A user-side quantum-safe service system and its interaction method

By installing a quantum-safe service system on the user end, the problem of user access to the quantum-safe layer is solved, realizing quantum-safe services without additional hardware devices and ensuring user communication security.

CN115643004BActive Publication Date: 2025-10-28MATRICTIME DIGITAL TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110821939.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-20
Publication Date
2025-10-28
Estimated Expiration
2041-07-20

AI Technical Summary

Technical Problem

Existing technologies have not effectively solved the problem of how users can access the quantum security layer network to obtain quantum security services.

Method used

A user-end quantum security service system is provided, including an interface unit, an information unit, and a key unit, for connecting to hardware devices, handling quantum security authentication and key management, and ensuring that the user end can legally access the quantum security layer and obtain quantum security services.

Benefits of technology

The system enables users to install a quantum-safe service system without additional hardware, saving costs and ensuring legitimate access to the quantum-safe layer, providing quantum-safe communication guarantees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643004B_ABST
    Figure CN115643004B_ABST
Patent Text Reader

Abstract

This invention discloses a quantum-secure service system for user terminals and its interaction method. The system can serve both individual and group user terminals. The system includes an interface unit, an information unit, and a key unit, both of which are connected to the interface unit. The quantum-secure service system proposed in this invention can be installed on existing user hardware, offering convenience and cost-effectiveness. After authentication, user terminals equipped with this system can access the quantum security layer as legitimate devices to obtain quantum-secure services, ensuring user communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum security, specifically to a user-side quantum security service system and its interaction method. Background Technology

[0002] With the rapid development of internet technology, users are increasingly completing various operations and obtaining services online. While online operations bring convenience, they also bring concerns about confidentiality and security. Hackers can intercept user-transmitted information through the network, thus compromising the security of that information. Quantum secure communication is currently widely recognized in the industry as an "unconditionally secure" means of communication, and has become a new generation of information network security technology. Its unconditional security provides strong support for information security and represents a major transformation and inevitable trend in the development of informatization.

[0003] Patent application number 202110768015.2 proposes a wide-area network quantum security layer networking system and method. In the case of an existing quantum security network, the technical problem of how users can access the security layer network and obtain quantum security services becomes the problem that needs to be solved. Summary of the Invention

[0004] Purpose of the Invention: The purpose of this invention is to provide a user-end quantum security service system and its interaction method, solving the technical problem of how users can access the security layer network and thus obtain quantum security services. The quantum security service system of this invention is installed on the user end, providing users with registration, authentication access to the quantum security layer, key acquisition from the quantum security layer, processing of session keys required for communication, and access to the necessary quantum security services.

[0005] Technical solution: The present invention provides a user-end quantum security service system, which is installed on the user end and includes an interface unit, an information unit and a key unit, wherein the information unit and the key unit are both connected to the interface unit;

[0006] The interface unit is used to connect the system with other systems or programs in the hardware device, so that the quantum security service system can call data in other systems or programs or transmit data to other systems or programs during operation.

[0007] The information unit includes an information processing module and an information reporting module connected to each other. The information processing module is used to read the necessary user terminal information when the user terminal accesses the quantum security layer for quantum security authentication, and to receive the authentication results sent by the quantum security layer and the information on the user terminal key consumption sent by the quantum security layer and to inform the key unit to replenish the key information. The information reporting module is used to report the read user terminal information to the quantum security layer for user network access authentication, to ensure that the user terminal can legally access the quantum security layer and obtain the corresponding quantum security services.

[0008] Furthermore, when the user terminal is a personal user terminal, the key unit includes a key receiving module and a key processing module connected to each other. The key receiving module has a key pool and is used to receive and store the key issued to the user terminal by the quantum security layer. The key processing module has a buffer area and is used to extract the key required for communication from the key pool of the key receiving module and store it in the buffer area of ​​the module when the user terminal is communicating. The extracted key is used to generate a temporary session key with the communicating peer user through the key relay of the quantum security layer. The key processing module also performs encryption, decryption, and hashing operations on the key and transmits the operation result information to the interface unit.

[0009] Furthermore, when a user terminal accesses the quantum security layer, the specific steps for quantum security authentication are as follows:

[0010] (1) Initial key distribution: The key distribution unit in the quantum security layer distributes the initial key to the quantum security service system. The initial key is stored in the key pool of the key receiving module of the quantum security service system. At the same time, the key paired with the initial key is stored in the quantum security layer.

[0011] (2) System installation: The quantum security service system is installed on the personal user terminal, which can be a mobile phone, PC, tablet, quantum security USB flash drive, quantum security shield, super SIM card or server equipment;

[0012] (3) User information reporting: The information processing module in the quantum security service system reads user information and authentication timestamps from the personal client and forms a user authentication message. The user authentication message is reported to the quantum security layer through the information reporting module.

[0013] (4) User information authentication: Quantum security authentication of messages between the personal client and the quantum security layer. After successful authentication, the personal client can access the quantum security layer normally and obtain quantum security services.

[0014] (5) Return authentication results: Return the authentication results to the individual user terminal so that the user knows the authentication results and can use the quantum security service in the future.

[0015] This invention also includes an interaction method for the aforementioned quantum security service system, comprising the following steps:

[0016] (1) Communication request and response: The first user terminal that accesses the quantum security layer initiates a communication request with the second user terminal through the quantum security service system installed on the first user terminal. This communication request requires quantum security authentication. If the second user terminal responds to this communication request, the communication continues.

[0017] (2) Establishing a key link: After receiving the communication request from the first user terminal, the network management system of the quantum security layer executes the routing algorithm according to the routing strategy of the network management system to establish a key link between the first user terminal and the second user terminal.

[0018] (3) Generate session key: Extract a key of a specific length K1 from the key pool in the key receiving module of the quantum security service system of the first user terminal. After key relay of the key link, the second user terminal will obtain the same key K1 as the session key for this communication.

[0019] (4) Performing quantum-safe communication: The first user terminal and the second user terminal generate the same session key K1. Both parties use this key to perform quantum-safe communication. Quantum-safe communication includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption and hash value calculation.

[0020] (5) Session key replenishment: The first user terminal and the second user terminal communicate through key K1. If K1 is sufficient to support this communication, then K1 is used to complete this communication; if K1 is insufficient to support this communication, then steps (3) to (4) are repeated to obtain a new session key to complete this communication.

[0021] (6) User key replenishment: After the communication ends, the keys of the first user terminal and the second user terminal are partially consumed; the quantum security layer has a user terminal key consumption threshold. If the key consumption of any user terminal exceeds the set threshold, the network management system of the quantum security layer notifies the service point of the quantum security layer to replenish the key to the quantum security service system of the user terminal for subsequent communication.

[0022] Furthermore, the key link in step (2) is composed of multiple paired nodes connected together, and each pair of paired nodes has the same paired key, with the second user terminal being the last node; the specific process of key relay in step (3) is as follows: the specific length key K1 extracted by the first user terminal is encrypted and decrypted using two pairs of paired keys of the same length on the first paired node of the key link. Both encryption and decryption operations are binary XOR operations; this is repeated until the last node, i.e. the second user terminal, and finally the second user terminal will obtain the same key K1 as the session key for this communication.

[0023] Furthermore, when the user terminal is a group user terminal with multiple personal terminals connected to it, the key unit includes a key processing module, a key receiving module, a key distribution module, a key generation module, and a personal terminal connection module. The key receiving module is connected to the key processing module, and the key processing module, the key generation module, and the personal terminal connection module are all connected to the key distribution module.

[0024] The key receiving module includes a key pool, used to receive and store keys issued to the user terminal by the quantum security layer. The key processing module includes a buffer, used to extract the necessary keys from the key pool of the key receiving module during user terminal communication, store them in the buffer, generate a temporary session key with the communicating peer using the extracted key and key relay through the quantum security layer, perform encryption, decryption, and hash operations on the key, and transmit the operation results to the interface unit. The key generation module generates quantum random numbers as keys and transmits these keys to the key distribution module. The key distribution module distributes the received keys to multiple personal terminals connected to the group user terminal. The personal terminal connection module contains n key storage areas, where n is the number of personal terminals connected to the group user terminal. Each key storage area corresponds one-to-one with a personal terminal connected to the group user terminal, storing the paired key for the corresponding personal terminal.

[0025] The information processing module is also used to record the correspondence between personal terminals and group user terminals.

[0026] Furthermore, the group user terminal forms a local area network with multiple personal terminals connected to it, and each personal terminal in the group user terminal is equipped with a quantum security service system for individual users.

[0027] This invention also includes an interaction method for the aforementioned quantum security service system, comprising the following steps:

[0028] (1) Communication request and response: The first individual terminal initiates a communication request with the second individual terminal to the first group user terminal. The first individual terminal is a personal terminal connected to the first group user terminal, and the second individual terminal is a personal terminal connected to the second group user terminal. This communication request requires the first group user terminal to initiate quantum security authentication to the second group user terminal through the quantum security layer. When the local area network formed by the group user terminal and the personal terminal is untrusted, the communication request needs to be quantum security authenticated between the group user terminal and the personal terminal; otherwise, it is not required. If the second group user terminal and the second individual terminal respond to this communication in turn, the communication continues.

[0029] (2) Establishing a key link: The network management system of the quantum security layer executes a routing algorithm to establish a key link between the first group user terminal and the second group user terminal;

[0030] (3) Generate session key: Extract a key string Ka of a specific length from the key of the first human terminal, and after key relay through the first group user terminal, the quantum security layer and the second group user terminal, the second human terminal will obtain the same Ka as the session key for this communication.

[0031] (4) Performing quantum-safe communication: The first and second personal terminals generate the same session key Ka. Both parties use this key to perform quantum-safe communication. Quantum-safe communication includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption and hash value calculation.

[0032] (5) Session key replenishment: The first and second personal terminals communicate through key Ka. If Ka is sufficient to support this communication, then Ka is used to complete this communication; if Ka is insufficient to support this communication, then steps (3) to (4) are repeated to obtain a new session key to complete this communication.

[0033] (6) User Key Replenishment: After communication ends, the keys of the first individual terminal, the second individual terminal, the first group user terminal, and the second group user terminal are partially consumed. The quantum security layer has a group user terminal key consumption threshold. If the key consumption of any group user terminal exceeds the set threshold, the network management system of the quantum security layer notifies the service point of the quantum security layer to replenish the key to the quantum security service system of that group user terminal for subsequent communication. The key storage area of ​​the personal terminal connection module of the group user terminal has a personal terminal key consumption threshold. If the key consumption of any individual terminal exceeds the set threshold, the corresponding group user terminal notifies the quantum security service system of that individual terminal to replenish the key for subsequent communication.

[0034] This invention also includes an interaction method for the aforementioned quantum security service system, comprising the following steps:

[0035] (1) Communication request and response: The first personal terminal initiates a communication request with the second personal terminal to the first group user terminal. Both the first personal terminal and the second personal terminal are personal terminals connected to the first group user terminal. When the local area network formed by the group user terminal and the personal terminal is untrusted, the communication request needs to be quantum-safely authenticated between the group user terminal and the personal terminal. Otherwise, it is not necessary. If the second personal terminal responds to the communication request, the communication continues.

[0036] (2) Generate session key: Extract a key string of a specific length from the key of the first user terminal. Extract a key string of a specific length from the key of the second-person terminal. After key relay by the first group of users, the second user terminal will obtain the same... This serves as the session key for this communication;

[0037] (3) Performing quantum-secure communication: The first and second human terminals generate the same session key. Both parties use this key to perform quantum-safe communication, which includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption, and hash value calculation.

[0038] (4) Session key supplementation: The first and second personal terminals communicate via key. To communicate, if If sufficient to support this communication, then use Complete this communication; if If the key is insufficient to support the current communication, repeat steps (2) to (3) to obtain a new session key to complete the current communication.

[0039] (5) User key replenishment: After the communication ends, the keys of the first and second personal terminals are partially consumed; the key storage area of ​​the personal terminal connection module of the first group user terminal is equipped with a personal terminal key consumption threshold. If the key consumption of any personal terminal exceeds the set threshold, the first group user terminal notifies the quantum security service system of the personal terminal to replenish the key for subsequent communication.

[0040] Furthermore, the specific process of key relay in step (2) is as follows: the first group user terminal extracts the same key from the key storage area of ​​the personal user connection module paired with the second personal terminal. To encrypt That is, perform the XOR operation. The result of the XOR operation is transmitted to the second terminal, which then decrypts the XOR result, i.e., performs the XOR operation again. Obtain the same session key as the first person's terminal. This serves as the session key for this communication.

[0041] Furthermore, the response requires quantum security authentication.

[0042] The beneficial effects of this invention are:

[0043] (1) The quantum security service system of the present invention can be easily installed on user terminals, such as mobile phones, PCs, tablets, quantum USB drives, quantum shields, super SIM cards and servers, without the need to purchase additional hardware equipment, which is convenient and cost-saving for users.

[0044] (2) Once the user terminal with the quantum security service system installed is authenticated, it can be used as a legitimate device to access the quantum security layer and obtain quantum security services to ensure the user's information security. Attached Figure Description

[0045] Figure 1 A schematic diagram illustrating the structural division of a quantum-safe service system for individual users;

[0046] Figure 2 A schematic diagram illustrating the connection of a quantum security service system for individual users to the quantum security layer;

[0047] Figure 3 A schematic diagram of the authentication process at the quantum security layer for a quantum-secure service system for individual users;

[0048] Figure 4 A schematic diagram of the interaction process of a quantum security service system for individual users at the quantum security layer;

[0049] Figure 5 A schematic diagram illustrating the architecture of a quantum security service system for group users;

[0050] Figure 6 A schematic diagram illustrating the connection of a quantum security service system for group users to the quantum security layer;

[0051] Figure 7 A schematic diagram illustrating the process of interaction between terminals in two different group user local area networks;

[0052] Figure 8 This diagram illustrates the process of interaction between terminals within the same group user local area network. Detailed Implementation

[0053] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0054] This invention provides a user-end quantum security service system that can be directly installed on the user terminal without requiring additional special hardware. The user terminal includes mobile phones, tablets, PCs, quantum security USB drives, quantum security shields, super SIM cards, and servers. The system provides users with the following functions: registration and authentication to access the quantum security layer; obtaining keys from the quantum security layer; processing session keys required for communication; and providing necessary quantum security services. The quantum security layer described in this invention includes modules for key generation, key distribution, device authentication, routing algorithms, and information management. When a user has communication needs, it distributes keys to the user and processes them to ensure communication security. This quantum security layer can be composed of the management center and service points proposed in patent application number 202110768015.2.

[0055] The structure of the quantum security service system and its interaction methods will be described in detail below with reference to the illustrations and embodiments.

[0056] Example 1

[0057] This invention proposes a quantum-safe service system installed on a personal user terminal. The system's structure is divided as follows: Figure 1 As shown. The system includes an interface unit 11, an information unit 12, and a key unit 13, both of which are connected to the interface unit 11;

[0058] The interface unit 11 is used to connect the system with other systems or programs in the hardware device, so that the quantum security service system can call data in other systems or programs or transmit data to other systems or programs during operation.

[0059] When the information unit 12 informs the key unit 13 to receive the supplementary key, it needs to interact with the key unit 13. The information interaction between the information unit 12 and the key unit 13 is also connected through the interface unit 11.

[0060] Information unit 12 includes an information processing module 1201 and an information reporting module 1202 connected to each other;

[0061] The functions of information processing module 1201 include, but are not limited to:

[0062] (1) Used to read the required user terminal information when the user terminal accesses the quantum security layer, for quantum security authentication;

[0063] (2) Used to receive authentication results sent by the quantum security layer;

[0064] (3) Receive billing information sent by the quantum security layer, trigger the user's payment process, and after the user completes the payment operation, receive the payment result notification returned by the quantum security layer.

[0065] (4) Receive information from the quantum security layer regarding the user terminal key consumption and inform the key unit 13 to replenish key information;

[0066] The information reporting module 1202 is used to report the read user terminal information to the quantum security layer for user network access authentication, ensuring that the user terminal can legally access the quantum security layer and obtain the corresponding quantum security services.

[0067] Key unit 13 includes a key receiving module 1301 and a key processing module 1302 connected to each other;

[0068] The key receiving module 1301 is equipped with a key pool. The key receiving module 1301 is used to receive and store the key issued to the user terminal by the quantum security layer.

[0069] The key processing module 1302 is equipped with a buffer area. When communicating with the user end, the key processing module 1302 extracts the key required for communication from the key pool of the key receiving module 1301 and puts it into the buffer area of ​​the module. It uses the extracted key and key relay through the quantum security layer to generate a temporary session key with the communicating peer user. It also performs encryption, decryption and hashing operations on the key and transmits the operation result information to the interface unit 11.

[0070] Before individual users can access the quantum security layer, they need to register with it. Registration can be performed through a service point within the quantum security layer, which is the same service point mentioned in patent application number 202110768015.2. This service point reports user information, such as user identity and phone number, to the quantum security layer's network management system to complete the registration process. If necessary, the communication process for reporting user information can be quantum-encrypted to protect user privacy.

[0071] How can a quantum-safe service system for individual users access the quantum-safe layer? Figure 2 As shown, individual user terminals equipped with a quantum-safe service system report user information through this system. After network access authentication by the quantum-safe layer, they join the quantum-safe layer. The quantum-safe layer then issues keys to the authenticated individual user terminals for communication. A quantum-safe layer network covers M individual user terminals, all of which connect to the quantum-safe layer to obtain quantum-safe services.

[0072] like Figure 3 As shown, when a quantum-safe service system for personal users accesses the quantum-safe layer, the specific steps for quantum-safe authentication are as follows:

[0073] (1) Initial key distribution: The key distribution unit in the quantum security layer pre-distributes the initial key to the quantum security service system. The initial key is stored in the key pool of the key receiving module 1301 of the quantum security service system. At the same time, the key paired with the initial key is stored in the quantum security layer. The quantum security layer distributes the quantum security service system containing the initial key to individual users.

[0074] (2) System installation: Individual users install the quantum security service system on their personal user terminals, which can be existing hardware devices such as mobile phones, PCs, tablets, quantum security USB drives, quantum security shields, super SIM cards, or servers.

[0075] (3) User information reporting: The information processing module 1201 in the quantum security service system reads necessary information such as user information and authentication timestamp from the personal client and forms a user authentication message. The user authentication message is reported to the quantum security layer through the information reporting module 1202.

[0076] (4) User information authentication: Quantum security authentication of messages between the personal client and the quantum security layer. After successful authentication, the personal client can access the quantum security layer normally and obtain quantum security services.

[0077] (5) Return authentication results: Return the authentication results to the individual user terminal so that the user knows the authentication results and can use the quantum security service in the future.

[0078] like Figure 4 As shown, the interaction method of the above-mentioned quantum security service system includes the following steps:

[0079] (1) Communication request and response: The first user terminal that accesses the quantum security layer initiates a communication request with the second user terminal through the quantum security service system installed on the first user terminal. This communication request requires quantum security authentication. If the second user terminal responds to this communication request, the communication continues. The response may be subject to quantum security authentication as needed.

[0080] (2) Establishing a key link: After receiving the communication request from the first user terminal, the network management system of the quantum security layer executes the routing algorithm according to the routing policy of the network management system to establish a key link between the first user terminal and the second user terminal. This key link is composed of multiple paired nodes connected together, and each pair of paired nodes has the same pairing key, with the second user terminal being the last node.

[0081] (3) Generating a session key: A key of a specific length K1 is extracted from the key pool of the key receiving module of the quantum security service system at the first user terminal. After key relay on the key link, the second user terminal will obtain the same key K1 as the session key for this communication. The specific key relay process is as follows: the specific length key K1 extracted by the first user terminal is encrypted and decrypted using two sets of matching keys of the same length at the first matching node on the key link. Both encryption and decryption operations are binary XOR operations. This process is repeated until the last node, i.e., the second user terminal. Finally, the second user terminal will obtain the same key K1 as the session key for this communication.

[0082] (4) Performing quantum-safe communication: The first user terminal and the second user terminal generate the same session key K1. Both parties use this key to perform quantum-safe communication. Quantum-safe communication includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption and hash value calculation.

[0083] (5) Session key replenishment: The first user terminal and the second user terminal communicate through key K1. If K1 is sufficient to support this communication, then K1 is used to complete this communication; if K1 is insufficient to support this communication, then steps (3) to (4) are repeated to obtain a new session key to complete this communication.

[0084] (6) User key replenishment: After the communication ends, the keys of the first user terminal and the second user terminal are partially consumed; the quantum security layer has a user terminal key consumption threshold. If the key consumption of any user terminal exceeds the set threshold, the network management system of the quantum security layer notifies the service point of the quantum security layer to replenish the key to the quantum security service system of the user terminal for subsequent communication.

[0085] Example 2

[0086] This invention also proposes a quantum-secure service system for a group user terminal, which is a group user terminal with multiple personal terminals connected to it. The system structure is as follows: Figure 5 As shown. The system includes an interface unit 21, an information unit 22, and a key unit 23, both of which are connected to the interface unit 21.

[0087] The structure and function of interface unit 21 and information unit 22 are the same as those of interface unit 11 and information unit 12 in the personal user terminal quantum security service system of Embodiment 1. The information processing module 1201 is also used to record the correspondence between personal terminals connected to the group user terminal and the group user terminal. In this embodiment, each of the multiple personal terminals connected to the group user terminal is equipped with a quantum security service system whose user terminal is a personal user terminal; that is, the quantum security service system of the personal terminals connected to the group user terminal is the same as the quantum security service system of the personal user terminal in Embodiment 1. The group user terminal and the multiple connected personal terminals form a local area network.

[0088] The key unit 23 of the group user terminal quantum security service system differs from the key unit 13 of the personal user client quantum security service system in Embodiment 1 in that, in addition to the key receiving module 2301 and the key processing module 2302, the key unit 23 also includes a key generation module 2303, a key distribution module 2304 and a personal terminal connection module 2305. The key receiving module 2301 is connected to the key processing module 2302, and the key processing module 2302, the key generation module 2303 and the personal terminal connection module 2305 are all connected to the key distribution module 2304.

[0089] The key receiving module 2301 includes a key pool, and the key receiving module 2304 receives and stores the keys issued to the user terminal by the quantum security layer. The key processing module 2302 includes a buffer, and during user terminal communication, the key processing module 2302 extracts the key required for communication from the key pool of the key receiving module 2301 and stores it in the buffer of this module. Using the extracted key and through key relay of the quantum security layer, it generates a temporary session key with the communicating peer user, performs encryption, decryption, and hash operations on the key, and transmits the operation results to the interface unit. The key generation module 2303 generates quantum random numbers as required in this embodiment. In the example, the keys for the quantum-secure local area network are transmitted to the key distribution module 2304. The key distribution module 2304 then distributes the received keys to multiple personal terminals connected to the group user terminal. The personal terminal connection module 2305 is connected to the key distribution module 2304 and contains n key storage areas, where n is the number of personal terminals connected to the group user terminal. Each key storage area in the personal terminal connection module 2305 corresponds one-to-one with a personal terminal connected to the group user terminal, storing the paired key for the corresponding personal terminal. Each key storage area has a personal terminal key consumption threshold. When the personal terminal key consumption exceeds this threshold, a key replenishment operation is triggered.

[0090] Before a group of users can access the quantum security layer, they must register with it. Registration can be performed through a service point within the quantum security layer. This service point reports necessary information, such as the group user's identifier, to the quantum security layer's network management system, completing the registration process. If necessary, quantum encryption can be applied during the communication process of reporting group user information to protect user privacy.

[0091] The way group user-end quantum security service systems access the quantum security layer is as follows: Figure 6 As shown. The group user terminal equipped with the quantum security service system of the present invention reports group user information through the quantum security service system. After network access authentication by the quantum security layer, it joins the quantum security layer. The quantum security layer issues a key to the authenticated group user terminal for use during communication. The network access authentication process of the group user terminal is the same as the specific steps of quantum security authentication when the individual user terminal accesses the quantum security layer in Example 1.

[0092] Unlike individual user terminals accessing the quantum security layer, the group user's quantum security service system resides in a local area network containing n individual terminals. Each individual terminal connects to the group user's quantum security service system, which distributes individual terminal keys to the n individual terminals within the local area network. The key in each key storage area of ​​the individual terminal connection module 2305 is the same as the key of the individual terminal in that local area network, forming a pairing relationship. The individual terminal keys are stored in... Figure 1 The key pool of the key receiving module 1301 shown.

[0093] The following is as follows Figure 7 The following diagram illustrates the interaction process of the quantum security service system between personal terminals located in different group user local area networks. The first personal terminal is a personal terminal connected to the first group user terminal, and the second personal terminal is a personal terminal connected to the second group user terminal. The steps are as follows:

[0094] (1) Communication Request and Response: The first individual terminal initiates a communication request with the second individual terminal to the first group user terminal. The first individual terminal is a personal terminal connected to the first group user terminal, and the second individual terminal is a personal terminal connected to the second group user terminal. This communication request requires the first group user terminal to initiate quantum security authentication to the second group user terminal through the quantum security layer. When the local area network formed by the group user terminal and the personal terminal is untrusted, the communication request needs to be quantum security authenticated between the group user terminal and the personal terminal; otherwise, it is not required. If the second group user terminal and the second individual terminal respond to this communication in turn, the communication continues. Quantum security authentication can be performed on the response as needed.

[0095] (2) Establishing a key link: The network management system of the quantum security layer executes a routing algorithm to establish a key link between the first group user terminal and the second group user terminal;

[0096] (3) Generate session key: Extract a key string Ka of a specific length from the key of the first user terminal. After key relay between the first group user terminal, the quantum security layer and the second group user terminal, the second user terminal will obtain the same Ka as the session key for this communication. This step is similar to step (3) of the interaction method in Example 1. The only difference is that the first and last two processes of session key generation need to be added, and the encryption and decryption of Ka are performed by the first group user terminal and the second group user terminal respectively.

[0097] (4) Performing quantum-safe communication: The first and second personal terminals generate the same session key Ka. Both parties use this key to perform quantum-safe communication. Quantum-safe communication includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption and hash value calculation.

[0098] (5) Session key replenishment: The first and second personal terminals communicate through key Ka. If Ka is sufficient to support this communication, then Ka is used to complete this communication; if Ka is insufficient to support this communication, then steps (3) to (4) are repeated to obtain a new session key to complete this communication.

[0099] (6) User Key Replenishment: After communication ends, the keys of the first individual terminal, the second individual terminal, the first group user terminal, and the second group user terminal are partially consumed. The quantum security layer has a group user terminal key consumption threshold. If the key consumption of any group user terminal exceeds the set threshold, the network management system of the quantum security layer notifies the service point of the quantum security layer to replenish the key to the quantum security service system of that group user terminal for subsequent communication. The key storage area of ​​the personal terminal connection module of the group user terminal has a personal terminal key consumption threshold. If the key consumption of any individual terminal exceeds the set threshold, the corresponding group user terminal notifies the quantum security service system of that individual terminal to replenish the key for subsequent communication.

[0100] Example 3

[0101] like Figure 8 The following diagram illustrates the interaction process of a quantum-safe service system between two personal terminals located within the same group user local area network. Both the first and second personal terminals are personal terminals connected to the first group user terminal. The steps are as follows:

[0102] (1) Communication request and response: The first personal terminal initiates a communication request with the second personal terminal to the first group user terminal. Both the first personal terminal and the second personal terminal are personal terminals connected to the first group user terminal. When the local area network formed by the group user terminal and the personal terminal is untrusted, the communication request needs to be quantum-safely authenticated between the group user terminal and the personal terminal; otherwise, it is not required. If the second personal terminal responds to the communication request, the communication continues. The response can be quantum-safely authenticated as needed.

[0103] (2) Generate session key: Extract a key string of a specific length from the key of the first user terminal. Extract a key string of a specific length from the key of the second-person terminal. in and Since the keys are of the same length, after key relay by the first group of user terminals, the second user terminal will obtain the same key. This serves as the session key for this communication;

[0104] The specific process of key relay is as follows: the first group user terminal retrieves the same key from the key storage area of ​​the personal user connection module paired with the second personal terminal. To encrypt That is, perform the XOR operation. The result of the XOR operation is transmitted to the second terminal, which then decrypts the XOR result, i.e., performs the XOR operation again. Obtain the same session key as the first person's terminal. This serves as the session key for this communication.

[0105] (3) Performing quantum-secure communication: The first and second human terminals generate the same session key. Both parties use this key to perform quantum-safe communication, which includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption, and hash value calculation.

[0106] (4) Session key supplementation: The first and second personal terminals communicate via key. To communicate, if If sufficient to support this communication, then use Complete this communication; if If the key is insufficient to support the current communication, repeat steps (2) to (3) to obtain a new session key to complete the current communication.

[0107] (5) User key replenishment: After the communication ends, the keys of the first and second personal terminals are partially consumed; the key storage area of ​​the personal terminal connection module of the first group user terminal is equipped with a personal terminal key consumption threshold. If the key consumption of any personal terminal exceeds the set threshold, the first group user terminal notifies the quantum security service system of the personal terminal to replenish the key for subsequent communication.

[0108] Individual and group users can access the quantum security layer and obtain quantum security services through the quantum security service system described in this invention, providing security for communication between users.

[0109] The quantum security service system for users of this invention can be easily installed on users' existing hardware devices, such as mobile phones, PCs, tablets, quantum USB drives, quantum shields, super SIM cards, and servers, without the need to purchase additional hardware, which is convenient and cost-effective for users. After authentication, the user terminal with this system installed can be used as a legitimate device to access the quantum security layer and obtain quantum security services, ensuring the user's communication security.

Claims

1. A user-side quantum-safe service system, characterized in that: The system is installed on the user terminal and includes an interface unit, an information unit, and a key unit, both of which are connected to the interface unit. The interface unit is used to connect the system with other systems or programs in the hardware device, so that the quantum security service system can call data in other systems or programs or transmit data to other systems or programs during operation. The information unit includes an information processing module and an information reporting module connected to each other. The information processing module is used to read the necessary user terminal information when the user terminal accesses the quantum security layer for quantum security authentication, and to receive the authentication results sent by the quantum security layer and the information on the user terminal key consumption sent by the quantum security layer and to inform the key unit to replenish the key information. The information reporting module is used to report the read user terminal information to the quantum security layer for user network access authentication, to ensure that the user terminal can legally access the quantum security layer and obtain the corresponding quantum security services. When the user terminal is a group user terminal with multiple personal terminals connected to it, the key unit includes a key processing module, a key receiving module, a key distribution module, a key generation module, and a personal terminal connection module. The key receiving module is connected to the key processing module, and the key processing module, the key generation module, and the personal terminal connection module are all connected to the key distribution module. The key receiving module includes a key pool, used to receive and store keys issued to the user terminal by the quantum security layer. The key processing module includes a buffer, used to extract the necessary keys from the key pool of the key receiving module during user terminal communication, store them in the buffer, generate a temporary session key with the communicating peer using the extracted key and key relay through the quantum security layer, perform encryption, decryption, and hash operations on the key, and transmit the operation results to the interface unit. The key generation module generates quantum random numbers as keys and transmits these keys to the key distribution module. The key distribution module distributes the received keys to multiple personal terminals connected to the group user terminal. The personal terminal connection module contains n key storage areas, where n is the number of personal terminals connected to the group user terminal. Each key storage area corresponds one-to-one with a personal terminal connected to the group user terminal, storing the paired key for the corresponding personal terminal. The information processing module is also used to record the correspondence between personal terminals and group user terminals; When the user terminal is a personal user terminal, the key unit includes a key receiving module and a key processing module connected to each other. The key receiving module has a key pool and is used to receive and store the key issued to the user terminal by the quantum security layer. The key processing module has a buffer area and is used to extract the key required for communication from the key pool of the key receiving module and store it in the buffer area of ​​the module when the user terminal is communicating. The extracted key is used to generate a temporary session key with the communicating peer user through key relay of the quantum security layer. The key processing module also performs encryption, decryption, and hashing operations on the key and transmits the operation result information to the interface unit.

2. The quantum-safe service system for a user terminal according to claim 1, characterized in that: When the user terminal accesses the quantum security layer, the specific steps for quantum security authentication are as follows: (1) Initial key distribution: The key distribution unit in the quantum security layer distributes the initial key to the quantum security service system. The initial key is stored in the key pool of the key receiving module of the quantum security service system. At the same time, the key paired with the initial key is stored in the quantum security layer. (2) System installation: The quantum security service system is installed on the personal user terminal, which can be a mobile phone, PC, tablet, quantum security USB flash drive, quantum security shield, super SIM card or server equipment; (3) User information reporting: The information processing module in the quantum security service system reads user information and authentication timestamps from the personal client and forms a user authentication message. The user authentication message is reported to the quantum security layer through the information reporting module. (4) User information authentication: Quantum security authentication of messages between the personal client and the quantum security layer. After successful authentication, the personal client can access the quantum security layer normally and obtain quantum security services. (5) Return authentication results: Return the authentication results to the individual user terminal so that the user knows the authentication results and can use the quantum security service in the future.

3. The quantum-safe service system for a user terminal according to claim 1, characterized in that: The group user terminal and multiple connected personal terminals form a local area network. Each personal terminal in the group user terminal is equipped with a quantum security service system for individual users.

4. An interaction method for a user-end quantum-safe service system based on claim 1, characterized in that, Includes the following steps: (1) Communication request and response: The first user terminal that accesses the quantum security layer initiates a communication request with the second user terminal through the quantum security service system installed on the first user terminal. This communication request requires quantum security authentication. If the second user terminal responds to this communication request, the communication continues. (2) Establishing a key link: After receiving the communication request from the first user terminal, the network management system of the quantum security layer executes the routing algorithm according to the routing strategy of the network management system to establish a key link between the first user terminal and the second user terminal. (3) Generate session key: Extract a key of a specific length K1 from the key pool in the key receiving module of the quantum security service system of the first user terminal. After key relay of the key link, the second user terminal will obtain the same key K1 as the session key for this communication. (4) Performing quantum-safe communication: The first user terminal and the second user terminal generate the same session key K1. Both parties use this key to perform quantum-safe communication. Quantum-safe communication includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption and hash value calculation. (5) Session key replenishment: The first user terminal and the second user terminal communicate through key K1. If K1 is sufficient to support this communication, then K1 is used to complete this communication; if K1 is insufficient to support this communication, then steps (3) to (4) are repeated to obtain a new session key to complete this communication. (6) User key replenishment: After the communication ends, the keys of the first user terminal and the second user terminal are partially consumed; the quantum security layer has a user terminal key consumption threshold. If the key consumption of any user terminal exceeds the set threshold, the network management system of the quantum security layer notifies the service point of the quantum security layer to replenish the key to the quantum security service system of the user terminal for subsequent communication.

5. The interaction method according to claim 4, characterized in that: The key link in step (2) is composed of multiple paired nodes connected together. Each pair of paired nodes has the same paired key, and the second user terminal is the last node. The key relay process in step (3) is as follows: the specific length key K1 extracted by the first user terminal is encrypted and decrypted using two pairs of paired keys of the same length on the first paired node of the key link. Both encryption and decryption operations are binary XOR operations. This process is repeated until the last node, i.e. the second user terminal. Finally, the second user terminal will obtain the same key K1 as the session key for this communication.

6. An interaction method for a user-end quantum security service system based on claim 3, characterized in that, Includes the following steps: (1) Communication request and response: The first individual terminal initiates a communication request with the second individual terminal to the first group user terminal. The first individual terminal is a personal terminal connected to the first group user terminal, and the second individual terminal is a personal terminal connected to the second group user terminal. This communication request requires the first group user terminal to initiate quantum security authentication to the second group user terminal through the quantum security layer. When the local area network formed by the group user terminal and the personal terminal is untrusted, the communication request needs to be quantum security authenticated between the group user terminal and the personal terminal; otherwise, it is not required. If the second group user terminal and the second individual terminal respond to this communication in turn, the communication continues. (2) Establishing a key link: The network management system of the quantum security layer executes a routing algorithm to establish a key link between the first group user terminal and the second group user terminal; (3) Generate session key: Extract a key string Ka of a specific length from the key of the first human terminal, and after key relay through the first group user terminal, the quantum security layer and the second group user terminal, the second human terminal will obtain the same Ka as the session key for this communication. (4) Performing quantum-safe communication: The first and second personal terminals generate the same session key Ka. Both parties use this key to perform quantum-safe communication. Quantum-safe communication includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption and hash value calculation. (5) Session key replenishment: The first and second personal terminals communicate through key Ka. If Ka is sufficient to support this communication, then Ka is used to complete this communication; if Ka is insufficient to support this communication, then steps (3) to (4) are repeated to obtain a new session key to complete this communication. (6) User Key Replenishment: After communication ends, the keys of the first individual terminal, the second individual terminal, the first group user terminal, and the second group user terminal are partially consumed. The quantum security layer has a group user terminal key consumption threshold. If the key consumption of any group user terminal exceeds the set threshold, the network management system of the quantum security layer notifies the service point of the quantum security layer to replenish the key to the quantum security service system of that group user terminal for subsequent communication. The key storage area of ​​the personal terminal connection module of the group user terminal has a personal terminal key consumption threshold. If the key consumption of any individual terminal exceeds the set threshold, the corresponding group user terminal notifies the quantum security service system of that individual terminal to replenish the key for subsequent communication.

7. An interaction method for a user-end quantum security service system based on claim 3, characterized in that, Includes the following steps: (1) Communication request and response: The first personal terminal initiates a communication request with the second personal terminal to the first group user terminal. Both the first personal terminal and the second personal terminal are personal terminals connected to the first group user terminal. When the local area network formed by the group user terminal and the personal terminal is untrusted, the communication request needs to be quantum-safely authenticated between the group user terminal and the personal terminal. Otherwise, it is not necessary. If the second personal terminal responds to the communication request, the communication continues. (2) Generate session key: Extract a key string of a specific length from the key of the first user terminal. Extract a key string of a specific length from the key of the second-person terminal. After key relay by the first group of users, the second user terminal will obtain the same... This serves as the session key for this communication; (3) Performing quantum-secure communication: The first and second human terminals generate the same session key. Both parties use this key to perform quantum-safe communication, which includes, but is not limited to, using their respective session keys to perform quantum-safe encryption, decryption, and hash value calculation. (4) Session key supplementation: The first and second personal terminals communicate via key. To communicate, if If sufficient to support this communication, then use Complete this communication; if If the key is insufficient to support the current communication, repeat steps (2) to (3) to obtain a new session key to complete the current communication. (5) User key replenishment: After the communication ends, the keys of the first and second personal terminals are partially consumed; the key storage area of ​​the personal terminal connection module of the first group user terminal is equipped with a personal terminal key consumption threshold. If the key consumption of any personal terminal exceeds the set threshold, the first group user terminal notifies the quantum security service system of the personal terminal to replenish the key for subsequent communication.

8. The interaction method according to claim 7, characterized in that: The specific process of key relay in step (2) is as follows: the first group user terminal extracts the same key from the key storage area of ​​the personal user connection module paired with the second personal terminal. To encrypt That is, perform the XOR operation. The result of the XOR operation is transmitted to the second terminal, which then decrypts the result and performs the XOR operation again. Obtain the same session key as the first person's terminal. This serves as the session key for this communication.

9. The interaction method according to claim 6 or 7, characterized in that: The response requires quantum security authentication.

Citation Information

Patent Citations

  • A wide-area network quantum security layer networking system and method

    CN115603899B

  • Quantum communication service station, quantum key management device, key configuration network, and key configuration method

    CN106452740A

  • Mobile quantum random number supplementing device and system

    CN213279683U