An encryption system and method based on quantum random numbers
By using the quantum random number generator to generate true random numbers as encryption keys in the instant communication system, and using the obfuscation protocol to disguise and transmit the data, the security risks of pseudo-random number encryption in the prior art are solved, and the resistance to quantum computer cracking and communication efficiency are improved.
Patent Information
- Application Number
- CN202210745366.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-27
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-06-27
AI Technical Summary
Existing instant messaging applications use pseudo-random numbers generated by soft algorithms for encryption, which poses security risks. Especially when facing the cracking threat of quantum computers, existing encryption algorithms such as RSA public key cryptography algorithms are easily cracked.
The encryption system based on quantum random numbers is adopted to generate true random numbers as encryption keys through the quantum random number generator, and the obfuscation protocol is used to disguise and transmit information to ensure the irregularity of the data transmission channel and prevent information leakage.
It improves the security of data transmission, prevents quantum computers from cracking existing encryption algorithms, reduces the computing time when clients use soft algorithms to generate pseudo-random numbers, and improves communication efficiency.
Smart Images

Figure CN115150076B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum encryption technology, and in particular to an encryption system and method based on quantum random numbers. Background Art
[0002] In recent years, the development of instant messaging software has advanced by leaps and bounds. In just a few years, network instant messaging software has a great tendency to replace traditional communication methods. Instant messaging software has also ceased to be just a simple chatting tool and has developed into a comprehensive information platform integrating communication, information, e-commerce, office collaboration, and enterprise customer service. With the development of mobile Internet, Internet instant messaging software is also expanding towards mobile, that is, instant messaging software has gradually developed from the initial personal life chatting application into an information platform integrating enterprise office communication, customer service communication, and e-commerce. However, when enterprises build internal instant messaging-related platforms, the easiest and most important problem to be overlooked is data security; especially for some units with high security and confidentiality requirements in the country, the above data security problem is more intractable. For example, when a citizen makes a call or sends and receives text messages using a mobile phone, lawbreakers can use fixed devices or drones to perform wireless signal filtering, eavesdropping, and signal decryption on the communication content transmitted by the above citizen. If the instant messaging software or related platform cannot ensure the security of encrypted data transmission, users can only communicate face-to-face, which greatly reduces work efficiency. Therefore, for instant messaging software or related platforms used by units or personnel with high confidentiality requirements or involving secrets, in addition to meeting the basic functions required for instant messaging, it is also necessary to ensure the security of encrypted data transmission during communication, so that even if the data is eavesdropped / intercepted during transmission, it cannot be deciphered.
[0003] Existing application programs / clients for instant messaging usually adopt an encryption mechanism combining asymmetric encryption and symmetric encryption, that is, when a user installs an application program / client for instant messaging, two keys are generated. The above two keys are a public key and a private key respectively. And a public key corresponds to a private key one by one. The application program / client for instant messaging encrypts data using the public key (public key) and decrypts it using the corresponding private key (private key). When the application program / client for instant messaging performs data transmission, the above application program / client will generate a new key pair to encrypt the data, so as to achieve encryption per session to ensure the secure transmission of data.
[0004] However, the above-mentioned existing technologies still have the following technical deficiencies: Existing applications / clients for instant messaging usually encrypt through pseudo-random numbers generated by soft algorithms, that is, generate random numbers through some mathematical algorithms, and the above-mentioned random numbers are not truly random numbers. This is because secure pseudo-random numbers in cryptography are not compressible, while the corresponding true random numbers can usually only be generated by physical systems. Therefore, the existing technology of encrypting the information to be transmitted through pseudo-random numbers generated by soft algorithms has certain security risks. If the setting of the above soft algorithm lacks rigor, the above soft algorithm will generate duplicate random keys, which may lead to the storage medium being attacked and cracked, and ultimately may cause security incidents such as key leakage. For example, the existing RSA public-key cryptography algorithm is one of the most widely used algorithms for secure communication and digital signature on the network currently. The security of the above RSA public-key cryptography algorithm is based on the difficulty of prime factorization in number theory, so the RSA public-key cryptography algorithm needs to use a large enough integer. In short, the more difficult the factorization is, the more difficult the password is to be deciphered, and the higher the security strength of the password. If someone finds an algorithm that can quickly factorize, then the reliability of the information encrypted by the RSA public-key cryptography algorithm will drop rapidly. For example, with the emergence of the SHOR algorithm and the in-depth research on quantum computers, the parallelism of quantum computing can be used to quickly factorize the prime factors of large numbers, so that quantum computers can easily crack the currently widely used encryption algorithms (such as the RSA public-key cryptography algorithm), and seriously threaten the information security in fields such as banks, networks, and e-commerce. The existing password encryption and decryption system includes symmetric and asymmetric encryption. If a supercomputer is used to crack the existing password encryption and decryption system, it is only a matter of time for the supercomputer to decipher the plaintext in transmission (such as encrypted information). Therefore, it is necessary to improve the deficiencies of the existing technology.
[0005] In addition, on the one hand, there are differences in the understanding of those skilled in the art; on the other hand, although the applicant studied a large number of documents and patents when making this invention, all details and content are not listed in detail due to space limitations. However, this does not mean that this invention does not possess the features of these existing technologies. On the contrary, this invention already possesses all the features of the existing technologies, and the applicant reserves the right to add relevant existing technologies in the background art. Summary of the Invention
[0006] Existing applications / clients for instant messaging usually encrypt through pseudo-random numbers generated by soft algorithms, that is, generate random numbers through some mathematical algorithms, and the above-mentioned random numbers are not truly random numbers. This is because secure pseudo-random numbers in cryptography are not compressible, while the corresponding true random numbers can usually only be generated by physical systems. Therefore, the existing technology of encrypting the information to be transmitted through pseudo-random numbers generated by soft algorithms has certain security risks.
[0007] In view of the deficiencies of the prior art, the present invention provides an encryption system and method based on quantum random numbers.
[0008] The method at least includes:
[0009] At least two clients send public keys corresponding to the clients to the server, and the clients can act as the sender or receiver of the information to be transmitted;
[0010] The server receives the public keys corresponding to the clients sent by the clients, and the server sends the public key of the client acting as the receiver of the information to be transmitted to the client acting as the sender of the information to be transmitted;
[0011] The quantum random number generator sends a quantum random key corresponding to the information to be transmitted to the server, and the server receives the quantum random key;
[0012] The server sends the quantum random key to the client acting as the sender of the information to be transmitted;
[0013] The client acting as the sender of the information to be transmitted encrypts the information to be transmitted using the quantum random key, and encrypts the quantum random key using the public key of the client acting as the receiver of the information to be transmitted, and then sends the data to be transmitted including at least the information to be transmitted and the quantum random key to the client acting as the receiver of the information to be transmitted;
[0014] After receiving the information to be transmitted, the client acting as the receiver of the information to be transmitted decrypts the quantum random key to obtain the quantum random key, and then decrypts the information to be transmitted using the quantum random key to obtain the information to be transmitted.
[0015] However, the structure, traffic rate, access address, etc. of the data packets (such as the information to be transmitted) in the data transmission channel between the clients are usually fixed or regular, and there will be no mixing of the data traffic of other application programs in the data in the above-mentioned data transmission channel. Therefore, the data packets are prone to be analyzed and / or located by some lawless elements, resulting in the security risk of information leakage. Therefore, the client acting as the sender of the information to be transmitted in the present invention sends the data to be transmitted including the information to be transmitted and the quantum random key to the client acting as the receiver of the information to be transmitted based on the obfuscation protocol. The obfuscation protocol mainly protects the information to be transmitted by the client by obfuscating the information to be transmitted in the data transmission channel.
[0016] According to a preferred embodiment, the step of sending the data to be transmitted including the information to be transmitted and the quantum random key to the client as the recipient of the information to be transmitted includes:
[0017] The client as the sender of the information to be transmitted disguises at least the information to be transmitted in the data to be transmitted based on an obfuscation protocol and forms first obfuscated data;
[0018] The server obtains the first obfuscated data and parses the first obfuscated data according to the obfuscation protocol to obtain the real request in the information to be transmitted;
[0019] The server forwards the first obfuscated data to the client as the recipient of the information to be transmitted corresponding to the real request based on the real request;
[0020] The client as the recipient of the information to be transmitted obtains the first obfuscated data forwarded by the server;
[0021] The client as the recipient of the information to be transmitted parses the first obfuscated data forwarded by the server based on the obfuscation protocol and obtains the data to be transmitted from the first obfuscated data.
[0022] According to a preferred embodiment, the first obfuscated data at least includes the information to be transmitted, the quantum random key, the obfuscated request, and the identifier. The obfuscated request corresponding to the real request in the information to be transmitted is generated by the client as the sender of the information to be transmitted based on the obfuscation protocol. The identifier is used to identify the obfuscation algorithm used by the client in the process of generating the obfuscated request. In the case where multiple servers can form a server group, the client as the sender of the information to be transmitted can send the first obfuscated data to at least one server corresponding to the obfuscated request in the server group based on the obfuscated request.
[0023] According to a preferred embodiment, the method for disguising the information to be transmitted includes:
[0024] The client as the sender of the information to be transmitted generates the obfuscated request through the obfuscation algorithm to hide the real request corresponding to the information to be transmitted;
[0025] The client as the sender of the information to be transmitted combines the information to be transmitted, the quantum random key, the obfuscated request, and the identifier corresponding to the obfuscation algorithm into the first obfuscated data.
[0026] Through the above configuration method, the client can use a variety of algorithms to disguise the real requests in the information to be transmitted, and can add disguised requests randomly generated by the disguise algorithm to the first disguised data, so as to ensure the randomness of the server accessed by the client / the client as the recipient of the information to be transmitted, and at the same time prevent the real requests corresponding to the information to be transmitted and the client as the recipient of the information to be transmitted corresponding to the real requests from being analyzed by criminals; at the same time, both the client and the server can disguise the real requests in the information to be transmitted based on the obfuscation protocol, and forward the first disguised data to the client as the recipient of the information to be transmitted corresponding to the real requests through the server corresponding to the disguised request, so as to hide the real requests of the information to be transmitted and prevent the leakage of the information to be transmitted.
[0027] In the prior art, the access address of the data transmitted by the client is often fixed. However, in the present invention, the information to be transmitted sent by the client is transmitted to the client as the recipient of the information to be transmitted through any one or more servers in the server group. Since the first disguised data corresponding to the information to be transmitted can be forwarded to the client as the recipient of the information to be transmitted corresponding to the real requests through a random one of the servers, the data transmission channel for transmitting the information to be transmitted is constantly changing and has no rules to follow, thereby preventing criminals from obtaining the information to be transmitted (such as real requests) and / or obtaining relevant information of the information to be transmitted from a fixed data transmission channel.
[0028] According to a preferred embodiment, the method for disguising the information to be transmitted further includes:
[0029] The client as the sender of the information to be transmitted performs random filling and / or multi-frequency Bit traffic disguised transmission on the information to be transmitted in the data to be transmitted, so as to obfuscate the information to be transmitted and prevent it from being deciphered by criminals.
[0030] In the prior art, other application program data traffic is not mixed into the information to be transmitted during the transmission of the information to be transmitted, and the structure, traffic rate, etc. of the information to be transmitted during the transmission process are also regular, so the above information to be transmitted is easily analyzed by criminals for relevant rules of the information to be transmitted, resulting in the leakage of the information to be transmitted. However, the present invention adds multi-node traffic obfuscation, that is, performs random filling and / or multi-frequency Bit traffic disguised transmission on the information to be transmitted in the data to be transmitted, so that the characteristics such as the structure and traffic rate of the information to be transmitted during the transmission process have no rules to follow, thereby realizing the obfuscation of the information to be transmitted and preventing the information to be transmitted from being deciphered by criminals.
[0031] Through the above configuration, the client of the present invention randomly mixes the real information to be transmitted into the data packets of other applications, and forwards the first disguised data in batches to one or more servers at irregular intervals (for example, the sending time of the first disguised data is also randomly set by a random algorithm), so that the structure, flow rate and other characteristics of the data packets of the transmitted first disguised data are irregular, thereby achieving the purpose of confusing data eavesdroppers. When the client and the server transmit the information to be transmitted or the first disguised data, the client of the present invention disguises the encrypted data packets of the information to be transmitted or the first disguised data as data packets with the same / similar structures as other applications and / or hides the encrypted data packets of the information to be transmitted or the first disguised data in the data packets of other applications, and then forwards them to the server in batches, so as to achieve the purpose of confusing data eavesdroppers.
[0032] According to a preferred embodiment, the quantum random number generator can send the quantum random key to the server when the information to be transmitted is generated, and the server can number the quantum random key and receive the quantum random key according to the number.
[0033] According to a preferred embodiment, the client as the sender of the information to be transmitted can send a request to the server when generating the information to be transmitted, and the request is used to request the server to obtain the quantum random key corresponding to the information to be transmitted. The server can obtain the request in real time and send the quantum random key corresponding to the information to be transmitted to the client that issued the request.
[0034] According to a preferred embodiment, when the client as the recipient of the information to be transmitted has obtained the information to be transmitted, the client as the recipient of the information to be transmitted can send second disguised data to the server. The second disguised data at least includes response data corresponding to the information to be transmitted in the first disguised data.
[0035] The present invention also provides an encryption system based on quantum random numbers. The encryption system at least comprises: at least two clients, a server and a quantum random number generator.
[0036] At least two clients are configured to be able to serve as senders or receivers of information to be transmitted.
[0037] The server is configured to receive a public key corresponding to the client sent by the client, and send the public key of the client as the recipient of the information to be transmitted to the client as the sender of the information to be transmitted.
[0038] The quantum random number generator is configured to be able to send a quantum random key corresponding to the information to be transmitted to the server.
[0039] In the case where the server sends the quantum random key to the client that is the sender of the information to be transmitted, the client that is the sender of the information to be transmitted uses the quantum random key to encrypt the information to be transmitted, and sends the data to be transmitted that at least includes the information to be transmitted and the quantum random key to the client that is the receiver of the information to be transmitted. The client that is the receiver of the information to be transmitted obtains the information to be transmitted through the quantum random key, so as to realize secure communication between the clients.
[0040] The present invention uses a quantum random generator to generate quantum random numbers / quantum random keys, that is, the generated quantum random numbers / quantum random keys are true random numbers, and can be obtained and used as needed. The security of quantum cryptography (such as quantum random numbers / quantum random keys) is guaranteed by physical characteristics such as the uncertainty, indivisibility, and non-replicability of quantum states. According to the "measurement collapse theory", measuring a quantum state will change the original quantum state, that is, the data eavesdropping behavior of a data eavesdropper will introduce additional error codes into the original quantum state. For example, when there is no data eavesdropper in the data transmission channel, the error rate of quantum cryptography is zero; when there is a data eavesdropper in the data transmission channel, the error rate of quantum cryptography is 25%. When the error rate of quantum cryptography exceeds the threshold, it means that there is a data eavesdropper in the data transmission channel. At this time, the warning module data-connected to the quantum random generator can send an alarm message to the server, and the server can discard the distributed quantum random key based on the alarm message. Through the above configuration method, that is, by using true quantum random numbers (such as quantum random keys) as encryption keys to encrypt the information content (such as the information to be transmitted) of instant messaging, the uncrackability and uniqueness of the information content of instant messaging are guaranteed, thereby realizing secure communication between clients. In addition, the present invention can also reduce the computing time consumed by the client to generate pseudo-random numbers using a soft algorithm, thereby improving efficiency; the present invention can also play a role in the confidentiality of information in combination with modern cryptographic algorithms (such as SM4, AES, etc.); the present invention can also play a role in requirements such as the authenticity and integrity of information other than confidentiality in combination with authentication and other cryptographic algorithms. Brief Description of the Drawings
[0041] Figure 1 It is a simplified schematic diagram of the connection relationship of modules of a preferred embodiment provided by the present invention.
[0042] List of Reference Numerals
[0043] 1: Client; 2: Server; 3: Quantum random number generator. Detailed implementation mode
[0044] The following will be described in detail with reference to the accompanying drawings.
[0045] The present invention also provides an encryption method based on quantum random numbers. The above encryption method at least includes:
[0046] At least two clients 1 send public keys corresponding to the clients 1 to the server 2, where the client 1 can be the sender or the receiver of the information to be transmitted;
[0047] The server 2 receives the public keys corresponding to the clients 1 sent by the clients 1, and the server 2 sends the public key of the client 1 as the receiver of the information to be transmitted to the client 1 as the sender of the information to be transmitted.
[0048] The quantum random number generator 3 sends a quantum random key corresponding to the information to be transmitted to the server 2. The server 2 receives the quantum random key.
[0049] The server 2 sends the quantum random key to the client 1 as the sender of the information to be transmitted.
[0050] Preferably, the above encryption method further includes:
[0051] The client 1 as the sender of the information to be transmitted encrypts the information to be transmitted using the quantum random key, and encrypts the quantum random key using the public key of the client 1 as the receiver of the information to be transmitted, and then sends the data to be transmitted including at least the information to be transmitted and the quantum random key to the client 1 as the receiver of the information to be transmitted;
[0052] After the client 1 as the receiver of the information to be transmitted receives the information to be transmitted, the client 1 as the receiver of the information to be transmitted decrypts the quantum random key to obtain the quantum random key, and the client 1 as the receiver of the information to be transmitted decrypts the information to be transmitted using the quantum random key to obtain the information to be transmitted.
[0053] The information to be transmitted is the information transmitted between the client 1 as the sender of the information to be transmitted and the client 1 as the receiver of the information to be transmitted.
[0054] The quantum random number generator 3 can automatically generate quantum random keys.
[0055] Preferably, the quantum random key corresponding to the information to be transmitted sent by the quantum random number generator 3 to the server 2 corresponds one-to-one with the information to be transmitted. Preferably, each information to be transmitted corresponds to a new quantum random key.
[0056] Preferably, the server 2 sends the quantum random key to the client 1, which is the sender of the information to be transmitted, through a two-way HTTPS transmission channel.
[0057] Preferably, the client 1, which is the sender of the information to be transmitted, uses the quantum random key and adopts a symmetric encryption mechanism to encrypt the information to be transmitted.
[0058] Preferably, the client 1, which is the sender of the information to be transmitted, sends the data to be transmitted containing the information to be transmitted to the client 1, which is the receiver of the information to be transmitted, based on an obfuscation protocol.
[0059] The data to be transmitted includes at least the information to be transmitted and the quantum random key.
[0060] Preferably, the private key used by the client 1, which is the receiver of the information to be transmitted, is stored in the client 1.
[0061] Preferably, after receiving the information to be transmitted, the client 1, which is the receiver of the information to be transmitted, uses the private key corresponding to the public key to decrypt the quantum random key encrypted by the public key in the data to be transmitted to obtain the quantum random key.
[0062] Preferably, the client 1, which is the receiver of the information to be transmitted, uses the quantum random key to decrypt the information to be transmitted encrypted by the quantum random key to obtain the information to be transmitted.
[0063] Preferably, the step of sending the data to be transmitted containing the information to be transmitted to the client 1, which is the receiver of the information to be transmitted, includes:
[0064] The client 1, which is the sender of the information to be transmitted, at least disguises the information to be transmitted in the data to be transmitted based on the obfuscation protocol and forms the first disguised data;
[0065] The server 2 obtains the first disguised data and parses the first disguised data according to the obfuscation protocol to obtain the real request in the information to be transmitted;
[0066] The server 2 forwards the first disguised data to the client 1, which is the receiver of the information to be transmitted and corresponds to the real request, based on the real request;
[0067] The client 1, which is the receiver of the information to be transmitted, obtains the first disguised data forwarded by the server 2;
[0068] The client 1, which is the receiver of the information to be transmitted, parses the first disguised data forwarded by the server 2 based on the obfuscation protocol and obtains the data to be transmitted from the first disguised data.
[0069] Particularly preferably, the number of servers 2 is two or more.
[0070] The real request is the address of client 1, which is the recipient of the information to be transmitted.
[0071] The obfuscation protocol at least includes methods for disguising the information to be transmitted and / or switching the data transmission channel for transmitting the information to be transmitted between client 1, server 2, and client 1, which is the recipient of the information to be transmitted, so as to protect the information to be transmitted by obfuscating the information to be transmitted in the data transmission channel.
[0072] Since the security of the data transmission channel between client 1 and client 1, which is the recipient of the information to be transmitted, is not high enough, the present invention proposes a rule for protecting the information to be transmitted in the data transmission channel, that is, the obfuscation protocol.
[0073] The purpose of the obfuscation protocol to switch the data transmission channel is to forward the information to be transmitted to client 1, which is the recipient of the information to be transmitted, through the server 2 corresponding to the randomly generated disguised request by using the disguised request generated by the obfuscation protocol, that is, to transmit and obfuscate the information to be transmitted through multiple nodes (such as a group of servers 2). The group of servers 2 includes multiple servers 2, and the information to be transmitted can be forwarded to client 1, which is the recipient of the information to be transmitted, by any one of the servers 2 in the group of servers 2. Therefore, the data transmission channel formed during the process of transmitting the information to be transmitted from client 1 to client 1, which is the recipient of the information to be transmitted, changes arbitrarily, and finally the data transmission channel of the information to be transmitted has no rules to follow, thus realizing the protection of the information to be transmitted.
[0074] The obfuscation protocol can also include an encryption method for performing secondary encryption on the information to be transmitted / the first disguised data. The above encryption method can be an asymmetric encryption and / or a symmetric encryption algorithm.
[0075] The data in the data transmission channel at least includes the information to be transmitted.
[0076] The data in the data transmission channel can also include the first disguised data.
[0077] Preferably, the first disguised data at least includes the information to be transmitted, a quantum random key, a disguised request, and an identifier. The disguised request corresponding to the real request in the information to be transmitted is generated by client 1, which is the sender of the information to be transmitted, based on the obfuscation protocol. The identifier is used to identify the disguised algorithm used by client 1, which is the sender of the information to be transmitted, in the process of generating the disguised request. In the case where multiple servers 2 can form a group of servers 2, client 1, which is the sender of the information to be transmitted, can send the first disguised data to at least one server 2 corresponding to the disguised request in the group of servers 2 based on the disguised request.
[0078] The information to be transmitted at least includes a real request. The real request is the address of Client 1, which is the recipient of the information to be transmitted, to which the information to be transmitted needs to be sent.
[0079] The type of the information to be transmitted can be determined according to the user's needs.
[0080] The disguised request is an address randomly generated by Client 1 by disguising the real request in the information to be transmitted and corresponding to any one of Server 2.
[0081] The type of the information to be transmitted can be added or deleted according to the actual application scenario.
[0082] For example, the information to be transmitted may include the information to be transmitted and the real request; at this time, the first disguised data includes the information to be transmitted, the real request, and the disguised request.
[0083] Client 1, Server 2, and Client 1, which is the recipient of the information to be transmitted, can all transmit the information to be transmitted based on the HTTPS protocol and the obfuscation protocol.
[0084] Preferably, the method for disguising the information to be transmitted includes:
[0085] Client 1, which is the sender of the information to be transmitted, generates a disguised request through a disguise algorithm to hide the real request corresponding to the information to be transmitted;
[0086] Client 1, which is the sender of the information to be transmitted, combines the information to be transmitted, the disguised request, and the identifier corresponding to the disguise algorithm into the first disguised data.
[0087] Preferably, the method for disguising the information to be transmitted further includes:
[0088] Client 1, which is the sender of the information to be transmitted, performs random filling and / or multi-frequency Bit traffic disguised transmission on the information to be transmitted in the data to be transmitted to obfuscate the information to be transmitted and prevent it from being deciphered by lawbreakers.
[0089] Preferably, both Server 2 and Client 1, which is the recipient of the information to be transmitted, can disguise the real request in the information to be transmitted based on the obfuscation protocol.
[0090] To ensure the efficiency of data transmission, the HTTPS protocol uses symmetric encryption for data transmission after successful certificate verification, that is, the HTTPS protocol only uses asymmetric encryption in the certificate verification stage. If a lawbreaker intercepts the information to be transmitted in the above data transmission, since the keys used in symmetric encryption are all pseudo-random numbers, and the current computer technology is in a stage of rapid development, it is very likely that the information to be transmitted will be deciphered by lawbreakers within a certain period of time after being intercepted.
[0091] Therefore, on the basis of symmetrically encrypting the to-be-transmitted information, the present invention performs another asymmetric encryption. The above operations will not significantly affect the transmission efficiency of the to-be-transmitted information, and can greatly improve the security of data transmission. That is, even if an illegal element intercepts the to-be-transmitted information that has been symmetrically encrypted and asymmetrically encrypted, the to-be-transmitted information cannot be cracked.
[0092] Before the client 1 sends the to-be-transmitted information to the server 2, the client 1 first encrypts the to-be-transmitted information through asymmetric encryption and symmetric encryption algorithms, and then the client 1 rewrites the real request in the to-be-transmitted information to disguise / hide the real request and generates a disguised request.
[0093] The disguised request is randomly generated by the client 1 using a disguise algorithm.
[0094] The above disguise algorithm has a specific identifier in the confusion protocol.
[0095] Particularly preferably, the first disguised data can further include: the identifier of the disguise algorithm used by the client 1 to disguise the to-be-transmitted information for this time.
[0096] The identifier can be one or more of symbols such as numbers and letters.
[0097] For example, if the identifier is "A", it means that the disguise algorithm used by the client 1 to disguise the to-be-transmitted information for this time is the first disguise algorithm; if the identifier is "B", the disguise algorithm used by the client 1 to disguise the to-be-transmitted information for this time is the second disguise algorithm, and so on.
[0098] The disguise algorithm can be flexibly selected according to the requirements of the actual application scenario. The disguise algorithm can be a message digest algorithm, a secure hash algorithm, a message authentication code algorithm, a cutting algorithm, a parallel splicing algorithm, etc. After the disguised request of the client 1, the sender of the to-be-transmitted information, is disguised using the disguise algorithm and sent to the server 2 or one of the servers in the server group, the server 2 finds the disguise algorithm used by the corresponding client 1, the sender of the to-be-transmitted information, according to the disguise algorithm identifier included in the first disguised data, and then resolves the real address of the client 1, the receiver of the to-be-transmitted information, based on the disguise algorithm. After that, the server 2 sends the first disguised data to the corresponding client 1, the receiver of the to-be-transmitted information, according to the resolved real address of the client 1, the receiver of the to-be-transmitted information.
[0099] For example, when the number of Client 1, which is the recipient of the information to be transmitted, is only one, the spoofing request indicates which server 2 in Server Group 2 forwards the first spoofed data to Client 1, which is the recipient of the information to be transmitted; when the number of Client 1, which is the recipient of the information to be transmitted, is more than one, the spoofing request indicates which server 2 forwards the first spoofed data to which Client 1 that is the recipient of the information to be transmitted.
[0100] The spoofing of the real request in the information to be transmitted by Client 1 is achieved by rewriting the network request interface.
[0101] Client 1 sends the first spoofed data to the server 2 corresponding to the spoofing request in Server Group 2 based on the spoofing request. The server 2 corresponding to the spoofing request can parse the first spoofed data based on the obfuscation protocol to obtain the real request corresponding to the information to be transmitted.
[0102] For example, the address of Client 1 (i.e., the real request), which is the recipient of a certain information to be transmitted, is www.cloudfront.com. The spoofing request can adopt any one or more of spoofed addresses such as a.com, b.net, and c.org.
[0103] After the server 2 corresponding to the spoofing request in Server Group 2 receives the first spoofed data sent by Client 1, the above-mentioned server 2 can obtain the identifier in the first spoofed data based on the obfuscation protocol, and parse out the spoofing algorithm used by Client 1 corresponding to the first spoofed data of this time through the above identifier, and then parse out the real request corresponding to the information to be transmitted from the first spoofed data (such as the spoofing request in the first spoofed data) based on the above spoofing algorithm. After that, the above one or more servers 2 forward the first spoofed data to Client 1, which is the recipient of the information to be transmitted corresponding to the real request, in batches based on the real request corresponding to the information to be transmitted.
[0104] Preferably, Server 2 and Client 1, which is the recipient of the information to be transmitted, can adopt the same model of Server 2.
[0105] Preferably, the job responsibilities borne by Server 2 and Client 1, which is the recipient of the information to be transmitted, can be switched with each other. For example, Client 1, which is the recipient of the information to be transmitted, can be used as a certain server 2 in Server Group 2; and a certain server 2 in Server Group 2 can also be used as Client 1, which is the recipient of the information to be transmitted.
[0106] Through the above configuration method, the client 1 can use a variety of algorithms to disguise the real request in the information to be transmitted, and can add a disguised request randomly generated by the disguise algorithm to the first disguised data, so as to ensure the randomness of the server 2 accessed by the client 1 / the client 1 as the recipient of the information to be transmitted, and at the same time avoid the real request corresponding to the information to be transmitted and the client 1 as the recipient of the information to be transmitted corresponding to the real request being analyzed by lawbreakers; at the same time, both the client 1 and the server 2 can disguise the real request in the information to be transmitted based on the obfuscation protocol, and forward the first disguised data to the client 1 as the recipient of the information to be transmitted corresponding to the real request through the server 2 corresponding to the randomly generated disguised request, so as to hide the real request of the information to be transmitted and prevent the leakage of the information to be transmitted.
[0107] In the prior art, the access address of the data transmitted by the client 1 is often fixed. However, the information to be transmitted sent by the client 1 in the present invention is transmitted to the client 1 as the recipient of the information to be transmitted through any one or more servers 2 in the server 2 group. Since the first disguised data corresponding to the information to be transmitted can be forwarded to the client 1 as the recipient of the information to be transmitted corresponding to the real request through a random server 2, the data transmission channel for transmitting the information to be transmitted is constantly changing and there is no pattern to follow, thereby preventing lawbreakers from obtaining the information to be transmitted (such as the real request) and / or obtaining relevant information of the information to be transmitted from a fixed data transmission channel.
[0108] In the case of only one server 2, although the transmission path of the information to be transmitted cannot be randomly changed, the methods of traffic disguise and random packet filling can still be applied to the information to be transmitted to protect the information to be transmitted.
[0109] Preferably, the method for disguising the information to be transmitted further includes:
[0110] The client 1 performs random filling and / or multi-frequency Bit traffic disguise transmission on the information to be transmitted in the data to be transmitted, so as to confuse the information to be transmitted and prevent it from being deciphered by lawbreakers.
[0111] Client 1 can use the corresponding script to disguise the information to be transmitted as a data packet with a structure different from that of the information to be transmitted (such as a data packet of a video music application), and interact with Server 2 irregularly to create the illusion of multi-frequency Bit traffic disguised transmission. At the same time, Client 1 can also randomly mix the data of other applications into the information to be transmitted, that is, after the information to be transmitted is divided into multiple sub-packets, the multiple sub-packets are hidden in the data packets of other applications in batches, and the data packets of other applications are transmitted to Server 2 or Client 1, which is the recipient of the information to be transmitted, in segments, so as to confuse the information to be transmitted and prevent the information to be transmitted from being deciphered by lawbreakers.
[0112] In the prior art, when transmitting the information to be transmitted, the data traffic of other applications, etc. is not mixed into the information to be transmitted, and the structure, traffic rate, etc. of the information to be transmitted during the transmission process are also regular. Therefore, the above-mentioned information to be transmitted is easily analyzed by lawbreakers for relevant rules of the information to be transmitted, resulting in the leakage of the information to be transmitted. The present invention adds multi-node traffic confusion, that is, randomly fills and / or performs multi-frequency Bit traffic disguised transmission on the information to be transmitted in the data to be transmitted, so that the structure, traffic rate and other characteristics of the information to be transmitted during the transmission process have no regular pattern, thereby realizing the confusion of the information to be transmitted and preventing the information to be transmitted from being deciphered by lawbreakers.
[0113] The steps for Client 1 to randomly fill the information to be transmitted in the data to be transmitted include:
[0114] Judge whether the information to be transmitted reaches the trigger condition for triggering random filling;
[0115] Randomly divide the information to be transmitted into multiple sub-packets;
[0116] Generate the filling data packets to be filled;
[0117] Randomly mix the filling data packets among the multiple sub-packets;
[0118] Send the sub-packets containing the filling data packets to Server 2 or Client 1, which is the recipient of the information to be transmitted, in batches.
[0119] Client 1 determines whether the information to be transmitted meets the triggering condition for random filling. The triggering condition can be set artificially according to the actual application scenario. For example, Client 1 can add a specific triggering identifier to the information to be transmitted. If Client 1 identifies the information to be transmitted and finds that the above triggering identifier exists in the first camouflage data, then the information to be transmitted is identified by Client 1 as the information to be transmitted that meets the triggering condition for random filling; if Client 1 identifies the information to be transmitted and finds that the above triggering identifier does not exist in the first camouflage data, then the information to be transmitted is identified by Client 1 as the information to be transmitted that does not meet the triggering condition for random filling.
[0120] The above triggering condition can be randomly generated by a corresponding algorithm, that is, the operation of Client 1 for randomly filling and transmitting the information to be transmitted is random.
[0121] The information to be transmitted is randomly divided into multiple sub-packets, so that the characteristics such as the size and quantity of the sub-packets are also unpredictable.
[0122] If Client 1 analyzes and determines that the information to be transmitted for the current time has met the preset triggering condition, then Client 1 generates a filling packet for filling the information to be transmitted / the first camouflage data according to a corresponding algorithm. The filling packet can be a packet with the same / similar structure as other application programs (such as video, music and other application programs). The above same / similar structure means that the characteristics such as the structure, traffic, frequency, etc. of the packet are the same or similar.
[0123] The number of filling packets filled between two sub-packets is random.
[0124] The time when Client 1 sends the sub-packet containing the filling packet to Server 2 or Client 1 as the receiver of the information to be transmitted can also be random.
[0125] Preferably, Server 2 or Client 1 as the receiver of the information to be transmitted can receive multiple sub-packets in a segmented receiving manner to reassemble the multiple sub-packets into the first camouflage data.
[0126] Through the above configuration method, the real information to be transmitted is randomly mixed into the packets of other application programs, and the first camouflage data is forwarded to one or more Servers 2 in batches at irregular times (for example, the sending time of the first camouflage data is also randomly set by a random algorithm), so that the characteristics such as the structure and traffic rate of the packets of the transmitted first camouflage data are unpredictable, so as to achieve the purpose of confusing data eavesdroppers.
[0127] The steps for Client 1 to perform multi-frequency Bit traffic camouflage transmission on the information to be transmitted in the data to be transmitted include:
[0128] Determine whether the information to be transmitted reaches the trigger condition for triggering multi-frequency Bit traffic disguised transmission;
[0129] Analyze the format of the data packets of the target application;
[0130] Disguise the information to be transmitted as the data packets of the target application based on the format of the data packets of the target application;
[0131] Send the disguised information to be transmitted to Server 2 or Client 1, which is the recipient of the information to be transmitted.
[0132] Client 1 determines whether the information to be transmitted in the current instance reaches the trigger condition for triggering Bit traffic disguised transmission. The trigger condition can be artificially set according to the actual application scenario. For example, Client 1 can add a specific trigger identifier to the information to be transmitted. If Client 1 identifies the information to be transmitted and finds that the above trigger identifier exists in the first disguised data, the above information to be transmitted is identified by Client 1 as the information to be transmitted that reaches the trigger condition for using Bit traffic disguised transmission; if Client 1 identifies the information to be transmitted and finds that the above trigger identifier does not exist in the first disguised data, the above information to be transmitted is identified by Client 1 as the information to be transmitted that does not reach the trigger condition for using Bit traffic disguised transmission.
[0133] The above trigger condition can be randomly generated by a corresponding algorithm, that is, the operation of Client 1 for performing Bit traffic disguised transmission on the information to be transmitted is random.
[0134] Client 1 and Server 2 can use methods such as traffic filling, traffic normalization, and traffic masking to disguise the traffic of the data packets to be transmitted.
[0135] Client 1 and Server 2 can also use methods such as re-routing, adding garbage packets, packet loss, inclusion union, packet fragmentation, packet out-of-order, flow mixing, flow splitting, and flow merging to disguise the traffic of the data packets to be transmitted.
[0136] Particularly preferably, the method adopted by Client 1 and Server 2 of the present invention to disguise the information to be transmitted is to disguise the encrypted information to be transmitted as data packets with the same or similar format / structure as the data packets of other applications (such as video, music, etc.).
[0137] For example, client 1 needs to disguise the information to be transmitted into the format of the data packet of the target application (such as a music application). Client 1 can first parse the format / structure of the data packet of the target application, and then disguise the information to be transmitted into the format / structure of the data packet of the music application, thereby making it impossible for criminals to identify the disguised information to be transmitted, thereby ultimately achieving the purpose of confusing data eavesdroppers.
[0138] Through the above configuration, when the client 1 and the server 2 transmit the information to be transmitted or the first disguised data, the encrypted data packet of the information to be transmitted or the first disguised data is disguised as a data packet with the same / similar structure as other applications and / or the encrypted data packet of the information to be transmitted or the first disguised data is hidden in the data packet of other applications, and then forwarded to the server 2 in batches, so as to confuse data eavesdroppers.
[0139] Preferably, the quantum random number generator 3 can send the quantum random key to the server 2 when the information to be transmitted is generated, and the server 2 can number the quantum random key and receive the quantum random key according to the number.
[0140] Preferably, the above numbering can be determined according to the time sequence of receiving the quantum random key. For example, the first quantum random key received by the server 2 on that day is numbered one, the second quantum random key is numbered two, and so on.
[0141] Preferably, the client 1 as the sender of the information to be transmitted can send a request to the server 2 when generating the information to be transmitted, and the request is used to request the quantum random key corresponding to the information to be transmitted from the server 2. The server 2 can obtain the request in real time and send the quantum random key corresponding to the information to be transmitted to the client 1 that issued the request.
[0142] Preferably, the request may include an identification code of the client 1 that issues the request.
[0143] Preferably, the server 2 can send the quantum random key corresponding to the information to be transmitted to the client 1 corresponding to the identification code based on the identification code.
[0144] Preferably, when the client 1 as the receiver of the information to be transmitted has obtained the information to be transmitted, the client 1 as the receiver of the information to be transmitted can send the second disguised data to the server 2. The second disguised data at least includes the response data corresponding to the information to be transmitted in the first disguised data.
[0145] The type of response data can be set according to user needs.
[0146] The server 2 can obtain the second disguised data and disguise the second disguised data as the third disguised data based on the obfuscation protocol.
[0147] Preferably, the information to be transmitted is used to request the second disguised data from the client 1 which is the recipient of the information to be transmitted.
[0148] The third disguised data at least includes the response data corresponding to the information to be transmitted.
[0149] In response to the information to be transmitted, the client 1 which is the recipient of the information to be transmitted can send the response data corresponding to the first disguised data to the server 2.
[0150] The client 1 which is the recipient of the information to be transmitted can also disguise the response data based on the obfuscation protocol to generate the second disguised data.
[0151] The server 2 can obtain the second disguised data and disguise the second disguised data as the third disguised data based on the obfuscation protocol.
[0152] The third disguised data can be transmitted by the server 2 to the client 1.
[0153] Preferably, the second disguised data may also include but is not limited to: response data, CA digital certificate signature public key, identity information, pseudo-random number, quantum random key, identifier of the obfuscation algorithm used by the client 1 as the recipient of the information to be transmitted this time, etc.
[0154] Preferably, the information to be transmitted is used to request the second disguised data from the client 1 which is the recipient of the information to be transmitted.
[0155] Preferably, the client 1 which is the recipient of the information to be transmitted can also encrypt the second disguised data in the ways of asymmetric encryption and symmetric encryption.
[0156] The third disguised data at least includes the response data corresponding to the information to be transmitted in the first disguised data.
[0157] Preferably, the third disguised data may also include but is not limited to: CA digital certificate signature public key, identity information, pseudo-random number, quantum random key, identifier of the obfuscation algorithm used by the server 2 this time, etc.
[0158] The processes of disguising and transmitting the second disguised data and the third disguised data are the same as those of the first disguised data, so the processes of disguising and transmitting the second disguised data and the third disguised data will not be elaborated here.
[0159] Figure 1Disclosed is an encryption system based on quantum random numbers. The encryption system at least includes: at least two clients 1, a server 2, and a quantum random number generator 3. The client 1 can act as a sender or a receiver of the information to be transmitted. The server 2 can receive the public key corresponding to the client 1 sent by the client 1, and send the public key of the client 1 as the receiver of the information to be transmitted to the client 1 as the sender of the information to be transmitted. The quantum random number generator 3 can send a quantum random key corresponding to the information to be transmitted to the server 2.
[0160] The client 1 as the sender of the information to be transmitted encrypts the information to be transmitted using the quantum random key, and sends the data to be transmitted including the information to be transmitted to the client 1 as the receiver of the information to be transmitted. The client 1 as the receiver of the information to be transmitted obtains the information to be transmitted through the quantum random key to ensure secure communication between the clients 1.
[0161] The present invention mainly relies on the quantum random number generator 3 to generate true random numbers. In the process of the user's client 1 using quantum random numbers / quantum random keys, there will be a situation where the quantum random numbers have been used and the new quantum random numbers have not been distributed to the client 1 in time. In order to ensure the normal communication of the client 1, when the quantum random numbers have been used and the new quantum random numbers have not been distributed in time in the client 1, the client 1 can generate pseudo-random numbers through a soft algorithm to temporarily replace the quantum random numbers / quantum random keys that have not been distributed in time for that time.
[0162] Since the quantum random numbers / quantum random keys in transmission themselves only carry the information of the original random bit string prepared for encryption, even if a data eavesdropper has stolen the quantum random numbers / quantum random keys in transmission, the data eavesdropper still cannot obtain the real information to be transmitted (such as highly confidential information). The present invention does not directly send or receive the information to be transmitted (such as highly confidential information), but sends or receives random bit strings / quantum random keys. Once the client 1 and / or the server 2 discovers that the transmission of the random bit string / quantum random key is disturbed, the client 1 and / or the server 2 can immediately interrupt the transmission of the information to be transmitted and discard the above-mentioned random bit string / quantum random key, thereby ensuring the security of the information to be transmitted.
[0163] The server 2 can receive the quantum random key in real time.
[0164] Each client 1 can send the public key corresponding to the client 1 to the server 2.
[0165] Preferably, the client 1 as the sender of the information to be transmitted can encrypt the quantum random key using the public key of the client 1 as the receiver of the information to be transmitted.
[0166] Preferably, the client 1, which is the recipient of the information to be transmitted, can receive the information to be transmitted in real time.
[0167] Preferably, the client 1, which is the recipient of the information to be transmitted, decrypts the encrypted quantum random key using the public key to obtain the quantum random key. The above public key comes from the client 1, which is the sender of the information to be transmitted.
[0168] Preferably, the client 1, which is the recipient of the information to be transmitted, decrypts the information to be transmitted encrypted with the quantum random key using the quantum random key to obtain the information to be transmitted.
[0169] For example, the main process of the client 1, which is the sender of the information to be transmitted, sending the information to be transmitted to the client 1, which is the recipient of the information to be transmitted, can be as follows:
[0170] S1: User A logs in through the client 1A and uploads their respective public keys (such as the public keys of the client 1A and the client 1B) to the server 2 respectively. After the server 2 receives the above public keys (such as the public keys of the client 1A and the client 1B), it encrypts and saves the public keys.
[0171] S2: The server 2 sends the public key of the client 1B used by User B, the friend of User A, to the client 1A used by User A. The client 1A encrypts the public key of the client 1B and stores it locally.
[0172] S3: The server 2 receives the quantum random key generated by the quantum random number generator 3 and saves the quantum random key to the server 2.
[0173] S4: The server 2 distributes the quantum random key to each client 1 through a two-way HTTPS transmission channel.
[0174] S5: The client 1 uses the quantum random key and adopts a symmetric encryption mechanism to encrypt the information to be transmitted, and then encrypts the above quantum random key using the public key of the client 1B. Subsequently, the data to be transmitted is sent to the recipient (such as the client 1B).
[0175] S6: After the client 1 (such as the client 1B), which is the recipient of the data to be transmitted, receives the above data to be transmitted, the client 1, as the recipient, decrypts the encrypted quantum random key using the private key stored locally to obtain the quantum random key. Then, the client 1, as the recipient, decrypts the information to be transmitted encrypted with the quantum random key using the above quantum random key to obtain the information to be transmitted.
[0176] After the user logs in, the public key information of the client 1 used by the user is uploaded to the server 2. The above upload process uses an asymmetric encryption algorithm. The asymmetric encryption algorithm requires two keys for encryption and decryption. Among them, the above two keys are the public key and the private key respectively. If the public key is used to encrypt the data, only the private key corresponding to the public key can be used to decrypt the encrypted data. In short, when the user logs in through the client 1, the client 1 can automatically generate the above public key and private key locally.
[0177] The client 1, as the sender of the information to be transmitted, needs to upload the public key it generates to the server 2.
[0178] The private key is generated locally (i.e., the client 1 as the sender of the information to be transmitted) and saved locally, and will not be transmitted over the Internet, thus ensuring the absolute security of the private key. After obtaining the above public key, the server 2 encrypts and saves the public key to ensure the security of the public key.
[0179] When the user adds a friend of the user (for example, the friend of the user uses the client 1B) through the client 1 (such as the client 1A), the server 2 will forward the public key of the client 1 used by the friend stored previously to the client 1 of the user. The client 1 of the current user encrypts and saves the public key of the friend locally (such as the client 1A).
[0180] Through this setting method, when the user and the user's friend communicate through the client 1A and the client 1B, there is no need to call the public key of the user's friend from the server 2 to reduce the possibility of the public key being leaked. Thus, even if the server 2 is attacked and the data is leaked, the attacker can only obtain the encrypted key (such as the public key) and cannot decrypt the message / data, ultimately achieving the purpose of ensuring the absolute security of the information to be transmitted.
[0181] In addition, the server 2 sends the quantum random key to the client 1 through a two-way HTTPS channel. The HTTPS protocol is a network protocol for encrypted transmission and authentication constructed by SSL (Secure Sockets Layer) and the HTTP protocol. All communication content between the server 2 and the client 1 based on the above HTTPS protocol is encrypted. In short, the client 1 first generates a symmetric key and exchanges the above key through the certificate of the server 2, which is the general handshake process; and all subsequent information / data exchanges are encrypted. Moreover, HTTPS itself can prevent man-in-the-middle attacks because it comes with a CA (Certificate Authority) certificate for verification. A certificate is a digital file that establishes the connection between a public key and an entity. It contains the following content: version information, serial number, name of the certificate recipient, name of the issuer, certificate validity period, public key, digital signature of the CA, and some other information. Certificates are issued by the CA. The CA can determine the validity period of the certificate. The certificate is signed by the CA. Each certificate has a unique serial number. The serial number of the certificate and the certificate issuer can determine the unique identity of a certificate. The unique identity of the above certificate can help confirm the identity of the server 2, and ultimately ensure the security of the quantum random number and the information to be transmitted.
[0182] It should be noted that the above specific embodiments are exemplary. Those skilled in the art can come up with various solutions inspired by the disclosure of the present invention, and these solutions also fall within the disclosure scope and protection scope of the present invention. Those skilled in the art should understand that the specification and drawings of the present invention are illustrative and do not constitute a limitation on the claims. The protection scope of the present invention is defined by the claims and their equivalents. The specification of the present invention contains multiple inventive concepts. Expressions such as "preferably", "according to a preferred embodiment", or "optionally" indicate that the corresponding paragraphs disclose an independent concept. The applicant reserves the right to file divisional applications based on each inventive concept.
Claims
1. A quantum random number-based encryption method, characterized in that, The method includes: At least two clients (1) send the public keys corresponding to the clients (1) as the senders of the information to be transmitted to the server (2). Among them, the client (1) can be the sender or the receiver of the information to be transmitted. The information to be transmitted sent by the client (1) is transmitted to the client (1) as the receiver of the information to be transmitted through any one or more of the servers (2) in the server group; The server (2) receives the public keys corresponding to the clients (1) sent by the clients (1), and the server (2) sends the public keys of the clients (1) as the receivers of the information to be transmitted to the clients (1) as the senders of the information to be transmitted; The quantum random number generator (3) can send a quantum random key corresponding to the information to be transmitted to the server (2) when the information to be transmitted is generated. The server (2) can number the quantum random key and receive the quantum random key according to the number; When generating the information to be transmitted, the client (1) as the sender of the information to be transmitted can send a request for obtaining to the server (2). The request for obtaining is used to request the server (2) for the quantum random key corresponding to the information to be transmitted, and the server (2) sends the quantum random key to the client (1) as the sender of the information to be transmitted; The client (1) as the sender of the information to be transmitted disguises at least the information to be transmitted in the data to be transmitted based on the confusion protocol and forms first disguised data. The client (1) can add a disguised request randomly generated by the disguise algorithm to the first disguised data.
2. The method according to claim 1, characterized in that, The method further includes: The client (1) as the sender of the information to be transmitted encrypts the information to be transmitted using the quantum random key, encrypts the quantum random key using the public key of the client (1) as the receiver of the information to be transmitted, and then sends the data to be transmitted including the information to be transmitted and the quantum random key to the client (1) as the receiver of the information to be transmitted; After receiving the data to be transmitted, the client (1) as the receiver of the information to be transmitted decrypts the quantum random key to obtain the quantum random key, and then decrypts the information to be transmitted using the quantum random key to obtain the information to be transmitted.
3. The method according to claim 2, wherein The step of sending the data to be transmitted including the information to be transmitted and the quantum random key to the client (1) as the receiver of the information to be transmitted includes: The server (2) obtains the first disguised data and parses the first disguised data according to the confusion protocol to obtain the real request in the information to be transmitted; The server (2) forwards the first disguised data to the client (1) as the receiver of the information to be transmitted corresponding to the real request based on the real request; The client (1) as a receiver of the information to be transmitted obtains the first disguised data forwarded by the server (2); The client (1) as the receiver of the information to be transmitted parses the first disguised data forwarded by the server (2) based on the obfuscation protocol, and obtains the data to be transmitted from the first disguised data.
4. The method according to claim 3, wherein The first disguised data at least includes information to be transmitted, a quantum random key, a disguised request and an identifier; The disguised request corresponding to the real request in the information to be transmitted is generated by the client (1) as the sender of the information to be transmitted based on the obfuscation protocol; The identifier is used to identify the disguise algorithm used by the client (1) as the sender of the information to be transmitted in the process of generating the disguise request.
5. The method according to claim 4, characterized in that, Methods for disguising information to be transmitted include: The client (1) as the sender of the information to be transmitted generates the disguised request based on the obfuscation protocol to hide the real request corresponding to the information to be transmitted; The client (1) as the sender of the information to be transmitted combines the information to be transmitted, the quantum random key, the disguise request and the identifier corresponding to the disguise algorithm into the first disguise data.
6. The method according to claim 4, wherein Other methods of disguising information to be transmitted include: The client (1) as the sender of the information to be transmitted randomly fills the information to be transmitted in the data to be transmitted and / or transmits it in a multi-frequency bit flow disguised manner, so as to confuse the information to be transmitted and prevent it from being deciphered by criminals.
7. The method according to claim 1, characterized in that, The server (2) can obtain the request in real time, and send the quantum random key corresponding to the information to be transmitted to the client (1) that issued the request.
8. The method according to claim 7, characterized in that When the client (1) as the recipient of the information to be transmitted has obtained the information to be transmitted, the client (1) as the recipient of the information to be transmitted can send second disguised data to the server (2), wherein the second disguised data at least includes response data corresponding to the information to be transmitted in the first disguised data.
9. A quantum random number-based encryption system capable of performing the encryption method according to any one of claims 1 to 8, characterized in that, At least: At least two clients (1) are configured to be able to serve as senders or receivers of information to be transmitted; The server (2) is configured to receive a public key corresponding to the client (1) as the sender of the information to be transmitted and sent by the client (1), and to send the public key of the client (1) as the receiver of the information to be transmitted to the client (1) as the sender of the information to be transmitted; A quantum random number generator (3) is configured to send a quantum random key corresponding to the information to be transmitted to the server (2); Among them, the client (1) that is the sender of the information to be transmitted can send a request for obtaining when generating the information to be transmitted. The request for obtaining is used to request the server (2) for a quantum random key corresponding to the information to be transmitted. When the server (2) sends the quantum random key to the client (1) that is the sender of the information to be transmitted, the client (1) that is the sender of the information to be transmitted encrypts the information to be transmitted using the quantum random key, and sends the data to be transmitted that at least includes the information to be transmitted and the quantum random key to the client (1) that is the receiver of the information to be transmitted. The client (1) that is the receiver of the information to be transmitted obtains the information to be transmitted through the quantum random key, so as to realize secure communication between the clients (1).
Citation Information
Patent Citations
Secure internet surfing method and device, and plug-and-play equipment
CN109450931A
Method for encrypting and decrypting information based on quantum network
CN109639407A