Method and system for realizing transparent encryption and decryption of multicast data by using quantum key distribution

By using quantum key distribution technology and stream table management module in the encryption gateway, transparent encryption and decryption is realized based on multicast IP addresses, solving the problem of transparent encryption and decryption of multicast data in the prior art, and realizing controllable and efficient network communication of multicast encryption communication keys.

CN115567192BActive Publication Date: 2025-07-01CHINA TELECOM QUANTUM TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211198406.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-29
Publication Date
2025-07-01
Estimated Expiration
2042-09-29

AI Technical Summary

Technical Problem

The prior art is difficult to realize transparent encryption and decryption of multicast data packets, resulting in waste of network bandwidth and increased data processing complexity, and lack of effective control over multicast group members.

Method used

Using quantum key distribution technology, by setting up a master key pool and flow table management module in the encryption gateway, matching flow table entries based on the multicast IP address, transparent encryption and decryption is achieved, and multicast session keys are centrally distributed online through the management and control platform.

Benefits of technology

It realizes the controllable and controllable multicast encryption communication keys, reduces network bandwidth waste and data processing complexity through transparent encryption and decryption, and has good network adaptability and high security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567192B_ABST
    Figure CN115567192B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for implementing transparent encryption and decryption of multicast data by using quantum key distribution, including receiving an outbound multicast data packet from a network interface connected to the internal network, and matching a flow entry according to the multicast IP address of the multicast data packet; if the matching is successful, performing transparent encryption processing with a fixed length on the multicast data packet by using the matched flow entry to obtain an outbound encrypted packet; if the matching is unsuccessful, generating a session key request message based on the multicast IP address of the multicast data packet and the corresponding master key, and sending the message to a management and control platform, so that the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table, and generates a session key distribution message; receiving the session key distribution message, creating a new flow entry, and performing transparent encryption processing on the multicast data packet based on the new flow entry to obtain an outbound encrypted packet; sending the outbound encrypted packet from a network interface connected to the external network to a receiving party for transparent decryption processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cryptographic applications, and in particular to a method and system for transparently encrypting and decrypting multicast data by using quantum key distribution. Background Art

[0002] Currently, for the data encryption problem in the network transmission process between multicast nodes of multicast services such as audio and video, due to the high complexity of key distribution, there are few successfully applied cases. In many cases, it is often transformed into the encryption problem of multiple unicast data streams. Moreover, due to the inability to achieve transparent encryption and decryption, relevant packet headers are added, resulting in a large waste of network bandwidth and an increase in data processing complexity, and the control over multicast group members is also relatively weak. The commonly used IGMP protocol itself lacks an authentication control mechanism.

[0003] In related technologies, the Chinese patent literature with publication number CN112653551A records a method for hierarchical structure multicast quantum key distribution. The method includes: a process of initializing the sender and receiver of the multicast group for necessary preliminary connection. Key generation, the first key is the group key, generated by the QMKDC for encrypting the communication between the QMKDC and the multicast group, and the second key is the shared symmetric key, used for encryption / decryption communication within the multicast group members and can also be shared among all members in the multicast group. Group key distribution, generated by randomly selecting a bit string and encrypting it with the private key of each multicast group. Each multicast group will retrieve the group key by decrypting the received message. Encrypt the message with the group shared key, and the receiver decrypts it with the same key to achieve communication with the multicast group members.

[0004] The group key used for encrypted communication in this solution adopts an asymmetric system of public key encryption / private key decryption. The private key is shared within the group and transmitted through a quantum private link to protect the long-term use of the public and private keys of the group key.

[0005] The Chinese patent literature with publication number CN106161015A records a DPI-based quantum key distribution method. The DPI analysis module of the system performs application layer analysis on network data streams, identifies the service types of various applications and submits them to the encryption policy selection module; the encryption policy selection module performs quantum key encryption or traditional key encryption or selects transparent transmission according to the priority for services with different security levels; the network transparent transmission or traditional key encryption module performs transparent transmission without encryption or encryption based on an algorithm-secure traditional encryption algorithm; the quantum key encryption module performs quantum encryption transmission. This method realizes the differentiation and identification of network core service traffic, performs hierarchical encryption on different service traffic, selects quantum key distribution encryption or traditional encryption methods according to the encryption policy, realizes quantum secure communication of network core service traffic, and takes into account the transmission efficiency of network services.

[0006] This solution uses quantum encryption and traditional encryption methods for different applications respectively. The quantum encryption method mainly obtains the session key through a quantum link. Summary of the Invention

[0007] The technical problem to be solved by the present invention is how to achieve transparent encryption and decryption of multicast data packets.

[0008] The present invention solves the above technical problems through the following technical means:

[0009] The present invention proposes a method for implementing transparent encryption and decryption of multicast data using quantum key distribution. The method is applied to an encryption gateway. At least one master key pool is set in the encryption gateway. The master key corresponding to the same multicast group is stored in each master key pool. The multicast IP address of each multicast group corresponds to a security domain, including the following steps:

[0010] Receive an outbound multicast data packet from the network interface connected to the internal network, and match the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key;

[0011] If the match is successful, perform transparent encryption processing of a fixed length on the multicast data packet using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet;

[0012] If the match is unsuccessful, generate a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address;

[0013] Send the session key request message to the management and control platform, so that the management and control platform reads the security attribute information corresponding to the multicast data packet from the pre-configured security policy table and generates a session key distribution message;

[0014] Receive the session key distribution message, create a new flow table entry, and perform transparent encryption processing on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet;

[0015] Send the outbound encrypted packet from the network interface connected to the external network to the receiving party, so that the receiving party performs transparent decryption processing on the outbound encrypted packet.

[0016] The present invention establishes independent security domains and master key pools for different multicast groups, creates a flow table based on the destination IP, i.e., the multicast IP address, adopts a method of centrally and online distributing multicast session keys, and combines it with fine-grained security policies to implement a software-defined quantum key distribution method, realizing the management and control of multicast encrypted communication keys; the multicast data packets are transparently encrypted and decrypted by matching the flow table entries, that is, without adding any extra data and business data traffic, without adding new packet headers, and having good network adaptability.

[0017] Further, if the matching fails, a session key request message is generated based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address, including:

[0018] If the matching fails, cache the multicast data packet and extract the multicast IP address from the multicast data packet;

[0019] Randomly select a master key ID from the master key pool corresponding to the multicast IP address;

[0020] Generate the session key request message based on the master key ID, the multicast IP address, and the security domain ID corresponding to the multicast IP address.

[0021] Further, the method further includes:

[0022] Select the corresponding master key based on the master key ID;

[0023] Use the master key to encrypt the address information in the session key request message to obtain an encrypted message;

[0024] Perform an HMAC operation on the encrypted message to obtain the encrypted and verified session key request information and send it to the management and control platform.

[0025] Further, the method further includes:

[0026] If there is no master key pool corresponding to the multicast IP address, discard the multicast data packet.

[0027] Further, the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message, including:

[0028] According to the security domain ID and the master key ID, obtain the corresponding master key from the quantum key distribution network to decrypt and verify the encrypted and verified session key request information;

[0029] After successful decryption and verification, obtain a session key from the quantum key distribution network based on the multicast IP address and the security domain ID identifier;

[0030] Read the security attribute information corresponding to the multicast data packet from the pre-configured security policy table, where the security attribute information includes an offset and an encryption mode;

[0031] Generate the session key distribution message based on the session key, the multicast IP address, the security attribute information, the security domain ID identifier, and a randomly selected master key ID identifier within the security domain.

[0032] Further, the method further includes:

[0033] The control platform retrieves a master key from the corresponding master key pool in the quantum key distribution network, and uses the master key to encrypt the session key, the security attribute information, and the multicast IP address in the session key distribution message to obtain an encrypted session key distribution message;

[0034] Perform an HMAC operation on the encrypted session key distribution message to obtain an encrypted and verified session key distribution message.

[0035] Further, receiving the session key distribution message and creating a flow table entry includes:

[0036] Match the multicast IP address and the security domain ID identifier;

[0037] After successful matching, create a flow table entry based on the multicast IP address, the security attribute information, and the session key.

[0038] Further, the method further includes:

[0039] Retrieve a master key from the master key pool corresponding to the security domain ID identifier, and use the master key to decrypt and verify the encrypted and verified session key distribution message to obtain the session key distribution message.

[0040] Further, the method further includes:

[0041] Send a registration request to the control platform to register multiple security domains, where each security domain corresponds to a multicast address;

[0042] Send a key injection request to the quantum key distribution network to obtain master keys corresponding to different security domains, and establish multiple master key pools, where each master key pool stores the master keys corresponding to the same security domain.

[0043] Further, the method further includes:

[0044] Establish a timeout for each entry in the flow table entry;

[0045] When not accessed near the timeout, send a session key update request to the control platform.

[0046] In addition, the present invention also proposes a multicast data transparent encryption and decryption gateway implemented by quantum key distribution. The gateway includes a data encryption and decryption processing module, a flow table management module, a key update module, a key injection module, and at least one master key pool. The input end of the key injection module is connected to at least one secure storage medium, and the output end is connected to the master key pool. The output end of the key update module is connected to the master key pool. Each master key pool stores the master key corresponding to the same multicast group, and the multicast IP address of each multicast group corresponds to a security domain;

[0047] The data encryption and decryption processing module is used to receive the outbound multicast data packet from the network interface connected to the internal network;

[0048] The flow table management module is used to match the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key;

[0049] The data encryption and decryption processing module is used to, when the matching is successful, perform a fixed-length transparent encryption process on the multicast data packet using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet;

[0050] The key update module is used to, when the matching is unsuccessful, generate a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address; and send the session key request message to the control platform, so that the control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message;

[0051] The flow table management module is used to receive the session key distribution message, create a new flow table entry, and perform a transparent encryption process on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet;

[0052] The data encryption and decryption processing module is used to send the outbound encrypted packet from the network interface connected to the external network to the receiving party, so that the receiving party performs a transparent decryption process on the outbound encrypted packet.

[0053] In addition, the present invention also provides a multicast data transparent encryption and decryption system implemented by quantum key distribution. The system includes a first encryption gateway, a second encryption gateway, a management and control platform, and a quantum key distribution network. The first encryption gateway, the second encryption gateway, and the quantum key distribution network are all connected to the management and control platform. The first encryption gateway and the second encryption gateway are both connected to the quantum key distribution network. Among them, the first encryption gateway and the second encryption gateway both include a data encryption and decryption processing module, a flow table management module, a key update module, a key injection module, and at least one master key pool. The input end of the key injection module is connected to at least one secure storage medium, and the output end is connected to the master key pool. The output end of the key update module is connected to the master key pool. Each master key pool stores the master key corresponding to the same multicast group, and the multicast IP address of each multicast group corresponds to a security domain;

[0054] The management and control platform is used for security domain division, registration and identity binding services of the first encryption gateway and the second encryption gateway, and distributing session keys and security policies to the first encryption gateway and the second encryption gateway;

[0055] The quantum key distribution network is used for pre-injecting the master key into the secure storage medium;

[0056] The data encryption and decryption processing module is used for receiving the outbound multicast data packet from the network interface connected to the internal network;

[0057] The flow table management module is used for matching the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key;

[0058] The data encryption and decryption processing module is used for, when the matching is successful, performing transparent encryption processing with a fixed length on the multicast data packet by using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet;

[0059] The key update module is used for, when the matching is unsuccessful, generating a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address; and sending the session key request message to the management and control platform, so that the management and control platform reads the security attribute information corresponding to the multicast data packet from the pre-configured security policy table and generates a session key distribution message;

[0060] The flow table management module is used for receiving the session key distribution message, creating a new flow table entry, and performing transparent encryption processing on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet;

[0061] The data encryption and decryption processing module is used to send the outbound encrypted message to the receiving party from the network interface connected to the external network, so that the receiving party can perform transparent decryption processing on the outbound encrypted message.

[0062] The advantages of the present invention are as follows:

[0063] (1) The present invention establishes independent security domains and master key pools for different multicast groups, establishes a flow table based on the destination IP, that is, the multicast IP address, adopts the method of centralized online distribution of multicast session keys, and combines with fine-grained security policies to implement the software-defined quantum key distribution method, realizing the controllability and manageability of the multicast encryption communication key; the multicast data message is transparently encrypted and decrypted by matching the flow table entries, that is, no additional data and service data traffic are added, no new message headers are added, and it has good network adaptability.

[0064] (2) The control platform establishes a security policy composed of elements such as multicast IP address and offset, encryption algorithm, session key, etc., and updates the multicast session key globally (multicast group) under the protection of the master key with one-time pad, realizing software-defined multicast transparent encryption communication, which has high security and flexibility, and realizes centralized control.

[0065] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. Description of the Drawings

[0066] Figure 1 is a schematic flowchart of a method for realizing transparent encryption and decryption of multicast data by using quantum key distribution in the first embodiment of the present invention;

[0067] Figure 2 is a schematic structural diagram of a gateway for realizing transparent encryption and decryption of multicast data by using quantum key distribution in the second embodiment of the present invention;

[0068] Figure 3 is a schematic structural diagram of a system for realizing transparent encryption and decryption of multicast data by using quantum key distribution in the third embodiment of the present invention;

[0069] Figure 4 is a schematic flowchart of a system for realizing transparent encryption and decryption of multicast data by using quantum key distribution in the present invention. Detailed Embodiments

[0070] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Apparently, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0071] Embodiment 1

[0072] The present invention proposes a method for implementing transparent encryption and decryption of multicast data using quantum key distribution. The method is applied to an encryption gateway, and at least one master key pool is set in the encryption gateway. The master key corresponding to the same multicast group is stored in each master key pool, and the multicast IP address of each multicast group corresponds to a security domain. The method includes the following steps:

[0073] S101. Receive an outbound multicast data packet from a network interface connected to the internal network, and match a flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key. When the match is successful, step S102 is executed; when the match is unsuccessful, step S103 is executed.

[0074] S102. Perform transparent encryption processing of a fixed length on the multicast data packet using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet.

[0075] It should be noted that when the flow table entry match is successful, transparent encryption processing of a fixed length is performed on the part of the entire data packet after the offset using the session key, and the encryption mode is CBC (an integer multiple of the algorithm block) + CFB (the remainder part outside the integer multiple of the algorithm block).

[0076] S103. Generate a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address.

[0077] S104. Send the session key request message to the management and control platform so that the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message.

[0078] S105. Receive the session key distribution message, create a new flow table entry, and perform transparent encryption processing on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet.

[0079] S106. Send the outbound encrypted packet from a network interface connected to the external network to the receiving party so that the receiving party performs transparent decryption processing on the outbound encrypted packet.

[0080] In this embodiment, independent security domains and master key pools are established for different multicast groups. Flow tables are established based on the destination IP, i.e., the multicast IP address. The method of centralized online distribution of multicast session keys is adopted and combined with fine-grained security policies to implement a software-defined quantum key distribution method, realizing the manageable and controllable of the keys for multicast encrypted communication. The multicast data packets are transparently encrypted and decrypted by matching the flow table entries, that is, without adding any extra data and service data traffic, without new packet headers, and having good network adaptability.

[0081] It should be noted that compared with the solution described in the Chinese invention patent with the publication number CN112653551A, the embodiment of the present invention is completely based on the symmetric cryptosystem. The group key for encrypted communication is protected by the pre-stored symmetric key in a one-time pad manner. The pre-stored key protection key, i.e., the master key, is offline and filled in large quantities. The communication channels between the gateway and the management and control platform are all public channels, without the need for private links. The key distribution is on-demand application and distribution based on the flow table, while this patent is actively distributed based on policies.

[0082] Compared with the solution described in the Chinese invention patent document with the publication number CN106161015A, in the embodiment of the present invention, the online distribution method of the session key realizes one-time pad distribution by using a large number of pre-stored keys, without the need for special channels. The key distribution is on-demand application and distribution based on the flow table, rather than actively distributed based on policies.

[0083] In one embodiment, the step S103: generating a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address includes the following steps:

[0084] Store the multicast data packet and extract the multicast IP address from the multicast data packet;

[0085] Randomly select a master key ID from the master key pool corresponding to the multicast IP address;

[0086] Generate the session key request message based on the master key ID, the multicast IP address, and the security domain ID corresponding to the multicast IP address.

[0087] In one embodiment, the method further includes the following steps:

[0088] Select the corresponding master key based on the master key ID;

[0089] Use the master key to encrypt the address information in the session key request message to obtain an encrypted message;

[0090] Perform an HMAC operation on the encrypted message to obtain the session key request information after encryption and verification, and send it to the management and control platform.

[0091] In one embodiment, the method further includes the following steps:

[0092] If there is no corresponding master key pool for the multicast IP address, discard the multicast data packet.

[0093] In one embodiment, in step S104, the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message, including the following steps:

[0094] According to the security domain ID and the master key ID, obtain the corresponding master key from the quantum key distribution network to decrypt and verify the session key request information after encryption and verification;

[0095] After successful decryption and verification, obtain the session key from the quantum key distribution network based on the multicast IP address and the security domain ID.

[0096] Read the security attribute information corresponding to the multicast data packet from the pre-configured security policy table, and the security attribute information includes an offset and an encryption mode;

[0097] Generate the session key distribution message based on the session key, the multicast IP address, the security attribute information, the security domain ID, and a randomly selected master key ID within the security domain.

[0098] In one embodiment, the method further includes:

[0099] The management and control platform retrieves the master key from the corresponding master key pool in the quantum key distribution network, and uses the master key to encrypt the session key, the security attribute information, and the multicast IP address in the session key distribution message to obtain the encrypted session key distribution message;

[0100] Perform an HMAC operation on the encrypted session key distribution message to obtain the encrypted and verified session key distribution message.

[0101] In this embodiment, after receiving the session key request message, the control platform obtains the master key decryption message from the quantum key distribution network (QKD) based on the security domain ID and the master key ID and performs integrity verification. If the verification fails, the current session is terminated. After the verification passes, the multicast IP is matched with the domain ID, and the session key is obtained from the QKD. The security attribute information such as the encryption algorithm and offset corresponding to the multicast group IP address is read from the pre-configured security policy table, and a session key distribution message is formed by combining the session key, the multicast IP, the security attribute information, the randomly selected in-domain master key ID, and the domain ID. Then, the master key corresponding to the master key ID is taken out from the master key pool within the corresponding security domain, the session key, the security attribute information, and the multicast IP in the message are encrypted, and the entire message is HMACed. Then, the session key distribution message is sent to all encrypted gateway device nodes within the security domain (multicast group).

[0102] In one embodiment, in step S105, receiving the session key distribution message and creating a new flow table entry includes the following steps:

[0103] Match the multicast IP address with the security domain ID identifier;

[0104] After the matching passes, a new flow table entry is created based on the multicast IP address, the security attribute information, and the session key.

[0105] It should be understood that if the matching fails, the current session is terminated.

[0106] In one embodiment, the method further includes the following steps:

[0107] Take out the master key from the master key pool corresponding to the security domain ID identifier, and use the master key to decrypt and verify the encrypted and verified session key distribution message to obtain the session key distribution message.

[0108] In one embodiment, the method further includes the following steps:

[0109] Send a registration request to the control platform to register multiple security domains, each security domain corresponding to a multicast address;

[0110] Send a key injection request to the quantum key distribution network to obtain the master keys corresponding to different security domains, and create multiple master key pools, each master key pool storing the master keys corresponding to the same security domain.

[0111] Based on the quantum key distribution technology, the large-capacity symmetric pre-shared key provided in this embodiment uses the quantum key distribution network to combine with the security policy management center to centrally and uniformly distribute the session keys used by each encryption gateway to encrypt the multicast data stream within the multicast group (security domain), and associates security policies to solve the problem of encrypted communication of network multicast data.

[0112] In one embodiment, the method further includes the following steps:

[0113] Establish a timeout for each entry in the flow table entry;

[0114] When not accessed near the timeout, a session key update request is sent to the management platform.

[0115] It should be noted that the steps for session key update are the same as steps S103 - S105 and will not be elaborated here.

[0116] This embodiment establishes independent security domains and master key pools for different multicast groups, creates a flow table based on the destination IP, that is, the multicast IP address, and establishes a security policy for the flow table entry consisting of elements such as the destination (multicast) IP address and offset, encryption algorithm, session key, etc. Under the protection of one-time pad of the master key, the global (multicast group) update of the multicast session key is realized, achieving multicast transparent encrypted communication in a software-defined manner, with high security and flexibility, and centralized management is also realized.

[0117] Embodiment 2

[0118] As Figure 2 shown, the second embodiment of the present invention proposes a multicast data transparent encryption and decryption gateway implemented using quantum key distribution. The gateway includes a data encryption and decryption processing module 11, a flow table management module 13, a key update module 14, a key injection module 12, and at least one master key pool. The input end of the key injection module 12 is connected to at least one secure storage medium, and the output end is connected to the master key pool. The output end of the key update module 14 is connected to the master key pool. Each master key pool stores the master key corresponding to the same multicast group, and the multicast IP address of each multicast group corresponds to a security domain;

[0119] The data encryption and decryption processing module 11 is used to receive the outbound multicast data packet from the network interface connected to the internal network;

[0120] The flow table management module 13 is used to match the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key;

[0121] The data encryption and decryption processing module 11 is used to, when the matching is successful, perform transparent encryption processing with a fixed length on the multicast data packet by using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet;

[0122] The key update module 14 is used to, when the matching is unsuccessful, generate a session key request message based on the multicast IP address of the multicast data packet and the primary key corresponding to the multicast IP address; and send the session key request message to the management and control platform 3, so that the management and control platform 3 reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message;

[0123] The flow table management module 13 is used to receive the session key distribution message, create a flow table entry, and perform transparent encryption processing on the multicast data packet based on the created flow table entry to obtain the outbound encrypted packet;

[0124] The data encryption and decryption processing module 11 is used to send the outbound encrypted packet from a network interface connected to the external network to the receiving party, so that the receiving party performs transparent decryption processing on the outbound encrypted packet.

[0125] In this embodiment, independent security domains and primary key pools are established for different multicast groups. A flow table is established based on the destination IP, that is, the multicast IP address. The method of software-defined quantum key distribution is implemented by adopting the method of centralized online distribution of multicast session keys and combining with fine-grained security policies, realizing the management and control of the multicast encryption communication key; the multicast data packet is transparently encrypted and decrypted by matching the flow table entry, that is, no additional data and service data traffic are added, no new packet header is added, and it has good network adaptability.

[0126] In one embodiment, the key update module 14 includes a session key request message generation unit, which is specifically used to perform the following steps:

[0127] Store the multicast data packet, and extract the multicast IP address from the multicast data packet;

[0128] Randomly select a primary key ID identifier from the primary key pool corresponding to the multicast IP address;

[0129] Generate the session key request message based on the primary key ID identifier, the multicast IP address, and the security domain ID identifier corresponding to the multicast IP address.

[0130] In one embodiment, the key update module 14 further includes a request message encryption unit, which is specifically used to perform the following steps:

[0131] Select the corresponding primary key based on the primary key ID identifier;

[0132] Use the master key to encrypt the address information in the session key request message to obtain an encrypted message;

[0133] Perform an HMAC operation on the encrypted message to obtain the session key request information after encryption and verification, and send it to the management and control platform 3.

[0134] In one embodiment, the management and control platform 3 includes:

[0135] A first decryption and verification module, configured to obtain a corresponding master key from the quantum key distribution network 4 according to the security domain ID identifier and the master key ID identifier for decrypting and verifying the session key request information after encryption and verification;

[0136] A session key acquisition module, configured to, after successful decryption and verification, obtain a session key from the quantum key distribution network 4 based on the multicast IP address and the security domain ID identifier;

[0137] A security attribute information reading module, configured to read the security attribute information corresponding to the multicast data packet from the pre-configured security policy table, where the security attribute information includes an offset and an encryption mode;

[0138] A session key distribution message generation module, configured to generate the session key distribution message based on the session key, the multicast IP address, the security attribute information, the security domain ID identifier, and a randomly selected master key ID identifier within the security domain.

[0139] In one embodiment, the management and control platform 3 further includes a session key distribution message encryption module, which is specifically configured to perform the following steps:

[0140] Take out the master key from the corresponding master key pool in the quantum key distribution network 4, and use the master key to encrypt the session key, the security attribute information, and the multicast IP address in the session key distribution message to obtain an encrypted session key distribution message;

[0141] Perform an HMAC operation on the encrypted session key distribution message to obtain the session key distribution message after encryption and verification.

[0142] In this embodiment, after receiving the session key request message, the management and control platform 3 obtains the master key decryption message from the quantum key distribution network 4QKD based on the security domain ID and the master key ID and performs integrity verification. If the verification fails, the current session is terminated. After the verification passes, the multicast IP is matched with the domain ID, and the session key is obtained from the QKD; the security attribute information such as the encryption algorithm and offset corresponding to the multicast group IP address is read from the pre-configured security policy table, and the session key + multicast IP + security attribute information + randomly selected in-domain master key ID + domain ID are used to form the session key distribution message. Then, the master key corresponding to the master key ID is taken out from the master key pool within the corresponding security domain, the session key, the security attribute information, and the multicast IP in the message are encrypted, the entire message is HMACed, and then the session key distribution message is sent to all encrypted gateway device nodes within the security domain (multicast group).

[0143] In one embodiment, the flow table management module 13 is specifically configured to perform the following steps:

[0144] Match the multicast IP address with the security domain ID identifier;

[0145] After the matching passes, a flow table entry is newly created based on the multicast IP address, the security attribute information, and the session key.

[0146] It should be understood that if the matching fails, the current session is terminated.

[0147] In one embodiment, the encrypted gateway further includes:

[0148] The second decryption and verification module is used to take out the master key from the master key pool corresponding to the security domain ID identifier and use the master key to decrypt and verify the encrypted and verified session key distribution message to obtain the session key distribution message.

[0149] In one embodiment, the encrypted gateway further includes:

[0150] The registration module is used to send a registration request to the management and control platform 3 to register multiple security domains, and each security domain corresponds to a multicast address;

[0151] The key injection request module is used to send a key injection request to the quantum key distribution network 4 to obtain the master keys corresponding to different security domains and establish multiple master key pools, and each master key pool stores the master keys corresponding to the same security domain.

[0152] The large-capacity symmetric pre-shared key provided in this embodiment based on quantum key distribution technology uses the quantum key distribution network 4 to centrally and uniformly distribute, in combination with the security policy management center, the session keys used by each encryption gateway to encrypt multicast data streams within the multicast group (security domain), and associates security policies to solve the problem of encrypted communication of network multicast data.

[0153] In one embodiment, the key update module 14 is further configured to:

[0154] Establish a timeout for each entry in the flow table entry;

[0155] When it is not accessed near the timeout, a session key update request is sent to the management platform 3.

[0156] This embodiment establishes independent security domains and master key pools for different multicast groups, creates a flow table based on the destination IP, that is, the multicast IP address, and establishes a security policy for the flow table entry composed of elements such as the destination (multicast) IP address and offset, encryption algorithm, and session key. Under the protection of the master key with one-time pad, the global (multicast group) update of the multicast session key is realized, achieving multicast transparent encrypted communication in a software-defined manner, with high security and flexibility, and centralized management is also realized.

[0157] It should be noted that for other embodiments or implementation methods of the present invention that use quantum key distribution to implement transparent encryption and decryption gateways for multicast data, reference can be made to the above method embodiment 1, and details are not repeated here.

[0158] Embodiment 3

[0159] As Figure 3 shown, the third embodiment of the present invention proposes a system for implementing transparent encryption and decryption of multicast data using quantum key distribution. The system includes a first encryption gateway 1, a second encryption gateway 2, a management platform 3, and a quantum key distribution network 4. The first encryption gateway 1, the second encryption gateway 2, and the quantum key distribution network 4 are all connected to the management platform 3. The first encryption gateway 1 and the second encryption gateway 2 are both connected to the quantum key distribution network 4. Among them, the first encryption gateway 1 and the second encryption gateway 2 both include a data encryption and decryption processing module 11, a flow table management module 13, a key update module 14, a key injection module 12, and at least one master key pool. The input end of the key injection module 12 is connected to at least one secure storage medium, and the output end is connected to the master key pool. The output end of the key update module 14 is connected to the master key pool. Each master key pool stores the master key corresponding to the same multicast group, and the multicast IP address of each multicast group corresponds to a security domain;

[0160] The control platform 3 is used for security domain division, as well as the registration and identity binding services of the first encryption gateway 1 and the second encryption gateway 2, and distributing session keys and security policies to the first encryption gateway 1 and the second encryption gateway 2;

[0161] The quantum key distribution network 4 is used for pre-filling the master key into the secure storage medium;

[0162] The data encryption and decryption processing module 11 is used to receive the outbound multicast data packet from the network interface connected to the internal network;

[0163] The flow table management module 13 is used to match the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key;

[0164] The data encryption and decryption processing module 11 is used to, when the matching is successful, perform transparent encryption processing with a fixed length on the multicast data packet by using the session key and security attribute information in the matched flow table entry to obtain the outbound encrypted packet;

[0165] The key update module 14 is used to, when the matching is unsuccessful, generate a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address; and send the session key request message to the control platform 3, so that the control platform 3 reads the security attribute information corresponding to the multicast data packet from the pre-configured security policy table and generates a session key distribution message;

[0166] The flow table management module 13 is used to receive the session key distribution message, create a new flow table entry, and perform transparent encryption processing on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet;

[0167] The data encryption and decryption processing module 11 is used to send the outbound encrypted packet from the network interface connected to the external network to the receiving party, so that the receiving party performs transparent decryption processing on the outbound encrypted packet.

[0168] In this embodiment, independent security domains and master key pools are established for different multicast groups. Flow tables are established based on the destination IP, that is, the multicast IP address. The method of centrally and online distributing multicast session keys is adopted and combined with fine-grained security policies to implement the software-defined quantum key distribution method, realizing the manageable and controllable of the multicast encryption communication key; the multicast data packet is transparently encrypted and decrypted by matching the flow table entry, that is, no additional data and service data traffic are added, no new packet headers are added, and it has good network adaptability.

[0169] Specifically in this embodiment, the encryption gateway: is used for transparently encrypting and decrypting multicast data transmitted through the network, and is composed of function modules such as data encryption and decryption processing, flow table management, key update, and key injection;

[0170] The management and control platform 3: is used to provide the corresponding relationships of the encryption gateway, key proxy, and quantum network nodes, perform multicast security domain division, provide registration and identity binding services for the encryption gateway, maintain flow tables and security policies, and directly distribute session keys and security policies to the encryption gateway;

[0171] The key proxy: is used to provide a proxy function for key injection in the case where the encryption gateway cannot directly perform key injection at the nodes of the quantum key distribution network 4, and provide a proxy function for key distribution in the case where the encrypted communication network cannot be directly connected to the quantum key distribution network 4;

[0172] The quantum key distribution network 4: includes quantum network nodes and a quantum network link control center, and realizes services such as quantum key generation, quantum key relay, and quantum key provision;

[0173] The quantum network node: is used to store the generated quantum keys, receive key requests from the key proxy or the management and control platform 3, provide keys to the key proxy or the management and control platform 3, or directly provide key injection services;

[0174] The quantum network link control center: is used to establish quantum key distribution and relay links between nodes according to the quantum network node IDs.

[0175] It should be noted that the quantum key distribution device adopted in this embodiment is based on but not limited to the QKD key distribution network, and the involved key pre-injection and online key distribution functions can be implemented by any symmetric key management system and device.

[0176] In one embodiment, the management and control platform 3 includes:

[0177] The first decryption and verification module: is used to obtain the corresponding master key from the quantum key distribution network 4 according to the security domain ID identifier and the master key ID identifier for decrypting and verifying the encrypted and verified session key request information;

[0178] The session key acquisition module: is used to obtain the session key from the quantum key distribution network 4 based on the multicast IP address and the security domain ID identifier after successful decryption and verification;

[0179] The security attribute information reading module: is used to read the security attribute information corresponding to the multicast data packet from the pre-configured security policy table, and the security attribute information includes an offset and an encryption mode;

[0180] A session key distribution message generation module, which is used to generate the session key distribution message based on the session key, the multicast IP address, the security attribute information, the security domain ID identifier, and the master key ID identifier randomly selected within this security domain.

[0181] In one embodiment, the management and control platform 3 further includes a session key distribution message encryption module, which is specifically used to perform the following steps:

[0182] Take out the master key from the corresponding master key pool in the quantum key distribution network 4, and use this master key to encrypt the session key, the security attribute information, and the multicast IP address in the session key distribution message to obtain the encrypted session key distribution message;

[0183] Perform an HMAC operation on the encrypted session key distribution message to obtain the encrypted and verified session key distribution message.

[0184] As Figure 4 shown, the working process of the multicast data transparent encryption and decryption system implemented by using quantum key distribution proposed in this embodiment is as follows:

[0185] (1) The management and control platform delimits security domains. Each multicast address corresponds to a security domain. One encryption gateway device can register multiple security domains, that is, join multiple multicast groups. Through the quantum key distribution network QKD, using a large-capacity security storage medium such as a secure TF card or a secure USB flash drive, a large number of master keys are pre-injected into the secure storage media connected to each encryption gateway device node in the security domain, that is, the multicast group. Devices within the same security domain share the same master key identified by the same key ID. The domain ID directly corresponds to the multicast IP address; The encryption gateway device that joins multiple security domains, that is, multicast groups, needs to use multiple different storage media for multiple injections, and each injection corresponds to a security domain.

[0186] Among them, the key format is 4-byte domain ID + 4-byte key ID + n bytes of key and n bytes of initialization vector, and the specific value of n is related to the encryption algorithm.

[0187] (2) The encryption gateway device node within the security domain obtains the master key through the secure storage medium it is connected to and establishes a master key pool.

[0188] If the encryption gateway device that joins multiple security domains, that is, multicast groups, needs to establish multiple master key pools, use multiple different storage media for key injection, and each injection corresponds to a master key pool and a security domain (multicast group). The master key pools are distinguished by the domain ID, that is, the multicast IP address.

[0189] (3) The encryption gateway device node matches the outbound multicast data packet against the flow table entry according to its destination IP, i.e., the multicast IP address. The flow table entry consists of elements such as the multicast IP address and offset, encryption algorithm, session key, etc. If the match is successful, the session key is used to perform a transparent encryption process with a fixed length on the part of the data packet after the offset. The encryption mode is CBC (integer multiple of the algorithm block) + CFB (remainder part outside the integer multiple of the algorithm block).

[0190] (4) If the flow table entry is not successfully matched in the previous step (3), the multicast data packet is cached, and its multicast IP address is extracted. A master key ID is randomly selected from the master key pool corresponding to the multicast IP address. A session key request message is formed based on the multicast IP address + master key ID + security domain ID; then the master key corresponding to the master key ID is taken out from the master key pool, the address information in the session key request message is encrypted and an HMAC operation is performed on the entire message, and then it is sent to the management and control platform.

[0191] It should be noted that if the master key pool corresponding to the multicast IP address does not exist, the multicast data packet is discarded.

[0192] (5) After receiving the session key request message, the management and control platform obtains the master key decryption message from the quantum key distribution network QKD according to the security domain ID + master key ID and performs integrity verification, matches the multicast IP with the security domain ID, obtains the session key from QKD, reads the security attribute information such as the encryption algorithm and offset corresponding to the multicast group from the pre-configured security policy table, and forms a session key distribution message with the session key + multicast IP + security attribute information + randomly selected in-domain master key ID + domain ID; then the master key corresponding to the master key ID is taken out from the master key pool within the corresponding security domain, the session key, security attribute information, and multicast IP in the message are encrypted, and an HMAC operation is performed on the entire message, and then the session key distribution message is sent to all encryption gateway device nodes within the domain (multicast group).

[0193] (6) After receiving the session key distribution message, the encryption gateway device node takes out the master key corresponding to the master key ID from the master key pool corresponding to the security domain ID, decrypts the message and performs integrity verification, and matches the multicast IP with the security domain ID. After passing the match, a flow table entry is newly created based on the multicast IP address, security attribute information, and session key, and the data stream matching the newly created flow table is transparently encrypted and decrypted as in step (3) according to the flow table entry information.

[0194] (7) The encryption gateway device node as the receiver matches the inbound data packet against the flow table entry according to its multicast IP address, takes out the session key of the hit flow table entry to decrypt the data packet, and discards the multicast data packet if there is no hit flow table entry.

[0195] Furthermore, a timeout is set for each entry in the data flow table on the encryption gateway device, and a session key update operation is initiated when the timeout is approaching. The operation process is the same as steps (4) to (6).

[0196] Based on the large-capacity symmetric pre-shared keys provided by the quantum key distribution technology, this embodiment uses the quantum key distribution network combined with the security policy control center to centrally and uniformly distribute the session keys used by each encryption gateway to encrypt the multicast data stream within the multicast group (security domain), and associates security policies to solve the problem of network multicast data encrypted communication. Different from the technology of key negotiation based on public key cryptography, it provides a multicast communication transparent encryption and decryption method that does not rely on public key cryptography technology and can centrally and uniformly distribute session keys within the multicast group with one-flow-one-key, realizing the centralized and unified strong control and low overhead of network multicast data encrypted communication. It solves the problem of secure interconnection of multicast services such as audio and video when the encryption gateway does not directly interact with key and security policy information, can significantly reduce the relevant interaction information and complexity of key management involved in multicast encrypted communication, avoid the complexity of group key management and the modification of data packet structure, and enhance network adaptability.

[0197] It should be noted that the logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection part with one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or processing it in other suitable ways if necessary, and then storing it in a computer memory.

[0198] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following technologies well known in the art can be used: discrete logic circuits with logic gate circuits for implementing logic functions on data signals, application specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0199] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0200] In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" can explicitly or implicitly include at least one of these features. In the description of the present invention, the meaning of "a plurality" is at least two, such as two, three, etc., unless otherwise specifically and clearly defined.

[0201] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A method for implementing transparent encryption and decryption of multicast data using quantum key distribution, characterized in that The method is applied to an encryption gateway, in which at least one master key pool is set. Each master key pool stores a master key corresponding to the same multicast group. The multicast IP address of each multicast group corresponds to a security domain, and the method includes the following steps: Receive an outbound multicast data packet from a network interface connected to the internal network, and match a flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key. The security attribute information includes an offset and an encryption mode; If the match is successful, perform transparent encryption processing of a fixed length on the multicast data packet by using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet; If the match is unsuccessful, generate session key request information based on the multicast IP address, the master key corresponding to the multicast IP address, and the security domain ID identifier corresponding to the multicast IP address; Send the session key request message to a management and control platform, so that the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message; Receive the session key distribution message, create a new flow table entry, and perform transparent encryption processing on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet; Send the outbound encrypted packet from a network interface connected to the external network to a receiving party, so that the receiving party performs transparent decryption processing on the outbound encrypted packet; Among them, the process of delimiting the security domain includes: sending a registration request to the management and control platform to register multiple security domains, and each security domain corresponds to a multicast address; sending a key injection request to a quantum key distribution network to obtain master keys corresponding to different security domains, and establishing multiple master key pools. Each master key pool stores a master key corresponding to the same security domain.

2. The method for realizing transparent encryption and decryption of multicast data by using quantum key distribution according to claim 1, characterized in that The step of, if the match is unsuccessful, generating a session key request message based on the multicast IP address of the multicast data packet and the master key corresponding to the multicast IP address includes: If the match is unsuccessful, cache the multicast data packet and extract the multicast IP address from the multicast data packet; Randomly select a master key ID identifier from the master key pool corresponding to the multicast IP address; Generate the session key request message based on the master key ID identifier, the multicast IP address, and the security domain ID identifier corresponding to the multicast IP address.

3. The method for realizing transparent encryption and decryption of multicast data by using quantum key distribution according to claim 2, characterized in that, The method further includes: Select a corresponding master key based on the master key ID identifier; Use the master key to encrypt the address information in the session key request message to obtain an encrypted message; Perform an HMAC operation on the encrypted message to obtain an encrypted and verified session key request information and send it to the management and control platform.

4. The method for realizing transparent encryption and decryption of multicast data by using quantum key distribution according to claim 2, characterized in that, The method further includes: If there is no master key pool corresponding to the multicast IP address, discard the multicast data packet.

5. The method for implementing transparent encryption and decryption of multicast data using quantum key distribution according to claim 3, characterized in that, The step that the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message includes: Obtain the corresponding master key from the quantum key distribution network according to the security domain ID identifier and the master key ID identifier for decrypting and verifying the encrypted and verified session key request information; After successful decryption and verification, obtain the session key from the quantum key distribution network based on the multicast IP address and the security domain ID identifier; Read the security attribute information corresponding to the multicast data packet from the pre-configured security policy table, where the security attribute information includes an offset and an encryption mode; Generate the session key distribution message based on the session key, the multicast IP address, the security attribute information, the security domain ID identifier, and the master key ID identifier randomly selected within the security domain.

6. The method for realizing transparent encryption and decryption of multicast data by using quantum key distribution according to claim 5, wherein The method further includes: The management and control platform takes out the master key from the corresponding master key pool in the quantum key distribution network, and uses the master key to encrypt the session key, the security attribute information, and the multicast IP address in the session key distribution message to obtain the encrypted session key distribution message; Perform an HMAC operation on the encrypted session key distribution message to obtain the encrypted and verified session key distribution message.

7. The method for transparently encrypting and decrypting multicast data using quantum key distribution according to claim 5, wherein Receiving the session key distribution message and creating a flow table entry, including: Matching the multicast IP address and the security domain ID identifier; After passing the match, create a flow table entry based on the multicast IP address, the security attribute information, and the session key.

8. The method for transparently encrypting and decrypting multicast data using quantum key distribution according to claim 6, characterized in that, The method further includes: Take out the master key from the master key pool corresponding to the security domain ID identifier, and use the master key to decrypt and verify the encrypted and verified session key distribution message to obtain the session key distribution message.

9. The method for realizing transparent encryption and decryption of multicast data by using quantum key distribution according to claim 1, characterized in that, The method further includes: Establish a timeout for each entry in the flow table entry; When not accessed near the timeout, send a session key update request to the management and control platform.

10. A multicast data transparent encryption and decryption gateway implemented by quantum key distribution, characterized in that, The gateway includes a data encryption and decryption processing module, a flow table management module, a key update module, a key injection module, and at least one master key pool. The input end of the key injection module is connected to at least one secure storage medium, and the output end is connected to the master key pool. The output end of the key update module is connected to the master key pool. Each master key pool stores the master key corresponding to the same multicast group. The multicast IP address of each multicast group corresponds to a security domain. Among them, the security domain delineation process includes: sending a registration request to the management and control platform to register multiple security domains, and each security domain corresponds to a multicast address; sending a key injection request to the quantum key distribution network to obtain the master key corresponding to different security domains, and establishing multiple master key pools, and each master key pool stores the master key corresponding to the same security domain; The data encryption and decryption processing module is used to receive the outbound multicast data packet from the network interface connected to the internal network; The flow table management module is used to match the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, the security attribute information, and the session key. The security attribute information includes an offset and an encryption mode; The data encryption and decryption processing module is used to, when the matching is successful, perform transparent encryption processing with a fixed length on the multicast data packet by using the session key and security attribute information in the matched flow table entry to obtain an outbound encrypted packet; The key update module is used to, when the matching is unsuccessful, generate session key request information based on the multicast IP address, the master key corresponding to the multicast IP address, and the security domain ID identifier corresponding to the multicast IP address; and send the session key request message to the management and control platform, so that the management and control platform reads the security attribute information corresponding to the multicast data packet from a pre-configured security policy table and generates a session key distribution message; The flow table management module is used to receive the session key distribution message, create a flow table entry, and perform transparent encryption processing on the multicast data packet based on the newly created flow table entry to obtain the outbound encrypted packet; The data encryption and decryption processing module is used to send the outbound encrypted packet from a network interface connected to the external network to the receiving party, so that the receiving party performs transparent decryption processing on the outbound encrypted packet.

11. A multicast data transparent encryption and decryption system implemented by quantum key distribution, characterized in that, The system includes a first encryption gateway, a second encryption gateway, a management and control platform, and a quantum key distribution network. The first encryption gateway, the second encryption gateway, and the quantum key distribution network are all connected to the management and control platform. The first encryption gateway and the second encryption gateway are both connected to the quantum key distribution network. Among them, the first encryption gateway and the second encryption gateway both include a data encryption and decryption processing module, a flow table management module, a key update module, a key injection module, and at least one master key pool. The input end of the key injection module is connected to at least one secure storage medium, and the output end is connected to the master key pool. The output end of the key update module is connected to the master key pool. Each master key pool stores the master key corresponding to the same multicast group. Each multicast IP address of each multicast group corresponds to a security domain. Among them, the process of delimiting the security domain includes: sending a registration request to the management and control platform to register multiple security domains, and each security domain corresponds to a multicast address; sending a key injection request to the quantum key distribution network to obtain the master key corresponding to different security domains, and establishing multiple master key pools, and each master key pool stores the master key corresponding to the same security domain; The management and control platform is used to perform security domain division, as well as the registration and identity binding services of the first encryption gateway and the second encryption gateway, and distribute session keys and security policies to the first encryption gateway and the second encryption gateway; The quantum key distribution network is used to pre-inject the master key into the secure storage medium; The data encryption and decryption processing module is used to receive the outbound multicast data packet from a network interface connected to the internal network; The flow table management module is used to match the flow table entry according to the multicast IP address of the multicast data packet. The information in the flow table entry includes the multicast IP address, security attribute information, and session key. The security attribute information includes an offset and an encryption mode; The data encryption and decryption processing module is used to perform transparent encryption processing of a fixed length on the multicast data packet by using the session key and security attribute information in the matched flow table entry when the matching is successful, so as to obtain an outbound encrypted packet; The key update module is used to generate session key request information based on the multicast IP address, the master key corresponding to the multicast IP address, and the security domain ID identifier corresponding to the multicast IP address when the matching is unsuccessful; and send the session key request message to the management and control platform, so that the management and control platform reads the security attribute information corresponding to the multicast data packet from the pre-configured security policy table and generates a session key distribution message; The flow table management module is used to receive the session key distribution message, create a new flow table entry, and perform transparent encryption processing on the multicast data packet based on the new flow table entry to obtain the outbound encrypted packet; The data encryption and decryption processing module is used to send the outbound encrypted packet from the network interface connected to the external network to the receiving party, so that the receiving party performs transparent decryption processing on the outbound encrypted packet.

Citation Information

Patent Citations

  • Quantum secrete key distribution method based on DPI

    CN106161015A

  • Centralized key management method based on key distribution multicast

    CN112653551A

  • Method and system for realizing multicast data encryption and decryption by adopting quantum key distribution

    CN115567207A