their overall communication and computational overhead depends on the combination of cryptographic primitives adopted. In contrast, the proposed RLWE-based method integrates mutual authentication, identity privacy protection, and session key agreement within a unified protocol. Together with its low computational cost and high communication efficiency, the proposed method provides a favorable balance for offshore wind farm communication.
Table 5.
Comparison of representative post-quantum schemes.
7. Conclusions
This paper addressed the security requirements of the cross-sea communication link in offshore wind farms by proposing an RLWE-based privacy-preserving key agreement method. Theoretical analysis and experiments demonstrated its security as well as its computational and communication efficiency. The current method primarily targets point-to-point communication between an offshore substation and an onshore centralized control center. For multi-node or hierarchical offshore wind farm networks, the proposed two-round authentication mechanism can be extended through pairwise key agreement while maintaining the same handshake structure for each individual session; however, the overall authentication and key-management overhead will increase as the number of active communication relationships grows. Future work will therefore focus on hierarchical key management, group authentication, and dynamic session management to improve the scalability of the proposed method in large-scale offshore wind farm environments. Further work is required for key management in large-scale multi-node environments, practical deployment on devices with limited computing capacity, and data-privacy protection after the communication channel has been established.
Author Contributions
Conceptualization, X.L.; methodology, X.L.; software, X.L.; validation, H.C., X.C., J.M. and W.Z.; formal analysis, X.L.; investigation, H.C., X.C., J.M. and W.Z.; resources, H.C. and W.Z.; data curation, X.L.; writing—original draft preparation, X.L.; writing—review and editing, H.C., C.J. and H.Q.; visualization, X.L.; supervision, H.Q.; project administration, H.C.; funding acquisition, H.C. All authors have read and agreed to the published version of the manuscript.
Funding
This work was supported by the Shanghai Pujiang Program of China under Grant No. 25PJD047.
Institutional Review Board Statement
Not applicable.
Informed Consent Statement
Not applicable.
Data Availability Statement
Data are contained within the article. The original simulation data and program code are available from the corresponding author upon reasonable request.
Acknowledgments
The authors acknowledge the funding support described above.
Conflicts of Interest
Authors Haiwen Chen, Xianzhong Chen, Jiahao Mao, and Wei Zhang were employed by Huadian (Zhejiang) Marine Energy Technology Co., Ltd. The remaining authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.
References
- Yuan, J.; Shang, S.; Wu, S. “Dual-Carbon” Goal: Background, Importance, Popular Science Path and Outlook. Acad. J. Manag. Soc. Sci. 2024, 9, 116–119. [Google Scholar] [CrossRef] [Scilit]
- Zhang, J.; Wang, H. Development of Offshore Wind Power and Foundation Technology for Offshore Wind Turbines in China. Ocean Eng. 2022, 266, 113256. [Google Scholar] [CrossRef] [Scilit]
- Zou, M.; Zhao, C.; Xu, J. Modeling for Large-Scale Offshore Wind Farm Using Multi-Thread Parallel Computing. Int. J. Electr. Power Energy Syst. 2023, 148, 108928. [Google Scholar] [CrossRef] [Scilit]
- Yang, Y.; Bian, X.; Xu, J.; Zhang, P.; Xu, L.; Zhang, M. Optimal Planning of a Grid Integration Network for an Offshore Wind Power Cluster Incorporating Interconnected Lines. Front. Energy Res. 2026, 14, 1777837. [Google Scholar] [CrossRef] [Scilit]
- Staggs, J.; Ferlemann, D.; Shenoi, S. Wind Farm Security: Attack Surface, Targets, Scenarios and Mitigation. Int. J. Crit. Infrastruct. Prot. 2017, 17, 3–14. [Google Scholar] [CrossRef] [Scilit]
- Bueger, C.; Edmunds, T. Maritime Security and the Wind: Threats and Risks to Offshore Renewable Energy Infrastructure. Ocean Yearb. Online 2024, 38, 433–458. [Google Scholar] [CrossRef] [Scilit]
- Yu, S.; Chen, J.; Wang, S.; Zhang, Y.; Ma, K. A Secure and Lightweight ECC-Based Authentication Protocol for Wireless Medical Sensors Networks. Sensors 2025, 25, 6567. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Amiya, K.S.; Suraj, S.; Deepak, P. Lightweight Multi-Party Authentication and Key Agreement Protocol in IoT-Based E-Healthcare Service. ACM Trans. Multim. Comput. Commun. Appl. 2021, 17, 64. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Abbasinezhad-Mood, D.; Nikooghadam, M. An Anonymous ECC-Based Self-Certified Key Distribution Scheme for the Smart Grid. IEEE Trans. Ind. Electron. 2018, 65, 7996–8004. [Google Scholar] [CrossRef] [Scilit]
- Zhang, S.; Liu, Y.; Han, Z.; Yang, Z. A Lightweight Authentication Protocol for UAVs Based on ECC Scheme. Drones 2023, 7, 315. [Google Scholar] [CrossRef] [Scilit]
- Chen, F.; Xue, M.; Qiu, Y.; Yang, L.; Chen, Q.; Yu, C.; Yang, L.; Zou, L. Multi-Terminal Wireless Differential Protection Method for Offshore Wind Power Collection Lines. IEEE Access 2024, 12, 58789–58800. [Google Scholar] [CrossRef] [Scilit]
- Arjun, S.; Ananthakrishnan, G.; Asha, N.; Kanagasabapathy, G. Lightweight Cryptographic Framework for Securing IoT in Renewable Energy Systems: An ECC-Based Approach. In Proceedings of the 6th International Conference on IoT Based Control Networks and Intelligent Systems (ICICNIS), Bengaluru, India, 15–17 December 2025; pp. 609–616. [Google Scholar] [CrossRef] [Scilit]
- M"uller, M.; de Jong, J.; van Heesch, M.; Overeinder, B.; Hesselman, C. Retrofitting Post-Quantum Cryptography in Internet Protocols: A Case Study of DNSSEC. ACM SIGCOMM Comput. Commun. Rev. 2020, 50, 49–57. [Google Scholar] [CrossRef] [Scilit]
- Xagawa, K. Research Trends in Post-Quantum Cryptography. NTT Tech. Rev. 2019, 17, 22–26. [Google Scholar] [CrossRef] [Scilit]
- Lyubashevsky, V.; Peikert, C.; Regev, O. On Ideal Lattices and Learning with Errors over Rings. J. ACM 2013, 60, 43:1–43:35. [Google Scholar] [CrossRef] [Scilit]
- Zhao, Z.X.; Lian, H.H.; Shen, J. Identity-Based Authenticated Key Exchange Protocol from Lattice. J. Cryptol. Res. 2024, 11, 441–454. [Google Scholar] [CrossRef]
- Rewal, P.; Singh, M.; Mishra, D.; Pursharthi, K.; Mishra, A. Quantum-Safe Three-Party Lattice Based Authenticated Key Agreement Protocol for Mobile Devices. J. Inf. Secur. Appl. 2023, 75, 103505. [Google Scholar] [CrossRef] [Scilit]
- Ni, L.; Liu, X.; Gu, B.; Zhang, Y.; Zhou, H.; Wang, N. Anonymous Identity-Based Authenticated Key Agreement Protocol for Smart Healthcare. Appl. Res. Comput. 2025, 42, 282–287. [Google Scholar] [CrossRef]
- Hong, L.; Huang, H.Y.; Hu, W. Parameter Analysis of Group Key Exchange Protocol Based on RLWE Problem. J. Cryptol. Res. 2025, 12, 370–383. [Google Scholar] [CrossRef]
- Pursharthi, K.; Mishra, D. Towards Post-Quantum Authenticated Key Agreement Scheme for Mobile Devices. J. Inf. Secur. Appl. 2024, 82, 103754. [Google Scholar] [CrossRef] [Scilit]
- Park, H.; Son, S.; Park, Y.; Park, Y. Provably Quantum-Secure Three-Party Mutual Authentication and Key Exchange Protocol Based on Modular Learning with Error. Electronics 2024, 13, 3930. [Google Scholar] [CrossRef] [Scilit]
- Liu, F.; Zheng, Z.; Gong, Z.; Tian, K.; Zhang, Y.; Hu, Z.; Li, J.; Xu, Q. A Survey on Lattice-Based Digital Signature. Cybersecurity 2024, 7, 7. [Google Scholar] [CrossRef] [Scilit]
- Yang, Y.T.; Han, X.G.; Huang, J.R.; Zhao, Y. Bidirectional Authentication Key Agreement Protocol Supporting Identity’s Privacy Preservation Based on RLWE. J. Commun. 2019, 40, 180–186. [Google Scholar] [CrossRef]
- Liu, L.; Ma, J.; Wu, D.; Zhao, Y. Offshore Integrated Energy Systems for Low-Carbon Transition: A Review of Offshore Renewables, Geothermal Integration, Multi-Energy Coupling, and Optimization Methods. Processes 2026, 14, 2162. [Google Scholar] [CrossRef] [Scilit]
- Ge, C.; Yan, J.; Liu, Y.; Lu, Z. Review of Key Technologies for Operation Control and Maintenance of Offshore Wind Farm. Proc. CSEE 2022, 42, 4278–4291. [Google Scholar] [CrossRef]
- Kim, D.; Ryu, G.; Moon, C.; Kim, B. Accuracy of a Short-Term Wind Power Forecasting Model Based on Deep Learning Using LiDAR-SCADA Integration: A Case Study of the 400-MW Anholt Offshore Wind Farm. Appl. Energy 2024, 373, 123882. [Google Scholar] [CrossRef] [Scilit]
- Jiang, C.; Li, X.; Du, D.; Qian, H.; Wen, M.; Wu, L.; Findeisen, R. Privacy Preservation for Cloud-Edge-Collaborative Energy Management System Using Post-Quantum Homomorphic Encryption. IEEE Trans. Smart Grid 2025, 16, 3282–3294. [Google Scholar] [CrossRef] [Scilit]
- Paul, S.; Scheible, P.; Wiemer, F. Towards post-quantum security for cyber-physical systems: Integrating PQC into industrial M2M communication. J. Comput. Secur. 2022, 30, 623–653. [Google Scholar] [CrossRef] [Scilit]
- Trungadi, F.; Fabiano, M.; Aloisio, D.; Brunaccini, G.; Sergi, F.; Merlino, G.; Longo, F. Securing Modbus in legacy industrial control systems: A decentralized approach using proxies, post-quantum cryptography and self-sovereign identity. J. Inf. Secur. Appl. 2025, 94, 104199. [Google Scholar] [CrossRef] [Scilit]
- Ponnuru, R.B.; Palaniswamy, B.; Azab, M.; Palmieri, P.; Roedig, U. Protecting DNP3-SAB (SAv6): A quantum-safe hybrid authentication protocol with moving target defense. IEEE Trans. Consum. Electron. 2025, 71, 8383–8395. [Google Scholar] [CrossRef] [Scilit]
- Wu, Y.; Feng, T.; Su, C.; Liu, C. MSAUPL: A multi-server authentication and key agreement protocol for industrial IoT based on user privacy level. J. Inf. Secur. Appl. 2025, 89, 103991. [Google Scholar] [CrossRef] [Scilit]
- Yang, K.; Wang, H.; Zhu, H.; Sun, L. An effective intrusion-resilient mechanism for programmable logic controllers against data tampering attacks. Comput. Ind. 2022, 138, 103613. [Google Scholar] [CrossRef] [Scilit]
- Duraibi, S.; Alashjaee, A.M. Lightweight post-quantum secure communication protocol for IoT devices using code-based cryptography. IEEE Trans. Consum. Electron. 2025, 71, 11228–11236. [Google Scholar] [CrossRef] [Scilit]
- Liu, C.-H. Lightweight hash-based post-quantum signature scheme for Industrial Internet of Things. Comput. Mater. Contin. 2026, 86, 1–18. [Google Scholar] [CrossRef] [Scilit]
- Shahid, A.B.; Mansoor, K.; Bangash, Y.A.; Iqbal, W.; Mussiraliyeva, S. Post-quantum cryptographic authentication protocol for Industrial IoT using lattice-based cryptography. Sci. Rep. 2026, 16, 9582. [Google Scholar] [CrossRef] [Scilit] [PubMed]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.

