Secure communication method, key distribution center, device, medium, and product
By using QKD nodes to share quantum keys as session keys in a quantum key distribution network, the problem of poor session key security in key distribution centers is solved, enabling secure communication between highly secure terminal devices and servers based on quantum technology.
Patent Information
- Application Number
- CN202410245342.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-04
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2044-03-04
AI Technical Summary
In existing technologies, session keys generated by key distribution centers have poor security.
By sharing quantum keys as session keys among QKD nodes in a quantum key distribution network, and utilizing the true randomness of quantum technology, secure communication between terminal devices and servers can be achieved.
It improves the security of the secure connection between mobile terminals and servers, ensuring the confidentiality and unbreakability of communication.
Smart Images

Figure CN118827017B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communications, and in particular to a secure communication method, a server, a key distribution center, a terminal device, a key update terminal device, a first quantum key distribution node, a computer readable storage medium, and a computer program product. BACKGROUND
[0002] Currently, two parties participating in communication encrypt communication data through a session key, so as to ensure the security of network communication. In related technologies, a key distribution center (KDC) generates a session key, and transmits the session key to each communication party through a secure channel established by a long-term key shared by the KDC and each communication party.
[0003] However, the above-mentioned session key acquisition scheme at least has the problem of poor security. SUMMARY
[0004] Embodiments of the present application provide a secure communication method, a server, a key distribution center, a terminal device, a key update terminal device, a first quantum key distribution node, a computer readable storage medium, and a computer program product, and provide a scheme for supporting distribution of keys in a QKDN to communication parties in an application layer.
[0005] In a first aspect, the present application provides a secure communication method, applied to a server, comprising:
[0006] receiving session information sent by a key distribution center through a first secure channel; wherein the session information comprises an identifier of a first quantum key distribution node connected to the server, an identifier of a second quantum key distribution node connected to a key update terminal device, an identifier of the terminal device, and an identifier of the server; and the key update terminal device imports an authentication encryption key for the terminal device;
[0007] sending a key request message to the first quantum key distribution node; wherein the key request message is used to acquire a key between the first quantum key distribution node and the second quantum key distribution node; and the key request message comprises the identifier of the first quantum key distribution node and the identifier of the second quantum key distribution node;
[0008] receiving a session key sent by the first quantum key distribution node;
[0009] sending the session key to the terminal device through the key distribution center; wherein the session key is used for secure communication between the server and the terminal device.
[0010] In a second aspect, the embodiments of the present application provide a secure communication method, applied to a key distribution center, comprising:
[0011] receiving a session key request message sent by a terminal device; wherein the session key request message is used to request to obtain a session key; the session key request message comprises an identity of an authentication encryption key, an identity of the terminal device, an identity of a server, a third verification code and a third random number generated by the terminal device; the third verification code is a verification code generated by using a message verification code algorithm based on the identity of the terminal device, the identity of the server, the third random number and the identity of the authentication encryption key;
[0012] determining a key between a second quantum key distribution node connected with a key update terminal device and a first quantum key distribution node connected with the server based on the session key request message; wherein the key update terminal device is used to import the authentication encryption key into the terminal device;
[0013] sending session information to the server through a first secure channel; wherein the session information comprises the identity of the first quantum key distribution node, the identity of the second quantum key distribution node, the identity of the terminal device and the identity of the server;
[0014] receiving the session key and a first random number sent by the server through the first secure channel;
[0015] sending the session key to the terminal device; wherein the session key is used for the server to perform secure communication with the terminal device.
[0016] In a third aspect, the embodiments of the present application provide a secure communication method, applied to a terminal device, comprising:
[0017] sending a session key request message to a key distribution center; wherein the session key request message is used to request to obtain a session key; the session key request message comprises an identity of an authentication encryption key, an identity of the terminal device, an identity of a server, a third verification code and a third random number generated by the terminal device; wherein the third verification code is a verification code generated by using a message verification code algorithm based on the identity of the terminal device, the identity of the server, the third random number and the identity of the authentication encryption key;
[0018] receiving a session key sent by the key distribution center; wherein the session key is used for the server to perform secure communication with the terminal device; the session key is a key between a first quantum key distribution node connected with the server and a second quantum key distribution node connected with a key update terminal device.
[0019] In a fourth aspect, the embodiments of the present application provide a secure communication method, applied to a key update terminal device, comprising:
[0020] receiving a key request sent by a terminal device; wherein the key request is used to request to obtain a one-time key connected to a key distribution node;
[0021] receiving a key file sent by a second quantum key distribution node; wherein the key file comprises one or more keys and metadata corresponding to each key;
[0022] binding the terminal and the key metadata corresponding to the key; wherein the key metadata comprises a key identifier, a source identifier and a destination identifier; the source identifier is an identifier corresponding to the binding between the key update terminal device and the second quantum key distribution node; and the destination identifier is an identifier corresponding to the binding between the key distribution center and the third quantum key distribution node;
[0023] sending the key file to the terminal device.
[0024] In a fifth aspect, the embodiments of the present application provide a secure communication method, applied to a first quantum key distribution node, comprising:
[0025] receiving a key request message sent by a server; wherein the key request message is used to obtain a key between the first quantum key distribution node and a second quantum key distribution node connected to a key update terminal device; and the key request message comprises an identifier of the first quantum key distribution node and an identifier of the second quantum key distribution node;
[0026] performing a key generation process between the first quantum key distribution node and the second quantum key distribution node to obtain a session key;
[0027] sending the session key to the server; wherein the session key is used for the server to perform secure communication with a terminal device.
[0028] In a sixth aspect, the embodiments of the present application provide a server, comprising:
[0029] a first receiving module, configured to receive session information sent by a key distribution center through a first secure channel; wherein the session information comprises an identifier of a first quantum key distribution node connected to the server, an identifier of a second quantum key distribution node connected to a key update terminal device, an identifier of the terminal device and an identifier of the server; and the key update terminal device is used to input an authentication encryption key for the terminal device;
[0030] The first sending module is configured to send a key request message to the first quantum key distribution node; wherein the key request message is used to obtain a key between the first quantum key distribution node and the second quantum key distribution node; and the key request message comprises an identifier of the first quantum key distribution node and an identifier of the second quantum key distribution node.
[0031] The first receiving module is configured to receive a session key sent by the first quantum key distribution node.
[0032] The first sending module is configured to send the session key to the terminal device through the key distribution center; wherein the session key is used for secure communication between the server and the terminal device.
[0033] In a seventh aspect, an embodiment of the present application provides a key distribution center, which comprises:
[0034] The second receiving module is configured to receive a session key request message sent by a terminal device; wherein the session key request message is used to request to obtain a session key; and the session key request message comprises an identifier of an authentication encryption key, an identifier of the terminal device, an identifier of the server, a third verification code, and a third random number generated by the terminal device; the third verification code is a verification code generated by using a message verification code algorithm on the basis of the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key.
[0035] The second processing module is configured to determine, on the basis of the session key request message, to obtain a key between a second quantum key distribution node connected with a key update terminal device and a first quantum key distribution node connected with a server; wherein the key update terminal device is used to input an authentication encryption key into the terminal device.
[0036] The second sending module is configured to send session information to the server through a first secure channel; wherein the session information comprises an identifier of the first quantum key distribution node, an identifier of the second quantum key distribution node, an identifier of the terminal device, and an identifier of the server.
[0037] The second receiving module is configured to receive the session key and a first random number sent by the server through the first secure channel.
[0038] The second sending module is configured to send the session key to the terminal device; wherein the session key is used for secure communication between the server and the terminal device.
[0039] In an eighth aspect, an embodiment of the present application provides a terminal device, which comprises:
[0040] The third sending module is configured to send a session key request message to the key distribution center; wherein the session key request message is used to request to obtain a session key; the session key request message comprises an identifier of the authentication encryption key, an identifier of the terminal device, an identifier of the server, a third verification code, and a third random number generated by the terminal device; wherein the third verification code is a verification code generated by using a message verification code algorithm based on the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key;
[0041] The third receiving module is configured to receive a session key sent by the key distribution center; wherein the session key is used for secret communication between the server and the terminal device; and the session key is a key between a first quantum key distribution node connected with the server and a second quantum key distribution node connected with the key update terminal device.
[0042] In a ninth aspect, an embodiment of the present application provides a key update terminal device, which comprises:
[0043] The fourth receiving module is configured to receive a key request sent by a terminal device; wherein the key request is used to request to obtain a one-time key connected with a key distribution node;
[0044] The fourth receiving module is configured to receive a key file sent by the second quantum key distribution node; wherein the key file comprises one or more keys and metadata corresponding to each key.
[0045] The fourth processing module is configured to bind the terminal with the key metadata corresponding to the key; wherein the key metadata comprises a key identifier, a source identifier, and a destination identifier; the source identifier is an identifier corresponding to the binding between the key update terminal device and the second quantum key distribution node; and the destination identifier is an identifier corresponding to the binding between the key distribution center and the third quantum key distribution node.
[0046] The fourth sending module is configured to send the key file to the terminal device.
[0047] In a tenth aspect, an embodiment of the present application provides a first quantum key distribution node, which comprises:
[0048] The fifth receiving module is configured to receive a key request message sent by a server; wherein the key request message is used to obtain a key between the first quantum key distribution node and a second quantum key distribution node connected with a key update terminal device; and the key request message comprises an identifier of the first quantum key distribution node and an identifier of the second quantum key distribution node.
[0049] The fifth processing module is configured to perform a key generation process between the first quantum key distribution node and the second quantum key distribution node, and obtain a session key.
[0050] The fifth sending module is configured to send the session key to a server, where the session key is used for the server to perform secure communication with a terminal device.
[0051] In a eleventh aspect, an embodiment of the present application provides a key distribution center, the key distribution center comprising:
[0052] The first memory is configured to store executable instructions.
[0053] The first processor is configured to execute the executable instructions stored in the first memory, and implement the secure communication method.
[0054] In a twelfth aspect, an embodiment of the present application provides a terminal device, the terminal device comprising:
[0055] The second memory is configured to store executable instructions.
[0056] The second processor is configured to execute the executable instructions stored in the second memory, and implement the secure communication method.
[0057] In a thirteenth aspect, an embodiment of the present application provides a server, the server comprising:
[0058] The third memory is configured to store executable instructions.
[0059] The third processor is configured to execute the executable instructions stored in the third memory, and implement the secure communication method.
[0060] In a fourteenth aspect, an embodiment of the present application provides a key update terminal device, the key update terminal device comprising:
[0061] The fourth memory is configured to store executable instructions.
[0062] The fourth processor is configured to execute the executable instructions stored in the fourth memory, and implement the secure communication method.
[0063] In a fifteenth aspect, an embodiment of the present application provides a first quantum key distribution node, the first quantum key distribution node comprising:
[0064] The fifth memory is configured to store executable instructions.
[0065] The fifth processor is configured to execute the executable instructions stored in the fifth memory, and implement the secure communication method.
[0066] In a sixteenth aspect, an embodiment of the present application provides a computer readable storage medium, which stores one or more programs, and the one or more programs are executable by one or more processors to implement the secure communication method.
[0067] In a seventeenth aspect, an embodiment of the present application provides a computer program product, which comprises a computer program, and the computer program, when executed by a processor, implements the secure communication method.
[0068] The present application provides a scheme for distributing a key in a QKDN to a communication party in an application layer, using a quantum key shared between two QKD nodes as a session key, so that a mobile terminal can establish a secure connection with a server based on the session key; meanwhile, the session key is generated based on quantum technology and has the characteristics of a true random number, and the secure connection established by the mobile terminal using the key has higher security. BRIEF DESCRIPTION OF DRAWINGS
[0069] Figure 1 A schematic diagram of a secure communication system according to an embodiment of the present application;
[0070] Figure 2 A schematic diagram of a KDC according to an embodiment of the present application;
[0071] Figure 3 A schematic diagram of a QKDN according to an embodiment of the present application;
[0072] Figure 4 A flowchart of a secure communication method according to an embodiment of the present application Figure 1 ;
[0073] Figure 5 A flowchart of a secure communication method according to an embodiment of the present application Figure 2 ;
[0074] Figure 6 A flowchart of a secure communication method according to an embodiment of the present application Figure 3 ;
[0075] Figure 7 A flowchart of a secure communication method according to an embodiment of the present application Figure 4 ;
[0076] Figure 8 A schematic block diagram of a server according to an embodiment of the present application;
[0077] Figure 9 A schematic block diagram of a key distribution center according to an embodiment of the present application;
[0078] Figure 10A schematic block diagram of a terminal device provided for an embodiment of the present application;
[0079] Figure 11 A schematic block diagram of a key update terminal device provided for an embodiment of the present application;
[0080] Figure 12 A schematic block diagram of a first quantum key distribution node provided for an embodiment of the present application;
[0081] Figure 13 A schematic structural diagram of a communication device provided for an embodiment of the present application. DETAILED DESCRIPTION
[0082] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.
[0083] Figure 1 A schematic diagram of a secure communication system provided for an embodiment of the present application.
[0084] As shown in Figure 1 , the system architecture of the secure communication system is a two-layer architecture. The upper layer is a service layer, which is composed of a KDC, a key update terminal device, a server and a terminal device. The lower layer is a quantum key distribution network (QKDN) layer, which includes a plurality of quantum key distribution (QKD) nodes, and generates and provides keys for the service layer.
[0085] Among them, Figure 1 The KDC in the above is a facility for managing keys. The functions of the KDC at least include key generation, entity identity authentication, key distribution and key life cycle management. For example, the KDC such as Kerberos is composed of an authentication server (AS) and a ticket granting server (TGS). Kerberos, as a trusted third party, supports secure identity authentication of users on a target server over an unprotected network. Kerberos can also establish an encryption key between the client and the target server. In most cases, the KDC shares a key with each communication party. The KDC generates a temporary session key and uses the shared key to establish a secure channel to assign a session key for each communication party to communicate with other communication parties, as shown in Figure 2As shown, the KDC establishes a secure channel with user A by sharing a key with user A, and assigns a session key to user A; the KDC establishes a secure channel with user B by sharing a key with user B, and assigns a session key to user B; the KDC establishes a secure channel with user C by sharing a key with user C, and assigns a session key to user C; the KDC establishes a secure channel with User D by sharing a key with User D, and assigns a session key to User D. The operation of the KDC typically employs a symmetric cryptographic algorithm, such as a symmetric cryptographic algorithm with a key length of 256 bits, Advanced Encryption Standard (AES)-256, to resist quantum computing attacks. If the key length is 256 bits, then the KDC is a quantum-secure key distribution center.
[0086] Figure 1 The terminal device in the network device can be any terminal device connected to the network device or other terminal devices through wired or wireless connection. For example, the terminal device can be an access terminal, a user equipment (UE), a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal can be a cellular telephone, a cordless telephone, a Session Initiation Protocol (SIP) phone, an IoT device, a satellite handset, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication function, a computing device, or other processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a 5G network, or a terminal device in a future evolved network.
[0087] Figure 1 The server in the network device can provide different services for the terminal device, such as a WWW server.
[0088] Figure 1 The key update terminal device in the network device is a terminal device that can provide keys for terminal devices.
[0089] QKDN is a network for quantum key distribution based on QKD technology, mainly composed of QKD nodes. QKD uses quantum mechanics to ensure communication security, which enables both parties to generate and share a random, secure key to encrypt and decrypt messages. QKD transmits light particles or photons through optical fiber cables between the two parties. The significant advantage of QKD is its ability to resist quantum computing attacks based on its own quantum physics implementation principle, i.e., single quantum indivisibility and quantum state cloning. The no-cloning theorem of quantum states shows that it is impossible to create identical copies of unknown quantum states, which will prevent attackers from simply copying data, as they do with network traffic today. In addition, if an attacker interferes with or views the system, the system state changes, and the relevant parties know that the system has been attacked. If the distance between QKD nodes exceeds a certain range, QKD trusted relay nodes need to be deployed between QKD nodes. QKDN is logically a four-layer structure, which is quantum layer, key management layer, QKDN control layer and application layer from bottom to top, as shown in Figure 3 The QKD module of the quantum layer generates quantum keys and provides them to the key manager; the key manager of the QKD node provides quantum keys to the application in the application layer, and the key manager of the QKD trusted relay node is used for relay management of quantum keys and does not provide quantum keys to the application layer. The QKDN control layer includes a QKDN controller. In addition, a QKDN network management system needs to be deployed in QKDN to realize the management and control of the quantum layer, the key management layer, and the QKDN control layer. The application layer is managed and controlled by the corresponding application management system.
[0090] It should be noted that the QKD node can be further divided into a QKDN user node and a QKDN access node; the QKDN user node is a trusted node located on the QKD user side, responsible for obtaining keys from the QKDN and providing corresponding keys for specific cryptographic applications for secure communication. The QKDN access node is responsible for aggregating the key traffic of multiple user nodes connected to it and forwarding the key traffic to the remote QKD node through the One-Time Pad (OTP) channel based on the trusted relay scheme; that is, the QKDN user node can only obtain the shared quantum key between it and other QKD nodes in the network; while the QKDN access node can obtain the shared quantum key between any two QKD nodes in the QKDN.
[0091] KDC, key update terminal device, server are connected with lower QKD nodes to obtain the key of QKDN layer. The QKD user nodes connected with KDC, key update terminal device, server can only obtain the shared key between them and other QKD nodes in the network. The terminal device injects the key from QKDN (the key between QKD A node and QKD C node) in batches through the key update terminal device, and uses the key as the one-time authentication encryption key connected with KDC. The mobile terminal and KDC use the authentication encryption key to authenticate each other, and at the same time, KDC transmits the session information to the server through the secure channel. The server obtains the key between the QKD node connected with the key update terminal and the QKD node connected with the key update terminal from QKDN. The server uses the key as the session key and transmits it to KDC through the secure channel. KDC uses the authentication encryption key to encrypt the session key and transmits the encrypted session key to the mobile terminal. The mobile terminal uses the session key to securely access the server.
[0092] It should be noted that the QKD C node connected with the KDC in Figure 1 is a QKD user node; the QKD A node connected with the key update terminal device in Figure 1 is a QKD user node; and the QKD E node connected with the server in Figure 1 is a QKD user node.
[0093] It should be noted that the QKD C node connected with the KDC in Figure 1 is a QKD user node; the QKD A node connected with the key update terminal device in Figure 1 is a QKD user node; and the QKD E node connected with the server in Figure 1 is a QKD user node. Figure 1The system to which the embodiments of the present application apply is shown by way of example only, and the method shown by the embodiments of the present application can also be applied to other systems. In addition, the terms "system" and "network" are often used interchangeably herein. The term "and / or" herein is only used to describe the associated relationship of associated objects, and can represent three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects. It should also be understood that the "indication" mentioned in the embodiments of the present application can be direct indication or indirect indication, and can also represent an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship. It should also be understood that the "corresponding" mentioned in the embodiments of the present application can represent a direct corresponding or indirect corresponding relationship between the two, or can represent an associated relationship between the two, or can mean an indication and being indicated, configuration and being configured, and the like. It should also be understood that the "predefined" or "predefined rule" mentioned in the embodiments of the present application can be realized by pre-saving corresponding codes, tables or other means for indicating related information in devices (for example, including terminal devices and network devices), and the specific implementation manner of the present application is not limited. For example, the predefinition can mean the definition in the protocol. It should also be understood that the "protocol" in the embodiments of the present application can mean a standard protocol in the communication field, for example, can include the LTE protocol, the NR protocol and the related protocol applied to the future communication system, and the present application is not limited thereto.
[0094] In order to facilitate the understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described below, and the following related technologies can be combined with the technical solutions of the embodiments of the present application in any way, which all belong to the protection scope of the embodiments of the present application.
[0095] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0096] Figure 4 A flowchart of a secure communication method provided by the embodiments of the present application is shown in FIG. 4, and the method is applied to the secure communication system shown in FIG. 1. The method comprises the following steps. Figure 4 As shown in FIG. 4, the method is applied to the secure communication system shown in FIG. 1, and the method comprises the following steps. Figure 1
[0097] Step 401: The terminal device sends a session key request message to the key distribution center.
[0098] The session key request message is used to request a session key; the session key is used for secure communication between the server and the terminal device; the session key request message comprises an identifier of the authentication encryption key, an identifier of the terminal device, an identifier of the server, a third verification code and a third random number generated by the terminal device; the third verification code is generated by using a message verification code algorithm based on the authentication encryption key, the identifier of the terminal device, the identifier of the server, the third random number and the identifier of the authentication encryption key.
[0099] In the embodiments of the present application, the terminal device can send the session key request message to the key distribution center through an existing wireless channel, so as to better be compatible with the existing system and reduce the cost of system reconstruction.
[0100] The random number of the present application can be a quantum random number generated by a quantum random number generator, or can be a common random number, which is used to prevent replay attacks.
[0101] In the embodiments of the present application, the identifier of the terminal device comprises, but is not limited to, a Mobile Station international Integrated Services Digital Network number (MSISDN), an International Mobile Subscriber Identity (IMSI), an International Mobile Equipment Identity (IMEI), a service identifier (such as a domain name of the terminal, etc.), a service number of an application of the user (such as a user identifier of a chat software, a communication software or other software installed on the terminal, etc.).
[0102] In the embodiments of the present application, the identifier of the server comprises an Internet Protocol (IP) address and a Medium Access Control (MAC) address of the server.
[0103] In the embodiments of the present application, each authentication encryption key has a unique identifier; in some embodiments, the identifier comprises a color identifier, a graphic identifier, a character identifier, a number identifier, a position identifier, etc.
[0104] It should be noted that the key distribution center can also be referred to as a (quantum) cryptographic security service center, a (quantum) cryptographic service center, a (quantum) security service center, a (quantum) security center, etc.
[0105] In the embodiments of the present application, the authentication encryption key can be a quantum key or a common key generated by a pseudo-random number generator / physical noise source generator. If the authentication encryption key is a quantum key, the quantum key can be generated by a quantum random number generator or can be generated by negotiation of at least a QKD node in the QKDN, and then provided to the terminal device by the key update terminal device.
[0106] In the embodiments of the present application, the message authentication code algorithm includes but is not limited to a keyed hashed message authentication code (HMAC) function, an MD5 Message-Digest Algorithm (MD5), a Secure Hash Algorithm 1 (SHA1), a Cyclic Redundancy Check (CRC), a Data Encryption Standard (DES), and an Advanced Encryption Standard (AES).
[0107] It should be noted that the secure communication includes but is not limited to encrypted calls, encrypted short messages, encrypted instant messages, encrypted audio and video conferences, encrypted 5th Generation Mobile Communication Technology (5G) messages (for example, Rich Communication Services (RCS) messages), encrypted intercom messages, encrypted emails, etc.
[0108] Step 402, the key distribution center receives the session key request message, and determines to obtain the key between the second quantum key distribution node connected with the key update terminal device and the first quantum key distribution node connected with the server based on the session key request message.
[0109] The key update terminal device is configured to input the authentication encryption key into the terminal device.
[0110] In the embodiments of the present application, the key distribution center receives the session key request message sent by the terminal device through a wireless channel; the key distribution center needs to determine to obtain the shared quantum key between the first quantum key distribution node and the second quantum key distribution node according to the content included in the session key request message.
[0111] Exemplarily, the first quantum key distribution node and the second quantum key distribution node are both QKDN user nodes.
[0112] Step 403, the key distribution center sends session information to the server through the first secure channel.
[0113] The session information includes an identifier of the first quantum key distribution node, an identifier of the second quantum key distribution node, an identifier of the terminal device, and an identifier of the server.
[0114] It should be noted that each quantum key distribution node has a unique identifier.
[0115] Step 404, the server receives the session information through the first secure channel.
[0116] Step 405, the server sends a key request message to the first quantum key distribution node.
[0117] The key request message is used to obtain a key between the first quantum key distribution node and the second quantum key distribution node, and the key request message includes an identifier of the first quantum key distribution node and an identifier of the second quantum key distribution node.
[0118] Step 406, the first quantum key distribution node receives the key request message, performs a key generation process between the first quantum key distribution node and the second quantum key distribution node, and obtains a session key.
[0119] In the embodiment of the application, the first quantum key distribution node and the second quantum key distribution node negotiate a key to obtain a negotiated quantum key. In the embodiment of the application, the first quantum key distribution node feeds back the negotiated quantum key to the server as a session key.
[0120] Step 407, the first quantum key distribution node sends the session key to the server.
[0121] In some embodiments, the first quantum key distribution node sends the session key and metadata corresponding to the session key to the server.
[0122] In the embodiment of the application, each key has corresponding key metadata, and the format of the key metadata is shown in Table 1:
[0123]
[0124]
[0125] Table 1
[0126] It should be noted that the KeyID can be a unique identifier of a quantum key shared between two QKD nodes. The key length can be 128 bits or 256 bits; the key providing time can be a time point at which the QKD node provides the key to the service layer; the source identifier can be an identifier of a QKD A node to which the key update terminal device is connected and a name of the key update terminal device; and the destination identifier can be an identifier of a QKD C node to which the KDC is connected and a name of the KDC.
[0127] In step 408, the server receives the session key and sends the session key to the terminal device through the key distribution center.
[0128] In the embodiments of the present application, the session key can be sent in the following ways: in-band, out-of-band, media, signaling, data, message, control plane, user plane, etc. Among them, the existing media channel can be used to send the session key, so as to better compatible with the existing system and reduce the cost of system modification. In addition, when multi-party secure communication is performed, the established media plane communication channel is a one-to-many multicast / broadcast communication channel. Thus, the session key is sent only once through the established multicast / broadcast communication channel, and other terminals or servers can receive it, thereby effectively reducing the number of message transmissions.
[0129] The embodiment of the present application provides a secure communication method, which comprises the following steps: a terminal device sends a session key request message to a key distribution center; wherein the session key request message is used for requesting to obtain a session key; the key distribution center receives the session key request message, and determines to obtain a key between a second quantum key distribution node connected with a key update terminal device and a first quantum key distribution node connected with a server based on the session key request message; wherein the key update terminal device is used for importing an authentication encryption key into the terminal device; the key distribution center sends session information to the server through a first secure channel; the server receives the session information through the first secure channel; the server sends a key request message to the first quantum key distribution node; wherein the key request message is used for obtaining a key between the first quantum key distribution node and the second quantum key distribution node; the first quantum key distribution node receives the key request message, performs a key generation process between the first quantum key distribution node and the second quantum key distribution node, and obtains the session key; the first quantum key distribution node sends the session key to the server; wherein the session key is used for the server and the terminal device to perform secure communication; and the server receives the session key and sends the session key to the terminal device through the key distribution center. That is to say, the present application provides a scheme for distributing the key in the QKDN to the communication party in the application layer, uses the quantum key shared between two QKD nodes as the session key, so that the mobile terminal can establish a secure connection with the server based on the session key; meanwhile, the session key is generated based on quantum technology and has the characteristics of a true random number, and the secure connection established by the mobile terminal using the key has higher security.
[0130] The present application introduces the KDC, and the mobile terminal can obtain the session key for communicating with a plurality of servers through the KDC only by obtaining the key for authenticating the KDC, realizes the management of the key from the QKDN based on the KDC, and provides the secure key service for a large number of users.
[0131] Figure 5 A flowchart of a secure communication method provided by the embodiment of the present application is shown in Fig. 1, the method is applied to the secure communication system shown in Fig. 1, and the method comprises the following steps. Figure 5 Figure 1
[0132] Step 501: A terminal device sends a session key request message to a key distribution center.
[0133] The session key request message is used to request a session key; the session key is used for secure communication between the server and the terminal device; the session key request message includes the identifier of the authentication encryption key, the identifier of the terminal device, the identifier of the server, a third verification code, and a third random number generated by the terminal device; the third verification code is a verification code generated using a message verification code algorithm based on the identifier of the authentication encryption key, the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key.
[0134] Step 502: The key distribution center receives the session key request message, determines the authentication encryption key based on the identifier of the authentication encryption key, and verifies the third verification code based on the authentication encryption key.
[0135] In this embodiment, based on the identifier of the authentication encryption key, the system searches the key files stored in the key distribution center to see if the authentication encryption key is stored. If it is not stored, the process terminates. If it is stored, step 503 is executed.
[0136] In this embodiment, after receiving the session key request message, the key distribution center uses a message verification code algorithm to generate a first reference verification code based on the authentication encryption key in the session key request message, the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key in the session key request message. Then, it compares the first reference verification code with the third verification code. If the first reference verification code and the third verification code are the same, it is determined that the first verification code has been verified and that the session key request message was sent by the terminal device. If the first reference verification code and the third verification code are not completely the same, it indicates that the first verification code has failed to verify, and a prompt message is returned to the terminal device, or the process is terminated.
[0137] It should be noted that the message verification code algorithm used by the key distribution center to generate the first reference verification code is the same as the message verification code algorithm used by the terminal device to generate the third verification code. Here, the key distribution center can obtain relevant information about the message verification code algorithm used by the terminal device from the session key request message, or the key distribution center and the terminal device can negotiate a message verification code algorithm in advance; this application does not make specific limitations in this regard.
[0138] Step 503: If the verification is successful, the key distribution center determines that the session key request message was sent by the terminal device; based on the identifier of the terminal device and the identifier of the authentication encryption key, it determines that the source node corresponding to the session key is the second quantum key distribution node; based on the identifier of the server, it determines that the destination node corresponding to the session key is the first quantum key distribution node.
[0139] In this embodiment of the application, if the verification fails, the process is terminated.
[0140] In the embodiments of the present application, the key distribution center determines the identity of the key update terminal device that provides the authentication encryption key for the terminal device based on the identity of the terminal device and the identity of the authentication encryption key, and determines the identity of the second quantum key distribution node connected with the key update terminal device based on the identity of the key update terminal device. The key distribution center can determine the identity of the first quantum key distribution node connected with the server based on the identity of the server.
[0141] It should be noted that the key distribution center determines the destination node corresponding to the session key as the second quantum key distribution node based on the identity of the terminal device and the identity of the authentication encryption key, and determines the source node corresponding to the session key as the first quantum key distribution node based on the identity of the server.
[0142] In step 504, the key distribution center sends session information to the server through the first secure channel.
[0143] In the session information, the identity of the first quantum key distribution node connected with the server, the identity of the second quantum key distribution node connected with the key update terminal device, the identity of the terminal device, and the identity of the server are included. The key update terminal device imports the authentication encryption key for the terminal device.
[0144] In step 505, the server receives the session information through the first secure channel.
[0145] In step 506, the server sends a key request message to the first quantum key distribution node.
[0146] In the key request message, the identity of the first quantum key distribution node and the identity of the second quantum key distribution node are included, and the key request message is used to obtain the key shared between the first quantum key distribution node and the second quantum key distribution node.
[0147] In some embodiments, based on the identity of the first quantum key distribution node and the identity of the second quantum key distribution node in the session information, the server determines that the quantum key shared between the first quantum key distribution node and the second quantum key distribution node needs to be obtained, uses the shared quantum key as the session key of the terminal device and the server, and provides the shared quantum key to the terminal device through the key distribution center.
[0148] In step 507, the first quantum key distribution node receives the key request message, performs a key generation process between the first quantum key distribution node and the second quantum key distribution node, and obtains the session key.
[0149] In step 508, the first quantum key distribution node sends the session key to the server.
[0150] Step 509, the server receives the session key and generates a first random number.
[0151] It should be noted that the server receives the session key, and performs secret communication with the terminal device based on the session key.
[0152] Here, the first random number can be bound with the session key; the first random number is used to prevent replay attacks and determine the corresponding session key.
[0153] Step 510, the server sends the session key and the first random number to the key distribution center through the first secure channel.
[0154] Step 511, the key distribution center receives the session key and the first random number through the first secure channel.
[0155] Step 512, the key distribution center encrypts the session key based on the authentication encryption key to obtain an encrypted session key.
[0156] Step 513, the key distribution center sends a session key request response message to the terminal device.
[0157] The session key request response message includes the identifier of the terminal device, the identifier of the key distribution center, the third random number, the first random number, the encrypted session key, and the fourth verification code; the fourth verification code is a verification code generated by using a message verification code algorithm on the identifier of the terminal device, the identifier of the key distribution center, the third random number, the first random number, and the encrypted session key based on the authentication encryption key.
[0158] It should be noted that the fourth verification code is a verification code generated by using a message verification code algorithm on the identifier of the terminal device, the identifier of the key distribution center, the third random number, and the first random number based on the authentication encryption key.
[0159] Further, the key distribution center deletes the authentication encryption key from the secure storage area at the same time of sending the session key request response message to the terminal device, or before sending the session key request response message to the terminal device, or after sending the session key request response message to the terminal device; it should be noted that the authentication encryption key is one-time, and the key distribution center needs to delete the authentication encryption key after use.
[0160] Step 514, the terminal device receives the session key request response message, compares the third random number in the session key request response message with the third random number generated by the terminal device, and determines whether the session key request response message is a replay message.
[0161] In the embodiment of the present application, if the third random number in the session key request response message is the same as the third random number generated by the terminal device, it is determined that the session key request response message is not a replay message; if the third random number in the session key request response message is different from the third random number generated by the terminal device, it is determined that the session key request response message is a replay message.
[0162] In step 515, if the session key request response message is not a replay message, the terminal device verifies the fourth verification code based on the authentication encryption key.
[0163] In step 516, if the verification is passed, the terminal device determines that the communication counterpart is the key distribution center, and deletes the authentication encryption key.
[0164] In the embodiment of the present application, after the terminal device receives the session key request response message, the terminal device generates a second reference verification code by using a message verification code algorithm on the terminal device identifier, the key distribution center identifier, the third random number, the first random number and the encrypted session key in the session key request response message based on the authentication encryption key in the session key request response message; then, the second reference verification code is compared with the fourth verification code; if the second reference verification code is the same as the fourth verification code, it is determined that the fourth verification code is verified, it is determined that the session key request response message is sent by the key distribution center, and the terminal device deletes the internally stored authentication encryption key; if the second reference verification code is not the same as the fourth verification code, it is determined that the second verification code is not verified, and the terminal device returns a prompt information to the key distribution center or terminates the process.
[0165] In the embodiment of the present application, after the terminal device receives the session key request response message, the terminal device generates a second reference verification code by using a message verification code algorithm on the terminal device identifier, the key distribution center identifier, the third random number and the first random number in the session key request response message based on the authentication encryption key in the session key request response message; then, the second reference verification code is compared with the fourth verification code; if the second reference verification code is the same as the fourth verification code, it is determined that the fourth verification code is verified, it is determined that the session key request response message is sent by the key distribution center, and the terminal device deletes the internally stored authentication encryption key; if the second reference verification code is not the same as the fourth verification code, it is determined that the second verification code is not verified, and the terminal device returns a prompt information to the key distribution center or terminates the process.
[0166] It should be noted that the message authentication code algorithm used by the terminal device to generate the second reference verification code is the same as the message authentication code algorithm used by the key distribution center to generate the fourth verification code. Here, the terminal device can obtain the information about the message authentication code algorithm used by the key distribution center from the session key request response message, or the key distribution center and the terminal device can pre-agree on a message authentication code algorithm. In this regard, the present application does not make a specific limitation.
[0167] Step 517, the terminal device sends a session request to the server.
[0168] The session request includes the identifier of the terminal device, the identifier of the server, the first random number, the second random number generated by the terminal device, and the first verification code. The first verification code is generated by the terminal device based on the message authentication code algorithm using the identifier of the terminal device, the identifier of the server, the first random number, and the second random number.
[0169] Step 518, the server receives the session request, compares the first random number generated by the server with the first random number in the session request, and determines whether the session request is a replay message.
[0170] In the embodiments of the present application, if the first random number in the session request is the same as the first random number generated by the server, it is determined that the session request is not a replay message. If the first random number in the session request is different from the first random number generated by the server, it is determined that the session request is a replay message.
[0171] Step 519, if the session request is not a replay message, the server obtains the session key corresponding to the first random number, and verifies the first verification code based on the session key.
[0172] It should be noted that the server first binds the second random number with the session key. After the server receives and verifies the session request, the session key bound with the second random number is directly obtained.
[0173] In the embodiments of the present application, the server generates a third reference verification code by using the message authentication code algorithm based on the session key, the identifier of the terminal device, the identifier of the server, the first random number, and the second random number in the session request. Then, the third reference verification code and the first verification code are compared. If the third reference verification code and the first verification code are the same, it means that the verification of the first verification code is passed, and the session request response message is sent to the terminal device. If the third reference verification code and the first verification code are not the same, it means that the verification of the first verification code is not passed, and the prompt information is returned to the key distribution center or the process is terminated.
[0174] It should be noted that the message authentication code algorithm used by the server to generate the third reference verification code is the same as the message authentication code algorithm used by the terminal device to generate the first verification code. Here, the server can obtain the relevant information of the message authentication code algorithm used by the terminal device from the session request, or the server and the terminal device can pre-agree on a message authentication code algorithm. The present application does not make specific limitations in this regard.
[0175] Step 520, if the verification is passed, the server sends a session response message to the terminal device.
[0176] The session response message includes the identifier of the terminal device, the identifier of the server, the second random number and the second verification code. The second verification code is generated based on the session key using the message authentication code algorithm on the identifier of the terminal device, the identifier of the server and the second random number.
[0177] Step 521, the terminal device receives the session response message sent by the server, compares the second random number generated by the terminal device with the second random number in the session response message, and determines whether the session response message is a replay message.
[0178] In the present application, if the second random number in the session response message is the same as the second random number generated by the terminal device, it is determined that the session response message is not a replay message. If the second random number in the session response message is different from the second random number generated by the terminal device, it is determined that the session response message is a replay message.
[0179] Step 522, if the session response message is not a replay message, the terminal device verifies the second verification code based on the session key, and if the verification is passed, the terminal device performs secret communication with the server based on the session key.
[0180] In the present application, the terminal device generates a fourth reference verification code based on the session key using the message authentication code algorithm on the identifier of the terminal device, the identifier of the server and the second random number in the session request response message based on the session key. Then, the fourth reference verification code and the second verification code are compared. If the fourth reference verification code and the second verification code are the same, it means that the verification of the second verification code is passed, and the terminal device performs secret communication with the server based on the session key. If the fourth reference verification code and the second verification code are not exactly the same, it means that the verification of the second verification code is not passed, and the process is terminated.
[0181] It should be noted that the message authentication code algorithm used by the terminal device to generate the fourth reference verification code is the same as the message authentication code algorithm used by the server to generate the second verification code. Here, the terminal device can obtain the relevant information of the message authentication code algorithm used by the server from the session response message, or the server and the terminal device can pre-agree on a message authentication code algorithm. The present application does not make specific limitations in this regard.
[0182] It should be noted that the same steps and the same content in other embodiments are described with reference to the description of other embodiments, and will not be described here.
[0183] In some embodiments, as shown in Figure 6 The method provided by the embodiment of the application includes the following contents:
[0184] Step A1, the terminal device sends a key request to the key update terminal device.
[0185] The key request is used to request to obtain a one-time key connected to the key distribution center.
[0186] Step A2, the key update terminal device receives the key request and sends the key request to a second quantum key distribution node, for example, QKD A.
[0187] Step A3, QKD A performs QKD key negotiation with a third quantum key distribution node, for example, QKD C.
[0188] The QKD C is a quantum key distribution node connected to the KDC; and the QKD A is a quantum key distribution node connected to the key update terminal device.
[0189] Step A4, the QKD C sends a key file to the KDC; and the QKD A sends the key file to the key update terminal device.
[0190] The key file includes one or more keys and metadata corresponding to each key.
[0191] Further, the key update terminal device receives the key file sent by the second quantum key distribution node, that is, QKD A; and the key distribution center receives the key file sent by the third quantum key distribution node, that is, QKD C.
[0192] Step A5, the key update terminal device binds the terminal, for example, the identity of the user on the terminal, with the key metadata corresponding to the key.
[0193] The key metadata includes a key identity, a source identity and a destination identity; the source identity is an identity corresponding to the binding between the key update terminal device and the second quantum key distribution node; and the destination identity is an identity corresponding to the binding between the key distribution center and the third quantum key distribution node.
[0194] Step A6, the key update terminal device sends the key file to the terminal device; and further, the terminal device receives the key file.
[0195] Step A7, the key distribution center receives the mapping information between the terminal and the key metadata corresponding to the key sent by the key update terminal device through the second secure channel.
[0196] The key metadata includes a key identifier, a source identifier, and a destination identifier; the source identifier is an identifier corresponding to the binding of the key update terminal device and the second quantum key distribution node; and the destination identifier is an identifier corresponding to the binding of the key distribution center and the third quantum key distribution node.
[0197] It should be noted that after the key distribution center receives the mapping information, the terminal is bound based on the mapping information, for example, the identifier of the user on the terminal and the key metadata corresponding to the key.
[0198] Step A8, the key distribution center updates the key file based on the mapping information.
[0199] For example, a mobile user goes to the business hall of an operator and applies for batch injection of keys from a QKDN on a key update terminal device. The key update terminal device initiates a key application request to a connected QKD A node. The QKD A node starts a QKD key negotiation process with a connected QKD C node of a KDC to generate a key file containing batch keys and key metadata for key management. The key file is output to the key update terminal and the KDC respectively. The key update terminal device binds the identifier IDx of the mobile user with the key metadata and transmits it to the KDC through a long-term secure channel between the key update terminal and the KDC. The KDC finds the corresponding keys through the key metadata and binds the identifier IDx of the user with the keys and the key metadata.
[0200] For example, the mobile terminal uses an authentication encryption key to perform mutual authentication with the KDC. The KDC applies to a server for a session key. The server applies to a QKDN layer for a key between a QKD A node (connected to the key update terminal device) and a QKD E node (connected to the server Y). After obtaining the key, the server uses it as a session key and distributes it to the KDC. The KDC sends the encrypted session key to the mobile terminal, and the mobile terminal uses the session key to establish secure communication between the mobile terminal and the server. The distribution process of the session key is as shown in Figure 7
[0201] Step 701, the mobile terminal X sends a session key request message to the KDC.
[0202] For example, the mobile terminal X sends a message 1 to the KDC; the content of the message 1 includes IDx, IDy, N1x, KeyID, and MAC1.
[0203] Here, IDx is the identity of the mobile terminal X, IDy is the identity of the server Y, N1x is a random nonce generated by the mobile terminal X, KeyID is the identity of the authentication encryption key used by the mobile terminal this time, and MAC1 is a message authentication code generated based on the authentication encryption key using a message authentication code algorithm such as HMAC on IDx, IDy, N1x, and KeyID, and its calculation formula is as follows: MAC1 = HMAC(AE-key, IDx || IDy || N1x || KeyID); here, AE-key is the authentication encryption key corresponding to KeyID, and || is string concatenation.
[0204] Step 702, the KDC sends session information to the server Y.
[0205] For example, the KDC sends message 2 to the server Y; the content of message 2 includes IDx, IDy, ID QKD-A , and ID QKD-E .
[0206] Here, ID QKD-A is the identity of the QKD A node; and ID QKD-E is the identity of the QKD E node.
[0207] It should be noted that after the KDC receives message 1, the KDC searches for the corresponding authentication encryption key AE-key according to KeyID in message 1, and if no authentication encryption key AE-key is found, the process is terminated. When the authentication encryption key AE-key is found, the authentication encryption key AE-key is used to verify MAC1. If the verification is successful, it proves that message 1 has not been tampered with by an attacker, and at the same time it proves the identity of the message sender is the mobile terminal X. The KDC determines the authentication encryption key that the mobile terminal X obtains from which key update terminal device according to IDx and KeyID, and the identity of the QKD node corresponding to the key update terminal device, thereby determining that the QKD source node of the required key in the QKDN is QKD A. The KDC confirms that the QKD destination node of the required key in the QKDN is QKD E (connected to the server Y) according to IDy. In short, according to IDx, KeyID, IDy, the KDC can determine the required key Kae between QKDA node (connected to the key update terminal) and QKD E node (connected to the server Y). Further, the KDC sends session information to the server through a secure channel connected to the server.
[0208] Step 703, the server Y sends a key request message to the QKD E node.
[0209] For example, the server Y sends message 3 to the QKD E node; the content of message 3 includes ID QKD-A , and ID QKD-E .
[0210] It should be noted that after server Y receives message 2, server Y uses the ID... QKD-A ID QKD-E The system confirms the need for a key Kae between the QKDA node (connected to the key update terminal device) and the QKD E node (connected to server Y). Server Y sends a key request message to the QKD E node it is connected to.
[0211] Step 704: After receiving the key request message, the QKD E node executes the key generation process between the QKD A node and the QKD E node to obtain the key Kae.
[0212] Step 705: The QKD E node sends a key request response message to the server Y.
[0213] For example, the QKD E node sends message 5 to the server Y; the content of message 5 includes Kae.
[0214] Step 706: Server Y sends a session key and a one-time random number to KDC.
[0215] For example, server Y sends message 6 to KDC; the content of message 6 includes SE-key, Ny.
[0216] It should be noted that server Y uses the key Kae as the session key SE-key, generates a one-time random number Ny, and binds Ny to the session key SE-key. Server Y then sends the session key SE-key and the one-time random number Ny to KDC through a secure channel.
[0217] Step 707: KDC sends a session key request response message to mobile terminal X.
[0218] For example, KDC sends message 7 to mobile terminal X; the content of message 7 includes IDx, ID KDC N1x, Ny, [SE-key] AE-key , MAC2.
[0219] Here, [SE-key] AE-key This indicates the encrypted session key obtained by encrypting the session key SE-key using an encryption algorithm such as AES based on the authentication encryption key AE-key. MAC2 is based on the authentication encryption key pair IDx, ID... KDC N1x and Ny use a message verification code algorithm, such as HMAC, to generate a message verification code. The calculation formula is as follows: MAC2 = HMAC(AE-key, IDx‖ID) KDC ||N1x||Ny||[SE-key] AE-key) ; here, the encryption algorithm and the message authentication code algorithm used in step 707 are also used to implement the above functions based on the authenticated encryption key.
[0220] Further, the KDC deletes the one-time authenticated encryption key from the secure storage.
[0221] Step 708, the mobile terminal X sends a session request to the server Y.
[0222] Exemplarily, the mobile terminal X sends a message 8 to the server Y; the content of the message 8 includes IDx, IDy, N2x, Ny, MAC3.
[0223] Here, N2x is a one-time random number generated by the mobile terminal X, and MAC3 is a message authentication code generated based on the session key SE-key using a message authentication code algorithm such as HMAC on IDx, IDy, N2x, Ny, and its calculation formula is as follows: MAC3 = HMAC(SE-key, IDx‖IDy‖N2x‖Ny).
[0224] It should be noted that after receiving the message 7, the mobile terminal X compares N1x in the message 7 with N1x in the message 1, and if they are equal, it can be determined that the message 7 is not a replay message. The MAC2 is verified using the authenticated encryption key, and if the verification is successful, it proves that the communication counterpart is the KDC. The mobile terminal X deletes the one-time authenticated encryption key. The mobile terminal X generates a session request and sends it to the server Y.
[0225] Step 709, the server Y sends a session request response message to the mobile terminal X.
[0226] Exemplarily, the server Y sends a message 9 to the mobile terminal X; the content of the message 9 includes IDy, IDx, N2x, MAC4.
[0227] Here, MAC4 is a message authentication code generated based on the session key SE-key using a message authentication code algorithm such as HMAC on IDy, IDx, N2x, and its calculation formula is as follows: MAC4 = HMAC(SE-key, IDy‖IDx‖N2x).
[0228] It should be noted that after the server Y receives the message 8, the Ny in the message 8 is compared with the Ny sent in the message 6, if the same, it is confirmed that the message 8 is not replayed; and the corresponding session key SE-key is found according to the Ny. The server Y verifies the MAC3 using the SE-key, if the verification is passed, the authenticity of the mobile terminal X is proved and the session key is owned. The server Y generates a session request response message and sends it to the mobile terminal X, after the mobile terminal X receives the message 9, the N2x in the message 9 is compared with the N2x sent in the message 8, if the same, it is confirmed that the message 9 is not replayed. The mobile terminal X verifies the MAC4 using the session key SE-key, if the verification is passed, it is proved that the communication opposite is the server Y and the session key SE-key is owned.
[0229] Embodiments of the present application provide a server, which can be used to implement Figure 4 to 5 Corresponding embodiments provide a secure communication method, which refers to Figure 8 As shown in the figure, the server 800 includes:
[0230] The first receiving module 801 is configured to receive session information sent by a key distribution center through a first secure channel; wherein the session information includes an identifier of a first quantum key distribution node connected with the server, an identifier of a second quantum key distribution node connected with a key update terminal device, an identifier of the terminal device, and an identifier of the server; the key update terminal device imports an authentication encryption key for the terminal device;
[0231] The first sending module 802 is configured to send a key request message to the first quantum key distribution node; wherein the key request message is used to obtain a key between the first quantum key distribution node and the second quantum key distribution node; the key request message includes the identifier of the first quantum key distribution node and the identifier of the second quantum key distribution node;
[0232] The first receiving module 801 is configured to receive a session key sent by the first quantum key distribution node;
[0233] The first sending module 802 is configured to send the session key to the terminal device through the key distribution center; wherein the session key is used for secure communication between the server and the terminal device.
[0234] In other embodiments of the present application, the first processing module 803 is configured to perform secure communication with the terminal device based on the session key.
[0235] In other embodiments of the present application, the first sending module 802 is configured to send the session key and a first random number to the key distribution center through the first secure channel; wherein the first random number is generated by the server.
[0236] In other embodiments of the present application, the first receiving module 801 is configured to receive a session request sent by the terminal device, wherein the session request comprises the identifier of the terminal device, the identifier of the server, a first random number, a first verification code and a second random number generated by the terminal device; the first verification code is a verification code generated by using a message verification algorithm based on the session key, the identifier of the terminal device, the identifier of the server, the first random number and the second random number;
[0237] The first processing module 803 is configured to compare the first random number generated by the server with the first random number in the session request, and determine whether the session request is a replay message;
[0238] The first obtaining module 804 is configured to obtain the session key corresponding to the first random number if the session request is not a replay message.
[0239] The first processing module 803 is configured to verify the first verification code based on the session key.
[0240] The first sending module 802 is configured to send a session response message to the terminal device if the verification is passed, wherein the session response message comprises the identifier of the terminal device, the identifier of the server, the second random number and a second verification code; the second verification code is a verification code generated by using a message verification algorithm based on the session key, the identifier of the terminal device, the identifier of the server and the second random number.
[0241] The above description of the device embodiments is similar to the description of the method embodiments, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments for understanding.
[0242] It should be noted that, in the embodiments of the present application, if the above-mentioned secure communication method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application or the parts that make contributions to the related art can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a terminal device to execute all or part of the method embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk and various program code storage media. Thus, the embodiments of the present application are not limited to any specific hardware and software combination.
[0243] The embodiments of the present application provide a key distribution center, which can be used to implement Figure 4 to 5 The secure communication method provided by the corresponding embodiments is described with reference to Figure 9As shown, the key distribution center 900 includes:
[0244] The second receiving module 901 is configured to receive a session key request message sent by the terminal device; the session key request message is used to request to obtain a session key; the session key request message includes an identifier of an authentication encryption key, an identifier of the terminal device, an identifier of the server, a third verification code, and a third random number generated by the terminal device; the third verification code is a verification code generated by using a message verification code algorithm based on the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key;
[0245] The second processing module 902 is configured to determine, based on the session key request message, a key between a second quantum key distribution node connected with a key update terminal device and a first quantum key distribution node connected with the server; the key update terminal device is used to import the authentication encryption key into the terminal device.
[0246] The second sending module 903 is configured to send session information to the server through the first secure channel; the session information includes an identifier of the first quantum key distribution node, an identifier of the second quantum key distribution node, an identifier of the terminal device, and an identifier of the server.
[0247] The second receiving module 901 is configured to receive the session key and the first random number sent by the server through the first secure channel.
[0248] The second sending module 903 is configured to send the session key to the terminal device; the session key is used for the server to perform secure communication with the terminal device.
[0249] In other embodiments of the present application, the second processing module 902 is configured to determine the authentication encryption key based on the identifier of the authentication encryption key, verify the third verification code based on the authentication encryption key, determine that the session key request message is sent by the terminal device if the verification is passed, determine that the source node corresponding to the session key is the second quantum key distribution node based on the identifier of the terminal device and the identifier of the authentication encryption key, and determine that the destination node corresponding to the session key is the first quantum key distribution node based on the identifier of the server.
[0250] In other embodiments of the present application, the second processing module 902 is configured to encrypt the session key based on the authentication encryption key to obtain an encrypted session key.
[0251] The second sending module 903 is configured to send a session key request response message to the terminal device; the session key request response message comprises the identifier of the terminal device, the identifier of the key distribution center, the third random number, the first random number, the encrypted session key, and a fourth verification code; the fourth verification code is a verification code generated by using a message authentication code algorithm on the basis of the authentication encryption key, the identifier of the terminal device, the identifier of the key distribution center, the third random number, the first random number, and the encrypted session key.
[0252] In other embodiments of the present application, the second processing module 902 is configured to delete the authentication encryption key from the secure storage area.
[0253] In other embodiments of the present application, the second receiving module 901 is configured to receive a key file sent by the third quantum key distribution node; the key file comprises one or more keys and metadata corresponding to each key.
[0254] The second receiving module 901 is configured to receive, through the second secure channel, mapping information between the terminal and the key corresponding key metadata sent by the key update terminal device; the key metadata comprises a key identifier, a source identifier, and a destination identifier; the source identifier is an identifier corresponding to the binding between the key update terminal device and the second quantum key distribution node; and the destination identifier is an identifier corresponding to the binding between the key distribution center and the third quantum key distribution node.
[0255] The second processing module 902 is configured to update the key file on the basis of the mapping information.
[0256] In other embodiments of the present application, the second processing module 902 is configured to search, on the basis of the identifier of the authentication encryption key, whether the authentication encryption key is stored in the key file.
[0257] The above description of the device embodiments is similar to the description of the method embodiments, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments for understanding.
[0258] It should be noted that, in the embodiments of the present application, if the secure communication method described above is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing an end device to execute all or part of the method of each embodiment of the present application. The storage medium described above includes: a U disk, a mobile hard disk, a ROM, a magnetic disk or an optical disk, and various media that can store program codes. Thus, the embodiments of the present application are not limited to any specific hardware and software combination.
[0259] The embodiments of the present application provide a terminal device, which can be used to implement Figure 4 to 5 The secure communication method provided by the corresponding embodiments is described below with reference to Figure 10 As shown in the figure, the terminal device 1000 includes:
[0260] The third sending module 1001 is configured to send a session key request message to a key distribution center; wherein the session key request message is used to request to obtain a session key; the session key request message includes an identity of an authentication encryption key, an identity of the terminal device, an identity of the server, a third verification code and a third random number generated by the terminal device; wherein the third verification code is a verification code generated by using a message verification code algorithm based on the identity of the terminal device, the identity of the server, the third random number and the identity of the authentication encryption key.
[0261] The third receiving module 1002 is configured to receive a session key sent by the key distribution center; wherein the session key is used for the server and the terminal device to perform secure communication; the session key is a key between a first quantum key distribution node connected with the server and a second quantum key distribution node connected with the key update terminal device.
[0262] In other embodiments of the present application, the third receiving module 1002 is configured to receive a session key request response message sent by the key distribution center; wherein the session key request response message includes the identity of the terminal device, the identity of the key distribution center, the third random number, the first random number, the encrypted session key and the fourth verification code; the fourth verification code is a verification code generated by using a message verification code algorithm based on the identity of the terminal device, the identity of the key distribution center, the third random number, the first random number and the encrypted session key; the encrypted session key is obtained by encrypting the session key based on the authentication encryption key by the key distribution center.
[0263] In other embodiments of the present application, the third processing module 1003 is configured to compare the third random number in the session key request response message with the third random number generated by the terminal device, to determine whether the session key request response message is a replay message; if the session key request response message is not a replay message, to verify the fourth verification code based on the authentication encryption key; and if the verification is passed, to prove that the communication counterpart is the key distribution center, and to delete the authentication encryption key.
[0264] In other embodiments of the present application, the third sending module 1001 is configured to send a session request to a server; wherein the session request comprises the identifier of the terminal device, the identifier of the server, the first random number, the second random number generated by the terminal device, and the first verification code; and the first verification code is a verification code generated by using a message verification code algorithm based on the session key on the identifier of the terminal device, the identifier of the server, the first random number, and the second random number.
[0265] In other embodiments of the present application, the third receiving module 1002 is configured to receive a session response message sent by the server; wherein the session response message comprises the identifier of the terminal device, the identifier of the server, the second random number, and the second verification code; and the second verification code is a verification code generated by using a message verification code algorithm based on the session key on the identifier of the terminal device, the identifier of the server, and the second random number.
[0266] The third processing module 1003 is configured to compare the second random number generated by the terminal device with the second random number in the session response message, to determine whether the session response message is a replay message; and if the session response message is not a replay message, to perform secret communication with the server based on the session key.
[0267] In other embodiments of the present application, the third sending module 1001 is configured to send a key request to a key update node; wherein the key request is used to request to obtain a one-time key connected to the key distribution node.
[0268] The third receiving module 1002 is configured to receive a key file sent by the key update node; wherein the key file comprises one or more keys and metadata corresponding to each key.
[0269] The above description of the device embodiments is similar to the description of the method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments for understanding.
[0270] It should be noted that, in the embodiments of the present application, if the secure communication method described above is implemented in the form of a software function module and is sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing an end device to execute all or part of the method of each embodiment of the present application. The storage medium described above includes: a U disk, a mobile hard disk, a ROM, a magnetic disk or an optical disk, and various media that can store program codes. Thus, the embodiments of the present application are not limited to any specific hardware and software combination.
[0271] The embodiments of the present application provide a key update terminal device, which can be used to implement the secure communication method provided by the embodiments of the present application, and the key update terminal device is shown in Figure 11 The key update terminal device 1100 includes:
[0272] The fourth receiving module 1101 is configured to receive a key request sent by a terminal device; wherein the key request is used to request to obtain a one-time key for connecting a key distribution node; and receive a key file sent by a second quantum key distribution node; wherein the key file includes one or more keys and metadata corresponding to each key.
[0273] The fourth processing module 1102 is configured to bind the terminal and the key metadata corresponding to the key; wherein the key metadata includes a key identifier, a source identifier and a destination identifier; the source identifier is an identifier corresponding to the binding of the key update terminal device and the second quantum key distribution node; and the destination identifier is an identifier corresponding to the binding of the key distribution center and the third quantum key distribution node.
[0274] The fourth sending module 1103 is configured to send the key file to the terminal device.
[0275] The above device embodiments are similar to the descriptions of the above method embodiments, and have similar beneficial effects to the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0276] It should be noted that, in the embodiments of the present application, if the secure communication method described above is implemented in the form of a software function module and is sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for causing an end device to execute all or part of the method of each embodiment of the present application. The storage medium described above includes: a U disk, a mobile hard disk, a ROM, a magnetic disk or an optical disk, and various media that can store program codes. Thus, the embodiments of the present application are not limited to any specific hardware and software combination.
[0277] The embodiments of the present application provide a first quantum key distribution node, which can be used to implement Figure 4 to 5 The secure communication method provided by the corresponding embodiments is described with reference to Figure 12 The first quantum key distribution node 1200 includes:
[0278] The fifth receiving module 1201 is configured to receive a key request message sent by a server, wherein the key request message is used to obtain a key between the first quantum key distribution node and a second quantum key distribution node connected with the key update terminal device; and the key request message includes an identifier of the first quantum key distribution node and an identifier of the second quantum key distribution node.
[0279] The fifth processing module 1202 is configured to perform a key generation process between the first quantum key distribution node and the second quantum key distribution node, and obtain a session key.
[0280] The fifth sending module 1203 is configured to send the session key to the server, wherein the session key is used for the server and the terminal device to perform secure communication.
[0281] The above description of the device embodiments is similar to the description of the method embodiments described above, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0282] It should be noted that, in the embodiments of the present application, if the secure communication method described above is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to make a terminal device execute all or part of the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a ROM, a magnetic disk or an optical disk, and various media that can store program codes. Thus, the embodiments of the present application are not limited to any specific hardware and software combination.
[0283] Figure 13 FIG. 1 is a schematic structural diagram of a communication device 1300 provided by an embodiment of the present application. The communication device can be a key distribution center / terminal device / server / key update terminal device / first quantum key distribution node. Figure 13 The communication device 1300 shown in FIG. 1 includes a first processor 1310. The first processor 1310 can call and run a computer program from a memory to implement the method in the embodiments of the present application.
[0284] Optionally, as shown in FIG. 1, the communication device 1300 can further include a first memory 1320. The first processor 1310 can call and run a computer program from the first memory 1320 to implement the method in the embodiments of the present application. Figure 13
[0285] The first memory 1320 can be a separate device independent of the first processor 1310, or can be integrated in the first processor 1310.
[0286] Optionally, as shown in FIG. 1, the communication device 1300 can further include a transceiver 1330. The first processor 1310 can control the transceiver 1330 to communicate with other devices, specifically, to send information or data to other devices, or to receive information or data sent by other devices. Figure 13
[0287] The transceiver 1330 can include a transmitter and a receiver. The transceiver 1330 can further include an antenna, and the number of antennas can be one or more.
[0288] Optionally, the communication device 1300 can be a key distribution center / terminal device / server / key update terminal device / third quantum key distribution node of the embodiments of the present application, and the communication device 1300 can implement the corresponding processes in the various methods of the embodiments of the present application implemented by the key distribution center / terminal device / server / key update terminal device / first quantum key distribution node. For brevity, details are not repeated here.
[0289] In some embodiments, the embodiments of the present application also provide a computer program product comprising a computer program, which can be executed by the first processor 1310 of the communication device 1300 to complete the steps of any of the preceding methods.
[0290] It should be understood that the processor of the embodiments of the present application can be an integrated circuit chip having a processing capability of signals. In the implementation process, each step of the method embodiments described above can be completed by integrated logic circuits or instructions in the form of software in the processor. The processor described above can be a general processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can be any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, and other mature storage media in the art. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method.
[0291] As an embodiment, the processor can include one or more general central processing units (Central Processing Unit, CPU). Each of these processors can be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor here can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer execution instructions).
[0292] It is to be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example, but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced SDRAM (ESDRAM), synch link DRAM (SLDRAM) and direct Rambus RAM (DR RAM). It should be noted that the memory of the system and method described herein is intended to include, but not limited to, these and any other suitable types of memory.
[0293] It should be understood that the above-mentioned memory is exemplary but not limiting, for example, the memory in the embodiments of the present application can also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced SDRAM (ESDRAM), synch link DRAM (SLDRAM) and direct Rambus RAM (DR RAM) and the like. That is, the memory in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0294] The embodiments of the present application also provide a computer readable storage medium for storing a computer program.
[0295] Optionally, the computer readable storage medium can be applied to the key distribution center / terminal device / server / key update terminal device / first quantum key distribution node in the embodiments of the present application, and the computer program causes the computer to execute the corresponding processes implemented by the key distribution center / terminal device / server / key update terminal device / first quantum key distribution node in the various methods of the embodiments of the present application. For brevity, details are not repeated here.
[0296] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, all or part can be realized in the form of a computer program product.
[0297] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that the computer can store or be integrated into a data storage device such as a server, data center, etc. containing one or more available media. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, DVD), or semiconductor media (for example, solid state disk (SSD)) and the like.
[0298] The above describes the method for secure communication, the key distribution center, the terminal device, the server, the key update terminal device, the first quantum key distribution node, the computer readable storage medium and the computer program product provided by the embodiments of the present application in detail. The principles and implementation manners of the present application are described by applying specific examples in this paper. The above description of the embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation manner and application range will be changed; in view of the above, the content of the specification should not be understood as a limitation of the present application.
[0299] It should be understood that every feature, structure, or characteristic described in relation to one embodiment is applicable to at least one other embodiment, unless specifically noted otherwise. It should be understood that the appearance of a reference number in various embodiments of the application is merely intended to differentiate one embodiment from another, and is not intended to limit the scope of the application. It should be understood that the scope of the application is not limited by the order of execution of the steps of the methods described herein. It should be understood that the scope of the application encompasses the execution of the steps of the methods described herein in any order.
[0300] Unless specifically stated otherwise, implementing any step in the embodiments of the present application by the key distribution center / terminal device / server / key update terminal device / first quantum key distribution node can be implementing the step by the processor of the key distribution center / terminal device / server / key update terminal device / first quantum key distribution node. Unless specifically stated otherwise, the embodiments of the present application do not limit the order of implementing the steps by the key distribution center / terminal device / server / key update terminal device / first quantum key distribution node. In addition, the way of processing data in different embodiments can be the same method or different methods.
[0301] In several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other manners. The described device embodiments are merely schematic, and the division of units is merely logical function division, and there can be other division manners in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling, direct coupling, or communication connection between the components can be indirect coupling or communication connection through some interfaces, devices, or units, and can be electrical, mechanical, or in other forms.
[0302] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units; they can be located in one place, or distributed on a plurality of network units; and some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0303] In addition, each of the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be separately implemented as a unit, or two or more units can be integrated in one unit; the integrated unit can be implemented in the form of hardware or in the form of hardware plus software function unit.
[0304] The methods disclosed in the several method embodiments provided by the present application can be combined arbitrarily without conflict to obtain new method embodiments.
[0305] The features disclosed in the several product embodiments provided by the present application can be combined arbitrarily without conflict to obtain new product embodiments.
[0306] The features disclosed in the several method or device embodiments provided by the present application can be combined arbitrarily without conflict to obtain new method embodiments or device embodiments.
[0307] Those of ordinary skill in the art can understand that all or part of the steps of the above method embodiments can be completed by a program instructing related hardware, the foregoing program can be stored in a computer storage medium, and the program executes the steps including the above method embodiments when executed; and the foregoing storage medium includes mobile storage devices, ROM, magnetic discs or optical discs and various storage media that can store program codes.
[0308] Alternatively, the integrated unit of the present application, if implemented in the form of a software function module and sold or used as an independent product, can also be stored in a computer storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the embodiments of the present application. The foregoing storage medium includes mobile storage devices, ROM, magnetic discs or optical discs and various storage media that can store program codes.
[0309] The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are intended to include the plural forms, unless the context clearly indicates otherwise.
[0310] It should be noted that in each of the embodiments involved in the present application, all steps can be executed or part of the steps can be executed, as long as a complete technical solution is formed.
[0311] The above merely provides the implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of the change or replacement within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of secure communication, characterized by, The method applied to a server comprises: receiving session information sent by a key distribution center through a first secure channel; wherein the session information comprises an identifier of a first quantum key distribution node connected to the server, an identifier of a second quantum key distribution node connected to a key update terminal device, an identifier of the terminal device, and an identifier of the server; and the key update terminal device is used to import an authentication encryption key into the terminal device; sending a key request message to the first quantum key distribution node; wherein the key request message is used to obtain a key between the first quantum key distribution node and the second quantum key distribution node; and the key request message comprises the identifier of the first quantum key distribution node and the identifier of the second quantum key distribution node; receiving a session key sent by the first quantum key distribution node; sending the session key to the terminal device through the key distribution center; wherein the session key is used for secure communication between the server and the terminal device.
2. The method of claim 1, wherein, The method further comprises: performing secure communication with the terminal device based on the session key.
3. The method of claim 1, wherein, The method further comprises: sending the session key and a first random number to the key distribution center through the first secure channel; wherein the first random number is generated by the server.
4. The method of claim 3, wherein, The method further comprises: receiving a session request sent by the terminal device; wherein the session request comprises the identifier of the terminal device, the identifier of the server, the first random number, a first verification code, and a second random number generated by the terminal device; the first verification code is a verification code generated by using a message verification code algorithm based on the session key, the identifier of the terminal device, the identifier of the server, the first random number, and the second random number; comparing the first random number generated by the server with the first random number in the session request to determine whether the session request is a replay message; if the session request is not a replay message, obtaining a session key corresponding to the first random number; verifying the first verification code based on the session key; if the verification is passed, sending a session response message to the terminal device; wherein the session response message comprises the identifier of the terminal device, the identifier of the server, the second random number, and a second verification code; the second verification code is a verification code generated by using a message verification code algorithm based on the session key, the identifier of the terminal device, the identifier of the server, and the second random number.
5. A method of secure communication, characterized by The method applied to a key distribution center comprises: receiving a session key request message sent by a terminal device; wherein the session key request message is used to request to obtain a session key; the session key request message comprises an identifier of an authentication encryption key, an identifier of the terminal device, an identifier of a server, a third verification code, and a third random number generated by the terminal device; and the third verification code is a verification code generated by using a message verification code algorithm based on the authentication encryption key, the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key; sending the session key to the terminal device through the key distribution center; wherein the session key is used for secure communication between the server and the terminal device. determining, based on the session key request message, a key between a second quantum key distribution node connected with a key updating terminal device and a first quantum key distribution node connected with a server, wherein the key updating terminal device is configured to import an authentication encryption key into the terminal device; sending session information to the server through a first secure channel, wherein the session information comprises an identifier of the first quantum key distribution node, an identifier of the second quantum key distribution node, an identifier of the terminal device, and an identifier of the server; receiving the session key and a first random number sent by the server through the first secure channel; sending the session key to the terminal device, wherein the session key is used for secure communication between the server and the terminal device.
6. The method of claim 5, wherein, The method further comprises: determining, based on the session key request message, a key between a second quantum key distribution node connected with a key updating terminal device and a first quantum key distribution node connected with a server, wherein the key updating terminal device is configured to import an authentication encryption key into the terminal device; determining the authentication encryption key based on the identifier of the authentication encryption key; verifying the third verification code based on the authentication encryption key; if the verification is passed, determining that the session key request message is sent by the terminal device; determining that the source node corresponding to the session key is the second quantum key distribution node based on the identifier of the terminal device and the identifier of the authentication encryption key; 7. The method of claim 5, wherein, determining that the destination node corresponding to the session key is the first quantum key distribution node based on the identifier of the server. The method further comprises: encrypting the session key based on the authentication encryption key to obtain an encrypted session key; 8. The method of claim 7, wherein, sending a session key request response message to the terminal device, wherein the session key request response message comprises the identifier of the terminal device, the identifier of the key distribution center, the third random number, the first random number, the encrypted session key, and a fourth verification code; the fourth verification code is a verification code generated by using a message verification code algorithm based on the identifier of the terminal device, the identifier of the key distribution center, the third random number, the first random number, and the encrypted session key. The method further comprises:
9. The method of claim 5, wherein, deleting the authentication encryption key from the secure storage area. The method further comprises: receiving a key file sent by a third quantum key distribution node, wherein the key file comprises one or more keys and metadata corresponding to each key; receiving mapping information between a terminal and key corresponding key metadata sent by the key updating terminal device through a second secure channel, wherein the key metadata comprises a key identifier, a source identifier, and a destination identifier; the source identifier is an identifier corresponding to the binding between the key updating terminal device and the second quantum key distribution node; the destination identifier is an identifier corresponding to the binding between the key distribution center and the third quantum key distribution node; 10. The method of claim 9, wherein, updating the key file based on the mapping information. The method further comprises:
11. A method of secure communication, characterized by searching whether the authentication encryption key is stored in the key file based on the identifier of the authentication encryption key. The method comprises: sending a session key request message to the key distribution center; wherein the session key request message is used to request to obtain a session key; the session key request message comprises an identity of an authentication encryption key, an identity of a terminal device, an identity of a server, a third verification code and a third random number generated by the terminal device; wherein the third verification code is a verification code generated by using a message verification code algorithm based on the authentication encryption key, the identity of the terminal device, the identity of the server, the third random number and the identity of the authentication encryption key; receiving a session key sent by the key distribution center; wherein the session key is used for secure communication between the server and the terminal device; the session key is a key between a first quantum key distribution node connected with the server and a second quantum key distribution node connected with a key update terminal device; the key update terminal device is used to import an authentication encryption key into the terminal device; The method further comprises: sending a session request to the server; wherein the session request comprises an identity of a terminal device, an identity of a server, a first random number, a second random number generated by the terminal device and a first verification code; the first verification code is a verification code generated by using a message verification code algorithm based on the session key, the identity of the terminal device, the identity of the server, the first random number and the second random number.
12. The method of claim 11, wherein, The receiving the session key sent by the key distribution center comprises: receiving a session key request response message sent by the key distribution center; wherein the session key request response message comprises an identity of a terminal device, an identity of the key distribution center, the third random number, the first random number, an encrypted session key and a fourth verification code; the fourth verification code is a verification code generated by using a message verification code algorithm based on the authentication encryption key, the identity of the terminal device, the identity of the key distribution center, the third random number, the first random number and the encrypted session key; the encrypted session key is obtained by encrypting the session key based on the authentication encryption key by the key distribution center.
13. The method of claim 11, wherein, The method further comprises: receiving a session response message sent by the server; wherein the session response message comprises an identity of a terminal device, an identity of a server, a second random number and a second verification code; the second verification code is a verification code generated by using a message verification code algorithm based on the session key, the identity of the terminal device, the identity of the server and the second random number; comparing the second random number generated by the terminal device with the second random number in the session response message to determine whether the session response message is a replay message; if the session response message is not a replay message, performing secure communication with the server based on the session key.
14. The method of claim 11, wherein, The method further comprises: sending a key request to the key update node; wherein the key request is used to request to obtain a one-time key connected with the key distribution node; Receive the key file sent by the key update node; wherein the key file includes one or more keys and metadata corresponding to each key.
15. A method of secure communication, characterized by The method applied to the key update terminal device comprises: Receiving a key request sent by a terminal device and sending the key request to a second quantum key distribution node; wherein the key request is used to request to obtain a one-time key connected to the quantum key distribution node; the key update terminal device is used to import an authentication encryption key for the terminal device; Receiving a key file sent by the second quantum key distribution node; wherein the key file includes one or more keys and metadata corresponding to each key; the second quantum key distribution node is connected to the key update terminal device; Binding the key metadata corresponding to the terminal and the key; wherein the key metadata includes key identification, source identification and destination identification; the source identification is the identification corresponding to the binding of the key update terminal device and the second quantum key distribution node; the destination identification is the identification corresponding to the binding of the key distribution center and the third quantum key distribution node; Sending the key file to the terminal device.
16. A method of secure communication, characterized by The method applied to the first quantum key distribution node comprises: Receiving a key request message sent by a server; wherein the key request message is used to obtain a key between the first quantum key distribution node and a second quantum key distribution node connected to the key update terminal device; the key request message includes the identification of the first quantum key distribution node and the identification of the second quantum key distribution node; Performing a key generation process between the first quantum key distribution node and the second quantum key distribution node to obtain a session key; Sending the session key to the server; wherein the session key is used for the server and the terminal device to perform secure communication; the key update terminal device imports an authentication encryption key for the terminal device.
17. A server, characterized by The server comprises: A first receiving module is configured to receive session information sent by a key distribution center through a first secure channel; wherein the session information includes the identification of a first quantum key distribution node connected to the server, the identification of a second quantum key distribution node connected to a key update terminal device, the identification of a terminal device, and the identification of a server; the key update terminal device imports an authentication encryption key for the terminal device; A first sending module is configured to send a key request message to the first quantum key distribution node; wherein the key request message is used to obtain a key between the first quantum key distribution node and the second quantum key distribution node; the key request message includes the identification of the first quantum key distribution node and the identification of the second quantum key distribution node; A first receiving module is configured to receive a session key sent by the first quantum key distribution node; A first sending module is configured to send the session key to the terminal device through the key distribution center; wherein the session key is used for the server and the terminal device to perform secure communication.
18. A key distribution center, characterized by, The key distribution center comprises: The second receiving module is configured to receive a session key request message sent by the terminal device; the session key request message is used to request to obtain a session key; the session key request message comprises an identifier of an authentication encryption key, an identifier of the terminal device, an identifier of the server, a third verification code, and a third random number generated by the terminal device; the third verification code is a verification code generated by using a message authentication code algorithm based on the authentication encryption key, the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key; The second processing module is configured to determine, based on the session key request message, a key between a second quantum key distribution node connected with a key update terminal device and a first quantum key distribution node connected with the server; the key update terminal device is used to import the authentication encryption key into the terminal device. The second sending module is configured to send session information to the server through a first secure channel; the session information comprises an identifier of the first quantum key distribution node, an identifier of the second quantum key distribution node, an identifier of the terminal device, and an identifier of the server. The second receiving module is configured to receive the session key and a first random number sent by the server through the first secure channel. The second sending module is configured to send the session key to the terminal device; the session key is used for secure communication between the server and the terminal device.
19. A terminal device, comprising: The terminal device comprises: The third sending module is configured to send a session key request message to the key distribution center; the session key request message is used to request to obtain a session key; the session key request message comprises an identifier of an authentication encryption key, an identifier of the terminal device, an identifier of the server, a third verification code, and a third random number generated by the terminal device; the third verification code is a verification code generated by using a message authentication code algorithm based on the authentication encryption key, the identifier of the terminal device, the identifier of the server, the third random number, and the identifier of the authentication encryption key; The third receiving module is configured to receive a session key sent by the key distribution center; the session key is used for secure communication between the server and the terminal device; the session key is a key between a first quantum key distribution node connected with the server and a second quantum key distribution node connected with a key update terminal device; the key update terminal device is used to import the authentication encryption key into the terminal device. The third sending module is further configured to: send a session request to the server; the session request comprises an identifier of the terminal device, an identifier of the server, a first random number, a second random number generated by the terminal device, and a first verification code; the first verification code is a verification code generated by using a message authentication code algorithm based on the session key, the identifier of the terminal device, the identifier of the server, the first random number, and the second random number.
20. A key update terminal device, characterized by comprising: The key update terminal device comprises: The fourth receiving module is configured to receive a key request sent by the terminal device; wherein the key request is used to request to obtain a one-time key connected to the key distribution node; and the key updating terminal device is configured to import an authentication encryption key into the terminal device; The fourth sending module is configured to send the key request to a second quantum key distribution node; The fourth receiving module is configured to receive a key file sent by the second quantum key distribution node; wherein the key file comprises one or more keys and metadata corresponding to each key; and the second quantum key distribution node is connected to the key updating terminal device; The fourth processing module is configured to bind the key metadata corresponding to the terminal and the key; wherein the key metadata comprises a key identifier, a source identifier and a destination identifier; the source identifier is an identifier corresponding to the binding between the key updating terminal device and the second quantum key distribution node; and the destination identifier is an identifier corresponding to the binding between the key distribution center and the third quantum key distribution node; The fourth sending module is configured to send the key file to the terminal device.
21. A first quantum key distribution node, comprising: The first quantum key distribution node comprises: The fifth receiving module is configured to receive a key request message sent by a server; wherein the key request message is used to obtain a key between the first quantum key distribution node and a second quantum key distribution node connected to a key updating terminal device; the key updating terminal device is configured to import an authentication encryption key into the terminal device; and the key request message comprises an identifier of the first quantum key distribution node and an identifier of the second quantum key distribution node; The fifth processing module is configured to perform a key generation process between the first quantum key distribution node and the second quantum key distribution node, and obtain a session key; The fifth sending module is configured to send the session key to the server; wherein the session key is used for the server and the terminal device to perform secure communication.
22. An electronic device, comprising: The electronic device comprises: A memory is configured to store executable instructions; A processor is configured to execute the executable instructions stored in the memory, and implement the secure communication method in any one of claims 1 to 4, or the secure communication method in any one of claims 5 to 10, or the secure communication method in any one of claims 11 to 14, or the secure communication method in claim 15, or the secure communication method in claim 16.
23. A computer-readable storage medium, characterized in that, The computer readable storage medium stores one or more programs, which can be executed by one or more processors to implement the secure communication method in any one of claims 1 to 4, or the secure communication method in any one of claims 5 to 10, or the secure communication method in any one of claims 11 to 14, or the secure communication method in claim 15, or the secure communication method in claim 16.
24. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the secure communication method of any one of claims 1 to 4, or the secure communication method of any one of claims 5 to 10, or the secure communication method of any one of claims 11 to 14, or the secure communication method of claim 15, or the secure communication method of claim 16.
Citation Information
Patent Citations
Secret communication method, secret key distribution center, equipment, medium and product
CN118827016A