A communication encryption method and system based on quantum key centralized management
Through the bypass deployment of quantum encryption proxy terminals and gateways and the management of quantum key cloud platforms, the problems of data security, device deployment and key management in existing technologies have been solved, and efficient and secure quantum key management and communication encryption have been achieved.
Patent Information
- Application Number
- CN202211106902.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-13
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-09-13
AI Technical Summary
The existing communication encryption services with centralized quantum key management have problems such as data security leakage, difficulty in deploying link encryption equipment, difficulty in key management, inability to cope with quantum computing threats, multiple equipment failure points and high bandwidth usage.
Quantum encryption proxy terminals and gateway bypass deployment are adopted, and the quantum information and encryption strategies of the devices are centrally managed through the quantum key cloud platform to realize the negotiation and management of quantum session keys, perform data encryption and decryption, and perform identity authentication and key updates through the quantum key cloud platform.
It solves data security issues, simplifies device deployment, improves key management efficiency, enhances resistance to quantum computing, reduces device failure points, and optimizes bandwidth usage.
Smart Images

Figure CN115459912B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of quantum secure communication and the field of encryption technology, in particular to a communication encryption method and system based on quantum key centralized management. BACKGROUND
[0002] The existing communication encryption service technology of quantum key centralized management mainly has the following problems:
[0003] 1) With the acceleration of digitalization process, the business system exists in the transmission of plaintext mode, and there is a data security problem, which is easy to leak sensitive data;
[0004] 2) After the enterprise business is put on the cloud, it is difficult to deploy link encryption equipment in series in front of the business service end;
[0005] 3) The key used by the general link encryption equipment has the problem of difficult management;
[0006] 4) The general link encryption equipment, similar to VPN, uses a key agreement algorithm based on an asymmetric cryptography mechanism,
[0007] 5) Technical defects that cannot cope with the threat of potential quantum computing;
[0008] 6) The general link encryption equipment is generally connected in series in the communication link, which is easy to increase the device fault point and affect the original business;
[0009] 7) Similar VPN link encryption occupies more bandwidth, and there is an efficiency problem. SUMMARY
[0010] The present application aims to provide a communication encryption method and system based on quantum key centralized management to solve the technical defects of the current digital business system security transmission, the efficiency and reliability of the similar VPN link encryption, and the use of the key agreement algorithm based on the asymmetric cryptography mechanism cannot cope with the threat of potential quantum computing.
[0011] The technical solution of the present application is as follows:
[0012] A communication encryption method based on quantum key centralized management, comprising the following steps:
[0013] S1: quantum encryption gateway is deployed in parallel in the communication network, quantum encryption agent is deployed in series or in parallel in the communication network, quantum encryption agent terminal and quantum encryption agent gateway are registered in the quantum key cloud platform, and device quantum information and encryption strategy are obtained;
[0014] S2, the device quantum information of the quantum encryption agent terminal and the quantum encryption agent gateway is updated offline or online;
[0015] S3, quantum encryption proxy terminal and quantum encryption proxy gateway use the negotiated quantum session key to encrypt and decrypt the passing data according to the encryption policy requirements;
[0016] S4, identity authentication from quantum encryption proxy terminal or quantum encryption proxy gateway to quantum key cloud platform;
[0017] S5. The quantum encryption proxy terminal or quantum encryption proxy gateway obtains the quantum key from the quantum key cloud platform;
[0018] S6. The quantum encryption proxy terminal and the quantum encryption proxy gateway negotiate a quantum session key.
[0019] S7, the quantum encryption proxy terminal and the quantum encryption proxy gateway respectively use the negotiated quantum session key to encrypt and decrypt the sent data to form their own encrypted data packets.
[0020] Preferably, step S1 is specifically:
[0021] S11: Log in to the quantum key cloud platform to register, enter the quantum encryption agent device information, generate quantum encryption agent information and multiple sets of quantum symmetric keys associated with the quantum encryption agent, and save them on the quantum key cloud platform. At the same time, select an encryption strategy for the quantum encryption agent device and save it on the quantum key cloud platform;
[0022] S12: Download the quantum encryption proxy information, multiple sets of quantum symmetric keys and encryption strategies, and store them in the quantum encryption proxy composed of the quantum encryption proxy terminal and the quantum encryption proxy gateway.
[0023] Preferably, the offline update is to re-register the quantum encryption proxy terminal and the quantum encryption proxy gateway on the quantum key cloud platform.
[0024] Preferably, the online update comprises the following steps:
[0025] S21: The quantum encryption proxy terminal and the quantum encryption proxy gateway request the quantum key cloud platform to update device quantum information;
[0026] S22: The quantum key cloud platform receives the request, searches for the corresponding key update quantum key and verification quantum key, generates a new identity quantum key, a new key encryption quantum key, a new key update quantum key, and a new verification quantum key for the device, and encrypts the new multiple sets of quantum keys using the key update quantum key to generate key ciphertext data, uses the verification quantum key to generate key verification data, and sends the key ciphertext data and key verification data to the quantum encryption proxy terminal and the quantum encryption proxy gateway;
[0027] S23: The quantum encryption agent terminal and the quantum encryption agent gateway receive response data of the quantum key cloud platform, obtain key ciphertext data and key check data, check the key check data using a check quantum key, and decrypt the key ciphertext data using a key update quantum key to obtain a new identity quantum key, a new key encryption quantum key, a new key update quantum key, and a new check quantum key. If the check is passed, the update is successful, otherwise the update fails. If the update is successful, the quantum encryption agent terminal and the quantum encryption agent gateway send an update confirmation message to the quantum key cloud platform.
[0028] Preferably, step S3 specifically processes as follows:
[0029] S31: When the service terminal sends data to the service server, the quantum encryption agent terminal intercepts the data packet and judges the current encryption strategy.
[0030] S32: The quantum encryption agent terminal and the quantum encryption agent gateway negotiate a quantum session key. The quantum encryption agent terminal completes identity authentication with the quantum key cloud platform and obtains a quantum key. Correspondingly, the quantum encryption agent gateway also completes identity authentication with the quantum key cloud platform and obtains the same quantum key, completing the quantum session key negotiation.
[0031] S33: The quantum encryption agent terminal and the quantum encryption agent gateway negotiate a quantum session key to encrypt the data packet, forming an encrypted data packet.
[0032] S34: The quantum encryption agent gateway intercepts the encrypted data packet, decrypts the encrypted data packet, and sends the decrypted data to the service server.
[0033] S35: The service server returns response data to the service terminal. The quantum encryption agent gateway intercepts the response data packet, encrypts the response data packet using the quantum session key negotiated by the quantum encryption agent terminal and the quantum encryption agent gateway, and forms an encrypted data packet.
[0034] S36: The quantum encryption agent terminal intercepts the encrypted data packet, decrypts the encrypted data packet, and sends the decrypted data to the service terminal.
[0035] Preferably, in step S4, the quantum encryption agent terminal or the quantum encryption agent gateway respectively completes identity authentication with the quantum key cloud platform, and adopts a two-way authentication method based on quantum symmetric keys.
[0036] Preferably, in step S5, the quantum encryption agent terminal or the quantum encryption agent gateway obtains a quantum key from the quantum key cloud platform, and the specific steps include:
[0037] S51: The quantum encryption agent terminal or quantum encryption agent gateway requests the quantum key cloud platform to obtain quantum keys;
[0038] S52: The quantum key cloud platform receives the request, determines whether the quantum encryption agent has the right to obtain quantum keys according to the DeviceName of the quantum key cloud platform, and if the quantum encryption agent has the right, checks whether the corresponding KID key exists, and if the KID key does not exist, generates quantum session keys and verification quantum keys through a quantum random number generator or a QKD generation agent, finds the corresponding key encryption quantum keys and verification quantum keys through the DeviceName, encrypts the quantum keys using the key encryption quantum keys to generate key ciphertext data, generates key verification data using the DeviceName and the key ciphertext data using the verification quantum keys, and sends the key ciphertext data and the key verification data to the quantum encryption agent;
[0039] S53: The quantum encryption agent receives the response data of the quantum key cloud platform, obtains the key ciphertext data and the key verification data, checks the key verification data using the verification quantum keys, decrypts the key ciphertext data using the key encryption quantum keys to obtain quantum session keys and verification quantum keys, and if the checking is passed, the quantum encryption agent obtains the quantum keys successfully, otherwise, the quantum encryption agent fails to obtain the quantum keys, and if the quantum encryption agent successfully obtains the quantum keys, the quantum encryption agent sends an acquisition confirmation message to the quantum key cloud platform.
[0040] Preferably, in step S6, the quantum session key negotiation between the quantum encryption agent terminal and the quantum encryption agent gateway includes the following steps:
[0041] S61: When the service terminal sends data to the service server, the quantum encryption agent terminal intercepts the data packet, determines whether there is a negotiated quantum session key, and if there is, directly encrypts the data using the negotiated quantum session key, otherwise, performs quantum session key negotiation;
[0042] S62: The quantum encryption agent terminal detects whether the opposite end has a quantum encryption agent gateway, sends a detection message, and the detection message contains the DeviceName information of the quantum encryption agent terminal;
[0043] S63: The quantum encryption agent gateway receives the detection packet of the quantum encryption agent terminal, responds to the detection confirmation message, and the detection confirmation message includes the DeviceName information of the quantum encryption agent gateway;
[0044] S64: After the detection is completed, key negotiation is started, the quantum encryption agent terminal requests the quantum key cloud platform for quantum keys, the quantum key cloud platform responds to the quantum key request message, contains quantum session keys and verification quantum keys, and is encrypted using key encryption quantum keys;
[0045] S65: The quantum encryption agent terminal sends a key negotiation request message to the quantum encryption agent gateway.
[0046] S66: The quantum encryption agent gateway receives the message and requests a quantum key from the quantum key cloud platform. The quantum key cloud platform responds to the quantum key request message and encrypts the quantum key using the key. The quantum encryption agent gateway sends a key negotiation response message.
[0047] S67: The quantum encryption agent terminal receives the message and sends a key negotiation confirmation message to the quantum encryption agent gateway.
[0048] Preferably, in step S7, the quantum encryption agent terminal encrypts and decrypts the transmitted data using the quantum session key to form an encrypted data packet, and the specific steps include:
[0049] S71: When the service terminal sends data to the service server, the quantum encryption agent terminal intercepts the data packet and encapsulates it into an encrypted data packet, which is sent to the quantum encryption agent gateway.
[0050] S72: The quantum encryption agent gateway intercepts the encrypted data packet and decrypts it into an original data packet, which is sent to the service server.
[0051] Preferably, in step S7, the quantum encryption agent gateway encrypts and decrypts the transmitted data using the quantum session key to form an encrypted data packet, and the specific steps include:
[0052] S81: When the service server sends data to the service terminal, the quantum encryption agent gateway intercepts the data packet and encapsulates it into an encrypted data packet, which is sent to the quantum encryption agent terminal.
[0053] S82: The quantum encryption agent terminal intercepts the encrypted data packet and decrypts it into an original data packet, which is sent to the service terminal.
[0054] The application also provides a communication encryption system based on quantum key centralized management, which includes a quantum key cloud platform, a quantum encryption agent terminal, a quantum encryption agent gateway, a service terminal, a service server and the Internet. The quantum key cloud platform is connected to the quantum encryption agent terminal and the quantum encryption agent gateway. The Internet is connected to the service terminal and the service server. The quantum encryption agent terminal is connected in series or bypassed between the Internet and the service terminal according to networking requirements and encryption strategies. The quantum encryption agent gateway is bypassed between the service server and the Internet.
[0055] The quantum key cloud platform is used for completing quantum key centralized management, and is responsible for providing identity authentication services, quantum key management services and encryption policy management services to quantum encryption agent terminals and quantum encryption agent gateways,
[0056] The quantum encryption agent terminals and the quantum encryption agent gateways mainly register with the quantum key cloud platform, complete identity authentication, obtain encryption policies and quantum keys, and complete session key negotiation, so that the quantum encryption agent terminals and the quantum encryption agent gateways can encrypt and decrypt network transmission data.
[0057] Preferably, the quantum key cloud platform comprises a quantum random number module, a QKD networking module, a quantum key management module, a registration module, an identity authentication service module and an encryption policy management module.
[0058] Preferably, the quantum encryption agent terminals and the quantum encryption agent gateways respectively comprise a detection module, a quantum random number module, an identity authentication module, a key negotiation module, a network data processing module and a data encryption and decryption module.
[0059] Compared with the prior art, the present application has the following beneficial effects:
[0060] 1. The present application adopts quantum encryption agent terminals and quantum encryption agent gateways to manage quantum information of devices, and quantum session keys and verification quantum keys are managed by the quantum key cloud platform, so that the problem of key distribution in the symmetric key system in the prior art is solved.
[0061] 2. The present application can realize network data encryption communication between the quantum encryption agent terminals and the quantum encryption agent gateways, and can also realize network data encryption communication between the quantum encryption agent terminals.
[0062] 3. The quantum encryption agent gateway is deployed in bypass mode, which solves the problem that it is difficult to deploy link encryption devices in series in front of a service server.
[0063] 4. The quantum encryption agent gateway is deployed in bypass mode, which solves the problem that link encryption devices in the prior art generally need to be connected in series, so that normal service functions are affected by faults.
[0064] 5. The quantum encryption agent terminals and the quantum encryption agent gateways can update device quantum information through the quantum key cloud platform, can realize one certificate and one encryption of identity quantum keys, can realize one-time one encryption of key encryption quantum keys, and improve the security of quantum key centralized management. BRIEF DESCRIPTION OF DRAWINGS
[0065] Figure 1 It is a structural diagram of the communication encryption system based on quantum key centralized management of the present application (in series connection mode).
[0066] Figure 2 Structure diagram of the communication encryption system based on centralized management of quantum key (bypass mode) of the application;
[0067] Figure 3 Structure diagram of the quantum key cloud platform of the application;
[0068] Figure 4 Structure diagram of the quantum encryption agent terminal / quantum encryption agent gateway of the application;
[0069] Figure 5 Format diagram of the quantum encryption data message in the embodiment of the application. DETAILED DESCRIPTION
[0070] The application will be described in detail below with reference to the accompanying drawings of the embodiments of the application.
[0071] As shown in Figure 1 , Figure 2 The communication encryption system based on centralized management of quantum key of the application mainly comprises a quantum key cloud platform, a quantum encryption agent terminal and a quantum encryption agent gateway, wherein, Figure 1 The service terminal and the quantum encryption agent terminal are connected in series, Figure 2 The service terminal and the quantum encryption agent terminal are connected in bypass mode.
[0072] In summary, the service terminal and the quantum encryption agent terminal are connected in series or bypass mode according to networking requirements and encryption strategy, and the service server and the quantum encryption agent gateway are connected in bypass mode. The quantum encryption agent terminal can also be deployed to the service terminal in the form of pure software quantum encryption agent.
[0073] The quantum key cloud platform mainly completes centralized management of quantum key, and is responsible for providing identity authentication service, quantum key management service and encryption strategy management service to the quantum encryption agent terminal and the quantum encryption agent gateway.
[0074] The quantum encryption agent terminal and the quantum encryption agent gateway mainly register with the quantum key cloud platform, complete identity authentication, obtain encryption strategy and obtain quantum key.
[0075] The quantum encryption agent terminal and the quantum encryption agent gateway complete session key negotiation, and encrypt and decrypt network transmission data.
[0076] As shown in Figure 3 The quantum key cloud platform comprises a quantum random number module, a QKD networking module, a quantum key management module, a registration module, an identity authentication service module and an encryption strategy management module.
[0077] The quantum key cloud platform is responsible for generating quantum keys, the key management module is responsible for managing quantum keys, distributing quantum keys, the identity authentication module is responsible for identity authentication of quantum encryption proxy terminal / quantum encryption proxy gateway access, and the encryption policy management module is responsible for management and distribution of encryption policies to quantum encryption proxy terminals / quantum encryption proxy gateways.
[0078] As shown in Figure 4 The quantum encryption proxy terminal / quantum encryption proxy gateway mainly consists of a detection module, a quantum random number module, an identity authentication module, a key negotiation module, a network data processing module, and a data encryption and decryption module.
[0079] The quantum encryption proxy terminal / quantum encryption proxy gateway is responsible for receiving encryption policies from the quantum key cloud platform, completing identity authentication, obtaining quantum keys, negotiating quantum session keys between the quantum encryption proxy terminal and the terminal and between the quantum encryption proxy terminal and the gateway, processing network data, and completing network data encryption and decryption.
[0080] The quantum key cloud platform is characterized in that quantum keys are uniformly managed, quantum key services are provided, including storage, distribution, and destruction operations, and quantum keys K managed by the quantum key cloud platform contain two components, key identification KID and key value KV, and can be expressed as .
[0081] The quantum encryption proxy terminal / quantum encryption proxy gateway is registered with the quantum key cloud platform. The quantum key cloud platform generates device quantum information and initial encryption policies related to the quantum encryption proxy terminal / quantum encryption proxy gateway device information and stores them to the quantum encryption proxy terminal / gateway. The device quantum information mainly includes DeviceName and multiple sets of quantum symmetric keys, including identity quantum keys, key encryption quantum keys, key update quantum keys, and verification quantum keys.
[0082] When the business terminal and the business server communicate data, according to the encryption policy requirements, quantum encryption proxy detection is performed first, then quantum session key negotiation between the quantum encryption proxy terminal and the quantum encryption proxy gateway is performed, and then the data is encrypted and decrypted using the quantum session keys negotiated by the quantum encryption proxy terminal and the quantum encryption proxy gateway, respectively, to complete network data encryption communication.
[0083] Embodiment:
[0084] S1: Quantum encryption proxy terminal and quantum encryption proxy gateway register with the quantum password service platform:
[0085] In an embodiment of the present application, the quantum encryption agent terminal and the quantum encryption agent gateway are collectively referred to as a quantum encryption agent, and the quantum encryption agent terminal and the quantum encryption agent gateway are registered on the quantum key cloud platform to obtain device quantum information and encryption strategies. The main steps include:
[0086] S11: Log in to the quantum key cloud platform management system for registration, input quantum encryption agent device information, generate quantum encryption agent information associated with the quantum encryption agent, multiple sets of quantum symmetric keys, and save them in the quantum key cloud platform. At the same time, select an encryption strategy for the quantum encryption agent device and save it in the quantum key cloud platform.
[0087] S12: Download the quantum encryption agent information, multiple sets of quantum symmetric keys, and encryption strategies, and store them in the quantum encryption agent.
[0088] S2: Quantum encryption agent device quantum information update:
[0089] The device quantum information of the quantum encryption agent terminal and the quantum encryption agent gateway can be updated offline or online. Offline update mainly involves re-registering the quantum encryption agent terminal and the quantum encryption agent gateway on the quantum key cloud platform, and the specific steps are similar to registration. The steps of online update mainly include:
[0090] S21: The quantum encryption agent terminal and the quantum encryption agent gateway request to update the device quantum information on the quantum key cloud platform. The request mainly contains DeviceName.
[0091] S22: The quantum key cloud platform receives the request, finds the corresponding key update quantum key through DeviceName, checks the quantum key, generates new identity quantum keys, new key encryption quantum keys, new key update quantum keys, and new check quantum keys for the device, encrypts the new multiple sets of quantum keys using the key update quantum key to generate key ciphertext data, uses the check quantum key to generate key check data for DeviceName and key ciphertext data, and sends the key ciphertext data and key check data to the quantum encryption agent terminal and the quantum encryption agent gateway.
[0092] S23: The quantum encryption proxy terminal and the quantum encryption proxy gateway receive the response data from the quantum key cloud platform, obtain the key ciphertext data and key verification data, verify the key verification data using the verification quantum key, and decrypt the key ciphertext data using the key update quantum key to obtain the new identity quantum key, the new key encryption quantum key, the new key update quantum key, and the new verification quantum key. If the verification passes, the update is successful; otherwise, the update fails. If the update is successful, the quantum encryption proxy terminal and the quantum encryption proxy gateway send an update confirmation message to the quantum key cloud platform.
[0093] S3: The quantum encryption proxy terminal and quantum encryption proxy gateway use the negotiated quantum session key to encrypt and decrypt the passing data according to the encryption policy requirements.
[0094] When data communication is carried out between the service terminal and the service server, according to the encryption policy requirements, the quantum session key negotiated between the quantum encryption proxy terminal and the quantum encryption proxy gateway is used to encrypt and decrypt the data, thereby completing the encrypted communication of the network data. The main steps include:
[0095] S31: When the business terminal sends data to the business service end, the quantum encryption proxy terminal is used to intercept the data packet and determine the current encryption strategy. The encryption strategy mainly includes whether to force encryption, encryption method, key update method, encrypted traffic data object, serial or bypass deployment and other strategies.
[0096] S32: The quantum encryption proxy terminal negotiates the quantum session key with the quantum encryption proxy gateway. The quantum encryption proxy terminal completes identity authentication with the quantum key cloud platform and obtains the quantum key. The corresponding quantum encryption proxy gateway also completes identity authentication with the quantum key cloud platform and obtains the same quantum key, completing the quantum session key negotiation.
[0097] S33: Encrypt the data packet using the quantum session key negotiated between the quantum encryption proxy terminal and the quantum encryption proxy gateway to form an encrypted data packet;
[0098] S34: The quantum encryption proxy gateway intercepts the encrypted data packet, decrypts the encrypted data packet and sends the decrypted data to the business service end;
[0099] S35: The business service end returns response data to the business terminal, and the quantum encryption proxy gateway intercepts the response data packet and encrypts the response data packet using the quantum session key negotiated between the quantum encryption proxy terminal and the quantum encryption proxy gateway to form an encrypted data packet;
[0100] S36: The quantum encryption agent terminal intercepts the encrypted data packet, decrypts the encrypted data packet, and sends the decrypted data to the service terminal;
[0101] S4: Quantum encryption agent terminal or quantum encryption agent gateway to quantum key cloud platform identity authentication,
[0102] When the quantum encryption agent terminal or quantum encryption agent gateway and the quantum key cloud platform complete identity authentication, a two-way authentication method based on quantum symmetric key is adopted, and the main steps include:
[0103] S41: The quantum encryption agent terminal or quantum encryption agent gateway as a client sends a client-first-message to the server, including a locally generated quantum random number Client-nonce, DeviceName and the KID of the identity quantum key to the quantum key cloud platform.
[0104] S42: The quantum key cloud platform as a server receives DeviceName, KID and Client-nonce, finds the corresponding Salt and Iteration-count of DeviceName, generates a quantum random number Server-nonce, and sends a server-first-message to the quantum encryption agent terminal or quantum encryption agent gateway together with Salt and Iteration-count.
[0105] S43: The quantum encryption agent terminal or quantum encryption agent gateway receives Server-nonce, salt and iteration-count, calculates the client identity certificate Proof[c] = Key[c] ⊕ HC(H(Key[c], Auth)). Where KV is the identity quantum key, Auth = client-first-message + server-first-message. Key[c]= DK(KV, Salt, Iteration-count). HC() represents an abstract function whose output result is related to the input function, and one implementation can be a kind of algorithm related to cryptography. H() represents a hash function, and DK() represents a key derivation function. The quantum encryption agent terminal or quantum encryption agent gateway sends the identity certificate Proof[c] to the quantum key cloud platform.
[0106] S44: After receiving the message, the quantum key cloud platform finds the corresponding H(Key) stored by the server according to DeviceName, calculates Key[d] = Proof[c] HC(H(Key, Auth) combining client-first-message and server-first-message, compares H(Key[d]) with H(Key) to determine whether they are consistent, and if so, the authentication of the client is passed, otherwise, the authentication is not passed. If the authentication is passed, calculate Proof[d] = HC(H(Key[d], Auth), and send the server identity proof Proof[d] to the quantum encryption agent terminal or quantum encryption agent gateway.
[0107] S45: The quantum encryption agent terminal or quantum encryption agent gateway receives Proof[d], calculates Proof[e] = HC(H(Key[c], Auth), and compares the values of Proof[d] and Proof[e], and if they are consistent, the authentication of the server is passed, otherwise, the authentication is not passed.
[0108] S5: The quantum encryption agent terminal or quantum encryption agent gateway obtains the quantum key from the quantum key cloud platform,
[0109] After the quantum encryption agent terminal or quantum encryption agent gateway completes the identity authentication, the step of obtaining the quantum key from the quantum key cloud platform mainly includes:
[0110] S51: The quantum encryption agent terminal or quantum encryption agent gateway requests the quantum key from the quantum key cloud platform, the initiator in the quantum encryption agent terminal or quantum encryption agent gateway is called the start-end quantum encryption agent, and the opposite party is called the opposite-side quantum encryption agent. The start-end quantum encryption agent obtains the quantum key request mainly including the start-end DeviceName, the DeviceName of the opposite-side quantum encryption agent, and KID1, KID2. The opposite-side quantum encryption agent initiates the quantum key request, which needs to include its own DeviceName and KID1, KID2.
[0111] S52: The quantum key cloud platform receives the request, determines whether the quantum encryption agent has the right to obtain the quantum key according to its own DeviceName, and if so, finds whether the corresponding KID key exists, and if not, generates the quantum session key through the quantum random number generator or the QKD generation agent and the verification quantum key , find the corresponding key encryption quantum key, check quantum key through DeviceName, and encrypt the above multiple sets of quantum keys using the key encryption quantum key to generate key ciphertext data, generate key check data using the DeviceName and the key ciphertext data using the check quantum key, and send the key ciphertext data and the key check data to the quantum encryption agent.
[0112] S53: The quantum encryption agent receives the response data of the quantum key cloud platform, obtains the key ciphertext data and the key check data, checks the key check data using the check quantum key, and decrypts the key ciphertext data using the key encryption quantum key to obtain the quantum session key and the check quantum key , and if the check passes, the acquisition is successful, otherwise the acquisition fails. If the acquisition is successful, the quantum encryption agent sends an acquisition confirmation message to the quantum key cloud platform.
[0113] S6: Quantum session key negotiation between the quantum encryption agent terminal and the quantum encryption agent gateway,
[0114] When the business terminal and the business server communicate data, according to the encryption strategy requirement, the network data encryption communication is completed, and the key for network data encryption needs to be negotiated. The quantum encryption agent terminal and the quantum encryption agent gateway use the centralized management mode of the quantum key cloud platform to negotiate the final quantum session key. The main steps include:
[0115] S61: When the business terminal sends data to the business server, the quantum encryption agent terminal intercepts the data packet, judges whether there is a negotiated quantum session key, and if so, directly uses the negotiated quantum session key to encrypt the data. Otherwise, the quantum session key negotiation is performed.
[0116] S62: The quantum encryption agent terminal probes whether the opposite end exists the quantum encryption agent gateway, sends a probe message, and contains the quantum encryption agent terminal DeviceName information.
[0117] S63: The quantum encryption agent gateway receives the probe packet of the quantum encryption agent terminal, responds to the probe confirmation message, and includes the DeviceName information of the quantum encryption agent gateway.
[0118] S64: After the probe is completed, the key negotiation is started. The quantum encryption agent terminal requests the quantum key from the quantum key cloud platform, contains the quantum encryption agent terminal DeviceName information and the quantum encryption agent gateway DeviceName information, and the quantum key KID information. The quantum key cloud platform responds to the quantum key request message, contains the quantum session key And check quantum key And use key encryption quantum key encryption.
[0119] S65: The quantum encryption agent terminal sends a key negotiation request message to the quantum encryption agent gateway, containing KID1 and KID2 information.
[0120] S66: The quantum encryption agent gateway receives the message and requests the quantum key of KID from the quantum key cloud platform. The quantum key cloud platform responds to the quantum key request message, containing the quantum session key And check quantum key And use key encryption quantum key encryption. The quantum encryption agent gateway sends a key negotiation response message, containing KID1 and KID2 information.
[0121] S67: The quantum encryption agent terminal receives the message and sends a key negotiation confirmation message to the quantum encryption agent gateway.
[0122] The quantum session key update between the quantum encryption agent terminal and the quantum encryption agent gateway is the same as the quantum session key negotiation step between the quantum encryption agent terminal and the quantum encryption agent gateway.
[0123] S7: The quantum encryption agent terminal uses the quantum session key to encrypt and decrypt the data sent, forming an encrypted data packet,
[0124] When the service terminal sends data to the service server, the quantum encryption agent terminal intercepts the data packet, and uses the quantum session key of the quantum encryption agent terminal to encrypt the data packet, forming an encrypted data packet. The main steps include:
[0125] S71: When the service terminal sends data to the service server, the quantum encryption agent terminal intercepts the data packet, Figure 5 The quantum encryption agent terminal checks the encryption strategy, and splits the data packet into IP header data, protocol header data and payload data, wherein the IP header, protocol header data and payload data are defined as encrypted data. The encrypted data is encrypted into ciphertext data using the quantum session key, and the quantum encryption header and ciphertext data are used to generate quantum check data using the check quantum key. According to the new IP header, quantum encryption header, quantum encryption ciphertext, quantum check data, the encrypted data packet is encapsulated and sent to the quantum encryption agent gateway.
[0126] S72: The quantum encryption proxy gateway intercepts the encrypted data packet, splits the encrypted data packet into a new IP header, a quantum encryption header, to-be-quantum-decrypted data, and to-be-quantum-verified data. The to-be-quantum-verified data is verified using a verification quantum key, and the to-be-quantum-decrypted data is decrypted using a quantum session key. The decrypted data is encapsulated into a data packet according to the original IP header, the protocol header, and the original data, and is sent to the service server.
[0127] S8: The quantum encryption proxy gateway uses a quantum session key to encrypt and decrypt the transmitted data to form an encrypted data packet.
[0128] When the service server sends data to the service terminal, the quantum encryption proxy gateway intercepts the data packet, and the quantum encryption proxy gateway uses a quantum session key to encrypt the data packet to form an encrypted data packet. The main steps include:
[0129] S81: When the service server sends data to the service terminal, the quantum encryption proxy gateway intercepts the data packet, Figure 5 The quantum encryption proxy gateway checks the encryption policy and splits the data packet into IP header data, protocol header data, and payload data. The IP header, protocol header data, and payload data are referred to as to-be-encrypted data. The to-be-encrypted data is encrypted into ciphertext data using a quantum session key. The quantum encryption header and the ciphertext data are used to generate quantum verification data using a verification quantum key. The encrypted data packet is encapsulated according to the new IP header, the quantum encryption header, the quantum encryption ciphertext, and the quantum verification data, and is sent to the quantum encryption proxy terminal.
[0130] S82: The quantum encryption proxy terminal intercepts the encrypted data packet, splits the encrypted data packet into a new IP header, a quantum encryption header, to-be-quantum-decrypted data, and to-be-quantum-verified data. The to-be-quantum-verified data is verified using a verification quantum key, and the to-be-quantum-decrypted data is decrypted using a quantum session key. The decrypted data is encapsulated into a data packet according to the original IP header, the protocol header, and the original data, and is sent to the service terminal.
[0131] In some embodiments, the quantum encryption proxy terminal and the quantum encryption proxy gateway are in a one-to-many relationship.
[0132] In some embodiments, the quantum encryption proxy terminal and the quantum encryption proxy terminal can also complete encrypted communication of network data.
[0133] In some embodiments, the quantum encryption proxy terminal can be deployed in series or bypass. The quantum encryption proxy gateway is deployed in bypass.
[0134] In some embodiments, the quantum encryption proxy terminal and the quantum encryption proxy gateway both include a quantum random number module.
[0135] In some embodiments, the quantum encryption proxy terminal and the quantum encryption proxy gateway use a symmetric encryption method that is resistant to quantum computing attacks during the encryption and decryption process, and use a keyed message authentication code to verify the integrity of the key information and the ciphertext information.
[0136] In some embodiments, the device quantum information of the quantum encryption proxy terminal and the quantum encryption proxy gateway can be updated by key updating quantum key.
[0137] In some embodiments, the identity authentication between the quantum encryption proxy terminal and the quantum encryption proxy gateway and the quantum key cloud platform can be completed once the identity quantum key is replaced.
[0138] In some embodiments, the quantum encryption proxy terminal and the quantum encryption proxy gateway can update the quantum session key for encrypting and decrypting network data to achieve one-time-one-key.
[0139] Based on the structure, method and embodiments of the present invention, it can be seen that the present invention uses the device quantum information of the quantum encryption proxy terminal and the quantum encryption proxy gateway, as well as the quantum session key and the verification quantum key, to be centrally managed through the quantum key cloud platform, solving the key distribution problem of the symmetric key system in the prior art; the present invention can realize the encrypted communication of network data between the quantum encryption proxy terminal and the quantum encryption proxy gateway, and can also realize the encrypted communication of network data between the quantum encryption proxy terminal and the quantum encryption proxy terminal; the present invention deploys the quantum encryption proxy gateway in a bypass manner, which effectively solves the problem of the great difficulty in deploying link encryption equipment in series in front of the business service end; the bypass deployment of the quantum encryption proxy gateway in the present invention solves the problem that the link encryption equipment in the prior art generally needs to be connected in series with the network, and failures may affect normal business functions;
[0140] The quantum encryption proxy terminal and quantum encryption proxy gateway of the present invention can update the device quantum information through the quantum key cloud platform, realize one certificate and one secret for the identity quantum key, and at the same time realize one-time and one secret for the key encryption quantum key, thereby improving the security of centralized management of quantum keys.
Claims
1. A communication encryption method based on centralized quantum key management, characterized in that: The following steps are involved: S1: The quantum encryption proxy gateway is deployed in a bypass manner on the communication network, and the quantum encryption proxy terminal is deployed in series or in a bypass manner on the communication network. The quantum encryption proxy terminal and quantum encryption proxy gateway are registered on the quantum key cloud platform to obtain device quantum information and encryption strategies; S2, the quantum information of the device of the quantum encryption proxy terminal and the quantum encryption proxy gateway is updated offline or online; S3, quantum encryption proxy terminal and quantum encryption proxy gateway use the negotiated quantum session key to encrypt and decrypt the passing data according to the encryption policy requirements; S4, identity authentication from quantum encryption proxy terminal or quantum encryption proxy gateway to quantum key cloud platform; S5. The quantum encryption proxy terminal or quantum encryption proxy gateway obtains the quantum key from the quantum key cloud platform; S6. The quantum encryption proxy terminal and the quantum encryption proxy gateway negotiate a quantum session key. S7, the quantum encryption proxy terminal and the quantum encryption proxy gateway respectively use the negotiated quantum session key to encrypt and decrypt the sent data to form their own encrypted data packets. The online update includes the following steps: S21: The quantum encryption proxy terminal and the quantum encryption proxy gateway request the quantum key cloud platform to update device quantum information; S22: The quantum key cloud platform receives the request, searches for the corresponding key update quantum key and verification quantum key, generates a new identity quantum key, a new key encryption quantum key, a new key update quantum key, and a new verification quantum key for the device, and encrypts the new multiple sets of quantum keys using the key update quantum key to generate key ciphertext data, uses the verification quantum key to generate key verification data, and sends the key ciphertext data and key verification data to the quantum encryption proxy terminal and the quantum encryption proxy gateway; S23: The quantum encryption proxy terminal and the quantum encryption proxy gateway receive the response data from the quantum key cloud platform, obtain the key ciphertext data and the key verification data, use the verification quantum key to verify the key verification data, and use the key update quantum key to decrypt the key ciphertext data to obtain the new identity quantum key, the new key encryption quantum key, the new key update quantum key, and the new verification quantum key. If the verification passes, the update is successful, otherwise the update fails. If the update is successful, the quantum encryption proxy terminal and the quantum encryption proxy gateway send an update confirmation message to the quantum key cloud platform.
2. The communication encryption method based on centralized quantum key management according to claim 1, characterized in that: Step S1 is specifically as follows: S11: Log in to the quantum key cloud platform to register, enter the quantum encryption agent device information, generate quantum encryption agent information associated with the quantum encryption agent and multiple sets of quantum symmetric keys, and save them on the quantum key cloud platform. At the same time, select an encryption strategy for the quantum encryption agent device and save it on the quantum key cloud platform; S12: Download the quantum encryption proxy information, multiple sets of quantum symmetric keys and encryption strategies, and store them in the quantum encryption proxy composed of the quantum encryption proxy terminal and the quantum encryption proxy gateway.
3. The communication encryption method based on centralized quantum key management according to claim 1, characterized in that: The offline update is to re-register the quantum encryption proxy terminal and the quantum encryption proxy gateway on the quantum key cloud platform.
4. A communication encryption method based on centralized quantum key management according to claim 1, characterized in that: The specific process of step S3 is as follows: S31: When the service terminal sends data to the service server, the quantum encryption proxy terminal is used to intercept the data packet and determine the current encryption strategy; S32: The quantum encryption proxy terminal negotiates the quantum session key with the quantum encryption proxy gateway. The quantum encryption proxy terminal completes identity authentication with the quantum key cloud platform and obtains the quantum key. The corresponding quantum encryption proxy gateway also completes identity authentication with the quantum key cloud platform and obtains the same quantum key, completing the quantum session key negotiation. S33: Encrypt the data packet using the quantum session key negotiated between the quantum encryption proxy terminal and the quantum encryption proxy gateway to form an encrypted data packet; S34: The quantum encryption proxy gateway intercepts the encrypted data packet, decrypts the encrypted data packet and sends the decrypted data to the business service end; S35: The business service end returns response data to the business terminal, and the quantum encryption proxy gateway intercepts the response data packet and encrypts the response data packet using the quantum session key negotiated between the quantum encryption proxy terminal and the quantum encryption proxy gateway to form an encrypted data packet; S36: The quantum encryption proxy terminal intercepts the encrypted data packet, decrypts the encrypted data packet and sends the decrypted data to the service terminal.
5. The communication encryption method based on centralized quantum key management according to claim 1, wherein: In step S4, the quantum encryption proxy terminal or quantum encryption proxy gateway completes identity authentication with the quantum key cloud platform respectively, using a two-way authentication method based on quantum symmetric key.
6. The communication encryption method based on centralized quantum key management according to claim 1, characterized in that: In step S5, the quantum encryption proxy terminal or quantum encryption proxy gateway obtains the quantum key from the quantum key cloud platform. The specific steps include: S51: The quantum encryption proxy terminal or quantum encryption proxy gateway requests the quantum key cloud platform to obtain the quantum key; S52: The quantum key cloud platform receives the request and determines whether the quantum encryption agent has the authority to obtain the quantum key based on its own DeviceName. If the corresponding authority exists, it searches for the corresponding KID key. If not, it generates the agent's quantum session key and verification quantum key through a quantum random number generator or QKD, searches for the corresponding key encryption quantum key and verification quantum key through the DeviceName, and encrypts multiple sets of quantum keys with the key encryption quantum key to generate key ciphertext data, uses the verification quantum key to generate key verification data based on the DeviceName and the key ciphertext data, and sends the key ciphertext data and key verification data to the quantum encryption agent; S53: The quantum encryption agent receives the response data from the quantum key cloud platform, obtains the key ciphertext data and the key verification data, verifies the key verification data using the verification quantum key, decrypts the key ciphertext data using the key encryption quantum key, and obtains the quantum session key and the verification quantum key. If the verification passes, the acquisition is successful, otherwise the acquisition fails. If the acquisition is successful, the quantum encryption agent sends an acquisition confirmation message to the quantum key cloud platform.
7. The communication encryption method based on centralized quantum key management according to claim 1, characterized in that: In step S6, the quantum session key negotiation between the quantum encryption proxy terminal and the quantum encryption proxy gateway includes the following specific steps: S61: When the service terminal sends data to the service server, the quantum encryption proxy terminal intercepts the data packet and determines whether a negotiated quantum session key already exists. If so, the data is directly encrypted using the negotiated quantum session key; otherwise, quantum session key negotiation is performed. S62: The quantum encryption proxy terminal detects whether there is a quantum encryption proxy gateway on the other end and sends a detection message containing the quantum encryption proxy terminal DeviceName information; S63: The quantum encryption proxy gateway receives the detection packet from the quantum encryption proxy terminal and responds with a detection confirmation message, including the DeviceName information of the quantum encryption proxy gateway; S64: After the detection is completed, key negotiation is initiated. The quantum encryption proxy terminal requests the quantum key from the quantum key cloud platform. The quantum key cloud platform responds with a quantum key request message containing the quantum session key and the verification quantum key, and uses key encryption quantum key encryption; S65: The quantum encryption proxy terminal sends a key negotiation request message to the quantum encryption proxy gateway; S66: The quantum encryption proxy gateway receives the message and requests the quantum key from the quantum key cloud platform. The quantum key cloud platform responds to the quantum key request message and uses key encryption quantum key encryption. The quantum encryption proxy gateway sends a key negotiation response message. S67: The quantum encryption proxy terminal receives the message and sends a key negotiation confirmation message to the quantum encryption proxy gateway.
8. The communication encryption method based on centralized quantum key management according to claim 1, wherein: In step S7, the quantum encryption proxy terminal uses the quantum session key to encrypt and decrypt the sent data to form an encrypted data packet. The specific steps include: S71: When the service terminal sends data to the service server, the quantum encryption proxy terminal intercepts the data packet, encapsulates the data packet into an encrypted data packet, and sends it to the quantum encryption proxy gateway; S72: The quantum encryption proxy gateway intercepts the encrypted data packet and decrypts the encrypted data packet into the original data packet, and sends the original data packet to the business service end.
9. The communication encryption method based on centralized quantum key management according to claim 1, wherein: In step S7, the quantum encryption proxy gateway uses the quantum session key to encrypt and decrypt the sent data to form an encrypted data packet. The specific steps include: S81: When the service server sends data to the service terminal, the quantum encryption proxy gateway is used to intercept the data packet, encapsulate the data packet into an encrypted data packet, and send it to the quantum encryption proxy terminal; S82: The quantum encryption proxy terminal intercepts the encrypted data packet and decrypts the encrypted data packet into the original data packet, and sends the original data packet to the service terminal.
10. A communication encryption system based on centralized quantum key management, characterized in that: A communication encryption method based on centralized quantum key management for implementing any one of claims 1 to 9, comprising a quantum key cloud platform, a quantum encryption proxy terminal, a quantum encryption proxy gateway, a business terminal, a business service end, and the Internet, wherein the quantum key cloud platform is connected to the quantum encryption proxy terminal and the quantum encryption proxy gateway, respectively; the Internet is connected to the business terminal and the business service end, respectively; the quantum encryption proxy terminal is connected in series or in a bypass connection between the Internet and the business terminal according to networking requirements and encryption strategies; the quantum encryption proxy gateway is connected in a bypass connection between the business service end and the Internet; The quantum key cloud platform is used to complete the centralized management of quantum keys, and is responsible for providing identity authentication services, quantum key management services, and encryption policy management services to quantum encryption proxy terminals and quantum encryption proxy gateways. The quantum encryption proxy terminal and quantum encryption proxy gateway mainly register with the quantum key cloud platform, complete identity authentication, obtain encryption strategy, obtain quantum key, and the quantum encryption proxy terminal and quantum encryption proxy gateway complete session key negotiation to encrypt and decrypt network transmission data.
11. The communication encryption system based on centralized quantum key management according to claim 10, characterized in that: The quantum key cloud platform includes a quantum random number module, a QKD networking module, a quantum key management module, a registration module, an identity authentication service module and an encryption policy management module.
12. The communication encryption system based on centralized quantum key management according to claim 10, characterized in that: The quantum encryption proxy terminal and quantum encryption proxy gateway respectively include a detection module, a quantum random number module, an identity authentication module, a key negotiation module, a network data processing module, and a data encryption and decryption module.
Citation Information
Patent Citations
Communication system based on quantum encryption box
CN114398688A
Transmission communication mode determination method and system
CN114500177A