Key updating method and device, storage medium, terminal and system

By obtaining key-associated data to determine the usage status parameters, generating quantum key update requests and encrypting transmission, it solves the problem of untimely and low security in the key update of intelligent education terminals, realizing timely update and secure storage of keys, and improving the security of data transmission.

CN120263406APending Publication Date: 2025-07-04BEIJING XUEDIRUANJIAN DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510472616.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The key update frequency of existing smart education terminals is low, resulting in low key security, risk of being deciphered, and untimely update, affecting data transmission security.

Method used

By obtaining key association data, a quantum key update request is generated when the parameters exceed the threshold, a physically uncloned security component is encrypted and sent to the server, and a new key is received and stored to the trusted platform module.

Benefits of technology

It realizes the timeliness and security of key updates, reduces the probability of key deciphering, and ensures the security and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263406A_ABST
    Figure CN120263406A_ABST
Patent Text Reader

Abstract

The invention discloses a secret key updating method and device, a storage medium, a terminal and a system, relates to the technical field of data encryption transmission, and mainly aims to solve the problem of low timeliness and safety of existing secret key updating. The method mainly comprises the steps of determining key use state parameters according to key associated data; under the condition that the key use state parameter is greater than a preset use state parameter threshold, generating a quantum key updating request according to the key associated data, and generating an encryption key through a physical unclonable security component; encrypting the quantum key updating request according to the encryption key, and sending the encrypted quantum key updating request to the server, so that the server generates and returns a newly added key according to the quantum key updating request; and receiving a key update reply sent by the server in an encrypted manner, decrypting the key update reply through the physical unclonable security component, and storing the newly-added key obtained by decryption to the trusted platform module. The method is mainly used for key updating.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption transmission, and particularly to a key update method and device, a storage medium, a terminal, and a system. Background Art

[0002] With the deep integration of technologies such as the Internet and mobile communication with the education industry, many intelligent education terminals for online education have emerged on the market. At the same time, the onlineization of education has also brought new problems. During the communication process, it is necessary not only to encrypt data such as teaching materials, teaching aids, test papers, and audio-visual courses, but also to encrypt and transmit privacy data related to user learning. The leakage of course materials will cause impacts such as copyright disputes, competitive disadvantages, and economic losses, while the leakage of user privacy information will face problems such as security risks, user loss, and regulatory penalties. Therefore, before providing online education services, a secure and efficient identity authentication and encryption transmission mechanism is an extremely basic and important link.

[0003] The encryption keys used by existing intelligent education terminals in the user identity authentication and data transmission links are mainly implemented based on symmetric keys pre-injected during the production process of terminal products. During the actual use of the terminal, due to the risk of leakage in key updates, the update frequency of keys is relatively low, and there is even a situation where they are not updated. Long-term use is likely to be deciphered, resulting in low key security. Summary of the Invention

[0004] In view of this, the present invention provides a key update method and device, a storage medium, a terminal, and a system, mainly aiming to solve the problem of low timeliness and security of existing key updates.

[0005] According to one aspect of the present invention, a key update method is provided, including:

[0006] Obtain key-associated data, and determine a key usage status parameter based on the key-associated data;

[0007] When the key usage status parameter is greater than a preset usage status parameter threshold, generate a quantum key update request based on the key-associated data, and generate an encryption key through a physically unclonable security component;

[0008] Encrypt the quantum key update request according to the encryption key to obtain an encrypted quantum key update request, and send the encrypted quantum key update request to a server, so that the server generates and returns a new key based on the encrypted quantum key update request;

[0009] Receive the key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the newly added key obtained by decryption in the trusted platform module.

[0010] Further, the key association data includes key association data corresponding to different key levels respectively. Before obtaining the key association data, the method further includes:

[0011] In response to the key call operation, obtain the global key failure quantity and the total quantity of pre-stored keys, and calculate the ratio between the global key failure quantity and the total quantity of pre-stored keys to obtain the global failed key ratio;

[0012] If the global failed key ratio is greater than the preset ratio threshold, trigger the global key update mechanism to generate a quantum key update request for the global key;

[0013] If the global failed key ratio is less than or equal to the preset ratio threshold, execute the obtaining of the key association data, and respectively for different key levels, execute the step of generating a quantum key update request according to the key association data.

[0014] Further, the key association data of any key level includes key usage data, key level, communication quality data, and communication security data. For any level of key, the determining of the key usage status parameter according to the key association data includes:

[0015] Calculate the key usage parameter according to the key usage data;

[0016] Calculate the key communication quality parameter according to the communication quality data;

[0017] Calculate the key security parameter according to the communication security data;

[0018] Calculate the key usage status parameter according to the key level, key usage parameter, key communication quality parameter, and key security parameter.

[0019] Further, the calculating of the key usage status parameter according to the key level, key usage parameter, key communication quality parameter, and key security parameter includes:

[0020] Identify from the key level mapping relationship set the key length, key update coefficient, key reuse correction coefficient, key communication quality correction coefficient, and key security correction coefficient that match the key level, where the key level mapping relationship set includes the mapping relationships between different key levels and their respective corresponding key lengths, key update coefficients, key reuse correction coefficients, key communication quality correction coefficients, and key security correction coefficients;

[0021] Calculate the key usage status parameter based on the key length, the key update coefficient, the key multiplexing correction coefficient, the key communication quality correction coefficient, the key security correction coefficient, as well as the key usage parameters, the key communication quality parameters, and the key security parameters;

[0022] Among them, the key length, the key update coefficient, the key communication quality correction coefficient, the key multiplexing correction coefficient, and the key security correction coefficient are all positively correlated with the importance level represented by the key level.

[0023] Furthermore, the key usage data includes the real-time usage duration of the key pool, the limited usage duration of the key pool, and the usage times of the keys of the corresponding level within a preset duration. The key usage parameters calculated based on the key usage data include:

[0024] Calculate the ratio between the real-time usage duration of the key pool and the limited usage duration of the key pool to obtain the key pool usage duration ratio, and take the product of the usage times, the key pool usage duration ratio, and the global invalid key ratio as the key usage parameter;

[0025] The communication quality data includes the actual average delay duration, the reference delay duration, the actual packet loss rate, and the reference packet loss rate. The key communication quality parameters calculated based on the communication quality data include:

[0026] Calculate the ratio between the actual average delay duration and the reference delay duration to obtain the delay ratio, calculate the ratio between the actual packet loss rate and the reference packet loss rate to obtain the packet loss rate ratio, and take the product of the delay ratio and the packet loss rate ratio as the key communication quality parameter;

[0027] The communication security data includes the number of different types of attack events and the weight of each type of attack event. The key security parameters calculated based on the communication security data include:

[0028] Sum up the product of the number of each type of attack event and the corresponding weight to obtain the key security parameter.

[0029] Furthermore, generating the encryption key through the physically unclonable security component includes:

[0030] Randomly obtain the first challenge information, and input the first challenge information into the physically unclonable security component to generate the first response information corresponding to the first challenge information through the physically unclonable security component, and take the first response information as the encryption key;

[0031] The key update reply carries second challenge information. Decrypting the key update reply by the physically unclonable security component includes:

[0032] Inputting the second challenge information into the physically unclonable security component to generate, by the physically unclonable security component, second response information corresponding to the second challenge information, and decrypting the key update reply according to the second response information.

[0033] Further, the quantum key update request carries first challenge information and a terminal identification identifier. The server generating and transmitting back a new key according to the encrypted quantum key update request includes:

[0034] Retrieving first response information matching the first challenge information and the terminal identification identifier, and decrypting the quantum key update request according to the first response information to obtain a key type, a key quantity, and a key length;

[0035] Normally matching, by a quantum random number generator and a quantum key distribution machine, a new key for the key type, the key quantity, and the key length;

[0036] Obtaining second challenge information and second response information matching the terminal identification identifier, encrypting the new key according to the second response information to obtain a key update reply, and transmitting the key update reply and the second challenge information back to the terminal that sent the quantum key update request.

[0037] Further, generating a quantum key update request according to the key association data includes:

[0038] Identifying, from a key length mapping relationship set, a key length and a key type matching a key level;

[0039] Determining the key quantity according to a pre-stored key quantity and a key invalidation quantity matching the key level;

[0040] Generating a quantum key update request according to the key length, the key type, and the key quantity;

[0041] Wherein, the key level includes a first-class key, a second-class key, and a third-class key with decreasing importance levels. The first-class key is used for encrypting user sensitive information, the second-class key is used for encrypting teaching auxiliary data, and the third-class key is used for encrypting user learning interaction information.

[0042] According to another aspect of the present invention, there is provided a key update device, the device includes:

[0043] An acquisition module, configured to acquire key association data and determine a key usage status parameter according to the key association data;

[0044] A generation module, configured to generate a quantum key update request according to the key association data and generate an encryption key through a physically unclonable security component when the key usage status parameter is greater than a preset usage status parameter threshold;

[0045] A sending module, configured to encrypt the quantum key update request according to the encryption key to obtain an encrypted quantum key update request, and send the encrypted quantum key update request to a server, so that the server generates and sends back a new key according to the encrypted quantum key update request;

[0046] A receiving module, configured to receive a key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the obtained new key in a trusted platform module.

[0047] According to another aspect of the present invention, there is provided a storage medium storing at least one executable instruction, and the executable instruction causes a processor to perform operations corresponding to the above key update method.

[0048] According to another aspect of the present invention, there is provided a terminal, including: a processor, a memory, a communication interface, a communication bus, a physically unclonable security component, and a trusted platform module, and the processor, the memory, the physically unclonable security component, the trusted platform module, and the communication interface complete communication with each other through the communication bus;

[0049] The memory is configured to store at least one executable instruction, and the executable instruction causes the processor to perform operations corresponding to the above key update method.

[0050] According to another aspect of the present invention, there is provided a system including a terminal and a server, and the terminal is configured to perform operations corresponding to the above key update method;

[0051] The server is configured to receive a quantum key update request sent by the terminal, retrieve a first response message based on the first challenge information and the terminal identification identifier carried in the quantum key update request; decrypt the quantum key update request according to the first response message to obtain the key type, the number of keys and the key length; normally match the newly added keys of the key type, the number of keys and the key length through a quantum random number generator and a quantum key distribution machine; obtain a second challenge information and a second response message matching the terminal identification identifier, encrypt the newly added keys according to the second response message to obtain a key update reply, and transmit the encrypted newly added keys and the second challenge information back to the terminal that sent the request.

[0052] By means of the above technical solution, the technical solution provided by the embodiment of the present invention has at least the following advantages:

[0053] The present invention provides a key update method, device, storage medium, terminal, and system. Compared with the prior art, in the embodiment of the present invention, key association data is obtained, and a key usage status parameter is determined according to the key association data; in the case where the key usage status parameter is greater than a preset usage status parameter threshold, a quantum key update request is generated according to the key association data, and an encryption key is generated through a physically unclonable security component; the quantum key update request is encrypted according to the encryption key to obtain an encrypted quantum key update request, and the encrypted quantum key update request is sent to a server, so that the server generates and transmits back newly added keys according to the encrypted quantum key update request; receive the key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the decrypted newly added keys in a trusted platform module. The accurate monitoring of the key update timing is realized, the timeliness of key update is improved. At the same time, by encrypting and decrypting the quantum key update request and the key update reply through the physically unclonable security component and storing the keys in the trusted platform module, the security of the keys can be greatly ensured.

[0054] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other objects, features and advantages of the present invention more obvious and understandable, the following specific embodiments of the present invention are specifically described. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0056] Figure 1 Shows a flowchart of a key update method provided by an embodiment of the present invention;

[0057] Figure 2 Shows a flowchart of another key update method provided by an embodiment of the present invention;

[0058] Figure 3 Shows a quantum key update system in an intelligent education service scenario provided by an embodiment of the present invention;

[0059] Figure 4 Shows a block diagram of a key update device provided by an embodiment of the present invention;

[0060] Figure 5 Shows a schematic diagram of a terminal architecture provided by an embodiment of the present invention;

[0061] Figure 6 Shows a schematic diagram of a system architecture provided by an embodiment of the present invention. Detailed implementation manners

[0062] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0063] An embodiment of the present invention provides a key update method, as Figure 1 shown, the method includes:

[0064] 101. Obtain key association data, and determine a key usage status parameter according to the key association data.

[0065] In an embodiment of the present invention, the current execution entity is a front-end server of a terminal. This terminal is configured with a Trusted Platform Module (TPM) and a Physically Unclonable Security Component. The Trusted Platform Module is a microchip that provides key security protection and has secure key generation and storage functions to prevent physical extraction of keys. In the terminal, the Trusted Platform Module is used to store keys. In scenarios of user authentication and encrypted communication, the current execution entity needs to retrieve keys from the Trusted Platform Module to encrypt the authentication information and other data to be transmitted. The Physically Unclonable Security Component is constructed based on the Physically Unclonable Function (PUF). PUF is a hardware security technology that utilizes minute differences in the chip manufacturing process to generate a unique identifier for each chip. The same input value produces different output values for different chips. In the terminal, the Physically Unclonable Security Component is used to generate keys for encrypting quantum key update requests and decrypting key update responses during the key update process. Among them, the terminal corresponding to the current execution entity is an intelligent education terminal, which can specifically be terminal devices such as interactive intelligent whiteboards, student tablets, virtual reality headsets, robot teachers, intelligent schoolbags, etc. applied to intelligent education scenarios. The embodiments of the present invention do not make specific limitations.

[0066] During the process of determining whether a key needs to be updated, the current execution entity uses the key usage status parameter as the basis for determining whether the key needs to be updated. The key usage status parameter is a calculated value obtained from key-related data. Therefore, in order to determine whether a key needs to be updated, the current execution entity needs to first obtain the key-related data to determine the key usage status parameter based on the key-related data. Among them, the key-related data is data related to the usage information and usage environment of the key. For example, the key usage amount, the communication quality of key usage, the security threats of key usage, etc. The embodiments of the present invention do not make specific limitations. Determining the key usage status parameter through data closely related to the key such as the key usage amount, the communication quality of key usage, and the security threats of key usage, and using the key usage status parameter as the basis for key update can ensure the timeliness of key update, thereby greatly reducing the probability of the key being cracked and improving the security of the key.

[0067] 102. When the key usage status parameter is greater than the preset usage status parameter threshold, generate a quantum key update request based on the key-related data, and generate an encryption key through the Physically Unclonable Security Component.

[0068] In an embodiment of the present invention, when the key usage status parameter is greater than the preset usage status parameter threshold, it indicates that the current key needs to be updated. Therefore, a quantum key update request is generated to request the server to generate a new key. When the key usage status parameter is less than or equal to the preset usage status parameter threshold, it indicates that the current key does not need to be updated temporarily, and only the change of the key usage status parameter needs to be continuously monitored. That is, the key-related data is returned, and for different key levels, the step of generating a quantum key update request based on the key-related data is executed. Among them, the preset usage status parameter threshold can be configured based on the specific situation of whether the key corresponding to the historical key usage status parameter needs to be updated, and can be customized according to specific application scenarios. The embodiment of the present invention does not make specific limitations.

[0069] 103. Encrypt the quantum key update request according to the encryption key to obtain the encrypted quantum key update request, and send the encrypted quantum key update request to the server, so that the server generates and transmits back a new key according to the encrypted quantum key update request.

[0070] In an embodiment of the present invention, the key generation process is executed by the server. Therefore, after generating the quantum key update request, the quantum key update request is sent to the server. To ensure the security of the key update process, an encryption key also needs to be generated through a physically unclonable security component, so that after encrypting the quantum key update request with the encryption key, it is transmitted to the server. Among them, the server is a server configured with a key management system and a business system, which can be a local server or a cloud server. The embodiment of the present invention does not make specific limitations. The business system is a service system that provides relevant information for the terminal. In a specific education application scenario, the business system can be an education service system, and the education service system is used to authenticate the user account information during the user identity authentication process and provide relevant teaching auxiliary resources during the encrypted communication process.

[0071] 104. Receive the key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the decrypted new key in the trusted platform module.

[0072] In an embodiment of the present invention, after the server receives a quantum key update request, the server generates corresponding new keys according to the quantum key update request, and after encrypting the new keys, sends them back to the current execution entity in the form of a key update reply. After receiving the key update reply, the current execution entity decrypts it to obtain the new keys, and stores the new keys in the trusted platform module to ensure the security of key storage. Among them, the quantum key update request carries a unique identification identifier of the terminal. During the process of encrypting the new keys by the server, a key matching the physically unclonable security component configured for the current terminal is retrieved based on the unique identification identifier, so that on the primary side of the current terminal, the key update reply can be decrypted.

[0073] It should be noted that by storing keys and encrypting and sending quantum key update requests through a terminal configured with a trusted platform module and a physically unclonable security component, the security of key updates can be ensured from the dimensions of key storage and key transmission.

[0074] In an embodiment of the present invention, for further illustration and limitation, as Figure 2 shown, the step of determining the key usage status parameter according to the key association data includes:

[0075] 201. Calculate a key usage parameter according to the key usage data.

[0076] 202. Calculate a key communication quality parameter according to the communication quality data.

[0077] 203. Calculate a key security parameter according to the communication security data.

[0078] 204. Calculate a key usage status parameter according to the key level, key usage parameter, key communication quality parameter, and key security parameter.

[0079] In an embodiment of the present invention, the key association data includes key association data corresponding to different key levels respectively. That is, for keys of different levels, their key association data is respectively counted, and according to the key association data of keys of different levels, the corresponding key usage status parameters are respectively calculated to obtain the key usage status parameters corresponding to different key levels. Since the usage situations (reuse frequency, usage frequency) of keys of different levels are different, and the security requirements are also different, therefore, their update frequencies are also different. By calculating the key usage status parameters for keys of different levels respectively and judging whether to update respectively, the update of keys can be made more targeted and flexible, thereby improving the timeliness of key updates and the applicability to key updates in multiple scenarios.

[0080] Among them, the key association data of any key level includes key usage data, key level, communication quality data, and communication security data. That is, the key usage status parameter is determined based on data from multiple aspects such as key usage, key basic information, communication quality, and communication security threats, fully considering the impact of various factors on key security to ensure the accuracy and timeliness of the key update timing.

[0081] In an embodiment of the present invention, for further illustration and limitation, the step of determining the key usage status parameter according to the key association data includes:

[0082] Calculating the key usage status parameter based on the key level, key usage parameter, key communication quality parameter, and key security parameter, including:

[0083] Identifying from the key level mapping relationship set the key length, key update coefficient, key reuse correction coefficient, key communication quality correction coefficient, and key security correction coefficient that match the key level;

[0084] Calculating the key usage status parameter based on the key length, the key update coefficient, the key reuse correction coefficient, the key communication quality correction coefficient, and the key security correction coefficient, as well as the key usage parameter, the key communication quality parameter, and the key security parameter.

[0085] In the embodiment of the present invention, keys of different levels also correspond to different correction coefficients in each dimension of influencing factors. That is, the key level mapping relationship set includes the mapping relationships between different key levels and their corresponding key lengths, key update coefficients, key reuse correction coefficients, key communication quality correction coefficients, and key security correction coefficients. Among them, the key level mapping relationship set is a pre-constructed mapping relationship set, and the division of levels and the specific values of the key lengths, key update coefficients, key reuse correction coefficients, key communication quality correction coefficients, and key security correction coefficients corresponding to different levels can be customized according to specific application scenarios, and are not specifically limited in the embodiment of the present invention.

[0086] It should be noted that the mapping relationships among the key length, key update coefficient, key communication quality correction coefficient, key reuse correction coefficient, and key security correction coefficient are all positively correlated with the importance level characterized by the key level. That is, the more important the key level is, the higher the security requirements are, the longer the corresponding key length is, and the values of the corresponding key update coefficient, key communication quality correction coefficient, key reuse correction coefficient, and key security correction coefficient are larger than those of lower-level keys. Since key update is triggered when the key usage status parameter is greater than the preset usage status parameter threshold, by setting correction coefficients positively correlated with the key level, the key usage status parameter values calculated for keys with higher security levels can be made larger, making it easier to trigger key updates, thus enabling keys with higher security and importance levels to be updated more frequently.

[0087] In an embodiment of the present invention, for further illustration and limitation, calculating the key usage parameter based on the key usage data includes:

[0088] Calculating the ratio between the real-time usage duration of the key pool and the restricted usage duration of the key pool to obtain the key pool usage duration ratio, and taking the product of the usage times, the key pool usage duration ratio, and the global invalid key ratio as the key usage parameter;

[0089] Calculating the key communication quality parameter based on the communication quality data includes:

[0090] Calculating the ratio between the actual average delay duration and the reference delay duration to obtain the delay ratio, calculating the ratio between the actual packet loss rate and the reference packet loss rate to obtain the packet loss rate ratio, and taking the product of the delay ratio and the packet loss rate ratio as the key communication quality parameter;

[0091] Calculating the key security parameter based on the communication security data includes:

[0092] Summing up the products of the number of each type of attack event and the corresponding weight to obtain the key security parameter.

[0093] In an embodiment of the present invention, the key usage data includes the real-time usage duration of the key pool, the restricted usage duration of the key pool, and the usage times of keys of the corresponding level within a preset duration. The calculation formula of the key usage parameter is expressed as:

[0094]

[0095] Among them, σ u represents the key usage parameter, k u represents the global key invalidation quantity, k c represents the pre-stored key quantity, u fIndicates the number of times the corresponding - level key is used within the preset duration, \(t\) represents the real - time usage duration of the key pool, \(t\) max Indicates the restricted usage duration of the key pool.

[0096] The communication quality data includes the actual average latency duration, the reference latency duration, the actual packet loss rate, and the reference packet loss rate. The calculation formula for the key communication quality parameter is expressed as:

[0097]

[0098] Among them, \(\sigma\) t Indicates the key communication quality parameter, \(d\) avg Indicates the actual average latency duration, \(d\) stand Indicates the reference latency duration, \(p\) represents the actual packet loss rate, \(p\) stand Indicates the reference packet loss rate.

[0099] The communication security data includes the number of attack events of different categories and the weight of each category of attack event. The calculation formula for the key security parameter is expressed as:

[0100]

[0101] Among them, \(\sigma\) s Indicates the key security parameter, \(j\) represents the \(j\) - th category of attack event, \(n\) represents the total number of attack event categories, \(\omega\) j Indicates the weight of the \(j\) - th category of attack event, \(A\) j Indicates the number of the \(j\) - th category of attack event.

[0102] According to the above formula, the calculation formula for the key usage status parameter is expressed as:

[0103]

[0104] Among them, \(\alpha\) i Indicates the update coefficient of the \(i\) - th level key, \(l\) i Indicates the key length of the \(i\) - th level key, \(\beta\) i Indicates the key multiplexing correction coefficient of the \(i\) - th level key, \(\lambda\) i Indicates the key communication quality correction coefficient of the \(i\) - th level key, \(u\) i Indicates the key security correction coefficient of the \(i\) - th level key.

[0105] In an embodiment of the present invention, for further illustration and limitation, before obtaining the key - associated data, the method further includes:

[0106] In response to the key - call operation, obtain the global key failure quantity and the total quantity of pre - stored keys, and calculate the ratio between the global key failure quantity and the total quantity of pre - stored keys to obtain the global failed - key ratio;

[0107] If the proportion of the global invalid keys is greater than a preset proportion threshold, trigger a global key update mechanism to generate a quantum key update request for the global key;

[0108] If the proportion of the global invalid keys is less than or equal to the preset proportion threshold, execute the step of obtaining key association data, and respectively execute the step of generating a quantum key update request according to the key association data for different key levels.

[0109] In an embodiment of the present invention, before finely monitoring each level of keys respectively, as an overall strategy, the overall usage of keys can also be monitored, and all levels of keys can be updated as a whole. That is, according to the number of used keys (the number of global invalid keys) of all levels of keys and the total number of keys pre-stored in the current terminal, calculate the proportion of the current invalid keys in the total number of keys (the proportion of global invalid keys). In this process, without considering the key levels, all levels of keys are monitored as a whole. When the proportion of global invalid keys is greater than a preset proportion threshold, trigger a global key update mechanism to generate a quantum key update request for the global key. Among them, the preset proportion threshold can be customized according to specific application scenarios. For example, 90%, 85%, etc., and the embodiment of the present invention does not make specific limitations. The quantum key update request for the global key can be a single request or a set including quantum key update requests for each level, and the embodiment of the present invention does not make specific limitations. The transmission of the quantum key update request, the generation of new keys, and the transmission of the key update reply are the same as the corresponding processes of any level of keys, and will not be elaborated here. By calculating the proportion of global invalid keys, on the basis of monitoring the update of a single level of keys, the overall monitoring of global keys can be realized, and the comprehensive monitoring of key updates can be realized.

[0110] In an embodiment of the present invention, for further illustration and limitation, the generation of an encryption key by a physically unclonable security component includes:

[0111] Randomly obtain a first challenge message, and input the first challenge message into the physically unclonable security component, so as to generate a first response message corresponding to the first challenge message through the physically unclonable security component, and use the first response message as the encryption key;

[0112] The key update reply carries a second challenge message. The decryption of the key update reply by the physically unclonable security component includes:

[0113] Input the second challenge information into the physical unclonable security component to generate a second response information corresponding to the second challenge information through the physical unclonable security component, and decrypt the key update reply according to the second response information.

[0114] In the embodiments of the present invention, the encrypted transmission of the quantum key update request and the key update reply are both realized through the challenge-response pair. On the terminal side, the encryption process of the quantum key update request includes: the current execution entity randomly obtains a challenge information, i.e., the first challenge information, to generate a first response information corresponding to the first challenge information based on the physical unclonable security component, and encrypts the quantum key update request with the first response information as the encryption key. After the encryption is completed, the first challenge information, the terminal identification identifier, and the encrypted quantum key update request are sent to the server in plain text, so that the server can retrieve the first response information according to the first challenge information and the terminal identification identifier, thereby realizing the decryption of the quantum key update request. The decryption process of the key update reply includes: generating a second response information corresponding to the second challenge information through the physical unclonable security component, so that the current execution entity decrypts the key update reply according to the second response information.

[0115] In an embodiment of the present invention, for further illustration and limitation, the server generates and returns a new key according to the encrypted quantum key update request, including:

[0116] Retrieve the first response information that matches the first challenge information and the terminal identification identifier, and decrypt the quantum key update request according to the first response information to obtain the key type, the number of keys, and the key length;

[0117] Normally match a new key of the key type, the number of keys, and the key length through a quantum random number generator and a quantum key distribution machine;

[0118] Obtain the second challenge information and the second response information that match the terminal identification identifier, encrypt the new key according to the second response information to obtain a key update reply, and return the key update reply and the second challenge information to the terminal that sends the quantum key update request.

[0119] In the embodiments of the present invention, the quantum key update request carries the first challenge information and the terminal identification identifier. The server stores the challenge-response pairs corresponding to different terminal identification identifiers, and the first response information for decrypting the quantum key update request can be matched according to the first challenge information and the terminal identification identifier. After generating the new key, a pair of second challenge information and second response information are retrieved according to the terminal identification identifier to encrypt the new key through the second response information.

[0120] It should be noted that the server is also configured with a quantum random number generator and a quantum key distribution machine. The quantum random number generator generates random numbers for subsequent key production based on optical quantum polarization information. The quantum key distribution machine uses the generated random numbers to negotiate and generate binary strings between the key management system and the service system as quantum keys. Each produced key has a key identifier, and this identifier is used to indicate the encryption key used during the communication process. Although the key identifier is bound to the key, the identifier content has nothing to do with the key content. In the embodiments of the present invention, by splicing together the production timestamp of the key, the sequence number, and the identification identifier of the device, and performing a SHA256 hash calculation on the splicing result, the calculation result is used as the key identifier. Synchronously, the key identifiers of these newly added keys are bound to the identification identifier of the device and stored in the key management system.

[0121] In a specific educational application scenario, the service system is an education service system, the terminal is an intelligent education terminal, and the schematic diagram of the system architecture between the server and the terminal is as Figure 3 shown. By using quantum symmetric keys generated from true random numbers based on optical quantum polarization information to replace the asymmetric keys widely used in existing terminals, the security of information transmission is further ensured.

[0122] In an embodiment of the present invention, for further illustration and limitation, generating a quantum key update request based on the key association data includes:

[0123] Identifying the key length and key type that match the key level from the key length mapping relationship set;

[0124] Determining the key quantity according to the pre-stored key quantity and key failure quantity that match the key level;

[0125] Generating a quantum key update request based on the key length, the key type, and the key quantity.

[0126] In the embodiments of the present invention, the keys are classified according to the key usage scenarios for security levels. Class I keys are used for the most important scenarios, Class II keys are used for the less important scenarios, and Class III keys are used for important scenarios. That is, the key levels include Class I keys, Class II keys, and Class III keys, which represent a decreasing order of importance. In specific application scenarios, Class I keys can be used to encrypt user-sensitive information, such as account passwords, ID card information, privacy information, etc. Class II keys can be used to encrypt teaching auxiliary data, such as data involving copyright information like test papers, textbooks, course data, etc. Class III keys can be used to encrypt user learning interaction information, such as user's answer data, draft data, learning progress, etc.

[0127] The quantum key update request includes the key length, key type, and key quantity. The key length is the string length of the key, the key type indicates what kind of quantum key it is, and the key quantity is the number of new keys to be generated. The key length and key type correspond to the key level. The higher the key level, the longer the key length and the higher the complexity corresponding to the key type. Since the key quantity is limited by the hardware storage configuration of the terminal device, each level of key corresponds to a corresponding quantity of pre-stored keys. The number of new keys to be added can be equal to the number of expired keys or greater than the number of expired keys, but at most it cannot exceed the quantity of pre-stored keys. When the number of new keys is equal to the number of expired keys, the pre-stored unused keys can continue to be used; when the number of new keys is greater than the number of expired keys, some or all of the pre-stored unused keys will be overwritten.

[0128] The present invention provides a key update method. Compared with the prior art, in the embodiments of the present invention, key association data is obtained, and a key usage status parameter is determined based on the key association data; in the case where the key usage status parameter is greater than a preset usage status parameter threshold, a quantum key update request is generated based on the key association data, and an encryption key is generated through a physically unclonable security component; the quantum key update request is encrypted based on the encryption key to obtain an encrypted quantum key update request, and the encrypted quantum key update request is sent to the server so that the server generates and returns new keys based on the encrypted quantum key update request; the key update reply encrypted and sent by the server is received, the key update reply is decrypted through the physically unclonable security component, and the newly added keys obtained by decryption are stored in the trusted platform module. It realizes the accurate monitoring of the key update timing, improves the timeliness of key update. At the same time, by encrypting and decrypting the quantum key update request and the key update reply through the physically unclonable security component and storing the keys in the trusted platform module, the security of the keys can be greatly ensured.

[0129] Further, as an implementation of the method shown above Figure 1 As shown Figure 4 As shown, the embodiments of the present invention provide a key update device, and the device includes:

[0130] An acquisition module 31, configured to acquire key association data and determine a key usage status parameter based on the key association data;

[0131] A generation module 32, configured to generate a quantum key update request based on the key association data and generate an encryption key through a physically unclonable security component in the case where the key usage status parameter is greater than a preset usage status parameter threshold;

[0132] A sending module 33, configured to encrypt a quantum key update request according to the encryption key, obtain the encrypted quantum key update request, and send the encrypted quantum key update request to a server, so that the server generates and back-transmits a new key according to the encrypted quantum key update request;

[0133] A receiving module 34, configured to receive a key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the obtained new key in the trusted platform module.

[0134] Further, the apparatus further includes:

[0135] A first calculation module, configured to, in response to a key call operation, obtain the global key failure quantity and the total pre-stored keys, and calculate a ratio between the global key failure quantity and the total pre-stored keys to obtain a global failed key ratio;

[0136] A first comparison module, configured to, if the global failed key ratio is greater than a preset ratio threshold, trigger a global key update mechanism to generate a quantum key update request for the global key;

[0137] A second comparison module, configured to, if the global failed key ratio is less than or equal to the preset ratio threshold, execute the step of obtaining key association data, and respectively for different key levels, execute the step of generating a quantum key update request according to the key association data.

[0138] Further, the obtaining module 31 includes:

[0139] A first calculation unit, configured to calculate a key usage parameter according to the key usage data;

[0140] A second calculation unit, configured to calculate a key communication quality parameter according to the communication quality data;

[0141] A third calculation unit, configured to calculate a key security parameter according to the communication security data;

[0142] A fourth calculation unit, configured to calculate a key usage status parameter according to the key level, the key usage parameter, the key communication quality parameter, and the key security parameter.

[0143] Further, in a specific application scenario, the fourth calculation unit is specifically configured to identify, from the key level mapping relationship set, a key length, a key update coefficient, a key multiplexing correction coefficient, a key communication quality correction coefficient, and a key security correction coefficient that match the key level, where the key level mapping relationship set includes mapping relationships between different key levels and their respective corresponding key lengths, key update coefficients, key multiplexing correction coefficients, key communication quality correction coefficients, and key security correction coefficients;

[0144] Calculate a key usage status parameter based on the key length, the key update coefficient, the key multiplexing correction coefficient, the key communication quality correction coefficient, and the key security correction coefficient, as well as the key usage parameters, the key communication quality parameters, and the key security parameters;

[0145] Among them, the key length, the key update coefficient, the key communication quality correction coefficient, the key multiplexing correction coefficient, and the key security correction coefficient are all positively correlated with the importance level represented by the key level.

[0146] Further, the first calculation unit is specifically configured to calculate the ratio between the real-time usage duration of the key pool and the limited usage duration of the key pool to obtain the key pool usage duration ratio, and use the product of the usage times, the key pool usage duration ratio, and the global failed key ratio as the key usage parameter;

[0147] The second calculation unit is specifically configured to calculate the ratio between the actual average delay duration and the reference delay duration to obtain the delay ratio, calculate the ratio between the actual packet loss rate and the reference packet loss rate to obtain the packet loss rate ratio, and use the product of the delay ratio and the packet loss rate ratio as the key communication quality parameter;

[0148] The third calculation unit is specifically configured to sum the products of the number of each type of attack event and the corresponding weight to obtain the key security parameter.

[0149] Further, the generation module 32 includes:

[0150] A first generation unit, configured to randomly obtain a first challenge message, and input the first challenge message into the physically unclonable security component, so as to generate a first response message corresponding to the first challenge message through the physically unclonable security component, and use the first response message as the encryption key;

[0151] A second generation unit, configured to input the second challenge message into the physically unclonable security component, so as to generate a second response message corresponding to the second challenge message through the physically unclonable security component, and decrypt the key update reply according to the second response message.

[0152] Further, the receiving module includes:

[0153] Receiving a key update reply sent by the server, the generation process of the key update reply includes: retrieving and matching the first challenge information and the first response information of the terminal identification identifier, and decrypting the quantum key update request according to the first response information to obtain the key type, the number of keys, and the key length;

[0154] Normally matching the newly added keys of the key type, the number of keys, and the key length through a quantum random number generator and a quantum key distribution machine;

[0155] Obtaining the second challenge information and the second response information that match the terminal identification identifier, encrypting the newly added keys according to the second response information to obtain a key update reply, and transmitting the key update reply and the second challenge information back to the terminal that sent the quantum key update request.

[0156] Further, the generating module 32 includes:

[0157] An identification unit, configured to identify the key length and the key type that match the key level from the key length mapping relationship set;

[0158] A determination unit, configured to determine the number of keys according to the pre-stored number of keys and the number of expired keys that match the key level;

[0159] A third generating unit, configured to generate a quantum key update request according to the key length, the key type, and the number of keys;

[0160] Wherein, the key levels include a first-class key, a second-class key, and a third-class key whose importance levels decrease in sequence. The first-class key is used to encrypt user sensitive information, the second-class key is used to encrypt teaching assistant data, and the third-class key is used to encrypt user learning interaction information.

[0161] Further, according to another aspect of the present invention, a storage medium is provided. At least one executable instruction is stored in the storage medium, and the executable instruction enables the processor to perform operations corresponding to the above key update method.

[0162] Further, Figure 5 The structural schematic diagram of a terminal provided by an embodiment of the present invention is shown. The specific implementation of the terminal is not limited in the specific embodiments of the present invention.

[0163] As Figure 5As shown, the terminal may include: a processor 402, a communications interface 404, a memory 406, a physically unclonable security component 412, a trusted platform module 414, and a communication bus 408.

[0164] Among them: The processor 402, the communication interface 404, and the memory 406 communicate with each other through the communication bus 408.

[0165] The communication interface 404 is used for network communication with other devices such as clients or other servers.

[0166] The processor 402 is used to execute the program 410, and specifically can execute the relevant steps in the above data query method embodiments.

[0167] Specifically, the program 410 may include program code, and the program code includes computer operation instructions.

[0168] The processor 402 may be a central processing unit CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention. One or more processors included in the terminal may be of the same type of processor, such as one or more CPUs; or may be of different types of processors, such as one or more CPUs and one or more ASICs.

[0169] The memory 406 is used to store the program 410. The memory 406 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory.

[0170] According to an embodiment of the present invention, a system is provided, as Figure 6 shown in the schematic architecture diagram. The system includes a terminal 400 and a server 500;

[0171] The terminal 400 is used to perform the operations corresponding to the above key update method;

[0172] The server 500 is configured to receive a quantum key update request sent by the terminal, and retrieve a first response message based on the first challenge information and the terminal identification identifier carried in the quantum key update request; decrypt the quantum key update request according to the first response message to obtain the key type, the number of keys, and the key length; normally match the newly added keys of the key type, the number of keys, and the key length through a quantum random number generator and a quantum key distribution machine; obtain a second challenge information and a second response message that match the terminal identification identifier, encrypt the newly added keys according to the second response message to obtain a key update reply, and send the encrypted newly added keys and the second challenge information back to the terminal that sent the request.

[0173] The present invention provides a system. Compared with the prior art, in the embodiment of the present invention, the terminal obtains key association data, and determines a key usage status parameter according to the key association data; when the key usage status parameter is greater than a preset usage status parameter threshold, a quantum key update request is generated according to the key association data, and an encryption key is generated through a physically unclonable security component; the quantum key update request is encrypted according to the encryption key to obtain an encrypted quantum key update request, and the encrypted quantum key update request is sent to the server, so that the server generates and sends back newly added keys according to the encrypted quantum key update request; receive the key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the decrypted newly added keys in a trusted platform module. The accurate monitoring of the key update timing is realized, the timeliness of key update is improved. At the same time, the physically unclonable security component is used to encrypt and decrypt the quantum key update request and the key update reply, and the key is stored in the trusted platform module, which can greatly ensure the security of the key.

[0174] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described herein can be executed in a different order, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.

[0175] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A key update method, characterized in that Including: Obtain key - associated data, and determine a key usage status parameter based on the key - associated data; When the key usage status parameter is greater than a preset usage status parameter threshold, generate a quantum key update request based on the key - associated data, and generate an encryption key through a physically unclonable security component; Encrypt the quantum key update request based on the encryption key to obtain an encrypted quantum key update request, and send the encrypted quantum key update request to a server so that the server generates and back - transmits a new key based on the encrypted quantum key update request; Receive a key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the obtained new key in a trusted platform module.

2. The method according to claim 1, characterized in that The key - associated data includes key - associated data corresponding to different key levels. Before obtaining the key - associated data, the method further includes: In response to a key call operation, obtain the global key failure quantity and the total pre - stored keys, and calculate the ratio between the global key failure quantity and the total pre - stored keys to obtain the global failed key ratio; If the global failed key ratio is greater than a preset ratio threshold, trigger a global key update mechanism to generate a quantum key update request for the global key; If the global failed key ratio is less than or equal to the preset ratio threshold, execute the step of obtaining the key - associated data, and for each different key level, execute the step of generating a quantum key update request based on the key - associated data.

3. The method according to claim 2, characterized in that, The key - associated data of any key level includes key usage data, key level, communication quality data, and communication security data. For any level of key, determining the key usage status parameter based on the key - associated data includes: Calculate a key usage parameter based on the key usage data; Calculate a key communication quality parameter based on the communication quality data; Calculate a key security parameter based on the communication security data; Calculate a key usage status parameter based on the key level, key usage parameter, key communication quality parameter, and key security parameter.

4. The method according to claim 3, wherein Calculating the key usage status parameter based on the key level, key usage parameter, key communication quality parameter, and key security parameter includes: Identify, from a key - level mapping relationship set, a key length, a key update coefficient, a key multiplexing correction coefficient, a key communication quality correction coefficient, and a key security correction coefficient that match the key level, where the key - level mapping relationship set includes the mapping relationships between different key levels and their respective corresponding key lengths, key update coefficients, key multiplexing correction coefficients, key communication quality correction coefficients, and key security correction coefficients; Calculate a key usage status parameter based on the key length, the key update coefficient, the key multiplexing correction coefficient, the key communication quality correction coefficient, the key security correction coefficient, and the key usage parameter, the key communication quality parameter, and the key security parameter; Among them, the key length, the key update coefficient, the key communication quality correction coefficient, the key multiplexing correction coefficient, and the key security correction coefficient are all positively correlated with the importance level represented by the key level.

5. The method according to claim 3, characterized in that, The key usage data includes the real-time usage duration of the key pool, the limited usage duration of the key pool, and the usage times of the keys of the corresponding level within a preset duration. The key usage parameters calculated based on the key usage data include: Calculating the ratio between the real-time usage duration of the key pool and the limited usage duration of the key pool to obtain the key pool usage duration ratio, and taking the product of the usage times, the key pool usage duration ratio, and the global invalid key ratio as the key usage parameters; The communication quality data includes the actual average delay duration, the reference delay duration, the actual packet loss rate, and the reference packet loss rate. The key communication quality parameters calculated based on the communication quality data include: Calculating the ratio between the actual average delay duration and the reference delay duration to obtain the delay ratio, calculating the ratio between the actual packet loss rate and the reference packet loss rate to obtain the packet loss rate ratio, and taking the product of the delay ratio and the packet loss rate ratio as the key communication quality parameters; The communication security data includes the number of different types of attack events and the weight of each type of attack event. The key security parameters calculated based on the communication security data include: Performing a summation process on the product of the number of each type of attack event and the corresponding weight to obtain the key security parameters.

6. The method according to claim 1, wherein The generation of the encryption key by the physically unclonable security component includes: Randomly obtaining a first challenge message, and inputting the first challenge message into the physically unclonable security component to generate a first response message corresponding to the first challenge message through the physically unclonable security component, and taking the first response message as the encryption key; The key update reply carries a second challenge message. The decryption of the key update reply by the physically unclonable security component includes: Inputting the second challenge message into the physically unclonable security component to generate a second response message corresponding to the second challenge message through the physically unclonable security component, and decrypting the key update reply based on the second response message.

7. The method according to claim 6, wherein The quantum key update request carries a first challenge message and a terminal identification identifier. The server generates and transmits back a new key based on the encrypted quantum key update request, including: Retrieving a first response message that matches the first challenge message and the terminal identification identifier, and decrypting the quantum key update request based on the first response message to obtain the key type, the key quantity, and the key length; Normally matching the new keys of the key type, the key quantity, and the key length through a quantum random number generator and a quantum key distribution machine; Obtain the second challenge information and the second response information that match the terminal identification identifier, encrypt the newly added key according to the second response information to obtain a key update reply, and send the key update reply and the second challenge information back to the terminal that sent the quantum key update request.

8. The method according to claim 1, characterized in that The key association data includes a key level. The generating of the quantum key update request according to the key association data includes: Identify the key length and key type that match the key level from the key length mapping relationship set; Determine the key quantity according to the pre-stored key quantity and key invalidation quantity that match the key level; Generate a quantum key update request according to the key length, the key type, and the key quantity; Wherein, the key level includes a first-class key, a second-class key, and a third-class key whose importance degrees decrease in sequence. The first-class key is used to encrypt user sensitive information, the second-class key is used to encrypt teaching auxiliary data, and the third-class key is used to encrypt user learning interaction information.

9. A key update device, characterized in that, The device includes: An acquisition module, configured to acquire key association data and determine a key usage status parameter according to the key association data; A generation module, configured to, when the key usage status parameter is greater than a preset usage status parameter threshold, generate a quantum key update request according to the key association data and generate an encryption key through a physically unclonable security component; A sending module, configured to encrypt the quantum key update request according to the encryption key to obtain an encrypted quantum key update request, and send the encrypted quantum key update request to the server, so that the server generates and sends back a newly added key according to the encrypted quantum key update request; A receiving module, configured to receive the key update reply encrypted and sent by the server, decrypt the key update reply through the physically unclonable security component, and store the newly added key obtained by decryption in the trusted platform module.

10. A storage medium, in which at least one executable instruction is stored, and the executable instruction causes the processor to perform the operations corresponding to the key update method according to any one of claims 1-8.

11. A terminal, characterized in that, The terminal includes: a processor, a memory, a communication interface, a communication bus, a physically unclonable security component, and a trusted platform module. The processor, the memory, the physically unclonable security component, the trusted platform module, and the communication interface complete communication with each other through the communication bus; The memory is used to store at least one executable instruction, and the executable instruction causes the processor to perform the operations corresponding to the key update method according to any one of claims 1-8.

12. A system, characterized in that, The system includes a terminal and a server; The terminal is configured to perform the operations corresponding to the key update method according to any one of claims 1-8; The server is configured to receive the quantum key update request sent by the terminal, and retrieve the first response information according to the first challenge information and the terminal identification identifier carried in the quantum key update request; decrypt the quantum key update request according to the first response information to obtain the key type, the key quantity, and the key length; New keys that match the key type, the number of keys, and the key length through a quantum random number generator and a quantum key distribution machine; obtain a second challenge message and a second response message that match the terminal identification identifier, encrypt the new keys according to the second response message to obtain a key update reply, and transmit the encrypted new keys and the second challenge message back to the terminal that sent them.