A blockchain-based quantum key billing system

By using a blockchain-based distributed storage system, the problems of centralized data storage and insufficient security in quantum key billing methods are solved, enabling secure data storage and traceability, and ensuring the integrity and confidentiality of billing information.

CN116418489BActive Publication Date: 2026-01-30QUANTUMCTEK CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111655852.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-30
Publication Date
2026-01-30
Estimated Expiration
2041-12-30

AI Technical Summary

Technical Problem

Existing digital key billing methods have problems such as single point of failure due to centralized data storage, data forgery and tampering due to plaintext storage, lack of attribute information, and insufficient security.

Method used

A blockchain-based distributed storage system is adopted, and billing information is generated and signed through a quantum key management terminal. The decentralized and encryption mechanisms of blockchain are used to ensure the secure storage and transmission of billing information.

Benefits of technology

It ensures data security and integrity, avoids single points of failure and tampering risks, provides key lifecycle management and traceability capabilities, and ensures the authenticity and confidentiality of billing information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116418489B_ABST
    Figure CN116418489B_ABST
Patent Text Reader

Abstract

This invention discloses a blockchain-based quantum key billing system, belonging to the field of quantum communication technology. It includes: a quantum key management terminal, a blockchain-based distributed storage system, a quantum service support system, and quantum key application devices. The quantum key management terminal receives quantum key request information from the quantum key application devices, outputs quantum keys to the quantum key application devices, generates billing information including the amount of quantum keys output, and uploads the billing information to the distributed storage system. The quantum service support system retrieves billing information for each quantum key application device from the distributed storage system and determines whether to update the service status of the quantum key application device based on the amount of quantum keys, subscribed packages, and user balance in the billing information. This invention, based on blockchain technology, avoids data loss or corruption caused by single-point device failure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of quantum communication technology, and in particular relates to a quantum key billing system based on blockchain. Background Technology

[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.

[0003] like Figure 1 As shown, the current quantum key distribution method uses the following technical solution:

[0004] 1) Every time the "key management terminal" of the key management layer outputs a quantum key to the "key application layer device" of the key application layer, the billing list agent software in the "key management terminal" device will generate a key billing information (or billing information) for this key output behavior. The billing information includes: the ID of the local key application layer device, the ID of the peer key application layer device, the start and end time of the key output, and the amount of key output.

[0005] 2) The "Key Management Terminal" sends billing information to the "Quantum Business Support System" in real time, where it is centrally stored and managed.

[0006] 3) The “Quantum Business Support System” decides whether to shut down the “Key Application Layer Device” or continue to provide services to it based on the user’s package and billing information.

[0007] This technical solution, which centrally stores quantum key billing information data in the "Quantum Business Support System" business database, has the following drawbacks:

[0008] 1) Centralized data storage poses risks of single point of failure, data loss, and corruption.

[0009] 2) Billing information is stored in plaintext in the "Quantum Business Support System" database, which poses a risk of data forgery and tampering, resulting in incorrect billing information and difficulties in reconciliation;

[0010] 3) There is no corresponding attribute information for the generation and application of keys, which cannot meet the increasingly demanding user requirements, such as key information traceability;

[0011] 4) Data transmission and storage lack security protection mechanisms, making it impossible to guarantee data confidentiality and integrity. Summary of the Invention

[0012] To overcome the shortcomings of the existing technology, this invention provides a blockchain-based quantum key billing system. Based on blockchain technology, it ensures data security and avoids data loss or damage caused by single-point device failure.

[0013] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions:

[0014] A blockchain-based quantum key billing system includes: a quantum key management terminal, a blockchain-based distributed storage system, a quantum service support system, and quantum key application equipment; wherein,

[0015] The quantum key management terminal is used to receive quantum key request information from quantum key application devices, output quantum keys, and generate corresponding billing information, including the amount of quantum keys output this time; upload the billing information to the distributed storage system, and send the quantum keys to the quantum key application devices;

[0016] The quantum service support system is used to obtain the billing information of each quantum key application device from the distributed storage system, and determine whether to update the service status of the quantum key application device based on the quantum key quantity, subscribed package and user balance in the billing information.

[0017] Furthermore, the quantum key management terminal is equipped with a private key and uploads the corresponding public key to a distributed storage system;

[0018] The billing information generated by the quantum key management terminal also includes a billing information signature obtained by signing with the private key;

[0019] After receiving the billing information, the distributed storage system verifies it using the corresponding public key. If the verification is successful, it performs the storage operation.

[0020] Furthermore, the billing information generated by the quantum key management terminal also includes a service number that identifies the current billing behavior, and is sent to the quantum key application device; the quantum key application device queries the corresponding billing information from the distributed storage system based on the service number.

[0021] Furthermore, the billing information generated by the quantum key management terminal also includes one or more of the following: quantum key management terminal information, quantum key application device information, and peer quantum key application device information to be established for communication, as well as the start and end times of key output.

[0022] Furthermore, the quantum key management terminal is equipped with a private key and uploads the corresponding public key to a distributed storage system;

[0023] The data structure of the billing information is as follows: it includes a message header and a message body, and the message header includes a billing information signature obtained by signing with a private key.

[0024] After receiving the billing information, the distributed storage system verifies it using the corresponding public key. If the verification is successful, it performs the storage operation.

[0025] Furthermore, the message header also includes a service number that identifies this billing activity, and is sent to the quantum key application device; the quantum key application device queries the corresponding billing information from the distributed storage system based on the service number.

[0026] Furthermore, the quantum business support system has a private key and distributes the corresponding public key to the quantum key management terminal;

[0027] The message body includes a first ciphertext block, which includes a quantum key and is encrypted using the public key of the quantum business support system.

[0028] After obtaining billing information from the distributed storage system, the quantum business support system uses a private key to decrypt the first ciphertext block to obtain the quantum key quantity.

[0029] Furthermore, both the message header and the first ciphertext block also include a key verification value;

[0030] After the quantum business support system obtains and decrypts the billing information, it first compares the message header with the key verification value in the first ciphertext block. If they are the same, the verification is successful.

[0031] Furthermore, the first ciphertext block also includes one or more of the following: quantum key management terminal information, quantum key application device information, and peer quantum key application device information to be established for communication, as well as the start and end times of key output.

[0032] Furthermore, the message body also includes a second ciphertext block, the content of which is identical to that of the first ciphertext block, and is encrypted using a portion of the key at a set position in the quantum key distribution.

[0033] After obtaining the billing information, the quantum key application device uses quantum keys to decrypt it.

[0034] One or more embodiments provide a quantum key management terminal connected to a blockchain-based distributed storage system, configured to include:

[0035] The key request acquisition module is used to receive quantum key request information from quantum key application devices;

[0036] A quantum key output module is used to output a quantum key to a quantum key application device according to the quantum key request information;

[0037] The billing information generation module is used to generate corresponding billing information based on the data of this quantum key, and the billing information includes the amount of quantum key output this time;

[0038] The billing information uploading module is used to upload the billing information to the distributed storage system.

[0039] Furthermore, the quantum key management terminal is equipped with a private key and uploads the corresponding public key to a distributed storage system;

[0040] The billing information also includes a billing information signature obtained by signing with a private key, which is used for verification by the distributed storage system.

[0041] Furthermore, the billing information also includes a service number that identifies the current billing activity, which is sent to the quantum key application device for the quantum key application device to retrieve the corresponding billing information from the distributed storage system.

[0042] Furthermore, the quantum key management terminal is equipped with a private key and uploads the corresponding public key to a distributed storage system;

[0043] The data structure of the billing information is as follows: it includes a message header and a message body. The message header includes a billing information signature obtained by signing with a private key, which is used for verification by the distributed storage system.

[0044] Furthermore, the message header also includes a service number that identifies this billing activity, and is sent to the quantum key application device, which then retrieves the corresponding billing information from the distributed storage system.

[0045] Furthermore, the billing information also includes one or more of the following: quantum key management terminal information, quantum key application device information, and peer quantum key application device information to be established for communication, as well as the start and end times of key output.

[0046] Furthermore, the message body includes a first ciphertext block, which includes a quantum key quantity and is encrypted using the public key of the quantum business support system. This is used by the quantum business support system to decrypt the first ciphertext block using its private key after obtaining billing information from the distributed storage system, thereby obtaining the quantum key quantity.

[0047] Furthermore, both the message header and the first ciphertext block also include a key verification value, which is used by the quantum service support system to compare the key verification value in the message header and the first ciphertext block after obtaining and decrypting the billing information. If they are the same, the verification is successful.

[0048] Furthermore, the first ciphertext block also includes one or more of the following: quantum key management terminal information, quantum key application device information, and peer quantum key application device information to be established for communication, as well as the start and end times of key output.

[0049] Furthermore, the message body also includes a second ciphertext block, the content of which is identical to that of the first ciphertext block. The second ciphertext block is encrypted using a portion of the key at a set position in the quantum key distribution, and is used by the quantum key application device to decrypt the message after obtaining the billing information.

[0050] One or more embodiments provide a blockchain-based distributed storage system connected to a quantum key management terminal, wherein the quantum key management terminal has a private key and uploads the corresponding public key to the distributed storage system; the distributed storage system is configured to include:

[0051] The data verification module is used to receive billing information sent by the quantum key management terminal. The billing information includes a billing information signature obtained by signing with the private key of the quantum key management terminal. The module verifies the billing information signature using the public key. If the verification is successful, the module performs a storage operation on the billing information.

[0052] Furthermore, the billing information includes a service number that identifies this billing activity;

[0053] The system also includes a data query module, used to receive a billing information query request sent by the quantum key application device, the query request including a service number; to find the corresponding billing information according to the service number and return it to the quantum key application device, wherein the billing information includes the service number.

[0054] Furthermore, the data structure of the billing information includes a message header and a message body, wherein the message header includes a service number and the message body includes a second ciphertext block, which is encrypted using a portion of the key at the position set by the corresponding quantum key of the billing information;

[0055] The system also includes a data query module, which receives a billing information query request sent by the quantum key application device, searches for the corresponding billing information based on the service number in the query request, and returns it to the quantum key application device.

[0056] One or more embodiments provide a quantum key distribution device connected to a blockchain-based distributed storage system, configured to include:

[0057] The quantum key request module is used to send quantum key request information to the quantum key management terminal;

[0058] The quantum key receiving module is used to acquire the output quantum key and corresponding service number;

[0059] The billing information query module is used to send a billing information query request to the distributed storage system, the query request including the service number; and to obtain the queried billing information.

[0060] Furthermore, the data structure of the billing information includes a message header and a message body, wherein the message header includes a service number, and the message body includes a second ciphertext block, which is encrypted using a portion of the key at the position set by the corresponding quantum key of the billing information;

[0061] After obtaining the billing information from the query, it is decrypted using quantum key distribution.

[0062] One or more embodiments provide a quantum business support system connected to a blockchain-based distributed storage system, configured to include:

[0063] The application device service status management module is used to obtain the billing information of each quantum key application device from the distributed storage system, and determine whether to update the service status of the quantum key application device based on the quantum key quantity, subscribed package and user balance in the billing information.

[0064] Furthermore, the quantum business support system has a private key and distributes the corresponding public key to the quantum key management terminal;

[0065] The data structure of the billing information includes a message header and a message body. The message body includes a first ciphertext block, which is encrypted using the public key of the quantum business support system. The first ciphertext block includes a quantum key quantity.

[0066] The application device service status management module obtains the billing information of each quantum key application device from the distributed storage system and then decrypts it using the private key.

[0067] Furthermore, both the message header and the first ciphertext block also include a key verification value;

[0068] After obtaining and decrypting the billing information, the application device service status management module first compares the message header with the key verification value in the first ciphertext block. If they are the same, the verification is successful.

[0069] The above one or more technical solutions have the following beneficial effects:

[0070] By adopting a blockchain-based distributed storage system, decentralization is achieved, effectively avoiding the risk of data loss and damage due to single point of failure of equipment, and preventing tampering.

[0071] The billing information generated by the quantum key management terminal contains rich attribute information:

[0072] (1) Billing information signature is used by the distributed storage system to verify the data after receiving the billing information. The data is stored only after the verification is passed, thus ensuring the authenticity of the data.

[0073] (2) The business number that identifies this billing behavior is beneficial for the quantum business support system to manage billing information, and provides a retrieval index for quantum key application devices, making it easier to perform query operations from the distributed storage system;

[0074] (3) Quantum key management terminal information, quantum key application device information and peer quantum key application device information to be established for communication. This information is helpful for tracing any key or billing behavior and realizes key lifecycle management.

[0075] For billing information, a data structure containing a message header and a message body is provided. The message body is divided into a first ciphertext block and a second ciphertext block, which are used by the quantum business support system and the quantum key application device to obtain data, respectively. The relevant data can only be obtained by decrypting the ciphertext block, thus ensuring the security of data transmission.

[0076] A key hash value for verification is set in both the message header and the encrypted message body. After the message body is decrypted, the integrity of the information can be further guaranteed through the message header and message body. Attached Figure Description

[0077] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0078] Figure 1 This is an architecture diagram of a quantum key billing system in the existing technology;

[0079] Figure 2 This is an architecture diagram of a blockchain-based quantum key billing system in one or more embodiments of the present invention;

[0080] Figure 3 This is a schematic diagram of data storage in a blockchain-based distributed storage system according to one or more embodiments of the present invention;

[0081] Figure 4 This is the data structure for billing information in one or more embodiments of the present invention. Detailed Implementation

[0082] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0083] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0084] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0085] Example 1

[0086] This embodiment discloses a blockchain-based quantum key billing system for managing quantum key billing information (or billing information), such as... Figure 2 As shown, it includes: the billing information publisher (or data publisher), the data storage provider, and the data user.

[0087] The billing information publisher mainly consists of "quantum key management terminals" distributed throughout the quantum communication system. These terminals output quantum keys to the quantum key application devices to which communication is needed and upload the corresponding billing information to the data storage provider for storage. The data storage provider employs a blockchain-based distributed storage system. The data users include quantum key application devices and a quantum service support system. The quantum key application devices can be mobile terminals capable of querying their own bills from the data storage provider and verifying the accuracy of the bills. The quantum service support system manages the user packages of the quantum key application devices and can query all data on the quantum key information chain. Based on the user packages and billing information, it decides whether to suspend the quantum key application devices or continue providing services to them.

[0088] Furthermore, based on asymmetric encryption technology, the quantum key management terminal has a private key and uploads the corresponding public key to the distributed storage system; the quantum business support system also has a private key and distributes the corresponding public key to the quantum key management terminal.

[0089] The quantum key billing system will be described in detail below.

[0090] A quantum key management terminal is configured to acquire quantum key request information from a quantum key application device to be communicated with, output a quantum key, generate a billing information record for each quantum key output, and send the billing information to a distributed storage system. Specifically, a quantum key management terminal includes:

[0091] The key request acquisition module is used to acquire the quantum key request information of the quantum key application device. The quantum key request information includes the information of the quantum key application device and the information of the peer quantum key application device to which communication is to be established.

[0092] The quantum key output module is used to output the quantum key and the corresponding service number to the quantum key application device according to the quantum key request information.

[0093] The billing information generation module is used to generate corresponding billing information based on the output of this quantum key. The billing information includes: the signature value of the billing information, the service number, the quantum key management terminal information, the quantum key application device information of both parties, the quantum key verification value, and the output information of the quantum key.

[0094] The signature value of the billing information is used by the distributed storage system to verify the billing information after receiving it; the service number is used to uniquely identify the output of the quantum key, and each output of the quantum key corresponds to a billing behavior; the quantum key management terminal information and the quantum key application device information of both parties are used to trace the quantum key; the output information of the quantum key includes the start time, end time and key quantity of the key output, which is used to realize billing control and reconciliation between devices.

[0095] As one specific implementation, the data structure of the billing information includes a billing message header and a billing message body.

[0096] The billing message header includes quantum key management terminal information, billing information signature value, quantum key verification information (key HASH value in this embodiment), and billing bill service number. The billing information signature value is obtained by signing with a private key.

[0097] The billing message body includes a first encrypted data block and a second encrypted data block. The first and second encrypted data blocks contain the same content, both including quantum key management terminal information, quantum key application device information for both parties (in this embodiment, these are the quantum key management terminal ID, the local quantum key application device ID, and the peer quantum key application device ID, respectively), quantum key output information (including key output start time, key output end time, and key quantity), and the generated quantum key verification information (in this embodiment, the key HASH value). The first encrypted data block is encrypted using the public key of the quantum service support system, and only the quantum service support system can decrypt it. It is used by the quantum service support system to obtain the key output information of each quantum key application device for billing purposes. The second encrypted data block is encrypted using a portion of the key at a designated position in the output quantum key, and only the corresponding quantum key application device can decrypt it. It is used by the quantum key application device to query its own billing information or to reconcile accounts with other quantum key application devices. In this embodiment, the second encrypted data block is encrypted using the last 16 bytes of the quantum key.

[0098] The billing information uploading module is used to upload the billing information to the distributed storage system.

[0099] A blockchain-based distributed storage system includes multiple ledger nodes based on blockchain technology for distributed storage of billing information, receiving data acquisition requests from quantum key application devices or quantum business support systems, performing query operations, and returning the data. The consensus algorithm employs the proof-of-work method. The distributed storage system includes:

[0100] The data verification module receives billing information uploaded by the quantum key management terminal. All accounting node devices look up the corresponding public key based on the quantum key management terminal information in the message header, and use the public key to verify the "billing information signature value" information in the message header to ensure message integrity and authenticity. If the verification passes, the data storage module is invoked; if the verification fails, indicating a possible malicious attack, the billing information is sent to the quantum business support system for manual verification.

[0101] The data storage module is used by all ledger node devices to attempt to package the data. The first ledger node device to successfully package the data will broadcast the complete package information (hereinafter referred to as the block) to all other ledger nodes. All other ledger nodes will verify the validity of the block. If the block is valid, it will be stored on the quantum key chain.

[0102] The quantum key chain establishes a uniquely ordered blockchain by recording the hash value of the previous block within each block. The formation of this chain is independent of the system time of individual nodes, depending only on the actual order in which blocks are generated. Once a newly generated block is recognized by the entire network, it is stored across all network nodes, becoming part of the unified transaction record chain. Due to the mathematical nature of hash algorithms, once the chain is formed, altering a block's content or reversing its order requires recalculating the content of all blocks after the altered block. However, since the blockchain is stored across distributed nodes in the network, such modification is clearly impossible. A schematic diagram of the quantum key chain is shown below. Figure 3 .

[0103] The data query module is used to receive a billing information query request sent by the quantum key application device. The billing information query request includes a service number. The module queries the corresponding billing information according to the service number and returns it to the quantum key application device. Alternatively, it can receive a billing information retrieval request sent by the quantum service support system and return all billing information to the quantum service support system.

[0104] Both the quantum key application device and the quantum business support system use a unified blockchain operation interface (or access interface). The blockchain operation interface includes an information publishing interface and an information query interface, which are used to send information to the distributed storage system and retrieve query data from the distributed storage system, respectively.

[0105] Quantum key application devices are configured to include:

[0106] The user package subscription module is used to send package subscription requests to the quantum business support system, and to receive and confirm package information from the quantum business support system.

[0107] The quantum key request module is used to send quantum key request information to the quantum key management terminal. The quantum key request information includes information about the quantum key application device and information about the peer quantum key application device with which communication is to be established.

[0108] The quantum key receiving module is used to receive quantum keys and corresponding service numbers from the quantum key management terminal.

[0109] The billing information query module is used to send a billing information query request to the distributed storage system. The query request includes the service number and the billing information fed back by the distributed storage system. The second ciphertext block is decrypted using a partial key set at the corresponding quantum key location.

[0110] Upon receiving billing information from the distributed storage system, the system retrieves the corresponding key information based on the service number in the billing information message header. This retrieved key is then used to decrypt the second ciphertext block, yielding the plaintext bill. Based on this plaintext information, the integrity of the received quantum key can be verified, as well as the accuracy of the decrypted billing information can be confirmed (similar to how mobile users verify the accuracy of their bills after receiving them at a service center).

[0111] The quantum business support system is configured to include:

[0112] The user package subscription module is used to receive package subscription requests sent by the quantum key application device and feed back package information to the quantum key application device; and to receive confirmation information from the quantum key application device for a specified user package.

[0113] The user package management module manages package information for multiple quantum key application devices.

[0114] The application device service status management module is used to obtain the corresponding billing information of each quantum key application device from the distributed storage system, decrypt the first ciphertext block using the private key, and then compare the quantum key verification information in the first ciphertext block with the quantum key verification information in the message header to confirm whether the billing information is complete.

[0115] If the billing information is complete, the decrypted data will be stored. Since the billing behavior is uniquely identified by the business number, the problem of double billing under replay attack can be prevented.

[0116] Based on the amount of quantum key in the first ciphertext block, combined with the corresponding package information and remaining balance, it is determined whether the service status of the quantum key application device needs to be updated; the service status includes continued service status and shutdown status. If the amount of quantum key in the quantum key application device has exceeded the user's package limit, or the balance is insufficient, the service status will be updated to shutdown status, and services will be stopped for the quantum key application device.

[0117] The anomaly information verification module is used to receive billing information indicating signature verification failure sent by the distributed storage system, perform manual verification, and then re-upload it to the distributed storage system.

[0118] Example 2

[0119] Based on the billing system provided in Embodiment 1 above, the purpose of this embodiment is to provide a quantum key management terminal, connected to a blockchain-based distributed storage system, configured to include:

[0120] The key request acquisition module is used to receive quantum key request information from quantum key application devices;

[0121] A quantum key output module is used to output a quantum key to a quantum key application device according to the quantum key request information;

[0122] The billing information generation module is used to generate corresponding billing information based on the data of this quantum key, and the billing information includes the amount of quantum key output this time;

[0123] The billing information uploading module is used to upload the billing information to the distributed storage system.

[0124] To ensure the authenticity of the received billing information, the quantum key management terminal has a private key and has pre-uploaded the corresponding public key to the distributed storage system. The billing information also includes a billing information signature obtained by signing with the private key, which is used by the distributed storage system for verification. To facilitate the management of the billing information and to serve as an index for subsequent retrieval, the billing information also includes a service number identifying this billing activity, which is sent to the quantum key application device for the quantum key application device to retrieve the corresponding billing information from the distributed storage system.

[0125] To ensure the authenticity of the billing information, the quantum key management terminal is equipped with a private key and has uploaded the corresponding public key to the distributed storage system in advance. The data structure of the billing information includes a message header and a message body. The message header includes a billing information signature obtained by signing with the private key, which is used by the distributed storage system for verification.

[0126] The message header also includes a service number that identifies this billing activity, and is sent to the quantum key application device, which then retrieves the corresponding billing information from the distributed storage system.

[0127] As a further implementation, the message body includes a first ciphertext block, which includes a quantum key quantity and is encrypted using the public key of the quantum business support system. This is used by the quantum business support system to decrypt the first ciphertext block using its private key after obtaining billing information from the distributed storage system, thereby obtaining the quantum key quantity.

[0128] Both the message header and the first ciphertext block also include a key verification value. After the quantum service support system obtains and decrypts the billing information, it first compares the key verification value in the message header and the first ciphertext block. If they are the same, the verification is successful.

[0129] The first ciphertext block also includes one or more of the following: quantum key management terminal information, quantum key application device information, and peer quantum key application device information to be established for communication, as well as the start and end times of key output.

[0130] The message body also includes a second ciphertext block, the content of which is identical to that of the first ciphertext block. The second ciphertext block is encrypted using a portion of the key at a set position in the quantum key, and is used by the quantum key application device to decrypt the message after obtaining the billing information.

[0131] Example 3

[0132] Based on the billing system described in Embodiment 1, the purpose of this embodiment is to provide a blockchain-based distributed storage system connected to a quantum key management terminal. The quantum key management terminal has a private key and uploads the corresponding public key to the distributed storage system. The distributed storage system is configured to include:

[0133] The data verification module is used to receive billing information sent by the quantum key management terminal. The billing information includes a billing information signature obtained by signing with the private key of the quantum key management terminal. The module verifies the billing information signature using the public key. If the verification is successful, the module performs a storage operation on the billing information.

[0134] To facilitate the management of billing information and to serve as an index for subsequent retrieval, the billing information includes a service number that identifies the current billing activity.

[0135] The distributed storage system further includes a data query module, used to receive a billing information query request sent by the quantum key application device, the query request including a service number; to find the corresponding billing information according to the service number and return it to the quantum key application device, wherein the billing information includes the service number.

[0136] As a further implementation, the data structure of the billing information includes a message header and a message body. The message header includes a service number, and the message body includes a second ciphertext block, which is encrypted using a portion of the key at the corresponding quantum key setting position of the billing information. After receiving a billing information query request sent by the quantum key application device, the corresponding billing information is found based on the service number in the query request and returned to the quantum key application device.

[0137] Example 4

[0138] Based on the billing system described in Embodiment 1, the purpose of this embodiment is to provide a quantum key distribution device that connects to a blockchain-based distributed storage system and is configured to include:

[0139] The quantum key request module is used to send quantum key request information to the quantum key management terminal;

[0140] The quantum key receiving module is used to acquire the output quantum key and corresponding service number;

[0141] The billing information query module is used to send a billing information query request to the distributed storage system, the query request including the service number; and to obtain the queried billing information.

[0142] As a further implementation, the data structure of the billing information includes a message header and a message body. The message header includes a service number, and the message body includes a second ciphertext block, which is encrypted using a portion of the key at the position set by the corresponding quantum key of the billing information. After obtaining the queried billing information, it is decrypted using the quantum key.

[0143] Example 5

[0144] Based on the billing system described in Embodiment 1, the purpose of this embodiment is to provide a quantum service support system, connected to a blockchain-based distributed storage system, configured to include:

[0145] The application device service status management module is used to obtain the billing information of each quantum key application device from the distributed storage system, and determine whether to update the service status of the quantum key application device based on the quantum key quantity, subscribed package and user balance in the billing information.

[0146] As a further implementation, the quantum service support system has a private key and distributes the corresponding public key to the quantum key management terminal. The data structure of the billing information includes a message header and a message body, wherein the message body includes a first ciphertext block, which is encrypted using the public key of the quantum service support system, and the first ciphertext block includes the quantum key quantity; after obtaining the billing information of each quantum key application device from the distributed storage system, it is decrypted using the private key.

[0147] Both the message header and the first ciphertext block include a key verification value. After obtaining and decrypting the billing information, the key verification values ​​in the message header and the first ciphertext block are compared first. If they are the same, the verification is successful, meaning the message is complete.

[0148] For detailed implementation methods of Examples 2 to 5 above, please refer to the relevant description section of Example 1, which will not be repeated here.

[0149] The above one or more embodiments, based on blockchain technology, achieve the following technical effects:

[0150] 1) Decentralization: The quantum key chain consists of numerous accounting nodes. There is no centralized equipment or management institution. The failure of any node will not affect the overall accounting work of the system, thus ensuring data security.

[0151] 2) Immutable or unforgeable: By using cryptographic methods to link with two adjacent blocks, attackers can modify the data of individual nodes without affecting the database information of other nodes.

[0152] 3) Traceability: Rich billing attribute information. Each transaction contains information such as key manager and user device ID. Any key can be traced through billing (billing) information to achieve key lifecycle management.

[0153] 4) Establish a comprehensive security mechanism, storing all billing information in encrypted form on the ledger node devices of a blockchain-based distributed storage system. Only the actual key owner and the quantum business support system can decrypt the billing information, fully guaranteeing information confidentiality. All ledger nodes in the distributed storage system verify the billing information through digital signatures, fully guaranteeing the authenticity of the billing information, and ensuring non-repudiation of billing information exchange. Furthermore, the data structure of the billing information is designed to include a message header and a message body, with a key HASH value set in both the message header and the encrypted message body for verification. After decrypting the message body, the integrity of the information can be further guaranteed through the message header and message body.

[0154] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.

Claims

1. A quantum key billing system based on blockchain, characterized in that, Comprise: Quantum key management terminal, blockchain-based distributed storage system, quantum service support system and quantum key application device; wherein, The quantum key management terminal is used for receiving quantum key request information of the quantum key application device, outputting quantum keys, and generating corresponding billing information, wherein the billing information includes the amount of quantum keys output this time; uploading the billing information to the distributed storage system, and sending the quantum keys to the quantum key application device; The data structure of the billing information is: including a message header and a message body, the message body includes a first ciphertext block and a second ciphertext block, the first ciphertext block includes the amount of quantum keys and is encrypted by the public key of the quantum service support system; the second ciphertext block has the same content as the first ciphertext block and is encrypted by part of the key at a specified position in the quantum key; The quantum service support system is used for obtaining the billing information of each quantum key application device from the distributed storage system, decrypting the first ciphertext block by using a private key to obtain the amount of quantum keys, and judging whether to update the service state of the quantum key application device according to the amount of quantum keys, the subscribed package and the user balance in the billing information; The quantum key application device is used for obtaining the corresponding billing information of the quantum key application device from the distributed storage system, and decrypting the second ciphertext block by using part of the key at a specified position in the corresponding quantum key.

2. The quantum key billing system based on blockchain according to claim 1, wherein The quantum key management terminal is provided with a private key, and the corresponding public key is uploaded to the distributed storage system; The billing information generated by the quantum key management terminal further includes a billing information signature signed by the private key; After receiving the billing information, the distributed storage system verifies by using the corresponding public key, and if the verification is passed, the storage operation is performed.

3. The quantum key billing system based on blockchain according to claim 1, wherein The billing information generated by the quantum key management terminal further includes a service number identifying the billing behavior this time, and is sent to the quantum key application device; the quantum key application device queries the corresponding billing information from the distributed storage system according to the service number.

4. The quantum key billing system based on blockchain according to claim 1, wherein The billing information generated by the quantum key management terminal further includes one or more of the quantum key management terminal information, the quantum key application device information and the opposite quantum key application device information to be established for communication, and the start and end time of the key output.

5. The quantum key billing system based on blockchain according to claim 1, wherein The quantum key management terminal is provided with a private key, and the corresponding public key is uploaded to the distributed storage system; The message header includes a billing information signature signed by the private key; After receiving the billing information, the distributed storage system verifies by using the corresponding public key, and if the verification is passed, the storage operation is performed.

6. The quantum key billing system based on blockchain according to claim 5, wherein The message header also includes a service number identifying the current charging behavior, and is sent to the quantum key application device; the quantum key application device queries corresponding charging information from the distributed storage system according to the service number. 7.The quantum key charging system based on a blockchain according to claim 1, characterized in that, The message header and the first ciphertext block also include a key check value; After the quantum service support system acquires the charging information and decrypts it, the key check value in the message header and the first ciphertext block is compared first, and if they are the same, the verification is passed. 8.The quantum key charging system based on a blockchain according to claim 1, characterized in that, The first ciphertext block also includes one or more of quantum key management terminal information, the quantum key application device information, and the opposite quantum key application device information to be established for communication, and the start and end time of key output. 9.A quantum key management terminal connected with a distributed storage system based on a blockchain, characterized in that, is configured to include: A key request acquisition module for receiving quantum key request information of a quantum key application device; A quantum key output module for outputting quantum keys to the quantum key application device according to the quantum key request information; A charging information generation module for generating corresponding charging information according to the data of the current quantum key, the charging information including the quantum key amount output this time; the data structure of the charging information is: including a message header and a message body, the message body including a first ciphertext block and a second ciphertext block, the first ciphertext block including a quantum key amount and being encrypted with a public key of a quantum service support system, for the quantum service support system to acquire charging information from a distributed storage system, and then to decrypt the first ciphertext block with a private key to obtain the quantum key amount; the second ciphertext block has the same content as the first ciphertext block and is encrypted with part of the key at a specified position in the quantum key, for the quantum key application device to acquire corresponding charging information of the quantum key application device from the distributed storage system, and then to decrypt the second ciphertext block with part of the key at the specified position in the corresponding quantum key; A charging information upload module for uploading the charging information to the distributed storage system. 10.The quantum key management terminal according to claim 9, characterized in that, The quantum key management terminal is provided with a private key, and a corresponding public key is uploaded to the distributed storage system; The charging information also includes a charging information signature obtained by signing with the private key, for verification by the distributed storage system. 11.The quantum key management terminal according to claim 9, characterized in that, The charging information also includes a service number identifying the current charging behavior, and is sent to the quantum key application device, for the quantum key application device to search for corresponding charging information from the distributed storage system. 12.The quantum key management terminal according to claim 9, characterized in that, The charging information also includes one or more of quantum key management terminal information, the quantum key application device information, and the opposite quantum key application device information to be established for communication, and the start and end time of key output. 13.The quantum key management terminal of claim 9, wherein the quantum key management terminal is provided with a private key, and the corresponding public key is uploaded to the distributed storage system. The message header includes a charging information signature signed by the private key, and is used for verification by the distributed storage system. 14.The quantum key management terminal of claim 13, wherein the message header further includes a service number identifying the current charging behavior, and is sent to the quantum key application device, and is used for the quantum key application device to search for the corresponding charging information from the distributed storage system. 15.The quantum key management terminal of claim 9, wherein the message header and the first ciphertext block further include a key check value, which is used for the quantum service support system to obtain the charging information and decrypt it, and then compare the key check value in the message header and the first ciphertext block, and if they are the same, the verification is passed. 16.The quantum key management terminal of claim 9, wherein the first ciphertext block further includes one or more of quantum key management terminal information, the quantum key application device information, and the opposite quantum key application device information to be established for communication, and the start and end time of the key output. The quantum key management terminal is provided with a private key, and the corresponding public key is uploaded to the distributed storage system; and the distributed storage system is configured to include: A data verification module is configured to receive charging information sent by the quantum key management terminal, wherein the charging information includes a charging information signature signed by the private key of the quantum key management terminal; the charging information signature is verified by the public key, and if the verification is passed, a storage operation is performed on the charging information. A data query module is configured to receive a charging information query request from the quantum key application device or the quantum service support system, and return the charging information; the data structure of the charging information includes a message header and a message body, the message body includes a first ciphertext block and a second ciphertext block, the first ciphertext block includes a quantum key amount and is encrypted by the public key of the quantum service support system, and is used for the quantum service support system to obtain the charging information from the distributed storage system, and then decrypt the first ciphertext block by the private key to obtain the quantum key amount; the second ciphertext block has the same content as the first ciphertext block, and is encrypted by part of the key at a specified position in the quantum key, and is used for the quantum key application device to obtain the corresponding charging information from the distributed storage system, and then decrypt the second ciphertext block by part of the key at the specified position in the corresponding quantum key; wherein the quantum key is output to the quantum key application device after the quantum key management terminal receives the quantum key request information from the quantum key application device. 18.The distributed storage system based on a block chain of claim 17, wherein the charging information includes a service number identifying the current charging behavior; and the query request includes the service number.

17. A blockchain-based distributed storage system, connected with a quantum key management terminal, a quantum service support system and a quantum key application device respectively, characterized in that, 19.The distributed storage system based on a block chain of claim 17, wherein the message header includes the service number. ​ ​ ​ ​ ​ ​ 20.A quantum key application device connected with a blockchain-based distributed storage system, characterized in that, The distributed storage system is configured to receive and store the charging information sent by the quantum key management terminal, wherein the data structure of the charging information comprises a message header and a message body, the message body comprises a first ciphertext block and a second ciphertext block, the first ciphertext block comprises quantum key quantity and is encrypted by the public key of the quantum service support system, and the quantum service support system decrypts the first ciphertext block by using the private key to obtain the quantum key quantity after obtaining the charging information from the distributed storage system; the second ciphertext block has the same content as the first ciphertext block and is encrypted by part of the keys in the quantum key at a set position. The quantum key application device is configured to comprise: a quantum key request module configured to send quantum key request information to the quantum key management terminal; a quantum key receiving module configured to obtain the output quantum key and the corresponding service number; a charging information query module configured to send a charging information query request to the distributed storage system, wherein the query request comprises the service number, and obtain the charging information obtained by the query and decrypt the second ciphertext block by using part of the keys in the corresponding quantum key at a set position.

21. The quantum key application device of claim 20, wherein the message header comprises the service number. 22.A quantum business support system connected with a blockchain-based distributed storage system, characterized in that, The distributed storage system is configured to receive and store the charging information sent by the quantum key management terminal, wherein the data structure of the charging information comprises a message header and a message body, the message body comprises a first ciphertext block and a second ciphertext block, the first ciphertext block comprises quantum key quantity and is encrypted by the public key of the quantum service support system; the second ciphertext block has the same content as the first ciphertext block and is encrypted by part of the keys in the quantum key at a set position, and the quantum key application device decrypts the second ciphertext block by using part of the keys in the corresponding quantum key at a set position after obtaining the corresponding charging information of the quantum key application device from the distributed storage system; wherein the quantum key is output to the quantum key application device by the quantum key management terminal after receiving the quantum key request information of the quantum key application device; The quantum service support system is configured to comprise: an application device service state management module configured to obtain the charging information of each quantum key application device from the distributed storage system, decrypt the first ciphertext block by using the private key to obtain the quantum key quantity, and determine whether to update the service state of the quantum key application device according to the quantum key quantity, the subscribed package and the user balance in the charging information.

23. The quantum service support system of claim 22, wherein the message header and the first ciphertext block each further comprise a key check value; after obtaining and decrypting the charging information, the application device service state management module first compares the key check values in the message header and the first ciphertext block, and if they are the same, the verification is passed.

Citation Information

Patent Citations

  • Quantum network-based key charging method and quantum network-based key charging system

    CN111385086A

  • Charging pile transaction management method and system based on APP

    CN113506119A