VPN communication system and method based on quantum server cryptomachine and post-quantum cryptography
The three-layer decoupled architecture built by quantum server cryptography machine and post-quantum cryptography algorithm solves the security vulnerabilities of traditional VPNs and the deployment difficulties of QKD+PQC scheme, realizing a VPN communication system with high security, flexible deployment and low cost, suitable for enterprise-level applications.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI CIRCULATION QUANTUM TECH CO LTD
- Filing Date
- 2026-03-23
- Publication Date
- 2026-06-26
AI Technical Summary
Traditional VPNs are vulnerable to brute-force attacks due to static keys that have not been rotated for a long time during key exchange and certificate authentication. Improper storage of private keys makes them susceptible to man-in-the-middle attacks. Furthermore, traditional key exchange and certificate authentication rely on mathematical problems, which are vulnerable to quantum computer attacks. In addition, QKD+PQC solutions are inflexible in deployment and costly, failing to meet the needs of enterprise-level applications.
A quantum server cryptographic machine is used to generate quantum true random numbers. Combined with post-quantum cryptography (PQC) algorithm, a three-layer decoupled architecture is constructed through cloud platform and VPN terminal encryption device to realize the dynamic generation, management and distribution of quantum keys. It is deployed using existing network and adopts lattice-based key encapsulation mechanism and digital signature algorithm for key negotiation and authentication.
It achieves dual protection against quantum computing threats, improves key update frequency and deployment flexibility, reduces deployment costs, is suitable for diverse scenarios, and significantly improves security and networking efficiency.
Smart Images

Figure CN122293316A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of VPN communication technology, and more specifically, to a VPN communication system and method based on quantum server cryptography and post-quantum cryptography. Background Technology
[0002] SSL / TLS VPN solutions are widely used in scenarios such as remote work, cross-border trade, and branch office interconnection. However, VPNs involve key exchange and certificate authentication during the blockchain establishment process. Traditional VPNs may suffer from risks such as static keys not being rotated for a long time, leading to brute-force attacks; improper private key storage leading to man-in-the-middle attacks; and pre-shared keys being vulnerable to brute-force attacks. In addition, the vulnerability of traditional key exchange and certificate authentication, which rely on mathematical problems, makes them difficult to defend against attacks by quantum computers. A current mainstream solution is to introduce QKD+PQC. Compared with traditional methods, QKD enables dynamic generation of quantum keys, using a different key for each session, while PQC provides automatic key rotation and distributed management capabilities. Quantum keys themselves possess information-theoretic security, meaning they cannot be copied or calculated. This effectively solves the security risks of traditional VPNs. QKD provides absolute security at the physical layer, while PQC addresses quantum threats at the algorithmic layer. The combination of the two creates a full-chain quantum security fortress for VPNs, from key generation and distribution to destruction.
[0003] However, the QKD+PQC scheme requires fiber optic channels to distribute quantum keys and necessitates the deployment of QKD devices and quantum repeaters in pairs. This makes its deployment inflexible and unable to fully utilize existing networks. Furthermore, fiber optic link costs account for over 70% of deployment costs. This makes the QKD+PQC scheme more suitable for long-distance, cross-domain communication, such as inter-provincial quantum backbone networks. It is less suitable for enterprise-level applications that require flexible, convenient, and cost-effective deployment, and the ability to fully utilize existing infrastructure.
[0004] Patent application CN113489586A discloses a VPN network system compatible with quantum key negotiation, including a quantum key application device (including an IPSec VPN gateway, an SSL VPN gateway, a cryptographic machine, and an encryption application client), a random number service device, a virtual machine for the quantum node device, a security isolation device, a virtual quantum link slicing service device, and a quantum key service device. This invention can provide quantum service access and random number services to the quantum key application device through user-side quantum nodes, and the quantum key service device provides real-time negotiation of end-to-end shared quantum keys based on virtual quantum link slicing. However, this patent cannot completely solve the existing technical problems, nor can it meet the needs of this invention. Summary of the Invention
[0005] To address the shortcomings of existing technologies, the purpose of this invention is to provide a VPN communication system and method based on quantum server cryptography and post-quantum cryptography.
[0006] The VPN communication system based on quantum server cryptography and post-quantum cryptography provided by the present invention includes: a cloud platform and a VPN terminal encryption device;
[0007] The VPN terminal encryption device has at least two devices, and they communicate with the cloud platform via a network. The cloud platform includes a quantum server cryptographic machine, a key management service platform (KMS), and a quantum key service platform (QKS). The quantum server cryptographic machine is used to generate quantum true random numbers and generate quantum keys based on the quantum true random numbers; The Key Management Service Platform (KMS) is used to store and manage the quantum keys. The quantum key service platform QKS is used to support the secure distribution of the quantum key to the VPN terminal encryption device through a post-quantum cryptography algorithm. The VPN terminal encryption device has a built-in secure storage medium, which is pre-filled with user information, the local quantum cryptography private key, and the cloud-based quantum cryptography public key. The VPN terminal encryption device is used to obtain the quantum key from the cloud platform as a session key and establish a VPN communication tunnel with the peer VPN terminal encryption device based on the session key.
[0008] Preferably, the quantum server cryptographic machine includes a quantum random number generator (QRNG), and the QRNG includes: A quantum entropy source acquisition unit is used to generate simulated random signals based on quantum noise from vacuum field fluctuations or amplified spontaneous emission. An analog-to-digital converter (ADC) is used to sample and quantize the analog random signal into a raw quantum random bit stream; The post-processing unit is used to debias the original quantum random bit stream and output a uniformly distributed true random bit stream. The key derivation unit is used to take the true random bit stream as a seed input key derivation function to generate the quantum key.
[0009] Preferably, the quantum key distribution platform (QKS) employs the lattice-based key encapsulation mechanism (KEM) algorithm during the key exchange process in post-quantum cryptography. The expression for the KEM algorithm is as follows: , where A is the public coefficient matrix, s is the secret private key vector, e is the noise error vector, and b is the calculated vector.
[0010] Preferably, the quantum key service platform QKS uses a lattice-based digital signature algorithm to sign communication messages during the post-quantum cryptography authentication process.
[0011] Preferably, the communication process between the VPN terminal encryption device and the cloud platform includes: The first VPN terminal encryption device obtains local user information and post-quantum cryptography public and private keys from the secure storage medium; The first VPN terminal encryption device initiates an authenticated Hypertext Transfer Protocol Secure HTTPS connection to the Quantum Key Service Platform (QKS). The first VPN terminal encryption device applies to and obtains the session key and corresponding key identifier ID for this VPN communication from the quantum key service platform QKS; The first VPN terminal encryption device initiates a VPN session request to the second VPN terminal encryption device, and the VPN session request carries the key identifier ID; The second VPN terminal encryption device requests and obtains the same session key from the quantum key service platform QKS based on the key identifier ID.
[0012] Preferably, all request messages sent by the VPN terminal encryption device to the quantum key service platform QKS are processed by a post-quantum cryptography algorithm. Specifically, the content of the request message is encrypted using a shared key generated from the peer's post-quantum cryptography public key, and the request message is signed using the local post-quantum cryptography private key. The request message encapsulates the encrypted shared key ciphertext and the identification information of the local post-quantum cryptography public key.
[0013] Preferably, the VPN terminal encryption device is configured with a Security Association (SA) policy, which specifies that the VPN terminal encryption device uses a quantum key distributed from the cloud platform as a session key, and that the VPN terminal encryption device re-applies to the cloud platform and synchronizes a new session key after the session key expires.
[0014] The VPN communication method based on quantum server cryptography and post-quantum cryptography provided by the present invention includes the following steps: Step 1: The quantum server cryptographic machine on the cloud platform generates quantum true random numbers, and a quantum key is generated based on the quantum true random numbers; Step 2: The quantum key is stored and managed by the Key Management Service (KMS) platform on the cloud platform; Step 3: The first VPN terminal encryption device initiates an authentication and key application request to the quantum key service platform QKS on the cloud platform; Step 4: The quantum key service platform QKS securely distributes the quantum key as a session key to the first VPN terminal encryption device based on the post-quantum cryptography algorithm, and returns the corresponding key identifier ID; Step 5: The first VPN terminal encryption device initiates a VPN session request carrying the key identifier ID to the second VPN terminal encryption device; Step 6: The second VPN terminal encryption device requests and obtains the same session key from the quantum key service platform QKS based on the key identifier ID; Step 7: The first VPN terminal encryption device and the second VPN terminal encryption device establish a VPN communication tunnel based on the session key and conduct encrypted communication.
[0015] Preferably, the steps of the quantum key distribution platform QKS based on post-quantum cryptography algorithms for secure key distribution specifically include: Key negotiation is performed using the KEM algorithm, a lattice-based key encapsulation mechanism. A lattice-based digital signature algorithm is used to sign the distributed messages; The expression for the key encapsulation mechanism KEM algorithm is as follows: , where A is the public coefficient matrix, s is the secret private key vector, e is the noise error vector, and b is the calculated vector.
[0016] Preferably, the VPN terminal encryption device has a built-in secure storage medium pre-filled with user information and post-quantum cryptographic public and private keys; the method further includes: When the first VPN terminal encryption device or the second VPN terminal encryption device sends a request message to the quantum key service platform QKS, it uses the shared key generated by the peer's post-quantum cryptography public key to encrypt the message content, and uses its own post-quantum cryptography private key to sign the message.
[0017] Compared with the prior art, the present invention has the following beneficial effects: (1) This invention uses quantum random number generation technology and post-quantum cryptography (PQC) algorithm. The dual protection mechanism ensures that the key distribution and negotiation process cannot be cracked by quantum computers, thus solving the vulnerability of traditional public key cryptosystems under the threat of quantum computing. (2) The present invention adopts a three-layer decoupled architecture (key generation, key management, application access) to realize dynamic supply of keys, real-time monitoring and risk prevention and control, improve the key update frequency, and support traceability, which is significantly better than the static key management of traditional VPNs. (3) This invention uses a quantum server cryptographic machine to replace the QKD device as the basis for key generation, solves the "last mile" problem of QKD by pre-filling the key, and provides a standardized API interface by utilizing its heterogeneous encapsulation capability, so that VPN applications do not need to rely on the end-to-end physical link of QKD. (4) The present invention uses a traditional network to replace the fixed fiber optic link in the QKD scheme. Through open interfaces, VPN communication can be quickly integrated into diverse scenarios such as full office and Internet of Things, making deployment more flexible and improving the efficiency of large-scale networking. Attached Figure Description
[0018] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 This is a VPN communication mode based on quantum server cryptography machine + PQC. Detailed Implementation
[0019] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the protection scope of the present invention.
[0020] Example The quantum server cryptographic machine + PQC (post-quantum cryptography) mode proposed in this invention uses a QRNG (quantum random number generator) to locally generate truly random numbers as the original key material. The quantum server cryptographic machine, a key management service platform (KMS), and a quantum key service platform (QKS) complete the storage, management, and distribution of quantum keys generated from these truly random numbers. This solution offers high security, convenient and flexible deployment, and controllable costs, meeting most common commercial requirements.
[0021] Compared to traditional solutions, this approach offers significant improvements in three dimensions: key generation security (using a quantum true random entropy source instead of a pseudo-random algorithm), algorithm resistance to quantum attacks, and physical security. It constructs a triple protection system of "physical true randomness + mathematical quantum resistance + hardware leak prevention," providing a verifiable and long-term security foundation for high-security scenarios. The specific process is as follows: Step 1: Secure key generation. QRNG uses amplified spontaneous emission / vacuum fluctuation noise to generate an entropy source, solving the problem of small seed space and brute-force attack of traditional pseudo-random number (PRNG). Step 2: Quantum-resistant algorithm. The PQC algorithm uses a lattice-based Kyber (key exchange) / Dilithium (signature) algorithm for key negotiation and signing, solving the problem that the RSA / ECC algorithm collapses instantly in the face of Shor's algorithm in quantum computers; Step 3: Physical security, physical machine-level isolation between the cryptographic operation environment and the business application environment; constant-time implementation based on OQS (Open Quantum Security) to eliminate time leakage; plaintext keys are not written to disk to prevent key leakage caused by physical medium theft, and the external interface is highly convergent, significantly compressing the physical attack surface and solving the problem that the physical security boundary of traditional solutions is equivalent to the logical boundary of the operating system, which is easily breached; it fixes the "physical" vulnerability that is most easily exploited in traditional software, preventing remote key speculation via the network; and it reduces the risk of key leakage after the physical medium is stolen.
[0022] Regarding key generation security, traditional VPN devices typically rely on software algorithms to generate "pseudo-random numbers," which are essentially deterministic mathematical formulas and are susceptible to being guessed. In contrast, quantum server cryptographic machines utilize the intrinsic randomness of quantum mechanics (Heisenberg's uncertainty principle) to generate keys.
[0023] Its specific implementation process includes: 1) Quantum entropy source acquisition: Process: The laser inside the device emits laser light, which is then injected into a detection system based on vacuum field fluctuations or amplified spontaneous emission through a beam splitter. The quantum noise is then measured using a photodetector.
[0024] Physical phenomena: According to the uncertainty principle of quantum mechanics, the vacuum field always exhibits unavoidable zero-point oscillations (vacuum fluctuations); in the process of amplifying spontaneous emission, the generation and phase of photons also possess intrinsic quantum randomness. Both of these physical phenomena lead to the amplitude or phase of the light field exhibiting essentially unpredictable random fluctuations.
[0025] Conversion: The photodetector converts the light signal carrying quantum noise into an analog current signal, and then the noise signal is sampled and quantized by a high-speed analog-to-digital converter (ADC), ultimately converting the continuous physical random fluctuations into a discrete digital random bit stream.
[0026] 2) Post-processing (Whitening): Process: The original quantum bit stream may contain slight physical biases (such as imperfect detection efficiency). The quantum server cryptographic machine uses algorithms such as Toeplitz hash matrix extraction to extract the original data and output an unbiased, uniformly distributed, truly random bit stream.
[0027] 3) Key generation: Process: The extracted true random bit stream is used as a seed and input into the key derivation function (HKDF) to generate the symmetric key required for VPN communication.
[0028] In the key negotiation and authentication stages, traditional schemes can be broken by Shor's algorithm. The PQC scheme uses algorithms based on mathematical problems such as lattice problems, which can resist brute-force search by quantum computers.
[0029] Its specific implementation process includes: 1) Key Encapsulation (KEM): The device uses the Kyber algorithm to generate a public-private key pair. The public key is used to encapsulate the session key, and the private key is used to decapsulate it.
[0030] 2) Identity authentication: Use PQC signature algorithms such as Dilithium to sign communication messages to prevent man-in-the-middle attacks.
[0031] The Kyber algorithm expression is: , where A is the public coefficient matrix (part of the public key), s is the secret private key (small vector), e is the tiny error (noise) introduced to improve security, and b is the computed vector, which is another part of the public key.
[0032] The challenge faced by attackers (LWE problem) is: given and Please find .because The existence of this problem is considered extremely difficult in mathematics and in quantum computing. Currently, neither classical nor quantum computers can solve this problem in polynomial time. Compared to traditional solutions, the quantum server-based cryptographic machine + PQC scheme offers a significant and fundamental improvement in physical security. This improvement is primarily reflected in the convergence of the attack surface and the enhanced transformation of the key material's form:
[0033] Compared to the QKD (Quantum Key Distribution) + PQC scheme, this scheme exhibits significantly lower end-to-end encryption latency (<10ms) compared to the cross-domain key negotiation QKD + PQC scheme (≥50ms). In terms of deployment costs, a single quantum server cryptographic machine and related server software can operate independently in the cloud, eliminating the need for a dedicated fiber optic network and reducing hardware costs by 60%. Regarding security, QKD + PQC provides unconditional physical layer security (any eavesdropping leading to quantum state collapse is detectable), while the quantum server cryptographic machine relies on the mathematical security of PQC. PQC requires continuous algorithm updates to address new threats, but the quantum cryptographic machine + PQC is easier to deploy, and QRNG + PQC already meets the needs of most commercial scenarios.
[0034] The theoretical analysis of latency performance (core processing latency of key acquisition and algorithm operation, excluding network transmission) is as follows:
[0035] The high cost of the QKD+PQC solution mainly lies in dedicated facilities, professional data center environments, and operation and maintenance. QKD requires the laying or leasing of dedicated fiber optic channels (usually requiring independent fiber cores), and the transmission distance is limited (reliable relay nodes are needed for distances of hundreds of kilometers). Dedicated QKD terminal equipment (such as transmitters and receivers) is expensive and requires a professional data center environment and operation and maintenance. The cost advantage of the quantum server cryptographic machine + PQC solution is mainly reflected in its universal deployment and easy scalability: the quantum server cryptographic machine is essentially a high-performance PCIe card or server that can be directly deployed in existing data centers or the cloud, utilizing existing IP networks (Internet, 5G, fiber optic networks) for transmission, without the need for dedicated fiber optics. Since it eliminates the expensive QKD dedicated hardware (detectors, lasers, etc.) and dedicated fiber optic leasing / laying costs, only server and software costs remain. According to industry estimates, in small to medium-sized networks, the overall hardware investment of this solution may indeed be only about 30% to 40% of that of the QKD solution.
[0036] The Quantum Key Service (QKS) platform, acting as a cloud-based front-end, provides user management and cloud certificate registration / acquisition functions, and deploys the PQC algorithm to support secure key distribution. VPN (Virtual Private Network) terminal devices store their own user information, private key, and cloud public key in secure storage media (such as u-keys or secure storage cards). This storage operation is completed synchronously by the operator during the user registration process with the cloud.
[0037] After the terminal device starts up, it requests / obtains a key from the cloud according to the pre-configured identity, SA (Security Association) policy, protection node, and tunnel information. The main process is as follows: 1. The client terminal retrieves user information and public / private keys related to PQC from the secure storage medium; 2. The client terminal initiates an HTTPS (Hypertext Transfer Protocol Secure) request to the cloud and completes user authentication; 3. The client terminal initiates an HTTPS request to the cloud to request the allocation of a session key for this communication; 4. The client terminal initiates a VPN session request to the server terminal, and carries the key information in the request—the ID of the cloud quantum key; 5. After retrieving relevant information from the secure storage medium and completing user registration, the server terminal also sends a request to the cloud to obtain the quantum key with the specified ID.
[0038] Based on the above process, the client and server terminal devices obtain the same quantum key as their VPN communication session key. The client / server terminal will re-apply for and synchronize the session key after the session key expires.
[0039] To ensure the security of key distribution, during communication between the terminal device and the cloud, all messages sent by the sending end adhere to PQC requirements. The sent messages are encrypted using a shared key generated from the peer's PQC public key, and signed using the local PQC private key. In addition to the request content, the sent message entity should also include the ciphertext of the shared key and the ID information of the local PQC public key.
[0040] like Figure 1 As shown, the scheme should deploy server cryptographic machine hardware with QRNG (to generate quantum keys based on true random numbers) and key management service platform KMS and quantum key service platform QKS software (to provide PQC distribution function) in the cloud to build an overall cloud quantum key distribution platform.
[0041] On the VPN application side, VPN endpoint quantum encryption devices should be deployed separately for each independent application. The external network ports of each endpoint quantum encryption device should be interconnected. Each endpoint quantum encryption device should be inserted into a secure storage device filled with PQC-related certificates and user information. This VPN endpoint quantum encryption device must support: specifying the use of cloud-based quantum keys in the SA policy, and providing the function of requesting / retrieving cloud-based quantum keys in the background, including the accompanying PQC service and cloud access process. The remaining configuration is consistent with classic VPN endpoint devices.
[0042] Therefore, VPN terminal quantum encryption devices can establish sessions using quantum keys securely distributed in the cloud, with each session using a different key. VPN applications can communicate over a secure tunnel built between VPN terminal quantum encryption devices.
[0043] Those skilled in the art will understand that, in addition to implementing the system, apparatus, and their modules provided by this invention in purely computer-readable program code, the same program can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, the system, apparatus, and their modules provided by this invention can be considered a hardware component, and the modules included therein for implementing various programs can also be considered structures within the hardware component; alternatively, modules for implementing various functions can be considered both software programs implementing the method and structures within the hardware component.
[0044] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.
Claims
1. A VPN communication system based on quantum server cryptography and post-quantum cryptography, characterized in that, include: Cloud platform and VPN terminal encryption devices; The VPN terminal encryption device has at least two devices, and they communicate with the cloud platform via a network. The cloud platform includes a quantum server cryptographic machine, a key management service platform (KMS), and a quantum key service platform (QKS). The quantum server cryptographic machine is used to generate quantum true random numbers and generate quantum keys based on the quantum true random numbers; The Key Management Service Platform (KMS) is used to store and manage the quantum keys. The quantum key service platform QKS is used to support the secure distribution of the quantum key to the VPN terminal encryption device through the post-quantum cryptography PQC algorithm. The VPN terminal encryption device has a built-in secure storage medium, which is pre-filled with user information, the local quantum cryptography private key, and the cloud-based quantum cryptography public key. The VPN terminal encryption device is used to obtain the quantum key from the cloud platform as a session key and establish a VPN communication tunnel with the peer VPN terminal encryption device based on the session key.
2. The VPN communication system based on quantum server cryptography and post-quantum cryptography according to claim 1, characterized in that, The quantum server cryptographic machine includes a quantum random number generator (QRNG), which comprises: A quantum entropy source acquisition unit is used to generate simulated random signals based on quantum noise from vacuum field fluctuations or amplified spontaneous emission. An analog-to-digital converter (ADC) is used to sample and quantize the analog random signal into a raw quantum random bit stream; The post-processing unit is used to debias the original quantum random bit stream and output a uniformly distributed true random bit stream. The key derivation unit is used to take the true random bit stream as a seed input key derivation function to generate the quantum key.
3. The VPN communication system based on quantum server cryptography and post-quantum cryptography according to claim 1, characterized in that, The quantum key distribution platform (QKS) employs the lattice-based key encapsulation mechanism KEM algorithm during key exchange in post-quantum cryptography. The expression for the KEM algorithm is as follows: , where A is the public coefficient matrix, s is the secret private key vector, e is the noise error vector, and b is the calculated vector.
4. The VPN communication system based on quantum server cryptography and post-quantum cryptography according to claim 3, characterized in that, The quantum key service platform QKS uses a lattice-based digital signature algorithm to sign communication messages during the post-quantum cryptography authentication process.
5. The VPN communication system based on quantum server cryptography and post-quantum cryptography according to claim 1, characterized in that, The communication process between the VPN terminal encryption device and the cloud platform includes: The first VPN terminal encryption device obtains local user information and post-quantum cryptography public and private keys from the secure storage medium; The first VPN terminal encryption device initiates an authenticated Hypertext Transfer Protocol Secure HTTPS connection to the Quantum Key Service Platform (QKS). The first VPN terminal encryption device applies to and obtains the session key and corresponding key identifier ID for this VPN communication from the quantum key service platform QKS; The first VPN terminal encryption device initiates a VPN session request to the second VPN terminal encryption device, and the VPN session request carries the key identifier ID; The second VPN terminal encryption device requests and obtains the same session key from the quantum key service platform QKS based on the key identifier ID.
6. The VPN communication system based on quantum server cryptography and post-quantum cryptography according to claim 5, characterized in that, The request messages sent by the VPN terminal encryption device to the quantum key service platform QKS are all processed by post-quantum cryptography algorithms. Specifically, the content of the request message is encrypted using a shared key generated from the peer's post-quantum cryptography public key, and the request message is signed using the local post-quantum cryptography private key. The request message encapsulates the encrypted shared key ciphertext and the identification information of the local post-quantum cryptography public key.
7. The VPN communication system based on quantum server cryptography and post-quantum cryptography according to claim 1, characterized in that, The VPN terminal encryption device is configured with a Security Association (SA) policy, which specifies that the VPN terminal encryption device uses a quantum key distributed from the cloud platform as the session key, and that the VPN terminal encryption device re-applies to the cloud platform and synchronizes a new session key after the session key expires.
8. A VPN communication method based on quantum server cryptography and post-quantum cryptography, applied to the VPN communication system based on quantum server cryptography and post-quantum cryptography as described in claim 1, characterized in that, Includes the following steps: Step 1: The quantum server cryptographic machine on the cloud platform generates quantum true random numbers, and a quantum key is generated based on the quantum true random numbers; Step 2: The quantum key is stored and managed by the Key Management Service (KMS) platform on the cloud platform; Step 3: The first VPN terminal encryption device initiates an authentication and key application request to the quantum key service platform QKS on the cloud platform; Step 4: The quantum key service platform QKS securely distributes the quantum key as a session key to the first VPN terminal encryption device based on the post-quantum cryptography algorithm, and returns the corresponding key identifier ID; Step 5: The first VPN terminal encryption device initiates a VPN session request carrying the key identifier ID to the second VPN terminal encryption device; Step 6: The second VPN terminal encryption device requests and obtains the same session key from the quantum key service platform QKS based on the key identifier ID; Step 7: The first VPN terminal encryption device and the second VPN terminal encryption device establish a VPN communication tunnel based on the session key and conduct encrypted communication.
9. The VPN communication method based on quantum server cryptography and post-quantum cryptography according to claim 8, characterized in that, The quantum key distribution platform QKS, based on post-quantum cryptography algorithms, specifically includes the following steps for secure key distribution: Key negotiation is performed using the KEM algorithm, a lattice-based key encapsulation mechanism. A lattice-based digital signature algorithm is used to sign the distributed messages; The expression for the key encapsulation mechanism KEM algorithm is as follows: , where A is the public coefficient matrix, s is the secret private key vector, e is the noise error vector, and b is the calculated vector.
10. The VPN communication method based on quantum server cryptography and post-quantum cryptography according to claim 8, characterized in that, The VPN terminal encryption device has a built-in secure storage medium pre-filled with user information and post-quantum cryptographic public and private keys; the method further includes: When the first VPN terminal encryption device or the second VPN terminal encryption device sends a request message to the quantum key service platform QKS, it uses the shared key generated by the peer's post-quantum cryptography public key to encrypt the message content, and uses its own post-quantum cryptography private key to sign the message.
Citation Information
Patent Citations
VPN network system compatible with quantum key negotiation
CN113489586A