A method for secure communication based on quantum keys
By integrating security chips and quantum cryptography management service platforms into IoT terminal devices, generating and authenticating working keys, and establishing VPN tunnels, the problem of insufficient security in data transmission of IoT terminal devices is solved, and reliable data transmission is achieved.
Patent Information
- Application Number
- CN202411954837.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-27
AI Technical Summary
IoT terminal devices lack effective security encryption measures during data transmission. Especially when facing large quantum computers, the existing key negotiation methods are easily cracked, resulting in insufficient identity authentication and data security.
Integrate security chips and quantum cryptography management service platforms in IoT terminal devices, generate and authenticate working keys, establish VPN tunnels for secure communication, and ensure the reliability and integrity of data transmission.
It achieves secure and reliable data transmission between IoT terminals and business platforms, prevents keys from being cracked, and ensures the security and integrity of data messages.
Smart Images

Figure CN119766552B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of password application, in particular to a secure communication method based on quantum key. BACKGROUND
[0002] The Internet of Things is a large and intelligent network formed by combining various information sensing devices such as radio frequency identification devices, various sensor nodes, and various wireless communication devices with the Internet, and involves key technologies including RFID, sensors, wireless networks, artificial intelligence, and cloud computing. The biggest difference between the Internet of Things and the Internet and the mobile Internet is that a large number of sensing layer and edge layer nodes are added, which breaks through the original IT architecture. The system boundary is further expanded, and it is an organic integration of cloud and sensing nodes / edge nodes. Therefore, the security problems and challenges faced by the Internet of Things are quite different from those of cloud resources and traditional hardware products, mainly in the following aspects: device resource fragmentation, a large number of communication protocols, more openness, and poor deployment environment. In particular, the identity authentication security and data security mechanism throughout the cloud, management, and terminal three layers is the most core problem of the Internet of Things security and a realistic problem that needs to be urgently researched and solved.
[0003] The Internet of Things terminal device is generally connected to the network through Bluetooth, wifi, ZigBee, and 4G, and then performs data interaction with the Internet of Things business platform. However, the current data transmission method basically does not use security encryption technology or uses a software encryption method with very low security level, which is not sufficient to meet its own security needs. In addition, in the process of negotiating the working key, the generation of the key involves the plaintext transmission of key exchange information such as key parameters and key generation operation mode, and the public key of the asymmetric key is used to encrypt the key and transmit it to the opposite end in the form of ciphertext. The opposite end decrypts the key with a private key to obtain the key. However, with the realization of large-scale quantum computers, the key negotiation, encryption, and signature applications in classical cryptography will be affected to some extent. This key synchronization method provides an opportunity for attackers to crack the key. SUMMARY
[0004] The present application aims to overcome the deficiencies in the prior art and provide a secure communication method based on quantum key, so as to add a communication module integrated with a security chip, a quantum password management service platform, and a gateway device to the existing Internet of Things terminal device and Internet of Things business platform to form a complete data transmission security communication channel, i.e., a VPN tunnel, which can ensure the reliability, security, and integrity of business data message transmission.
[0005] To achieve the above-mentioned purpose, the technical solutions adopted by the embodiments of the present application are as follows:
[0006] In a first aspect, an embodiment of the present application provides a quantum key-based secure communication method, which is applied to a control unit in a communication module in an Internet of Things terminal, the method comprising:
[0007] Obtaining the serial number of the target injection key from the security chip in the communication module and generating client handshake information;
[0008] Sending the client handshake information to a gateway device, so that the gateway device obtains the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key and generates a server handshake message;
[0009] Receive the server handshake message and server certificate sent by the gateway device;
[0010] Calling the security chip to authenticate the server certificate, and generating a first working key in the security chip according to the target injection key;
[0011] Sending the client certificate of the communication module to the gateway device, so that the gateway device authenticates the client certificate through the quantum cryptography management service platform and generates a second working key according to the target injection key;
[0012] A VPN tunnel is established between the communication module and the gateway device according to the first working key and the second working key, for transmitting service data messages between the IoT terminal and the IoT service platform.
[0013] In an optional embodiment, obtaining the serial number of the target injection key from the security chip in the communication module and generating the client handshake information includes:
[0014] Determining an unused charging key from the multiple charging keys of the security chip as the target charging key, and obtaining a serial number of the target charging key;
[0015] The client handshake information is generated according to the serial number of the target charging key and the device identification of the communication module.
[0016] In an optional embodiment, before obtaining the serial number of the target charging key from the security chip in the communication module and generating the client handshake information, the method further includes:
[0017] Sending a key charging request to the quantum cryptography management service platform so that the quantum cryptography management service platform generates a charging key file; the charging key file includes: multiple charging keys;
[0018] Obtaining the charging key file returned by the quantum cryptography management service platform;
[0019] The key file is stored in the security chip.
[0020] In an optional embodiment, calling the security chip to authenticate the server certificate and generating a first working key in the security chip according to the target injection key includes:
[0021] Calling the authentication interface of the security chip to authenticate the server certificate;
[0022] Calling the algorithm interface of the security chip to calculate a first master key based on the target charging key, the first client random number, the first server random number, and a constant string, and calculating the first working key based on the first master key;
[0023] The first working key is stored in the security chip.
[0024] In an optional embodiment, the method further comprises:
[0025] Obtaining a first service data message generated by a service module in the Internet of Things terminal;
[0026] Invoking the security chip, encrypting the first service data message according to the first working key, and encapsulating the message into a first service data ciphertext;
[0027] Based on the VPN tunnel, the first business data ciphertext is sent to the gateway device, so that the gateway device calls the quantum cryptography management service platform, decapsulates and decrypts the first business data ciphertext according to the second working key, obtains the first business data message, and forwards it to the Internet of Things business platform.
[0028] In an optional embodiment, the method further comprises:
[0029] If it is detected that the VPN tunnel is disconnected, or the connection time of the VPN tunnel exceeds a preset time, the target injection key in the security chip is destroyed.
[0030] In a second aspect, an embodiment of the present application further provides a quantum key-based secure communication method, which is applied to a gateway device; the method includes:
[0031] Receiving client handshake information sent by a control unit in a communication module in an IoT terminal, where the control unit obtains a serial number of a target charging key from a security chip in the communication module and generates the client handshake information;
[0032] Obtain the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key, and generate a server-side handshake message;
[0033] Sending the server handshake message and the server certificate to the control unit, so that the control unit calls the security chip to authenticate the server certificate and generates a first working key in the security chip according to the target injection key;
[0034] receiving a client certificate of the communication module sent by the control unit, authenticating the client certificate through the quantum cryptography management service platform, and generating a second working key according to the target injection key;
[0035] A VPN tunnel is established between the communication module and the gateway device according to the first working key and the second working key, for transmitting service data messages between the IoT terminal and the IoT service platform.
[0036] In an optional embodiment, the receiving the client certificate of the communication module sent by the control unit, authenticating the client certificate through the quantum cryptography management service platform, and generating a second working key according to the target injection key includes:
[0037] Calling the authentication interface of the quantum cryptography management service platform to authenticate the client certificate;
[0038] Calling the algorithm interface of the quantum cryptography management service platform, the target charging key, the second client random number, the second server random number, and the constant string, calculating the second master key, and calculating the second working key based on the second master key;
[0039] The second working key is stored in the gateway device.
[0040] In an optional embodiment, the method further comprises:
[0041] Obtaining a second service data message generated by a service module in the Internet of Things service platform;
[0042] Invoking the quantum cryptography management service platform, encrypting the second service data message according to the second working key, and encapsulating the message into a second service data ciphertext;
[0043] Based on the VPN tunnel, the second business data ciphertext is sent to the communication module, so that the communication module calls the security chip, decapsulates and decrypts the second business data ciphertext according to the first working key, and obtains the second business data message.
[0044] In an optional embodiment, the method further comprises:
[0045] If it is detected that the connection of the VPN tunnel is disconnected or the connection time of the VPN tunnel exceeds a preset time, the target refilling key in the quantum password management service platform is destroyed.
[0046] The beneficial effects of the present application are:
[0047] The embodiment of the present application provides a kind of based on quantum key's secure communication method, it is applied to the control unit in the communication module in Internet of Things terminal, this method includes: by obtaining the serial number of target refilling key from the security chip in communication module, and generate client handshake information;Client handshake information is sent to gateway device, to make gateway device obtains target refilling key from quantum password management service platform according to the serial number of target refilling key, and generates server handshake message, receives the server handshake message and server certificate sent by gateway device;Call security chip to authenticate server certificate, and according to target refilling key, generate first working key in security chip, send the client certificate of communication module to gateway device, to make gateway device authenticate client certificate by quantum password management service platform, and generate second working key according to target refilling key;Finally, according to first working key and second working key, establish the VPN tunnel between communication module and gateway device, for Internet of Things terminal and Internet of Things service platform are carried out service data message transmission.The method of the present application is based on existing Internet of Things terminal device and Internet of Things service platform, join the communication module integrated security chip, quantum password management service platform and gateway device, form complete data transmission security communication channel, i.e. VPN tunnel, can guarantee the reliability, security and integrity of service data message transmission. BRIEF DESCRIPTION OF DRAWINGS
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0049] Figure 1 A schematic diagram of a secure communication system based on quantum key provided by the embodiment of the present application is shown in the figure.
[0050] Figure 2 One of the flowcharts of a secure communication method based on quantum key provided by the embodiment of the present application is shown in the figure.
[0051] Figure 3A second flow chart of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0052] Figure 4 The third flowchart of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0053] Figure 5 A fourth flow chart of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0054] Figure 6 Flowchart 5 of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0055] Figure 7 Flowchart 6 of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0056] Figure 8 Flowchart 7 of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0057] Figure 9 8. Flowchart of a secure communication method based on quantum keys provided in an embodiment of the present application;
[0058] Figure 10 A schematic diagram of the functional modules of a quantum key-based secure communication device provided in an embodiment of the present application;
[0059] Figure 11 A schematic diagram of the functional modules of another quantum key-based secure communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0060] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments.
[0061] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0062] In the description of the present application, it should be noted that if the terms "upper", "lower", etc. indicate the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of the present application is usually placed, only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application.
[0063] In addition, the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily describe a particular order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0064] It should be noted that the features in the embodiments of the present application can be combined with each other without conflict.
[0065] In order to better understand the solutions provided by the following embodiments of the present application, the technical terms related to the following embodiments of the present application are explained here.
[0066] The CSP (Cryptographic Service Provider) platform, i.e. the quantum cryptography management service platform in the embodiments of the present application, is a platform for providing password and key services for mobile Internet, Internet of Things and other services based on quantum key network, including password service platform software, exchange password machine, charging terminal software and other subsystems.
[0067] SSL (Secure Sockets Layer) is a protocol for encrypting Internet traffic and verifying server identity.
[0068] PRF (Pseudorandom Function) algorithm is an important algorithm for generating key material in SSL / TLS protocol. In the SSL / TLS handshake process, PRF is used to derive a master key from a pre-master key, and then derive a working key from the master key, which is used to encrypt and decrypt actual data transmission.
[0069] Figure 1A schematic diagram of a quantum key-based secure communication system provided in an embodiment of the present application is shown in FIG. Figure 1 As shown in the figure, the secure communication system based on quantum keys includes: Internet of Things terminals, gateway devices, quantum cryptography management service platform and Internet of Things business platform. Among them, the Internet of Things business platform and the gateway device establish a private network connection, and the gateway device establishes a private network connection with the quantum cryptography management service platform. The Internet of Things terminal establishes a communication channel through the integrated communication module and the gateway device.
[0070] Specifically, the IoT terminal hardware is integrated with a communication module, which interacts with the IoT terminal main control chip through AT commands, so that the IoT terminal main control chip calls the SSL VPN tunnel encryption capability provided by the communication module through AT commands, thereby realizing the secure encryption of IoT terminal business data and sending it to the IoT business platform.
[0071] The communication module is a hardware product of a 4G Cat.1 communication module. The communication module includes a radio frequency transceiver, a power amplifier, a filter, a baseband processor, a control unit, a security chip, etc. The communication module is directly integrated on the circuit board of the IoT terminal. The hardware of the communication module provided in the embodiment of the present application is integrated with a security chip, and the software system integrates an SSL VPN client software program, thereby providing SSL VPN tunnel encryption services and data transmission control functions. Among them, the security chip is a national secret chip. The security chip can adopt a 32-bit CPU architecture, support 7816, SPI, UART, I2C interfaces, and support multiple algorithms such as SM1, SM2, SM3, SM4, SM7, SHA, DES, AES, RSA and ECC, establishing a multi-level chip security protection system from the algorithm level, circuit level, system level to the software layer, complying with the commercial secret level 2 security standard and meeting the industrial and automotive grade reliability requirements. Therefore, the security chip has hardware encryption and decryption, signature verification, PRF and other algorithm capabilities and secure storage space to ensure hardware-level security compliance, and internally pre-installed multiple injection keys generated by the quantum cryptography service platform.
[0072] Specifically, the communication module interacts with the main control chip of the IoT terminal through AT commands, and the control unit of the communication module interacts with the security chip through APDU commands; the control unit of the communication module communicates with the main control chip of the IoT terminal through communication interfaces such as I2C, SPI, and UART. At the same time, the embedded program of the main control chip of the IoT device needs to call the embedded (Software Development Kit, SDK) interface program that matches the communication module to complete the call of the specific functions of the communication module. Among them, the embedded SDK is part of the main control program in the main control chip of the IoT device, and can be customized and compiled according to the development environment used by the main control chip of the IoT terminal. The communication module embedded SDK also integrates the SSL VPN client software program, and the cryptographic algorithm functions such as digital signatures and encryption / decryption required in the SSL security protocol are all processed by the operation interface provided by the security chip.
[0073] The gateway device is an SSL VPN gateway device, which is integrated with the SSL VPN server software program and connected to the Internet of Things business platform and the quantum cryptography management service platform. The gateway device calls the interface provided by the quantum cryptography management service platform to perform encryption and decryption operations, thereby encrypting and decrypting business data messages and forwarding the decrypted business data to the Internet of Things business platform.
[0074] The quantum cryptography management service platform provides quantum key storage and encryption and decryption computing capabilities, connects to the SSL VPN gateway, and provides an interface for obtaining injection keys, providing key injection functions for the communication modules in the IoT terminals.
[0075] In order to ensure the reliability, security and integrity of data transmission between the Internet of Things terminal and the Internet of Things service platform, the present application provides a quantum key-based secure communication method, which is applied to a control unit in a communication module in the Internet of Things terminal, obtains the serial number of the target injection key from the security chip in the communication module, and generates client handshake information; sends the client handshake information to a gateway device, so that the gateway device obtains the target injection key from the quantum cryptography management service platform according to the serial number of the target injection key, and generates a server handshake message, and receives the server handshake message and server certificate sent by the gateway device; calls the security chip to authenticate the server certificate, and generates a first working key in the security chip according to the target injection key, sends the client certificate of the communication module to the gateway device, so that the gateway device authenticates the client certificate through the quantum cryptography management service platform, and generates a second working key according to the target injection key; finally, establishes a VPN tunnel between the communication module and the gateway device based on the first working key and the second working key, for transmitting business data messages between the Internet of Things terminal and the Internet of Things service platform. Based on the existing IoT terminal devices and IoT business platforms, communication modules with integrated security chips, quantum cryptography management service platforms and gateway devices are added to form a complete secure communication channel for data transmission, which can ensure the reliability, security and integrity of business data message transmission.
[0076] The following describes the quantum key-based secure communication method provided by the present application through multiple examples with reference to the accompanying drawings. The quantum key-based secure communication method is applied to a control unit in a communication module in an IoT terminal. Figure 2 This is one of the flow charts of a quantum key-based secure communication method provided in an embodiment of the present application, such as Figure 2 As shown, the method includes:
[0077] S101: Obtain the serial number of the target injection key from the security chip in the communication module, and generate client handshake information.
[0078] In this embodiment, the security chip stores multiple injection keys, obtains the serial number of the target injection key from them, and fills the serial number of the target injection key in the extended field of the client handshake information, i.e., the Client Hello message based on the SSL protocol, to generate the client handshake information.
[0079] The client handshake message is the initial interaction between the communication module and the gateway device to initiate a secure communication connection. It contains important information such as the communication protocol version supported by the communication module, a client random number generated by the module, and the target key sequence number. It informs the gateway device of its communication preparation status and associated key identifiers, paving the way for subsequent negotiations to establish a secure connection.
[0080] S102: Send the client handshake information to the gateway device, so that the gateway device obtains the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key and generates a server handshake message.
[0081] Specifically, after receiving the client's handshake message, the gateway device extracts the serial number of the target charging key contained therein. Based on this serial number, it then initiates a request to the quantum cryptography management service platform to obtain the corresponding target charging key. As a platform that centrally manages and stores security resources such as keys, the quantum cryptography management service platform uses a strict permission management and search mechanism to locate and provide the corresponding target charging key to the gateway device based on the serial number.
[0082] After obtaining the target charging key, the gateway device generates a server handshake message. This message also contains some communication configuration information related to the gateway device itself, such as the supported protocol versions and the client random number generated by the gateway device. It is used to respond to the client handshake message from the communication module, continuing the process of establishing a secure connection between the two parties.
[0083] S103: Receive a server handshake message and a server certificate sent by the gateway device.
[0084] S104: Call the security chip to authenticate the server certificate, and generate a first working key in the security chip according to the target injection key.
[0085] Specifically, the communication module receives the server handshake message and server certificate sent by the gateway device and authenticates the received server certificate using the functions and stored trust roots, verification algorithms, and other resources within the security chip. For example, it verifies whether the issuing authority of the certificate is legitimate, whether the certificate is within its validity period, and whether the certificate content has been tampered with. Only after passing these rigorous verification processes can the gateway device's identity be confirmed as reliable, and subsequent communication can continue based on trust.
[0086] After confirming the validity of the server certificate, the communication module will inject the key according to the target and use the PRF algorithm to generate the first working key inside the security chip. The first working key is used for subsequent encrypted communication with the gateway device and data integrity verification.
[0087] S105. Send the client certificate of the communication module to the gateway device, so that the gateway device authenticates the client certificate through the quantum cryptography management service platform and generates a second working key according to the target injection key.
[0088] The communication module sends its client certificate to the gateway device so that the gateway can verify the communication module's identity. The client certificate also contains relevant information that proves the communication module's identity and serves as a token of the communication module's legal status within the entire secure communication system.
[0089] After receiving the client certificate, the gateway device submits it to the quantum cryptography management service platform for authentication. The quantum cryptography management service platform determines the legitimacy of the client certificate based on its stored trust information and verification rules. Once authentication is successful, a second working key is generated using the PRF algorithm based on the target key. This second working key corresponds to the first working key generated by the communication module, and the two are subsequently used together for secure communication operations such as encryption and decryption between the two parties.
[0090] S106. Establish a VPN tunnel between the communication module and the gateway device based on the first working key and the second working key, for transmitting service data messages between the IoT terminal and the IoT service platform.
[0091] Specifically, after the communication module and gateway device have generated a first working key and a second working key, they establish an SSL VPN (virtual private network) tunnel based on the negotiated working keys, using specific network communication technologies such as encryption and encapsulation. The SSL VPN tunnel creates a secure communication channel between IoT devices and the IoT service platform within a public network, establishing a dedicated, encrypted pipeline.
[0092] Once the VPN tunnel is successfully established, service data packets between the IoT terminal and the IoT service platform can be transmitted through the VPN tunnel. During transmission, the service data packets are encrypted and decrypted using an encryption and decryption algorithm based on the first working key and the second working key to ensure the confidentiality of the service data packets.
[0093] In summary, an embodiment of the present application provides a quantum key-based secure communication method, which is applied to a control unit in a communication module in an Internet of Things terminal. The method includes: obtaining the serial number of the target injection key from the security chip in the communication module and generating client handshake information; sending the client handshake information to a gateway device, so that the gateway device obtains the target injection key from the quantum cryptography management service platform according to the serial number of the target injection key, and generates a server handshake message, and receives the server handshake message and server certificate sent by the gateway device; calling the security chip to authenticate the server certificate, and generating a first working key in the security chip according to the target injection key, sending the client certificate of the communication module to the gateway device, so that the gateway device authenticates the client certificate through the quantum cryptography management service platform, and generates a second working key according to the target injection key; finally, establishing a VPN tunnel between the communication module and the gateway device based on the first working key and the second working key, for transmitting business data messages between the Internet of Things terminal and the Internet of Things business platform. The method of the present application is based on the existing IoT terminal devices and IoT business platforms, adding a communication module with an integrated security chip, a quantum cryptography management service platform and a gateway device to form a complete secure communication channel for data transmission, namely a VPN tunnel, which can ensure the reliability, security and integrity of business data message transmission.
[0094] Based on the above embodiments, the present application also provides another possible implementation of a quantum key-based secure communication method. Figure 3 The second flow chart of a secure communication method based on quantum keys provided in the embodiment of the present application is as follows: Figure 3 As shown, the serial number of the target injection key is obtained from the security chip in the communication module, and the client handshake information is generated, including:
[0095] S201: Determine an unused charging key from multiple charging keys of a security chip as a target charging key, and obtain a serial number of the target charging key.
[0096] In this embodiment, multiple prime keys are pre-stored in the communication module's security chip. To ensure the security of each communication connection and standardized key usage, an unused prime key is selected from these multiple prime keys as the target prime key for the current communication. Reusing a prime key that has already been used in other communications can pose security risks, such as key cracking or information leakage, which could be exploited by criminals. Therefore, selecting an unused prime key ensures that each new communication connection has an independent, secure, and reliable key foundation.
[0097] Since each charging key has a corresponding unique serial number, obtaining the serial number of the target charging key allows the gateway device to accurately obtain the corresponding target charging key from the quantum cryptography management service platform based on the serial number.
[0098] S202: Generate client handshake information according to the serial number of the target charging key and the device identification of the communication module.
[0099] The communication module's device ID uniquely identifies it within an IoT terminal system or a specific network environment. By obtaining the device ID, the gateway device can accurately determine the module initiating the connection request. This also facilitates accurate identity verification during subsequent authentication and other steps, preventing security issues such as unauthorized device misuse.
[0100] The serial number of the target injection key and the device identification of the communication module are filled in the extended field of the client handshake information, that is, the Client Hello message based on the SSL protocol, and finally the client handshake information is generated.
[0101] In the method provided in the embodiment of the present application, an unused charging key is determined from multiple charging keys of the security chip as the target charging key, and the serial number of the target charging key is obtained; client handshake information is generated based on the serial number of the target charging key and the device identification of the communication module, and the client handshake information is generated by reasonably selecting the target charging key and obtaining its serial number, and then combining it with the device identification of the communication module itself, to prepare for the subsequent establishment of a secure and reliable communication connection with the gateway device.
[0102] The present application also provides another possible implementation of a quantum key-based secure communication method. Figure 4 The third flow chart of a secure communication method based on quantum keys provided in the embodiment of the present application is as follows: Figure 4 As shown, before obtaining the serial number of the target injection key from the security chip in the communication module and generating the client handshake information, the method further includes:
[0103] S301. Send a key injection request to the quantum cryptography management service platform, so that the quantum cryptography management service platform generates an injection key file.
[0104] Among them, the charging key file includes: multiple charging keys.
[0105] In this embodiment, the communication module pre-sends a key charging request to the quantum cryptography management service platform via a key charging terminal, enabling the platform to generate a charging key file according to the established security policy. The charging key file contains multiple charging keys, each with unique cryptographic properties and functions, providing a rich key reserve for subsequent secure communication between the communication module and gateway devices.
[0106] S302. Obtain the charging key file returned by the quantum cryptography management service platform.
[0107] S303: Store the charging key file in the security chip.
[0108] Specifically, through the corresponding network communication interface and secure data transmission mechanism, the communication module receives the charging key file from the quantum cryptography management service platform and stores the charging key file in the secure storage space of the security chip.
[0109] In the method provided in the embodiment of the present application, a key charging request is sent to the quantum cryptography management service platform, so that the quantum cryptography management service platform generates a charging key file; the charging key file includes: multiple charging keys; the charging key file returned by the quantum cryptography management service platform is obtained, and the charging key file is stored in the security chip, so that the quantum cryptography management service platform and the security chip store the same charging key, thereby ensuring that the quantum cryptography management service platform can find the target charging key according to the serial number of the target charging key.
[0110] The present application also provides another possible implementation of a quantum key-based secure communication method. Figure 5 The fourth flow chart of a secure communication method based on quantum keys provided in the embodiment of the present application is as follows: Figure 5 As shown, calling the security chip to authenticate the server certificate and generating a first working key in the security chip according to the target injection key includes:
[0111] S401: Call the authentication interface of the security chip to authenticate the server certificate.
[0112] S402: Call the algorithm interface of the security chip to calculate the first master key according to the target injection key, the first client random number, the first server random number, and the constant string, and calculate the first working key according to the first master key.
[0113] S403: Store the first working key in the security chip.
[0114] In this embodiment, a dedicated authentication interface is built into the security chip, serving as an external communication channel for functional modules handling various certificate authentication operations. When the communication module establishes a secure connection with the gateway device, upon receiving the server certificate from the gateway, the authentication interface is invoked to verify the server certificate. This interface integrates a comprehensive set of authentication rules and verification mechanisms pre-defined within the security chip, enabling rigorous verification of the legitimacy, integrity, and validity of server certificates based on relevant standards and trust models.
[0115] For example, the system checks whether the issuing authority of the certificate is a trusted authority and verifies that the certificate is within its validity period. Expired certificates are obviously no longer valid for identity verification or secure communications. Furthermore, the system verifies the certificate content for signs of tampering, verifying its integrity by verifying information such as the digital signature. If the certificate content has been tampered with, it could potentially pose security risks such as man-in-the-middle attacks. Only when the server-side certificate successfully passes these various verifications performed by the authentication interface can the gateway device's identity be confirmed as reliable.
[0116] Specifically, the algorithm interface of the security chip is the key entry point for implementing various core algorithm operations such as encryption and key generation. It encapsulates advanced, secure and reliable encryption algorithms, key derivation algorithms and other functional modules. By calling the algorithm interface, the PRF algorithm is used to calculate the first master key based on the target injection key, the first client random number, the first server random number, and the constant string, and the PRF algorithm is used again to calculate the first working key based on the first master key. Among them, the first client random number is a random value generated by the communication module as a client role when the handshake is initially initiated, that is, the random number saved in the client handshake information, and the first server random number is the random number saved in the server handshake message sent by the gateway device. Finally, the first working key is stored in the security chip.
[0117] In the method provided in the embodiment of the present application, the authentication interface of the security chip is called to authenticate the server certificate; the algorithm interface of the security chip is called to calculate the first master key according to the target injection key, the first client random number, the first server random number, and the constant character string, and the first working key is calculated according to the first master key; finally, the first working key is stored in the security chip, and by calling different functional interfaces inside the security chip, the authentication of the server certificate and the generation and storage of the key first working key are completed, laying a solid foundation for building a secure communication connection between the communication module and the gateway device.
[0118] The present application also provides another possible implementation of a quantum key-based secure communication method. Figure 6 The fifth flow chart of a secure communication method based on quantum keys provided in the embodiment of the present application is as follows: Figure 6 As shown, the method includes:
[0119] S501: Acquire a first service data message generated by a service module in an Internet of Things terminal.
[0120] S502: Call the security chip, encrypt the first service data message according to the first working key, and encapsulate it into a first service data ciphertext.
[0121] S503. Based on the VPN tunnel, the first business data ciphertext is sent to the gateway device, so that the gateway device calls the quantum cryptography management service platform, decapsulates and decrypts the first business data ciphertext according to the second working key, obtains the first business data message, and forwards it to the Internet of Things business platform.
[0122] In this embodiment, the service module in the IoT terminal generates a first service data packet, the main control chip in the IoT terminal matches the configured route according to the destination address of the first service data packet, forwards the first service data packet to the virtual network card, and the SSL VPN client software program reads the first service data packet in the virtual network card.
[0123] The encryption operation is then performed using the first working key generated and stored in the security chip. The first working key is obtained through a complex key negotiation and generation process, possesses unique encryption properties, and matches the corresponding second working key on the gateway device. Using the encryption algorithm integrated within the security chip, the first service data message is encrypted using the first working key as a key parameter, converting the plaintext first service data message into ciphertext. After the encryption operation is completed, the encrypted content needs to be encapsulated to form the first service data ciphertext. The encapsulation process may involve adding some additional header information, verification information, etc., which helps the gateway device accurately identify, decapsulate, and perform subsequent processing operations.
[0124] Based on the VPN tunnel, the first business data ciphertext is sent to the gateway device. After receiving the first business data ciphertext, the gateway device needs to perform decapsulation and decryption operations to restore it to the original first business data message. First, the gateway device will call the quantum cryptography management service platform, and use the relevant functions provided by the platform and the second working key generated by itself to perform decapsulation and decryption operations. The decapsulation process is to remove the additional content such as header information and verification information previously added to the IoT terminal to restore the encrypted data part. Then, based on the second working key, the encrypted data is decrypted through the decryption algorithm corresponding to the encryption process (because the first working key and the second working key are matched with each other, the encryption and decryption algorithms are also corresponding), thereby obtaining the original first business data message.
[0125] After the gateway device converts the encrypted first service data into a first service data message, it forwards the first service data message to the IoT service platform according to the established network routing and service process. Upon receiving these data messages, the IoT service platform can perform corresponding processing, analysis, and subsequent service decision-making based on the service information contained therein, thereby achieving secure and effective service data exchange between IoT terminals and the IoT service platform.
[0126] In the method provided in the embodiment of the present application, a first business data message generated by a business module in an IoT terminal is obtained; a security chip is called to encrypt the first business data message according to a first working key and encapsulate it into a first business data ciphertext; the first business data ciphertext is sent to a gateway device based on a VPN tunnel, so that the gateway device calls a quantum cryptography management service platform, decapsulates and decrypts the first business data ciphertext according to a second working key, obtains the first business data message, and forwards it to the IoT business platform. This ensures that the business data generated by the IoT terminal can be securely and accurately transmitted to the IoT business platform in a complex network environment, achieving the secure flow of business data throughout the IoT system.
[0127] The present application also provides another possible implementation of a quantum key-based secure communication method, which further includes:
[0128] If it is detected that the VPN tunnel is disconnected, or the VPN tunnel connection time exceeds the preset time, the target injection key in the security chip is destroyed.
[0129] In this embodiment, the VPN tunnel is a key channel for ensuring secure communication between the communication module and the gateway device. However, due to the complexity of the network environment, the VPN tunnel may be disconnected for various reasons, such as network failure, server or client software failure, or external network attack. This may cause the previously established VPN tunnel to be unable to maintain a normal connection state, and data transmission is forced to be interrupted.
[0130] Alternatively, to further ensure communication security and manage key resource usage, a pre-set VPN tunnel connection duration threshold (preset duration) is set. If the VPN tunnel connection exceeds this set duration, even if the tunnel connection remains normal, the target key in the security chip must be destroyed. This is because using the same key for communication for extended periods can increase security risks such as key cracking and information leakage. By limiting the connection duration, regularly updating security resources such as keys and promptly destroying target keys that may pose security risks, communication security can be better ensured.
[0131] The embodiment of the present application also provides a quantum key-based secure communication method, which is applied to a gateway device. Figure 7 The sixth flow chart of a secure communication method based on quantum keys provided in the embodiment of the present application is as follows: Figure 7 As shown, the method further includes:
[0132] S601: Receive client handshake information sent by a control unit in a communication module in an IoT terminal.
[0133] The client handshake information is generated by the control unit after obtaining the serial number of the target charging key from the security chip in the communication module.
[0134] In this embodiment, the client handshake message is the initial interaction between the communication module and the gateway device to initiate a secure communication connection. The client handshake message includes important information such as the communication protocol version supported by the communication module, the client random number generated by the module, and the serial number of the target key.
[0135] S602: Obtain the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key, and generate a server handshake message.
[0136] Specifically, after receiving the client's handshake message, the gateway device extracts the serial number of the target charging key contained therein. Based on this serial number, it then initiates a request to the quantum cryptography management service platform to obtain the corresponding target charging key. As a platform that centrally manages and stores security resources such as keys, the quantum cryptography management service platform uses a strict permission management and search mechanism to locate and provide the corresponding target charging key to the gateway device based on the serial number.
[0137] After obtaining the target charging key, the gateway device generates a server handshake message. This message also contains some communication configuration information related to the gateway device itself, such as the supported protocol versions and the client random number generated by the gateway device. It is used to respond to the client handshake message from the communication module, continuing the process of establishing a secure connection between the two parties.
[0138] S603: Send a server handshake message and a server certificate to the control unit, so that the control unit calls the security chip to authenticate the server certificate and generates a first working key in the security chip according to the target injection key.
[0139] Specifically, after receiving the server handshake message and server certificate from the gateway device, the communication module authenticates the received server certificate using the security chip's internal functions and stored resources such as the root of trust and verification algorithms. For example, it verifies whether the certificate's issuing authority is legitimate, whether the certificate is valid, and whether the certificate content has been tampered with. Only after passing these rigorous verification processes can the gateway device's identity be confirmed as reliable, and subsequent communication can proceed based on trust.
[0140] After confirming the validity of the server certificate, the communication module will inject the key according to the target and use the PRF algorithm to generate the first working key inside the security chip. The first working key is used for subsequent encrypted communication with the gateway device and data integrity verification.
[0141] S604: Receive the client certificate of the communication module sent by the control unit, authenticate the client certificate through the quantum cryptography management service platform, and generate a second working key according to the target injection key.
[0142] After receiving the client certificate, the gateway device submits it to the quantum cryptography management service platform for authentication. The quantum cryptography management service platform determines the legitimacy of the client certificate based on its stored trust information and verification rules. Once authentication is successful, a second working key is generated using the PRF algorithm based on the target key. This second working key corresponds to the first working key generated by the communication module, and the two are subsequently used together for secure communication operations such as encryption and decryption between the two parties.
[0143] S605: Establish a VPN tunnel between the communication module and the gateway device based on the first working key and the second working key, so as to transmit service data messages between the IoT terminal and the IoT service platform.
[0144] Specifically, after the communication module and gateway device have generated a first working key and a second working key, they establish an SSL VPN (virtual private network) tunnel based on the negotiated working keys, using specific network communication technologies such as encryption and encapsulation. The SSL VPN tunnel creates a secure communication channel between IoT devices and the IoT service platform within a public network, establishing a dedicated, encrypted pipeline.
[0145] Once the VPN tunnel is successfully established, service data packets between the IoT terminal and the IoT service platform can be transmitted through the VPN tunnel. During transmission, the service data packets are encrypted and decrypted using an encryption and decryption algorithm based on the first working key and the second working key to ensure the confidentiality of the service data packets.
[0146] In summary, an embodiment of the present application provides a quantum key-based secure communication method, which is applied to a gateway device, and the method includes: receiving client handshake information sent by a control unit in a communication module in an Internet of Things terminal, where the client handshake information is the serial number of the target injection key obtained by the control unit from the security chip in the communication module, and the client handshake information generated, obtaining the target injection key from the quantum cryptography management service platform according to the serial number of the target injection key, and generating a server handshake message; sending a server handshake message and a server certificate to the control unit, so that the control unit calls the security chip to authenticate the server certificate, and generates a first working key in the security chip according to the target injection key; receiving the client certificate of the communication module sent by the control unit, authenticating the client certificate through the quantum cryptography management service platform, and generating a second working key according to the target injection key; establishing a VPN tunnel between the communication module and the gateway device according to the first working key and the second working key, for transmitting business data messages between the Internet of Things terminal and the Internet of Things business platform. The method of the present application is based on the existing IoT terminal devices and IoT business platforms, adding a communication module with an integrated security chip, a quantum cryptography management service platform and a gateway device to form a complete secure communication channel for data transmission, namely a VPN tunnel, which can ensure the reliability, security and integrity of business data message transmission.
[0147] Based on the above embodiments, the present application also provides another possible implementation of a quantum key-based secure communication method. Figure 8 The seventh flow chart of a secure communication method based on quantum keys provided in the embodiment of the present application is as follows: Figure 8 As shown, receiving the client certificate of the communication module sent by the control unit, authenticating the client certificate through the quantum cryptography management service platform, and generating a second working key according to the target injection key, including:
[0148] S701. Call the authentication interface of the quantum cryptography management service platform to authenticate the client certificate.
[0149] S702. Call the algorithm interface of the quantum cryptography management service platform, inject the target key, the second client random number, the second server random number, and the constant string, calculate the second master key, and calculate the second working key based on the second master key.
[0150] S703: Store the second working key in the gateway device.
[0151] In this embodiment, the quantum cryptography management service platform includes a dedicated authentication interface, serving as an external communication channel for functional modules that handle various certificate authentication-related operations. When the communication module establishes a secure connection with the gateway device, upon receiving the client certificate sent by the communication module, the authentication interface is invoked to verify the client certificate, rigorously checking its legitimacy, integrity, and validity.
[0152] For example, the authentication interface checks whether the issuing authority of the certificate is a trusted authority and verifies that the certificate is within its validity period. Expired certificates cannot be used to verify identity or secure communications. Furthermore, the authentication interface verifies the certificate content for signs of tampering and ensures its integrity by verifying information such as the digital signature. If the certificate content has been tampered with, it could potentially pose security risks such as man-in-the-middle attacks. Only when the client certificate successfully passes these various verifications performed by the authentication interface can the communication module's identity be confirmed as reliable.
[0153] Specifically, the algorithm interface of the quantum cryptography management service platform is the key entry point for implementing various core algorithm operations such as encryption and key generation. It encapsulates advanced, secure and reliable encryption algorithms, key derivation algorithms and other functional modules. By calling the algorithm interface, the PRF algorithm is used to calculate the second master key based on the target injection key, the second client random number, the second server random number, and the constant string. The PRF algorithm is then used again to calculate the second working key based on the second master key. Among them, the second client random number is a random value generated by the communication module as a client when the handshake is initially initiated, that is, the random number stored in the client handshake information. The second server random number is the random number stored in the server handshake message sent by the gateway device. Finally, the second working key is stored in the gateway device.
[0154] In the method provided in the embodiment of the present application, the client certificate is authenticated by calling the authentication interface of the quantum cryptography management service platform, the algorithm interface of the quantum cryptography management service platform is called, the target injection key, the second client random number, the second server random number, and the constant string are calculated, the second master key is calculated, and the second working key is calculated based on the second master key. Finally, the second working key is stored in the gateway device. By calling different functional interfaces inside the security chip, the authentication of the client certificate and the generation and storage of the key second working key are completed, laying a solid foundation for building a secure communication connection between the communication module and the gateway device.
[0155] The present application also provides another possible implementation of a quantum key-based secure communication method. Figure 9 This is a flowchart of a quantum key-based secure communication method provided in an embodiment of the present application, as shown in FIG8. Figure 9As shown, the method further includes:
[0156] S801: Acquire a second service data message generated by a service module in an Internet of Things service platform.
[0157] S802. Call the quantum cryptography management service platform, encrypt the second business data message according to the second working key, and encapsulate it into a second business data ciphertext.
[0158] S803. Send the second service data ciphertext to the communication module based on the VPN tunnel, so that the communication module calls the security chip, decapsulates and decrypts the second service data ciphertext according to the first working key, and obtains the second service data message.
[0159] In this embodiment, the business modules within the IoT service platform are responsible for executing various specific business logic and operations. For example, they analyze and process data collected from numerous IoT terminals to generate corresponding feedback instructions, or generate data to be distributed to IoT terminals based on the platform's own management and monitoring functions. The data generated by the business modules is organized and arranged according to a specific format to form a second business data message, which is then forwarded to the gateway device via routing.
[0160] The SSL VPN server software in the gateway device calls the encryption interface of the quantum cryptography management service platform. Using the built-in encryption algorithm and the second working key as the key parameter, it encrypts the second service data message, converting the plaintext data into encrypted ciphertext. After the encryption operation is completed, the encrypted content needs to be encapsulated to form the second service data ciphertext. The encapsulation process may involve adding some additional header information and verification information, which helps the communication module accurately identify, decapsulate, and perform subsequent processing operations.
[0161] Based on the VPN tunnel, the second service data ciphertext is sent to the communication module. After receiving the second service data ciphertext, the communication module needs to perform decapsulation and decryption operations to restore it to the original second service data message. First, the ciphertext is decapsulated using the relevant functional modules in the security chip. This removes the additional content previously added by the IoT service platform, such as header information and checksums, to extract the encrypted data portion. Then, based on the first working key stored in the security chip and the decryption algorithm corresponding to the encryption process (because the first working key and the second working key match each other, the corresponding encryption and decryption algorithms are also compatible), the encrypted data is decrypted, successfully obtaining the original second service data message. Subsequent operations are then performed based on the second service data message, such as passing relevant instructions to the corresponding functional modules of the IoT terminal, thereby achieving secure and efficient information exchange between the IoT service platform and the IoT terminal.
[0162] In the method provided in the embodiment of the present application, a second service data message generated by a service module in the IoT service platform is obtained, the quantum cryptography management service platform is called, the second service data message is encrypted according to the second working key, and the encrypted data is encapsulated into a second service data ciphertext. The second service data ciphertext is then sent to the communication module via a VPN tunnel, so that the communication module calls the security chip, decapsulates and decrypts the second service data ciphertext according to the first working key, and obtains the second service data message. This ensures that the service data generated by the IoT terminal can be securely and accurately transmitted to the IoT service platform in a complex network environment, thus achieving the secure flow of service data throughout the IoT system.
[0163] The present application also provides another possible implementation of a quantum key-based secure communication method, which further includes:
[0164] If it is detected that the VPN tunnel is disconnected, or the connection time of the VPN tunnel exceeds the preset time, the target injection key in the quantum cryptography management service platform will be destroyed.
[0165] In this embodiment, the VPN tunnel is a key channel for ensuring secure communication between the communication module and the gateway device. However, due to the complexity of the network environment, the VPN tunnel may be disconnected for various reasons, such as network failure, server or client software failure, or external network attack. This may cause the previously established VPN tunnel to be unable to maintain a normal connection state, and data transmission is forced to be interrupted.
[0166] Alternatively, to further ensure communication security and properly manage the use of key resources, a VPN tunnel connection duration threshold, also known as a preset duration, may be pre-set. If the VPN tunnel connection exceeds this preset duration, even if the tunnel connection remains normal, the target key in the quantum cryptography management service platform must be destroyed. This is because using the same key for communication for an extended period of time may increase security risks such as key cracking and information leakage. By limiting the connection duration, regularly updating security resources such as keys, and promptly destroying target keys that may pose security risks, communication security can be better ensured.
[0167] The following continues to explain the quantum key-based secure communication device provided by any of the above embodiments of the present application. Its specific implementation process and the technical effects produced are the same as those of the corresponding method embodiments mentioned above. For the sake of brief description, for the parts not mentioned in this embodiment, please refer to the corresponding content in the method embodiment.
[0168] Figure 10A schematic diagram of the functional modules of a quantum key-based secure communication device provided in an embodiment of the present application. A control unit in a communication module used in an IoT terminal, such as Figure 10 As shown, the quantum key-based secure communication device 100 includes:
[0169] The first generating module 110 is used to obtain the serial number of the target injection key from the security chip in the communication module and generate the client handshake information;
[0170] The first sending module 120 is used to send the client handshake information to the gateway device, so that the gateway device obtains the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key and generates a server handshake message;
[0171] The first receiving module 130 is configured to receive a server handshake message and a server certificate sent by the gateway device;
[0172] The first generating module 110 is further configured to call the security chip to authenticate the server certificate and generate a first working key in the security chip according to the target injection key;
[0173] The first sending module 120 is further configured to send the client certificate of the communication module to the gateway device, so that the gateway device authenticates the client certificate through the quantum cryptography management service platform and generates a second working key according to the target injection key;
[0174] The first establishing module 140 is used to establish a VPN tunnel between the communication module and the gateway device according to the first working key and the second working key, so as to transmit service data messages between the IoT terminal and the IoT service platform.
[0175] Optionally, the first generation module 110 is further used to determine an unused charging key from multiple charging keys of the security chip as a target charging key, and obtain the serial number of the target charging key; generate client handshake information according to the serial number of the target charging key and the device identification of the communication module.
[0176] Optionally, the first sending module 120 is further configured to send a key charging request to the quantum cryptography management service platform, so that the quantum cryptography management service platform generates a charging key file; the charging key file includes: multiple charging keys;
[0177] The first acquisition module is used to obtain the charging key file returned by the quantum cryptography management service platform;
[0178] The first storage module is used to store the charging key file in the security chip.
[0179] Optionally, the first generation module 110 is further configured to call an authentication interface of the security chip to authenticate the server certificate; call an algorithm interface of the security chip to calculate a first master key according to the target rekeying key, the first client random number, the first server random number and a constant string, and calculate a first working key according to the first master key; and store the first working key in the security chip.
[0180] Optionally, the first storage module is further configured to acquire first service data packets generated by a service module in the Internet of Things terminal.
[0181] The first encryption module is configured to call the security chip to encrypt the first service data packets according to the first working key and encapsulate the first service data packets into first service data ciphertext.
[0182] The first sending module 120 is further configured to send the first service data ciphertext to the gateway device based on the VPN tunnel, so that the gateway device calls the quantum cryptography management service platform to decapsulate and decrypt the first service data ciphertext according to the second working key, to obtain the first service data packets and forward the first service data packets to the Internet of Things service platform.
[0183] Optionally, the device further comprises:
[0184] The first destruction module is configured to destroy the target rekeying key in the security chip if it is detected that the connection of the VPN tunnel is disconnected or the connection time of the VPN tunnel exceeds a preset time length.
[0185] Figure 11 Another function module schematic diagram of a quantum key-based secure communication device provided by the embodiment of the application is provided. The quantum key-based secure communication device 200 is applied to a gateway device, as shown in the figure, and comprises: Figure 11
[0186] The second receiving module 210 is configured to receive client handshake information sent by a control unit in a communication module in the Internet of Things terminal, wherein the client handshake information is generated by the control unit by acquiring a serial number of a target rekeying key from a security chip in the communication module.
[0187] The second generation module 220 is configured to acquire the target rekeying key from the quantum cryptography management service platform according to the serial number of the target rekeying key and generate server handshake information.
[0188] The second sending module 230 is configured to send the server handshake information and a server certificate to the control unit, so that the control unit calls the security chip to authenticate the server certificate and generates a first working key in the security chip according to the target rekeying key.
[0189] The second generation module 220 is further configured to receive the client certificate of the communication module sent by the control unit, authenticate the client certificate through the quantum cryptography management service platform, and generate a second working key based on the target injection key;
[0190] The second establishing module 240 is used to establish a VPN tunnel between the communication module and the gateway device according to the first working key and the second working key, so as to transmit service data messages between the IoT terminal and the IoT service platform.
[0191] Optionally, the second generation module 220 is further used to call the authentication interface of the quantum cryptography management service platform to authenticate the client certificate; call the algorithm interface of the quantum cryptography management service platform, target the injection key, the second client random number, the second server random number, and the constant string, calculate the second master key, and calculate the second working key based on the second master key; and store the second working key in the gateway device.
[0192] Optionally, the device further comprises:
[0193] A second acquisition module is used to acquire a second service data message generated by a service module in the Internet of Things service platform;
[0194] A second encryption module is used to call the quantum cryptography management service platform, encrypt the second business data message according to the second working key, and encapsulate it into a second business data ciphertext;
[0195] The second sending module 230 is also used to send the second business data ciphertext to the communication module based on the VPN tunnel, so that the communication module calls the security chip, decapsulates and decrypts the second business data ciphertext according to the first working key, and obtains the second business data message.
[0196] Optionally, the device further comprises:
[0197] The second destruction module is used to destroy the target injection key in the quantum cryptography management service platform if it is detected that the VPN tunnel is disconnected or the connection time of the VPN tunnel exceeds a preset time.
[0198] The above-mentioned device is used to execute the method provided in the above-mentioned embodiment. Its implementation principle and technical effect are similar and will not be repeated here.
[0199] The above modules can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors, or one or more field programmable gate arrays (FPGAs). For another example, when a module is implemented by scheduling program code through a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0200] The above are only specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A secure communication method based on quantum key, characterized in that: A control unit in a communication module in an Internet of Things terminal, the method comprising: Obtaining the serial number of the target injection key from the security chip in the communication module and generating client handshake information; Sending the client handshake information to a gateway device, so that the gateway device obtains the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key and generates a server handshake message; Receive the server handshake message and server certificate sent by the gateway device; Calling the security chip to authenticate the server certificate, and generating a first working key in the security chip according to the target injection key; Sending the client certificate of the communication module to the gateway device, so that the gateway device authenticates the client certificate through the quantum cryptography management service platform and generates a second working key according to the target injection key; A VPN tunnel is established between the communication module and the gateway device based on the first working key and the second working key, for transmitting service data messages between the Internet of Things terminal and the Internet of Things service platform.
2. The method according to claim 1, characterized in that The step of obtaining the serial number of the target charging key from the security chip in the communication module and generating client handshake information includes: Determining an unused charging key from the multiple charging keys of the security chip as the target charging key, and obtaining a serial number of the target charging key; The client handshake information is generated according to the serial number of the target charging key and the device identification of the communication module.
3. The method according to claim 1, characterized in that Before obtaining the serial number of the target charging key from the security chip in the communication module and generating the client handshake information, the method further includes: Sending a key charging request to the quantum cryptography management service platform so that the quantum cryptography management service platform generates a charging key file; the charging key file includes: multiple charging keys; Obtaining the charging key file returned by the quantum cryptography management service platform; The key file is stored in the security chip.
4. The method according to claim 1, wherein The calling of the security chip to authenticate the server certificate and generating a first working key in the security chip according to the target injection key includes: Calling the authentication interface of the security chip to authenticate the server certificate; Calling the algorithm interface of the security chip to calculate a first master key based on the target charging key, the first client random number, the first server random number, and a constant string, and calculating the first working key based on the first master key; The first working key is stored in the security chip.
5. The method according to claim 1, characterized in that The method further comprises: Obtaining a first service data message generated by a service module in the Internet of Things terminal; Invoking the security chip, encrypting the first service data message according to the first working key, and encapsulating the message into a first service data ciphertext; Based on the VPN tunnel, the first business data ciphertext is sent to the gateway device, so that the gateway device calls the quantum cryptography management service platform, decapsulates and decrypts the first business data ciphertext according to the second working key, obtains the first business data message, and forwards it to the Internet of Things business platform.
6. The method according to claim 1, characterized in that The method further comprises: If it is detected that the VPN tunnel is disconnected, or the connection time of the VPN tunnel exceeds a preset time, the target injection key in the security chip is destroyed.
7. A secure communication method based on quantum key, characterized in that: Applied to a gateway device; the method includes: Receiving client handshake information sent by a control unit in a communication module in an IoT terminal, where the control unit obtains a serial number of a target charging key from a security chip in the communication module and generates the client handshake information; Obtain the target charging key from the quantum cryptography management service platform according to the serial number of the target charging key, and generate a server-side handshake message; Sending the server handshake message and the server certificate to the control unit, so that the control unit calls the security chip to authenticate the server certificate and generates a first working key in the security chip according to the target injection key; receiving a client certificate of the communication module sent by the control unit, authenticating the client certificate through the quantum cryptography management service platform, and generating a second working key according to the target injection key; A VPN tunnel is established between the communication module and the gateway device based on the first working key and the second working key, for transmitting service data messages between the Internet of Things terminal and the Internet of Things service platform.
8. The method according to claim 7, characterized in that The receiving the client certificate of the communication module sent by the control unit, authenticating the client certificate through the quantum cryptography management service platform, and generating a second working key according to the target injection key includes: Calling the authentication interface of the quantum cryptography management service platform to authenticate the client certificate; Calling the algorithm interface of the quantum cryptography management service platform, the target charging key, the second client random number, the second server random number, and the constant string, calculating the second master key, and calculating the second working key based on the second master key; The second working key is stored in the gateway device.
9. The method according to claim 7, characterized in that The method further comprises: Obtaining a second service data message generated by a service module in the Internet of Things service platform; Invoking the quantum cryptography management service platform, encrypting the second service data message according to the second working key, and encapsulating the message into a second service data ciphertext; Based on the VPN tunnel, the second business data ciphertext is sent to the communication module, so that the communication module calls the security chip, decapsulates and decrypts the second business data ciphertext according to the first working key, and obtains the second business data message.
10. The method according to claim 7, characterized in that The method further comprises: If it is detected that the VPN tunnel is disconnected, or the connection time of the VPN tunnel exceeds a preset time, the target injection key in the quantum cryptography management service platform is destroyed.
Citation Information
Patent Citations
Quantum key management method and system based on security chip carrier
CN113536362A
Implementation method and system for enhancing safety of working key based on quantum key
CN113852460A