A quantum key secure distribution method and system based on the Internet of Things

By centralizing encryption strategies at the IoT platform layer and utilizing quantum key generation and symmetric encryption algorithms, a quantum key secure distribution system is constructed, solving the problems of high cost and high latency in IoT platforms and achieving improvements in security and efficiency.

CN115361129BActive Publication Date: 2025-10-31HENGTONG QASKY QUANTUM INFORMATION RES INST CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211049438.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-30
Publication Date
2025-10-31
Estimated Expiration
2042-08-30

AI Technical Summary

Technical Problem

Existing IoT platforms suffer from high costs for layered encryption during secure transmission and lack a vertically integrated security protection system, resulting in high overall costs and high latency.

Method used

A centralized encryption strategy is implemented at the platform layer. Public and private key certificates and a first key are generated using a quantum random generator. A routing group is constructed using the Dijkstra algorithm. The secure distribution of quantum keys is achieved by using symmetric encryption algorithms and public key encryption, thereby reducing the frequency of key interactions.

Benefits of technology

It reduces encryption costs and transmission latency, improves security and communication efficiency, solves the problem of difficult key interaction, realizes the design of global keys and group keys, and ensures the uniformity of the security system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115361129B_ABST
    Figure CN115361129B_ABST
Patent Text Reader

Abstract

This invention relates to a quantum key secure distribution system based on the Internet of Things (IoT), comprising a quantum random number generator, a terminal layer, an access layer, and a platform layer. The platform layer includes a quantum key service module, a resource and information management module, a secure access management module, and a secure encoding / decoding management module. The IoT-based quantum key secure distribution method applied to this system, from the perspective of protecting key security, designs group keys and global keys based on quantum random numbers that conform to the characteristics of the IoT. These are encrypted and distributed to terminals using a public key, and the terminals decrypt them to obtain session keys, which are then used to decrypt and retrieve instructions. This method deploys each module at the platform layer, enabling the IoT system to shift from a traditional hierarchical encryption strategy to one focused on business-level security encryption. This results in lower costs and lower transmission latency when building a security system with the same security level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum key distribution technology, and in particular to a quantum key secure distribution method and system based on the Internet of Things. Background Technology

[0002] The core functions of current IoT platforms are massive device connectivity, edge fragmentation, secure management services, and trusted secure access. Currently, massive device connectivity is mainly achieved through load balancing technology, enabling distributed connection, collection, and storage of massive amounts of data, but there are few comprehensive solutions for massive security keys. The main means of addressing edge fragmentation is to implement multi-interface, multi-homed access, adapting to different device scenarios through different access methods. Secure management services primarily utilize cloud services and cloud computing for slice-based management, integrating security features across segments. Regarding secure access, the security system is empowered by the trustworthiness of the terminal, the network, and the stability of the connection, with layered isolation and protection at each level and technology, using different technologies for different scenarios to ensure the platform's security features.

[0003] Current IoT platforms prioritize virus and attack prevention, but suffer from weak vertical security, lacking secure key management and distribution mechanisms tailored to IoT scenarios. Traditional IoT security technologies primarily employ encryption at the transport layer, with less encryption at the business layer, failing to manage massive access volumes and lacking a vertically integrated security protection system. For security, security devices must be layered at each level, resulting in high overall costs and latency. Traditional IoT network architectures employ hierarchical security strategies, mainly building VPN tunnels from the perspective of establishing a trusted network, but failing to implement secure encryption strategies at the business layer.

[0004] Quantum communication is an important branch of quantum information science. Current quantum key distribution technologies mainly rely on the complementary functions of quantum key generation and quantum key receiving modules to transmit keys, and depend on separate channels to transmit key information. This requires dedicated lines for management, resulting in high costs. Summary of the Invention

[0005] Therefore, the technical problem to be solved by the present invention is to overcome the high cost of hierarchical and layered encryption during secure transmission in the prior art.

[0006] To address the aforementioned technical problems, this invention provides a quantum key secure distribution method based on the Internet of Things (IoT), applied at the platform layer, comprising:

[0007] Obtain the initial terminal number of the target terminal, and encrypt the initial terminal number to generate an encrypted terminal number;

[0008] The encrypted terminal number and private key certificate are obtained and packaged into an initial SDK;

[0009] Obtain the routing information of the target terminal, and construct a set of initial SDKs for all terminals under the same routing group based on the routing information;

[0010] Obtain a set of decryption terminal numbers based on the initial SDK set, compare the initial terminal number with the set of decryption terminal numbers, and if there is a number in the set of decryption terminal numbers that matches the initial terminal number, randomly select a first key for the target terminal;

[0011] Based on the routing information of the target terminal, the first key is encrypted using a public key and distributed to the target terminal, so that the target terminal can use the private key certificate to decrypt and obtain the session key;

[0012] The public key, private key certificate, and first key are all derived from quantum keys generated by a quantum random generator.

[0013] In one embodiment of the present invention, the encryption of the initial terminal number to generate the encrypted terminal number uses a symmetric encryption algorithm.

[0014] In one embodiment of the present invention, obtaining the routing information of the target terminal includes obtaining the routing information during the routing aggregation process when the target terminal carries its initial SDK to apply for network access and perform routing aggregation.

[0015] Among them, route aggregation is the shortest path selection aggregation using Dijkstra's algorithm under global routing.

[0016] In one embodiment of the present invention, obtaining the decryption terminal number set based on the initial SDK set includes: using a symmetric encryption algorithm to decrypt the encrypted terminal numbers in the initial SDK set to obtain the decryption terminal number set.

[0017] In one embodiment of the present invention, the comparison of the initial terminal number with the decrypted terminal number set further includes, if there is no number in the decrypted terminal number set that matches the initial terminal number, then a network access failure is reported and the terminal is discarded.

[0018] In one embodiment of the present invention, randomly selecting a first key for the target terminal includes:

[0019] When the target terminal is a terminal, a first key is randomly selected for the terminal as a group key, and the group key is used to encrypt a single instruction distributed to the terminal.

[0020] When the target terminal is a trusted network terminal, a first key is randomly selected for the trusted network terminal as a global key, and the global key is used to encrypt the combined instructions distributed to the trusted network terminal.

[0021] The term "end terminal" refers to the last terminal in each routing group, and the term "trusted network terminal" refers to the remaining terminals in each routing group excluding the end terminal.

[0022] This invention also provides a quantum key secure distribution system based on the Internet of Things, comprising:

[0023] A quantum random number generator is used to generate truly random numbers as quantum keys.

[0024] The terminal layer, including end terminals and trusted network terminals, all carry the initial SDK;

[0025] The access layer includes a gateway, which is communicatively connected to the terminal layer;

[0026] At the platform layer, the IoT-based quantum key secure distribution method as described in any one of claims 1 to 6 is applied for data transmission with the target terminal using a secure session key, comprising:

[0027] The quantum key service module is used to acquire and store the quantum key pushed by the quantum random generator, acquire and encrypt the initial terminal number to generate an encrypted terminal number, and randomly select the first key for the verified target terminal.

[0028] The resource and information management module is used to acquire and store the terminal's private key certificate, initial terminal number and decrypted terminal number, encapsulate the initial SDK, and compare the initial terminal number and the decrypted terminal number to verify whether the target terminal is secure.

[0029] The secure encoding / decoding management module is used to obtain and decrypt the initial SDK set and the decryption terminal number set.

[0030] The secure access management module is used to obtain the routing information of the target terminal, construct a set of initial SDKs for all terminals under the same routing group, encrypt the first key, and distribute it to the target terminal according to the routing information.

[0031] In one embodiment of the present invention, the quantum key service module obtains the quantum key pushed by the quantum random generator and securely stores it in the form of a queue as a key pool.

[0032] In one embodiment of the present invention, the terminal receives a single instruction ciphertext encrypted with a group key from the platform layer, and decrypts it using a session key to obtain the single instruction.

[0033] In one embodiment of the present invention, the trusted network terminal receives a combined instruction ciphertext forwarded by the gateway from the platform layer, and decrypts it using a session key to obtain the combined instruction.

[0034] The gateway forwarding process includes the gateway obtaining a combined instruction encrypted with a global key issued by the platform layer, decrypting it with the global key to obtain a new combined instruction, and then encrypting the new combined instruction again with the global key before forwarding it to the trusted network terminal.

[0035] The technical solution of the present invention has the following advantages compared with the prior art:

[0036] The IoT-based quantum key secure distribution method described in this invention centralizes the encryption strategy at the platform layer. By deploying each module at the platform layer, the IoT system transforms from a traditional hierarchical encryption strategy to one focused on business-level security encryption. This results in lower costs and lower transmission latency when building a security system with the same security level. The method utilizes a first key to design a global key and a group key. The group key reduces the frequency of key interactions while ensuring security, thus improving efficiency. The global key is broadcast using a centralized gateway, solving the problem of difficult key interactions for downlink commands on the platform. Distributing quantum keys through the IoT is independent of traditional network media attributes, allowing distribution in a transparent transmission channel without modifying the transmitted business message body, thus ensuring the security of key transmission. Attached Figure Description

[0037] To make the content of this invention easier to understand, the invention will be further described in detail below with reference to specific embodiments and accompanying drawings, wherein...

[0038] Figure 1 This is a flowchart of the steps of the quantum key secure distribution method based on the Internet of Things provided in the embodiments of the present invention;

[0039] Figure 2 This is a schematic diagram of the composition of the IoT-based quantum key secure distribution system provided in an embodiment of the present invention. Detailed Implementation

[0040] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, so that those skilled in the art can better understand and implement the present invention. However, the embodiments described are not intended to limit the present invention.

[0041] Reference Figure 1 As shown, the IoT-based quantum key secure distribution method provided in this embodiment of the invention includes:

[0042] S1. Obtain the initial terminal number of the target terminal, and encrypt the initial terminal number to generate an encrypted terminal number.

[0043] S2. Obtain the encrypted terminal number and private key certificate and encapsulate them into an initial SDK.

[0044] S3. The target terminal carries its initial SDK to apply for network access and route aggregation, obtains routing information during the route aggregation process, and constructs a set of initial SDKs of all terminals under the same routing group based on the routing information.

[0045] Among them, route aggregation is the shortest path selection aggregation using Dijkstra's algorithm under global routing.

[0046] S4. Use a symmetric encryption algorithm to decrypt the initial SDK set to obtain a decrypted terminal number set. Compare the initial terminal number with the decrypted terminal number set. If there is a number in the decrypted terminal number set that matches the initial terminal number, randomly select a first key for the target terminal.

[0047] If there is no terminal number in the set of decrypted terminal numbers that matches the initial terminal number, then the network access failure is reported and the terminal is discarded.

[0048] S5. Based on the routing information of the target terminal, the first key is encrypted and distributed to the target terminal using a public key, so that the target terminal can use the private key certificate to decrypt and obtain the session key.

[0049] The public key, private key certificate, and first key are all derived from quantum keys generated by a quantum random generator. The first key includes a group key and a global key; the group key is used to encrypt a single instruction distributed to the end terminal; the global key is used to encrypt a combination of instructions distributed to trusted network terminals; the end terminal is the last terminal in each routing group, and the trusted network terminals are the remaining terminals in each routing group excluding the end terminal. The end terminal receives the ciphertext of the single instruction encrypted with the group key from the platform layer and decrypts it using the session key to obtain the single instruction; the trusted network terminal receives the ciphertext of the combination of instructions forwarded from the platform layer by the gateway and decrypts it using the session key to obtain the combination of instructions; the gateway forwarding includes the gateway receiving the combination of instructions encrypted with the global key issued by the platform layer, decrypting it using the global key to obtain a new combination of instructions, and then encrypting the new combination of instructions again using the global key before forwarding it to the trusted network terminal.

[0050] A global key and a group key were designed by randomly selecting the first key based on routing information. The group key is used to transmit a single instruction, while the global key is used to issue combined instructions. The group key solves the security problem of the key required for uplink information of terminals under a routing set, reducing the frequency of key interaction and improving efficiency while ensuring security. Traditional strategies do not have unified key management and use point-to-point asymmetric encryption. Key interaction usually uses a relatively complex block algorithm for key synchronization, while the global key solves the problem of difficult key interaction for downlink instructions on the platform.

[0051] Reference Figure 2 As shown, the IoT-based quantum key secure distribution system provided in the embodiments of the present invention comprises: a quantum random generator for generating truly random numbers as quantum keys; a terminal, including an end terminal and a trusted network terminal, both carrying an initial SDK; and a platform layer, which applies the above-described IoT-based quantum key secure distribution method for securely transmitting session keys with the terminals for data transmission.

[0052] The platform layer includes: a quantum key service module, used to acquire quantum keys pushed by a quantum random generator and securely store them in a queue as a key pool; acquire and encrypt the initial terminal number to generate an encrypted terminal number; and randomly select a first key for verified terminals; a resource and information management module, used to acquire and store the terminal's private key certificate, initial terminal number, and decrypted terminal number; encapsulate the initial SDK; and compare the initial terminal number and decrypted terminal number to verify the terminal's security; a secure encoding and decoding management module, used to acquire and decrypt the set of initial SDKs to obtain the set of decrypted terminal numbers; and a secure access management module, used to acquire the terminal's routing information; construct a set of initial SDKs for all terminals under the same routing group; encrypt the first key; and distribute it to the terminal according to the routing information.

[0053] Specifically, based on the above embodiments, the specific steps of applying the IoT-based quantum key secure distribution method provided in this invention to an IoT-based quantum key secure distribution system include:

[0054] Before the device is connected to the network, a trusted network is built based on the platform layer. A quantum random generator is used to distribute keys and generate Qkey(n). The quantum key service module stores the keys securely in the form of a queue to form a key queue: Qkey(n)...Qkey(n+n).

[0055] The resource and information management module obtains the initial terminal number and applies for encryption to the quantum key service module, so that the quantum key service module can use a symmetric encryption algorithm to encrypt the initial terminal number to generate an encrypted terminal number; the quantum key service module obtains the private key certificate distributed to the terminal; the encrypted terminal number and the private key certificate are encapsulated into an initial SDK and reported to the secure access management module.

[0056] The terminal, carrying its initial SDK, reports it layer by layer at the network layer to apply for network access and route aggregation. The secure access management module records the routing information and synchronously reports it to the quantum key service module, enabling the sharing of route sets between the two modules and constructing a set of encodings K1…K for all terminal initial SDKs under a routing group. n The information is then reported to the security encoding / decoding management module. Route aggregation refers to the use of Dijkstra's algorithm to select and aggregate the shortest paths under global routing.

[0057] The secure encoding and decoding management module uses a symmetric encryption algorithm to decrypt the encrypted terminal numbers in the initial SDK set to obtain the decrypted terminal numbers, and then reports them to the resource and information management module.

[0058] If the initial terminal number and the decryption terminal number mentioned in the resource and information management module match, the initial terminal number is reported to the quantum key service module; if they do not match, the information is fed back to the secure access management module, which sends a network access failure message to the terminal and discards the terminal.

[0059] The quantum key service module, based on the initial terminal number, matches routing information and randomly selects a first key from the key pool Qkey(n)...Qkey(n+n). The first key includes a group key for encrypting and distributing single instructions to the end terminal and a global key for encrypting and distributing combined instructions to trusted network terminals; that is, a new group key Qkey(p1)...Qkey(p2) is randomly generated for each group. n The system then randomly selects a key from Qkey(n) to generate a global key Qkey(q) and reports it to the secure access management module. Here, the last terminal is the last terminal in each routing group, and the trusted network terminal is any other terminal in each routing group excluding the last terminal.

[0060] The secure access management module uses public key pairs to group keys Qkey(p1)...Qkey(p1) n After encryption, it is distributed to the end terminal of each route set according to the original route. At the same time, the global key Qkey(q) is encrypted using the public key and distributed to all trusted network terminals level by level.

[0061] After receiving the key information, the terminal decrypts it using the private key certificate to obtain the symmetric key Qkey(p), which is the session key. After obtaining the session key, the terminal receives a single instruction ciphertext from the platform layer and decrypts it using the session key to obtain the single instruction; the trusted network terminal receives a combined instruction ciphertext from the platform layer forwarded by the gateway and decrypts it using the session key to obtain the combined instruction.

[0062] In this embodiment, the quantum key secure distribution system based on the Internet of Things uses a symmetric encryption algorithm during sessions, that is, the platform layer and the terminal use the same key for encryption and decryption; the public key, private key certificate and session key used by the entire system are all true random numbers generated by a quantum random number generator.

[0063] Specifically, based on the above embodiments, in a single instruction scenario, the terminal uses the session key Qkey(p) to encrypt the communication data data1, obtains the encrypted data data2, sends the encrypted data data2 to the platform layer according to the routing information stored in the secure access management module, and selects the corresponding session key for secure decryption, extracts and restores the communication data data1, and submits it to the platform layer; when the platform issues a single instruction, it selects the corresponding session key Qkey(p) according to the routing information of the secure access management module to encrypt the issued data data3, obtains the encrypted data data4, and the terminal uses the session key Qkey(p) obtained by decrypting with its private key certificate to decrypt data data4 to obtain the issued data data3.

[0064] In a single-command interaction business flow, the encryption and decryption keys used are session keys Qkey(p1)...Qkey(p1) selected based on the routing information from the security access management module. n In a single-command scenario, the session key is obtained by the terminal decrypting the received group key using a private key certificate. The group key solves the security problem of the key required for uplink information of all terminals under a routing set. While ensuring security, it reduces the frequency of key interaction between the terminal and the platform, improves communication efficiency, and reduces communication overhead.

[0065] Specifically, based on the above embodiments, in the scenario where the platform issues combined instructions, the platform issues combined instructions encrypted with a global key to the gateway. The gateway decrypts the combined instructions using the global key, parses the instructions, encrypts the parsed combined instructions again using the global key, and issues them to the trusted network terminal. After receiving the parsed and encrypted combined instructions, the trusted network terminal decrypts them using the global key to obtain the combined instructions issued by the platform.

[0066] The global key manages keys under the same gateway in a unified manner, and uses a centralized gateway to interact between the platform and various terminals, which reduces the network pressure of large-scale key forwarding and solves the problem of difficult key interaction for downlink commands on the platform.

[0067] In this embodiment, the distribution of quantum keys is based on the Internet of Things, which is independent of the network medium attributes and does not rely on the network channel. Instead, it uses a transparent transmission network pipeline for distribution. No processing is performed on the transmitted business message body during the transmission process, which ensures the transmission security of the business message body to a certain extent.

[0068] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention.

Claims

1. A quantum key secure distribution method based on the Internet of Things, characterized in that, Applied to the platform layer, including: Obtain the initial terminal number of the target terminal, and encrypt the initial terminal number to generate an encrypted terminal number; The encrypted terminal number and private key certificate are obtained and packaged into an initial SDK; Obtain the routing information of the target terminal, and construct a set of initial SDKs for all terminals under the same routing group based on the routing information; Obtain the decryption terminal number set based on the initial SDK set, and compare the initial terminal number set with the decryption terminal number set: If there is no number in the set of decrypted terminal numbers that matches the initial terminal number, then the network access failure is reported and the terminal is discarded. If the set of decryption terminal numbers contains a number that matches the initial terminal number, a first key is randomly selected for the target terminal. This includes: when the target terminal is the last terminal, a first key is randomly selected for the last terminal as a group key, which is used to encrypt a single instruction distributed to the last terminal; when the target terminal is a trusted network terminal, a first key is randomly selected for the trusted network terminal as a global key, which is used to encrypt a combination of instructions distributed to the trusted network terminal. The last terminal is the terminal at the very end of each routing group, and the trusted network terminal is any terminal in each routing group other than the last terminal. Based on the routing information of the target terminal, the first key is encrypted using a public key and distributed to the target terminal, so that the target terminal can use the private key certificate to decrypt and obtain the session key; The private key certificate, the first key, and the public key are all derived from quantum keys generated by a quantum random generator.

2. The quantum key secure distribution method based on the Internet of Things according to claim 1, characterized in that, The encryption of the initial terminal number to generate the encrypted terminal number uses a symmetric encryption algorithm.

3. The quantum key secure distribution method based on the Internet of Things according to claim 1, characterized in that, The process of obtaining the routing information of the target terminal includes: When the target terminal carries its initial SDK to apply for network access and perform route aggregation, it obtains the routing information during the route aggregation process; Among them, route aggregation is the shortest path selection aggregation using Dijkstra's algorithm under global routing.

4. The quantum key secure distribution method based on the Internet of Things according to claim 1, characterized in that, The step of obtaining the decryption terminal number set based on the initial SDK set includes: using a symmetric encryption algorithm to decrypt the encrypted terminal numbers in the initial SDK set to obtain the decryption terminal number set.

5. A quantum key secure distribution system based on the Internet of Things, characterized in that, include: A quantum random number generator is used to generate truly random numbers as quantum keys. The terminal layer, including end terminals and trusted network terminals, all carry the initial SDK; The access layer includes a gateway, which is communicatively connected to the terminal layer; At the platform layer, the IoT-based quantum key secure distribution method as described in any one of claims 1 to 4 is applied for data transmission with the target terminal via secure transmission of session keys, comprising: The quantum key service module is used to acquire and store the quantum key pushed by the quantum random generator, acquire and encrypt the initial terminal number to generate an encrypted terminal number, and randomly select the first key for the verified target terminal. The resource and information management module is used to acquire and store the terminal's private key certificate, initial terminal number and decrypted terminal number, encapsulate the initial SDK, and compare the initial terminal number and the decrypted terminal number to verify whether the target terminal is secure. The secure encoding / decoding management module is used to obtain and decrypt the initial SDK set and the decryption terminal number set. The secure access management module is used to obtain the routing information of the target terminal, construct a set of initial SDKs for all terminals under the same routing group, encrypt the first key, and distribute it to the target terminal according to the routing information.

6. The IoT-based quantum key secure distribution system according to claim 5, characterized in that, The quantum key service module obtains the quantum keys pushed by the quantum random generator and securely stores them in the form of a queue as a key pool.

7. The IoT-based quantum key secure distribution system according to claim 5, characterized in that, The terminal receives a single instruction ciphertext encrypted with a group key from the platform layer, and decrypts it using a session key to obtain the single instruction.

8. The IoT-based quantum key secure distribution system according to claim 5, characterized in that, The trusted network terminal receives the combined instruction ciphertext forwarded by the gateway from the platform layer, and decrypts it using the session key to obtain the combined instruction. The gateway forwarding process includes the gateway obtaining a combined instruction encrypted with a global key issued by the platform layer, decrypting it with the global key to obtain a new combined instruction, and then encrypting the new combined instruction again with the global key before forwarding it to the trusted network terminal.

Citation Information

Patent Citations

  • Secure multicast method for overlay network at low expenses

    CN103997463A

  • Method and system for remote initialization of Internet of Things virtual subscriber identity module card

    CN104185176A

  • Internet of Things data interaction method, system and device based on quantum key and medium

    CN113922956A