A signal encryption method and device based on quantum key distribution

By constructing a multi-server quantum key distribution system, the problem of insufficient anti-interference capability of quantum key distribution in long-distance and complex environments was solved, realizing efficient and dynamic key distribution and encryption, and improving the security and accuracy of satellite navigation systems.

CN121036976BActive Publication Date: 2026-01-30CETC XINGHE BEIDOU TECH (XIAN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511563342.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-30
Publication Date
2026-01-30
Estimated Expiration
2045-10-30

AI Technical Summary

Technical Problem

Existing quantum key distribution protocols have limited resistance to interference in long-distance transmission and complex environments, making it difficult to meet the requirements of high-dynamic key distribution. Furthermore, traditional encryption algorithms are easily cracked by quantum computing, affecting the security and accuracy of navigation systems.

Method used

A quantum key distribution system based on multiple interconnected quantum key servers is constructed. Quantum keys are generated and updated through quantum key distribution units and communication relay units, and encryption is performed using quantum channels. Combined with inter-satellite networks and dynamic key management, efficient and dynamic key distribution and encryption are achieved.

Benefits of technology

It improves the efficiency and dynamic management capabilities of key distribution, enhances the flexibility and security of encryption, reduces key distribution delays and leakage risks, expands the system's coverage, and ensures the secure transmission of satellite navigation data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121036976B_ABST
    Figure CN121036976B_ABST
Patent Text Reader

Abstract

This application discloses a signal encryption method and apparatus based on quantum key distribution, relating to the field of satellite navigation technology. The method includes: constructing a quantum key distribution system based on multiple interconnected quantum key servers, with a user communication terminal connected to the nearest quantum key server; a communication relay unit performing basis vector comparison on quantum state data from satellites and ground stations using a key distribution protocol to generate a quantum key; a key distribution unit dynamically updating the quantum key and distributing it to the user communication terminal; the user communication terminal using the quantum key to encrypt satellite navigation data, obtaining an encrypted data packet, which is then sent to a receiving end via the communication relay unit; and the receiving end decrypting the encrypted data packet based on the quantum key to obtain the satellite navigation data. This method can improve the quantum key generation rate, enhance the anti-interference performance of the quantum key distribution system in complex environments, and ensure the stability and reliability of the quantum key distribution system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of satellite navigation technology, and in particular to a signal encryption method and apparatus based on quantum key distribution. Background Technology

[0002] With the rapid development of satellite navigation technology, many fields such as transportation, public safety, and surveying have undergone unprecedented changes, while also promoting the intelligent upgrading of related industries and bringing enormous social benefits. However, with the widespread application of satellite navigation technology, its security issues have become increasingly prominent.

[0003] Existing technologies combining quantum key distribution with satellite navigation systems can effectively enhance the encryption strength of navigation signals, ensuring that the signals cannot be maliciously tampered with or cracked. However, due to limitations of the quantum physical layer, quantum key distribution protocols cannot achieve long-distance transmission. Furthermore, in complex environments, such as extreme weather conditions, their anti-interference capabilities are limited, potentially leading to link interruptions and inability to respond in real time.

[0004] Traditional encryption algorithms and public key infrastructure (PKI) rely entirely on computational complexity for security, while quantum computing can quickly crack these algorithms. Furthermore, quantum computing suffers from limitations and simplistic key distribution and update mechanisms, making it unable to fully defend against increasingly diverse cyberattacks or signal interference. In addition, slow encryption and decryption speeds can also affect navigation accuracy and security, especially in high-security applications requiring high dynamism and low latency. Summary of the Invention

[0005] This application provides a signal encryption method and apparatus based on quantum key distribution, which solves the problems of weak anti-interference ability and difficulty in meeting the requirements of high dynamic key distribution in the existing quantum key distribution process.

[0006] In a first aspect, embodiments of this application provide a signal encryption method based on quantum key distribution, comprising: constructing a quantum key distribution system based on multiple interconnected quantum key servers, wherein a user communication terminal is connected to the nearest quantum key server; wherein the quantum key distribution system includes a key allocation unit and a communication relay unit, the communication relay unit including a satellite and a ground station; the user communication terminal including a transmitter and a receiver; the communication relay unit performing basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol to generate a quantum key, and sending the quantum key to the key allocation unit for storage; the key allocation unit dynamically updating the quantum key and distributing the quantum key to the user communication terminal; the user communication terminal using the quantum key to encrypt satellite navigation data to obtain an encrypted data packet, and sending the encrypted data packet to the receiver through the communication relay unit; the receiver decrypting the received encrypted data packet based on the quantum key to obtain the satellite navigation data.

[0007] In one possible implementation, the key distribution unit includes multiple key management nodes, and the user communication terminal establishes a quantum channel with the communication relay unit by accessing the key management node; the key management node configures a quantum key for the quantum channel to build a secure channel to encrypt the communication between the user communication terminals.

[0008] In one possible implementation, before the communication relay unit performs basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol, it further includes: synchronizing the clock precision of the satellite and the ground station; and controlling the satellite or the ground station to send or receive the corresponding quantum state data in a preset order and time interval.

[0009] In one possible implementation, before the communication relay unit performs basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol, it further includes: introducing a quantum random number generator into the satellite to generate qubits in parallel; sharing the qubits with the ground station through a quantum channel; and encoding the qubits according to redundancy coding to obtain the quantum state data.

[0010] In one possible implementation, the communication relay unit compares the quantum state data of the satellite and the ground station using a key distribution protocol to generate a quantum key. This includes: the ground station and the satellite randomly selecting transmission basis vectors, and the ground station transmitting its quantum state data to the satellite based on these vectors; the satellite randomly selecting measurement basis vectors, and measuring the quantum state data of the ground station based on these vectors to obtain a measurement result; wherein the ground station and the satellite transmit the transmission basis vectors and the measurement basis vectors via a classical channel; comparing the transmission basis vectors and the measurement basis vectors; if the transmission basis vectors of the ground station and the measurement basis vectors of the satellite are the same, the measurement result is retained; if the transmission basis vectors of the ground station and the measurement basis vectors of the satellite are different, the satellite performs error detection on the measurement result according to a preset threshold; based on the detection result, the corresponding quantum state data of the ground station is corrected to obtain corrected quantum state data; and the corrected quantum state data is compressed to generate the quantum key.

[0011] In one possible implementation, the key distribution unit dynamically updates the quantum key, including: determining the state of each quantum key in the key distribution unit; if the state of the quantum key is normal, storing it in the key distribution unit; if the state of the quantum key is abnormal, initiating a key generation request to the communication relay unit to update the quantum key.

[0012] In one possible implementation, distributing the quantum key to the user communication terminal further includes: constructing an inter-satellite network in the communication relay unit based on multiple satellites and ground stations; adjusting the key distribution path using the inter-satellite network according to the state of the quantum key, and feeding back the adjusted distribution path to the key distribution unit to update the distribution path of the quantum key.

[0013] In one possible implementation, the user communication terminal uses the quantum key to encrypt satellite navigation data to obtain an encrypted data packet, including: the user communication terminal transmitting the quantum key according to the secure channel and encrypting the satellite navigation data; wherein, the encryption of the satellite navigation data is performed as follows:

[0014] ;

[0015] In the formula, This refers to the encrypted satellite navigation data. Indicates encryption processing Encryption algorithm, This refers to the satellite navigation data before encryption. This refers to the quantum key.

[0016] In one possible implementation, the user communication terminal uses the quantum key to encrypt satellite navigation data, and further includes: preloading the quantum key to the key distribution unit according to the quantum key distribution protocol to reduce encryption latency.

[0017] Secondly, embodiments of this application provide a signal encryption device based on quantum key distribution, comprising: a system construction module for constructing a quantum key distribution system based on multiple interconnected quantum key servers, wherein a user communication terminal is connected to the nearest quantum key server; wherein the quantum key distribution system includes a key allocation unit and a communication relay unit, the communication relay unit including a satellite and a ground station; the user communication terminal including a transmitter and a receiver; a quantum key generation module for the communication relay unit to perform basis vector comparison on the quantum state data of the satellite and the ground station through a key distribution protocol to generate a quantum key, and send the quantum key to the key allocation unit for storage; a key update module for the key allocation unit to dynamically update the quantum key and distribute the quantum key to the user communication terminal; an encryption module for the user communication terminal to encrypt satellite navigation data using the quantum key to obtain an encrypted data packet, and send the encrypted data packet to the receiver through the communication relay unit; and a decryption module for the receiver to decrypt the received encrypted data packet based on the quantum key to obtain satellite navigation data.

[0018] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:

[0019] This application employs a signal encryption method and apparatus based on quantum key distribution. By constructing a quantum key distribution system, it improves the efficiency and dynamic management capabilities of key distribution. Generating quantum keys based on a quantum key distribution protocol enables more efficient parallel generation of quantum keys. User communication terminals can access any nearby quantum key server, reducing key distribution latency. It effectively solves the problems of limited transmission distance, slow key generation rate, and weak anti-interference capability. Dynamically updating the quantum keys allows for real-time monitoring of the quantum key status, reducing the risk of quantum key leakage. Encrypting satellite navigation data using quantum keys enhances encryption flexibility. Integrating the key distribution unit, communication relay unit, and user communication terminal into a unified system improves the operational security and efficiency of the quantum key distribution system. Attached Figure Description

[0020] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A flowchart of a signal encryption method based on quantum key distribution provided in this application embodiment;

[0022] Figure 2 This is a schematic diagram of a signal encryption device based on quantum key distribution, provided as an embodiment of this application. Detailed Implementation

[0023] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0024] The following description of some technologies involved in the embodiments of this application is provided to aid understanding and should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and brevity, some descriptions of well-known functions and structures are omitted in the following description.

[0025] Figure 1 This is a flowchart of a signal encryption method based on quantum key distribution provided in an embodiment of this application, including steps 101 to 105. Figure 1 This is merely one execution order shown in the embodiments of this application and does not represent the only execution order of a signal encryption method based on quantum key distribution. Where the final result can be achieved, Figure 1 The steps shown can be performed in parallel or in reverse order, as detailed below.

[0026] Step 101: Construct a quantum key distribution system based on multiple interconnected quantum key servers, with user communication terminals connecting to the nearest quantum key server. The quantum key distribution system includes a key distribution unit and a communication relay unit, with the communication relay unit comprising satellites and ground stations. The user communication terminal includes a transmitter and a receiver.

[0027] In this embodiment, the key distribution unit includes multiple key management nodes. User communication terminals establish a quantum channel with the communication relay unit by accessing the key management nodes. The key management nodes configure quantum keys for the quantum channel to build a secure channel and encrypt communication between user communication terminals.

[0028] In this embodiment, a "space-ground collaborative" quantum key distribution system is constructed to achieve highly secure communication of satellite navigation data during transmission. The quantum key distribution system consists of multiple interconnected quantum key servers, with user communication terminals connecting to any nearby quantum key server to reduce quantum key distribution latency. Specifically, a key distribution unit manages the generated quantum keys, distributes them to user communication terminals, and performs global dynamic scheduling when quantum keys need updating. A communication relay unit transmits quantum state data and generates quantum keys according to the quantum key distribution protocol. User communication terminals perform encryption and decryption processing on the satellite navigation data. In this application, the quantum channel can be an optical fiber network or a free-space optical link.

[0029] Specifically, user communication terminals can choose to connect to any key management node of the key distribution unit, enabling interconnection between the key management node and the user communication terminal. Once a user communication terminal connects to the key distribution unit, the unit automatically identifies the secure communication requirements of the current user communication terminal and configures the same security code between the user communication terminals requiring a secure channel through the corresponding key management node. This security code, derived from a set of security codes and generated by a quantum random process, serves as a pre-configured authentication credential between the user communication terminal and the key distribution unit, possessing the characteristic of being unreproducible. The security code set can be used as a session key between user communication terminals. When a user communication terminal connects, authentication is performed using quantum digital signatures with administrator authorization, assigning the same security code to both the sending and receiving ends of the secure communication, thereby ensuring the integrity and security of the communication.

[0030] In this embodiment, a hierarchical key management system can also be established, using the quantum key as the root key to derive session keys. These session keys, essentially quantum keys, are used to encrypt communication between user terminals (between the sender and receiver). The quantum key derives the session key, which in turn generates encrypted data packets. Furthermore, a key inheritance mechanism can be formed based on the derivation relationship to enhance the flexibility and security of key management.

[0031] After acquiring the quantum key, the user communication terminal stores it in a key storage chip within the terminal. Further, the transmitting end selects the corresponding quantum key from the key storage chip and encodes the satellite navigation data using the first set of quantum keys to generate an encrypted data packet. After encoding, the encrypted data packet is transmitted to the receiving end via a communication relay unit. The receiving end uses the same second set of quantum keys to decrypt the encrypted data packet and reconstruct the satellite navigation data.

[0032] In this embodiment, the quantum key generated by a quantum random process enables the quantum key distribution system to effectively prevent data interception and decryption attacks. Furthermore, the quantum key has a dynamic refresh function, which further reduces the possibility of data leakage and provides multiple layers of protection for communication security. Specifically, when the quantum key is used a preset number of times, the quantum key distribution unit automatically generates a new quantum key and pushes it to the relevant user communication terminal through the communication relay unit to ensure continuous communication security. The preset number of uses is set to 10.

[0033] The key distribution unit comprises a quantum key generation center, a dynamic key management server, and a post-quantum encryption engine. The quantum key generation center transmits the real-time generated quantum key in two paths according to the quantum key distribution protocol. The first path is directly transmitted to the post-quantum encryption engine via a quantum channel for session encryption. The second path connects to the dynamic key management server via a quantum channel (such as an encrypted fiber optic link) for lifecycle marking, recording the number of times the quantum key has been used and its key status. When the anti-interference control system initiates a frequency band switching command, the quantum key generation center immediately adjusts its quantum key generation strategy to adapt to the new communication frequency band requirements.

[0034] The post-quantum encryption engine continuously receives quantum keys from the quantum key generation center. Based on the security policy issued by the dynamic key management server, it automatically selects AES-256 (a block-based encryption algorithm with a 256-bit key length) or NTRU (a lattice-based encryption algorithm) to encapsulate the quantum key. After encapsulation, a session key is obtained, which is then transmitted to the anti-interference control system through a dedicated channel for frequency band adaptation processing.

[0035] The dynamic key management server is used to monitor the key status from the quantum key generation center in real time. When it detects that the quantum key is about to expire, it sends a key update instruction to the quantum key generation center and notifies the subsequent quantum encryption engine to prepare for algorithm switching. The key update instruction is sent to the communication relay unit through the quantum channel selected by the anti-interference control system.

[0036] The anti-interference control system continuously analyzes the quality of the quantum channel. When an interference threat is detected, it immediately sends a frequency band switching request to the dynamic key management server and simultaneously notifies the subsequent quantum encryption engine to adjust its encryption parameters. During the switching process, the quantum key generation center suspends the generation of new quantum keys.

[0037] Step 102: The communication relay unit compares the basis vectors of the quantum state data between the satellite and the ground station through the key distribution protocol, generates a quantum key, and sends the quantum key to the key distribution unit for storage.

[0038] Before the communication relay unit performs basis vector comparison on the quantum state data between the satellite and the ground station via the key distribution protocol, it also includes: synchronizing the clock precision of the satellite and the ground station; and controlling the satellite or ground station to send or receive the corresponding quantum state data according to a preset order and time interval.

[0039] Specifically, in the communication relay unit, an inter-satellite network is constructed based on satellites, ground stations, and quantum channels. Within the inter-satellite network, the distribution path of the quantum key is adjusted according to the satellite status, and the adjusted distribution path is fed back to the key distribution unit to update the quantum key distribution path.

[0040] Specifically, in the communication relay unit, satellites and ground stations are used as nodes, and quantum channels are used as edges to connect satellites and ground stations, constructing an inter-satellite network. Ground stations receive satellite quantum state data from satellites, perform quantum state measurements, and conduct classical communication with satellites or other ground stations for post-processing (error correction, privacy amplification). Communication networks exist between ground stations, typically via terrestrial fiber optic networks or secure internet connections.

[0041] Satellites act as trusted communication relay nodes in the air, responsible for sending qubits to ground stations. Each satellite carries an onboard quantum payload, which can be connected to other satellites via laser communication links and to ground stations via free-space optical links or radio frequency links, collectively constructing a redundant communication topology network, i.e., an inter-satellite network.

[0042] Among them, on-board quantum payloads are a type of system integrated on artificial satellites specifically designed for quantum communication. They utilize quantum mechanical principles (such as quantum entanglement and quantum superposition) to achieve secure communication and high-precision time synchronization. The inter-satellite network optimizes the distribution path of quantum keys in real time. When a satellite fails, the communication relay unit automatically selects an alternative path to continue transmitting quantum keys and satellite navigation data. The path switching information is synchronously fed back to the dynamic key management server of the key distribution unit, which then updates the key distribution strategy across the entire network.

[0043] Furthermore, the user communication terminal's dual-mode receiver connects to the satellite's onboard quantum payload via a quantum communication interface and to the ground station's communication network via a classical radio frequency interface. The dual-mode receiver operates in both quantum and classical modes.

[0044] For example, the on-board quantum payload has a built-in miniature QRNG (quantum random number generator) that can autonomously generate quantum keys in orbit and share them through a quantum key distribution protocol. When an interruption in the quantum key supply from the ground station is detected, it automatically switches to on-board key generation mode to ensure the continuous operation of the quantum key distribution system.

[0045] In quantum mode, the dual-mode receiver receives the downlink quantum key from the satellite via a SPAD (single-photon detector). When the quantum channel is interrupted, it automatically switches to classical mode, obtaining emergency communication services via a 5G link or a BeiDou short message link. The mode switching process is securely verified by a security protocol processor. The security protocol processor connects to the dual-mode receiver via a hardware-level bus and to the anti-spoofing positioning module via a secure channel. The security protocol processor employs an HSM (Hardware Security Chip Architecture) to implement hardware-level protection for the received quantum key, supporting one-time encryption and a physical circuit breaker mechanism. Upon detecting an unauthorized access attempt, a key self-destruction procedure is immediately triggered, and the current security event is reported through the anti-spoofing positioning module.

[0046] The anti-spoofing positioning module connects to the security protocol processor via a data interface and to the communication relay unit via a navigation signal receiver. It uses the quantum key stored in the security protocol processor to authenticate the source of satellite navigation data. By comparing the characteristics of the satellite navigation data with the quantum key, it identifies forged signals. When a spoofing attack is detected, it automatically switches to a backup positioning mode and notifies the dual-mode receiver to update the quantum channel.

[0047] Based on the quantum key generation according to the quantum key distribution protocol, quantum key obfuscation technology is introduced. Through dynamic routing, multi-path transmission or virtual topology obfuscation, the real distribution path of the quantum key can be hidden, thereby increasing the difficulty for attackers to eavesdrop or interfere.

[0048] The multi-mode encryption repeater is used to connect with the on-board quantum payload via a high-speed data channel. The multi-mode encryption repeater receives quantum keys from the on-board quantum payload in real time, and adjusts the encryption mode switching process synchronously with the pointing of the smart beamforming antenna according to the encryption strategy issued by the dynamic key management server.

[0049] Meanwhile, the multi-mode encryption repeater connects to the smart beamforming antenna via an RF interface and connects the anti-interference control system to the ground station via a control network. The smart beamforming antenna continuously monitors the quality of the quantum channel. When the anti-interference control system detects an interference threat, it immediately adjusts the smart beam direction to avoid the interference area and synchronously transmits the smart beam redirection command to the multi-mode encryption repeater, triggering corresponding encryption parameter adjustments.

[0050] In this embodiment, an improvement is made based on the BB84 protocol (a quantum key distribution protocol). Data between the satellite and the ground station is in the form of qubits (i.e., quantum state data). The ground station and the satellite each select a set of quantum states and transmit them as qubits. Common quantum states include Z-based quantum states (…). ) and X-base ( The ground station sends random qubits to the satellite via a quantum channel.

[0051] Furthermore, it is also possible to: introduce a quantum random number generator into the satellite to generate qubits in parallel; share the qubits with the ground station via a quantum channel; and encode the qubits according to redundancy coding to obtain quantum state data.

[0052] For example, GPS synchronization and atomic clock timing control are employed to ensure precise clock synchronization between the ground station and the satellite, guaranteeing that the transmission and reception of qubits can occur within the correct time window. Furthermore, precise timing control circuitry and related protocols enable qubits to be transmitted or received according to a predetermined sequence and time intervals, avoiding measurement errors or security vulnerabilities caused by timing deviations.

[0053] Because quantum bits (i.e., quantum state data) may experience excessive channel noise or even information loss during transmission due to extreme weather conditions such as atmospheric turbulence, storms, and heavy rain, redundant coding is used to encode quantum state data. This involves distributing a single logical quantum state across multiple physical quantum states, creating redundancy. This prevents the encoded quantum state data from being easily copied. Quantum entanglement is used to detect and correct errors, reducing the error rate and minimizing key loss during the privacy amplification stage (data compression). Furthermore, this approach compensates for quantum channel losses, extends transmission distance, and improves the feasibility and efficiency of quantum key distribution systems under complex conditions.

[0054] Furthermore, the quantum key distribution protocol in this application incorporates intelligent beamforming technology to handle quantum channels. This reduces beam realignment time from minutes to seconds, minimizing alignment errors or beam drift caused by high-speed satellite movement.

[0055] In this embodiment, the ground station and the satellite randomly select transmission basis vectors and transmit the ground station's quantum state data to the satellite based on these vectors. The satellite randomly selects measurement basis vectors and measures the ground station's quantum state data based on these vectors to obtain the measurement result. The ground station and the satellite transmit the transmission and measurement basis vectors via a classical channel. The transmission and measurement basis vectors are compared. If the ground station's transmission basis vector and the satellite's measurement basis vector are the same, the measurement result is retained. If they are different, the satellite performs error detection on the measurement result according to a preset threshold (exemplarily set to 5% of the normal range). Based on the detection result, the corresponding ground station's quantum state data is corrected to obtain corrected quantum state data. The corrected quantum state data is then compressed to generate a quantum key.

[0056] The quantum key is transmitted through a secure channel, and the satellite navigation data is encrypted using an encryption formula. The specific encryption formula is as follows:

[0057] .

[0058] In the formula, Represents the shared quantum key. This refers to the quantum key distribution protocol. and These represent ground stations and satellites, respectively.

[0059] In one possible implementation, the ground station has two sets of orthogonal bases for preparing photons with different polarization states. It randomly selects one set, randomly prepares a polarization state under the transmitting basis vector, obtains the ground station's quantum state data, and transmits it to the satellite. Simultaneously, it records the transmitted basis vector locally. Upon receiving the ground station's quantum state data, the satellite randomly selects a set of measurement basis vectors to measure it, and records the selected measurement basis vectors and the measurement results. The ground station and satellite exchange and compare their transmitted and measured basis vectors via a classical channel. This classical channel is used for key negotiation, bit error rate detection, and the exchange of security parameters between the communicating parties. If the ground station and satellite use the same measurement basis vectors for their quantum state data, the obtained quantum state data is considered identical, and the measurement results are retained. If the ground station and satellite use different measurement basis vectors for their quantum state data, resulting in different quantum state data, these results are excluded. A portion of the retained measurement results is randomly selected for public comparison to detect the error rate. If the error rate exceeds a preset threshold, the current key distribution is abandoned. Otherwise, forward error correction coding technology is applied to correct the remaining excluded quantum state data, resulting in corrected quantum state data. Privacy amplification is performed using a hash function, bit compression is applied to the corrected quantum state data, and the final quantum key is generated and stored in the key distribution unit. Furthermore, parallel processing via inter-satellite networks enables the simultaneous generation of multiple quantum keys, significantly improving the efficiency of quantum key generation.

[0060] Unlike traditional quantum key distribution protocols, the quantum key distribution protocol in this application introduces a high-speed quantum random number generator, accelerating the generation speed of quantum state data and significantly improving the quantum key generation rate. It also enables the quantum key distribution system to meet the needs of more users accessing the system simultaneously and dynamically updating quantum keys at high frequencies. Furthermore, by utilizing quantum repeaters and entanglement purification methods, it overcomes the transmission distance limitations of existing quantum key distribution protocols, achieving longer-distance quantum entanglement distribution and expanding the coverage of the "space-ground collaborative" quantum key distribution system. In addition, the adaptive quantum key distribution protocol switching mechanism can dynamically select the most suitable protocol based on the actual conditions of the quantum channel, further optimizing key distribution efficiency.

[0061] This application can also preload quantum keys into the key distribution unit according to the quantum key distribution protocol to reduce encryption latency.

[0062] Step 103: The key distribution unit dynamically updates the quantum key and distributes it to the user communication terminal. In this embodiment, the key distribution unit includes multiple key management nodes. The user communication terminal establishes a quantum channel with the communication relay unit by accessing the key management node. The key management node configures the quantum key for the quantum channel, constructing a secure channel to encrypt communication between user communication terminals.

[0063] In this embodiment, the state of each quantum key in the key distribution unit is determined. If the quantum key is in a normal state, it is stored in the key distribution unit. If the quantum key is in an abnormal state, a key generation request is initiated to the communication relay unit to update the quantum key.

[0064] Furthermore, distributing quantum keys to user communication terminals also includes: constructing an inter-satellite network based on multiple satellites and ground stations within the communication relay unit. Based on the state of the quantum key, the distribution path of the key is adjusted using the inter-satellite network, and the adjusted distribution path is fed back to the key distribution unit to update the quantum key distribution path.

[0065] For example, in satellite communications with high security requirements, an anti-eavesdropping mechanism is used to detect eavesdropping behavior. If the anti-eavesdropping mechanism detects potential eavesdropping behavior, such as the error rate of quantum state data exceeding 11% of the normal range, it will immediately activate the emergency response of the dynamic key management server, reducing the current update frequency to 1 / 3 to 1 / 2 of the original preset update frequency, which is 5-10 minutes. This dynamic key update mechanism ensures that even if some quantum keys are leaked, it will not pose a long-term threat to the quantum key distribution system.

[0066] In this embodiment of the application, a new quantum key is rapidly generated through a quantum key generation center and a post-quantum encryption engine. At the same time, the post-quantum encryption engine encapsulates the updated quantum key and transmits it through a secure channel to ensure the security of communication.

[0067] Step 104: The user communication terminal uses quantum key distribution to encrypt the satellite navigation data to obtain encrypted data packets, and then sends the encrypted data packets to the receiving end through the communication relay unit.

[0068] In this embodiment, the satellite navigation data includes information such as the satellite's position and time. The transmitting end encrypts the satellite navigation data using a quantum key that has undergone session processing. Encryption algorithms. Furthermore, this application reduces computational complexity, significantly shortens the time spent on encryption and decryption processing, and reduces the consumption of computing resources by introducing hardware accelerators, such as dedicated quantum encryption chips or AES-NI (Advanced Encryption Standard Instruction Set).

[0069] Specifically, the user communication terminal transmits the quantum key through a secure channel and encrypts the satellite navigation data. The encryption of the satellite navigation data is as follows:

[0070] .

[0071] In the formula, This indicates encrypted satellite navigation data. Indicates encryption processing Encryption algorithm, This represents the satellite navigation data before encryption. This represents a quantum key.

[0072] Quantum keys generated according to quantum key distribution protocols can dynamically adjust encryption parameters, enhancing the flexibility of encryption.

[0073] Specifically, satellite navigation data is divided into square matrices, each in bytes, known as state matrices. Each byte in the state matrix undergoes a nonlinear transformation using an S-box. An S-box is a... The matrix consists of an 8-bit hexadecimal number for each element. During the transformation, the high 4 bits of the input byte are used as the row index, and the low 4 bits as the column index to locate the corresponding transformed byte in the S-box.

[0074] For example, the input byte 0x5C becomes 0x87 after an S-box transformation. The rows of the state matrix are cyclically shifted: row 0 remains unchanged, row 1 is shifted left by 1 byte, row 2 by 2 bytes, row 3 by 3 bytes, and so on. The columns of the state matrix are then linearly transformed. Each column of 4 bytes is treated as a polynomial and modulo a fixed polynomial is performed. For example, after a linear transformation, each byte of a column [0x00, 0x01, 0x02, 0x03] will be updated with a new value, thus completing the encryption process.

[0075] In addition, according to the quantum key distribution protocol, quantum keys can be preloaded into the key distribution unit to reduce encryption latency.

[0076] Step 105: The receiving end decrypts the received encrypted data packet using quantum key distribution to obtain satellite navigation data. Specifically, decryption uses... The inverse processing of the encryption algorithm yields satellite navigation data. The reverse processing of the encryption algorithm is as follows:

[0077] .

[0078] In the formula, Representing quantum keys, This indicates encrypted satellite navigation data. This indicates the decrypted satellite navigation data. This indicates decryption processing, i.e. Inverse processing of encryption algorithms.

[0079] Furthermore, the quantum key distribution system, through quantum key distribution protocols, encryption, and decryption processes, not only improves the quality and efficiency of quantum key generation but also effectively enhances the encryption strength of satellite navigation data, ensuring that the satellite navigation data is not maliciously tampered with or cracked during transmission.

[0080] While this application provides the method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-inventive labor. The order of steps listed in this embodiment is merely one possible execution order among many and does not represent the only execution order. In actual device or client product execution, the methods shown in this embodiment or the accompanying drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment).

[0081] like Figure 2 As shown in the figure, this application embodiment also provides a signal encryption device 200 based on quantum key distribution. The device includes: a system construction module 201, a quantum key generation module 202, a key update module 203, an encryption module 204, and a decryption module 205, as detailed below.

[0082] System building module 201 is used to construct a quantum key distribution system based on multiple interconnected quantum key servers, with user communication terminals connected to the nearest quantum key server. The quantum key distribution system includes a key distribution unit and a communication relay unit, with the communication relay unit comprising satellites and ground stations. The user communication terminal includes a transmitter and a receiver.

[0083] The quantum key generation module 202 is used by the communication relay unit to perform basis vector comparison on the quantum state data of the satellite and the ground station through the key distribution protocol, generate a quantum key, and send the quantum key to the key distribution unit for storage.

[0084] The key update module 203 is used by the key distribution unit to dynamically update the quantum key and distribute the quantum key to the user communication terminal.

[0085] The encryption module 204 is used by the user communication terminal to encrypt satellite navigation data using quantum keys to obtain encrypted data packets, and then send the encrypted data packets to the receiving end through the communication relay unit.

[0086] The decryption module 205 is used by the receiver to decrypt the received encrypted data packets based on quantum keys to obtain satellite navigation data.

[0087] Some modules in the apparatus described in this application can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0088] The apparatus or module described in the above embodiments can be implemented by a computer chip or physical entity, or by a product with a certain function. For ease of description, the above apparatus is described by dividing it into various modules according to their functions. When implementing the embodiments of this application, the functions of each module can be implemented in one or more software and / or hardware. Of course, a module that implements a certain function can also be implemented by combining multiple sub-modules or sub-units.

[0089] The methods, apparatus, or modules described in this application can be implemented in a computer-readable program code manner. The controller can be implemented in any suitable manner, such as a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of a memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code manner, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included within it for implementing various functions can also be considered as structures within the hardware component. Alternatively, the device used to implement various functions can be viewed as either a software module that implements the method or a structure within a hardware component.

[0090] This application also provides an apparatus for executing a signal encryption method based on quantum key distribution. The apparatus includes: a processor; a memory for storing processor-executable instructions; and when the processor executes the executable instructions, it implements the method described in this application.

[0091] This application also provides a non-volatile computer-readable storage medium storing a computer program or instructions thereon, which, when executed, enables the method described in this application embodiment to be implemented.

[0092] Furthermore, in the various embodiments of this application, each functional module can be integrated into one processing module, or each module can exist independently, or two or more modules can be integrated into one module.

[0093] The aforementioned storage media include, but are not limited to, Random Access Memory (RAM), Read-Only Memory (ROM), Cache, Hard Disk Drive (HDD), or Memory Card. The memory can be used to store computer program instructions.

[0094] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary hardware. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product, or it can be embodied in the process of data migration. The computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, mobile terminal, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0095] The various embodiments described in this specification are presented in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on its differences from other embodiments. All or part of this application can be used in numerous general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, mobile communication terminals, multiprocessor systems, microprocessor-based systems, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices, etc.

[0096] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of this application.

Claims

1. A signal encryption method based on quantum key distribution, characterized by, The application relates to a quantum key distribution system based on multiple interconnected quantum key servers, wherein a user communication terminal is connected with a nearest quantum key server; the quantum key distribution system comprises a key distribution unit and a communication relay unit, the communication relay unit comprises a satellite and a ground station; the user communication terminal comprises a sending end and a receiving end; a double-mode receiver of the user communication terminal is connected with an on-satellite quantum load of the satellite through a quantum communication interface and connected with a communication network of the ground station through a classical radio frequency interface; a micro quantum random number generator is built in the on-satellite quantum load, used for autonomously generating quantum keys in orbit and realizing key sharing through a quantum key distribution protocol; when the quantum key supply of the ground station is detected to be interrupted, the on-satellite quantum load is automatically switched to an on-satellite key generation mode, so as to ensure continuous operation of the quantum key distribution system; quantum state data is encoded through redundant encoding, 1 logical quantum state data is dispersed to multiple physical quantum state data, and redundancy is formed, so that the encoded quantum state data cannot be copied; the communication relay unit compares base vectors of quantum state data of the satellite and the ground station through a key distribution protocol, generates quantum keys, and sends the quantum keys to the key distribution unit for storage; the key distribution unit dynamically updates the quantum keys and distributes the quantum keys to the user communication terminal; the user communication terminal encrypts satellite navigation data through the quantum keys, obtains encrypted data packets, and sends the encrypted data packets to the receiving end through the communication relay unit; and the receiving end decrypts the received encrypted data packets based on the quantum keys and obtains satellite navigation data. The key distribution unit comprises multiple key management nodes, and a user communication terminal establishes a quantum channel between the communication relay unit by accessing a key management node; The key management node configures quantum keys for the quantum channel, constructs a secure channel, and encrypts communication between the user communication terminals. Before the communication relay unit compares base vectors of quantum state data of the satellite and the ground station through a key distribution protocol, the method further comprises the following steps: Synchronizing clock accuracy of the satellite and the ground station; Controlling the satellite or the ground station to send or receive corresponding quantum state data according to a preset order and time interval. Before the communication relay unit compares base vectors of quantum state data of the satellite and the ground station through a key distribution protocol, the method further comprises the following steps: Introducing a quantum random number generator into the satellite to generate quantum bits in parallel; 2. The method of claim 1, wherein, Sharing the quantum bits with the ground station through a quantum channel; Encoding the quantum bits through redundant encoding to obtain the quantum state data.

3. The method of claim 1, wherein, The communication relay unit compares base vectors of quantum state data of the satellite and the ground station through a key distribution protocol, generates quantum keys, and comprises the following steps: The ground station and the satellite randomly select sending base vectors and send quantum state data of the ground station to the satellite based on the sending base vectors. ​ 4. The method of claim 2, wherein, ​ ​ ​ ​ 5. The method of claim 4, wherein, ​ ​ The satellite randomly selects a measurement basis vector, measures quantum state data of a ground station based on the measurement basis vector, and obtains a measurement result; wherein the sending basis vector and the measurement basis vector are transmitted between the ground station and the satellite through a classical channel; The sending basis vector and the measurement basis vector are compared; If the sending basis vector of the ground station is the same as the measurement basis vector of the satellite, the measurement result is retained; If the sending basis vector of the ground station is not the same as the measurement basis vector of the satellite, the satellite performs error detection on the measurement result according to a preset threshold; Based on the detection result, the quantum state data of the corresponding ground station is corrected to obtain corrected quantum state data; The corrected quantum state data is compressed to generate the quantum key.

6. The method of claim 1, wherein, The key distribution unit dynamically updates the quantum key, including: Determining the state of each quantum key in the key distribution unit; If the state of the quantum key is in a normal state, it is stored in the key distribution unit; If the state of the quantum key is in an abnormal state, a key generation request is initiated to the communication relay unit to update the quantum key.

7. The method of claim 1, wherein, The quantum key is distributed to the user communication terminal, further including: In the communication relay unit, an intersatellite network is constructed according to multiple satellites and ground stations; According to the state of the quantum key, the distribution path of the key is adjusted using the intersatellite network, and the adjusted distribution path is fed back to the key distribution unit to update the distribution path of the quantum key.

8. The method of claim 2, wherein, The user communication terminal encrypts satellite navigation data using the quantum key to obtain an encrypted data packet, including: The user communication terminal transmits the quantum key through the secure channel and encrypts the satellite navigation data; wherein the satellite navigation data is encrypted as follows: ; In the formula, represents the encrypted satellite navigation data, represents the satellite navigation data before encryption, encryption algorithm, represents the satellite navigation data before encryption, represents the quantum key.

9. The method of claim 1, wherein, The user communication terminal encrypts satellite navigation data using the quantum key, further including: According to the quantum key distribution protocol, the quantum key is preloaded to the key distribution unit to reduce encryption delay.

10. A signal encryption apparatus based on quantum key distribution, characterized by comprising: a quantum key distribution apparatus; a quantum key distribution receiver; and a signal encryption apparatus. Including: A system construction module is used to construct a quantum key distribution system based on multiple interconnected quantum key servers, and a user communication terminal is connected to a nearby quantum key server; wherein the quantum key distribution system includes a key distribution unit and a communication relay unit, and the communication relay unit includes satellites and ground stations; the user communication terminal includes a sending end and a receiving end; wherein a dual-mode receiver of the user communication terminal is connected to an on-board quantum payload of the satellite through a quantum communication interface and connected to a communication network of the ground station through a classical radio frequency interface; the on-board quantum payload is embedded with a micro quantum random number generator for generating quantum keys autonomously in orbit, and key sharing is achieved through a quantum key distribution protocol; when it is detected that the quantum key supply of the ground station is interrupted, the system is automatically switched to an on-board key generation mode to ensure continuous operation of the quantum key distribution system; The quantum key generation module is used for encoding processing of quantum state data through redundant encoding, dispersing one logical quantum state data to multiple physical quantum state data, forming redundancy, so that the quantum state data after encoding processing cannot be copied. The communication relay unit compares the base vectors of the quantum state data of the satellite and the ground station through a key distribution protocol, generates a quantum key, and sends the quantum key to the key distribution unit for storage. The key update module is used for the key distribution unit to dynamically update the quantum key and distribute the quantum key to the user communication terminal. The encryption module is used for the user communication terminal to encrypt satellite navigation data using the quantum key to obtain an encrypted data packet, and send the encrypted data packet to the receiving end through the communication relay unit. The decryption module is used for the receiving end to decrypt the received encrypted data packet based on the quantum key to obtain satellite navigation data.

Citation Information

Patent Citations

  • Quantum key based satellite communication encryption system and method

    CN106953729A

  • Satellite-ground integrated quantum key distribution system suitable for power system

    CN111934784A

  • Implementation method for Beidou quantum encryption communication

    CN115915119A