Quantum encryption authentication method and electronic equipment
Through the integrated quantum encryption method of quantum middleware SDK, the security risks of pre-arranged keys in financial data transmission are solved, efficient, secure distribution and automated management of quantum keys are realized, and the security and reliability of data transmission are improved.
Patent Information
- Application Number
- CN202510382320.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, the security risks caused by the pre-arrangement of the key during the financial data transmission process, and the lack of the security and real-time update mechanism of the keys, resulting in the risk of leakage of the communication process.
The modularly designed quantum middleware SDK integrates quantum encryption methods and distributes keys through the quantum security service platform to achieve one-time encryption, resists quantum computer cracking attacks, integrates key generation, storage, distribution and encryption and decryption processes, and improves security and flexibility.
It improves the security and reliability of the financial business system, avoids the security risks caused by key leakage, realizes efficient, secure distribution and automated management of quantum keys, and reduces labor costs.
Smart Images

Figure CN120281520A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data encryption technologies, and in particular to a quantum encryption authentication method and an electronic device. Background Art
[0002] With the continuous development of network technologies, the security during data transmission has become particularly important. In the field of financial data, since financial data involves a large amount of sensitive information and financial transactions, it is crucial to protect the security and privacy of this data. Data encryption is an effective measure that can ensure that data is properly protected during transmission and storage, and helps financial institutions comply with relevant laws and regulations and build customer trust.
[0003] In related technologies, when a financial business system provides data query services to external customers, during the authentication and encryption processes, data is transmitted based on the Hypertext Transfer Protocol. The transmitted data includes the business serial number of the business system, the client identity identifier, and the signature string, etc. These data are encrypted by a classical symmetric encryption algorithm, and the key is pre-shared, randomly generated by the system and fixed in the configuration file. This makes the key in related technologies pre-agreed, and once the key is leaked, security risks are likely to occur. Summary of the Invention
[0004] The present disclosure provides a quantum encryption authentication method and an electronic device.
[0005] According to a first aspect of the present disclosure, there is provided a quantum encryption authentication method, which is applied to a terminal. The terminal includes a first financial application module and a first quantum middleware SDK. The method includes:
[0006] In response to a data query operation, the first financial application module sends a first data query request to the first quantum middleware SDK;
[0007] The first quantum middleware SDK authenticates the received first data query request. In the case where the authentication is passed, the first data query request is encrypted to generate an encrypted data packet, and a second data query request including the encrypted data packet is sent to the first financial application module; wherein, the first quantum middleware SDK obtains a key distributed by a quantum security service platform, which is respectively used for authenticating and encrypting the first data query request;
[0008] The first financial application module receives the second data query request and sends the second data query request to the server.
[0009] According to a second aspect of the present disclosure, there is provided a quantum encryption authentication method, which is applied to a server. The server includes a second financial application module and a second quantum middleware SDK. The method includes:
[0010] The second financial application module receives a second data query request sent by a terminal and sends the second data query request to the second quantum middleware SDK; wherein, the second data query request includes an encrypted data packet.
[0011] The second quantum middleware SDK authenticates the received second data query request. When the authentication is passed, it decrypts the encrypted data packet based on the key obtained from the quantum security service platform and sends the decrypted first data query request to the second financial application module.
[0012] The second financial application module obtains a data query result based on the first data query request, encrypts the data query result, and sends the encrypted data query result to the terminal.
[0013] According to a third aspect of the present disclosure, an electronic device is provided. The electronic device includes: a memory and a processor. A computer program is stored on the memory. When the electronic device is a terminal, the processor executes the method corresponding to the first aspect; when the electronic device is a server, the processor executes the method corresponding to the second aspect.
[0014] The quantum encryption authentication method and the electronic device provided by the embodiments of the present disclosure integrate the authentication and encryption functions during data transmission into the first quantum middleware SDK, which is beneficial to the maintenance of keys. And the first quantum middleware SDK will obtain the keys distributed by the quantum security service platform and authenticate and encrypt the first data query request based on the keys obtained from the quantum security service platform. There is no need to pre-agree on keys, which can avoid the security risks caused by the leakage of keys, and thus can greatly improve the security during data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In the following description of exemplary embodiments with reference to the accompanying drawings, more details, features and advantages of the present disclosure are disclosed. In the drawings:
[0016] Figure 1 is a schematic diagram of a system architecture provided by an exemplary embodiment of the present disclosure;
[0017] Figure 2 is a flowchart of a quantum encryption authentication method provided by an exemplary embodiment of the present disclosure;
[0018] Figure 3 is a flowchart of a quantum encryption authentication method provided by another exemplary embodiment of the present disclosure;
[0019] Figure 4 is a flowchart of a quantum encryption authentication method provided by yet another exemplary embodiment of the present disclosure;
[0020] Figure 5 Schematic block diagram of the functional modules of the quantum encryption authentication device provided by an exemplary embodiment of the present disclosure;
[0021] Figure 6 Schematic block diagram of the functional modules of the quantum encryption authentication device provided by another exemplary embodiment of the present disclosure;
[0022] Figure 7 Schematic block diagram of the structure of the electronic device provided by an exemplary embodiment of the present disclosure;
[0023] Figure 8 Schematic block diagram of the structure of the computer system provided by an exemplary embodiment of the present disclosure. Detailed implementation manners
[0024] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0025] It should be understood that the steps described in the method embodiments of the present disclosure can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0026] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules or units.
[0027] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0028] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are for illustrative purposes only and are not used to limit the scope of these messages or information.
[0029] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0030] For example, when responding to an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of the present disclosure according to the prompt message.
[0031] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving an active request from the user may be, for example, in the form of a pop-up window, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry selection controls for the user to choose "agree" or "disagree" to provide personal information to the electronic device. It can be understood that the above process of notifying and obtaining the user's authorization is only illustrative and does not constitute a limitation on the implementation manner of the present disclosure. Other manners that meet relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0032] In the related art, the secret keys used by the system for password operations are derived from random numbers generated by classical physical processes or software algorithms, and the randomness is insufficient. At the same time, the secret keys are always pre-agreed by both communication parties, lacking the security of the secret keys, and there is no mechanism for real-time update after the secret keys are set. Once the secret keys are leaked, the entire communication process will face the risk of leakage. In addition, the existing system has a single module for password operations and no system for complete management. The password operation module always maintains a high degree of coupling and is not easy to maintain.
[0033] Therefore, to solve the above technical problems existing in the related art, embodiments of the present disclosure provide a quantum middleware SDK. By adopting a modular design concept, the process of encrypting transmitted data is integrated into the quantum middleware SDK. All function modules related to cryptographic operations are uniformly handed over to the quantum middleware SDK. On the basis of the original encryption, quantum encryption means are added to realize the secure distribution of quantum keys during the encryption process, achieving one-time pad encryption, and having the ability to resist quantum computer cracking attacks. It can solve the problems of integration, standardization, and extensibility in the process of key generation, storage, distribution, encryption, and decryption, improve the security, reliability, and flexibility of the financial business system, realize the efficient and secure distribution of quantum keys, and ensure the security and reliability of the encryption, decryption, and authentication processes.
[0034] Specifically, as Figure 1 shown, Figure 1 is a schematic diagram of the system architecture provided by embodiments of the present disclosure. The system may include a client and a server. Among them, the client integrates a first financial application module and a first quantum middleware SDK (Software Development Kit). The first quantum middleware SDK has functions such as authentication and encryption, and the first quantum middleware SDK includes an in-memory database for storing data such as keys. The first quantum middleware SDK can be integrated into the prototype system of the client, and the prototype system includes a cryptographic module for data encryption and decryption. In addition, the second quantum middleware SDK has functions such as decryption and verification. The second quantum middleware SDK includes an in-memory database for storing data such as keys. The second quantum middleware SDK can be integrated into the prototype system of the server, and the prototype system includes a cryptographic module for data encryption and decryption.
[0035] In the embodiment, the quantum network distributes keys to the quantum security server platform, and the quantum security server distributes the received keys to the client and the server respectively through key negotiation or infusion.
[0036] Combined with Figure 1As shown in the figure, when the client receives a data query operation sent by the user, the first financial application module generates a data query request based on the data query operation and sends the data query request to the first quantum middleware SDK. The first quantum middleware SDK authenticates the data query request by receiving it. If the authentication is passed, it obtains a key from the in-memory database to encrypt the data query request, and sends the encrypted data to the second financial application module in the server through the first financial application module. The second financial application module receives the encrypted data sent by the client and sends the encrypted data to the second quantum middleware SDK. The second quantum middleware receives the encrypted data and authenticates the encrypted data. If the authentication is passed, it obtains a key from the content database to decrypt the encrypted data, obtains the data query request, and sends the data query request to the second financial application module. The second financial application module obtains the corresponding data query result according to the data query request, encrypts the data query result through the second quantum middleware SDK, and sends the encrypted data query result to the client. Among them, the encrypted data carries a key index, and the second quantum middleware can obtain the corresponding key according to the key index to decrypt the encrypted data.
[0037] As Figure 1 , the quantum key wirelessly distributed to the quantum security service platform based on the quantum network is remote key distribution with quantum states as the information carrier. Based on physical principles, it can resist interception, eavesdropping, and decryption, and securely distributes keys for both ends of the financial application prototype system, thereby improving the security and independence of key management as a whole. On the basis of the original simple use of classical soft password operation methods, the quantum middleware SDK integrated into the financial application prototype system is a key management suite that integrates key generation, storage, import, export, distribution, use, update, and destruction. The financial application prototype system combines the quantum middleware SDK to complete the quantum fusion enhancement of its password operation-related services, including a series of operations such as identity authentication, encrypted transmission of key data, data decryption, and key update, ensuring one-time pad. The data encrypted through the quantum middleware SDK is transmitted between the two ends of the financial application based on the https (Hypertext Transfer Protocol Secure) protocol, ensuring the security and reliability of financial data during transmission. The financial application prototype system only needs to hand over the data to be processed to the quantum middleware SDK, and the subsequent password operation-related operations are automatically completed by the quantum middleware SDK. The prototype system does not need to pay attention to the entire life cycle of key generation, storage, distribution, update, and destruction.
[0038] Specifically, the above-mentioned first quantum middleware SDK may include: an SDK interface module, a quantum key generation module, a quantum key storage module, a quantum key distribution module, and a middleware management module. Among them:
[0039] The SDK interface module is used to provide a unified interface for financial services involved in financial applications, including data encryption authentication, data decryption verification, data encryption, data decryption, identity data information synchronization and update, data statistics, etc. based on the https protocol, and encapsulate and respond the service information processed by the quantum middleware SDK to the financial application.
[0040] The quantum key generation module is used to apply for quantum keys from the quantum security service platform according to the quantum key information data vector in the configuration information after the initialization environment is completed. After receiving the request, the quantum security service platform applies for keys from the quantum network to complete the generation of quantum keys.
[0041] The quantum key distribution module is used to remotely distribute the quantum keys generated by the quantum key generation module based on the BB84 protocol with quantum states as information carriers. Based on physical principles, it can resist interception, eavesdropping, and decryption, and distribute quantum keys for the quantum key distribution module.
[0042] The quantum key storage module is used to store the quantum keys distributed by the quantum key distribution module in a one-to-one correspondence with the session obtained from the quantum security cipher card in the in-use key queue for subsequent cryptographic operations. When the financial application prototype system finishes using the quantum keys in the in-use key queue, the quantum keys in the in-use key queue are added to the key update queue. When the quantum key update period arrives, the SDK actively clears the quantum keys from the in-use queue, and at the same time moves the quantum keys from the update queue to the key destruction queue for delayed destruction. When the keys in the in-use queue are cleared, the key generation module and distribution module are used to replenish the keys in a timely manner.
[0043] The middleware management module is used to uniformly manage and schedule the above-mentioned various modules to ensure the stable and secure operation of the entire financial application prototype system.
[0044] Similarly, the above-mentioned second quantum middleware SDK may include: a quantum key generation module, a quantum key storage module, a quantum key distribution module, an SDK interface module, and a middleware management module, and has corresponding functions respectively corresponding to the modules in the first quantum middleware SDK. For specific descriptions, please refer to the descriptions of the above-mentioned embodiments and will not be elaborated here.
[0045] Based on the above embodiments, in another embodiment provided by the present disclosure, as Figure 2 shown Figure 2Schematic flowchart of the quantum encryption authentication method provided by the embodiments of the present disclosure, which may specifically include the following steps:
[0046] Step 1: The first financial application module sends a data query request to the first quantum middleware SDK.
[0047] Step 2, the first quantum middleware SDK authenticates and encrypts the data authentication and encryption request.
[0048] In the embodiment, the first financial application in the client sends a data query request to the prototype system based on the https protocol for authenticating and encrypting the request. After receiving the request, the system parses the request input parameters, splices the secretKey, requestRefId, and secretId in the request parameters, takes out a session from the session pool after splicing, performs an authentication operation on the spliced data according to the signature authentication function, and splices the signature result signData with the key index keyId1 of the authentication operation according to the splicing process and writes it back to the signature data lzSignature. After authentication, a session is taken out from the session pool to perform a data encryption operation on the query request data in the request, and the encrypted result encData is spliced with the key index keyId2 of the encryption operation and written back to the request. Among them, lzSignature will be included in the request header, requestRefId, secretKey, and secretId are the parameters in the data query request respectively, requestRefId represents the request identifier, and secretKey and secretId represent key-value pairs, which have a unique corresponding relationship in the client and are used to identify the client.
[0049] Step 3, the first quantum middleware SDK3 returns the encrypted data to the first financial application module.
[0050] After the query data is encrypted, the first quantum middleware SDK encapsulates and responds the authentication and encryption result to the prototype system, and the prototype system returns the encrypted data packet to the first financial application module on the client side based on the https protocol.
[0051] Step 4, the first financial application module sends the encrypted data to the second financial application module in the server.
[0052] After receiving the encrypted data packet, the first financial application on the client side transmits the encrypted data packet to the second financial application module on the server side based on the https protocol.
[0053] Step 5, the second financial application module sends the encrypted data to the second quantum middleware SDK.
[0054] Step 6: The second quantum middleware SDK parses the encrypted data, authenticates and decrypts the parsed data, and obtains a data query request.
[0055] In the embodiment, after the second financial application on the server side obtains the encrypted data, it initiates a data decryption verification request to the prototype system based on the https protocol. After receiving the request, the system parses the request input parameters, obtains the signature data lzSignature from the request header in the request through an inverse operation, and extracts the key index keyId1 and data authentication signature signData for verification operation from lzSignature, and concatenates the secretKey, requestRefId and secretId in the request parameters, and then takes out the session from the session pool according to the key index to perform data authentication operation, compares and verifies the signature data signData1 after the operation with the signature signData extracted from the input parameters, and after the verification is successful, extracts the key index keyId2 and data ciphertext encData for decryption operation from the response through an inverse operation, takes out the session from the session pool according to keyId2, decrypts the ciphertext data encData, and writes decData back to the response.
[0056] Step 7: The second quantum middleware SDK returns the decrypted data query request to the second financial application module.
[0057] After the data query request is decrypted, the quantum middleware SDK will encapsulate the decryption verification result and respond to the prototype system. The prototype system returns the second quantum middleware SDK decryption verification package, i.e. the data query request, to the second financial application based on the https protocol.
[0058] Step 8: The second financial application module obtains the data query result corresponding to the data query request.
[0059] Step 9: The second financial application module sends the data query result to the second quantum middleware SDK.
[0060] Step 10: The second quantum middleware SDK encrypts the data query result to obtain a query result encrypted package.
[0061] In the query result return stage, the second financial application module initiates a query result encryption request to the prototype system based on the https protocol. After receiving the request, the system parses the request input parameters, takes out a session from the session pool, performs data encryption operation on the query result data in the request, and splices the encrypted result encData with the encryption operation key index keyId2 and writes it back to the request.
[0062] Step 11: The second quantum middleware SDK data query result encrypted package is returned to the second financial application module.
[0063] After the query result is encrypted, the second quantum middleware SDK will encapsulate the encrypted result and respond to the prototype system. The prototype system returns the encrypted package confirmed by the second quantum middleware SDK to the second financial application module based on the https protocol.
[0064] Step 12: The second financial application module sends an encrypted data query result package to the first financial application module on the client side.
[0065] After receiving the encrypted data query result package, the second financial application module transmits the encrypted data query result package to the first financial application module on the client side based on the https protocol.
[0066] Step 13: The first financial application module sends a query result decryption request to the first quantum middleware SDK.
[0067] Step 14: The first quantum middleware SDK decrypts the data query result encrypted package to obtain a query data result package.
[0068] After the first financial application module obtains the encrypted package of the data query result, it initiates a query result data decryption request to the prototype system based on the https protocol. After receiving the request, the system parses the request input parameters, extracts the key index keyId2 and data ciphertext encData used for decryption operation from the response through inverse operation, takes out the session from the session pool according to keyId2, decrypts the ciphertext data encData, and writes the query result data decData back to the response.
[0069] Step 15: The first quantum middleware SDK sends a query data result package to the first financial application module.
[0070] After the query data result is decrypted, the first quantum middleware SDK will encapsulate the decryption result and respond to the prototype system. The prototype system returns the query data result package decrypted by the first quantum middleware SDK to the first financial application module based on the https protocol, so that the query data result can be displayed to the user through the first financial application module.
[0071] Based on the above embodiment, in another embodiment provided by the present disclosure, the embodiment of the present disclosure further provides a quantum encryption authentication method, which is applied to a terminal. The client in the above embodiment can be located in the terminal. The terminal includes a first financial application module and a first quantum middleware SDK, such as Figure 3 As shown, the method may include the following steps:
[0072] In step S310, in response to a data query operation, the first financial application module sends a first data query request to the first quantum middleware SDK.
[0073] In an embodiment, when the terminal receives a user's data query operation, the first financial application module generates a first data query request based on the data query operation and sends the first data query request to the first quantum middleware SDK.
[0074] In step S320, the first quantum middleware SDK authenticates the received first data query request. If the authentication is passed, the first data query request is encrypted to generate an encrypted data packet, and a second data query request including the encrypted data packet is sent to the first financial application module. Among them, the first quantum middleware SDK obtains the keys distributed by the quantum security service platform, which are respectively used for authenticating and encrypting the first data query request.
[0075] In step S330, the first financial application module receives the second data query request and sends the second data query request to the server.
[0076] In an embodiment, the first quantum middleware SDK authenticates the received first data query request to determine the legality of the first data query request. If the authentication is passed, it can be determined that the first data query request is legal, avoiding problems such as data leakage caused by query requests initiated by illegal users.
[0077] If the authentication of the first data query request is passed, the first data query request is encrypted to obtain an encrypted data packet, and a second data query request including the encrypted data packet is sent to the first financial application module. In this way, the first financial application module can send the received second data query request to the server in order to receive the data query result returned by the server.
[0078] The quantum encryption method provided by the embodiments of the present disclosure integrates the authentication and encryption functions during data transmission into the first quantum middleware SDK, which is beneficial to the maintenance of keys. And the first quantum middleware SDK obtains the keys distributed by the quantum security service platform and authenticates and encrypts the first data query request based on the keys obtained from the quantum security service platform. There is no need to pre-agree on keys, which can avoid security risks caused by the leakage of keys, and thus can greatly improve the security during data transmission. In addition, the embodiment does not require manual configuration of symmetric keys. The quantum middleware SDK automatically realizes the distribution of quantum keys and the full-automatic encryption and decryption operations of each end of the financial application, which can greatly save labor costs.
[0079] Based on the above embodiments, in another embodiment provided by the present disclosure, step S320 may specifically further include the following steps:
[0080] In step S321, the first quantum middleware SDK receives a first data query request sent by the first financial application module. Among them, the first data query request carries request parameters.
[0081] In the embodiment, the request parameters may be the secretKey, requestRefId, and secretId parameters in the above embodiment, and the embodiment is not limited thereto.
[0082] In step S322, the first quantum middleware SDK splices the request parameters to obtain first spliced data.
[0083] In the embodiment, the first quantum middleware SDK obtains the string lengths corresponding to multiple parameters, sets flag bits based on the string lengths, and pads the multiple parameters to the target string length respectively. The first quantum middleware SDK divides the multiple parameters with the target string length into M parts according to fields, and extracts N-bit data from each of the M parts respectively. The first quantum middleware SDK adds the N-bit data extracted from each of the M parts to obtain multiple target parameters corresponding to the multiple parameters respectively. The first quantum middleware SDK splices the multiple parameters and the flag bits to obtain the first spliced data. Among them, both M and N are positive integers.
[0084] Specifically, taking the multiple parameters as secretKey, requestRefId, and secretId as an example, each field can be marked with Flag and padded to the target bit length first. Then each field is divided into three parts bit by bit, and the bit values of the corresponding fields are taken from each part. The bit values of the same part of the three fields are added together to generate new NewsecretKey, NewrequestRefId, and NewsecretId respectively. Then the flag Flag and the three newly generated fields are spliced, encrypted using the quantum key and transmitted to the peer end. The peer end decrypts using the quantum key and restores the original secretKey, requestRefId, and secretId according to the flag Flag. Compared with the traditional method of directly splicing the heads and tails of these three fields, this splicing algorithm authenticates and signs the spliced data by splicing and desensitizing the financial data in the request and then calling the authentication algorithm, which can ensure the confidentiality of sensitive information during the data transmission process. Specifically, it may include the following process:
[0085] (1) Calculate the lengths of the three strings secretKey, requestRefId, and secretId. If the lengths are all less than or equal to 32 bits, then set the flag bit Flag and mark Flag = 0, and pad all three strings to 32 bits; if the lengths are all greater than 32 bits but less than or equal to 64 bits, then mark Flag = 1, and pad all three strings to 64 bits; and so on. Thus, new strings NewsecretKey, newrequestRefId, and NewsecretId with the lengths of the strings padded can be obtained.
[0086] (2) Calculate the new NewsecretKey = the bit value of secretKey (number of bits / 3 = 0) + the bit value of requestRefId (number of bits / 3 = 0) + the bit value of secretId (number of bits / 3 = 0).
[0087] Calculate the new NewrequestRefId = the bit value of secretKey (number of bits / 3 = 1) + the bit value of requestRefId (number of bits / 3 = 1) + the bit value of secretId (number of bits / 3 = 1).
[0088] Calculate the new NewsecretId = the bit value of secretKey (number of bits / 3 = 2) + the bit value of requestRefId (number of bits / 3 = 2) + the bit value of secretId (number of bits / 3 = 2).
[0089] (4) Use a quantum key to perform confidentiality and integrity processing on the concatenated value of Flag, NewsecretKey, NewrequestRefId, and NewsecretId, and then transmit it to the server side. After the server side obtains Flag, use the same quantum key to perform an inverse operation on the concatenated value of NewsecretKey, NewrequestRefId, and NewsecretId to obtain the initial secretKey, requestRefId, and secretId.
[0090] In the embodiment, by directly concatenating the three fields secretKey, requestRefId, and secretId at the head and tail and transmitting them to the business system at the opposite end, the confidentiality of sensitive information during the data transmission process can be ensured.
[0091] In step S323, the first quantum middleware SDK obtains a first session from a pre-built key session pool, performs an authentication operation on the first spliced data based on the first session and a preset signature authentication function to obtain signature data, and determines whether the first data query request passes authentication based on the signature data. The key session pool stores keys distributed by the quantum security service platform, and the key session pool includes the correspondence between sessions and keys.
[0092] In the embodiment, the key session pool includes the correspondences between multiple sessions and keys respectively. In this way, a session can be randomly obtained from the key session pool, the key corresponding to the session can be obtained, and the above first spliced data can be authenticated through the key and the preset signature authentication function to obtain signature data. By comparing the obtained signature data with the pre-stored signature data, if the two are consistent, the authentication passes; otherwise, the authentication fails. In this way, through the data splicing method and key acquisition method provided by the embodiment, the security of authentication can be greatly improved.
[0093] Based on the above embodiment, in another embodiment provided by the present disclosure, the method may further include the following steps:
[0094] In step S340, the first quantum middleware SDK obtains a first key index corresponding to the first session in the key session pool.
[0095] In step S350, the first quantum middleware SDK splices the first key index and the signature data to obtain second spliced data, and adds the second spliced data to the request header of the second data query request.
[0096] In the embodiment, since the key session pool includes the correspondence between sessions and keys, and each key corresponds to a key index, the key index may be the ID of the session or the key ID, which is used to obtain the corresponding key according to the key index. Therefore, by obtaining the first key index corresponding to the first session in the key session pool and splicing the first key index and the signature data to obtain second spliced data, the second spliced data can be further added to the request header of the second data query request. In this way, when the peer receives the second data query request, the second spliced data can be obtained from the request header of the request, and then the corresponding key can be obtained according to the first key index in the second spliced data for authenticating the received request, thereby improving the security of data transmission.
[0097] Based on the above embodiment, in another embodiment provided by the present disclosure, when encrypting the first data query request, step S320 may specifically further include the following steps:
[0098] In step S324, obtain a second session from a pre-constructed key session pool, and obtain a second key and a second key index corresponding to the second session in the key session pool.
[0099] In step S325, encrypt the first data query request with the second key to obtain an encryption result.
[0100] In step S326, splice the encryption result with the second key index to obtain an encrypted data packet.
[0101] In the embodiment, by obtaining the second session from the key session pool, the second key and the second key index respectively corresponding to the second session can be obtained. The second key index is used to obtain the corresponding second key. In this way, the first data query request is encrypted with the second key, and the obtained encryption result and the second key index are spliced to obtain an encrypted data packet. In this way, when the peer receives the encrypted data packet, the second key index can be obtained from the encrypted data packet, and the corresponding second key can be obtained according to the second key index. Furthermore, the encryption result can be decrypted with the second key to implement secure processing of data encryption and decryption.
[0102] Based on the above embodiments, in the embodiments provided in the present disclosure, the method may further include the following steps:
[0103] In step S360, the first quantum middleware SDK sends a key acquisition request to the quantum security service platform.
[0104] In step S370, the first quantum middleware SDK receives the key sent by the quantum security service platform and stores the key in the key session pool.
[0105] In step S380, when the first quantum middleware SDK detects that there is a key in the key session pool that reaches the update period, the key that reaches the update period is destroyed from the key session pool.
[0106] In the embodiments provided by the present disclosure, a key session pool can be created in advance, and the key session pool can be divided into an in-use pool, an update pool, and a destruction pool. By creating the in-use pool, update pool, and destruction pool of the key session pool and starting an update daemon thread. The first quantum middleware SDK sends a key application to the quantum security service platform, and the successfully applied quantum key is stored in the in-use pool. During application operations, a key can be randomly selected from the in-use pool, and transferred to the update pool or destruction pool according to the key expiration status. If a key cannot be found in the in-use pool, it is queried from the update pool and destruction pool in sequence. The key quantity in the in-use pool is detected in real time. When the key quantity in the in-use pool is insufficient, it is replenished. The keys that expire in the update pool are transferred to the destruction pool when they expire, and the keys that reach the destruction time in the destruction pool are cleared. Thus, the life cycle of the key can be managed more precisely to ensure that password operations can still be performed after the key is destroyed at the critical point. Specifically, it may include the following processing procedures:
[0107] (1) During the initialization phase of the system, a key in-use pool qKeyPool, an update pool delayUpdatePool, and a destruction pool delayDestoryPool are newly created, and a key update daemon thread is started simultaneously.
[0108] (2) After the quantum key application is successful according to the key configuration item in the configuration file, the successfully applied quantum key is stored in the in-use library qKeyPool.
[0109] (3) When the application performs data password operations, a key is randomly selected from the key in-use pool qKeyPool for password operations. At the same time, it is judged whether the key has expired. If the key has not expired, it is transferred to the update pool delayUpdatePool. If the key has reached the expiration time, it is transferred to the destruction pool delayDestoryPool for delayed destruction. When a key cannot be found in the in-use library qKeyPool, the system will query from the update pool delayUpdatePool and the destruction pool delayDestoryPool in sequence to ensure that password operations can still be performed after the key is destroyed at the critical point.
[0110] (4) According to the configuration information in the configuration file, the key in-use pool qKeyPool detects the key quantity in real time. When it is insufficient, it is replenished in time. The update pool delayUpdatePool detects in real time whether the key has reached the cycle. After the cycle is reached, it is transferred to the destruction pool delayDestoryPool in time. The destruction pool delayDestoryPool detects in real time and clears the key after the key reaches the delayed destruction time.
[0111] Based on the above embodiments, in another embodiment provided by the present disclosure, a quantum encryption authentication method is further provided. This method can be applied to a server, and the server includes a second financial application module and a second quantum middleware SDK, asFigure 4 As shown, the method may include the following steps:
[0112] In step S410, the second financial application module receives a second data query request sent by the terminal and sends the second data query request to the second quantum middleware SDK. The second data query request includes an encrypted data packet.
[0113] In step S420, the second quantum middleware SDK authenticates the received second data query request. When the authentication is passed, the encrypted data packet is decrypted based on the key obtained from the quantum security service platform, and the decrypted first data query request is sent to the second financial application module.
[0114] In step S430, the second financial application module obtains a data query result based on the first data query request, encrypts the data query result, and sends the encrypted data query result to the terminal.
[0115] In the embodiment, the request header of the second data query request includes a first key index, first signature data, and request parameters. When the second quantum middleware SDK authenticates the second data query request, it may obtain the corresponding first key from the quantum security service platform based on the first key index, or obtain the corresponding first key from a pre-established key session pool based on the first key index. In this way, an authentication operation can be performed on the request parameters based on the first key and a preset signature authentication function to obtain second signature data. When the second signature data is consistent with the first signature data, it is determined that the authentication is passed.
[0116] In the embodiment, the encrypted data packet carries a second key index. When decrypting the encrypted data packet based on the key obtained from the quantum security service platform or the key session pool, the second quantum middleware SDK sends a key acquisition request to the quantum security service platform or the key session pool. The key acquisition request carries the second key index. The second quantum middleware SDK receives the second key sent by the quantum security service platform or obtains the second key corresponding to the second key index from the key session pool, and decrypts the encrypted data packet based on the second key to obtain the first data query request.
[0117] The embodiment also integrates the authentication and encryption functions during data transmission into the first quantum middleware SDK, which is beneficial to the maintenance of keys. Moreover, the first quantum middleware SDK will obtain the keys distributed by the quantum security service platform, and authenticate and decrypt the first data query request based on the keys obtained from the quantum security service platform. There is no need to pre-agree on keys, which can avoid the security risks caused by the leakage of keys, and thus can greatly improve the security during data transmission. In addition, the embodiment does not require manual configuration of symmetric keys. The quantum middleware SDK automatically realizes the distribution of quantum keys and the full-automatic encryption and decryption operations of each end of the financial application, which can greatly save labor costs.
[0118] In the embodiment, the keys obtained from the quantum security service platform can also be stored in the key session pool, and the corresponding keys can be directly obtained from the key session pool. The implementation is not limited to this. In this way, the key session pool includes the corresponding relationships between multiple sessions and the keys respectively. In this way, the keys corresponding to the key indexes can be obtained from the key session pool respectively, including the first key and the second key, which can be used to authenticate the request and decrypt the encrypted data packet respectively.
[0119] Randomly obtain a session from the key session pool. In this way, the key corresponding to the session can be obtained, and the above first spliced data is authenticated through the key and the preset signature authentication function to obtain the signature data. By comparing the signature data with the pre-stored signature data, if the two are consistent, the authentication passes, otherwise the authentication fails. In this way, through the data splicing method and key acquisition method provided by the embodiment, the security of authentication can be greatly improved.
[0120] In the case of dividing each functional module according to the corresponding functions, the embodiment of the present disclosure provides a quantum encryption authentication device, and the quantum encryption authentication device can be located in the above terminal. Figure 5 It is a schematic block diagram of the functional modules of the quantum encryption authentication device provided by an exemplary embodiment of the present disclosure. As Figure 5 shown, the quantum encryption authentication device includes:
[0121] The first financial application module 51 is configured to send a first data query request to the first quantum middleware SDK in response to a data query operation;
[0122] The first quantum middleware SDK 52 is used to authenticate the first data query request received by the first quantum middleware SDK. In the case of successful authentication, encrypt the first data query request to generate an encrypted data packet, and send a second data query request containing the encrypted data packet to the first financial application module; wherein, the first quantum middleware SDK obtains keys distributed by the quantum security service platform, which are respectively used to authenticate and encrypt the first data query request;
[0123] The first financial application module 51 is further configured to receive the second data query request and send the second data query request to the server.
[0124] In another embodiment provided by the present disclosure, the first quantum middleware is specifically further configured to:
[0125] Receive a first data query request sent by the first financial application module, where the first data query request carries request parameters;
[0126] Concatenate the request parameters to obtain first concatenated data;
[0127] Obtain a first session from a pre-constructed key session pool, perform an authentication operation on the first concatenated data based on the first session and a preset signature authentication function to obtain signature data, and confirm whether the first data query request passes authentication based on the signature data; wherein, the key session pool stores keys distributed by the quantum security service platform, and the key session pool includes the correspondence between sessions and keys.
[0128] In another embodiment provided by the present disclosure, the request parameters include multiple parameters; the first quantum middleware SDK is specifically further configured to:
[0129] Obtain the string lengths corresponding to the multiple parameters respectively, set flag bits based on the string lengths, and pad the multiple parameters to a target string length respectively;
[0130] Divide the multiple parameters with the target string length into M parts according to fields respectively, and extract N-bit data from each of the M parts respectively;
[0131] The first quantum middleware SDK adds the N-bit data extracted from each M part respectively to obtain multiple target parameters corresponding to the multiple parameters respectively;
[0132] The first quantum middleware SDK concatenates the multiple parameters and the flag bits to obtain first concatenated data.
[0133] In another embodiment provided by the present disclosure, the first quantum middleware is further specifically configured to:
[0134] Obtain a first key index corresponding to the first session in the key session pool;
[0135] Concatenate the first key index and the signature data to obtain second concatenated data, and add the second concatenated data to the request header of the second data query request.
[0136] In another embodiment provided by the present disclosure, the first quantum middleware is further specifically configured to:
[0137] Obtain a second session from a pre-constructed key session pool, and obtain a second key and a second key index corresponding to the second session in the key session pool;
[0138] Encrypt the first data query request with the second key to obtain an encryption result;
[0139] Concatenate the encryption result and the second key index to obtain an encrypted data packet.
[0140] In another embodiment provided by the present disclosure, the first quantum middleware is further specifically configured to:
[0141] Send a key acquisition request to the quantum security service platform;
[0142] Receive the key sent by the quantum security service platform, and store the key in the key session pool;
[0143] When detecting that there is a key in the key session pool that reaches the update period, destroy the key that reaches the update period from the key session pool.
[0144] Based on the above embodiments, when each function is divided into corresponding function modules, the embodiments of the present disclosure provide a quantum encryption authentication device, and this quantum encryption authentication device can be located in the above server. Figure 6 It is a schematic block diagram of function modules of a quantum encryption authentication device provided by an exemplary embodiment of the present disclosure. As Figure 6 shown, this quantum encryption authentication device includes:
[0145] A second financial application module 61, configured to receive a second data query request sent by a terminal, and send the second data query request to the second quantum middleware SDK 62; wherein, the second data query request includes an encrypted data packet;
[0146] The second quantum middleware SDK 62 is used to authenticate the received second data query request. When the authentication is passed, the encrypted data packet is decrypted based on the key obtained from the quantum security service platform, and the decrypted first data query request is sent to the second financial application module;
[0147] The second financial application module 61 is further used to obtain a data query result based on the first data query request, encrypt the data query result, and send the encrypted data query result to the terminal.
[0148] In another embodiment provided by the present disclosure, the request header of the second data query request includes a first key index, first signature data, and request parameters; the second quantum middleware SDK 62 is specifically further used for:
[0149] Obtain the corresponding first key from the quantum security service platform based on the first key index;
[0150] Perform an authentication operation on the request parameters based on the first key and a preset signature authentication function to obtain second signature data. When the second signature data is consistent with the first signature data, it is determined that the authentication is passed.
[0151] In another embodiment provided by the present disclosure, the encrypted data packet carries a second key index; the second quantum middleware SDK 62 is specifically further used for:
[0152] The second quantum middleware SDK sends a key acquisition request to the quantum security service platform, and the key acquisition request carries the second key index;
[0153] The second quantum middleware SDK receives the second key sent by the quantum security service platform and decrypts the encrypted data packet based on the second key to obtain a first data query request.
[0154] The quantum encryption authentication device provided by the embodiments of the present disclosure integrates the authentication and encryption functions during data transmission into the first quantum middleware SDK, which is beneficial to the maintenance of keys. And the first quantum middleware SDK will obtain the keys distributed by the quantum security service platform and authenticate and encrypt the first data query request based on the keys obtained from the quantum security service platform. There is no need to pre-agree on keys, which can avoid the security risks caused by the leakage of keys, and thus can greatly improve the security during data transmission.
[0155] An embodiment of the present disclosure further provides an electronic device, including: at least one processor; a memory for storing executable instructions of the at least one processor; wherein the at least one processor is configured to execute the instructions to implement the above method disclosed in the embodiment of the present disclosure.
[0156] Figure 7 It is a schematic structural diagram of an electronic device provided by an exemplary embodiment of the present disclosure. As Figure 7 shown, the electronic device 1800 includes at least one processor 1801 and a memory 1802 coupled to the processor 1801, and the processor 1801 can execute the corresponding steps in the above method disclosed in the embodiment of the present disclosure.
[0157] The above-mentioned processor 1801 can also be referred to as a central processing unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the above method disclosed in the embodiment of the present disclosure can be completed by the integrated logic circuit in the hardware of the processor 1801 or by instructions in software form. The above-mentioned processor 1801 can be a general-purpose processor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiment of the present disclosure can be directly embodied as being executed and completed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in the memory 1802, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, and other mature storage media in the art. The processor 1801 reads the information in the memory 1802 and combines its hardware to complete the steps of the above method.
[0158] In addition, when various operations / processings according to the present disclosure are implemented by software and / or firmware, a program constituting the software can be installed from a storage medium or a network into a computer system with a dedicated hardware structure, such as Figure 8 the computer system 1900 shown. When various programs are installed in the computer system, it can execute various functions, including functions such as those described above. Figure 8 It is a block diagram of the structure of a computer system provided by an exemplary embodiment of the present disclosure.
[0159] The computer system 1900 is intended to represent computer devices of various forms of digital electronics, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic devices can also represent various forms of mobile devices, such as, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0160] As Figure 8 shown, the computer system 1900 includes a computing unit 1901, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 1902 or a computer program loaded from a storage unit 1908 into a random access memory (RAM) 1903. In the RAM 1903, various programs and data required for the operation of the computer system 1900 can also be stored. The computing unit 1901, the ROM 1902, and the RAM 1903 are connected to each other through a bus 1904. An input / output (I / O) interface 1905 is also connected to the bus 1904.
[0161] Multiple components in the computer system 1900 are connected to the I / O interface 1905, including: an input unit 1906, an output unit 1907, a storage unit 1908, and a communication unit 1909. The input unit 1906 can be any type of device capable of inputting information into the computer system 1900. The input unit 1906 can receive input digital or character information and generate key signal inputs related to user settings and / or function controls of the electronic device. The output unit 1907 can be any type of device capable of presenting information and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 1908 can include, but is not limited to, magnetic disks, optical disks. The communication unit 1909 allows the computer system 1900 to exchange information / data with other devices through a network such as the Internet and can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a BluetoothTM device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0162] The computing unit 1901 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1901 executes the various methods and processes described above. For example, in some embodiments, the above-described methods disclosed in the embodiments of the present disclosure can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 1908. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device via the ROM 1902 and / or the communication unit 1909. In some embodiments, the computing unit 1901 can be configured to execute the above-described methods disclosed in the embodiments of the present disclosure by any other suitable means (e.g., by means of firmware).
[0163] The embodiments of the present disclosure also provide a computer-readable storage medium, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the above-described methods disclosed in the embodiments of the present disclosure.
[0164] The computer-readable storage medium in the embodiments of the present disclosure can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The above computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specifically, the above computer-readable storage medium can include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0165] The above computer-readable medium can be included in the above electronic device; or can exist separately and not be assembled into the electronic device.
[0166] The embodiments of the present disclosure also provide a computer program product, including a computer program, wherein when the computer program is executed by a processor, the above-described methods disclosed in the embodiments of the present disclosure are implemented.
[0167] In embodiments of the present disclosure, computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The foregoing programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network (including a local area network (LAN) or a wide area network (WAN)), or may be connected to an external computer.
[0168] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0169] The modules, components, or units described in the embodiments of the present disclosure may be implemented in software or in hardware. Among them, the names of the modules, components, or units do not, in some cases, constitute a limitation on the modules, components, or units themselves.
[0170] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, by way of non-limitation, exemplary hardware logic components that may be used include: field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), and so on.
[0171] The above description is only some embodiments of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.
[0172] Although some specific embodiments of the present disclosure have been described in detail by way of examples, those skilled in the art should understand that the above examples are only for illustration and not for limiting the scope of the present disclosure. Those skilled in the art should understand that the above embodiments can be modified without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.
Claims
1. A quantum encryption authentication method, characterized in that, Applied to a terminal, the terminal includes a first financial application module and a first quantum middleware SDK, and the method includes: In response to a data query operation, the first financial application module sends a first data query request to the first quantum middleware SDK; The first quantum middleware SDK authenticates the received first data query request. If the authentication is passed, it encrypts the first data query request to generate an encrypted data packet, and sends a second data query request including the encrypted data packet to the first financial application module; wherein, the first quantum middleware SDK obtains keys distributed by the quantum security service platform for authenticating and encrypting the first data query request respectively; The first financial application module receives the second data query request and sends the second data query request to the server.
2. The method according to claim 1, wherein The first quantum middleware SDK authenticating the received first data query request includes: The first quantum middleware SDK receives the first data query request sent by the first financial application module, and the first data query request carries request parameters; The first quantum middleware SDK splices the request parameters to obtain first spliced data; The first quantum middleware SDK obtains a first session from a pre-constructed key session pool, performs an authentication operation on the first spliced data based on the first session and a preset signature authentication function to obtain signature data, and confirms whether the first data query request passes the authentication based on the signature data; wherein, the key session pool stores keys distributed by the quantum security service platform, and the key session pool includes the corresponding relationship between the session and the key.
3. The method according to claim 2, wherein The request parameters include multiple parameters; the first quantum middleware SDK splicing the request parameters to obtain first spliced data includes: The first quantum middleware SDK obtains the string lengths corresponding to the multiple parameters respectively, sets flag bits based on the string lengths, and pads the multiple parameters to a target string length respectively; The first quantum middleware SDK divides the multiple parameters with the target string length into M parts according to fields respectively, and extracts N-bit data from each of the M parts respectively; The first quantum middleware SDK adds the N-bit data extracted from each of the M parts respectively to obtain multiple target parameters corresponding to the multiple parameters respectively; The first quantum middleware SDK splices the multiple parameters and the flag bits to obtain first spliced data.
4. The method according to claim 2, wherein The method further includes: The first quantum middleware SDK obtains a first key index corresponding to the first session in the key session pool; The first quantum middleware SDK splices the first key index and the signature data to obtain second spliced data, and adds the second spliced data to the request header of the second data query request.
5. The method according to claim 1, wherein The encrypting the first data query request to generate an encrypted data packet includes: Obtain a second session from a pre-constructed key session pool, and obtain the corresponding second key and second key index of the second session in the key session pool; Encrypt the first data query request with the second key to obtain an encryption result; Concatenate the encryption result with the second key index to obtain an encrypted data packet.
6. The method according to claim 1, characterized in that The method further includes: The first quantum middleware SDK sends a key acquisition request to the quantum security service platform; The first quantum middleware SDK receives the key sent by the quantum security service platform and stores the key in the key session pool; When the first quantum middleware SDK detects a key in the key session pool that has reached the update period, the key that has reached the update period is destroyed from the key session pool.
7. A quantum encryption authentication method, characterized in that, Applied to a server, the server includes a second financial application module and a second quantum middleware SDK, and the method includes: The second financial application module receives a second data query request sent by a terminal and sends the second data query request to the second quantum middleware SDK; wherein, the second data query request includes an encrypted data packet; The second quantum middleware SDK authenticates the received second data query request. When the authentication is passed, the encrypted data packet is decrypted based on the key obtained from the quantum security service platform, and the decrypted first data query request is sent to the second financial application module; The second financial application module obtains a data query result based on the first data query request, encrypts the data query result, and sends the encrypted data query result to the terminal.
8. The method according to claim 7, wherein The request header of the second data query request includes a first key index, first signature data, and request parameters; the second quantum middleware SDK authenticates the received second data query request, including: The second quantum middleware SDK obtains the corresponding first key from the quantum security service platform based on the first key index; The second quantum middleware SDK performs an authentication operation on the request parameters based on the first key and a preset signature authentication function to obtain second signature data. When the second signature data is consistent with the first signature data, it is determined that the authentication is passed.
9. The method according to claim 7, wherein The encrypted data packet carries a second key index; the decrypting the encrypted data packet based on the key obtained from the quantum security service platform includes: The second quantum middleware SDK sends a key acquisition request to the quantum security service platform, and the key acquisition request carries the second key index; The second quantum middleware SDK receives the second key sent by the quantum security service platform and decrypts the encrypted data packet based on the second key to obtain a first data query request.
10. An electronic device, characterized in that, Includes: At least one processor; A memory for storing executable instructions of the at least one processor; Wherein, the at least one processor is configured to execute the instructions to implement the method according to any one of claims 1 to 6 when the electronic device is a terminal; and to implement the method according to any one of claims 7 to 9 when the electronic device is a server.