A Secure Supplementary Method, Device, System and Medium for Quantum Keys
By establishing an encryption channel in the quantum key distribution system and decrypting the target key using a pre-save encryption key, the problems of reduced key count and reduced security are solved, and reliable supplementation and secure transmission of keys are achieved, and communication security is improved.
Patent Information
- Application Number
- CN202211290256.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-10-21
AI Technical Summary
In the existing quantum key distribution technology, the number of keys is constantly decreasing, which has caused the security of subsequent communication of the device to be threatened, and the flexibility of security patches and system upgrades is lacking, reducing the security and cost of key distribution.
By establishing an encryption channel between the key center and the quantum secure terminal, the received encryption target key is decrypted using the pre-saved encryption key, and the key pool is supplemented according to the supplementary encryption key, ensuring the security and continuous supply of the key.
It realizes reliable supplementation of keys, avoids plaintext transmission of keys during network transmission, improves the security and communication security of quantum keys, and reduces costs and internal security risks.
Smart Images

Figure CN115664654B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical fields of information security and quantum encryption technology, and particularly relates to a method, device, system and medium for securely supplementing quantum keys. Background Art
[0002] With the vigorous development of Internet technology, the importance of communication security is increasing day by day. In many situations, both communication parties hope to conduct confidential communication while using a public channel. For example, when a user submits an account number and password to an online bank, the user hopes that this information is confidential during the transmission process, that is, no third party can eavesdrop. The currently widely used encryption method is the public key encryption algorithm. Such algorithms are based on the algorithm complexity of certain mathematical problems. With the development of technology, their security is threatened. Therefore, we urgently need to develop a more secure and reliable encryption method.
[0003] Quantum key distribution technology is a brand-new key distribution solution based on the characteristics of quantum mechanics and is one of the most promising technologies in quantum information technology. This technology can combine the one-time pad encryption method, and the shared quantum key can be used to encrypt the data in the communication to ensure communication security. In this technology, quantum keys need to be continuously consumed for data encryption, resulting in a continuous reduction in the number of keys in the device using this technology. Therefore, how to securely supplement quantum keys is a prerequisite for ensuring the subsequent communication security of this device.
[0004] In related technologies, the key injection period of the QKD (Quantum Key Distribution) network can be set; every time a key injection period arrives, all the encryption services to be carried in this period are obtained, and key resources are allocated to each encryption service to be carried in this period in turn; every time a key injection period arrives, key resources are supplemented, and the amount of keys supplemented in this period is the amount of keys consumed for allocating key resources in the previous key injection period, so that key resources can be stably and efficiently supplemented during the process of the QKD network consuming key resources due to continuously carrying encryption services. For this quantum key distribution method, it is realized through physical layer communication. Users need dedicated optical fiber connections or hardware systems such as controlling free space transmission devices to establish a quantum key distribution channel before they can conduct key distribution, which makes it lack the flexibility of security patches and system upgrades, reduces the security of key distribution, increases the cost of key distribution and internal security risks, and limits many application scenarios. Summary of the Invention
[0005] This application provides a method, device, system and medium for securely supplementing quantum keys to achieve reliable key supplementation.
[0006] In a first aspect, the present application provides a method for securely supplementing quantum keys. The method is applied to a quantum security terminal and includes:
[0007] If an encrypted target key sent by a key center is received, decrypt the received encrypted key according to a pre-stored encryption key to obtain the target key; wherein, the target key includes a supplementary encryption key and a supplementary key;
[0008] Supplement the encryption key according to the supplementary encryption key, and supplement the key pool according to the supplementary key.
[0009] In a second aspect, the present application further provides a method for securely supplementing quantum keys. The method is applied to a key center and includes:
[0010] Encrypt a target key pre-assigned to a quantum security terminal based on the obtained encryption key to obtain an encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key;
[0011] Send the encrypted target key to the quantum security terminal.
[0012] In a third aspect, the present application further provides a device for securely supplementing quantum keys. The device is applied to a quantum security terminal and includes:
[0013] A receiving unit, configured to receive an encrypted target key sent by a key center; wherein, the target key includes a supplementary encryption key and a supplementary key;
[0014] A processing unit, configured to decrypt the received encrypted key according to a pre-stored encryption key to obtain the target key;
[0015] An updating unit, configured to supplement the encryption key according to the supplementary encryption key, and supplement the key pool according to the supplementary key.
[0016] In a fourth aspect, the present application further provides a device for securely supplementing quantum keys. The device is applied to a key center and includes:
[0017] An obtaining module, configured to obtain an encryption key;
[0018] An encrypting module, configured to encrypt a target key pre-assigned to a quantum security terminal based on the obtained encryption key to obtain an encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key;
[0019] A sending module, configured to send the encrypted target key to the quantum security terminal.
[0020] In a fifth aspect, the present application further provides a quantum secure terminal, which at least includes a processor and a memory. When the processor executes a computer program stored in the memory, the steps of the method for securely supplementing quantum keys as described in the first aspect above are implemented.
[0021] In a sixth aspect, the present application further provides a key center, which at least includes a processor and a memory. When the processor executes a computer program stored in the memory, the steps of the method for securely supplementing quantum keys as described in the second aspect above are implemented.
[0022] In a seventh aspect, the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the method for securely supplementing quantum keys as described in the first aspect above are implemented, or the steps of the method for securely supplementing quantum keys as described in the second aspect above are implemented.
[0023] In an eighth aspect, the present application further provides a computer program product, which includes: computer program code. When the computer program code runs on a computer, the computer is caused to execute the steps of the method for securely supplementing quantum keys as described in the first aspect above, or the steps of the method for securely supplementing quantum keys as described in the second aspect above are implemented.
[0024] In a ninth aspect, the present application further provides a system for securely supplementing quantum keys, which includes a quantum secure terminal that executes the method described in the first aspect and a key center that executes the method described in the second aspect.
[0025] The beneficial effects of the present application are as follows:
[0026] 1. Since the key center also obtains an encryption key when allocating a supplementary key to the quantum secure terminal, when the key center subsequently receives a download request from the quantum secure terminal, it can encrypt and send the supplementary key to the quantum secure terminal according to the encryption key, so that the supplementary key is not transmitted in plain text during network transmission, avoiding security problems such as the supplementary key being stolen or the supplementary key being tampered with, ensuring the security of the process of securely supplementing quantum keys, and thus improving the security of subsequent quantum secure communication.
[0027] 2. When the key center assigns supplementary keys to the quantum secure terminal, it also assigns supplementary encryption keys to the quantum secure terminal, and sends the supplementary encryption keys and supplementary keys to the quantum secure terminal, so that after the quantum secure terminal decrypts the obtained target key according to the saved encryption key, it can supplement the consumed encryption key according to the decrypted supplementary encryption key, thereby ensuring that the quantum secure terminal always stores the encryption key and can decrypt the next obtained encrypted target key based on the supplementary encryption key.
[0028] 3. Since the encryption key is pre-stored in the quantum secure terminal, the quantum secure terminal does not need to obtain the encryption key from the quantum secure base station, reducing the network resources consumed by the quantum secure terminal to obtain the encryption key from the quantum secure base station, and thus reducing the load of the quantum secure terminal and the quantum secure base station.
[0029] 4. There is no need for a dedicated optical fiber connection or a hardware system such as a free-space transmission device for control, reducing the cost of key distribution and internal security risks, avoiding reducing the security of key distribution due to the security problems of the hardware system itself, and expanding the application scenarios of key distribution. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1 Schematic diagram of a secure supplementary process of a quantum key provided by an embodiment of the present application;
[0032] Figure 2 Schematic diagram of a secure supplementary process of a quantum key provided by an embodiment of the present application;
[0033] Figure 3 Another schematic diagram of a secure supplementary process of a quantum key provided by an embodiment of the present application;
[0034] Figure 4 Schematic diagram of the structure of a key supplementary system provided by an embodiment of the present application;
[0035] Figure 5 Schematic diagram of the working process of a specific quantum key secure supplementary system provided by the present application;
[0036] Figure 6 Schematic diagram of the structure of a quantum key secure supplementary device provided by an embodiment of the present application;
[0037] Figure 7 Schematic structural diagram of another security supplement device for quantum key provided by an embodiment of the present application;
[0038] Figure 8 Schematic structural diagram of a quantum security terminal provided by an embodiment of the present application;
[0039] Figure 9 Schematic structural diagram of another key center provided by an embodiment of the present application. Specific embodiments
[0040] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present application.
[0041] In order to achieve the security supplement of the key, the present application provides a method, device, system, and medium for the security supplement of quantum key.
[0042] Embodiment 1:
[0043] Figure 1 Schematic diagram of a security supplement process for quantum key provided by an embodiment of the present application, and the process includes:
[0044] S101: If the encrypted target key sent by the key center is received, decrypt the received encrypted key according to the pre-saved encryption key to obtain the target key; wherein, the target key includes a supplementary encryption key and a supplementary key.
[0045] The method for the security supplement of quantum key provided by the present application is applied to a quantum security terminal, which can be an intelligent device, such as a global quantum security device, an isolation area device, etc., or a server, such as an application server, a business server, etc.
[0046] In a possible application scenario, a key is saved in the quantum security terminal, and this key can be used for aspects such as quantum encryption and decryption, quantum hash verification, etc. To ensure the security of quantum secure communication, the key saved in the quantum security terminal will only be used once, and the used key will be discarded, so that the unused keys in the quantum security terminal will become fewer and fewer. Therefore, in the present application, the quantum security terminal can obtain a supplementary key from the key center and perform key supplementation according to this supplementary key.
[0047] Considering the possible security issues during the process of the quantum-secure terminal downloading the supplementary key from the key center, the key center can encrypt and send the supplementary key to the quantum-secure terminal, that is, send the encrypted supplementary key to the quantum-secure terminal. For example, after receiving the first download request sent by the quantum-secure terminal, the key center can obtain the encryption key, and encrypt the supplementary key according to this encryption key, and send the encrypted supplementary key to the quantum-secure terminal.
[0048] After the quantum-secure terminal obtains the encrypted supplementary key sent by the key center, it can obtain the encryption key, and decrypt the received encrypted supplementary key according to this encryption key to obtain the supplementary key.
[0049] In a possible embodiment, the encryption key can be obtained by the quantum-secure terminal from the quantum-secure base station.
[0050] In another possible embodiment, considering that if the quantum-secure terminal obtains the encryption key from the quantum-secure base station, the process of the quantum-secure terminal obtaining the encryption key may consume a large amount of network resources between the quantum-secure terminal and the quantum-secure base station, and may even cause problems such as network congestion, increasing the load of the quantum-secure terminal and the quantum-secure base station. Based on this, in this application, the quantum-secure terminal can pre-save the encryption key locally. When the quantum-secure terminal receives the encrypted supplementary key sent by the key center, it can decrypt the received encrypted supplementary key according to the pre-saved encryption key to obtain the supplementary key.
[0051] Among them, the sources of the encryption key include one or more of the following: input by the staff after connecting the quantum-secure terminal to the key distributor; obtained from other devices; filled by the staff before the quantum-secure terminal leaves the factory.
[0052] For example, before the quantum-secure terminal leaves the factory, the staff can fill the quantum-secure terminal with the encryption key by connecting the key distributor. After the quantum-secure terminal leaves the factory, it can obtain the supplementary encryption key from the key center, so as to ensure that the encryption key is always saved in the quantum-secure terminal and does not occupy the network resources between the quantum-secure terminal and the quantum-secure base station.
[0053] Since the encryption key pre - stored in the quantum - safe terminal will be consumed during the process of decrypting the encrypted supplementary key, based on this, it is necessary to supplement the encryption key in the quantum - safe terminal. Exemplarily, the quantum - safe terminal can obtain the supplementary encryption key from the key center to supplement the consumed encryption key according to the supplementary encryption key. Exemplarily, the quantum - safe terminal can obtain the encrypted target key from the key center. Wherein, the target key includes the supplementary key and the supplementary encryption key. The quantum - safe terminal decrypts the encrypted target key according to the pre - stored encryption key to obtain the decrypted target key, so as to obtain the supplementary key and the supplementary encryption key sent by the key center.
[0054] In one example, before receiving the encrypted target key sent by the key center, the method further includes:
[0055] If it is determined that the key pool meets the preset key - supplement requirement, generate a key - supplement request and send it to the quantum - safe base station;
[0056] Obtain the allocation information sent by the quantum - safe base station; wherein, the allocation information includes the address of the key center, the first information of the supplementary key, and the second information of the supplementary encryption key;
[0057] Send a first download request to the key center at the address; wherein, the first download request is used to request the key center to send the encrypted supplementary key, and the first download request carries the first information and the second information.
[0058] To perform key supplementation in a timely manner, in this application, the quantum - safe terminal can be pre - configured with a key - supplement requirement to determine the timing of supplementing the key through the key - supplement requirement. Wherein, the key - supplement requirement can be that the number of keys already used in the key pool reaches a first preset threshold, the number of unused keys in the key pool is lower than a second preset threshold, etc. The quantum - safe terminal can monitor the usage of keys in the key pool. After determining that the key pool meets the preset key - supplement request, it can generate a key - supplement request and send the key - supplement request to the quantum - safe base station accessed by the quantum - safe terminal, so as to allocate a key center for the quantum - safe terminal through the quantum - safe base station and send the key - supplement request to the key center.
[0059] Wherein, the key - supplement request includes the number of keys to be supplemented in the key pool (supplementary quantity). Optionally, the key - supplement request can also include one or more of the following: the total data size of the keys to be supplemented in the key pool, the length of the keys to be supplemented in the key pool, etc.
[0060] After receiving the key supplementation request, the quantum-secure base station may send the key supplementation request to the key center, so that the key center can determine how to allocate a supplementary key to the quantum-secure terminal according to the information carried in the key supplementation request.
[0061] After receiving the key supplementation request, the key center responds to the key supplementation request and allocates a supplementary key and a supplementary encryption key to the quantum-secure terminal according to the information carried in the key supplementation request. After determining the supplementary key and the supplementary encryption key, the key center generates allocation information according to the information of the supplementary key (denoted as the first information), the information of the supplementary encryption key (denoted as the second information), and the address of the key center, and sends the allocation information to the quantum-secure base station, so that the quantum-secure base station can send the allocation information to the quantum-secure terminal.
[0062] Among them, the quantum-secure base station can send the allocation information to the quantum-secure terminal in plaintext, or encrypt and send the allocation information to the quantum-secure terminal. To facilitate the quantum-secure terminal to decrypt the allocation information, the key index (denoted as the first key index) of the key used to encrypt the allocation information will also be sent to the quantum-secure terminal.
[0063] It should be noted that the first information may include one or more of the following: the hash value of the supplementary key, the storage path of the supplementary key, the size of the supplementary key, the available status of the supplementary key, and the generation time of the supplementary key. The hash value of the supplementary key is obtained by performing a hash operation on the supplementary key. The second information may include one or more of the following: the hash value of the supplementary encryption key, the storage path of the supplementary encryption key, the size of the supplementary encryption key, the available status of the supplementary encryption key, and the generation time of the supplementary encryption key. The hash value of the supplementary encryption key is obtained by performing a hash operation on the supplementary encryption key.
[0064] After receiving the allocation information sent by the quantum-secure base station, the quantum-secure terminal can determine the address of the key center, the first information of the supplementary key, and the second information of the supplementary encryption key according to the allocation information. Then, a download request (denoted as the first download request) carrying the first information and the second information is sent to the key center at the address to obtain the supplementary key and the supplementary encryption key from the key center.
[0065] In one example, if the quantum-secure terminal receives the encrypted allocation information and the first key index, it obtains the key from the key pool according to the first key index. According to the key, the encrypted allocation information is decrypted to obtain the allocation information.
[0066] After the key center receives the first download request, it obtains the encryption key and the target key. According to the encryption key, it encrypts the target key and sends the encrypted target key to the quantum security terminal.
[0067] Among them, the key center can obtain the encryption key locally or from the quantum security base station.
[0068] Taking the case where the key center obtains the encryption key locally as an example, after the key center receives the first download request, it obtains the encryption key corresponding to the quantum security terminal pre-stored, encrypts the target key according to the encryption key, and sends the encrypted target key to the quantum security terminal.
[0069] Taking the case where the key center obtains the encryption key from the quantum security base station as an example, after the quantum security base station receives the allocation information sent by the key center, it obtains the encryption key corresponding to the quantum security terminal pre-stored and sends the encryption key to the key center. After receiving the encryption key, the key center can encrypt the target key according to the encryption key and send the encrypted target key to the quantum security terminal.
[0070] Among them, after the quantum security base station determines that the encryption key has been successfully sent to the key center, it can send a notification message to the quantum security terminal to notify the quantum security terminal that it can send the first download request to the key center, so as to avoid the situation that the quantum security terminal cannot obtain the target key after sending the first download request and ensure the reliability of key replenishment.
[0071] S102: Supplement the encryption key according to the supplementary encryption key, and supplement the key pool according to the supplementary key.
[0072] After obtaining the supplementary encryption key based on the above embodiment, the consumed encryption key can be supplemented according to the supplementary encryption key, so as to ensure that the encryption key is always stored in the quantum security terminal, so that the encrypted target key obtained next time can be decrypted based on the stored encryption key.
[0073] Similarly, after the quantum security terminal obtains the supplementary key, it can supplement the key pool of the quantum security terminal according to the supplementary key, so as to facilitate subsequent processing such as hash calculation and quantum encryption and decryption based on the keys in the key pool.
[0074] In a possible application scenario, considering the security issue that the encrypted supplementary key may be tampered with during transmission, the quantum security terminal can perform integrity verification on the encrypted target key after obtaining it, or the quantum security terminal can perform integrity verification on the target key after obtaining it. When it is determined that the target key has not been tampered with, that is, the encrypted target key passes the integrity verification, or the target key passes the integrity verification, the consumed encryption key can be supplemented according to the supplementary encryption key, and the key pool can be supplemented according to the supplementary key.
[0075] Since the quantum security base station is used for reliable transmission of the key relay message sent by the quantum security terminal, the quantum security base station needs to store the key paired with the quantum security terminal. Based on this, in this application, after obtaining the allocation information, the quantum security base station can obtain the supplementary key from the key center corresponding to this address, so as to supplement the key pool paired with the quantum security terminal in the quantum security base station according to the supplementary key.
[0076] In a possible implementation manner, the quantum security base station obtaining the supplementary key from the key center includes the following two cases:
[0077] Case 1: The encryption key obtained by the key center from the local.
[0078] The key center can store the encryption key corresponding to each quantum security terminal based on each quantum security terminal, so the quantum security base station does not need to obtain the encryption key of the quantum security terminal. Therefore, after the quantum security base station obtains the allocation information, it sends a download request (denoted as the third download request) to the key center to instruct the key center to send the supplementary key to the quantum security base station through this third download request. Among them, the third download request carries the address of the key center and the first information. After receiving the third download request sent by the quantum security base station, in response to this third download request, the key center sends the supplementary key corresponding to the first information to the quantum security base station.
[0079] After the quantum security base station obtains the supplementary key from the key center, the quantum security base station and the quantum security terminal can perform consistency verification on the supplementary keys obtained by each of them, so as to avoid that the supplementary key downloaded by the quantum security base station from the key center cannot be paired with the supplementary key downloaded by the quantum security terminal from the key center, thus affecting the reliability of subsequent quantum security communication.
[0080] Considering that the key center consumes the encryption key saved locally when encrypting the target key, based on this, after encrypting the target key according to the encryption key corresponding to the quantum security terminal saved locally, the key center can supplement the encryption key according to the obtained supplementary encryption key, so that the key center can encrypt the target key determined for the quantum security terminal next time according to the supplementary encryption key.
[0081] After the quantum security terminal determines that the obtained target key passes the consistency check, it supplements the consumed encryption key according to the supplementary encryption key, and supplements the key pool of the quantum security terminal according to the supplementary key; otherwise, the quantum security terminal reinitiates a key supplementation request.
[0082] Similarly, after the quantum security base station determines that the obtained target key passes the consistency check, it supplements the key pool corresponding to the quantum security terminal according to the supplementary key; otherwise, the quantum security base station discards the obtained supplementary key.
[0083] In one example, the key center can perform a consistency check on the supplementary encryption key through the quantum security base station and the quantum security terminal to ensure that the supplementary encryption key saved by the key center is consistent with the supplementary encryption key downloaded by the quantum security terminal. Exemplarily, the key center can determine the check code (denoted as the second check code) of the supplementary encryption key according to the saved supplementary encryption key and the preconfigured consistency check algorithm (such as, hash algorithm, etc.). Then the key center sends the second check code to the quantum security base station. After obtaining the second check code, the quantum security base station can perform a consistency check on the supplementary encryption key with the quantum security terminal according to the second check code to determine that the supplementary encryption key downloaded by the quantum security terminal is consistent with the supplementary encryption key saved by the key center.
[0084] For example, the quantum security terminal can determine the check code (denoted as the first check code) of the supplementary encryption key according to the downloaded supplementary encryption key and the preconfigured consistency check algorithm. The quantum security terminal determines whether the supplementary encryption key is consistent with the supplementary encryption key saved by the key center by determining whether the first check code is consistent with the second check code obtained by the quantum security base station. Specifically, if the quantum security terminal determines that the first check code is consistent with the second check code obtained by the quantum security base station, it determines that the supplementary encryption key is consistent with the supplementary encryption key saved by the key center; otherwise, it determines that the supplementary encryption key is inconsistent with the supplementary encryption key saved by the key center.
[0085] When the quantum - secure terminal determines that the downloaded supplementary encryption key passes the consistency check, it supplements the consumed encryption key according to the supplementary encryption key. Exemplarily, if the key center encrypts the supplementary key based on the pre - saved encryption key to obtain it, after obtaining the target key, before supplementing the encryption key according to the supplementary encryption key and supplementing the key pool according to the supplementary key, the method further includes:
[0086] Determine that the supplementary key passes the consistency check with the supplementary key downloaded by the quantum - secure base station, and determine that the supplementary encryption key passes the consistency check with the supplementary encryption key saved by the key center;
[0087] Among them, determining that the supplementary encryption key passes the consistency check with the supplementary encryption key saved by the key center includes:
[0088] If the first check code of the supplementary encryption key is consistent with the second check code obtained by the quantum - secure base station from the key center, it is determined that the supplementary encryption key passes the consistency check with the supplementary encryption key saved by the key center; where the second check code is determined by the key center according to the saved supplementary encryption key and a preset consistency check algorithm.
[0089] Case 2: The key center obtains the encryption key from the quantum - secure base station.
[0090] Considering that the key center saves the corresponding encryption keys for different quantum - secure terminals, which will consume a large amount of resources of the key center, and subsequent quantum - secure terminals may obtain the target key from another key center. Based on this, the encryption key corresponding to the quantum - secure terminal can be saved in the quantum - secure base station. Subsequently, no matter which key center is assigned to the quantum - secure terminal, the key center can obtain the encryption key corresponding to the quantum - secure terminal from the quantum - secure base station accessed by the quantum - secure terminal, and then encrypt the target key according to the encryption key. In this case, the encryption keys saved in the quantum - secure base station will be consumed. Based on this, the quantum - secure base station also needs to supplement the saved encryption keys. Exemplarily, after the quantum - secure base station determines that the encryption key is successfully sent to the key center, it sends a download request (denoted as the second download request) to the key center to instruct the key center to send the supplementary key and the supplementary encryption key to the quantum - secure base station through the second download request. Wherein, the second download request carries the address of the key center, the first information, and the second information. After receiving the second download request sent by the quantum - secure base station, in response to the second download request, the key center sends the supplementary key corresponding to the first information and the supplementary encryption key corresponding to the second information to the quantum - secure base station.
[0091] After the quantum-secure base station obtains the target key from the key center, the quantum-secure base station and the quantum-secure terminal can perform a consistency check on the target keys they obtained respectively, so as to avoid the situation that the target key downloaded by the quantum-secure base station from the key center cannot be paired with the target key downloaded by the quantum-secure terminal from the key center, thus affecting the reliability of subsequent quantum-secure communication.
[0092] After the quantum-secure terminal determines that the obtained target key passes the consistency check, it replenishes the consumed encryption key according to the supplementary encryption key, and replenishes the key pool of the quantum-secure terminal according to this supplementary key; otherwise, the quantum-secure terminal reinitiates a key replenishment request.
[0093] Similarly, after the quantum-secure base station determines that the obtained target key passes the consistency check, it replenishes the encryption key corresponding to the quantum-secure terminal according to the supplementary encryption key, and replenishes the key pool corresponding to the quantum-secure terminal according to this supplementary key; otherwise, the quantum-secure base station discards the obtained target key.
[0094] The beneficial effects of this application are as follows:
[0095] 1. Since the key center also obtains the encryption key when allocating the supplementary key for the quantum-secure terminal, when the key center receives the download request from the quantum-secure terminal subsequently, it can encrypt and send the supplementary key to the quantum-secure terminal according to this encryption key, so that the supplementary key is not transmitted in plain text during the network transmission process, avoiding security problems such as the supplementary key being stolen or the supplementary key being tampered with, ensuring the security of the quantum key replenishment process, and thus improving the security of subsequent quantum-secure communication.
[0096] 2. When the key center allocates the supplementary key for the quantum-secure terminal, it also allocates a supplementary encryption key for the quantum-secure terminal and sends the supplementary encryption key and the supplementary key to the quantum-secure terminal. After the quantum-secure terminal decrypts the obtained target key according to the saved encryption key, it can replenish the consumed encryption key according to the decrypted supplementary encryption key, so as to ensure that the quantum-secure terminal always stores the encryption key and can decrypt the next obtained encrypted target key based on this supplementary encryption key.
[0097] 3. Since the encryption key is pre-stored in the quantum-secure terminal, the quantum-secure terminal does not need to obtain the encryption key from the quantum-secure base station, reducing the network resources consumed by the quantum-secure terminal to obtain the encryption key from the quantum-secure base station, and thus reducing the load of the quantum-secure terminal and the quantum-secure base station.
[0098] 4. There is no need for a dedicated optical fiber connection or a hardware system such as a free - space transmitting device for control, which reduces the cost of key distribution and internal security risks, avoids reducing the security of key distribution due to the security problems of the hardware system itself, and broadens the application scenarios of key distribution.
[0099] Embodiment 2:
[0100] Based on the above - mentioned embodiment, in the present application, the encryption key saved before the quantum security terminal first performs key supplementation can be filled into the quantum security terminal by the staff through a key distributor before the quantum security terminal leaves the factory. Based on this, the key center needs to obtain the encryption key filled into the quantum security terminal by the key distributor in order to encrypt the target key first allocated to the quantum security terminal according to the encryption key.
[0101] In one example, the staff can save the keys filled before the quantum security terminal leaves the factory (including the keys in the key pool when the quantum security terminal leaves the factory and the encryption key) in the factory - out key management device (such as the root key center). After the quantum security terminal leaves the factory and accesses the quantum security base station, the quantum security base station can obtain the keys in the quantum security terminal from the factory - out key management device, that is, synchronize the keys with the quantum security terminal, so that the subsequent key center can obtain the encryption key filled into the quantum security terminal before leaving the factory from the quantum security base station.
[0102] Embodiment 3:
[0103] The key management method provided by the present application will be described in detail through specific embodiments below. Figure 2 It is a schematic diagram of the security supplementation process of a quantum key provided by an embodiment of the present application. Taking the quantum security terminal as the execution subject, the process includes:
[0104] S201: If it is determined that the quantum security base station is not accessed, an access request is sent to the quantum security base station.
[0105] Among them, the access request carries device identification information.
[0106] S202: Receive the access feedback information sent by the quantum security base station.
[0107] S203: Determine that the access feedback information carries information that the quantum security base station supports online key distribution.
[0108] S204: If it is determined that the number of used keys has reached a preset threshold, a key supplementation request is generated and sent to the quantum security base station.
[0109] After the quantum - secure base station receives the key - supplement request, it can send a query request to the network management device. After the network management device receives the query request, according to the allocation policies such as the load and working status of each key center, it allocates a key center for the quantum - secure base station and sends the address of the allocated key center to the quantum - secure base station. For example, the network management device allocates the key center with the lowest load to the quantum - secure base station and sends the address of the allocated key center to the quantum - secure base station. After the quantum - secure base station determines the key center, it sends the key - supplement request to the key center so that the key center can, according to the information carried in the key - supplement request, allocate a target key for the quantum - secure terminal.
[0110] After the key center determines the supplementary key and the supplementary encryption key, the key center can generate allocation information based on the address of the key center, the first information of the supplementary key, and the second information of the supplementary encryption key. Then it sends the allocation information to the quantum - secure base station so that the quantum - secure base station can send the allocation information to the quantum - secure terminal.
[0111] After the quantum - secure base station receives the allocation information, it can directly send the allocation information to the quantum - secure terminal, or it can encrypt the allocation information according to the key paired with the quantum - secure terminal and send the encrypted allocation information to the quantum - secure terminal.
[0112] S205: Receive the encrypted allocation information and the key index sent by the quantum - secure base station.
[0113] S206: Determine the key according to the received key index, and decrypt the encrypted allocation information according to the key to obtain the allocation information.
[0114] S207: Send a first download request to the key center at the address in the allocation information.
[0115] After the quantum - secure terminal receives the allocation information, it sends a first download request carrying the first information and the second information to the key center at the address so that the key center encrypts and sends the supplementary key and the supplementary encryption key to the quantum - secure terminal based on the encryption key.
[0116] In a possible implementation, after obtaining the allocation information, the quantum-secure terminal may send the encryption key to the key center so that the key center can encrypt the target key based on the encryption key. In this case, after determining that the encryption key has been successfully sent, the quantum-secure base station may send a notification message to the quantum-secure terminal to notify the quantum-secure terminal that it can send a first download request to the key center. And, after determining that the encryption key has been successfully sent, the quantum-secure base station may download the target key from the key center according to the allocation information, so as to supplement the consumed encryption key according to the supplementary encryption key in the target key, and supplement the key pool corresponding to the quantum-secure terminal saved according to the supplementary key in the target key.
[0117] S208: Receive the encrypted target key sent by the key center.
[0118] S209: Decrypt the encrypted target key according to the pre-saved encryption key to obtain the target key.
[0119] If the target key is the first one obtained by the quantum-secure terminal after leaving the factory, the encryption key is filled in by connecting to the key distributor before the quantum-secure terminal leaves the factory.
[0120] If the target key is not the first one obtained by the quantum-secure terminal after leaving the factory, the encryption key is the supplementary encryption key obtained by the quantum-secure terminal from the key center last time.
[0121] S210: Perform integrity verification on the target key.
[0122] S211: If the target key passes the integrity verification, perform consistency verification on the target key and the target key downloaded by the quantum-secure base station.
[0123] In another example, if the quantum-secure base station only downloads the supplementary key from the key center, that is, the quantum-secure terminal is not used to save the encryption key corresponding to the quantum-secure terminal, perform consistency verification on the supplementary key in the target key and the supplementary key downloaded by the quantum-secure base station.
[0124] In one example, the key center can perform consistency verification on the supplementary encryption key with the quantum - secure terminal through a quantum - secure base station to ensure that the supplementary encryption key saved by the key center is consistent with the supplementary encryption key downloaded by the quantum - secure terminal. Exemplarily, the key center can determine a second verification code of the supplementary encryption key according to the saved supplementary encryption key and a pre - configured consistency verification algorithm (such as, a hash algorithm, etc.). Then the key center sends the second verification code to the quantum - secure base station. After obtaining the second verification code, the quantum - secure base station can perform consistency verification on the supplementary encryption key with the quantum - secure terminal according to the second verification code to determine that the supplementary encryption key downloaded by the quantum - secure terminal is consistent with the supplementary encryption key saved by the key center.
[0125] For example, the quantum - secure terminal can determine a first verification code of the supplementary encryption key according to the downloaded supplementary encryption key and a pre - configured consistency verification algorithm. The quantum - secure terminal determines whether the supplementary encryption key is consistent with the supplementary encryption key saved by the key center by determining whether the first verification code is consistent with the second verification code obtained by the quantum - secure base station. Specifically, if the quantum - secure terminal determines that the first verification code is consistent with the second verification code obtained by the quantum - secure base station, it determines that the supplementary encryption key is consistent with the supplementary encryption key saved by the key center; otherwise, it determines that the supplementary encryption key is inconsistent with the supplementary encryption key saved by the key center.
[0126] When the quantum - secure terminal determines that the downloaded supplementary encryption key passes the consistency verification, it supplements the consumed encryption key according to the supplementary encryption key.
[0127] S212: If it is determined that the target key passes the consistency verification, then supplement the consumed encryption key according to the supplementary encryption key, and supplement the key pool of the quantum - secure terminal according to the supplementary key.
[0128] Embodiment 4:
[0129] The present application also provides a method for securely supplementing quantum keys, and the method is applied to a key center. Figure 3 For another schematic diagram of the secure supplementary process of quantum keys provided by the embodiments of the present application, the process includes:
[0130] S301: Encrypt the target key pre - allocated for the quantum - secure terminal based on the obtained encryption key to obtain the encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key.
[0131] In this embodiment, the security supplement method for the quantum key is applied to a key center, which can be an intelligent device, such as a global quantum security device, an isolation area device, etc., or a server, such as an application server, a business server, etc.
[0132] In this application, the key center is used to cache a large number of keys and allocate target keys (including supplementary keys and supplementary encryption keys) to each quantum security terminal.
[0133] When the key center needs to send a target key to a quantum security terminal, it can obtain an encryption key, and then encrypt the target key pre-allocated to the quantum security terminal according to the encryption key to obtain the encrypted target key.
[0134] In one example, before encrypting the target key pre-allocated to the quantum security terminal based on the obtained encryption key to obtain the encrypted target key, the method further includes:
[0135] Receiving a key supplement request sent by a quantum security base station; wherein, the key supplement request is used to instruct the key center to allocate a target key to the quantum security terminal;
[0136] In response to the key supplement request, allocating the target key;
[0137] Determining allocation information according to the information of the target key and the address of the key center and sending the allocation information to the quantum security base station, so that the quantum security base station sends the allocation information to the quantum security terminal; wherein, the information of the target key includes the first information of the supplementary key and the second information of the supplementary encryption key;
[0138] Receiving a first download request sent by the quantum security terminal; wherein, the first download request carries the allocation information.
[0139] To perform key supplement in a timely manner, in this application, a key supplement requirement can be pre-configured in the quantum security terminal to determine the timing of the supplementary key through the key supplement requirement. Among them, the key supplement requirement can be that the number of used keys in the key pool reaches a first preset threshold, the number of unused keys in the key pool is lower than a second preset threshold, etc. The quantum security terminal can monitor the usage of keys in the key pool. After determining that the preset key supplement request is met in the key pool, it can generate a key supplement request and send the key supplement request to the quantum security base station accessed by the quantum security terminal, so as to allocate a key center for the quantum security terminal through the quantum security base station and send the key supplement request to the key center.
[0140] Among them, the key replenishment request includes the number of keys (replenishment quantity) required to be replenished in the key pool. Optionally, the key replenishment request may further include one or more of the following: the total data size of the keys required to be replenished in the key pool, the length of the keys required to be replenished in the key pool, etc.
[0141] After receiving the key replenishment request, the quantum-secure base station may send the key replenishment request to the key center, so that the key center can determine how to allocate replenishment keys to the quantum-secure terminal according to the information carried in the key replenishment request.
[0142] After receiving the key replenishment request, the key center responds to the key replenishment request, and allocates replenishment keys and replenishment encryption keys to the quantum-secure terminal according to the information carried in the key replenishment request. After determining the replenishment keys and the replenishment encryption keys, according to the information of the replenishment keys (denoted as the first information), the information of the replenishment encryption keys (denoted as the second information), and the address of the key center, generate allocation information, and send the allocation information to the quantum-secure base station, so as to send the allocation information to the quantum-secure terminal through the quantum-secure base station.
[0143] In one example, the key center determines the replenishment keys and the replenishment encryption keys according to the information carried in the key replenishment request and a pre-configured allocation rule. For example, according to the information carried in the key replenishment request, determine the first quantity of the replenishment keys required. According to the pre-configured encryption ratio and the target quantity, determine the second quantity of the replenishment encryption keys required. Sequentially obtain the first quantity of replenishment keys and the second quantity of replenishment encryption keys from the cached keys, etc.
[0144] Among them, the quantum-secure base station may send the allocation information in plaintext to the quantum-secure terminal, or encrypt and send the allocation information to the quantum-secure terminal. And for the convenience of the quantum-secure terminal to decrypt the allocation information, it will also send the key index (denoted as the first key index) of the key used to encrypt the allocation information to the quantum-secure terminal.
[0145] It should be noted that the first information may include one or more of the following: the hash value of the replenishment key, the storage path of the replenishment key, the size of the replenishment key, the available status of the replenishment key, and the generation time of the replenishment key. The hash value of the replenishment key is obtained by performing a hash operation on the replenishment key. The second information may include one or more of the following: the hash value of the replenishment encryption key, the storage path of the replenishment encryption key, the size of the replenishment encryption key, the available status of the replenishment encryption key, and the generation time of the replenishment encryption key. The hash value of the replenishment encryption key is obtained by performing a hash operation on the replenishment encryption key.
[0146] After receiving the allocation information sent by the quantum-secure base station, the quantum-secure terminal can determine the address of the key center, the first information of the supplementary key, and the second information of the supplementary encryption key according to the allocation information. Then, a download request (denoted as the first download request) carrying the first information and the second information is sent to the key center at this address to obtain the supplementary key and the supplementary encryption key from the key center.
[0147] In one example, if the quantum-secure terminal receives the encrypted allocation information and the first key index, it obtains the key from the key pool according to the first key index. The encrypted allocation information is decrypted according to the key to obtain the allocation information.
[0148] After obtaining the first download request, the key center obtains the encryption key and the target key. The target key is encrypted according to the encryption key, and the encrypted target key is sent to the quantum-secure terminal.
[0149] Exemplarily, the method for the key center to obtain the encryption key is described below:
[0150] Method A: Taking the key center obtaining the encryption key locally as an example, the key center obtains the encryption key corresponding to the quantum-secure terminal pre-stored, encrypts the target key according to the encryption key, and sends the encrypted target key to the quantum-secure terminal.
[0151] Among them, the encryption key may be determined according to the supplementary encryption key previously allocated by the key center for the quantum-secure terminal.
[0152] In one example, since the encryption key saved by the quantum-secure terminal before the first key supplement can be filled by connecting to the key distribution machine before the quantum-secure terminal leaves the factory, the key center needs to obtain the filled encryption key. Based on this, the staff can save the keys filled before the quantum-secure terminal leaves the factory (including the keys in the key pool and the encryption key when the quantum-secure terminal leaves the factory) in the factory key management device (such as the root key center). After the quantum-secure terminal leaves the factory and accesses the quantum-secure base station, the quantum-secure base station can obtain the keys in the quantum-secure terminal from the factory key management device, that is, synchronize the keys with the quantum-secure terminal. When the key center does not save the encryption key corresponding to the quantum-secure terminal, it can obtain the encryption key filled before the quantum-secure terminal leaves the factory from the quantum-secure base station.
[0153] Method B: Taking the key center obtaining the encryption key from the quantum-secure base station as an example, after the quantum-secure base station obtains the allocation information sent by the key center, it obtains the encryption key corresponding to the quantum-secure terminal pre-stored and sends the encryption key to the key center.
[0154] Among them, after the quantum - secure base station determines that the encryption key has been successfully sent to the key center, it can send a notification message to the quantum - secure terminal to notify the quantum - secure terminal that it can send a first download request to the key center, thereby avoiding the situation where the quantum - secure terminal cannot obtain the target key after sending the first download request and ensuring the reliability of key replenishment.
[0155] After the key center receives the first download request, it encrypts the target key according to the encryption key and sends the encrypted target key to the quantum - secure terminal.
[0156] S302: Send the encrypted target key to the quantum - secure terminal.
[0157] After obtaining the encrypted target key based on the above - mentioned embodiment, the key center can send the encrypted target key to the quantum - secure terminal, so that the quantum - secure terminal can decrypt the encrypted target key based on the pre - saved encryption key to obtain the target key. According to the supplementary encryption key in the target key, the consumed encryption key is replenished, and according to the supplementary key, the key pool of the quantum - secure terminal is replenished.
[0158] Since the quantum - secure base station is used for reliable transmission of the key relay message sent by the quantum - secure terminal, the quantum - secure base station needs to store the key paired with the quantum - secure terminal. Based on this, in this application, after the quantum - secure base station obtains the allocation information, it can obtain the supplementary key from the key center at this address to replenish the key pool paired with the quantum - secure terminal in the quantum - secure base station according to the supplementary key.
[0159] In a possible implementation manner, the quantum - secure base station obtaining the supplementary key from the key center includes the following two cases:
[0160] Case 1: The encryption key obtained by the key center from the local.
[0161] The key center can save the encryption key corresponding to each quantum - secure terminal. Then the quantum - secure base station does not need to obtain the encryption key of the quantum - secure terminal. Therefore, after the quantum - secure base station obtains the allocation information, it sends a download request (denoted as the third download request) to the key center to instruct the key center to send the supplementary key to the quantum - secure base station through the third download request. Among them, the third download request carries the address of the key center and the first information. After the key center receives the third download request sent by the quantum - secure base station, in response to the third download request, it sends the supplementary key corresponding to the first information to the quantum - secure base station.
[0162] After the quantum-secure base station obtains the supplementary key from the key center, the quantum-secure base station and the quantum-secure terminal can perform a consistency check on the obtained supplementary keys respectively, so as to avoid the situation that the supplementary key downloaded by the quantum-secure base station from the key center cannot be paired with the supplementary key downloaded by the quantum-secure terminal from the key center, thus affecting the reliability of subsequent quantum-secure communication.
[0163] Considering that the key center will consume the encryption key saved locally when encrypting the target key, based on this, after encrypting the target key according to the encryption key corresponding to the quantum-secure terminal saved locally, the key center can supplement the encryption key according to the obtained supplementary encryption key, so that the key center can use the supplementary encryption key to encrypt the target key determined for the quantum-secure terminal next time.
[0164] After the quantum-secure terminal determines that the obtained target key passes the consistency check, it supplements the consumed encryption key according to the supplementary encryption key, and supplements the key pool of the quantum-secure terminal according to the supplementary key; otherwise, the quantum-secure terminal reinitiates a key supplementation request.
[0165] Similarly, after the quantum-secure base station determines that the obtained target key passes the consistency check, it supplements the key pool corresponding to the quantum-secure terminal according to the supplementary key; otherwise, the quantum-secure base station discards the obtained supplementary key.
[0166] In one example, the key center can perform a consistency check on the supplementary encryption key through the quantum-secure base station and the quantum-secure terminal to ensure that the supplementary encryption key saved by the key center is consistent with the supplementary encryption key downloaded by the quantum-secure terminal. Exemplarily, the key center can determine the check code (denoted as the second check code) of the supplementary encryption key according to the saved supplementary encryption key and the preconfigured consistency check algorithm (such as, hash algorithm, etc.). Then the key center sends the second check code to the quantum-secure base station. After obtaining the second check code, the quantum-secure base station can perform a consistency check on the supplementary encryption key with the quantum-secure terminal according to the second check code to determine that the supplementary encryption key downloaded by the quantum-secure terminal is consistent with the supplementary encryption key saved by the key center.
[0167] For example, the quantum-secure terminal can determine the verification code of the supplementary encryption key (denoted as the first verification code) according to the downloaded supplementary encryption key and the pre-configured consistency verification algorithm. The quantum-secure terminal determines whether the supplementary encryption key is consistent with the supplementary encryption key stored in the key center by determining whether the first verification code is consistent with the second verification code obtained by the quantum-secure base station. Specifically, if the quantum-secure terminal determines that the first verification code is consistent with the second verification code obtained by the quantum-secure base station, it determines that the supplementary encryption key is consistent with the supplementary encryption key stored in the key center; otherwise, it determines that the supplementary encryption key is inconsistent with the supplementary encryption key stored in the key center.
[0168] When the quantum-secure terminal determines that the downloaded supplementary encryption key passes the consistency verification, it supplements the consumed encryption key according to the supplementary encryption key. Exemplarily, if the key center encrypts the supplementary key based on the pre-stored encryption key and obtains it, after obtaining the target key, before supplementing the encryption key according to the supplementary encryption key and supplementing the key pool according to the supplementary key, the method further includes:
[0169] Determine that the supplementary key is consistent with the supplementary key downloaded by the quantum-secure base station through consistency verification, and determine that the supplementary encryption key is consistent with the supplementary encryption key stored in the key center through consistency verification;
[0170] Among them, determining that the supplementary encryption key is consistent with the supplementary encryption key stored in the key center through consistency verification includes:
[0171] If the first verification code of the supplementary encryption key is consistent with the second verification code obtained by the quantum-secure base station from the key center, it is determined that the supplementary encryption key is consistent with the supplementary encryption key stored in the key center through consistency verification; among them, the second verification code is determined by the key center according to the stored supplementary encryption key and the preset consistency verification algorithm.
[0172] Case 2: The key center obtains the encryption key from the quantum-secure base station.
[0173] Considering that the key center saves the corresponding encryption keys based on different quantum security terminals, which will consume a large amount of resources of the key center, and subsequent quantum security terminals may obtain the target key from another key center. Based on this, the encryption key corresponding to the quantum security terminal can be saved in the quantum security base station. Subsequently, no matter which key center is assigned to the quantum security terminal, the key center can obtain the encryption key corresponding to the quantum security terminal from the quantum security base station accessed by the quantum security terminal, and then encrypt the target key according to the encryption key. In this case, the encryption keys saved in the quantum security base station will be consumed. Based on this, the quantum security base station also needs to replenish the saved encryption keys. Exemplarily, after the quantum security base station determines that the encryption key has been successfully sent to the key center, it sends a download request (denoted as the second download request) to the key center to indicate to the key center to send the supplementary key and the supplementary encryption key to the quantum security base station through the second download request. Wherein, the second download request carries the address of the key center, the first information, and the second information. After receiving the second download request sent by the quantum security base station, the key center, in response to the second download request, sends the supplementary key corresponding to the first information and the supplementary encryption key corresponding to the second information to the quantum security base station.
[0174] After the quantum security base station obtains the target key from the key center, the quantum security base station and the quantum security terminal can perform consistency verification on the target keys obtained by each of them, so as to avoid the situation that the target key downloaded by the quantum security base station from the key center cannot be paired with the target key downloaded by the quantum security terminal from the key center, thus affecting the reliability of subsequent quantum security communication.
[0175] After the quantum security terminal determines that the obtained target key passes the consistency verification, it replenishes the consumed encryption key according to the supplementary encryption key, and replenishes the key pool of the quantum security terminal according to the supplementary key; otherwise, the quantum security terminal reinitiates a key replenishment request.
[0176] Similarly, after the quantum security base station determines that the obtained target key passes the consistency verification, it replenishes the encryption key corresponding to the quantum security terminal according to the supplementary encryption key, and replenishes the key pool corresponding to the quantum security terminal according to the supplementary key; otherwise, the quantum security base station discards the obtained target key.
[0177] Embodiment 5:
[0178] The present application also provides a quantum key security replenishment system. Figure 4 FIG. 4 is a schematic structural diagram of a key replenishment system provided for an embodiment of the present application. The system includes a quantum security terminal 41 that implements the method described in Embodiments 1-3 above, and a key center 42 that implements the method described in Embodiment 4 above.
[0179] It should be noted that the principle of the security supplement system for the quantum key to solve problems has been elaborated in the above embodiments. For specific details, please refer to the content in the above embodiments, and no repeated description will be given here.
[0180] The working process of the security supplement system for the quantum key provided by the present application will be described below through specific embodiments. Figure 5 FIG. is a schematic diagram of the working process of the security supplement system for the specific quantum key provided by the present application. The process includes:
[0181] S501: The quantum security terminal determines that it is not connected to the quantum security base station and sends an access request to the quantum security base station.
[0182] S502: After receiving the access request, if the quantum security base station determines that the quantum security terminal is allowed to access the quantum security base station, it sends the first access feedback information to the quantum security terminal.
[0183] Among them, the first access feedback information carries the information that the quantum security base station supports online key distribution.
[0184] S503: After receiving the first access feedback information, if the quantum security terminal determines that the number of used keys has reached the preset threshold, it generates a key supplement request and sends it to the quantum security base station.
[0185] S504: After receiving the key supplement request, the quantum security base station determines the key center that allocates keys for the quantum security terminal and sends the key supplement request to the key center.
[0186] After obtaining the key supplement request, the quantum security base station may send a query request to the network management device. After receiving the query request, the network management device allocates a key center for the quantum security base station according to distribution policies such as the load and working status of each key center, and sends the address of the allocated key center to the quantum security base station. For example, the network management device allocates the key center with the lowest load to the quantum security base station and sends the address of the allocated key center to the quantum security base station. After determining the key center, the quantum security base station sends the key supplement request to the key center so that the key center can allocate keys for the quantum security terminal according to the information carried in the key supplement request.
[0187] S505: After receiving the key supplement request, the key center allocates a target key for the quantum security terminal, generates allocation information according to the address of the key center and the information of the target key, and sends the allocation information to the quantum security base station.
[0188] Among them, the target key includes a supplementary key and a supplementary encryption key.
[0189] In one example, the key center determines the supplementary key and the supplementary encryption key according to the information carried in the key supplementation request and the pre-configured allocation rule. For example, according to the information carried in the key supplementation request, the first quantity of the required supplementary key is determined. According to the pre-configured encryption ratio and the target quantity, the second quantity of the required supplementary encryption key is determined. The first quantity of supplementary keys and the second quantity of supplementary encryption keys are sequentially obtained from the cached keys, etc.
[0190] S506: After receiving the allocation information, the quantum-secure base station encrypts the allocation information according to the first key paired with the quantum-secure terminal to obtain the first encrypted ciphertext, and sends the first encrypted ciphertext and the first key index corresponding to the first key to the quantum-secure terminal.
[0191] S507: After obtaining the allocation information, the quantum-secure base station sends the encryption key corresponding to the quantum-secure terminal to the key center.
[0192] S508: After determining that the encryption key has been successfully sent to the key center, the quantum-secure base station sends a notification message to the quantum-secure terminal to notify the quantum-secure terminal that it can download the target key from the key center.
[0193] S509: After receiving the first encrypted ciphertext and the first key index, the quantum-secure terminal obtains the first key according to the first key index, and decrypts the first encrypted ciphertext according to the first key to obtain the allocation information.
[0194] It should be noted that S509 can be executed at any step after S506 and before S510, and no specific limitation is made here.
[0195] S510: After receiving the notification message sent by the quantum-secure base station, the quantum-secure terminal sends a first download request to the key center at the address in the allocation information.
[0196] S511: After receiving the first download request, the key center encrypts the target key pre-allocated for the quantum-secure terminal according to the encryption key sent by the quantum-secure base station to obtain the encrypted target key.
[0197] S512: The key center sends the encrypted target key to the quantum-secure terminal.
[0198] S513: After receiving the encrypted target key, the quantum-secure terminal decrypts the encrypted target key according to the pre-saved encryption key to obtain the target key.
[0199] If the target key is obtained for the first time after the quantum security terminal leaves the factory, the encryption key is injected through connecting to a key distribution machine before the quantum security terminal leaves the factory.
[0200] If the target key is obtained for the first time after the quantum security terminal leaves the factory, the encryption key is the supplementary encryption key that the quantum security terminal obtained from the key center last time.
[0201] S514: The quantum security terminal performs integrity verification on the target key.
[0202] S515: After determining that the encryption key has been successfully sent to the key center, the quantum security base station sends a second download request to the key center.
[0203] Among them, the second download request carries allocation information to download the target key from the key center.
[0204] S516: After obtaining the second download request, the key center sends the target key to the quantum security base station.
[0205] S517: The quantum security base station performs integrity verification on the target key.
[0206] It should be noted that S515 to S517 can be executed in any step after S507 and before S518, and the specific execution order is not specifically limited here.
[0207] S518: If it is determined that the supplementary key passes the integrity verification, the quantum security terminal performs consistency verification on the supplementary key and the supplementary key downloaded by the quantum security base station.
[0208] S519: If the quantum security terminal determines that the supplementary key passes the consistency verification, it supplements the consumed encryption key according to the supplementary encryption key and supplements the key pool of the quantum security terminal according to the supplementary key.
[0209] S520: If the quantum security base station determines that the supplementary key passes the consistency verification, it supplements the consumed encryption key according to the supplementary encryption key and supplements the key pool corresponding to the quantum security terminal saved according to the supplementary key.
[0210] Embodiment 6:
[0211] This application also provides a quantum key security supplement device. Figure 6 As shown in the structural schematic diagram of a key supplement device provided by an embodiment of this application, this device is applied to a quantum security terminal, and this device includes:
[0212] A receiving unit 61, configured to receive the encrypted target key sent by the key center; wherein, the target key includes a supplementary encryption key and a supplementary key;
[0213] A processing unit 62, configured to decrypt the received encrypted key according to the pre-stored encryption key to obtain the target key;
[0214] An updating unit 63, configured to supplement the encryption key according to the supplementary encryption key and supplement the key pool according to the supplementary key.
[0215] It should be noted that the principle of the quantum key security supplement device provided in this embodiment for solving technical problems is the same as that in the above-mentioned Embodiments 1-3, and the repeated parts will not be elaborated.
[0216] Embodiment 7:
[0217] The present application further provides a quantum key security supplement device, Figure 7 which is a schematic structural diagram of another key supplement device provided in the embodiments of the present application. This device is applied to a key center and includes:
[0218] An obtaining module 71, configured to obtain an encryption key;
[0219] An encryption module 72, configured to encrypt the target key pre-allocated for the quantum security terminal based on the obtained encryption key to obtain the encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key;
[0220] A sending module 73, configured to send the encrypted target key to the quantum security terminal.
[0221] It should be noted that the principle of the quantum key security supplement device provided in this embodiment for solving technical problems is the same as that in the above-mentioned Embodiment 4, and the repeated parts will not be elaborated.
[0222] Embodiment 8:
[0223] Based on the above embodiments, the embodiments of the present application further provide a quantum security terminal, Figure 8 which is a schematic structural diagram of a quantum security terminal provided in the embodiments of the present application. As Figure 8 shown, it includes: a processor 81, a communication interface 82, a memory 83, and a communication bus 84. Among them, the processor 81, the communication interface 82, and the memory 83 communicate with each other through the communication bus 84;
[0224] The memory 83 stores a computer program. When the program is executed by the processor 81, the processor 81 is caused to execute the following steps:
[0225] If the encrypted target key sent by the key center is received, the received encrypted key is decrypted according to the pre-stored encryption key to obtain the target key; wherein, the target key includes a supplementary encryption key and a supplementary key.
[0226] Supplement the encryption key according to the supplementary encryption key, and supplement the key pool according to the supplementary key.
[0227] Since the principle of the above quantum security terminal to solve problems is similar to the quantum security key method, the implementation of the above quantum security terminal can refer to Embodiments 1-3 of the method, and the repeated parts will not be elaborated.
[0228] Embodiment 9:
[0229] Based on the above embodiments, an embodiment of the present application further provides a key center. Figure 9 For another structural schematic diagram of the key center provided by the embodiment of the present application, as Figure 9 shown, it includes: a processor 91, a communication interface 92, a memory 93, and a communication bus 94. Among them, the processor 91, the communication interface 92, and the memory 93 complete mutual communication through the communication bus 94.
[0230] A computer program is stored in the memory 93. When the program is executed by the processor 91, the processor 91 is caused to execute the following steps:
[0231] Based on the obtained encryption key, encrypt the target key pre-allocated for the quantum security terminal to obtain the encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key.
[0232] Send the encrypted target key to the quantum security terminal.
[0233] Since the principle of the above key center to solve problems is similar to the quantum security key method, the implementation of the above key center can refer to Embodiment 4 of the method, and the repeated parts will not be elaborated.
[0234] Embodiment 10:
[0235] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium. A computer program executable by a processor is stored in the computer-readable storage medium. When the program runs on the processor, the processor is caused to execute the following steps when executed:
[0236] If the encrypted target key sent by the key center is received, decrypt the received encrypted key according to the pre - saved encryption key to obtain the target key; wherein, the target key includes a supplementary encryption key and a supplementary key.
[0237] Supplement the encryption key according to the supplementary encryption key, and supplement the key pool according to the supplementary key.
[0238] Since the principle of the above - mentioned computer - readable storage medium for solving problems is similar to the method for secure supplementation of quantum keys, the implementation of the above - mentioned computer - readable storage medium can refer to Embodiments 1 - 3 of the method, and the repeated parts will not be elaborated.
[0239] Embodiment 15:
[0240] Based on the above embodiments, the embodiment of the present application further provides a computer - readable storage medium. The computer - readable storage medium stores a computer program executable by a processor. When the program runs on the processor, the processor is caused to execute the following steps:
[0241] Encrypt the target key pre - allocated for the quantum - secure terminal based on the obtained encryption key to obtain the encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key.
[0242] Send the encrypted target key to the quantum - secure terminal.
[0243] Since the principle of the above - mentioned computer - readable storage medium for solving problems is similar to the method for secure supplementation of quantum keys, the implementation of the above - mentioned computer - readable storage medium can refer to Embodiment 4 of the method, and the repeated parts will not be elaborated.
Claims
1. A security supplement system for quantum keys, characterized in that, the system includes a quantum security terminal, a quantum security base station, and a key center; The working process of the system includes: S501: The quantum security terminal determines that it is not connected to the quantum security base station and sends an access request to the quantum security base station; S502: After receiving the access request, if the quantum security base station determines that the quantum security terminal is allowed to access the quantum security base station, it sends the first access feedback information to the quantum security terminal; wherein, the first access feedback information carries information that the quantum security base station supports online key distribution; S503: After receiving the first access feedback information, if the quantum security terminal determines that the number of used keys has reached a preset threshold, it generates a key supplement request and sends it to the quantum security base station; S504: After receiving the key supplement request, the quantum security base station determines the key center that allocates keys for the quantum security terminal and sends the key supplement request to the key center; S505: After receiving the key supplement request, the key center allocates a target key for the quantum security terminal, generates allocation information according to the address of the key center and the information of the target key, and sends the allocation information to the quantum security base station; wherein, the target key includes a supplementary key and a supplementary encryption key; S506: After receiving the allocation information, the quantum security base station encrypts the allocation information according to the first key paired with the quantum security terminal to obtain the first encrypted ciphertext, and sends the first encrypted ciphertext and the first key index corresponding to the first key to the quantum security terminal; S507: After obtaining the allocation information, the quantum security base station sends the encryption key corresponding to the quantum security terminal to the key center; S508: After determining that the encryption key has been successfully sent to the key center, the quantum security base station sends a notification message to the quantum security terminal to notify the quantum security terminal to download the target key from the key center; S509: After receiving the first encrypted ciphertext and the first key index, the quantum security terminal obtains the first key according to the first key index, and decrypts the first encrypted ciphertext according to the first key to obtain the allocation information; S510: After receiving the notification message sent by the quantum security base station, the quantum security terminal sends a first download request to the key center at the address in the allocation information; S511: After receiving the first download request, the key center encrypts the target key pre-allocated for the quantum security terminal according to the encryption key sent by the quantum security base station to obtain the encrypted target key; S512: The key center sends the encrypted target key to the quantum security terminal; S513: After receiving the encrypted target key, the quantum security terminal decrypts the encrypted target key according to the pre-saved encryption key to obtain the target key; S514: The quantum security terminal performs integrity verification on the target key; S515: After the quantum - secure base station determines that the encrypted key has been successfully sent to the key center, it sends a second download request to the key center; wherein, the second download request carries allocation information to download the target key from the key center. S516: After the key center receives this second download request, it sends the target key to the quantum - secure base station. S517: The quantum - secure base station performs an integrity check on the target key. S518: If it is determined that the supplementary key passes the integrity check, the quantum - secure terminal performs a consistency check on the supplementary key and the supplementary key downloaded by the quantum - secure base station. S519: If the quantum - secure terminal determines that the supplementary key passes the consistency check, it replenishes the consumed encrypted key according to the supplementary encryption key and replenishes the key pool of the quantum - secure terminal according to the supplementary key. S520: If the quantum - secure base station determines that the supplementary key passes the consistency check, it replenishes the consumed encrypted key according to the supplementary encryption key and replenishes the key pool corresponding to the quantum - secure terminal it stores according to the supplementary key.
2. A supplementary method for a quantum - key security supplementary system according to claim 1, characterized in that: This method is applied to a quantum - secure terminal, and the method includes: If the encrypted target key sent by the key center is received, decrypt the received encrypted key according to the pre - stored encrypted key to obtain the target key; wherein, the target key includes a supplementary encryption key and a supplementary key. Replenish the encrypted key according to the supplementary encryption key and replenish the key pool according to the supplementary key. Wherein, before receiving the encrypted target key sent by the key center, the method further includes: If it is determined that the key pool meets the preset key replenishment requirement, generate a key replenishment request and send it to the quantum - secure base station. Obtain the allocation information sent by the quantum - secure base station; wherein, the allocation information includes the address of the key center, the first information of the supplementary key, and the second information of the supplementary encryption key. Send a first download request to the key center at the address; wherein, the first download request is used to request the key center to send the encrypted supplementary key, and the first download request carries the first information and the second information. After obtaining the encrypted target key and before replenishing the encrypted key according to the supplementary encryption key and replenishing the key pool according to the supplementary key, the method further includes: Determine that the decrypted target key passes the integrity check, or determine that the encrypted target key passes the integrity check. The encrypted target key is obtained through at least one of the following methods: The key center encrypts the target key based on the encrypted key sent by the quantum - secure base station. The key center encrypts the supplementary key based on the pre - stored encrypted key. If the encrypted target key is obtained by the key center encrypting the target key based on the encryption key sent by the quantum security base station, after obtaining the target key, before supplementing the encryption key according to the supplementary encryption key and supplementing the key pool according to the supplementary key, the method further includes: Determine that the target key passes a consistency check with the target key downloaded by the quantum security base station; If the key center encrypts the supplementary key based on the pre-stored encryption key, after obtaining the target key, before supplementing the encryption key according to the supplementary encryption key and supplementing the key pool according to the supplementary key, the method further includes: Determine that the supplementary key passes a consistency check with the supplementary key downloaded by the quantum security base station, and determine that the supplementary encryption key passes a consistency check with the supplementary encryption key stored in the key center; Wherein, determining that the supplementary encryption key passes a consistency check with the supplementary encryption key stored in the key center includes: If the first check code of the supplementary encryption key is consistent with the second check code obtained by the quantum security base station from the key center, determine that the supplementary encryption key passes a consistency check with the supplementary encryption key stored in the key center; wherein, the second check code is determined by the key center according to the stored supplementary encryption key and a preset consistency check algorithm; If it is determined that the encrypted supplementary key sent by the key center is received for the first time, the encryption key is filled in by the quantum security terminal before leaving the factory by connecting to a key distribution machine.
3. A supplementary method for a quantum key security supplementary system according to claim 1, Characterized in that: This method is applied to a key center, and the method includes: Based on the obtained encryption key, encrypt the target key pre-allocated for the quantum security terminal to obtain an encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key; Send the encrypted target key to the quantum security terminal; Wherein, before encrypting the target key pre-allocated for the quantum security terminal based on the obtained encryption key to obtain an encrypted target key, the method further includes: Receive a key supplementary request sent by the quantum security base station; wherein, the key supplementary request is used to instruct the key center to allocate a target key for the quantum security terminal; In response to the key supplementary request, allocate the target key; Determine allocation information according to the information of the target key and the address of the key center and send the allocation information to the quantum security base station, so that the quantum security base station sends the allocation information to the quantum security terminal; wherein, the information of the target key includes the first information of the supplementary key and the second information of the supplementary encryption key; Receive the first download request sent by the quantum security terminal; wherein, the first download request carries the allocation information; The obtaining of the encryption key includes: Receive the encryption key sent by the quantum-secure base station; wherein, the encryption key is sent by the quantum-secure base station after receiving the allocation information; After receiving the encryption key sent by the quantum-secure base station, the method further includes: Receive a second download request carrying the allocation information sent by the quantum-secure base station; wherein, the second download request is used to instruct the key center to send the supplementary key and the supplementary encryption key to the quantum-secure base station; In response to the second download request, send the supplementary key and the supplementary encryption key to the quantum-secure base station; The allocating the target key in response to the key supplementation request includes: Determine the supplementary key and the supplementary encryption key according to the information carried in the key supplementation request and a pre-configured allocation rule; If the encryption key is pre-saved, after determining the supplementary encryption key, the method further includes: Update the encryption key according to the supplementary encryption key; After sending the allocation information to the quantum-secure base station, the method further includes: Receive a third download request sent by the quantum-secure base station; wherein, the third download request is used to instruct the key center to send the supplementary key to the quantum-secure base station, and the third download request carries the address of the key center and the first information; In response to the third download request, send the supplementary key to the quantum-secure base station; After sending the encrypted target key to the quantum-secure terminal, the method further includes: Determine a second verification code of the supplementary encryption key according to the supplementary encryption key and a pre-configured consistency verification algorithm; Send the second verification code to the quantum-secure base station, so that the quantum-secure base station performs consistency verification of the supplementary encryption key with the quantum-secure terminal according to the second verification; Obtaining the encryption key includes: If it is determined that the encryption key corresponding to the quantum-secure terminal is not locally saved, obtain the encryption key from the quantum-secure base station.
4. A supplementary device for a quantum key security supplementation system according to claim 1, characterized in that: The device is applied to a quantum-secure terminal, and the device includes: A receiving unit, configured to receive the encrypted target key sent by the key center; wherein, the target key includes a supplementary encryption key and a supplementary key; A processing unit, configured to decrypt the received encrypted key according to a pre-saved encryption key to obtain the target key; An updating unit, configured to supplement the encryption key according to the supplementary encryption key and supplement the key pool according to the supplementary key.
5. A supplementary device for a quantum key security supplementation system according to claim 1, characterized in that: The device is applied to the key center, and the device includes: An obtaining module, configured to obtain the encryption key; An encryption module, configured to encrypt a target key pre-assigned to a quantum secure terminal based on an obtained encryption key, so as to obtain an encrypted target key; wherein, the target key includes a supplementary encryption key and a supplementary key; A sending module, configured to send the encrypted target key to the quantum secure terminal.
6. A quantum secure terminal, Characterized in that, The quantum secure terminal at least includes a processor and a memory, and the processor is configured to implement the steps of the supplementary method as described in claim 2 when executing a computer program stored in the memory.
7. A key center, Characterized in that, The key center at least includes a processor and a memory, and the processor is configured to implement the steps of the supplementary method as described in claim 3 when executing a computer program stored in the memory.
8. A computer-readable storage medium, Characterized in that, It stores a computer program, and the computer program, when executed by a processor, implements the steps of the supplementary method as described in claim 2, or implements the steps of the supplementary method as described in claim 3.
Citation Information
Patent Citations
Cloud platform management method and system based on quantum key distribution technology
CN112134695A