An Encryption Transmission Method for Engineering Electronic Archives

The dual quantum key encryption method addresses vulnerabilities in existing engineering document transmission by using synchronized quantum keys and message verification to ensure security and integrity.

CN115834126BActive Publication Date: 2025-07-15CHINA THREE GORGES CORPORATION
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211287875.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-07-15
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

There are problems in the transmission of existing engineering electronic files that have high-strength computing power to crack, the public key system cannot be truly random and one-secret at a time, and the sending end is easy to tamper with.

Method used

The double quantum key encryption method is used to divide the file into two segments for encryption, and the key is confirmed through the synchronization number of the quantum key, combined with message verification code verification, to ensure the security and integrity of data transmission.

Benefits of technology

The encrypted transmission of "four characteristics" (authenticity, integrity, availability and security) is realized, which improves the transmission security and integrity of engineering electronic files and prevents tampering on the sending side.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834126B_ABST
    Figure CN115834126B_ABST
Patent Text Reader

Abstract

An engineering electronic file encryption and transmission method, the method is as follows: Split file A into two segments A1 and A2; Synchronize quantum keys at the sending and receiving ends, and confirm key a by means of synchronous numbering; Then confirm key b by means of secondary random synchronous numbering; Keys a and b are respectively used to encrypt file A1 and file A2 to obtain ciphertexts C1 and C2; File A generates a message authentication code B through a message authentication function and encrypts it into ciphertext D; At the quantum decryption end, C1, C2, and D are respectively decrypted through a decryption function and a message authentication function to obtain A1′, A2′, and B′; Merge A1′ and A2′ to obtain A′, and obtain a message authentication code E′ through a message authentication code function; Finally, perform result comparison, compare E′ with B′, if the two are equal, it proves that A is complete, otherwise, the file is not received. The present invention can ensure the security and integrity of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of encrypted transmission, and particularly relates to an encrypted transmission method for engineering electronic archives. Background Art

[0002] There are many associated parties such as project owners, designers, constructors, supervisors, and monitors involved in engineering archives management, as well as various business information systems. As a result, the propagation cycle and chain path of the whole process of engineering electronic archives formation, circulation, review and signature, filing, and preservation are relatively long. Generally, the transmission of engineering electronic archives generally relies on the public key system encryption and decryption scheme, but it cannot cope with the cracking problem of high-strength computing power. At the same time, most encryption schemes only consider the end-to-end encryption method, that is, the sending end encrypts the archives and the receiving end decrypts the archives, without considering problems such as the archives at the sending end being tampered with before sending. There are security risks in the encrypted transmission of engineering electronic archive data. The technical problems existing in the prior art (for example, the electronic archive verification method and device disclosed in Chinese Patent Document CN104320257B, and the information security transmission method based on a cross-domain distributed microservice architecture disclosed in Chinese Patent Document CN110086805B) are as follows:

[0003] 1. The public key system encryption and decryption scheme cannot cope with the cracking problem of high-strength computing power.

[0004] 2. The existing key system cannot achieve "true randomness" and "one-time one-key".

[0005] 3. Based on the end-to-end encryption method, it is easy to tamper with the archives at the sending end. Summary of the Invention

[0006] In view of the technical problems existing in the background art, an encrypted transmission method for engineering electronic archives provided by the present invention, when transmitting electronic archives between two business systems, is carried out by means of double quantum key encryption to further ensure the security and integrity of data transmission.

[0007] In order to solve the above technical problems, the present invention adopts the following technical solutions to achieve:

[0008] An encrypted transmission method for engineering electronic archives, the steps are as follows:

[0009] Step S1: Divide the business system into a sending-end business system T and a receiving-end business system F. The engineering electronic archives that need to be encrypted and transmitted between the sending-end business system T and the receiving-end business system F are defined as A, and A is split into two segments A1 and A2;

[0010] Step S2: The receiving-end business system F confirms the key a through the synchronous number of the quantum key; at the same time, the receiving-end business system F confirms the key b again by means of secondary random synchronous numbering;

[0011] Step S3: Encrypt A1 with the key a to obtain the ciphertext C1; encrypt A2 with the key b to obtain the ciphertext C2;

[0012] Step S4: A generates a message authentication code B through a message authentication function and encrypts it into the ciphertext D;

[0013] Step S5: Using the decryption function and the message authentication function, decrypt C1 at the quantum decryption end to obtain A1′, decrypt C2 to obtain A2′, and decrypt D to obtain B′;

[0014] Step S6: Combine A1′ and A2′ to obtain A′, and obtain the message authentication code E′ through the message authentication code function;

[0015] Step S7: Finally, perform a result comparison, compare E′ with B′. If the two are equal, it proves that A is complete and can be sent to the receiving-end service system F. If they are not equal, it proves that the sending-end service system T has tampered with A, and this file will not be received.

[0016] Preferably, before step S1, a communication transmission system based on quantum keys is built. The communication transmission system includes a quantum channel, a traditional channel, a quantum encryption end, and a quantum decryption end. The quantum channel does not transmit ciphertexts and is only responsible for transmitting quantum keys; the traditional channel is used to transmit the ciphertext information encrypted with quantum keys. Quantum key distribution is equivalent to adding a password lock to traditional communication. Its principle is exactly based on the physical characteristics of quantum indivisibility, non-clonability, and uncertainty. Therefore, quantum cryptographic communication can achieve absolute security and cannot be cracked even with a very strong computing power.

[0017] Preferably, in step S4, a message authentication code for A is generated based on a one-way hash function to obtain the message authentication code B.

[0018] Preferably, an engineering electronic file encryption transmission system adopts the described engineering electronic file encryption transmission method.

[0019] This patent can achieve the following beneficial effects:

[0020] 1. A new engineering electronic file encryption transmission method is proposed, that is, encrypt and transmit the file data through a dual quantum key method based on secondary synchronization, which can further ensure the "four properties" of engineering electronic files (i.e., authenticity, integrity, availability, and security).

[0021] 2. The quantum key encryption method is introduced, which can quickly generate "true random" keys. The keys have no correlation before and after, will not repeat, and are unpredictable. Moreover, the "one-time pad" encryption method is adopted to enhance the transmission security of electronic files.

[0022] 3. Compared with the two existing patent documents, namely, the electronic file verification method and device disclosed in Chinese Patent Document CN104320257B and the information security transmission method based on a cross-domain distributed microservice architecture disclosed in Chinese Patent Document CN110086805B, the advantages of the present invention are as follows: 1) The quantum key used in the present invention is generated by a communication transmission system based on quantum key, which can quickly generate a "true random" key. The key has no correlation before and after, will not repeat and is unpredictable, and the "one-time pad" encryption method is used to improve the transmission security of electronic files. In contrast, both of the two compared patents use traditional keys. 2) The keys generated by the encryption methods of the existing patents are directly transmitted through the communication transmission system, while the key determination method of the present invention is determined by the method of synchronous numbering, which will not cause the leakage of the encryption key. 3) The keys of the existing patents are determined by random methods and there is only one key, while the present invention is determined by the method of synchronous numbering and is synchronized twice, which can further enhance the security of the key. 4) The present invention divides the document to be encrypted into two segments for encryption, greatly improving the cracking difficulty, and the existing patent technology is more easily cracked. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The present invention will be further described below with reference to the drawings and embodiments:

[0024] Figure 1 is the encryption flow chart of the present invention;

[0025] Figure 2 is the framework diagram of the communication transmission system based on quantum key of the present invention; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] Embodiment 1:

[0027] The preferred solution is as Figures 1 to 2 shown. A method for encrypting and transmitting engineering electronic files comprises the following steps:

[0028] I. Initialization preparation work:

[0029] Build a communication transmission system based on quantum key. Here, taking the transmission of engineering electronic files between the sending-end service system T and the receiving-end service system F as an example, the architecture of the built communication transmission system is as Figure 1 shown.

[0030] The channels required for quantum key distribution include a quantum channel and a traditional channel. The quantum channel does not transmit ciphertext and is only responsible for transmitting quantum keys; while the traditional channel is mainly used for transmitting the ciphertext information encrypted with quantum keys.

[0031] Quantum key distribution is equivalent to adding a password lock to traditional communication. Its principle is based on the physical properties of quantum indivisibility, non-clonability, and uncertainty. Therefore, quantum cryptographic communication can achieve absolute security and cannot be cracked even with extremely powerful computing power.

[0032] II. Electronic file encryption process:

[0033] Step S1: Divide the business system into a sending-end business system T and a receiving-end business system F. The sending-end business system T prepares the engineering electronic files that need to be encrypted and transmitted, and generates the corresponding fingerprint A through the hash algorithm. A will uniquely identify the file, and A can be regarded as equivalent to the file. For the convenience of understanding, it will be directly described as file A later. At the same time, split file A into two parts, A1 and A2;

[0034] The hash algorithm maps binary values of any length to shorter fixed-length binary values. This small binary value is called the hash value. The hash value is a unique and extremely compact numerical representation of a piece of data. If a piece of plaintext is hashed and even one letter of the paragraph is changed, the subsequent hash will produce a different value. Considering that electronic files are unstructured data and cannot directly participate in operations, and for the convenience of encryption and decryption, here the electronic files are mapped into a string of numerical values through the hash algorithm for later mapping identification.

[0035] Step S2: The receiving-end business system F confirms the key a through the synchronous number of the quantum key; at the same time, the receiving-end business system F confirms the key b again through the method of secondary random synchronous number;

[0036] Based on the previously established quantum channel transmission system, through the preparation, transmission, measurement of single-photon quantum states and post-processing of classical communication protocols, combined with the "one-time pad" symmetric encryption, both communication parties use passwords of the same length as the information for bit-by-bit encryption and decryption operations to ensure the absolute security of the quantum key;

[0037] Step S3: Encrypt A1 with the key a to obtain the ciphertext C1; encrypt A2 with the key b to obtain the ciphertext C2;

[0038] Step S4: A generates a message authentication code B through the message authentication function. Specifically, generate the message authentication code B for file A through the message authentication code (HMAC) based on the one-way hash function and encrypt it into the ciphertext D;

[0039] Send the ciphertext C1, ciphertext C2, and ciphertext D to the quantum decryption end.

[0040] III. Electronic file decryption process:

[0041] The quantum decryption OKD device end receives the ciphertext C1, ciphertext C2, and ciphertext D.

[0042] Step S5: Using the decryption function and the message verification function, decrypt C1 to obtain A1' at the quantum decryption end, decrypt C2 to obtain A2', and decrypt D to obtain B'

[0043] IV. Comparison and verification:

[0044] Step S6: Combine A1' and A2' to obtain A', and obtain the message verification code E' through the message authentication code function

[0045] Step S7: Finally, conduct a result comparison. Compare E' with B'. If the two are equal, it proves that A is complete, A' = A, and it can be sent to the receiving-end service system F. If they are not equal, it proves that the sending-end service system T has tampered with A, and this file will not be received

[0046] V. Achieved effects:

[0047] 1. This solution splits the original electronic file using the double quantum key encryption method and encrypts them separately, greatly improving the security of the original file. Even if one happens to guess a part of the key, only a part of the file can be decrypted, and in fact, the complete electronic file cannot be obtained

[0048] 2. Using the message authentication code method can effectively guarantee the authenticity of the electronic file at the sending end. Whether the file is tampered with before sending or during transmission, the receiving end can verify the result through the message authentication code, and then determine whether the file has been tampered with

[0049] An engineering electronic file encryption and transmission system adopts the described engineering electronic file encryption and transmission method

[0050] The above embodiments are only the preferred technical solutions of the present invention and should not be regarded as limitations on the present invention. The protection scope of the present invention should be the technical solutions recorded in the claims, including the equivalent replacement solutions of the technical features in the technical solutions recorded in the claims. That is, the equivalent replacement improvements within this scope are also within the protection scope of the present invention

Claims

1. An engineering electronic file encryption and transmission method, characterized in that It includes the following steps: Step S1: Divide the business system into a sending - end business system T and a receiving - end business system F. Define the engineering electronic files that need to be encrypted and transmitted between the sending - end business system T and the receiving - end business system F as A, and split A into two segments A1 and A2; Step S2: The receiving - end business system F confirms the key a through the synchronous number of the quantum key; at the same time, the receiving - end business system F confirms the key b again by means of secondary random synchronous number; Step S3: Encrypt A1 with the key a to obtain the ciphertext C1; encrypt A2 with the key b to obtain the ciphertext C2; Step S4: Generate a message authentication code B for A through a message authentication function and encrypt it into ciphertext D; Step S5: Use the decryption function and the message authentication function to decrypt C1 to obtain A1′ at the quantum decryption end, decrypt C2 to obtain A2′, and decrypt D to obtain B′; Step S6: Merge A1′ and A2′ to obtain A′, and obtain the message authentication code E′ through the message authentication code function; Step S7: Finally, conduct a result comparison. Compare E′ with B′. If the two are equal, it proves that A is complete and can be sent to the receiving - end business system F. If they are not equal, it proves that the sending - end business system T has tampered with A, and this file will not be received.

2. The engineering electronic file encryption transmission method according to claim 1, wherein: Before step S1, build a communication transmission system based on quantum keys. The communication transmission system includes a quantum channel, a traditional channel, a quantum encryption end, and a quantum decryption end. The quantum channel does not transmit ciphertext and is only responsible for transmitting quantum keys; the traditional channel is used to transmit the ciphertext information encrypted with quantum keys.

3. The method for encrypted transmission of engineering electronic files according to claim 1, wherein: In step S4, generate the message authentication code B for A based on the message authentication code of the one - way hash function.

4. An engineering electronic file encryption and transmission system, characterized in that: Adopt an engineering electronic file encryption and transmission method according to any one of claims 1 - 3.

Citation Information

Patent Citations

  • Electronic document verification method and device

    CN104320257B

  • Information security transmission method based on cross-domain distributed microservice architecture

    CN110086805B

  • Data encryption method and system

    CN102567687A

  • Power grid communication encryption method

    CN110868298A