An identity authentication and authorization method applicable to quantum key distribution networks
By adopting the identity authentication ticket issuance and authentication method based on anti-quantum symmetric cryptography algorithm in the quantum key distribution network, the problem that the existing technology cannot meet the authentication and authorization needs of quantum key distribution network is solved, and the effect of resisting quantum attacks and efficient authentication is achieved.
Patent Information
- Application Number
- CN202210902659.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-29
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-07-29
AI Technical Summary
The prior art cannot provide a simple and efficient identity authentication and authorization mechanism to meet the authentication and authorization needs of quantum key distribution networks, and the mainstream identity authentication system is built based on the PKI system, and the SM2 algorithm used cannot resist quantum attacks.
The identity authentication ticket issuance and authentication method based on the anti-quantum symmetric cryptography algorithm is adopted. The authentication key is generated and saved through the identity authentication authorization system, and the intelligent password key is used for offline charging and import, and the authentication ticket is generated and saved, and authentication is performed through the HMAC algorithm.
It realizes the advantages of resisting quantum attacks, offline secure transmission and simple and efficient authentication, and meets the authentication and authorization needs of the quantum key distribution network.
Smart Images

Figure CN115276980B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum key distribution, and specifically relates to an identity authentication and authorization method applicable to a quantum key distribution network. Background Art
[0002] In recent years, the development of quantum technology has advanced by leaps and bounds, becoming a frontier field of the new round of scientific and technological revolution and industrial transformation. Accelerating the development of quantum technology plays a very important role in promoting high-quality development and ensuring national security.
[0003] A quantum key distribution network is a mesh quantum key distribution network based on point-to-point QKD technology and constructed through quantum relays, which realizes the secure distribution of user application keys from end to end over long distances and generates and distributes secure quantum keys for both communication parties.
[0004] Quantum Key Service (abbreviation: "QKS") is a new generation of cryptographic infrastructure that a quantum key distribution network provides quantum key distribution to a typical cryptographic application system, that is, a service node for a typical cryptographic application system to access the quantum key distribution network.
[0005] Although the construction of the quantum key distribution network has achieved initial results, how to effectively integrate user classical cryptographic applications with the quantum key distribution network has always been a key issue in the practical application of quantum key distribution technology.
[0006] To ensure the security of the quantum key distribution network distributing keys to a typical cryptographic application system, the typical cryptographic application system must pass the authentication and authorization of the quantum key distribution network to use the quantum key distribution function of the quantum key service node.
[0007] Currently, there is no simple and efficient identity authentication and authorization mechanism to meet the authentication and authorization requirements of the quantum key distribution network. The mainstream identity authentication system is built based on the PKI system and mainly uses the SM2 algorithm. However, the SM2 cryptographic system is huge, has a bloated structure, is complex to deploy and implement, and cannot meet the security requirements of resisting quantum attacks, so it cannot be used as a supporting authentication and authorization system for the quantum key distribution network. Therefore, it is very necessary to build an identity authentication and authorization method based on the symmetric cryptographic system to resist quantum attacks. Summary of the Invention
[0008] The technical problem to be solved by the present invention is to provide an identity authentication and authorization method applicable to a quantum key distribution network, which has the advantages of resisting quantum attacks, off-line secure transmission, and simple and efficient authentication.
[0009] To solve the above technical problems, the technical solutions adopted by the present invention are as follows.
[0010] An identity authentication and authorization method applicable to a quantum key distribution network, comprising the following steps:
[0011] S1: The identity authentication and authorization system generates an authentication key for the quantum key service device and saves it, and offline injects it into the quantum key service device through a smart cryptographic key;
[0012] S2: The identity authentication and authorization system calculates and generates an authentication ticket for the typical cryptographic application system and saves it, and offline imports it into the typical cryptographic application system through a smart cryptographic key;
[0013] S3: The typical cryptographic application system calls the service interface of the quantum key service device through an online interface, and at the same time presents the authentication ticket as an interface parameter to the quantum key service device;
[0014] S4: After receiving the interface request, the quantum key service device authenticates the ticket presented by the typical cryptographic application system using the authentication key;
[0015] S5: The quantum key service device returns a response result to the typical cryptographic application system.
[0016] Preferably, the authentication key generation processing flow in step S1 includes the following steps:
[0017] S100: The identity authentication and authorization system reads a 16-byte random number from the cryptographic card belonging to the identity authentication and authorization system as the authentication key, denoted as authKey;
[0018] S101: The identity authentication and authorization system calls the encryption interface of the cryptographic card to encrypt authKey;
[0019] S102: The cryptographic card performs an encryption operation on authKey using the key encryption key KEK. The encryption algorithm adopts the ECB mode of SM4. If the calculation fails, step S100 is repeated. If the calculation is successful, the key ciphertext is denoted as cipherKey;
[0020] S103: The identity authentication and authorization system binds the identifier qksName of the quantum key service device to cipherKey;
[0021] S104: The identity authentication and authorization system writes qksName and cipherKey into the database;
[0022] S105: The database saves qksName and cipherKey;
[0023] S106: The generation of the authentication key ends.
[0024] Preferably, the authentication key offline injection processing flow in step S1 includes the following steps:
[0025] S107: The identity authentication and authorization system reads the encrypted authentication key cipherKey from the database;
[0026] S108: Decrypt cipherKey to restore the authentication key authKey, and the decryption algorithm uses the ECB mode of SM4;
[0027] S109: The identity authentication and authorization system exports the authentication key to the smart password key;
[0028] S110: The smart password key stores the authentication key in the internal secure storage area;
[0029] S111: The quantum key service device imports the authentication key from the smart password key;
[0030] S112: The quantum key service device saves the authentication key by itself.
[0031] Preferably, the authentication ticket generation and processing flow in step S2 includes the following steps:
[0032] S200: The identity authentication and authorization system enters the ticket parameters and the identifier qksName of the quantum key service device;
[0033] S201: The identity authentication and authorization system reads the encrypted authentication key cipherKey from the database according to qksName;
[0034] S202: The identity authentication and authorization system calls the decryption interface of the cryptographic card to decrypt cipherKey;
[0035] S203: The cryptographic card decrypts cipherKey to restore the authentication key authKey, the decryption algorithm uses the ECB mode of SM4. If the calculation fails, step S200 is performed again. If the calculation is successful, the plaintext key is recorded as authKey;
[0036] S204: The identity authentication and authorization system performs HMAC operation on the ticket parameters using authKey, and takes the operation result as the authentication ticket ticket;
[0037] S205: The identity authentication and authorization system binds the authentication ticket ticket with the identifier appName of the typical cryptographic application system and writes it into the database;
[0038] S206: The database saves the authentication ticket ticket;
[0039] S207: The generation of the authentication ticket ends.
[0040] Preferably, the authentication ticket offline issuance processing flow in step S2 includes the following steps:
[0041] S208: The identity authentication and authorization system reads the authentication ticket from the database;
[0042] S209: The identity authentication and authorization system exports the ticket to the smart password key;
[0043] S210: The smart password key saves the ticket in the internal file storage area in the form of a file;
[0044] S211: The typical password application system imports and parses the ticket from the smart password key;
[0045] S212: The typical password application system saves the ticket by itself.
[0046] Preferably, the authentication ticket authentication and authorization processing flow in step S4 includes the following steps:
[0047] S400: The typical password application system reads the authentication ticket from the database;
[0048] S401: The typical password application system calls the online interface of the quantum key service device according to different scenarios, and sends the ticket parameters and the ticket to the quantum key service device;
[0049] S402: The quantum key service device reads the authentication key authKey;
[0050] S403: The quantum key service device performs HMAC operation on the ticket parameters using authKey, and the operation result is recorded as ticket1;
[0051] S404: The quantum key service device compares the ticket with ticket1;
[0052] S405: If the comparison is consistent, the required data is provided; otherwise, the service is refused and an error is returned.
[0053] Preferably, step S5 includes the following steps:
[0054] S501: The quantum key service device returns the response result of step S405 to the typical password application system;
[0055] S502: The typical password application system obtains the response result and performs business processing.
[0056] Preferably, there are four types of authentication tickets designed according to different scenarios of using quantum key service devices in a typical cryptographic application system, including application tickets, access tickets, issuance tickets, and subscription tickets; the application ticket refers to the identity credential information granted by the identity authentication and authorization system to the typical cryptographic application system to access the quantum key service device; the access ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system to apply for an end-to-end key from the quantum key service device; the issuance ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system to publish a group key topic through the quantum key service device; the subscription ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system to subscribe to a group key topic through the quantum key service device.
[0057] Preferably, the authentication key is the authentication key authKey between the identity authentication and authorization system and the quantum key service device, the authentication algorithm is the HMAC algorithm based on SM3, and the ticket parameters include one or more combinations of the identifier appName of the typical cryptographic application system, the identifier qksName of the quantum key service device, the identifier sQksName of the sending quantum key service device, the identifier dQksName of the receiving quantum key service device, the key topic topic, the identifier sAppName of the sending typical cryptographic application system, and the identifier dAppName of the receiving typical cryptographic application system.
[0058] Preferably, the calculations of different said authentication tickets are as follows:
[0059] Application ticket: appTkt = HMAC(authKey, appName|qksName);
[0060] Access ticket: accTkt =
[0061] HMAC(authKey, topic|sAppName|sQksName|dAppName|dQksName);
[0062] Issuance ticket: pubTkt = HMAC(authKey, topic|sAppName|sQksName);
[0063] Subscription ticket: subTkt =
[0064] HMAC(authKey, topic|sAppName|sQksName|dAppName|dQksName).
[0065] Due to the adoption of the above technical solutions, the technical progress achieved by the present invention is as follows.
[0066] The method for issuing and authenticating identity authentication tickets based on the anti-quantum symmetric cryptography algorithm of the present invention has the advantages of anti-quantum attack, offline secure transmission, simple and efficient authentication, etc. Description of the Drawings
[0067] Figure 1 is the hardware framework of the identity authentication and authorization system of the present invention;
[0068] Figure 2 is the software framework of the identity authentication and authorization system of the present invention;
[0069] Figure 3 is the overall authentication flowchart of the present invention;
[0070] Figure 4 is the authentication key generation processing flowchart of the present invention;
[0071] Figure 5 is the authentication key offline charging processing flowchart of the present invention;
[0072] Figure 6 is the authentication ticket generation processing flowchart of the present invention;
[0073] Figure 7 is the authentication ticket offline issuance processing flowchart of the present invention;
[0074] Figure 8 is the authentication ticket authentication processing and response result return flowchart of the present invention;
[0075] Figure 9 is the calculation flowchart of the authentication ticket of the present invention. Detailed Embodiments
[0076] The present invention will be further described in detail below in conjunction with the drawings and specific embodiments.
[0077] An identity authentication and authorization method applicable to a quantum key distribution network includes an identity authentication and authorization system. The hardware of the identity authentication and authorization system mainly consists of a power supply module, a CPU, a memory, a hard disk, a cryptographic card, a bridge chip, a USB controller, and an Ethernet controller. Among them, the cryptographic card is a PCI-E cryptographic card, and the bridge chip is a PCI-E bridge chip. The hardware framework of the identity authentication and authorization system is as Figure 1 shown. The output end of the CPU is respectively connected to the input ends of the PCI-E bridge chip and the memory. The output end of the PCI-E bridge chip is respectively connected to the input ends of the PCI-E cryptographic card, the hard disk, the USB controller, and the Ethernet controller. The output end of the CPU is also connected to a VGA interface. The power supply module is used to provide power for the identity authentication and authorization system, and the power supply module is connected to a power interface.
[0078] The software of the identity authentication and authorization system mainly consists of an identity authentication and authorization program, a database, a password card driver program, etc. The identity authentication and authorization program consists of a system management module, a key management module, and a ticket management module. The system management module is used to manage the system through a management page. The key management module mainly manages authentication keys, and the ticket management module mainly manages authentication tickets. The database stores system data. The password card driver program provides a call service for the PCI-E password card. The software framework of the identity authentication and authorization system is as Figure 2 shown.
[0079] The overall authentication process of the identity authentication and authorization system is as Figure 3 shown and includes the following steps:
[0080] S1: The identity authentication and authorization system generates and saves an authentication key for the quantum key service device and injects it into the quantum key service device offline through an intelligent password key.
[0081] As Figure 4 shown, the authentication key generation processing flow includes the following steps:
[0082] S100: The identity authentication and authorization system reads a 16-byte random number from the password card belonging to the identity authentication and authorization system as the authentication key, denoted as authKey;
[0083] S101: The identity authentication and authorization system calls the encryption interface of the password card to encrypt authKey.
[0084] S102: The password card performs an encryption operation on authKey using the key encryption key KEK. The encryption algorithm uses the ECB mode of SM4. If the calculation fails, step S100 is repeated. If the calculation is successful, the encrypted key ciphertext is denoted as cipherKey.
[0085] S103: The identity authentication and authorization system binds the identifier qksName of the quantum key service device to cipherKey.
[0086] S104: The identity authentication and authorization system writes qksName and cipherKey into the database.
[0087] S105: The database stores qksName and cipherKey.
[0088] S106: The generation of the authentication key ends.
[0089] As Figure 5 shown, the authentication key offline injection processing flow includes the following steps:
[0090] S107: The identity authentication and authorization system reads the encrypted authentication key cipherKey from the database.
[0091] S108: Decrypt the cipherKey to restore the authentication key authKey, and the decryption algorithm uses the ECB mode of SM4.
[0092] S109: The identity authentication and authorization system exports the authentication key to the smart password key.
[0093] S110: The smart password key stores the authentication key in the internal secure storage area.
[0094] S111: The quantum key service device imports the authentication key from the smart password key.
[0095] S112: The quantum key service device saves the authentication key by itself.
[0096] S2: The identity authentication and authorization system calculates and generates an authentication ticket for the typical password application system and saves it, and imports it offline into the typical password application system through the smart password key.
[0097] As Figure 6 shown, the authentication ticket generation processing flow includes the following steps:
[0098] S200: The identity authentication and authorization system enters the ticket parameters and the identifier qksName of the quantum key service device.
[0099] S201: The identity authentication and authorization system reads the ciphertext of the authentication key cipherKey from the database according to qksName.
[0100] S202: The identity authentication and authorization system calls the decryption interface of the cryptographic card to decrypt the cipherKey.
[0101] S203: The cryptographic card decrypts the cipherKey to restore the authentication key authKey, and the decryption algorithm uses the ECB mode of SM4. If the calculation fails, step S200 is performed again. If the calculation is successful, the cleartext of the key is recorded as authKey.
[0102] S204: The identity authentication and authorization system performs an HMAC operation on the ticket parameters using authKey, and uses the operation result as the authentication ticket ticket.
[0103] S205: The identity authentication and authorization system binds the authentication ticket ticket to the identifier appName of the typical password application system and writes it into the database.
[0104] S206: The database saves the authentication ticket ticket.
[0105] S207: The generation of the authentication ticket ends.
[0106] As Figure 7 shown, the process of offline issuance of authentication tickets includes the following steps:
[0107] S208: The identity authentication and authorization system reads the authentication ticket ticket from the database.
[0108] S209: The identity authentication and authorization system exports the ticket to the smart password key.
[0109] S210: The smart password key saves the ticket in the internal file storage area in the form of a file.
[0110] S211: The typical password application system imports and parses the ticket from the smart password key.
[0111] S212: The typical password application system saves the ticket by itself.
[0112] S3: The typical password application system calls the service interface of the quantum key service device through the online interface, and presents the authentication ticket as an interface parameter vector to the quantum key service device.
[0113] S4: After receiving the interface request, the quantum key service device authenticates the ticket presented by the typical password application system using the authentication key.
[0114] As Figure 8 shown, the authentication process of the authentication ticket includes the following steps:
[0115] S400: The typical password application system reads the authentication ticket ticket from the database.
[0116] S401: The typical password application system calls the online interface of the quantum key service device according to different scenarios, and sends the ticket parameters and ticket to the quantum key service device.
[0117] S402: The quantum key service device reads the authentication key authKey.
[0118] S403: The quantum key service device performs an HMAC operation on the ticket parameters using authKey, and the operation result is recorded as ticket1.
[0119] S404: The quantum key service device compares the ticket and ticket1.
[0120] S405: If the comparison is consistent, the required data is provided; otherwise, the service is refused and an error is returned.
[0121] According to different scenarios of using quantum key service devices in typical cryptographic application systems, the present invention designs four types of authentication tickets, including application tickets, access tickets, publishing tickets, and subscription tickets.
[0122] An application ticket refers to the identity credential information granted by the identity authentication and authorization system to the typical cryptographic application system for accessing the quantum key service device.
[0123] An access ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system for applying for end-to-end keys from the quantum key service device.
[0124] A publishing ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system for publishing group key topics through the quantum key service device.
[0125] A subscription ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system for subscribing to group key topics through the quantum key service device.
[0126] The authentication key is the authentication key authKey between the identity authentication and authorization system and the quantum key service device. The authentication algorithm is the HMAC algorithm based on SM3. The ticket parameters include one or more combinations of the identifier appName of the typical cryptographic application system, the identifier qksName of the quantum key service device, the identifier sQksName of the sending-end quantum key service device, the identifier dQksName of the receiving-end quantum key service device, the key topic topic, the identifier sAppName of the sending-end cryptographic application system, and the identifier dAppName of the receiving-end cryptographic application system.
[0127] The calculation flow chart of the authentication ticket is as Figure 9 shown. The calculations for different authentication tickets are as follows:
[0128] Application ticket: appTkt = HMAC(authKey, appName|qksName).
[0129] Access ticket: accTkt =
[0130] HMAC(authKey, topic|sAppName|sQksName|dAppName|dQksName).
[0131] Publishing ticket: pubTkt = HMAC(authKey, topic|sAppName|sQksName).
[0132] Subscription ticket: subTkt =
[0133] HMAC(authKey, topic|sAppName|sQksName|dAppName|dQksName).
[0134] The authentication ticket is saved in the root directory of the smart password key, i.e., the root directory, in the form of a file. The file structure is in JSON format. Different tickets have relatively fixed file names, and the file size is 256 bytes.
[0135] The file name of the application ticket is APPT, and the data format is shown in Table 1:
[0136] Table 1 Data format of the application ticket
[0137]
[0138] The file name of the access ticket is ACCT, and the data format is shown in Table 2:
[0139] Table 2 Data format of the access ticket
[0140]
[0141] The file name of the publication ticket is PUBT, and the data format is shown in Table 3:
[0142] Table 3 Data format of the publication ticket
[0143]
[0144] The file name of the subscription ticket is SUBT, and the data format is shown in Table 4:
[0145] Table 4 Data format of the publication ticket
[0146]
[0147] S5: The quantum key service device returns the result to the typical cryptographic application system.
[0148] S5 includes the following steps:
[0149] S501: The quantum key service device returns the response result of step S405 to the typical cryptographic application system.
[0150] S502: The typical cryptographic application system obtains the response result and conducts business processing.
[0151] When in use, the present invention has the advantages of anti-quantum attack, offline secure transmission, simple and efficient authentication, etc.
Claims
1. An authentication and authorization method applicable to a quantum key distribution network, characterized in that: It includes the following steps: S1: The identity authentication and authorization system generates an authentication key for the quantum key service device and saves it, and offline injects it into the quantum key service device through an intelligent cryptographic key; In the authentication key generation and processing flow of step S1, it includes the following steps: S100: The identity authentication and authorization system reads a 16-byte random number from the cryptographic card belonging to the identity authentication and authorization system as the authentication key, denoted as authKey; S101: The identity authentication and authorization system calls the encryption interface of the cryptographic card to encrypt authKey; S102: The cryptographic card performs an encryption operation on authKey using the key encryption key KEK. The encryption algorithm adopts the ECB mode of SM4. If the calculation fails, step S100 is repeated. If the calculation is successful, the ciphertext of the key is denoted as cipherKey; S103: The identity authentication and authorization system binds the identifier qksName of the quantum key service device to cipherKey; S104: The identity authentication and authorization system writes qksName and cipherKey into the database; S105: The database saves qksName and cipherKey; S106: The generation of the authentication key ends; S2: The identity authentication and authorization system calculates and generates an authentication ticket for the typical cryptographic application system and saves it, and offline imports it into the typical cryptographic application system through an intelligent cryptographic key; The authentication ticket is four types designed according to different scenarios of the typical cryptographic application system using the quantum key service device, including application ticket, access ticket, release ticket and subscription ticket. The authentication ticket is generated based on the HMAC algorithm of SM3. The ticket parameters include one or more combinations of the identifier appName of the typical cryptographic application system, the identifier qksName of the quantum key service device, the identifier sQksName of the sending-end quantum key service device, the identifier dQksName of the receiving-end quantum key service device, the key topic, the identifier sAppName of the sending-end typical cryptographic application system, and the identifier dAppName of the receiving-end typical cryptographic application system; In the authentication ticket generation and processing flow of step S2, it includes the following steps: S200: The identity authentication and authorization system enters the ticket parameters and the identifier qksName of the quantum key service device; S201: The identity authentication and authorization system reads the ciphertext of the authentication key cipherKey from the database according to qksName; S202: The identity authentication and authorization system calls the decryption interface of the cryptographic card to decrypt cipherKey; S203: The cryptographic card decrypts cipherKey to restore the authentication key authKey. The decryption algorithm adopts the ECB mode of SM4. If the calculation fails, step S200 is repeated. If the calculation is successful, the plaintext of the key is denoted as authKey; S204: The identity authentication and authorization system performs an HMAC operation on the ticket parameters using authKey, and takes the operation result as the authentication ticket ticket; S205: The identity authentication and authorization system binds the authentication ticket ticket to the identifier appName of the typical cryptographic application system and writes it into the database; S206: The database saves the authentication ticket ticket; S207: The generation of the authentication ticket ends; S3: The typical cryptographic application system calls the service interface of the quantum key service device through the online interface, and presents the authentication ticket as an interface parameter vector to the quantum key service device; specifically, the typical cryptographic application system calls the online interface of the quantum key service device according to different scenarios, and sends the ticket parameter and ticket to the quantum key service device; S4: After receiving the interface request, the quantum key service device authenticates the ticket presented by the typical cryptographic application system using the authentication key; S5: The quantum key service device returns a response result to the typical cryptographic application system.
2. The authentication and authorization method applicable to a quantum key distribution network according to claim 1, characterized in that: The authentication key offline injection processing flow in step S1 includes the following steps: S107: The identity authentication and authorization system reads the ciphertext of the authentication key cipherKey from the database; S108: Decrypt cipherKey to restore the authentication key authKey, and the decryption algorithm uses the ECB mode of SM4; S109: The identity authentication and authorization system exports the authentication key to the smart cryptographic key; S110: The smart cryptographic key saves the authentication key in the internal secure storage area; S111: The quantum key service device imports the authentication key from the smart cryptographic key; S112: The quantum key service device saves the authentication key by itself.
3. The authentication and authorization method applicable to a quantum key distribution network according to claim 1, characterized in that: The authentication ticket offline issuance processing flow in step S2 includes the following steps: S208: The identity authentication and authorization system reads the authentication ticket ticket from the database; S209: The identity authentication and authorization system exports ticket to the smart cryptographic key; S210: The smart cryptographic key saves ticket in the internal file storage area in the form of a file; S211: The typical cryptographic application system imports and parses ticket from the smart cryptographic key; S212: The typical cryptographic application system saves ticket by itself.
4. An authentication and authorization method applicable to a quantum key distribution network according to claim 3, characterized in that: The authentication ticket authentication processing flow in step S4 includes the following steps: S400: The quantum key service device reads the authentication key authKey; S401: The quantum key service device performs an HMAC operation on the ticket parameter using authKey, and the operation result is recorded as ticket1; S402: The quantum key service device compares ticket and ticket1; S403: If the comparison is consistent, the required data is provided, otherwise the service is refused and an error is returned.
5. An authentication and authorization method applicable to a quantum key distribution network according to claim 4, characterized in that: Step S5 includes the following steps: S501: The quantum key service device returns the response result of step S403 to the typical cryptographic application system; S502: The typical cryptographic application system obtains the response result and performs business processing.
6. An authentication and authorization method applicable to a quantum key distribution network according to claim 4, characterized in that: The application ticket refers to the identity credential information granted by the identity authentication and authorization system to the typical cryptographic application system to access the quantum key service device; the access ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system to apply for an end-to-end key from the quantum key service device; the release ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system to publish a group key topic through the quantum key service device; The subscription ticket refers to the permission credential information granted by the identity authentication and authorization system to the typical cryptographic application system to subscribe to the group key topic through the quantum key service device.
7. An authentication and authorization method applicable to a quantum key distribution network according to claim 1, characterized in that: The calculation of different authentication tickets is as follows: Application ticket: appTkt = HMAC(authKey, appName|qksName); Access ticket: accTkt = HMAC(authKey, topic|sAppName|sQksName|dAppName|dQksName); Publication ticket: pubTkt = HMAC(authKey, topic|sAppName|sQksName); Subscription ticket: subTkt = HMAC(authKey, topic|sAppName|sQksName|dAppName|dQksName).
Citation Information
Patent Citations
Method and apparatus implementing remote access control based on portable memory apparatus
CN101340436A
Identity authentication method of quantum cryptography network expansion network equipment
CN114697039A