A quantum-secure root key derivation device, method, root key center, and medium
By obtaining and processing the root key export instructions, the root key files are exported in turn according to the device identification, which solves the problems of low efficiency and management difficulties in the prior art, and realizes efficient and flexible root key file management and charging process.
Patent Information
- Application Number
- CN202211580498.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-12-09
AI Technical Summary
In the prior art, the root key derivation process of quantum security devices is inefficient and cannot achieve simultaneous derivation of multiple devices, resulting in management difficulties and quality degradation.
A quantum secure root key derivation device and method are provided. By obtaining the root key derivation instruction by the acquisition unit, the determination unit determines the root key file according to the filtering conditions, and sequentially exports it to the target storage directory in units of device identification through the processing unit, realizing flexible and efficient root key file management.
Improve the efficiency and quality of root key derivation, avoid confusion between root key files, simplify the management process of multiple devices, and improve user experience and charging efficiency.
Smart Images

Figure CN115913547B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication security technologies, and in particular, to a quantum secure root key derivation device, method, root key center, and medium. Background Art
[0002] In order to ensure the security of data transmission, the sender usually encrypts the data to be sent using an encryption algorithm, and the receiver decrypts the received data using the corresponding decryption algorithm. Classical cryptography has been able to solve the above data security transmission problem well for a long time. However, the security of classical cryptography is based on computational complexity. With the rapid improvement of quantum computing in terms of computing power, there already exist known quantum algorithms to crack traditional public key cryptography technologies, which greatly affects the security of classical cryptography. Therefore, how to ensure the security of data transmission has become an issue that people have increasingly concerned about in recent years.
[0003] As a cross - product of quantum mechanics and cryptography, the security of quantum keys is guaranteed based on the principles of quantum mechanics (the uncertainty principle of unknown quantum states, the measurement collapse principle, and the no - cloning principle), and is independent of the attacker's computing power and storage capacity. Quantum keys can well provide security guarantees for data transmission. Therefore, more and more application scenarios apply quantum secure communication to improve data communication security.
[0004] Currently, if one wants to implement quantum secure communication for quantum secure devices, generally, a large number of keys, that is, root keys, are manually assigned to the quantum secure devices before they leave the factory. Then, the root keys are exported to a key injection machine, so that the key injection machine can inject the root keys into two quantum secure devices that need to communicate, to achieve the pairing of keys in these two quantum secure devices. Subsequently, the two quantum secure devices can perform quantum communication based on the paired keys. For this method, it is necessary to export the root key corresponding to a certain device identifier generated in real - time to the key injection machine, and the key injection machine injects the root key corresponding to the device identifier and the device identifier into the quantum secure device. Only then can the key injection machine continue to export the root key corresponding to the next generated device identifier and inject the exported root key into the next quantum secure device. Otherwise, it will cause confusion between the root keys corresponding to different device identifiers exported, which is not convenient for management and greatly reduces the efficiency and quality of root key injection. In the case of a very large number of quantum secure devices, the disadvantages of this root key export method are particularly obvious. Therefore, there is an urgent need for a method that can improve the efficiency and quality of allocating root keys to quantum secure devices. Summary of the Invention
[0005] The present application provides a quantum-secure root key derivation device, method, root key center, and medium, which are used to solve the problems of low efficiency in the existing root key derivation process and the inability to simultaneously derive the root keys of multiple quantum-secure devices.
[0006] In a first aspect, the present application provides a quantum-secure root key derivation device, which includes an acquisition unit, a determination unit, and a processing unit;
[0007] The acquisition unit is configured to acquire a root key derivation instruction; wherein, the root key derivation instruction carries a screening condition for the root key to be derived and a target storage directory of a quantum-secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing the information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported;
[0008] The determination unit is configured to determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier;
[0009] The processing unit is configured to sequentially export each root key file to the target storage directory in units of the device identifier according to the first file sequence number of each root key file.
[0010] In a second aspect, the present application provides a quantum-secure root key derivation method, which includes:
[0011] Acquire a root key derivation instruction; wherein, the root key derivation instruction carries a screening condition for the root key to be derived and a target storage directory of a quantum-secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing the information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported;
[0012] Determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier;
[0013] According to the first file sequence number of each root key file, sequentially export each root key file to the target storage directory in units of the device identifier.
[0014] In a third aspect, the present application provides a root key center, which at least includes a processor and a memory. When the processor executes the computer program stored in the memory, it implements the steps of the quantum-secure root key derivation method as described above.
[0015] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements the steps of the quantum-secure root key derivation method as described above.
[0016] In a fifth aspect, the present application provides a computer program product, which includes computer program code. When the computer program code runs on a computer, it causes the computer to execute the steps of the quantum-secure root key derivation method as described above.
[0017] The beneficial effects of the present application are as follows:
[0018] 1. Since the root key derivation instruction obtained by the root key center carries the screening conditions for the root key to be derived, and the screening conditions include one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status. According to these screening conditions, more flexible derivation of the root key can be achieved, and the derived root key files all meet the user's requirements, which not only improves the user experience but also avoids the problem of manual mis-derivation of the root key file and improves the quality of the derived root key file.
[0019] 2. In the present application, the root key center can obtain in advance the root key files corresponding to different device identifiers, and then accurately determine the root key files to be derived according to the screening conditions. The derived root key files can correspond to different device identifiers, so as to achieve simultaneous derivation of the root key files of multiple quantum-secure devices, greatly improving the efficiency of root key derivation. There is no need to manually export the root key files corresponding to each device identifier to the target storage directory one by one, reducing the workload of the staff, which is beneficial to subsequent simultaneous injection of root keys into multiple quantum-secure devices and improving the efficiency of the root key injection process.
[0020] 3. Since the root key center exports the root key files to the target storage directory in sequence by device identifier according to the first file sequence number of each root key file, it avoids confusion between the root key files corresponding to different device identifiers and facilitates the management of the root key files corresponding to each device identifier. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0022] Figure 1 Schematic diagram of a root key derivation process provided by an embodiment of the present application;
[0023] Figure 2 Schematic diagram of a specific root key derivation process provided by an embodiment of the present application;
[0024] Figure 3 Schematic diagram of the structure of a root key derivation device provided by the present application;
[0025] Figure 4 Schematic diagram of the structure of a root key center provided by an embodiment of the present application. Detailed implementation manners
[0026] In order to make the objectives, technical solutions, and advantages of the present application clearer, the following further describes the present application in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0027] In order to improve the efficiency and quality of filling root keys for quantum security devices and achieve simultaneous filling of multiple quantum security devices, the embodiments of the present application provide a quantum security root key derivation method, device, root key center, and medium.
[0028] Embodiment 1:
[0029] Figure 1 Schematic diagram of a root key derivation process provided by an embodiment of the present application, the process including:
[0030] S101: Obtain a root key derivation instruction; wherein, the root key derivation instruction carries screening conditions for the root key to be derived and a target storage directory of a quantum security storage device, and the screening conditions include one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing information required for generating the root key, and the information import status indicates whether the information required for generating the root key is successfully imported.
[0031] The key derivation method provided by this application is applied to a root key center, which can be a quantum security device, such as a quantum security all-in-one machine, a quantum security computer, etc., or a quantum security server, such as a quantum security service server, a quantum security application server, etc.
[0032] In a possible application scenario, the root key center stores root key files corresponding to at least one quantum security device respectively. Among them, the root key file can be generated by the root key center. For example, it can be generated by the quantum random number board generator card installed in the root key center, or it can be obtained by the root key center from a quantum random number generation device. Considering that the root key files between different quantum security devices may be confused, therefore, after obtaining the root key file, the root key center can store the relevant information of the root key file corresponding to the storage location of the root key file, so as to facilitate subsequent finding the storage location of any root key file according to the relevant information, thereby realizing the export of the root key file at the storage location. Among them, the relevant information of the root key file includes one or more of the following: the device identifier of the quantum security device to which the root key file belongs (denoted as the device identifier corresponding to the root key file), the device type of the quantum security device to which the root key file belongs, the batch number of the generation batch where the root key is located, the key generation time, the information import time, the file serial number of the root key file (denoted as the first file serial number), and the information import status.
[0033] Among them, the device identifier corresponding to the root key file is used to represent the identity of the quantum security device filled with the root key file, such as the device ID, which can be represented in the form of numbers, strings, etc., or in other forms, as long as it can uniquely identify the quantum security device, it can be applied to this application, and no specific limitation is made here. The device type can include one or more of the following: quantum security desktop computer, quantum security all-in-one machine, and quantum security notebook. Of course, the device type can also be flexibly set according to the device type of the quantum security device that needs to be filled with the root key in the actual scenario, and no specific limitation is made here. In this application, the root key can be generated in batches, and all root key files corresponding to one device identifier are in the same batch. When generating the root key, the batch number of the generation batch where the root key is located can be recorded. The key generation time represents the time when the root key is generated. The information import time represents the time when the information required to generate the root key is imported. The information import status represents whether the information required to generate the root key is successfully imported. The first file serial number is used to represent the sequential relationship of each root key file.
[0034] It should be noted that the root key is recorded in the root key file.
[0035] When the root key center needs to export the root key, the root key center can obtain a root key export instruction. Among them, the root key export instruction can carry the screening conditions of the root key to be exported and the target storage directory of the quantum secure storage device. After obtaining the root key export instruction, the root key center can, according to the screening conditions carried in the root key export instruction and the corresponding relationship between the relevant information of the root key files saved by the root key center and the storage locations, find the root key to be exported, and then export the found root key to the target storage directory.
[0036] Among them, the root key center can obtain the root key export instruction input by the staff from the display corresponding to the root key center, or can receive the root key export instruction sent by other devices.
[0037] It should be noted that there are many ways for the staff to input the root key export instruction to the display corresponding to the root key center. For example, the root key export instruction can be input to the display corresponding to the root key center by means of text input, or can be input to the display corresponding to the root key center by means of voice input, or can also be input to the display corresponding to the root key center by means of selecting the content displayed on the display. No specific limitation is made here.
[0038] S102: Determine each root key file that meets the screening conditions; among them, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier.
[0039] After obtaining the root key export instruction, the root key center can, according to the screening conditions carried in the root key export instruction and the corresponding relationship between the relevant information of the root key files saved by the root key center and the storage locations, find the root key files whose relevant information matches the screening conditions, and then export the found root key files to the target storage directory.
[0040] For example, after the root key center saves the pre-allocated root key files, it can obtain the generation record according to the relevant information of the root key files and the storage locations of the root key files. Subsequently, after the root key center obtains the root key export instruction, it can, according to the screening conditions carried in the root key export instruction, search the generation record, determine the storage locations of the root key files that meet the screening conditions, and then obtain the root key files from the determined storage locations.
[0041] Among them, any root key file corresponds to the device identifier corresponding to the root key file and the total number of root key files corresponding to the device identifier, so as to facilitate subsequent export of each root key file to the target storage location.
[0042] S103: Export each root key file to the target storage directory in sequence based on the first file serial number of each root key file, with the device identifier as the unit.
[0043] Considering that each root key file determined based on the above embodiments may correspond to different device identifiers, and a quantum security device can only be filled with the root key file corresponding to one device identifier. Based on this, in this application, after the root key center obtains each root key file that meets the screening conditions, it can obtain the first file serial number of each root key file. Then, based on the first file serial number of each root key file, export each root key file to the target storage directory in sequence with the device identifier as the unit. For example, the file serial numbers of the obtained root key files are File 1 to File 20 respectively. The device identifiers corresponding to File 1 to File 5 are ID1, the device identifiers corresponding to File 6 to File 12 are ID2, and the device identifiers corresponding to File 13 to File 20 are ID3. The root key center takes the device identifier as the unit and exports File 1 to File 5 corresponding to the device identifier ID1 to the target storage directory in sequence, exports File 6 to File 12 corresponding to the device identifier ID2 to the target storage directory in sequence, and exports File 13 to File 20 corresponding to the device identifier ID3 to the target storage directory in sequence.
[0044] In one example, the root key files corresponding to different device identifiers can be exported to different subdirectories under the target storage directory to facilitate subsequent filling of the root keys for different quantum security devices and avoid confusion between the root key files corresponding to different device identifiers.
[0045] In some possible implementation manners, to facilitate the management of each pre-allocated root key file, after the root key center exports each root key file that meets the screening conditions to the target storage directory, it can record the export information of each root key file to facilitate the staff to monitor the export situation of each root key file. Among them, the export information includes one or more of the following: whether the root key file is completely exported, the device information of the device where the target storage directory is located, and the export time of the root key file.
[0046] In one example, the export status of the root key file can be determined to check whether the root key file is completely exported. For example, the export status can include not exported, export failed, and successfully exported. Before exporting the root key file, the export status of the root key file is not exported. If the root key center determines that the root key file has been completely exported, the export status of the root key file can be updated to successfully exported; if the root key center determines that the root key file cannot be completely exported to the target storage directory during the export process, the export status of the root key file can be updated to export failed. For another example, the export status can include not exported and successfully exported. Before exporting the root key file, the export status of the root key file is not exported. If the root key center determines that the root key file has been completely exported, the export status of the root key file can be updated to successfully exported; otherwise, the export status of the root key file is not updated.
[0047] For the security of the root key file, in this application, the root key center does not repeatedly export the root key file that has been successfully exported. Exemplarily, when determining the root key file to be exported, the root key file to be exported not only meets the screening conditions but also has not been successfully exported.
[0048] In some possible application scenarios, there may be a situation where it is necessary to repeatedly export the root key file that has been successfully exported. Then, it can be determined whether to repeatedly export the root key file that has been successfully exported according to the permission of the account that currently inputs the root key export instruction. Exemplarily, the root key export instruction obtained by the root key center can carry the account permission, and the root key center determines each root key file to be exported according to the account permission and the screening conditions. For example, if the account permission includes allowing repeated export of the root key file, all root key files that meet the screening conditions are exported to the target storage directory; if the account permission includes not allowing repeated export of the root key file, each root key file that meets the screening conditions and has not been successfully exported is exported to the target storage directory.
[0049] In some possible implementation manners, the screening condition further includes a group identifier. Among them, the quantum-secure root key export device pre-allocates at least one group of root keys for at least one quantum-secure device, and any group of root keys includes at least one root key file. The group identifier is used to identify the group where the root key allocated for the quantum-secure device is located.
[0050] When a quantum - secure device accesses a quantum - secure base station, the quantum - secure device can verify the root key with the root key center through the quantum - secure base station. Only after the root key center determines that the root key verification is passed will the root key of the quantum - secure device be sent down to the quantum - secure base station. In this process, situations such as damage or loss of the root key file of the quantum - secure device may occur, resulting in the failure of root key verification, and further causing the quantum - secure base station to be unable to obtain the root key from the root key center. Based on this, in the present application, multiple groups of root keys can be allocated to a quantum - secure device with a device identifier. Any group of root keys includes at least one root key file, so that subsequently, if a group of root keys fails verification, the quantum - secure device can use other root keys to continue verifying with the root key center, ensuring that the quantum - secure device can be reliably connected to the quantum - secure base station. And to facilitate the subsequent processing of these multiple groups of root keys, a group identifier can be assigned to each group of root keys to facilitate subsequent determination of which root key files belong to the same group of root keys according to this group identifier.
[0051] Among them, the group identifier is used to identify which group of root keys a root key file belongs to, that is, the group to which the root key file belongs. It can be represented in the form of numbers, strings, etc., or in other forms, as long as it can uniquely identify the group of root keys, it can be applied to the present application, and no specific limitation is made here.
[0052] In the case where one device identifier may correspond to multiple groups of root keys, if it is necessary to export the root keys corresponding to a certain device identifier, the staff can, according to the requirements, only export some or all of the group root keys corresponding to the device identifier to the target storage directory. Based on this, in the present application, the filtering condition obtained by the root key center can also include the group identifier. According to this filtering condition carrying the group identifier, several groups of root keys corresponding to one device identifier can be exported, thereby realizing a more flexible export of root keys and improving the user experience.
[0053] Among them, the group identifiers corresponding to any two device identifiers can be exactly the same, partially the same, or completely different. For example, the group identifiers corresponding to the device identifier ID1 include group identifier 1 and group identifier 2, and the group identifiers corresponding to the device identifier ID2 also include group identifier 1 and group identifier 2, or, the group identifiers corresponding to the device identifier ID1 include group identifier 1 and group identifier 2, and the group identifiers corresponding to the device identifier ID2 also include group identifier 1 and group identifier 3, or, the group identifiers corresponding to the device identifier ID1 include group identifier 1 and group identifier 2, and the group identifiers corresponding to the device identifier ID2 also include group identifier 3 and group identifier 4.
[0054] In one example, the step of sequentially exporting the root key files to the target storage directory in units of device identifiers according to the first file sequence numbers of the root key files includes:
[0055] If each of the root key files corresponds to a group identifier and the number of root key files corresponding to the group identifier, for the device identifiers corresponding to the respective root key files, according to the first file numbers of the respective root key files corresponding to the device identifier, the respective root key files corresponding to the device identifier are sequentially exported to the target storage directory in units of the group identifier.
[0056] Among the respective root key files obtained by the root key center based on the above embodiments that meet the screening conditions, there may be multiple groups of root keys corresponding to one device identifier. Based on this, in the present application, when exporting the respective root key files corresponding to any device identifier to the target storage directory, it is also necessary to sequentially export the respective root key files corresponding to the device identifier to the target storage directory in units of the group identifier according to the first file numbers of the respective root key files corresponding to the device identifier. For example, the respective root key files corresponding to the device identifier ID2 are files 6 to 12. Files 6 to 8 correspond to the group identifier group identifier 1, files 9 to 10 correspond to the group identifier group identifier 2, and files 11 to 12 correspond to the group identifier group identifier 3. The root key center sequentially exports files 6 to 8 corresponding to the device identifier ID2 to the target storage directory, sequentially exports files 9 to 10 corresponding to the device identifier ID2 to the target storage directory, and sequentially exports files 11 to 12 corresponding to the device identifier ID2 to the target storage directory.
[0057] In one example, the root key files corresponding to different group identifiers can be exported to different subdirectories under the target storage directory to facilitate subsequent injection of the root keys of different group identifiers for any quantum security device and avoid confusion between the root key files of different group identifiers. For example, the root key center creates different device directories under the directory storage directory. The device directory is used to store the respective root key files corresponding to any device identifier. Different group directories can also be created under any device directory. The group directory is used to store the respective root key files corresponding to any group identifier among the respective root key files corresponding to the device identifier.
[0058] Among them, the root key file may also correspond to the total number of root key files belonging to the same group as the root key file (denoted as the group file number), so as to facilitate subsequent determination of whether the root key files of the group are completely exported according to the group file number.
[0059] In this application, the root key file of a certain device identifier can be injected into a quantum-secure device to be shipped. To enable communication between two quantum-secure devices, after the quantum-secure device is shipped, it is connected to a quantum-secure base station in the quantum-secure network. The quantum-secure base station can obtain the root key file paired with the quantum-secure device from the root key center based on the device identifier of the quantum-secure device. Subsequently, the root key center can determine the root key corresponding to the key index in the key relay packet to be relayed based on the paired root key, and then send the root key to another quantum-secure device. There is no need to manually inject the root key file into the two quantum-secure devices in advance, reducing the manpower and material resources required for manual key injection and greatly reducing the cost of quantum-secure communication between the two quantum-secure devices. Moreover, after the quantum-secure device is connected to the quantum-secure network, the quantum-secure base station in the quantum-secure network can obtain the root key file of the quantum-secure device from the root key center, improving the flexibility of quantum-secure communication.
[0060] The beneficial effects of this application are as follows:
[0061] 1. Since the root key export instruction obtained by the root key center carries the screening conditions for the root key to be exported, the screening conditions include one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status. According to these screening conditions, more flexible export of the root key can be achieved, and the exported root key files all meet the user's requirements, not only improving the user experience but also avoiding the problem of manual mis-export of the root key file and improving the quality of the exported root key file.
[0062] 2. In this application, the root key center can obtain in advance the root key files corresponding to different device identifiers, and subsequently, according to the screening conditions, accurately determine the root key files to be exported. The exported root key files can correspond to different device identifiers, thus enabling the simultaneous export of the root key files of multiple quantum-secure devices, greatly improving the efficiency of root key export. There is no need to manually export the root key files corresponding to each device identifier to the target storage directory one by one, reducing the workload of the staff and facilitating the subsequent injection of the root key into multiple quantum-secure devices at the same time, improving the efficiency of the root key injection process.
[0063] 3. Since the root key center exports the root key files to the target storage directory in sequence by device identifier according to the first file number of each root key file, it avoids confusion between the root key files corresponding to different device identifiers and facilitates the management of the root key files corresponding to each device identifier.
[0064] Example 2:
[0065] To ensure the security of the quantum - safe device when it is connected to the quantum - safe base station after leaving the factory and to reduce the load of the quantum - safe device, based on the above - mentioned embodiments, in the present application, if the screening condition includes an exported random - number identifier, the method further includes:
[0066] Determine the random - number files corresponding to each root - key file; wherein each of the random - number files corresponds to a random number and a device identifier, and the random number is used for the quantum - safe device to access the quantum - safe base station;
[0067] According to the second file sequence numbers of the random - number files, export the random - number files to the target storage directory in units of the device identifier in sequence.
[0068] During the process of the quantum - safe device performing root - key verification with the root - key center through the quantum - safe base station, the quantum - safe device generates a random number and sends the random number to the root - key center through the quantum - safe base station. Since the quantum - safe device does not have the ability to generate true random numbers, that is, the random numbers generated by the quantum - safe device are pseudo - random numbers, it is possible for a third - party device to collide with the random number, and then the third - party device can impersonate a legitimate device to continue communicating with the quantum - safe device, reducing the security of subsequent quantum - safe communication. Moreover, the quantum - safe device needs to consume resources to generate random numbers, increasing the load of the quantum - safe device. Based on this, in the present application, a corresponding random number can be pre - assigned to a certain device identifier. Subsequently, when exporting each root - key file corresponding to the device identifier, the root - key center can also obtain the random number corresponding to the device identifier and export the random number corresponding to the device identifier to improve the security of the quantum - safe device when it is connected to the quantum - safe base station after leaving the factory and to reduce the load of the quantum - safe device.
[0069] In some possible application scenarios, some quantum - safe devices do not need to be filled with random numbers for the first - access authentication before leaving the factory. Therefore, in the present application, the staff can flexibly set whether to output the corresponding random - number files when exporting the root - key files according to the requirements. Exemplarily, the screening condition obtained by the root - key center may further include an identifier indicating whether to export the random number. If the screening condition obtained by the root - key center includes an exported random - number identifier, it indicates that the random number needs to be exported, and then determine the random - number files corresponding to each root - key file that meets the screening condition; if the screening condition obtained by the root - key center includes a non - exported random - number identifier, it indicates that the random number does not need to be exported, and then export each root - key file that meets the screening condition to the target storage directory.
[0070] Wherein, the identifier indicating whether to export the random number can be represented in the form of a number, a string, etc., or in other forms, as long as it can uniquely identify whether to export the random number, it can be applied to the present application, and no specific limitation is made here.
[0071] It should be noted that each random number file corresponds to a file serial number (denoted as the second file serial number), a device identifier, and the total number of random number files corresponding to the device identifier.
[0072] If random numbers need to be exported, after the root key center obtains the random number files to be exported, it can export each random number file to the target storage directory in sequence based on the device identifier according to the second file serial number of each random number file. For example, the second file serial numbers of the obtained random number files are respectively random number file 1 to random number file 20, the device identifier corresponding to random number file 1 to random number file 5 is ID1, the device identifier corresponding to random number file 6 to random number file 12 is ID2, and the device identifier corresponding to random number file 13 to random number file 20 is ID3. The root key center exports random number file 1 to random number file 5 corresponding to the device identifier ID1 to the target storage directory in sequence, exports random number file 6 to random number file 12 corresponding to the device identifier ID2 to the target storage directory in sequence, and exports random number file 13 to random number file 20 corresponding to the device identifier ID3 to the target storage directory in sequence.
[0073] In one example, the random number files corresponding to different device identifiers can be exported to different subdirectories under the target storage directory to facilitate subsequent injection of root keys for different quantum security devices and avoid confusion between random number files corresponding to different device identifiers.
[0074] In one possible implementation, multiple groups of root keys may be pre-allocated for any device identifier. Then, each group of root keys requires a corresponding group of random numbers. Based on this, in this application, if multiple groups of root keys are allocated for any device identifier, a corresponding group of random numbers is allocated for the multiple groups of root keys so that each group of root keys has a corresponding group of random numbers. Any group of random numbers includes at least one random number file. Each group of random numbers corresponds to a group identifier, so that it can be determined which random number files belong to the same group of random numbers through the group identifier. Subsequently, when random number files need to be exported, all the random number files included in the entire group of random numbers are exported.
[0075] Among them, it is also possible to determine a group of random numbers corresponding to any group of root keys through the group identifier.
[0076] In one example, when exporting random number files to the target storage directory, for the device identifier corresponding to each random number file respectively, according to the random number files corresponding to the device identifier, the random number files corresponding to the device identifier are exported to the target storage directory in sequence based on the group identifier to avoid confusion between random number files of different groups.
[0077] To facilitate monitoring the export status of each random number file, after each random number file is exported to the target storage directory, the export information of each random number file can also be recorded.
[0078] Embodiment 3:
[0079] To facilitate the monitoring and management of the exported files, based on the above embodiments, in this application, if each file includes the root key file and the random number file, the method includes:
[0080] Generate an export record table according to each file; wherein, the export record table corresponds to the device identifier respectively corresponding to each file, the export status respectively corresponding to each file, the key type respectively corresponding to each file, and the file serial number of each file; wherein, the key type includes the root key and random numbers.
[0081] In some possible scenarios, the staff may need to view and manage the already exported files. Among them, the file can be the root key file or the random number file. Therefore, in this application, after the root key center exports any file to the target storage directory, the device identifier corresponding to the file, the export status corresponding to the file, the key type corresponding to the file, and the file serial number of the file can be recorded in the export record table to facilitate the subsequent staff to view and manage the export status of the file.
[0082] Among them, the key type includes random numbers and the root key.
[0083] It should be noted that the key type can be represented in the form of numbers, strings, etc., or in other forms, as long as it can uniquely identify the form of the file of the key type, it can be applied to this application, and no specific limitation is made here.
[0084] To ensure the security of the files after export and after being filled into the quantum security device, in this application, according to the file serial numbers of each file, each file is exported to the target storage directory in sequence by device identifier, including:
[0085] Determine the checksum respectively corresponding to each file; wherein, each file includes the root key file and the random number file;
[0086] According to the file serial numbers of each file, each file and the checksum respectively corresponding to each file are exported to the target storage directory in sequence by device identifier.
[0087] Considering that after the file is exported from the root key center, security issues such as file tampering and damage may occur. Based on this, in this application, after the root key center obtains any file to be exported based on the above embodiments, it can determine the checksum corresponding to the file. For example, the checksum corresponding to the file can be determined through a preset checksum algorithm. Then, the file and the checksum corresponding to the file are exported to the target storage directory, so that subsequent security issues such as whether the file is tampered with or damaged can be detected in a timely manner based on the checksum.
[0088] Embodiment 4:
[0089] The following uses specific embodiments to describe in detail a quantum-secure root key export method provided by this application. Figure 2 It is a schematic diagram of the specific root key export process provided by the embodiments of this application. The process includes:
[0090] S201: Obtain a root key export instruction.
[0091] Among them, the root key export instruction carries the screening conditions of the root key to be exported and the target storage directory of the quantum-secure storage device. The screening conditions include one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, information import status, account permission, and export random number identifier.
[0092] Optionally, the screening conditions may further include a group identifier.
[0093] S202: Determine each root key file that meets the screening conditions according to the account permission, and the random number file corresponding to each root key file.
[0094] S203: Determine the check code corresponding to each file.
[0095] Among them, each exported file includes each random number file determined in S202 and each root key file determined in S202.
[0096] S204: Export each file and the check code corresponding to each file to the target storage directory in sequence in units of the device identifier according to the file serial number of each file.
[0097] Among them, specifically exporting each root key file to the target storage directory in sequence in units of the device identifier according to the first file serial number of each root key file includes: exporting each root key file corresponding to the device identifier to the target storage directory in sequence in units of the group identifier according to the first file serial number of each root key file corresponding to the device identifier.
[0098] Specifically, according to the second file sequence number of each random number file, each random number file is exported to the target storage directory in units of device identifiers, including: for the device identifier corresponding to each random number file, according to the second file sequence number of each random number file corresponding to the device identifier, each random number file corresponding to the device identifier is exported to the target storage directory in units of group identifiers in sequence.
[0099] S205: Generate an export record form for each exported file.
[0100] Among them, the export record form corresponds to the device identifier corresponding to each file, the export status corresponding to each file, the key type corresponding to each file, and the file sequence number of each file; among them, the key type includes a root key and a random number.
[0101] Embodiment 5:
[0102] The present application also provides a quantum-secure root key export device. Figure 3 As shown in the structural schematic diagram of a quantum-secure root key export device provided by the present application, the device includes: an acquisition unit 31, a determination unit 32, and a processing unit 33.
[0103] The acquisition unit 31 is used to acquire a root key export instruction; wherein, the root key export instruction carries a screening condition for the root key to be exported and a target storage directory of a quantum-secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported.
[0104] The determination unit 32 is used to determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier.
[0105] The processing unit 33 is used to export each root key file to the target storage directory in units of device identifiers according to the first file sequence number of each root key file.
[0106] In some possible implementation manners, the processing unit 33 is further used to record the export information of each root key file; wherein, the export information includes one or more of the following: whether the root key file is completely exported, the device information of the quantum-secure storage device, and the export time of the root key file.
[0107] In some possible embodiments, the determining unit 32 is specifically configured to determine each root key file that meets the screening conditions and has not been successfully exported.
[0108] In some possible embodiments, the determining unit 32 is specifically configured to, if the root key export instruction carries account permissions, determine each root key file that meets the screening conditions according to the account permissions.
[0109] In some possible embodiments, the processing unit 33 is specifically configured to, if each of the root key files corresponds to a group identifier and the number of root key files corresponding to the group identifier, for the device identifier corresponding to each of the root key files, according to the first file serial number of each root key file corresponding to the device identifier, export each root key file corresponding to the device identifier to the target storage directory in units of the group identifier in sequence.
[0110] In some possible embodiments, the screening conditions further include a group identifier, wherein the quantum-secure root key export device pre-allocates at least one group of root keys to at least one quantum-secure device, and any group of root keys includes at least one root key file, and the group identifier is used to identify the group where the root keys allocated to the quantum-secure device are located.
[0111] In some possible embodiments, the determining unit 32 is further configured to, if the screening conditions include an export random number identifier, determine the random number files corresponding to the respective root key files; wherein each of the random number files corresponds to a device identifier and the total number of random number files corresponding to the device identifier, and the random numbers are used for quantum-secure devices to access a quantum-secure base station.
[0112] The processing unit 33 is further configured to export each of the random number files to the target storage directory in units of the device identifier in sequence according to the second file serial number of each of the random number files.
[0113] In some possible embodiments, the processing unit 33 is further configured to generate an export record table according to the respective files; wherein the export record table corresponds to the device identifier corresponding to each of the files, the export status corresponding to each of the files, the key type corresponding to each of the files, and the file serial number of each of the files; wherein the respective files include the respective root key files and the respective random number files, and the key types include root keys and random numbers.
[0114] In some possible embodiments, the determining unit 32 is further configured to determine the check code corresponding to each of the files before exporting each of the files to the target storage directory in units of the device identifier according to the file serial number of each of the files; wherein the respective files include the root key files and the random number files.
[0115] The processing unit 33 is specifically configured to export each of the files and the corresponding check codes of each of the files to the target storage directory in sequence by device identifier according to the file sequence numbers of the files.
[0116] The beneficial effects of this application are as follows:
[0117] 1. Since the root key export instruction obtained by the root key center has screening conditions corresponding to the root keys to be exported, the screening conditions include one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status. According to these screening conditions, more flexible export of root keys can be achieved, and the exported root key files all meet the user's requirements. This not only improves the user experience but also avoids the problem of manual mis-exporting root key files, improving the quality of the exported root key files.
[0118] 2. In this application, the root key center can obtain in advance the root key files corresponding to different device identifiers, and then accurately determine the root key files to be exported according to the screening conditions. The exported root key files can correspond to different device identifiers, thus realizing the simultaneous export of root key files of multiple quantum security devices, greatly improving the efficiency of root key export. There is no need to manually export the root key files corresponding to each device identifier to the target storage directory one by one, reducing the workload of the staff and facilitating the subsequent simultaneous injection of root keys into multiple quantum security devices, improving the efficiency of the root key injection process.
[0119] 3. Since the root key center exports each root key file to the target storage directory in sequence by device identifier according to the first file sequence number of each root key file, it avoids confusion between the root key files corresponding to different device identifiers and facilitates the management of the root key files corresponding to each device identifier.
[0120] Embodiment 6:
[0121] Based on the above embodiments, an embodiment of this application further provides a root key center. Figure 4 It is a schematic structural diagram of a root key center provided by an embodiment of this application, as Figure 4 shown, including: a processor 41, a communication interface 42, a memory 43, and a communication bus 44. Among them, the processor 41, the communication interface 42, and the memory 43 communicate with each other through the communication bus 44;
[0122] A computer program is stored in the memory 43. When the program is executed by the processor 41, the processor 41 is caused to execute the following steps:
[0123] Obtain a root key export instruction; wherein, the root key export instruction carries a screening condition for the root key to be exported and a target storage directory of the quantum secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported;
[0124] Determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier;
[0125] According to the first file serial number of each root key file, export each root key file to the target storage directory in units of the device identifier in sequence.
[0126] Since the principle of the above root key center for solving problems is similar to the quantum secure root key export method, the implementation of the above root key center can refer to the embodiments of the method, and the repeated parts will not be elaborated.
[0127] The communication bus mentioned in the above root key center may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface 42 is used for communication between the above root key center and other devices. The memory may include a Random Access Memory (RAM), and may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0128] The above processor may be a general-purpose processor, including a central processor, a Network Processor (NP), etc.; it may also be a Digital Signal Processing (DSP), an application-specific integrated circuit, a field-programmable gate array or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0129] Embodiment 6:
[0130] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program executable by a processor. When the program runs on the processor, the processor is caused to perform the following steps:
[0131] Obtain a root key export instruction; wherein, the root key export instruction carries a screening condition for the root key to be exported and a target storage directory of the quantum secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported;
[0132] Determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier;
[0133] According to the first file sequence numbers of the respective root key files, export the respective root key files to the target storage directory in units of the device identifier.
[0134] Since the principle of the above computer-readable storage medium for solving problems is similar to that of the quantum secure root key export method, the implementation of the above computer-readable storage medium can refer to the embodiments of the method, and the repeated parts will not be described again.
[0135] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on two or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0136] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 2 one process or multiple processes and / or blocks Figure 2means for the functions specified in one or more boxes.
[0137] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 2 one or more processes and / or boxes Figure 2 means for the functions specified in one or more boxes.
[0138] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 2 one or more processes and / or boxes Figure 2 means for the functions specified in one or more boxes.
[0139] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these changes and modifications.
Claims
1. A quantum-secure root key derivation device, characterized in that, The device includes: an acquisition unit, a determination unit, and a processing unit; The acquisition unit is configured to acquire a root key export instruction; wherein, the root key export instruction carries a screening condition for the root key to be exported and a target storage directory of the quantum-secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing the information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported; The determination unit is configured to determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier; The processing unit is configured to sequentially export each of the root key files to the target storage directory in units of the device identifier according to the first file sequence number of each root key file.
2. The device according to claim 1, characterized in that, The processing unit is further configured to record the export information for each of the root key files; wherein, the export information includes one or more of the following: whether the root key file is completely exported, the device information of the quantum-secure storage device, and the export time of the root key file.
3. The device according to claim 2, wherein The determination unit is specifically configured to determine each root key file that meets the screening condition and has not been successfully exported.
4. The device according to claim 2, characterized in that The determination unit is specifically configured to, if the root key export instruction carries an account privilege, determine each root key file that meets the screening condition according to the account privilege.
5. The device according to claim 1, characterized in that, The processing unit is specifically configured to, if each of the root key files corresponds to a group identifier and the number of root key files corresponding to the group identifier, for each device identifier corresponding to each root key file, sequentially export the root key files corresponding to the device identifier to the target storage directory in units of the group identifier; wherein, the group identifier is used to identify the group where the root key allocated to the quantum-secure device is located.
6. The device according to claim 1, characterized in that, The screening condition further includes a group identifier, wherein the quantum-secure root key export device has pre-allocated at least one group of root keys for at least one quantum-secure device, and any group of root keys includes at least one root key file, and the group identifier is used to identify the group where the root key allocated to the quantum-secure device is located.
7. The device according to claim 1, characterized in that The determination unit is further configured to, if the screening condition includes an export random number identifier, determine the random number file corresponding to each root key file; wherein, each random number file corresponds to a device identifier and the total number of random number files corresponding to the device identifier, and the random number is used for the quantum-secure device to access the quantum-secure base station; The processing unit is further configured to sequentially export each of the random number files to the target storage directory in units of the device identifier according to the second file sequence number of each random number file.
8. The device according to claim 7, characterized in that, The processing unit is further configured to generate an export record table according to each file; wherein, the export record table corresponds to the device identifier respectively corresponding to each file, the export status respectively corresponding to each file, the key type respectively corresponding to each file, and the file serial number of each file; wherein, each file includes each root key file and each random number file, and the key type includes root key and random number.
9. The device according to claim 7, characterized in that, The determining unit is further configured to determine the check code respectively corresponding to each file before sequentially exporting each file to the target storage directory in units of device identifiers according to the file serial number of each file; wherein, each file includes the root key file and the random number file; The processing unit is specifically configured to sequentially export each file and the check code respectively corresponding to each file to the target storage directory in units of device identifiers according to the file serial number of each file.
10. A quantum-secure root key derivation method, characterized in that, The method includes: Obtain a root key export instruction; wherein, the root key export instruction carries a screening condition for the root key to be exported and a target storage directory of the quantum secure storage device, and the screening condition includes one or more of the following: device identifier, device type, batch number of the generation batch where the root key is located, key generation time, information import time, and information import status; wherein, the information import time is the time for importing the information required to generate the root key, and the information import status indicates whether the information required to generate the root key is successfully imported; Determine each root key file that meets the screening condition; wherein, any root key file corresponds to a device identifier and the total number of root key files corresponding to the device identifier; According to the first file serial number of each root key file, sequentially export each root key file to the target storage directory in units of device identifiers.
11. A root key center, characterized in that, The root key center at least includes a processor and a memory, and the processor is configured to implement the steps of the quantum secure root key export method as claimed in claim 10 when executing the computer program stored in the memory.
12. A computer-readable storage medium, characterized in that, It stores a computer program, and when the computer program is executed by a processor, it implements the steps of the quantum secure root key export method as claimed in claim 10.
13. A computer program product, characterized in that, The computer program product includes: computer program code, and when the computer program code runs on a computer, it causes the computer to execute the steps of the quantum secure root key export method as claimed in claim 10 above.
Citation Information
Patent Citations
Key processing method and device and terminal equipment
CN114531676A
Encrypted communication based on quantum key
IN201941025665A