A Quantum-Secure Root Key Distribution Method, Device, Root Key Center, and Medium
Through the root key center, the root key files are automatically generated and managed, and the problems of low efficiency and poor quality of manual allocation of root keys are solved, efficient and convenient root key allocation and management are achieved, and the security and communication efficiency of quantum security devices are improved.
Patent Information
- Application Number
- CN202211580533.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-12-09
AI Technical Summary
In the prior art, the root key allocation of quantum security devices relies on manual allocation, resulting in low efficiency, poor quality and inconvenient management, affecting the efficiency and security of quantum secure communication.
The root key center automatically obtains the generation and import information, generates the root key file according to the device identification and root key size, and manages it through file serial number and storage location records to achieve automated root key allocation and management.
It improves the efficiency and quality of root key allocation, reduces manpower and material consumption, and facilitates the management of root key files and the configuration of subsequent quantum security devices.
Smart Images

Figure CN115883085B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum security technologies, and particularly to a quantum-secure root key distribution method, apparatus, root key center, and medium. Background Art
[0002] Traditional communication encryption methods rely on keys. Once the key is cracked, the security of the data is difficult to guarantee. Moreover, there are known quantum algorithms that can crack the public-key cryptography of traditional communication encryption methods, which greatly affects the security of traditional communication encryption methods. In addition, traditional symmetric encryption algorithms all use programming methods to generate random numbers, and the generated random numbers have the characteristics of pseudo-randomness and are at risk of being attacked. Therefore, how to improve data security is an issue that people are increasingly concerned about.
[0003] Quantum key distribution technology is a method that uses the characteristics of quantum mechanics to ensure communication security. In this quantum key distribution technology, the quantum keys generated by a quantum random number generator have the characteristics of true randomness, and using the generated quantum keys can prevent attackers from attacking the keys at the source. With the help of this quantum key and quantum encryption method, we can achieve high-security encryption of data. Based on this, as quantum computing technology continues to progress, the importance of quantum security technologies, including quantum encryption technology, in secure data communication has become increasingly prominent.
[0004] Currently, if we want to achieve quantum-secure communication for quantum-secure devices, generally a large number of factory keys, that is, root keys, are manually assigned to a certain device identifier, and then the device identifier and the root key corresponding to the device identifier are injected into the quantum-secure device to facilitate the quantum-secure device to perform quantum encryption and decryption and other processes based on the device identifier and the injected root key after leaving the factory. For this method, manually distributing root keys is a time-consuming, laborious, and costly task. In the case where a very large number of root keys corresponding to different device identifiers need to be generated, not only the workload of the staff will be very large, but also it is not convenient to manage the already distributed root keys, which affects the efficiency and quality of root key distribution, and further affects subsequent quantum-secure communication, making the disadvantages of this method particularly obvious. Therefore, there is an urgent need for a method that can improve the efficiency and quality of distributing root keys for quantum-secure devices. Summary of the Invention
[0005] This application provides a quantum-secure root key distribution method, apparatus, root key center, and medium, which are used to solve the problems of low efficiency, poor quality, and inconvenient management of root key distribution caused by relying on manual distribution of existing root keys.
[0006] In a first aspect, this application provides a quantum-secure root key distribution method, and the method includes:
[0007] Obtain the generation import information required to generate the root key; wherein, the generation import information includes a device identifier and a root key size;
[0008] Generate each root key file corresponding to the device identifier according to the root key size and a preset root key file granularity;
[0009] Determine the first file serial numbers of the root key files, and save the root key files;
[0010] Obtain a first generation record according to the device identifier, the first file serial numbers of the root key files corresponding to the device identifier, and the storage locations of the root key files corresponding to the device identifier, so as to find the root key files corresponding to the device identifier according to the first generation record.
[0011] In a second aspect, the present application provides a quantum-secure root key distribution device, and the device includes:
[0012] An obtaining unit, configured to obtain the generation import information required to generate the root key; wherein, the generation import information includes a device identifier and a root key size;
[0013] A generating unit, configured to generate each root key file corresponding to the device identifier according to the root key size and a preset root key file granularity;
[0014] A first processing unit, configured to determine the first file serial numbers of the root key files, and save the root key files;
[0015] A second processing unit, configured to obtain a first generation record according to the device identifier, the first file serial numbers of the root key files corresponding to the device identifier, and the storage locations of the root key files corresponding to the device identifier, so as to find the root key files corresponding to the device identifier according to the first generation record.
[0016] In a third aspect, the present application provides a root key center, and the root key center at least includes a processor and a memory, and the processor is configured to implement the steps of the quantum-secure root key distribution method as described above when executing a computer program stored in the memory.
[0017] In a fourth aspect, the present application provides a computer-readable storage medium, which stores a computer program, and the computer program is configured to implement the steps of the quantum-secure root key distribution method as described above when executed by a processor.
[0018] Fifth aspect, the present application provides a computer program product, which includes: computer program code that, when running on a computer, causes the computer to execute the steps of the quantum-secure root key distribution method as described above.
[0019] The beneficial effects of the present application are as follows:
[0020] 1. Since the root key center can accurately generate and distribute the root key after obtaining the generation import information required for generating the root key, it avoids reducing the efficiency and quality of root key distribution by using the method of manual root key distribution, and reduces the manpower and material resources consumed for root key distribution.
[0021] 2. After obtaining each root key file, the first file serial number of each root key file will also be determined, which facilitates the subsequent export or injection of each root key file into the quantum-secure device by the root key center in sequence.
[0022] 3. After saving each root key file, the first generation record can be obtained according to the device identifier, the first file serial number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier, so that any root key file corresponding to the device identifier can be quickly and accurately found according to the first generation record subsequently, which is beneficial to the management of the root key files corresponding to each device identifier. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 It is a schematic diagram of a root key distribution process provided by an embodiment of the present application;
[0025] Figure 2 It is a schematic diagram of a specific root key distribution process provided by an embodiment of the present application;
[0026] Figure 3 It is a schematic diagram of the structure of a quantum-secure root key distribution device provided by the present application;
[0027] Figure 4 It is a schematic diagram of the structure of a root key center provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] To make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.
[0029] To improve the efficiency and quality of allocating root keys for quantum - secure devices and facilitate the management of the allocated root keys, the embodiments of this application provide a quantum - secure root - key allocation method, apparatus, root - key center, and medium.
[0030] Embodiment 1:
[0031] Figure 1 The following is a schematic diagram of a root - key allocation process provided by the embodiments of this application. This process includes:
[0032] S101: Obtain the generation import information required to generate the root key; where the generation import information includes the device identifier and the root - key size.
[0033] The root - key allocation process provided by this application is applied to a root - key center, which can be a quantum - secure device, such as a quantum - secure all - in - one machine, a quantum - secure computer, etc., or a quantum - secure server, such as a quantum - secure service server, a quantum - secure application server, etc.
[0034] In a possible application scenario, before leaving the factory, a quantum - secure device needs to be allocated a root key and the allocated root key is injected into the quantum - secure device to facilitate quantum - secure communication by the quantum - secure device after leaving the factory. In this application, the root - key center can generate the root key and allocate the generated root key to the quantum - secure device. Exemplarily, the root - key center can obtain the generation import information required to generate the root key. Among them, the generation import information can include the device identifier, such as the device ID, the device factory code, etc., and the root - key size. Then, according to the obtained generation import information, corresponding processing is performed to generate the root key corresponding to the device identifier.
[0035] In one example, the generation import information can be input into the root - key center in a manual input manner. For example, a staff member can input the generation import information in the configuration interface displayed on the display corresponding to the root - key center.
[0036] In another example, the root key center can also obtain the generated import information from other devices (such as a quantum-secure network management device, etc.). For example, if another device receives a fetch request sent by the root key center, it will send the pre-stored generated import information to the root key center. For another example, after obtaining the generated import information, the other device can send the generated import information to the root key center. Among them, the other device sends the generated import information to the root key center in real time, or sends the generated import information to the root key center according to a preset period or time point, or sends the generated import information to the root key center after receiving a send instruction, etc.
[0037] S102: Generate each root key file corresponding to the device identifier according to the root key size and a preset root key file granularity.
[0038] Based on the above embodiments, after the root key center obtains the generated import information, it can generate the root key corresponding to the device identifier according to the root key size included in the generated import information. Among them, the root key size can be the total size of the root key corresponding to the device identifier. Exemplarily, there is a preset root key file granularity, and the root key center generates each root key file corresponding to the device identifier according to the obtained root key size and the preset root key file granularity.
[0039] In one example, if the root key center has a key generation function, for example, is equipped with a random number generator, the root key center can generate a random number through the random number generator. Determine the root key of the root key size from the generated random numbers.
[0040] In another example, if the root key center does not have a key generation function, the root key center can cache the random numbers generated by the random number generation device. Determine the root key of the root key size from the cached random numbers.
[0041] When a quantum - secure device accesses a quantum - secure base station, the quantum - secure device can verify the root key with the root key center through the quantum - secure base station. Only after the root key center determines that the root key verification is passed, will the root key of the quantum - secure device be sent to the quantum - secure base station. During this process, situations such as damage or loss of the root key file of the quantum - secure device may occur, resulting in the failure of root key verification, and further causing the quantum - secure base station to be unable to obtain the root key from the root key center. Based on this, in this application, when generating the root key, the root key center can allocate multiple groups of root keys for the quantum - secure device, so that when one group of root keys fails the verification, the quantum - secure device can use other root keys to continue verifying with the root key center, ensuring that the quantum - secure device can be reliably connected to the quantum - secure base station. Exemplarily, the generation import information obtained by the root key center may also include the number of root key copies. According to this generation import information, multiple groups of root keys corresponding to the device identifier are generated.
[0042] For example, when the root key size in the generation import information represents the total size of the root key, the size of each group of root keys can be determined according to the root key size and the number of root key copies. Among them, the size of each group of root keys can be the same or different. Then, for the determined size of each group of root keys, according to the size of this group of root keys and the preset root key file granularity, each root key file corresponding to this group of root keys is generated for the device identifier.
[0043] For another example, when the root key size in the generation import information represents the size of each group of root keys, then according to this root key size and the preset root key file granularity, each root key file corresponding to each group of root keys is generated for the device identifier. Among them, the number of groups of root keys corresponding to the device identifier is the number of root key copies.
[0044] In a possible implementation manner, the step of saving the respective root key files includes:
[0045] Determine the checksum corresponding to each root key file;
[0046] Save the respective root key files and the checksum corresponding to each root key file correspondingly.
[0047] Considering that after the root key center exports the root key file, the exported root key file may have security problems such as being tampered with or damaged. Based on this, in this application, after the root key center obtains any root key file, it can determine the checksum corresponding to this root key file. For example, through a preset checksum algorithm, the checksum corresponding to this root key file is determined. Then when saving this root key file, this root key file and the checksum corresponding to this root key file can be saved correspondingly, so that subsequent security problems such as the root key file being tampered with or damaged can be detected in a timely manner based on this checksum.
[0048] S103: Determine the first file serial number of each root key file, and save each root key file.
[0049] Based on the above-mentioned embodiments, there is a certain order relationship between the root key files obtained. Based on this, after obtaining the root key files, the file number of each root key file (recorded as the first file number) can be determined according to the order of each root key file, so as to determine the order relationship of each root key file through the first file number corresponding to each root key file, so as to facilitate the subsequent export, filling and other processing of each root key file in order. After obtaining each root key file, the root key center will also save each root key file. Among them, the root key center can save each root key file locally, or save each root key file in other devices.
[0050] In one possible implementation, the root key center may have generated multiple groups of root keys for a certain device identifier. When the root key center determines the first file identifiers of each root key file corresponding to any group of root keys, it may determine, for each group of root keys, the first file identifiers of each root key file corresponding to the group of root keys, that is, the first file identifiers of each root key file corresponding to the group of root keys only represent the sequential relationship of the root key files corresponding to the group of root keys.
[0051] It should be noted that, in order to facilitate the distinction between the root key files corresponding to different groups of root keys, the first file serial numbers of the root key files corresponding to different groups of root keys are all different.
[0052] S104: Obtain a first generation record according to the device identification, the first file sequence number of each root key file corresponding to the device identification, and the storage location of each root key file corresponding to the device identification, so as to search for each root key file corresponding to the device identification according to the first generation record.
[0053] After the root key center saves each root key file, the generation record (recorded as the first generation record) can be obtained according to the device identification, the first file serial number of each root key file corresponding to the device identification, and the storage location of each root key file corresponding to the device identification.
[0054] For example, the first generation record is determined based on the correspondence between the device identifier and the first file serial number of each root key file corresponding to the device identifier, and the correspondence between the first file serial number of each root key file corresponding to the device identifier and the storage location of each root key file corresponding to the device identifier.
[0055] For ease of understanding, the corresponding relationship between the device identification and the first file sequence number of each root key file corresponding to the device identification is exemplarily shown in the form of a table:
[0056]
[0057]
[0058] For ease of understanding, the correspondence between the first file sequence number of each root key file corresponding to the device identification and the storage location of each root key file corresponding to the device identification is exemplarily shown in the form of a table:
[0059] First File Serial Number Storage Location file-1 \dir\filepath\UserA\ID1\genmiyao\file-1 file-2 \dir\filepath\UserA\ID1\genmiyao\file-2 file-3 \dir\filepath\UserA\ID1\genmiyao\file-3 file-4 \dir\filepath\UserA\ID1\genmiyao\file-4 file-5 \dir\filepath\UserB\ID2\genmiyao\file-5 file-6 \dir\filepath\UserB\ID3\genmiyao\file-6
[0060] For another example, the correspondence between the device identification, the first file sequence number of each root key file corresponding to the device identification, and the storage location of each root key file corresponding to the device identification is determined as the first generation record. The root key center can subsequently search for any root key file of the quantum security device of the device identification according to the first generation record.
[0061] For ease of understanding, the correspondence between the device identification, the first file sequence number of each root key file corresponding to the device identification, and the storage location of each root key file corresponding to the device identification is determined as the first generation record and is exemplarily displayed in the form of a table:
[0062]
[0063]
[0064] In a possible implementation, the generating import information further includes auxiliary information, and the acquiring the first generation record according to the device identifier, the first file sequence number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier includes:
[0065] A first generation record is obtained based on the device identification, the auxiliary information, the first file serial number of each root key file corresponding to the device identification, and the storage location of each root key file corresponding to the device identification, so as to obtain relevant information of each root key file corresponding to the auxiliary information from the first generation record based on the input auxiliary information; wherein the auxiliary information includes one or more of the following: key generation time, information import time, and device type, and the relevant information of each root key file includes one or more of the following: the device identification corresponding to each root key file, the storage location of each root key file, and the first file serial number of each root key file.
[0066] To facilitate subsequent monitoring and management of each generated root key file, in this application, the generated root key file can also be searched through auxiliary information. The auxiliary information includes one or more of the following: key generation time, information import time, device type, batch number of the generation batch where the key is located, and information import status. Optionally, the auxiliary information can also include key export status, key export time, etc. The information import time represents the time when the generation import information is imported. The information import status indicates whether the generation import information is successfully imported. In this application, the root keys can be generated in batches, and all root key files corresponding to a device identifier are in the same batch. When generating the root key, the batch number of the generation batch where the root key is located can be recorded. And for convenient query, a first generation record can be generated according to the auxiliary information.
[0067] It should be noted that the device type can include one or more of the following: quantum-secure desktop computer, quantum-secure all-in-one computer, and quantum-secure notebook. Of course, the device type can also be flexibly set according to the device type of the quantum-secure device that needs to generate root keys in the actual scenario, and no specific limitation is made here.
[0068] Exemplarily, if the generation import information obtained by the root key center also includes the key generation time, that is, the time when the root key is generated. After obtaining each root key file corresponding to the device identifier based on the above embodiments, the first generation record can be obtained according to the key generation time, device identifier, the first file number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier. Subsequently, when the staff needs to query the root key file at a certain key generation time, the relevant information of each root key file generated at the key generation time can be queried from the first generation record according to the key generation time. The relevant information of each root key file includes one or more of the following: the device identifier corresponding to each root key file, the storage location of each root key file, and the first file number of each root key file.
[0069] For example, the first generation record obtained according to the information import time, the device identifier of the quantum-secure device, the first file number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier is shown exemplarily in the form of a table:
[0070]
[0071]
[0072] Another exemplary case is that if the generation import information obtained by the root key center further includes the information import time, that is, the time when the root key center obtains the generation import information. After obtaining the respective root key files corresponding to the device identifier based on the above embodiments, a first generation record can be obtained according to the information import time, the device identifier, the first file serial numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier. Subsequently, when a staff member needs to query the root key files for a certain information import time, the relevant information of the root key files generated at that information import time can be queried from the first generation record according to the information import time. Among them, the relevant information of the respective root key files includes one or more of the following: the device identifiers respectively corresponding to the respective root key files, the storage locations of the respective root key files, and the first file serial numbers of the respective root key files.
[0073] For example, an exemplary display of obtaining the first generation record in the form of a table according to the information import time, the device identifier, the first file serial numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier is as follows:
[0074]
[0075]
[0076] It should be noted that the method of obtaining the first generation record according to the above auxiliary information is similar to the above embodiments, and the repeated parts will not be elaborated.
[0077] In this application, the first generation record can be obtained according to various auxiliary information. For example, if the generation import information obtained by the root key center further includes the information import time and the key generation time. After obtaining the respective root key files corresponding to the device identifier based on the above embodiments, a first generation record can be obtained according to the information import time, the key generation time, the device identifier, the first file serial numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier. Subsequently, when a staff member needs to query the root key files for a certain information import time and / or a certain key generation time, the relevant information of the root key files that meet the input auxiliary information can be queried from the first generation record according to the input auxiliary information.
[0078] For example, an exemplary display of obtaining the first generation record in the form of a table according to the information import time, the key generation time, the device identifier, the first file serial numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier is as follows:
[0079]
[0080]
[0081] In some possible implementation manners, the root key center may generate multiple groups of root keys for the quantum-secure device of the device identifier. Therefore, the root key center can determine the group identifier corresponding to each group of root keys respectively, and then obtain a first generation record according to the device identifier, the first file sequence number of each root key file corresponding to the device identifier, the storage location of each root key file corresponding to the device identifier, and the group identifier to which each root key file corresponding to the device identifier belongs. The group identifier is used to represent the group where the root key is located.
[0082] For example, determine the first generation record according to the correspondence relationship between the device identifier, the group identifier to which each root key file corresponding to the device identifier belongs, and the first file sequence number of each root key file corresponding to the device identifier, and the correspondence relationship between the first file sequence number of each root key file corresponding to the device identifier and the storage location of each root key file corresponding to the device identifier.
[0083] For ease of understanding, the correspondence relationship between the device identifier of the quantum-secure device, the group identifier to which each root key file corresponding to the device identifier belongs, and the first file sequence number of each root key file corresponding to the device identifier is exemplarily shown in the form of a table:
[0084] Device Identification Group Identification First File Serial Number ID1 group-1 file-1 ID1 group-1 file-2 ID1 group-2 file-3 ID1 group-2 file-4 ID2 group-1 file-5 ID3 group-2 file-6
[0085] For another example, determine the correspondence relationship between the device identifier, the group identifier to which each root key file corresponding to the device identifier belongs, the first file sequence number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier as the first generation record.
[0086] For ease of understanding, the correspondence relationship between the device identifier, the group identifier to which each root key file corresponding to the device identifier belongs, the first file sequence number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier is exemplarily shown in the form of a table:
[0087]
[0088] The group identifier can be identified in the form of numbers, strings, etc., or can be represented in other ways, as long as the way that can uniquely identify the group of root keys can be applied to this application, and no specific limitation is made here.
[0089] Exemplarily, after obtaining the respective root key files corresponding to the device identifier based on the above embodiments, the staff can operate the key output interface of the display corresponding to the root key center, and input the filtering conditions of the root key files to be exported on this interface. For example, device identifier, key generation time, etc. There are many ways for the staff to input the filtering conditions. They can be input by typing text, by voice, or by selection operations. In the specific implementation process, it can be flexibly set according to actual needs and will not be specifically limited here. After the root key center obtains the input filtering conditions, it can find the root key files that meet the filtering conditions from the first generation record and display the relevant information of the filtered root key files on the display interface of the display. The staff can input which root key files to export to the root key center by single selection or batch selection. The root key center exports the root key files selected by this selection operation to the key distributor connected to the root key center and displays the export progress on the display corresponding to the root key center. After the staff determines that the root key center has completed the export of the root key files, the key distributor can be disconnected from the root key center, and subsequently, the root key can be injected into the quantum security device through the key distributor.
[0090] The beneficial effects of this application are as follows:
[0091] 1. Since the root key center can accurately generate and distribute the root key after obtaining the generation import information required for generating the root key, it avoids reducing the efficiency and quality of root key distribution by using the manual root key distribution method, and reduces the manpower and material resources consumed for distributing the root key.
[0092] 2. After obtaining the respective root key files, the first file serial number of each root key file will also be determined, which facilitates the subsequent export or injection of each root key file into the quantum security device in sequence by the root key center.
[0093] 3. After saving each root key file, the first generation record can be obtained according to the device identifier, the first file serial number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier, so that any root key file corresponding to the device identifier can be quickly and accurately found according to the first generation record subsequently, which is beneficial to the management of the root key files corresponding to each device identifier.
[0094] Embodiment 2:
[0095] To ensure the security of the quantum security device when it is connected to the quantum security base station after leaving the factory and to reduce the load of the quantum security device, based on the above embodiments, in the present application, if the generated import information further includes the size of the random number, after obtaining the generated import information, before obtaining the first generation record according to the device identifier, the first file sequence numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier, the method further includes:
[0096] Generate respective random number files corresponding to the device identifier according to the size of the random number and a preset random number file granularity; wherein, the random number is used for the quantum security device with the device identifier to access the quantum security base station;
[0097] Determine the second file sequence numbers of the respective random number files, and save the respective random number files;
[0098] Obtain a second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, and the storage locations of the respective random number files corresponding to the device identifier, so as to search for the respective random number files corresponding to the device identifier according to the second generation record.
[0099] During the process of the quantum security device performing root key verification with the root key center through the quantum security base station, the quantum security device will generate a random number and send the random number to the root key center through the quantum security base station. Since the quantum security device does not have the ability to generate true random numbers, that is, the random numbers generated by the quantum security device are pseudo-random numbers, it is possible for a third-party device to collide with the random number, and then allow the third-party device to impersonate a legitimate device and continue to communicate with the quantum security device, reducing the security of subsequent quantum security communications. Moreover, the quantum security device needs to consume resources to generate random numbers, increasing the load of the quantum security device. Based on this, in the present application, during the process of the root key center allocating root keys to the quantum security device, random numbers can also be allocated to the quantum security device. Exemplarily, the generated import information obtained by the root key center further includes the size of the random number. The root key center generates respective random number files for the device identifier according to the size of the random number and a preset random number file granularity, so as to enable the subsequent quantum security device to use the true random number to perform root key verification with the root key center, improving the security of the process of the quantum security device accessing the quantum security base station, and eliminating the need for the quantum security device to generate random numbers, reducing the load of the quantum security device.
[0100] In a possible implementation, the root key center may allocate multiple groups of root keys to the quantum security device. Based on this, in the present application, the root key center may allocate random numbers to the quantum security device identified by the device identifier according to the number of root keys and the size of the random numbers, so that each group of root keys has a corresponding random number. For example, if the size of the random number represents the size of a group of random numbers, then random numbers of the number of root keys are allocated to the quantum security device identified by the device identifier, and the size of each group of random numbers is the size of the random number. According to the size of the random number and the preset random number file granularity, random number files corresponding to each group of random numbers are generated for the device identifier. Wherein, the number of groups corresponding to the random numbers is the number of root keys.
[0101] For another example, if the size of the random number represents the total size of the random numbers, then the size of a group of random numbers is determined according to the number of root keys and the size of the random numbers. For the determined size of each group of random numbers, respective random number files corresponding to the group of random numbers are allocated to the device identifier according to the determined size of the group of random numbers and the preset random number file granularity.
[0102] Wherein, the specific process of the root key center allocating random numbers to the quantum security device may refer to the process of the root key center allocating root keys to the quantum security device in the above embodiment, which will not be elaborated here.
[0103] Wherein, when the root key center subsequently exports the root key file corresponding to a certain device identifier, it may determine whether to export the random number file corresponding to the device identifier together according to the received operation or default setting.
[0104] In one example, saving the respective random number files includes:
[0105] Determining the checksum corresponding to each of the random number files;
[0106] Correspondingly saving the respective random number files and the checksums corresponding to the respective random number files.
[0107] Considering that after the root key center exports the random number file subsequently, the exported random number file may have security problems such as being tampered with or damaged. Based on this, in the present application, after the root key center obtains any random number file, it may determine the checksum corresponding to the random number file. For example, the checksum corresponding to the random number file is determined through a preset checksum algorithm. Then when saving the random number file, the random number file and the checksum corresponding to the random number file may be correspondingly saved, so that subsequent security problems such as the random number file being tampered with or damaged can be detected in a timely manner based on the checksum.
[0108] After determining each random number file based on the above embodiments, the file serial number of each random number file (denoted as the second file serial number) can be determined to determine the order relationship of each random number file based on the second file serial number.
[0109] In a possible implementation manner, the root key center may generate multiple groups of random numbers for a certain device identifier. When determining the second file identifier of each random number file corresponding to any group of random numbers, the root key center can, for each group of random numbers, determine the second file identifier of each random number file corresponding to that group of random numbers, that is, the second file identifier of each random number file corresponding to that group of random numbers only represents the order relationship of each random number file corresponding to that group of random numbers.
[0110] It should be noted that, in order to facilitate distinguishing the random number files corresponding to different groups of random numbers, the second file serial numbers of the random number files corresponding to different groups of random numbers are all different.
[0111] After the root key center saves each random number file, a generation record (denoted as the second generation record) can be obtained according to the device identifier, the second file serial number of each random number file corresponding to the device identifier, and the storage location of each random number file corresponding to the device identifier. For example, according to the correspondence relationship between the device identifier and the second file serial number of each random number file corresponding to the device identifier, and the correspondence relationship between the second file serial number of each random number file corresponding to the device identifier and the storage location of each random number file corresponding to the device identifier, the second generation record is determined. For another example, the correspondence relationship between the device identifier, the second file serial number of each random number file corresponding to the device identifier, and the storage location of each random number file corresponding to the device identifier is determined as the second generation record. Subsequently, the root key center can search for any random number file corresponding to the device identifier according to the second generation record.
[0112] In an example, the root key center may generate multiple groups of random numbers corresponding to a certain device identifier. Based on this, after generating each group of random numbers, the root key center can, according to the group identifier corresponding to each group of root keys, determine the group identifier corresponding to each group of random numbers respectively, so as to determine a group of random numbers corresponding to each group of root keys respectively according to the group identifier. After the root key center obtains each random number file corresponding to the device identifier based on the above embodiments and saves each random number file, a second generation record can be obtained according to the device identifier of the quantum security device, the second file serial number of each random number file corresponding to the device identifier, the group identifier of each random number file corresponding to the device identifier, and the storage location of each random number file corresponding to the device identifier.
[0113] It should be noted that the first generation record may include the content of the second generation record, that is, the content recorded in the second generation record can also be found through the first generation record.
[0114] During the process of the quantum security device accessing the quantum security base station, the root key center also needs to send the generated random number to the quantum security device. The random number can be generated in real time by the root key center or pre-generated by the root key center.
[0115] Exemplarily, after obtaining the generated import information, the root key center can determine each random number file (denoted as the second random number file) corresponding to the random number for local configuration according to the size of the random number and the preset random number file granularity, and save it. According to the device identifier, the second file sequence number of each second random number file corresponding to the device identifier, and the storage location of each second random number file corresponding to the device identifier, a generation record is obtained, so that the root key center can conveniently find any second random number file corresponding to the device identifier according to the generation record, and obtain the random number to be sent to the quantum security device with the device identifier from the second random number file.
[0116] Another exemplarily, the obtaining of the second generation record according to the device identifier, the second file sequence number of each random number file corresponding to the device identifier, and the storage location of each random number file corresponding to the device identifier includes:
[0117] According to the preset distribution rule, determine the first random number file and the second random number file in each random number file; wherein, the first random number file is used to be configured into the quantum security device with the device identifier, and the second random number file is used for local configuration;
[0118] According to the device identifier, the second file sequence number of each random number file corresponding to the device identifier, the storage location of each random number file corresponding to the device identifier, and the file attributes respectively corresponding to each random number file corresponding to the device identifier, obtain the second generation record, so as to find each random number file corresponding to the device identifier according to the second generation record; wherein, the file attributes include the first random number file and the second random number file.
[0119] After obtaining the random number file based on the above embodiments, the root key center can also determine, from the random number file, the random number file (denoted as the first random number file) for configuring into the quantum secure device with the device identifier, and the second random number file for configuring locally. Exemplarily, an allocation rule is pre-configured. For example, the first random number file and the second random number file are determined from the random number file according to a ratio of 1:1, or the first random number file and the second random number file are determined from the random number file according to a ratio of 6:4. The root key center determines the first random number file and the second random number file in each random number file according to the preset allocation rule. Then, according to the device identifier, the second file sequence number of each random number file corresponding to the device identifier, the storage location of each random number file corresponding to the device identifier, and the file attributes respectively corresponding to each random number file corresponding to the device identifier, a second generation record is obtained. Wherein, the file attributes include the first random file and the second random file. For example, according to the correspondence relationship between the device identifier of the quantum secure device, the second file sequence number of each random number file corresponding to the device identifier, and the file attributes respectively corresponding to each random number file corresponding to the device identifier, and the correspondence relationship between the second file sequence number of each random number file corresponding to the device identifier and the storage location of each random number file corresponding to the device identifier, a second generation record is determined. For another example, the correspondence relationship between the device identifier of the quantum secure device, the second file sequence number of each random number file corresponding to the device identifier, the file attributes respectively corresponding to each random number file corresponding to the device identifier, and the storage location of each random number file corresponding to the device identifier is determined as the second generation record.
[0120] Embodiment 3:
[0121] The quantum secure root key distribution method provided by the present application will be introduced below through specific embodiments. Figure 2 It is a schematic diagram of the specific root key distribution process provided by the embodiment of the present application. The process includes:
[0122] S201: Obtain the generation import information required for generating the root key.
[0123] Among them, the generation import information includes the device identifier, the random number size, the key generation time, the information import time, the number of root keys, and the root key size.
[0124] S202: Generate each root key file corresponding to each group of root keys for the device identifier according to the root key size and the preset root key file granularity.
[0125] Among them, the number of groups of root keys corresponding to the device identifier is the number of root keys.
[0126] S203: For each group of root keys, determine the first file serial number of each root key file corresponding to this group of root keys and the checksum corresponding to each root key file respectively, save each root key file and the checksum corresponding to each root key file respectively, and then execute S207.
[0127] S204: According to the size of this random number and the preset random number file granularity, generate each random number file corresponding to each group of random numbers for this device identifier.
[0128] Wherein, the number of groups of random numbers corresponding to this device identifier is the number of copies of this root key.
[0129] It should be noted that the random number is used for the quantum-secure device corresponding to this device identifier to access the quantum-secure base station.
[0130] S205: For each group of random numbers, determine the second file serial number of each random number file corresponding to this group of random numbers and the checksum corresponding to each random number file respectively, save each random number file and the checksum corresponding to each random number file respectively.
[0131] It should be noted that S204 - S205 can occur before S202 - S203, can also occur after S202 - S203, or can occur simultaneously with S202 - S203, and no specific limitation is made here.
[0132] S206: Determine the group identifier corresponding to each group of files respectively.
[0133] Wherein, any group of files includes each root key file corresponding to a group of root keys and each random number file corresponding to a group of random numbers.
[0134] S207: Obtain the file generation record according to the device identifier, the file serial number of each file corresponding to this device identifier, the storage location of each file corresponding to this device identifier, the key type corresponding to each file corresponding to this device identifier respectively, and the group identifier to which each file corresponding to this device identifier belongs.
[0135] Wherein, the key type includes root key and random number.
[0136] Embodiment 4:
[0137] This application also provides a quantum-secure root key distribution device, Figure 3 As a structural schematic diagram of a quantum-secure root key distribution device provided by this application, this device includes:
[0138] An obtaining unit 31, configured to obtain the generation import information required for generating the root key; wherein, the generation import information includes a device identifier and a root key size;
[0139] A generating unit 32, configured to generate each root key file corresponding to the device identifier according to the root key size and a preset root key file granularity;
[0140] A first processing unit 33, configured to determine a first file serial number of each root key file and save each root key file;
[0141] A second processing unit 34, configured to obtain a first generation record according to the device identifier, the first file serial number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier, so as to find each root key file corresponding to the device identifier according to the first generation record.
[0142] In some possible implementation manners, the generating unit 32 is specifically configured to, if the generated import information further includes the number of root keys, when the root key size represents the total size of the root keys, determine the size of each group of root keys according to the root key size and the number of root keys; for the determined size of each group of root keys, generate each root key file corresponding to the group of root keys for the device identifier according to the size of the group of root keys and a preset root key file granularity; or, when the root key size represents the size of each group of root keys, generate each root key file corresponding to each group of root keys for the device identifier according to the root key size and a preset root key file granularity; wherein, the number of groups of root keys corresponding to the device identifier is the number of root keys;
[0143] The first processing unit 33 is specifically configured to, for each group of root keys, determine the first file serial number of each root key file corresponding to the group of root keys;
[0144] The second processing unit 34 is specifically configured to determine a group identifier corresponding to each group of root keys; obtain the first generation record according to the device identifier, the first file serial number of each root key file corresponding to the device identifier, the storage location of each root key file corresponding to the device identifier, and the group identifier to which each root key file corresponding to the device identifier belongs, so as to find any group of root keys corresponding to the device identifier according to the first generation record.
[0145] In some possible implementation manners, the first processing unit 33 is specifically configured to determine a checksum corresponding to each root key file; save each root key file and the checksum corresponding to each root key file in a corresponding manner.
[0146] In some possible embodiments, the generating unit 32 is further configured to, if the generated import information further includes the size of the random number, after obtaining the generated import information and before obtaining the first generation record according to the device identifier, the first file sequence numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier, generate respective random number files corresponding to the device identifier according to the size of the random number and a preset random number file granularity; wherein the random number is used for a quantum security device with the device identifier to access a quantum security base station.
[0147] The first processing unit 33 is further configured to determine the second file sequence numbers of the respective random number files and save the respective random number files.
[0148] The second processing unit 34 is further configured to obtain a second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, and the storage locations of the respective random number files corresponding to the device identifier, so as to find the respective random number files corresponding to the device identifier according to the second generation record.
[0149] In some possible embodiments, the generating unit 32 is specifically configured to, if the generated import information includes the number of root keys, when the size of the random number represents the total size of the random number, determine the size of each group of random numbers according to the size of the random number and the number of root keys; for the determined size of each group of random numbers, generate respective random number files corresponding to the group of random numbers for the device identifier according to the size of the group of random numbers and a preset random number file granularity; or, when the size of the random number represents the size of each group of random numbers, generate respective random number files corresponding to each group of random numbers for the device identifier according to the size of the random number and a preset random number file granularity; wherein the number of groups of random numbers corresponding to the device identifier is the number of root keys.
[0150] The first processing unit 33 is specifically configured to, for each group of random numbers, determine the second file sequence numbers of the respective random number files corresponding to the group of random numbers.
[0151] The second processing unit 34 is specifically configured to determine the group identifier corresponding to each group of random numbers; obtain the second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, the storage locations of the respective random number files corresponding to the device identifier, and the group identifier to which the respective random number files corresponding to the device identifier belong, so as to find any group of random numbers corresponding to the device identifier according to the second generation record.
[0152] In some possible implementation manners, the second processing unit 34 is specifically configured to determine a first random number file and a second random number file in each of the random number files according to a preset allocation rule; wherein, the first random number file is used to be configured into the quantum secure device with the device identifier, and the second random number file is used to be configured locally; obtain a second generation record according to the device identifier, the second file serial numbers of the random number files corresponding to the device identifier, the storage locations of the random number files corresponding to the device identifier, and the file attributes respectively corresponding to the random number files corresponding to the device identifier, so as to find the random number file of the quantum secure device with the device identifier according to the second generation record; wherein, the file attributes include the first random number file and the second random number file.
[0153] In some possible implementation manners, the second processing unit 34 is specifically configured to, if the generated import information further includes auxiliary information, obtain a first generation record according to the device identifier, the auxiliary information, the first file serial numbers of the root key files corresponding to the device identifier, and the storage locations of the root key files corresponding to the device identifier, so as to obtain the relevant information of the root key files corresponding to the auxiliary information from the first generation record according to the input auxiliary information; wherein, the auxiliary information includes one or more of the following: key generation time, information import time, device type, batch number of the generation batch where the key is located, and information import status, and the relevant information of the root key files includes one or more of the following: the device identifiers respectively corresponding to the root key files, the storage locations of the root key files, and the first file serial numbers of the root key files.
[0154] The beneficial effects of this application are as follows:
[0155] 1. Since the root key center can accurately generate and allocate root keys after obtaining the generation import information required for generating root keys, it avoids reducing the efficiency and quality of root key allocation by using the manual root key allocation method, and reduces the manpower and material resources consumed for allocating root keys.
[0156] 2. After obtaining each root key file, the first file serial number of each root key file will also be determined, which facilitates the subsequent export or filling of each root key file into the quantum secure device by the root key center in sequence.
[0157] 3. After saving each root key file, a first generation record can be obtained according to the device identifier, the first file serial number of the root key files corresponding to the device identifier, and the storage location of the root key files corresponding to the device identifier, so that any root key file corresponding to the device identifier can be quickly and accurately found according to the first generation record subsequently, which is beneficial to the management of the root key files corresponding to each device identifier.
[0158] Example 5:
[0159] Based on the above embodiments, an embodiment of the present application further provides a root key center. Figure 4 FIG. is a schematic structural diagram of a root key center provided by an embodiment of the present application. As Figure 4 shown, it includes: a processor 41, a communication interface 42, a memory 43, and a communication bus 44. Among them, the processor 41, the communication interface 42, and the memory 43 complete mutual communication through the communication bus 44;
[0160] A computer program is stored in the memory 43. When the program is executed by the processor 41, the processor 41 is caused to execute the following steps:
[0161] Obtain the generation import information required for generating the root key; wherein, the generation import information includes a device identifier and a root key size;
[0162] Generate each root key file corresponding to the device identifier according to the root key size and a preset root key file granularity;
[0163] Determine the first file serial number of each root key file, and save each root key file;
[0164] Obtain a first generation record according to the device identifier, the first file serial number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier, so as to search for each root key file corresponding to the device identifier according to the first generation record.
[0165] Since the principle of the above root key center for solving problems is similar to that of the quantum-secure root key distribution method, the implementation of the above root key center can refer to the embodiments of the method, and the repeated parts will not be described again.
[0166] The communication bus mentioned in the above root key center may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface 42 is used for communication between the above root key center and other devices. The memory may include a Random Access Memory (RAM), or may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0167] The above processor may be a general-purpose processor, including a central processing unit, a Network Processor (NP), etc.; it may also be a Digital Signal Processing (DSP), an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0168] Embodiment 6:
[0169] Based on the above embodiments, the embodiment of the present application further provides a computer-readable storage medium, in which a computer program executable by a processor is stored. When the program runs on the processor, the processor is caused to execute the following steps:
[0170] Obtain the generation import information required to generate the root key; wherein, the generation import information includes a device identifier and a root key size;
[0171] Generate each root key file corresponding to the device identifier according to the root key size and a preset root key file granularity;
[0172] Determine the first file serial number of each root key file, and save each root key file;
[0173] Obtain a first generation record according to the device identifier, the first file serial number of each root key file corresponding to the device identifier, and the storage location of each root key file corresponding to the device identifier, so as to find each root key file corresponding to the device identifier according to the first generation record.
[0174] Since the principle of the above computer-readable storage medium for solving problems is similar to that of the quantum-secure root key distribution method, the implementation of the above computer-readable storage medium can refer to the embodiments of the method, and the repeated parts will not be elaborated here.
[0175] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on two or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0176] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the specified functions in Figure Two one process or multiple processes and / or blocks Figure Two one block or multiple blocks.
[0177] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the specified functions in Figure Two one process or multiple processes and / or blocks Figure Two one block or multiple blocks.
[0178] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the specified functions in Figure Two one process or multiple processes and / or blocks Figure Two one block or multiple blocks.
[0179] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to cover these changes and modifications.
Claims
1. A quantum-secure root key distribution method, characterized in that The method includes: Obtaining generation import information required for generating a root key; wherein, the generation import information includes a device identifier and a root key size; Generating respective root key files corresponding to the device identifier according to the root key size and a preset root key file granularity; Determining a first file sequence number of each of the root key files, and saving each of the root key files; Obtaining a first generation record according to the device identifier, the first file sequence number of each of the root key files corresponding to the device identifier, and the storage location of each of the root key files corresponding to the device identifier, so as to find each of the root key files corresponding to the device identifier according to the first generation record; Wherein, if the generation import information further includes the number of root key copies, the generating respective root key files corresponding to the device identifier according to the root key size and a preset root key file granularity includes: In the case where the root key size represents the total size of the root key, determining the size of each group of root keys according to the root key size and the number of root key copies; for the determined size of each group of root keys, generating respective root key files corresponding to the group of root keys for the device identifier according to the size of the group of root keys and a preset root key file granularity; In the case where the root key size represents the size of each group of root keys, generating respective root key files corresponding to each group of root keys for the device identifier according to the root key size and a preset root key file granularity; wherein, the number of groups of root keys corresponding to the device identifier is the number of root key copies; The determining the first file sequence number of each of the root key files includes: For each group of root keys, determining the first file sequence number of each of the root key files corresponding to the group of root keys; The obtaining a first generation record according to the device identifier, the first file sequence number of each of the root key files corresponding to the device identifier, and the storage location of each of the root key files corresponding to the device identifier includes: Determining a group identifier corresponding to each group of root keys, where the group identifier is used to represent the group where the root key is located; Obtaining the first generation record according to the device identifier, the first file sequence number of each of the root key files corresponding to the device identifier, the storage location of each of the root key files corresponding to the device identifier, and the group identifier to which each of the root key files corresponding to the device identifier belongs, so as to find any group of root keys corresponding to the device identifier according to the first generation record.
2. The method according to claim 1, characterized in that, The saving each of the root key files includes: Determining a checksum corresponding to each of the root key files; Correspondingly saving each of the root key files and the checksum corresponding to each of the root key files.
3. The method according to any one of claims 1 or 2, characterized in that If the generation import information further includes a random number size, after obtaining the generation import information and before obtaining a first generation record according to the device identifier, the first file sequence number of each of the root key files corresponding to the device identifier, and the storage location of each of the root key files corresponding to the device identifier, the method further includes: Generate each random number file corresponding to the device identifier according to the size of the random number and the preset random number file granularity; wherein, the random number is used for a quantum-secure device with the device identifier to access a quantum-secure base station. Determine the second file sequence numbers of the respective random number files and save the respective random number files. Obtain a second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, and the storage locations of the respective random number files corresponding to the device identifier, so as to find the respective random number files corresponding to the device identifier according to the second generation record.
4. The method according to claim 3, characterized in that If the generated import information includes the number of root key shares, the generating, according to the size of the random number, each random number file corresponding to the device identifier includes: When the size of the random number represents the total size of the random number, determine the size of each group of random numbers according to the size of the random number and the number of root key shares; for the determined size of each group of random numbers, generate each random number file corresponding to the group of random numbers for the device identifier according to the size of the group of random numbers and the preset random number file granularity. When the size of the random number represents the size of each group of random numbers, generate each random number file corresponding to each group of random numbers respectively for the device identifier according to the size of the random number and the preset random number file granularity; wherein, the number of groups of random numbers corresponding to the device identifier is the number of root key shares. The determining the second file sequence numbers of the respective random number files includes: For each group of random numbers, determine the second file sequence numbers of the respective random number files corresponding to the group of random numbers. The obtaining a second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, and the storage locations of the respective random number files corresponding to the device identifier includes: Determine the group identifiers corresponding to each group of random numbers respectively. Obtain the second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, the storage locations of the respective random number files corresponding to the device identifier, and the group identifiers to which the respective random number files corresponding to the device identifier belong, so as to find any group of random numbers corresponding to the device identifier according to the second generation record.
5. The method according to claim 3, characterized in that The obtaining a second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, and the storage locations of the respective random number files corresponding to the device identifier includes: Determine a first random number file and a second random number file among the respective random number files according to a preset distribution rule; wherein, the first random number file is used to be configured in the quantum-secure device with the device identifier, and the second random number file is used to be configured locally. Obtain a second generation record according to the device identifier, the second file sequence numbers of the respective random number files corresponding to the device identifier, the storage locations of the respective random number files corresponding to the device identifier, and the file attributes respectively corresponding to the respective random number files corresponding to the device identifier, so as to search for the respective random number files corresponding to the device identifier according to the second generation record; wherein, the file attributes include the first random number file and the second random number file.
6. The method according to claim 1, characterized in that, The generated import information further includes auxiliary information. The obtaining of the first generation record according to the device identifier, the first file sequence numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier includes: Obtain a first generation record according to the device identifier, the auxiliary information, the first file sequence numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier, so as to obtain the relevant information of the respective root key files corresponding to the auxiliary information from the first generation record according to the input auxiliary information; wherein, the auxiliary information includes one or more of the following: key generation time, information import time, device type, batch number of the batch where the key is located, and information import status, and the relevant information of the respective root key files includes one or more of the following: the device identifiers respectively corresponding to the respective root key files, the storage locations of the respective root key files, and the first file sequence numbers of the respective root key files.
7. A quantum-secure root key distribution device, characterized in that, The device is used to execute the quantum-secure root key distribution method according to any one of claims 1-6, and includes: An obtaining unit, configured to obtain the generated import information required for generating a root key; wherein, the generated import information includes a device identifier and a root key size; A generating unit, configured to generate the respective root key files corresponding to the device identifier according to the root key size and a preset root key file granularity; A first processing unit, configured to determine the first file sequence numbers of the respective root key files and save the respective root key files; A second processing unit, configured to obtain a first generation record according to the device identifier, the first file sequence numbers of the respective root key files corresponding to the device identifier, and the storage locations of the respective root key files corresponding to the device identifier, so as to search for the respective root key files corresponding to the device identifier according to the first generation record.
8. A root key center, characterized in that, The root key center at least includes a processor and a memory. When the processor executes a computer program stored in the memory, the steps of the quantum-secure root key distribution method according to any one of claims 1-6 are implemented.
9. A computer-readable storage medium, characterized in that, It stores a computer program, and when the computer program is executed by a processor, the steps of the quantum-secure root key distribution method according to any one of claims 1-6 are implemented.
10. A computer program product, characterized in that, The computer program product includes: computer program code. When the computer program code runs on a computer, the computer is caused to execute the steps of the quantum-secure root key distribution method according to any one of claims 1-6 above.
Citation Information
Patent Citations
Generation method and device of root key and medium
CN110417544A
Quantum key distribution method and device and computer readable storage medium
CN115276981A