Quantum key encryption, decryption method and system
By encrypting the encrypted quantum key using random numbers and prefabricated quantum keys in the quantum key encryption system, the problem of insufficient security and applicability of quantum key transmission in the prior art is solved, and higher security and wide applicability are achieved.
Patent Information
- Application Number
- CN202211100040.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-09
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-09-09
AI Technical Summary
When the prior art uses quantum keys for encryption, there are problems with low security performance and applicability. For example, the quantum key is not encrypted during transmission, there is a risk of leakage and cracking, and a mobile storage medium is required. The process is cumbersome and limited to user equipment with USB interface.
By receiving a session creation request initiated by the user equipment, a session identifier is generated and a request is sent to the quantum random number generator, an encrypted quantum key is determined, and the encrypted quantum key is encrypted using the random number and prefabricated quantum key to ensure the secure transmission of the prefabricated quantum key.
Improve the security of quantum keys, ensure the secure transmission and storage of prefabricated quantum keys, and are suitable for various types of user equipment, enhancing applicability.
Smart Images

Figure CN115473638B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly relates to a quantum key encryption, decryption method and system. Background Art
[0002] In network communication, how to ensure the security of data has always been one of the key research directions. In recent years, with the rapid development of quantum communication technology, using quantum keys to encrypt data to be transmitted has become increasingly popular among enterprises and institutions. Since quantum keys are true random numbers, using quantum keys to encrypt data to be transmitted has relatively high security, and the application scenarios are also constantly expanding.
[0003] The patent application with the publication number CN114844639A discloses a data transmission method, system and storage medium based on quantum keys. This patent application discloses that "encrypt the data with the quantum key and send the encrypted data to the backend server. Since the quantum key is updated each time of transmission and the data is encrypted during the transmission process", it can be seen that the quantum key is not encrypted during the transmission process and exists in plain text form, which has the possibility of being cracked due to leakage and has a certain security risk. The patent application with the publication number CN114448633A discloses a file encryption method, device, electronic device and medium based on quantum keys. This patent application discloses that "send the ciphertext of the file encryption key to the mobile storage medium and receive the response to the ciphertext of the file encryption key from the mobile storage medium. Send the file to be encrypted to the mobile storage medium and receive the encrypted file generated based on the plaintext file encryption key returned by the mobile storage medium", it can be seen that although this patent application discloses the ciphertext of the encryption key, it does not disclose the specific implementation method of encrypting the encryption key to obtain the ciphertext of the encryption key, and a mobile storage medium (such as a quantum security USB flash drive) is required, the process is cumbersome and only applicable to user devices with a USB interface, which has certain limitations. Summary of the Invention
[0004] Embodiments of the present invention provide a quantum key encryption, decryption method and system to solve the defects of low security performance and applicability existing in the prior art.
[0005] In a first aspect, the quantum key encryption provided by the embodiments of the present invention includes the following steps:
[0006] Receive a session creation request initiated by a first user device.
[0007] Determine whether there is an available session currently. If not, create a session.
[0008] Generate a session identifier for the session, send the session identifier to the first user device, and send a quantum random number acquisition request to the quantum random number generator, and receive the quantum random number of a set byte size generated and sent by the quantum random number generator.
[0009] Determine an encrypted quantum key based on the quantum random number of the set byte size.
[0010] Receive a quantum key acquisition request sent by the first user device, where the quantum key acquisition request carries a first random number, a user ID, and the session identifier.
[0011] Encrypt the encrypted quantum key using the first random number and a prefabricated quantum key.
[0012] As a preferred implementation of the first aspect, determining an encrypted quantum key based on the quantum random number of the set byte size includes:
[0013] Take the first n bytes of the quantum random number as the encrypted quantum key, where n is a natural number greater than 0.
[0014] As a preferred implementation of the first aspect, encrypting the encrypted quantum key using the first random number and a prefabricated quantum key includes:
[0015] Based on the HMAC algorithm, use the first k bytes of the first random number as the key, obtain the message digest of the first k bytes of the prefabricated quantum key to get the first message digest, where k is a natural number greater than 0 and k is less than n.
[0016] Based on the first message digest, encrypt the first k bytes of the encrypted quantum key.
[0017] Based on the HMAC algorithm, use the first k bytes of the first random number as the key, obtain the message digest of the second k bytes of the prefabricated quantum key to get the second message digest.
[0018] Based on the second message digest, encrypt the second k bytes of the encrypted quantum key.
[0019] Repeat the above steps until the prefabricated quantum key is used up.
[0020] As a preferred implementation of the first aspect, after the prefabricated quantum key is used up, the method further includes:
[0021] Based on the SM3 algorithm, obtain the message digest of the first random number;
[0022] Use the message digest as the second random number;
[0023] Based on the second random number and the prefabricated quantum key, use the same method as the above quantum key encryption method to encrypt the encrypted quantum key until the encryption of the encrypted quantum key is completed.
[0024] In a second aspect, the quantum key decryption method provided by the embodiments of the present invention includes the following steps:
[0025] Receive the encrypted encrypted quantum key sent by the cloud server and store the encrypted encrypted quantum key.
[0026] When sending data, decrypt the encrypted encrypted quantum key based on the first random number and the prefabricated quantum key.
[0027] As a preferred implementation of the second aspect, decrypting the encrypted encrypted quantum key based on the first random number and the prefabricated quantum key includes:
[0028] Based on the HMAC algorithm, use the first k bytes of the first random number as the key, obtain the message digest of the first k bytes of the prefabricated quantum key to get the third message digest, where k is a natural number greater than 0.
[0029] Based on the third message digest, decrypt the first k bytes of the encrypted encrypted quantum key to obtain the first encrypted quantum key.
[0030] Based on the HMAC algorithm, use the first k bytes of the first random number as the key, obtain the message digest of the second k bytes of the prefabricated quantum key to get the fourth message digest.
[0031] Based on the fourth message digest, decrypt the second k bytes of the encrypted encrypted quantum key to obtain the second encrypted quantum key.
[0032] And so on until the prefabricated quantum key is used up.
[0033] As a preferred implementation of the second aspect, after the prefabricated quantum key is used up, the method further includes:
[0034] Based on the SM3 algorithm, obtain the message digest of the first random number.
[0035] Use the message digest as the third random number.
[0036] Based on the third random number and the prefabricated quantum key, use the same method as the above-mentioned quantum key decryption method to decrypt the encrypted encrypted quantum key until the decryption of the encrypted quantum key is completed.
[0037] As a preferred implementation manner of the second aspect, after obtaining the first encrypted quantum key, the method further includes:
[0038] Use the first encrypted quantum key to encrypt the first k bytes of the data to be sent this time. After the encryption is completed, destroy the first encrypted quantum key.
[0039] As a preferred implementation manner of the second aspect, after obtaining the second encrypted quantum key, the method further includes:
[0040] Use the second encrypted quantum key to encrypt the second k bytes of the data to be sent this time. After the encryption is completed, destroy the second encrypted quantum key;
[0041] And so on until the data to be sent this time is encrypted.
[0042] As a preferred implementation manner of the second aspect, after the data to be sent this time is encrypted, the method further includes:
[0043] Send the pre-stored session identifier, the first encrypted quantum key identifier, and the encrypted data to be sent to the second user device.
[0044] In a third aspect, the quantum key encryption system provided by an embodiment of the present invention includes:
[0045] A first receiving module, configured to receive a session creation request initiated by a first user device.
[0046] A creation module, configured to determine whether there is an available session currently. If not, create a session.
[0047] A sending module, configured to generate a session identifier of the session, send the session identifier to the first user device, and send a quantum random number acquisition request to a quantum random number generator, and receive the quantum random number of a set byte size generated and sent by the quantum random number generator.
[0048] A determination module, configured to determine an encrypted quantum key based on the quantum random number of the set byte size.
[0049] The first receiving module is further configured to receive a quantum key acquisition request sent by the first user device, where the quantum key acquisition request carries a first random number, a user ID, and the session identifier.
[0050] An encryption module, configured to encrypt the encrypted quantum key by using the first random number and a prefabricated quantum key.
[0051] In a fourth aspect, a quantum key decryption system provided by an embodiment of the present invention includes:
[0052] A second receiving module, configured to receive the encrypted encrypted quantum key sent by the cloud server;
[0053] A decryption module, configured to decrypt the encrypted encrypted quantum key based on a first random number and a prefabricated quantum key.
[0054] In a fifth aspect, an embodiment of the present invention provides a computer-readable storage medium, where the storage medium stores a computer program, and the computer program is used to execute the method described in the first or second aspect above.
[0055] In a sixth aspect, an embodiment of the present invention provides an electronic device, where the electronic device includes:
[0056] A processor;
[0057] A memory for storing executable instructions of the processor;
[0058] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in the first or second aspect above.
[0059] The quantum key encryption, decryption method and system provided by the embodiments of the present invention have the following beneficial effects:
[0060] (1) Encrypting the encrypted quantum key based on a random number and a prefabricated quantum key ensures the security of the transmission and storage of the prefabricated quantum key;
[0061] (2) Using multiple encryption keys to encrypt the data to be transmitted multiple times ensures the security of data transmission;
[0062] (3) Applicable to various types of user devices, with strong applicability. Description of the Drawings
[0063] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0064] Figure 1 It is a schematic diagram of a communication scenario between user devices;
[0065] Figure 2 Schematic flow diagram of the quantum key encryption method provided by the embodiment of the present invention;
[0066] Figure 3 Schematic flow diagram of the quantum key decryption method provided by the embodiment of the present invention;
[0067] Figure 4 Schematic structural diagram of the quantum key encryption system provided by the embodiment of the present invention;
[0068] Figure 5 Schematic structural diagram of the quantum key decryption system provided by the embodiment of the present invention;
[0069] Figure 6 Schematic structural diagram of the electronic device provided by the embodiment of the present invention. Detailed implementation manners
[0070] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0071] As Figure 1 shown, the communication system for realizing communication between user devices consists of a quantum random number generator, a cloud server, an authentication system, user device A, and user device B. Among them, user device A sends a first login request to the authentication system, and user device B sends a second login request to the authentication system. The authentication system and the cloud server jointly verify the first login request and the second login request. Only when both the first login request and the second login request are verified successfully can communication be achieved between user device A and user device B.
[0072] The solutions involved in the quantum key encryption, decryption methods and systems provided by the embodiments of the present invention will be described in detail below.
[0073] Embodiment 1
[0074] As Figure 2 shown, the embodiment of the present invention provides a quantum key encryption method, which is applied to a cloud server and includes the following steps:
[0075] S101, receiving a session creation request initiated by a first user device.
[0076] Specifically, the session creation request carries a first user ID, a first user device ID, and a second user ID.
[0077] S102, Determine whether there is an available session currently. If not, create a session.
[0078] Specifically, the cloud service determines whether there is currently a session between the first user device and the second user device corresponding to the second user according to the first user device ID and the second user ID.
[0079] After the cloud server creates a session, the session is bound to the first user ID, the first user device ID associated with the first user ID, the second user ID, and the second user device ID associated with the second user ID respectively, so that the session is only used for communication between the first user device and the second user device.
[0080] S103, Generate a session identifier for the session, send the session identifier to the first user device and send a quantum random number acquisition request to the quantum random number generator, and receive the quantum random number of the set byte size generated and sent by the quantum random number generator.
[0081] Specifically, the quantum random number of the set byte size is a quantum random number of 512K.
[0082] S104, Determine an encrypted quantum key based on the quantum random number of the set byte size.
[0083] As an implementable implementation, take the first n bytes of the quantum random number as the encrypted quantum key, where n is a natural number greater than 0.
[0084] Specifically, the first 16 bytes of the quantum random number are used as the encrypted quantum key.
[0085] S105, Receive the quantum key acquisition request sent by the first user device, where the quantum key acquisition request carries the first random number, the user ID, and the session identifier.
[0086] Specifically, the first random number is a random number with a byte size of 32 generated by the first user device before the first user device obtains the encrypted quantum key from the cloud server.
[0087] S106, Encrypt the encrypted quantum key using the first random number and the prefabricated quantum key.
[0088] Specifically, the prefabricated quantum key is the quantum key obtained after the cloud server sends a prefabricated quantum key request to the quantum random number generator after the first user device sends a registration request to the cloud server and the verification is successful, and the byte size is 32K.
[0089] In an implementable embodiment, step S106 includes:
[0090] S1061: Based on the HMAC algorithm, using the first k bytes of the first random number as the key, obtain the message digest of the first k bytes of the prefabricated quantum key to get the first message digest, where k is a natural number greater than 0 and less than n.
[0091] Specifically, adopt the SM3_HMAC algorithm, use the first 16 bytes of the first random number as the key, and obtain the message digest of the first 16 bytes of the prefabricated quantum key.
[0092] S1062: Based on the first message digest, encrypt the first k bytes of the encrypted quantum key.
[0093] Specifically, adopt the SM4 algorithm, use the first message digest as the key, and encrypt the first 16 bytes of the encrypted quantum key.
[0094] S1063: Based on the HMAC algorithm, using the first k bytes of the first random number as the key, obtain the message digest of the second k bytes of the prefabricated quantum key to get the second message digest.
[0095] Specifically, adopt the SM3_HMAC algorithm, use the first 16 bytes of the first random number as the key, and obtain the message digest of the second 16 bytes of the prefabricated quantum key.
[0096] S1064: Based on the second message digest, encrypt the second k bytes of the encrypted quantum key.
[0097] Specifically, adopt the SM4 algorithm, use the second message digest as the key, and encrypt the second 16 bytes of the encrypted quantum key.
[0098] S1065: Repeat the above steps until the prefabricated quantum key is used up.
[0099] Particularly, when the prefabricated quantum key is less than 16 bytes, fill 0s after the prefabricated quantum key to make up 16 bytes.
[0100] In an implementable embodiment, after step S1065, the quantum key encryption method provided by the embodiment of the present invention further includes:
[0101] Based on the SM3 algorithm, obtain the message digest of the first random number.
[0102] Specifically, the byte size of the message digest is 32.
[0103] Use the message digest as the second random number.
[0104] Based on the second random number and the prefabricated quantum key, use the same method as in steps S1061 - S1065 to encrypt the encrypted quantum key until the encryption of the encrypted quantum key is completed.
[0105] Specifically, when the number of unencrypted encrypted quantum keys in the encrypted quantum key is less than 16 bytes, fill in 0 after the unencrypted encrypted quantum key to make up 16 bytes.
[0106] Embodiment 2
[0107] As Figure 3 shown, an embodiment of the present invention provides a quantum key decryption method applied to a first user device, including the following steps:
[0108] S201, receive the encrypted encrypted quantum key sent by the cloud server and store the encrypted encrypted quantum key.
[0109] S202, when sending data, decrypt the encrypted encrypted quantum key based on the first random number and the prefabricated quantum key.
[0110] Specifically, decrypt the encrypted encrypted quantum key only when the first user device needs to send data.
[0111] In an implementable embodiment, step S202 includes:
[0112] S2021, based on the HMAC algorithm, use the first k bytes of the first random number as the key, obtain the message digest of the first k bytes of the prefabricated quantum key to get the third message digest, where k is a natural number greater than 0.
[0113] Specifically, use the SM3_HMAC algorithm, use the first 16 bytes of the first random number as the key, and obtain the message digest of the first 16 bytes of the prefabricated quantum key.
[0114] S2022, based on the third message digest, decrypt the first k bytes of the encrypted encrypted quantum key to obtain the first encrypted quantum key.
[0115] Specifically, use the SM4 algorithm, use the third message digest as the key, and decrypt the first 16 bytes of the encrypted encrypted quantum key.
[0116] S2023, based on the HMAC algorithm, use the first k bytes of the first random number as the key, obtain the message digest of the second k bytes of the prefabricated quantum key to get the fourth message digest.
[0117] Specifically, the SM3_HMAC algorithm is adopted, and the first 16 bytes of the first random number are used as the key to obtain the message digest of the first 16 bytes of the prefabricated quantum key.
[0118] S2024, based on the fourth message digest, decrypt the first k bytes of the second encrypted quantum key after encryption to obtain the second encrypted quantum key.
[0119] Specifically, the SM4 algorithm is adopted, and the fourth message digest is used as the key to decrypt the first 16 bytes of the second encrypted quantum key after encryption.
[0120] S2025, and so on until the prefabricated quantum key is used up.
[0121] In an implementable embodiment, after step S2025, the quantum key decryption method provided by the embodiment of the present invention further includes:
[0122] Based on the SM3 algorithm, obtain the message digest of the first random number.
[0123] Specifically, the byte size of the message digest is 32.
[0124] Use the message digest as the third random number.
[0125] Based on the third random number and the prefabricated quantum key, use the same method as S2021 - S2025 to decrypt the encrypted quantum key after encryption until the encrypted quantum key is decrypted completely.
[0126] In an implementable embodiment, after obtaining the first encrypted quantum key, the quantum key decryption method provided by the embodiment of the present invention further includes:
[0127] Use the first encrypted quantum key to encrypt the first k bytes of the data to be sent this time. After encryption, destroy the first encrypted quantum key.
[0128] Specifically, use the first encrypted quantum key as the key and adopt the SM4 algorithm to encrypt the first 16 bytes of the data to be sent this time.
[0129] In an implementable embodiment, after obtaining the second encrypted quantum key, the quantum key decryption method provided by the embodiment of the present invention further includes:
[0130] Use the second encrypted quantum key to encrypt the first k bytes of the data to be sent this time. After encryption, destroy the second encrypted quantum key.
[0131] Specifically, using the second encrypted quantum key as the key, the SM4 algorithm is employed to encrypt the first 16 bytes of the second part of the data to be sent this time.
[0132] And so on until the encryption of the data to be sent this time is completed.
[0133] Particularly, when the unencrypted data in the data to be sent this time is less than 16 bytes, 0s are appended after the unencrypted data to make up 16 bytes.
[0134] In an implementable embodiment, after the encryption of the data to be sent this time is completed, the quantum key decryption method provided by the embodiments of the present invention further includes:
[0135] Sending the pre - saved session identifier, the first encrypted quantum key identifier, and the encrypted data to be sent to the second user device.
[0136] Specifically, the first encrypted quantum key identifier indicates which bytes to which bytes in the quantum random number of the set byte size are the first encrypted key. The first user device requests the decryption quantum key for decrypting the received data from the cloud server according to the session identifier, where the encryption key used by the first user device is the decryption key used by the second user device.
[0137] Particularly, when the second user device sends data to the first user device, the data to be sent can be encrypted using the same method as in Embodiment 1. Similarly, when the first user device receives data sent by the second user device, the received data can be decrypted using the same method as in Embodiment 2.
[0138] Embodiment 3
[0139] As Figure 4 shown, the quantum key encryption system provided by the embodiments of the present invention includes:
[0140] A first receiving module, configured to receive a session creation request initiated by the first user device.
[0141] A creation module, configured to determine whether there is an available session currently. If not, a session is created.
[0142] A sending module, configured to generate the session identifier of the session, send the session identifier to the first user device, and send a quantum random number acquisition request to the quantum random number generator, and receive the quantum random number of the set byte size generated and sent by the quantum random number generator.
[0143] A determination module, configured to determine the encrypted quantum key based on the quantum random number of the set byte size.
[0144] The first receiving module is further configured to receive a quantum key acquisition request sent by a first user device, where the quantum key acquisition request carries a first random number, a user ID, and the session identifier.
[0145] The encryption module is configured to encrypt the encrypted quantum key by using the first random number and a prefabricated quantum key.
[0146] Embodiment 4
[0147] As Figure 5 shown, the quantum key decryption system provided by an embodiment of the present invention includes:
[0148] The second receiving module is configured to receive the encrypted encrypted quantum key sent by the cloud server;
[0149] The decryption module is configured to decrypt the encrypted encrypted quantum key based on the first random number and a prefabricated quantum key.
[0150] Embodiment 5
[0151] Figure 6 is the structure of an electronic device provided by an exemplary embodiment of the present invention. As Figure 6 shown, the electronic device can be any one or both of the first device and the second device, or a stand-alone device independent of them, and the stand-alone device can communicate with the first device and the second device to receive the input signals collected from them. Figure 6 The block diagram of an electronic device according to an exemplary embodiment of the present invention is illustrated. As Figure 6 shown, the electronic device includes one or more processors 401 and a memory 402.
[0152] The processor 401 can be a central processing unit (CPU) or other forms of processing units with penetration data processing capabilities and / or instruction execution capabilities, and can control other components in the electronic device to perform desired functions.
[0153] The memory 402 may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage media, and the processor 401 may run the program instructions to implement the method for information mining of historical change records in the software programs of the various disclosed embodiments described above and / or other desired functions. In one example, the electronic device may further include: an input device 403 and an output device 404, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).
[0154] In addition, the input device 403 may further include, for example, a keyboard, a mouse, and so on.
[0155] The output device 404 may output various information to the outside. The output device 404 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, and so on.
[0156] Of course, for simplicity, Figure 6 only some of the components related to the disclosure of the present invention in the electronic device are shown, and components such as buses, input / output interfaces, and so on are omitted. In addition, according to specific application scenarios, the electronic device may further include any other appropriate components.
[0157] Embodiment 6
[0158] In addition to the above methods and devices, an embodiment of the present invention disclosure may also be a computer program product, which includes computer program instructions, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the method for penetration data annotation, encapsulation, and acquisition according to various embodiments of the present invention disclosure described in the "Exemplary Method" section above in this specification.
[0159] The computer program product may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present invention disclosure. The programming languages include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0160] In addition, an embodiment disclosed by the present invention may also be a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the methods for annotating, encapsulating, and obtaining penetration data according to various embodiments disclosed by the present invention described in the above "Exemplary Method" section of this specification.
[0161] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0162] The basic principles disclosed by the present invention have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, advantages, effects, etc. mentioned in the disclosure of the present invention are only examples and not limitations, and it cannot be considered that these advantages, advantages, effects, etc. are essential for each embodiment of the present invention. In addition, the above-disclosed specific details are only for the purposes of illustration and facilitating understanding, rather than limitations. The above details do not limit the present invention to necessarily adopt the above specific details for implementation.
[0163] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and reference can be made to the partial description of the method embodiment for the relevant parts.
[0164] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present disclosure are merely illustrative examples and are not intended to require or imply that the connection, arrangement, and configuration must be in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any way. Words such as "comprising," "including," "having," etc. are open-ended terms, meaning "including but not limited to," and can be used interchangeably with each other. The words "or" and "and" used herein refer to the phrase "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0165] The methods and apparatuses disclosed in the present disclosure can be implemented in many ways. For example, the methods and apparatuses disclosed in the present disclosure can be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of the steps for the method is only for illustration, and the steps of the methods disclosed in the present disclosure are not limited to the specific order described above, unless otherwise specifically stated. In addition, in some embodiments, the present disclosure can also be implemented as a program recorded on a recording medium, and these programs include machine-readable instructions for implementing the methods according to the present disclosure. Therefore, the present disclosure also covers a recording medium storing a program for executing the methods according to the present disclosure.
[0166] It should also be noted that in the apparatuses, equipment, and methods disclosed in the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but to the broadest scope consistent with the principles and novel features disclosed herein.
[0167] The above description has been given for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, adaptations, additions, and sub-combinations thereof.
[0168] It can be understood that the relevant features in the above methods and apparatuses can be referred to each other. In addition, the "first," "second," etc. in the above embodiments are used to distinguish each embodiment, and do not represent the advantages or disadvantages of each embodiment.
[0169] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
[0170] It should be noted that the above embodiments do not limit the present invention in any form. Any technical solutions obtained by means of equivalent replacement or equivalent transformation fall within the protection scope of the present invention.
[0171] It can be understood that the relevant features in the above methods and devices can be referred to each other. In addition, the "first", "second", etc. in the above embodiments are used to distinguish each embodiment and do not represent the superiority or inferiority of each embodiment.
[0172] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
[0173] It should be noted that the above embodiments do not limit the present invention in any form. Any technical solutions obtained by means of equivalent replacement or equivalent transformation fall within the protection scope of the present invention.
Claims
1. A quantum key encryption method, characterized in that, It includes: Receiving a session creation request initiated by a first user device; Judging whether there is an available session currently. If not, creating a session; Generating a session identifier for the session, sending the session identifier to the first user device and sending a quantum random number acquisition request to a quantum random number generator, and receiving a quantum random number of a set byte size generated and sent by the quantum random number generator; Determining an encrypted quantum key based on the quantum random number of the set byte size; Receiving a quantum key acquisition request sent by the first user device, where the quantum key acquisition request carries a first random number, a user ID, and the session identifier; Encrypting the encrypted quantum key by using the first random number and a prefabricated quantum key; After the prefabricated quantum key is used up, obtaining a message digest of the first random number based on the SM3 algorithm; Taking the message digest as a second random number; Encrypting the encrypted quantum key based on the second random number and the prefabricated quantum key until the encrypted quantum key is encrypted completely.
2. The quantum key encryption method according to claim 1, wherein Determining an encrypted quantum key based on the quantum random number of the set byte size includes: Taking the first n bytes of the quantum random number as the encrypted quantum key, where n is a natural number greater than 0.
3. The quantum key encryption method according to claim 1, characterized in that Encrypting the encrypted quantum key by using the first random number and a prefabricated quantum key includes: Based on the HMAC algorithm, taking the first k bytes of the first random number as a key, obtaining a message digest of the first k bytes of the prefabricated quantum key to get a first message digest, where k is a natural number greater than 0 and k is less than n; Encrypting the first k bytes of the encrypted quantum key based on the first message digest; Based on the HMAC algorithm, taking the first k bytes of the first random number as a key, obtaining a message digest of the second k bytes of the prefabricated quantum key to get a second message digest; Encrypting the second k bytes of the encrypted quantum key based on the second message digest; Repeating the above steps until the prefabricated quantum key is used up.
4. The quantum key encryption method according to claim 3, wherein Based on the second random number and the prefabricated quantum key, using the same method as in claim 3 to encrypt the encrypted quantum key until the encrypted quantum key is encrypted completely.
5. A quantum key decryption method, characterized in that, It includes: Receiving the encrypted encrypted quantum key sent by a cloud server and storing the encrypted encrypted quantum key; When sending data, decrypting the encrypted encrypted quantum key based on a first random number and a prefabricated quantum key; After the prefabricated quantum key is used up, obtaining a message digest of the first random number based on the SM3 algorithm; Taking the message digest as a third random number; Decrypting the encrypted encrypted quantum key based on the third random number and the prefabricated quantum key until the encrypted quantum key is decrypted completely.
6. The quantum key decryption method according to claim 5, characterized in that, Decrypting the encrypted encrypted quantum key based on a first random number and a prefabricated quantum key includes: Based on the HMAC algorithm, use the first k bytes of the first random number as the key to obtain the message digest of the first k bytes of the prefabricated quantum key, and obtain the third message digest, where k is a natural number greater than 0; Based on the third message digest, decrypt the first k bytes of the encrypted encrypted quantum key to obtain the first encrypted quantum key; Based on the HMAC algorithm, use the first k bytes of the first random number as the key to obtain the message digest of the second k bytes of the prefabricated quantum key, and obtain the fourth message digest; Based on the fourth message digest, decrypt the second k bytes of the encrypted encrypted quantum key to obtain the second encrypted quantum key; And so on until the prefabricated quantum key is used up.
7. The quantum key decryption method according to claim 6, wherein Based on the third random number and the prefabricated quantum key, use the same method as in claim 6 to decrypt the encrypted encrypted quantum key until the decryption of the encrypted quantum key is completed.
8. The quantum key decryption method according to claim 6, wherein After obtaining the first encrypted quantum key, the method further includes: Use the first encrypted quantum key to encrypt the first k bytes of the data to be sent this time. After the encryption is completed, destroy the first encrypted quantum key.
9. The quantum key decryption method according to claim 6, characterized in that, After obtaining the second encrypted quantum key, the method further includes: Use the second encrypted quantum key to encrypt the second k bytes of the data to be sent this time. After the encryption is completed, destroy the second encrypted quantum key; And so on until the data to be sent this time is encrypted.
10. The quantum key decryption method according to claim 9, characterized in that, After the data to be sent this time is encrypted, the method further includes: Send the pre-stored session identifier, the first encrypted quantum key identifier, and the encrypted data to be sent to the second user device.
11. A quantum key encryption system, characterized in that, Includes: A first receiving module, configured to receive a session creation request initiated by a first user device; A creation module, configured to determine whether there is an available session currently. If not, create a session; A sending module, configured to generate a session identifier for the session, send the session identifier to the first user device, and send a quantum random number acquisition request to a quantum random number generator, and receive the quantum random number of a set byte size generated and sent by the quantum random number generator; A determination module, configured to determine an encrypted quantum key based on the quantum random number of the set byte size; The first receiving module is further configured to receive a quantum key acquisition request sent by the first user device, where the quantum key acquisition request carries a first random number, a user ID, and the session identifier; A first encryption module, configured to encrypt the encrypted quantum key using the first random number and the prefabricated quantum key, An acquisition module, configured to obtain the message digest of the first random number based on the SM3 algorithm after the prefabricated quantum key is used up; A random number generation module, configured to use the message digest as a second random number; A second encryption module, configured to encrypt the encrypted quantum key based on the second random number and the prefabricated quantum key until the encryption of the encrypted quantum key is completed.
12. A quantum key decryption system, characterized in that, Comprising: A second receiving module, configured to receive the encrypted encrypted quantum key sent by the cloud server; A first decryption module, configured to decrypt the encrypted encrypted quantum key based on a first random number and a prefabricated quantum key, An obtaining module, configured to obtain a message digest of the first random number based on the SM3 algorithm after the prefabricated quantum key is used up; A random number generation module, configured to use the message digest as a third random number; A second decryption module, configured to decrypt the encrypted encrypted quantum key based on the third random number and the prefabricated quantum key until the decryption of the encrypted quantum key is completed.
Citation Information
Patent Citations
File encryption method and device based on quantum key, electronic equipment and medium
CN114448633A
Data transmission method and system based on quantum key and storage medium
CN114844639A
Mobile communication authentication method and system based on quantum key, terminal and storage medium
CN109787763A