Output quantum security key and authentication parameter method, device and root key center

The key file is determined based on the device identification and other conditions through the root key center, and the authentication parameters and random numbers are used to ensure the security of the key file, solving the security problem after the root key is derived, and improving the flexibility and efficiency of quantum secure communication.

CN116032473BActive Publication Date: 2025-08-12MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310066684.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-17
Publication Date
2025-08-12
Estimated Expiration
2043-01-17

AI Technical Summary

Technical Problem

The root keys of existing quantum security devices are insufficient after derivation, and the flexibility of quantum secure communication is low, resulting in waste of manpower and physical costs and the communication method is not flexible enough.

Method used

The output command is obtained through the root key center, and the key file is determined based on the device identification, type, batch generation, generation time and other conditions, and the authentication parameters and random numbers are used to ensure the security of the key file, so as to realize the flexible export and secure communication of the key file.

Benefits of technology

It improves the security and export efficiency of key files, reduces storage pressure, enhances the flexibility and security of quantum secure communication, and reduces manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032473B_ABST
    Figure CN116032473B_ABST
Patent Text Reader

Abstract

This application discloses a method, device, and root key center for outputting quantum secure keys and authentication parameters. When exporting key files, the root key center also exports fixed data determined based on the authentication parameters corresponding to each key file. The authentication parameters include a first random number to be expanded for encrypting and decrypting each key file, an index for searching the authentication parameters, a first random number for encrypting the encrypted data in an access request, and a second random number for decrypting the decrypted data in an access response. The first random number to be expanded enables the encrypted output of the key file and its injection into a quantum secure device, ensuring the security of the key file. The first and second random numbers enable the quantum secure device to use ciphertext communication during its initial access to a quantum secure base station, ensuring the security of the initial access process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of quantum security technology, and in particular to a method, device, and root key center for outputting quantum security keys and authentication parameters. Background Art

[0002] As a crucial means of information security, traditional encryption communication methods have long garnered widespread attention. However, with the rapid development of electronic computers, particularly supercomputers, these methods are facing serious threats. The emergence of quantum computers, which could, in principle, rapidly crack widely used traditional cryptographic systems, raises concerns about the security of traditional encryption methods that rely on mathematical complexity.

[0003] Unlike traditional encrypted communication methods that rely on mathematical algorithms for security, the absolute security of quantum secure communication is guaranteed by fundamental principles of physics. The quantum keys used in this communication, a cross between quantum mechanics and cryptography, are based on the principles of quantum mechanics (the uncertainty principle of unknown quantum states, the measurement collapse principle, and the non-cloning principle). They are independent of the attacker's computing and storage capabilities, providing excellent security for data transmission. For this reason, quantum secure communication has been widely used in information security.

[0004] In related technologies, quantum secure communication can be achieved using quantum security devices. Before a quantum security device leaves the factory, a large number of factory keys, known as root keys, are manually assigned to a specific device ID. This device ID and the root key corresponding to it are then injected into the two quantum security devices that need to communicate, thereby pairing the keys in the two quantum security devices. The two quantum security devices can then conduct quantum secure communication based on this paired key. Whether the quantum security device can securely and accurately obtain the pre-assigned root key is a crucial prerequisite for subsequent quantum secure communication. However, in this approach, the derived root key may be subject to security issues such as theft, tampering, and corruption, thus compromising the security of the root key and, in turn, the quantum security device that injected it, significantly impacting the security of quantum secure communication. Moreover, since this method requires staff to pre-charge the two quantum security devices that wish to communicate with paired keys before quantum secure communication can be carried out between the two quantum security devices, it not only wastes a lot of manpower, physical and other costs, but also is not flexible enough when additional quantum security devices that wish to communicate are needed or when communication with a certain quantum security device is no longer needed. Summary of the Invention

[0005] The present application provides a method, apparatus, and root key center for outputting quantum security keys and authentication parameters, to address the existing problems of being unable to guarantee the security of root keys after export and having low flexibility in quantum security communication between any two quantum security devices.

[0006] In a first aspect, the present application provides a device for outputting quantum security keys and authentication parameters, the device comprising: an acquisition unit, a determination unit, and a processing unit;

[0007] The acquisition unit is configured to acquire an output command; wherein the output command carries an output condition for the key and a target storage directory of the quantum secure storage device, the output condition including one or more of the following: a device identifier, a device type, a batch number of a key generation batch, a key generation time, an information import time, and an information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported;

[0008] The determining unit is configured to determine each key file that meets the output condition and the authentication parameters corresponding to each key file; wherein each key file includes at least one root key file, and the at least one root key file is used for quantum encryption and decryption. The authentication parameters include a first random number to be expanded for encrypting and decrypting each key file, an authentication index for searching the authentication parameter, a first random number for encrypting the data to be encrypted in the access request, and a second random number for decrypting the data to be decrypted in the access response information. The first random number to be expanded is configured in the quantum security device. The access request is a message for the quantum security device to request the first access to a quantum security base station in the quantum security network. The access response information is a message sent by the quantum security base station to the quantum security device in response to the access request. After the quantum security base station allows the quantum security device to access, the quantum security base station relays the keys sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center; obtains the encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file; for each key file, determines the encryption and decryption key corresponding to the key file according to the encryption and decryption root key corresponding to the key file, encrypts the key file according to the encryption and decryption key, obtains the encrypted key file, and determines the solidified data corresponding to the encrypted key file according to the authentication parameter corresponding to the key file; wherein the solidified data includes the first random number to be expanded;

[0009] The processing unit is used to export each encryption key file and the solidified data corresponding to each encryption key file to the target storage directory in sequence based on the device identification according to the file serial numbers corresponding to each pre-saved key file.

[0010] In a second aspect, the present application provides a method for outputting quantum secure keys and authentication parameters, the method comprising:

[0011] Obtain an output command; wherein the output command carries the key output conditions and the target storage directory of the quantum secure storage device, the output conditions including one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported;

[0012] Determining key files that meet the output condition and authentication parameters corresponding to the key files; wherein the key files include at least one root key file, the at least one root key file is used for quantum encryption and decryption, the authentication parameters include a first random number to be expanded for encrypting and decrypting the key files, an authentication index for searching the authentication parameters, a first random number for encrypting data to be encrypted in an access request, and a second random number for decrypting data to be decrypted in an access response message, the first random number to be expanded is configured in a quantum security device, the access request is a message from the quantum security device requesting first access to a quantum security base station in a quantum security network, the access response message is a feedback message sent by the quantum security base station to the quantum security device in response to the access request, and after the quantum security base station allows the quantum security device to access, it relays the key sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center;

[0013] Obtaining encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file;

[0014] For each key file, determining an encryption and decryption key corresponding to the key file based on the encryption and decryption root key corresponding to the key file, encrypting the key file based on the encryption and decryption key to obtain an encrypted key file, and determining, based on the authentication parameters corresponding to the key file, the fixed data corresponding to the encrypted key file; wherein the fixed data includes the first random number to be expanded;

[0015] According to the pre-saved file serial numbers corresponding to the key files, the encryption key files and the hardened data corresponding to the encryption key files are exported to the target storage directory in sequence based on the device identification.

[0016] In a third aspect, the present application provides a root key center, which includes at least a processor and a memory, and the processor is used to implement the steps of the method for outputting quantum security keys and authentication parameters as described above when executing a computer program stored in the memory.

[0017] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the method for outputting quantum security keys and authentication parameters as described above.

[0018] In a fifth aspect, the present application provides a computer program product, comprising: computer program code, which, when executed on a computer, enables the computer to execute the steps of the method for outputting quantum security keys and authentication parameters as described above.

[0019] The beneficial effects of this application are as follows:

[0020] 1. Since the output instruction obtained by the root key center carries output conditions, the output conditions include one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status. According to the output conditions, more flexible key file export can be achieved, and the exported key files meet user needs, which not only improves the user experience, but also avoids the problem of human misleading key files, and improves the quality of the exported key files.

[0021] 2. In this application, the root key center can obtain the key files corresponding to different device identifiers in advance, and then accurately determine the need to export each key file based on the output conditions. The exported key files can correspond to different device identifiers, thereby realizing the simultaneous export of key files for multiple device identifiers, greatly improving the efficiency of key export. There is no need to manually export the key files corresponding to each device identifier to the target storage directory in turn, reducing the workload of the staff, and facilitating the subsequent simultaneous injection of root keys into multiple quantum security devices, thereby improving the efficiency of the key injection process.

[0022] 3. Because the quantum security base station to which the quantum security device identified by the device is connected can obtain the key file identified by the device from the root key center, key pairing can be achieved between the quantum security base station and the quantum security device identified by the device. Subsequently, the quantum security base station can be used to relay keys sent and received by the quantum security device identified by the device, thereby enabling quantum secure communication between the quantum security device and other quantum security devices. Furthermore, the quantum security device only needs to perform key pairing with the quantum security base station it is connected to, i.e., it does not need to perform key pairing with any quantum security device with which it needs to communicate. This allows the quantum security device to only store the key file identified by the device. This not only reduces the storage pressure on the quantum security device, but also allows any two quantum security devices connected to a quantum security base station in the quantum security network to relay keys through the quantum security network during quantum secure communication, thereby increasing the flexibility of quantum secure communication and eliminating the need for staff to pre-fill the two quantum security devices with keys, reducing the workload expended by staff in key filling.

[0023] 4. Since the root key center exports the solidified data determined based on the authentication parameters corresponding to each key file at the same time as exporting the key file, the authentication parameters include the first random number to be expanded for encrypting and decrypting each key file, the index for searching the authentication parameters, the first random number for encrypting the data to be encrypted in the access request, and the second random number for decrypting the data to be decrypted in the access response information. The first random number to be expanded can be used to encrypt and output the key file and inject it into the quantum security device, thereby ensuring the security of the key file. The first random number and the second random number can be used to enable the quantum security device to use ciphertext communication during the first access to the quantum security base station, thereby ensuring the security of the first access to the quantum security base station.

[0024] 5. Since the root key center exports each encryption key file and the corresponding fixed data of each encryption key file to the target storage directory in sequence based on the file serial number of each encryption key file and the device identification as a unit, confusion between the encryption key files corresponding to different device identifications and the corresponding fixed data of each encryption key file is avoided, and the management of the key files corresponding to each device identification is facilitated. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0026] Figure 1 A schematic diagram of a process for outputting a quantum secure key provided in an embodiment of the present application;

[0027] Figure 2 A schematic diagram of a specific process for outputting quantum secure keys and authentication parameters provided in an embodiment of the present application;

[0028] Figure 3 A schematic diagram of the structure of a device for outputting quantum secure keys and authentication parameters provided in an embodiment of the present application;

[0029] Figure 4 A schematic diagram of the structure of a root key center provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. It should be understood that the embodiments described herein are only a portion of the embodiments of this application, and not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this application without inventive effort are intended to fall within the scope of protection of this application.

[0031] In order to ensure the security of the key after output and improve the flexibility of quantum secure communication, the embodiments of the present application provide a method, device and root key center for outputting quantum secure keys and authentication parameters.

[0032] Example 1:

[0033] Figure 1 A schematic diagram of a process for outputting quantum secure keys and authentication parameters provided in an embodiment of the present application, the process including:

[0034] S101: Obtain an output command; wherein the output command carries the output conditions of the key and the target storage directory of the quantum secure storage device, the output conditions including one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status. The information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported.

[0035] The method for outputting quantum security keys and authentication parameters provided in this application is applied to a root key center, which can be a quantum security device, such as a quantum security all-in-one machine, a quantum security computer, etc., or a quantum security server, such as a quantum security business server, a quantum security application server, etc.

[0036] In one possible application scenario, the root key center stores a key file corresponding to at least one device identifier. The key file may be generated by the root key center, for example, by a quantum random number generator board installed by the root key center, or may be obtained by the root key center from a quantum random number generator. Considering that key files corresponding to different device identifiers may be confused and inconvenient to manage, the root key center may store the relevant information of the key file and the storage location of the key file after obtaining the key file, so that the storage location of any key file can be found based on the relevant information, thereby exporting the key file from the storage location. The relevant information of the key file includes one or more of the following: the device identifier of the quantum security device to which the key file belongs (recorded as the device identifier corresponding to the key file), the device type of the quantum security device to which the key file belongs, the batch number of the key generation batch, the key generation time, the information import time, and the information import status.

[0037] Among them, the device identifier corresponding to the key file is used to characterize the identity of the quantum security device that is filled with the key file, such as a device ID, which can be represented in the form of numbers, strings, etc., or in other forms. As long as the form can uniquely identify the quantum security device, it can be applied to this application and is not specifically limited here. The device type may include one or more of the following: quantum security desktop, quantum security all-in-one machine, and quantum security notebook. Of course, the device type can also be flexibly set according to the device type of the quantum security device that needs to be filled with keys in the actual scenario, and is not specifically limited here. In this application, keys can be generated in batches, and all key files corresponding to a device identifier are in the same batch. When generating the key, the batch number of the generation batch of the key can be recorded. The key generation time indicates the time when the key is generated. The information import time represents the time when the information required to generate the key is imported. The information import status represents whether the information required to generate the key is successfully imported.

[0038] It should be noted that the key file includes at least one root key file, which is used to perform quantum encryption and decryption on data.

[0039] When the root key center needs to export a key file, it can obtain an export command. This export command can carry the export conditions for the key file to be exported and the target storage directory of the quantum secure storage device. After receiving the export command, the root key center can find the key file to be exported based on the export conditions carried in the export command and the corresponding relationship between the relevant information and storage location of the key file stored by the root key center, and then export the found key file to the target storage directory.

[0040] The root key center may obtain output commands input by a staff member from a display corresponding to the root key center, and may also receive output commands sent by other devices.

[0041] It should be noted that there are many ways for the staff to input and output commands to the display corresponding to the root key center. For example, the staff can input and output commands to the display corresponding to the root key center through text input, or through voice input, or by selecting the content displayed on the display. There are no specific limitations here.

[0042] S102: Determine each key file that meets the output condition and the authentication parameters corresponding to each key file; wherein each key file includes at least one root key file, and the at least one root key file is used for quantum encryption and decryption. The authentication parameters include a first random number to be expanded for encrypting and decrypting each key file, an authentication index for searching the authentication parameters, a first random number for encrypting data to be encrypted in an access request, and a second random number for decrypting data to be decrypted in an access response message. The first random number to be expanded is configured in a quantum security device. The access request is a message from the quantum security device requesting first access to a quantum security base station in a quantum security network. The access response message is a feedback message sent by the quantum security base station to the quantum security device in response to the access request. After allowing the quantum security device access, the quantum security base station relays the key sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center.

[0043] After the root key center obtains the output command based on the above-mentioned embodiment, it can find the key file whose relevant information matches the output condition according to the output condition carried in the output command and the correspondence between the relevant information and storage location of the key file saved by the root key center, and then export the found key file to the target storage directory.

[0044] For example, the root key center can obtain the key generation record based on the relevant information of the key file and the storage location of the key file. After receiving the output command, the root key center can then search the key generation record based on the output conditions carried in the output command to determine the storage location of the key file that meets the output conditions, and then obtain the key file to be output from the determined storage location.

[0045] Considering the potential for tampering and eavesdropping during the export and injection process, each key file could be compromised, potentially impacting the security of the quantum security device used to inject the key file. Based on this, in this application, the root key center also stores authentication parameters corresponding to each key file. These authentication parameters include a first random number to be expanded for encrypting and decrypting each key file. Based on the first random number to be expanded corresponding to each key file, the encryption and decryption key corresponding to each key file can be determined. Consequently, each key file can be encrypted based on the encryption and decryption key corresponding to each key file, thereby improving the security of each key file.

[0046] In order to facilitate indexing to the authentication parameters corresponding to the device identifier, the authentication parameters also include an authentication index.

[0047] To achieve quantum secure communication between two quantum security devices, staff are generally required to pre-fill the two quantum security devices with paired keys. Subsequently, the two quantum security devices use this paired key to perform quantum encryption and decryption on the communication data. With this quantum secure communication method, each quantum security device must store not only its own key file, but also the key files of the other quantum security devices it needs to communicate with, consuming a significant amount of the quantum security device's storage resources. Furthermore, any two quantum security devices that need to communicate require staff to pre-fill the key file, making this quantum secure communication method costly. This quantum secure communication method also has limited flexibility for scenarios such as adding or removing other quantum security devices that communicate with the quantum security device. Therefore, in this application, a quantum security device can access a quantum secure base station in a quantum secure network. After allowing the quantum security device access, the quantum secure base station can obtain the quantum security device's key file from the root key center to achieve key pairing with the quantum security device. Subsequently, the quantum secure base station can relay the keys sent and received by the quantum security device based on the quantum security device's key file. In this quantum communication mode, the quantum security device does not need to store the key files of other quantum security devices, which greatly reduces the storage pressure of the quantum security device. After the quantum security device is connected to the quantum security network, it can conduct quantum secure communication with other quantum security devices connected to the quantum security network, improving the flexibility of quantum secure communication.

[0048] To improve the security of a quantum security device during its initial access to a quantum security base station, in this application, the authentication parameters may also include a first random number for encrypting the data to be encrypted in the access request, and a second random number for decrypting the data to be decrypted in the access response message. The access request is a message from the quantum security device identified by the device requesting initial access to a quantum security base station in a quantum security network, and the access response is a feedback message sent by the quantum security base station to the quantum security device in response to the access request. Based on the first random number, subsequent messages from the quantum security device requesting access to the quantum security base station can be encrypted, thereby improving the security of access requests sent by the quantum security device identified by the device to the quantum security base station. Based on the second random number, subsequent feedback messages from the root key center in response to the quantum security device's access request can also be encrypted, thereby improving the security of access response messages received by the quantum security device identified by the device.

[0049] It should be noted that the authentication parameters are all true random numbers.

[0050] Based on this, the root key center determines the key files that meet the output conditions, and also obtains the authentication parameters corresponding to each key file that meets the output conditions. Based on the authentication parameters corresponding to each key file, it processes each key file and exports the processed key files to the target storage directory.

[0051] In one possible implementation, if multiple groups of key files corresponding to at least one device identifier are stored, and each key file in the same group corresponds to the same group identifier and the same authentication parameter, determining the authentication parameters corresponding to each key file includes:

[0052] For each of the key files, multiple groups of authentication parameters corresponding to the device identifier of the key file are determined based on the correspondence between the device identifier and the authentication parameters; the authentication parameters corresponding to the key file are determined based on the group identifiers corresponding to the multiple groups of authentication parameters and the group identifier corresponding to the key file; wherein any group of key files includes at least one key file, and the group identifier is used to identify the group to which the key file belongs.

[0053] When a quantum security device accesses a quantum security base station, it can verify its key files with the root key center through the quantum security base station. Only after the root key center determines that the key files have been verified will it send the key files of the quantum security device to the quantum security base station. During this process, at least one key file of the quantum security device may be damaged or missing, resulting in failure of key file verification, and thus the quantum security base station cannot obtain the key files of the quantum security device from the root key center. Based on this, in the present application, the root key center can store multiple sets of key files corresponding to at least one device identifier. Subsequently, the multiple sets of key files corresponding to any device identifier are output to a quantum security storage device. The quantum security storage device then injects the multiple sets of key files corresponding to the device identifier into the quantum security device. This allows the quantum security device, which has been injected with the multiple sets of key files corresponding to the device identifier, to continue using other sets of key files to verify the key files through the quantum security base station and the root key center if one set of key files fails verification, thereby ensuring that the quantum security device can reliably access the quantum security base station. Exemplarily, the metadata acquired by the root key center may further include the number of key groups, and the root key center determines how many groups of key files to generate for the device identifier based on the number of key groups.

[0054] In this application, different group key files corresponding to any device identifier correspond to different group identifiers, and key files in the same group correspond to the same group identifier, so that the group identifier can be used to distinguish which key files belong to the same group. The group identifiers corresponding to any device identifier can be different from each other, or the group identifiers corresponding to any device identifier can be different from the group identifiers corresponding to any other device identifiers.

[0055] It should be noted that the group identifier can be identified in the form of numbers, strings, etc., or expressed in other ways. As long as the method can uniquely identify the group key, it can be applied to this application and is not specifically limited here.

[0056] If the root key center stores multiple groups of key files corresponding to at least one device identifier, each group of key files corresponds to different authentication parameters, and each key file in the same group corresponds to the same authentication parameters. Furthermore, by establishing a correspondence between authentication parameters, group identifiers, and device identifiers, it is possible to easily distinguish authentication parameters corresponding to different groups of key files. When determining the authentication parameters corresponding to a key file to be output, the multiple groups of authentication parameters corresponding to the device identifier of the key file can be determined based on the correspondence between the device identifier and the authentication parameters. Then, based on the group identifiers corresponding to the multiple groups of authentication parameters and the group identifier corresponding to the key file, the authentication parameters corresponding to the key file can be determined.

[0057] In a possible implementation, if the output condition further includes outputting a quantum-safe computing random number, then each key file further includes at least one quantum-safe computing random number file; wherein the quantum-safe computing random number is used for quantum-safe computing.

[0058] Considering that quantum-safe devices also require random numbers when performing quantum-safe computations, such as hash calculations, in this application, the root key center may store the quantum-safe computation random number corresponding to the device identifier, so that quantum-safe devices charged with the quantum-safe computation random number corresponding to the device identifier can use this quantum-safe computation random number to perform quantum-safe computations. When the root key center subsequently determines key files that meet output conditions, these key files may also include the quantum-safe computation random number file.

[0059] In a possible implementation, if the output condition further includes outputting an encryption key, then each key file further includes at least one encryption key file; wherein the encryption key is used by the quantum security device identified by the device to decrypt the received encryption supplementary key after leaving the factory.

[0060] During quantum secure communication, quantum security devices continuously consume pre-factory key injections, requiring them to replenish their keys after leaving the factory. To ensure the security of these supplementary keys, in this application, the supplementary keys downloaded from the key center by the quantum security device may be encrypted. Upon receiving the encrypted supplementary key (denoted as an encrypted supplementary key), the quantum security device decrypts it using a pre-acquired encryption key, thereby replenishing its key using the obtained supplementary key. The root key center may also store encryption key files for the quantum security device identified by the device. Each encryption key file associated with the device is injected into the quantum security device identified by the device before it leaves the factory, allowing the quantum security device identified by the device to decrypt the received encryption supplementary key using the injected encryption key files after leaving the factory. When the encryption key file injected into the quantum security device identified by the device is consumed, the quantum security device may also obtain a key from the key center to replenish the stored encryption key file. Therefore, in this application, the root key center may also store encryption keys corresponding to at least one device identifier. When the root key center subsequently determines the key files that meet the output conditions, the key files may also include encryption key files.

[0061] Based on the above embodiment, if the root key center stores multiple sets of key files corresponding to at least one device identifier, the multiple sets of key files corresponding to the device identifier stored in the root key center include the following situations:

[0062] Case 1: When the key type is only the root key, any set of key files stored in the root key center only includes at least one root key file of the root key type.

[0063] Case 2: When the key type includes a root key and a quantum-safe random number, any set of key files stored in the key center includes at least one root key file whose key type is a root key. Optionally, at least one set of key files may also include at least one quantum-safe random number file whose key type is a quantum-safe random number.

[0064] It should be noted that if multiple groups of quantum secure computing random numbers corresponding to a certain device identification are stored, the number of groups of quantum secure computing random numbers corresponding to the device identification is the same as the number of groups of the root key file corresponding to the device identification.

[0065] Subsequent staff can determine, based on demand, whether to export the quantum-safe random number file corresponding to a particular device identifier along with the root key file corresponding to that device identifier. For example, the output conditions obtained by the root key center may also include information on whether to output a key file whose key type is quantum-safe random number. If the output conditions include outputting a key file whose key type is quantum-safe random number, the key files determined by the root key center to meet the output conditions will also include at least one quantum-safe random number file. For example, the root key center determines the root key files that meet the output conditions and, based on the group identifiers corresponding to the root key files to be output and the correspondence between the quantum-safe random number files and the group identifiers, determines the quantum-safe random number files to be output, thereby exporting the quantum-safe random number file corresponding to a particular device identifier along with the root key file corresponding to that device identifier. Simultaneously, the authentication parameters to be output are determined based on the device identifiers and group identifiers corresponding to the key files to be output.

[0066] Case 3: When the key types include root keys and encryption keys, any set of key files stored in the key center includes at least one root key file of the root key type. Optionally, at least one set of key files may also include at least one encryption key file of the encryption key type.

[0067] It should be noted that if multiple groups of encryption keys corresponding to a certain device identification are stored, the number of groups of encryption keys corresponding to the device identification is the same as the number of groups of the root key file corresponding to the device identification.

[0068] Subsequent staff can determine, based on demand, whether to export the encryption key file corresponding to a certain device identifier together with the root key file corresponding to the device identifier. Exemplarily, the output conditions obtained by the root key center may also include information on whether to output a key whose key type is an encryption key. If the output conditions include outputting a key file whose key type is an encryption key, then the key files that meet the output conditions determined by the root key center also include at least one encryption key file. For example, the root key center determines the root key files that meet the output conditions, and determines the quantum secure computing files to be output based on the group identifiers corresponding to the root key files to be output and the correspondence between the quantum secure computing files and the group identifiers, thereby exporting the encryption key file corresponding to a certain device identifier together with the root key file corresponding to the device identifier. At the same time, the authentication parameters to be output are determined based on the device identifiers and group identifiers corresponding to the key files to be output.

[0069] Case 4: When the key types include root keys, quantum-safe random numbers, and encryption keys, any set of key files stored in the key center includes at least one root key file whose key type is root key. Optionally, the at least one set of key files may also include at least one encryption key file whose key type is encryption key, and / or at least one quantum-safe random number file whose key type is quantum-safe random number.

[0070] Subsequent staff can determine, based on demand, whether to export the encryption key file corresponding to a certain device identifier together with the root key file corresponding to the device identifier. Exemplarily, the output conditions obtained by the root key center may also include information on whether to export a key file whose key type is an encryption key. If the output conditions include outputting a key file whose key type is an encryption key, then the key files that meet the output conditions determined by the root key center also include at least one encryption key file. For example, the root key center determines the root key files that meet the output conditions, and based on the group identifiers corresponding to the root key files to be output and the correspondence between the quantum secure computing files and the group identifiers, determines the quantum secure computing files to be output, thereby achieving the export of the encryption key file corresponding to a certain device identifier together with the root key file corresponding to the device identifier.

[0071] Similarly, staff can also determine, based on demand, whether to export the quantum-safe computing random number file corresponding to a particular device identifier together with the root key file corresponding to that device identifier. For example, the output conditions obtained by the root key center may also include information on whether to output a key whose key type is a quantum-safe computing random number. If the output conditions include outputting a key file whose key type is a quantum-safe computing random number, then the key files that meet the output conditions determined by the root key center also include at least one quantum-safe computing random number file. For example, the root key center determines the root key files that meet the output conditions, and based on the group identifiers corresponding to the root key files to be output and the corresponding relationship between the quantum-safe computing files and the group identifiers, determines the quantum-safe computing files to be output, thereby exporting the quantum-safe computing random number file corresponding to a particular device identifier together with the root key file corresponding to that device identifier.

[0072] At the same time, the authentication parameters to be output can be determined according to the device identifiers and group identifiers corresponding to the key files to be output.

[0073] S103: Obtain the encryption and decryption root keys corresponding to the key files respectively; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file.

[0074] In order to avoid security issues such as tampering and theft of the exported key files, in this application, the root key center can obtain the encryption and decryption root keys corresponding to each key file that needs to be output, and then determine the encryption and decryption keys corresponding to each key file based on the encryption and decryption root keys, so as to encrypt each key file according to the encryption and decryption keys corresponding to each key file, so as to improve the security of each key file after export.

[0075] In one example, the root key center also pre-stores the encryption and decryption root key corresponding to any key file. The encryption and decryption root key corresponding to any key file can be determined in advance by the root key center based on the first random number to be expanded corresponding to the key file, or can be obtained by the root key center from other devices.

[0076] The first random number to be expanded is a random number to be expanded that can be derived.

[0077] In another example, after determining any key file that needs to be output, the root key center may also determine the encryption and decryption root key corresponding to the key file based on the first random number to be expanded corresponding to the key file.

[0078] To further enhance security during key output, the encryption and decryption root keys corresponding to each key file can be determined based on the first and second random numbers to be expanded. The first random number to be expanded can be exported to the quantum security device identified by the device, while the second random number to be expanded is configured in the root key center. This means that only the first random number to be expanded is output, not the second random number to be expanded. The quantum security device that is subsequently charged with each key file identified by the device and the first random number to be expanded corresponding to the device identifier can obtain the second random number to be expanded from the root key center only after securely accessing the quantum security base station and passing the authentication of the root key center. The quantum security device can obtain the encryption and decryption root key based on the second random number to be expanded and the first random number to be expanded obtained during charging. Then, based on the encryption and decryption root key, the quantum security device determines the encryption and decryption keys corresponding to each key file, and then decrypts the charged key files according to the encryption and decryption keys corresponding to each key file, thereby ensuring the security of the charged key files, avoiding security issues such as the theft of the charged key files, and helping to further improve the security of quantum secure communication.

[0079] It should be noted that the length of the random number to be expanded (including the first random number to be expanded and the second random number to be expanded) is pre-configured, for example, 128 bits, 256 bits, 512 bits, etc.

[0080] For example, if the random number to be expanded includes a first random number to be expanded and a second random number to be expanded, then after the root key center obtains the key files for a particular device identifier, it can determine the number of key files for that device identifier. Based on this number, the number of encryption and decryption keys is determined, for example, as the number of encryption and decryption keys, or based on this number and a preset value, the encryption and decryption root key is determined. The root key center determines the root key to be expanded based on the first random number to be expanded and the second random number to be expanded, for example, by copying the first random number to be expanded and the second random number to be expanded by a preset multiple, concatenating the copied random numbers to be expanded, and determining the resulting random number as the root key to be expanded. For another example, the first random number to be expanded and the second random number to be expanded are concatenated, and the resulting random number is determined as the root key to be expanded. The root key to be expanded is expanded according to a preset first key expansion algorithm, thereby determining the encryption and decryption root key for the number of encryption and decryption keys. For example, a first key expansion algorithm can be used to expand the root key to be expanded, obtaining an expanded random number. The expanded random number is greater than the number of encryption and decryption keys. The encryption and decryption root keys corresponding to the number of encryption and decryption keys are then determined based on the obtained expanded random number. The root key center determines the correspondence between the encryption and decryption root keys corresponding to the number of encryption and decryption keys and each key file, that is, determines the encryption and decryption root keys corresponding to each key file. For example, the encryption and decryption root keys corresponding to each key file are determined based on the generation order of the encryption and decryption root keys for the number of encryption and decryption keys and the file sequence number of each key file.

[0081] In a possible implementation, obtaining the encryption and decryption root keys corresponding to the key files includes:

[0082] For the group identifiers corresponding to the key files, the target key files corresponding to the group identifiers are determined in the key files; the root key to be expanded is determined based on the first random number to be expanded in the authentication parameter corresponding to the group identifier; and the encryption and decryption root keys corresponding to the target key files are determined based on the first preset key expansion algorithm corresponding to the group identifier and the root key to be expanded.

[0083] If the root key center generates multiple sets of key files corresponding to a device ID, the root key center can obtain the encryption and decryption root keys corresponding to each key file in the following two ways:

[0084] Method 1: The root key center predetermines the encryption and decryption root keys corresponding to each key file. When obtaining the encryption and decryption root keys corresponding to any key file later, it can directly obtain them from the pre-saved encryption and decryption root keys. Exemplarily, the root key center can determine the number of key files in each group of key files identified by a certain device. Based on the number, the number of encryption and decryption keys is determined, and the root key to be expanded is determined based on the random number to be expanded corresponding to the group of key files. The root key to be expanded is expanded according to the first key expansion algorithm corresponding to the group of key files, thereby determining the encryption and decryption root keys for the number of encryption and decryption keys. The root key center determines the correspondence between the encryption and decryption root keys for the number of encryption and decryption keys and each key file in the group, that is, determines the encryption and decryption root keys corresponding to each key file in the group. For example, based on the generation order of the encryption and decryption root keys for the number of encryption and decryption keys and the file serial numbers of each key file in the group, the encryption and decryption root keys corresponding to each key file in the group are determined.

[0085] The first key expansion algorithms corresponding to each set of key files may be completely identical, partially identical, or completely different. The first key expansion algorithms corresponding to each set of key files may be default settings or configured by staff as needed.

[0086] Method 2: After determining the key files that need to be output, the root key center determines the encryption and decryption root keys corresponding to each key file.

[0087] In one possible implementation, after the root key center determines each key file that meets the output conditions, it determines the target key file corresponding to the group identifier in each key file. The root key to be expanded is determined based on the first random number to be expanded in the authentication parameter corresponding to the group identifier. Exemplarily, the root key center generates a second random number to be expanded corresponding to the group identifier, and then determines the root key to be expanded based on the first random number to be expanded and the second random number to be expanded corresponding to the group identifier. For example, the first random number to be expanded and the second random number to be expanded are copied by a preset multiple, the copied random numbers to be expanded are spliced, and the random number obtained after splicing is determined to be the root key to be expanded, or the first random number to be expanded and the second random number to be expanded are spliced, and the spliced random number to be expanded is determined to be the root key to be expanded, etc. Then, based on the first preset key expansion algorithm corresponding to the group identifier and the root key to be expanded, the encryption and decryption root key for the target key file quantity is determined. Exemplarily, the root key to be expanded is expanded according to a preset first key expansion algorithm to determine the encryption and decryption root keys for the target number of key files. For example, the root key to be expanded can be expanded using the first key expansion algorithm to obtain an expanded random number, where the number of the expanded random number is greater than the number of encryption and decryption keys. The encryption and decryption root keys for the target number of key files are determined based on the obtained expanded random number. The root key center determines the encryption and decryption root keys corresponding to each target key file corresponding to the group identifier based on the generation order of the encryption and decryption root keys corresponding to the group identifier and the file sequence number of each target key file corresponding to the group identifier.

[0088] S104: For each key file, determine the encryption and decryption key corresponding to the key file based on the encryption and decryption root key corresponding to the key file, encrypt the key file based on the encryption and decryption key to obtain the encrypted key file, and determine the solidified data corresponding to the encrypted key file based on the authentication parameters corresponding to the key file; wherein the solidified data includes the first random number to be expanded.

[0089] After determining the key file to be output and the encryption and decryption root key corresponding to the key file based on the above embodiment, the encryption and decryption key corresponding to the key file can be determined based on the encryption and decryption root key. For example, if the encryption and decryption root key is equal to the length of the key file, the encryption and decryption root key is directly determined as the encryption and decryption key; if the encryption and decryption root key is less than the length of the key file, the length of the encryption and decryption root key is extended according to a preset value to obtain a key equal to the length of the key file, and the obtained key is determined as the encryption and decryption key; if the encryption and decryption root key is greater than the length of the key file, a key equal to the length of the key file can be obtained from the encryption and decryption root key according to a preset interception rule, and the obtained key is determined as the encryption and decryption key. For another example, the encryption and decryption key corresponding to the key file is determined based on the length of the key file (recorded as the target length), the preset key expansion algorithm used to determine the encryption and decryption key (recorded as the second preset key expansion algorithm), and the encryption and decryption root key corresponding to the key file. Exemplarily, based on the second preset key expansion algorithm, the encryption / decryption root key is expanded into a key of a target length, and the key of the target length is determined as the encryption / decryption key. The key file is encrypted according to the encryption / decryption root key corresponding to the key file, thereby obtaining an encryption key file. The encryption key file includes one or more of the following information: the key type of the key file, the number of key files of the key type in each key file corresponding to the device identifier of the key file, the total number of key files corresponding to the device identifier of the key file, and the file sequence number corresponding to each key file of the key type in each key file corresponding to the device identifier of the key file.

[0090] In one example, if the root key center generates multiple groups of key files corresponding to a certain device identifier, each group of key files may correspond to a second preset key expansion algorithm. The second key expansion algorithms corresponding to each group of key files may be completely identical, partially identical, or completely different. The second key expansion algorithms corresponding to each group of key files may be default settings or configured by staff based on needs. When encrypting any key file to be output, the root key center obtains the second key expansion algorithm corresponding to the group identifier to which the key file belongs. Based on the encryption and decryption root key corresponding to the key file and the obtained second key expansion algorithm, the root key center determines an encryption and decryption key with a length equal to the length of the key file. Based on the encryption and decryption key, the root key center encrypts the key file, thereby obtaining an encrypted key file. In which, the encryption key file includes one or more of the following information: the key type of the key file, the group identifier to which the key file belongs, the first file quantity of the key files of the key type-group identifier in each key file corresponding to the device identifier of the key file, the second file quantity of each key file of the group identifier in each key file corresponding to the device identifier of the key file, and the file sequence number corresponding to each key file of the key type-group identifier in each key file corresponding to the device identifier of the key file.

[0091] Taking into account the security issues that may occur after the device identification is output, such as being stolen by a third-party device, thereby affecting the security of the first access authentication process of the quantum security device filled with the device identification, and the security of the subsequent quantum security device with the device identification performing quantum secure communication, therefore, in this application, the root key center also stores an encrypted device identification (referred to as the encrypted device identification) so that after a subsequent quantum security device accesses the quantum security base station, the quantum security base station can only obtain the encrypted device identification through a legitimate quantum security device, and can obtain the key file of the quantum security device from the root key center through the encrypted device identification.

[0092] In one example, the encryption device identifier can be determined based on a selected random number corresponding to the device identifier. The selected random number can be injected into the quantum security device so that the quantum security device determines the encryption device identifier based on the selected random number and the device identifier. Exemplarily, the device encryption key can be determined based on the parity of the selected random number, the first key expansion algorithm in the above-described embodiment, and the random number to be expanded. For example, the random number to be expanded can be expanded using the first key expansion algorithm to obtain an expanded random number, and a target encryption key can be determined from the obtained expanded random number. The number of the expanded random numbers is greater than the number of encryption and decryption keys, and the target encryption key is different from any encryption and decryption root key. For example, the expanded random numbers can be sorted based on their generation order, and the expanded random number at a preset position can be determined as the target encryption key. The device encryption key is then determined based on the target encryption key and the parity of the selected random number. Exemplarily, if the selected random number is an odd number, the key of the first preset length before the target encryption key is determined as the device encryption key; if the selected random number is an even number, the key of the second preset length after the target encryption key is determined as the device encryption key, and the first preset length and the second preset length are both smaller than the length of the target encryption key, for example, the first preset length and the second preset length are both half the length of the target encryption key; or, if the selected random number is an odd number, the key of the third preset length after the target encryption key is determined as the device encryption key; if the selected random number is an even number, the key of the fourth preset length before the target encryption key is determined as the device encryption key, and the third preset length and the fourth preset length are both smaller than the length of the target encryption key.

[0093] If a quantum security device is charged with multiple groups of key files, the quantum security device can determine, for each group of key files, a selected random number corresponding to the group of key files, and determine the device encryption key corresponding to the group of key files based on the parity of the selected random number, the first key expansion algorithm corresponding to the group of key files, and the random number to be expanded corresponding to the group of key files.

[0094] It should be noted that the selected random number can be pre-stored by the root key center or generated by the root key center when exporting the key file. In the specific implementation process, it can be flexibly set according to needs and is not specifically limited here.

[0095] When exporting a key file, the selected random number corresponding to the key file must also be exported so that the quantum security device can determine the encrypted device identity based on the selected random number and the device identity. Therefore, the encryption key file obtained by the root key center also includes the selected random number, which is used to determine the key used to encrypt the device identity.

[0096] At the same time, the root key center can determine the fixed data corresponding to the encryption key file based on the authentication parameters corresponding to the key file, so that the quantum security device filled with the encryption key file and the fixed data corresponding to the encryption key file can decrypt the encryption key file based on the fixed data and successfully access the quantum security base station. The fixed parameters include at least the first random number to be expanded in the authentication parameters.

[0097] For example, the device identification, authentication index, first random number, second random number, encryption / decryption root key, and second preset key expansion algorithm for determining the encryption / decryption key corresponding to the key file are determined as the fixed data corresponding to the encryption / decryption key file. For another example, if the root key center obtains the first random number to be expanded and the second random number to be expanded, the device identification, authentication index, first random number, second random number, first random number to be expanded, first preset key expansion algorithm for determining the encryption / decryption root key, and second preset key expansion algorithm for determining the encryption / decryption key corresponding to the key file are determined as the fixed data corresponding to the encryption / decryption key file.

[0098] S105: According to the pre-saved file serial numbers corresponding to the key files, the encryption key files and the hardened data corresponding to the encryption key files are sequentially exported to the target storage directory in units of device identification.

[0099] Considering that each encryption key file determined based on the above embodiment may correspond to a different device identifier, and that a quantum security device can only be charged with an encryption key file corresponding to one device identifier, in this application, after obtaining each encryption key file, the root key center can obtain the file serial number corresponding to each encryption key file, that is, the file serial number corresponding to the key file before encryption. Then, based on the file serial number of each encryption key file, each encryption key file and the corresponding fixed data are exported to the target storage directory in sequence, based on the device identifier. For example, the file serial numbers of the obtained encryption key files are file 1 to file 20, the device identification corresponding to file 1 to file 5 is ID1, the device identification corresponding to file 6 to file 12 is ID2, and the device identification corresponding to file 13 to file 20 is ID3. The root key center uses device identification as a unit to export files 1 to file 5 corresponding to device identification ID1 and the fixed data corresponding to files 1 to file 5 in sequence to the target storage directory, exports files 6 to file 12 corresponding to device identification ID2 and the fixed data corresponding to files 6 to file 12 in sequence to the target storage directory, and exports files 13 to file 20 corresponding to device identification ID3 and the fixed data corresponding to files 13 to file 20 in sequence to the target storage directory.

[0100] In one example, encryption key files corresponding to different device identifiers can be exported to different subdirectories under the target storage directory to facilitate the subsequent filling of encryption key files for different quantum security devices and avoid confusion between encryption key files corresponding to different device identifiers.

[0101] Similarly, the fixed data corresponding to different device identifiers can also be exported to different subdirectories under the target storage directory to facilitate the subsequent filling of fixed data for different quantum security devices and avoid confusion between the fixed data corresponding to different device identifiers.

[0102] In certain possible implementations, to facilitate the management of pre-assigned key files, the root key center can record the export information of each key file after exporting each encryption key file to the target storage directory, allowing staff to monitor the export status of each key file. This export information includes one or more of the following: whether the key file was fully exported, device information about the quantum secure storage device, the time the key file was exported, the key type of the key file, and the file identifier of the key file.

[0103] In one example, the key file export status can be used to determine whether the key file has been completely exported. For example, the export status can include not exported, export failed, and successfully exported. Before the key file is exported, the export status of the key file is not exported. If the root key center determines that the key file has been completely exported, the export status of the key file can be updated to successfully exported. If the root key center determines that the key file cannot be completely exported to the target storage directory during the export process, the export status of the key file can be updated to export failed. For another example, the export status can include not exported and successfully exported. Before the key file is exported, the export status of the key file is not exported. If the root key center determines that the key file has been completely exported, the export status of the key file can be updated to successfully exported. Otherwise, the export status of the key file is not updated.

[0104] For the security of the key file, in this application, the root key center does not repeatedly export the key file that has been successfully exported. Exemplarily, when the key file determines the key file to be exported, the key file to be exported not only meets the export conditions but also fails to be exported successfully.

[0105] In some possible application scenarios, there may be a need to repeatedly export a root key file that has been successfully exported. In this case, the authority of the account that currently inputs the export command can be used to determine whether to repeatedly export the root key file that has been successfully exported. Exemplarily, the export command obtained by the root key center can carry account authority, and the root key center determines the key files that need to be exported based on the account authority and the export conditions. For example, if the account authority includes allowing repeated export of key files, all key files that meet the export conditions will be exported to the target storage directory; if the account authority includes not allowing repeated export of key files, all key files that meet the output conditions and have not been successfully exported will be exported to the target storage directory.

[0106] In cases where a device ID may correspond to multiple groups of key files, staff can control the root key center to export only some or all of the group key files corresponding to the device ID to the target storage directory as needed. Based on this, in this application, the output conditions obtained by the root key center can also include the group ID. Based on the output conditions carrying the group ID, several groups of key files corresponding to a device ID can be exported, thereby achieving more flexible key file export and improving user experience.

[0107] The group identifiers corresponding to any two device identifiers may be completely identical, partially identical, or completely different. For example, the group identifier corresponding to device identifier ID1 includes group identifier 1 and group identifier 2, and the group identifier corresponding to device identifier ID2 also includes group identifier 1 and group identifier 2; or, the group identifier corresponding to device identifier ID1 includes group identifier 1 and group identifier 2, and the group identifier corresponding to device identifier ID2 also includes group identifier 1 and group identifier 3; or, the group identifier corresponding to device identifier ID1 includes group identifier 1 and group identifier 2, and the group identifier corresponding to device identifier ID2 also includes group identifier 3 and group identifier 4.

[0108] In one example, exporting each encryption key file and the hardened data corresponding to each encryption key file to the target storage directory in sequence based on a device identification according to the file sequence number corresponding to each encryption key file includes:

[0109] For the device identification corresponding to each key file, according to the file serial number corresponding to each key file of the device identification, each encryption key file of the device identification and the solidified data corresponding to each encryption key file of the device identification are exported to the target storage directory in sequence in units of group identification.

[0110] The key files that meet the output conditions obtained by the root key center based on the above embodiment may contain multiple groups of key files corresponding to a device identifier. Based on this, in this application, when exporting the encryption key files corresponding to any device identifier to the target storage directory, it is also necessary to export the encryption key files corresponding to the device identifier and the hardened data corresponding to the encryption key files of the device identifier to the target storage directory in sequence based on the file sequence number of the encryption key files corresponding to the device identifier, using group identifiers as units. For example, the encryption key files corresponding to the device identifier ID2 are files 6 to file 12 respectively, the group identifier corresponding to files 6 to file 8 is group identifier 1, the group identifier corresponding to files 9 to file 10 is group identifier 2, and the group identifier corresponding to files 11 to file 12 is group identifier 3. The root key center exports files 6 to file 8 corresponding to group identifier 1 and the fixed data corresponding to files 6 to file 8 to the target storage directory in sequence, exports files 9 to file 10 corresponding to group identifier 2 and the fixed data corresponding to files 9 to file 10 to the target storage directory in sequence, and exports files 11 to file 12 corresponding to group identifier 3 and the fixed data corresponding to files 11 to file 12 to the target storage directory in sequence.

[0111] In one example, encryption key files corresponding to different group identifiers can be exported to different subdirectories under the target storage directory to facilitate subsequent injection of encryption key files with different group identifiers for any device identifier into a quantum security device, thereby preventing confusion between encryption key files with different group identifiers. For example, the root key center creates different device directories under the directory storage directory. These device directories are used to store the encryption key files corresponding to any device identifier and the hardened data corresponding to each encryption key file. Within any device directory, group directories corresponding to different group identifiers belonging to the device identifier can also be created. The group directory corresponding to any group identifier is used to store the root key files corresponding to the device identifier and the key files corresponding to the group identifier.

[0112] In one possible implementation, if a group of key files includes key files of at least two key types, the root key center may create different key type directories under the group directory corresponding to the group of key files when exporting the group of key files to the target storage directory. Each key type directory is used to store key files of that key type in the group of key files. The root key center exports the group of key files sequentially to the target storage directory by key type.

[0113] The beneficial effects of this application are as follows:

[0114] 1. Since the output instruction obtained by the root key center carries output conditions, the output conditions include one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status. According to the output conditions, more flexible key file export can be achieved, and the exported key files meet user needs, which not only improves the user experience, but also avoids the problem of human misleading key files, and improves the quality of the exported key files.

[0115] 2. In this application, the root key center can obtain the key files corresponding to different device identifiers in advance, and then accurately determine the need to export each key file based on the output conditions. The exported key files can correspond to different device identifiers, thereby realizing the simultaneous export of key files for multiple device identifiers, greatly improving the efficiency of key export. There is no need to manually export the key files corresponding to each device identifier to the target storage directory in turn, reducing the workload of the staff, and facilitating the subsequent simultaneous injection of root keys into multiple quantum security devices, thereby improving the efficiency of the key injection process.

[0116] 3. Because the quantum security base station to which the quantum security device identified by the device is connected can obtain the key file identified by the device from the root key center, key pairing can be achieved between the quantum security base station and the quantum security device identified by the device. Subsequently, the quantum security base station can be used to relay keys sent and received by the quantum security device identified by the device, thereby enabling quantum secure communication between the quantum security device and other quantum security devices. Furthermore, the quantum security device only needs to perform key pairing with the quantum security base station it is connected to, i.e., it does not need to perform key pairing with any quantum security device with which it needs to communicate. This allows the quantum security device to only store the key file identified by the device. This not only reduces the storage pressure on the quantum security device, but also allows any two quantum security devices connected to a quantum security base station in the quantum security network to relay keys through the quantum security network during quantum secure communication, thereby increasing the flexibility of quantum secure communication and eliminating the need for staff to pre-fill the two quantum security devices with keys, reducing the workload expended by staff in key filling.

[0117] 4. Since the root key center exports the solidified data determined based on the authentication parameters corresponding to each key file at the same time as exporting the key file, the authentication parameters include the first random number to be expanded for encrypting and decrypting each key file, the index for searching the authentication parameters, the first random number for encrypting the data to be encrypted in the access request, and the second random number for decrypting the data to be decrypted in the access response information. The first random number to be expanded can be used to encrypt and output the key file and inject it into the quantum security device, thereby ensuring the security of the key file. The first random number and the second random number can be used to enable the quantum security device to use ciphertext communication during the first access to the quantum security base station, thereby ensuring the security of the first access to the quantum security base station.

[0118] 5. Since the root key center exports each encryption key file and the corresponding fixed data of each encryption key file to the target storage directory in sequence based on the file serial number of each encryption key file and the device identification as a unit, confusion between the encryption key files corresponding to different device identifications and the corresponding fixed data of each encryption key file is avoided, and the management of the key files corresponding to each device identification is facilitated.

[0119] Example 2:

[0120] The following describes a method for outputting quantum secure keys and authentication parameters provided by this application through specific embodiments. Figure 2 A schematic diagram of a specific process for outputting quantum security keys and authentication parameters provided in an embodiment of the present application, the process including:

[0121] S201: Obtain output commands.

[0122] Among them, the output command carries the output conditions of the key and the target storage directory of the quantum safe storage device. The output conditions include one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, group identification, key whose output key type is a quantum safe computing random number, key whose output key type is an encryption key, and information import status. The information import time is the time for importing the information required to generate the key, and the information import status indicates whether the information required to generate the key is successfully imported.

[0123] S202: Determine each key file that meets the output condition.

[0124] S203: For each key file, determine the multiple groups of authentication parameters corresponding to the device identifier of the key file based on the correspondence between the device identifier and the authentication parameters; determine the authentication parameters corresponding to the key file based on the group identifiers corresponding to the multiple groups of authentication parameters and the group identifier corresponding to the key file.

[0125] Among them, each key file includes each root key file whose key type is a root key, each quantum secure computing random number file whose key type is a quantum secure computing random number, and each encryption key file whose key type is an encryption key. The authentication parameter includes a first random number to be expanded for encrypting and decrypting each key file, an authentication index for searching the authentication parameter, a first random number for encrypting the data to be encrypted in the access request, and a second random number for decrypting the data to be decrypted in the access response information. The access request is a message for the quantum security device to request the first access to a quantum security base station in the quantum security network. The access response information is a feedback message sent by the quantum security base station to the quantum security device in response to the access request. After the quantum security base station allows the quantum security device to access, it relays the key sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center.

[0126] S204: For each key file, determine the checksum of the key file and add the checksum to the key file.

[0127] S205: Obtain the encryption and decryption root keys corresponding to each key file.

[0128] Among them, for the group identifier corresponding to each of the key files, the target key file corresponding to the group identifier in each of the key files is determined; based on the first random number to be expanded in the authentication parameter corresponding to the group identifier, the root key to be expanded is determined; based on the first preset key expansion algorithm corresponding to the group identifier and the root key to be expanded, the encryption and decryption root keys corresponding to each of the target key files are determined.

[0129] S206: For each key file, determine the encryption and decryption key corresponding to the key file based on the length of the key file, the second preset key expansion algorithm, and the encryption and decryption root key corresponding to the key file; encrypt the key file carrying the checksum based on the encryption and decryption key to obtain the encrypted key file, and determine the solidified data corresponding to the encrypted key file based on the authentication parameters corresponding to the key file.

[0130] The solidified data includes a first preset key expansion algorithm for determining an encryption and decryption root key, a second preset key expansion algorithm for determining an encryption and decryption key, a device identifier, an authentication index, a first random number, the second random number, and a first random number to be expanded.

[0131] The encryption key file includes one or more of the following information: the key type of the key file, the group identifier to which the key file belongs, the first file quantity of the key files of the key type-group identifier in each key file corresponding to the device identifier of the key file, the second file quantity of each key file of the group identifier in each key file corresponding to the device identifier of the key file, the file sequence numbers corresponding to each key file of the key type-group identifier in each key file corresponding to the device identifier of the key file, and a selected random number; wherein the selected random number is used to determine the key for encrypting the device identifier.

[0132] S207: For the device identification corresponding to each key file, according to the file serial number corresponding to each key file of the device identification, each encryption key file of the device identification and the solidified data corresponding to each encryption key file of the device identification are exported in sequence to the target storage directory in units of group identification and key type.

[0133] S208: For each key file, record the output information of the key file.

[0134] The output information includes one or more of the following: whether the key file is completely output, device information of the quantum secure storage device, output time of the key file, key type of the key file, and file identifier of the key file.

[0135] Example 5:

[0136] This application also provides a quantum secure key distribution device, Figure 3 A schematic diagram of a device for outputting quantum secure keys and authentication parameters provided in an embodiment of the present application, comprising: an acquisition unit 31, a determination unit 32, and a processing unit 33;

[0137] The acquisition unit 31 is configured to acquire an output command; wherein the output command carries a key output condition and a target storage directory of the quantum secure storage device, wherein the output condition includes one or more of the following: a device identifier, a device type, a batch number of the key generation batch, a key generation time, an information import time, and an information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported;

[0138] The determining unit 32 is configured to determine each key file that meets the output condition and the authentication parameters corresponding to each key file; wherein each key file includes at least one root key file, and the at least one root key file is used for quantum encryption and decryption. The authentication parameters include a first random number to be expanded for encrypting and decrypting each key file, an authentication index for searching the authentication parameter, a first random number for encrypting the data to be encrypted in the access request, and a second random number for decrypting the data to be decrypted in the access response information. The first random number to be expanded is configured in the quantum security device. The access request is a message for the quantum security device to request the first access to a quantum security base station in the quantum security network. The access response information is a message for the quantum security base station to send to the quantum security device in response to the access request. After the quantum security base station allows the quantum security device to access the feedback message sent by the quantum security device, the quantum security base station relays the keys sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center; obtains the encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file; for each key file, determines the encryption and decryption key corresponding to the key file according to the encryption and decryption root key corresponding to the key file; encrypts the key file according to the encryption and decryption key to obtain an encrypted key file; and determines the fixed data corresponding to the encrypted key file according to the authentication parameter corresponding to the key file; wherein the fixed data includes the first random number to be expanded;

[0139] The processing unit 33 is configured to export the encryption key files and the hardened data corresponding to the encryption key files to the target storage directory in sequence based on device identifications according to the file serial numbers corresponding to the encryption key files.

[0140] In some possible implementations, if the output condition further includes outputting a quantum-safe computing random number, then each key file further includes at least one quantum-safe computing random number file; wherein the quantum-safe computing random number is used for quantum-safe computing.

[0141] In some possible implementations, if the output condition further includes outputting an encryption key, then each key file further includes at least one encryption key file; wherein the encryption key is used by the quantum security device identified by the device to decrypt the received encryption supplementary key after leaving the factory.

[0142] In some possible implementations, the determination unit 32 is specifically used to determine, for each key file, the multiple groups of authentication parameters corresponding to the device identifier of the key file based on the correspondence between the device identifier and the authentication parameter if multiple groups of key files corresponding to at least one device identifier are saved, and each key file in the same group corresponds to the same group identifier and the same authentication parameter; determine the authentication parameter corresponding to the key file based on the group identifier corresponding to the multiple groups of authentication parameters and the group identifier corresponding to the key file; wherein any group of key files includes at least one key file, and the group identifier is used to identify the group to which the key file belongs.

[0143] In some possible implementations, the determination unit 32 is specifically used to determine, for each key file, a target key file corresponding to the group identifier corresponding to the group identifier; determine the root key to be expanded based on the first random number to be expanded in the authentication parameter corresponding to the group identifier; and determine the encryption and decryption root keys corresponding to each target key file based on the first preset key expansion algorithm corresponding to the group identifier and the root key to be expanded.

[0144] In some possible implementations, the processing unit 33 is specifically used to export, for each device identifier corresponding to each key file, the encryption key files of the device identifier and the solidified data corresponding to each encryption key file of the device identifier in sequence to the target storage directory in units of group identifiers according to the file serial numbers corresponding to each key file of the device identifier.

[0145] In some possible implementations, the encryption key file includes one or more of the following information: the key type of the key file, the group identifier to which the key file belongs, the first file quantity of key files of the key type-group identifier in each key file corresponding to the device identifier of the key file, the second file quantity of each key file of the group identifier in each key file corresponding to the device identifier of the key file, the file sequence numbers corresponding to each key file of the key type-group identifier in each key file corresponding to the device identifier of the key file, and a selected random number; wherein the selected random number is used to determine the key for encrypting the device identifier.

[0146] In some possible implementations, any key file carries a checksum corresponding to the key file.

[0147] In some possible implementations, the solidified data includes a first preset key expansion algorithm for determining an encryption and decryption root key, a second preset key expansion algorithm for determining an encryption and decryption key, the device identifier, the authentication index, the first random number, and the second random number.

[0148] In some possible implementations, the determination unit 32 is specifically configured to determine, for each key file, the encryption and decryption key corresponding to the key file based on the length of the key file, the second preset key expansion algorithm, and the encryption and decryption root key corresponding to the key file.

[0149] In some possible implementations, the processing unit 33 is further configured to record output information of each key file for each key file; wherein the output information includes one or more of the following: whether the key file is completely output, device information of the quantum secure storage device, output time of the key file, key type of the key file, and file identifier of the key file.

[0150] In some possible implementations, the determining unit 32 is specifically configured to determine each key file that meets the output condition and is not successfully output.

[0151] In some possible implementations, the determining unit 32 is specifically configured to determine each key file that meets the output condition according to the account authority if the output command carries the account authority.

[0152] The beneficial effects of this application are as follows:

[0153] 1. Since the output instruction obtained by the root key center carries output conditions, the output conditions include one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status. According to the output conditions, more flexible key file export can be achieved, and the exported key files meet user needs, which not only improves the user experience, but also avoids the problem of human misleading key files, and improves the quality of the exported key files.

[0154] 2. In this application, the root key center can obtain the key files corresponding to different device identifiers in advance, and then accurately determine the need to export each key file based on the output conditions. The exported key files can correspond to different device identifiers, thereby realizing the simultaneous export of key files for multiple device identifiers, greatly improving the efficiency of key export. There is no need to manually export the key files corresponding to each device identifier to the target storage directory in turn, reducing the workload of the staff, and facilitating the subsequent simultaneous injection of root keys into multiple quantum security devices, thereby improving the efficiency of the key injection process.

[0155] 3. Because the quantum security base station to which the quantum security device identified by the device is connected can obtain the key file identified by the device from the root key center, key pairing can be achieved between the quantum security base station and the quantum security device identified by the device. Subsequently, the quantum security base station can be used to relay keys sent and received by the quantum security device identified by the device, thereby enabling quantum secure communication between the quantum security device and other quantum security devices. Furthermore, the quantum security device only needs to perform key pairing with the quantum security base station it is connected to, i.e., it does not need to perform key pairing with any quantum security device with which it needs to communicate. This allows the quantum security device to only store the key file identified by the device. This not only reduces the storage pressure on the quantum security device, but also allows any two quantum security devices connected to a quantum security base station in the quantum security network to relay keys through the quantum security network during quantum secure communication, thereby increasing the flexibility of quantum secure communication and eliminating the need for staff to pre-fill the two quantum security devices with keys, reducing the workload expended by staff in key filling.

[0156] 4. Since the root key center exports the solidified data determined based on the authentication parameters corresponding to each key file at the same time as exporting the key file, the authentication parameters include the first random number to be expanded for encrypting and decrypting each key file, the index for searching the authentication parameters, the first random number for encrypting the data to be encrypted in the access request, and the second random number for decrypting the data to be decrypted in the access response information. The first random number to be expanded can be used to encrypt and output the key file and inject it into the quantum security device, thereby ensuring the security of the key file. The first random number and the second random number can be used to enable the quantum security device to use ciphertext communication during the first access to the quantum security base station, thereby ensuring the security of the first access to the quantum security base station.

[0157] 5. Since the root key center exports each encryption key file and the corresponding fixed data of each encryption key file to the target storage directory in sequence based on the file serial number of each encryption key file and the device identification as a unit, confusion between the encryption key files corresponding to different device identifications and the corresponding fixed data of each encryption key file is avoided, and the management of the key files corresponding to each device identification is facilitated.

[0158] Example 6:

[0159] Based on the above embodiment, the present application embodiment further provides a root key center, Figure 4 A schematic diagram of the structure of a root key center provided in an embodiment of the present application is shown as follows: Figure 4As shown, it includes: a processor 41, a communication interface 42, a memory 43 and a communication bus 44, wherein the processor 41, the communication interface 42, and the memory 43 communicate with each other through the communication bus 44;

[0160] The memory 43 stores a computer program. When the program is executed by the processor 41, the processor 41 performs the following steps:

[0161] Obtain an output command; wherein the output command carries the key output conditions and the target storage directory of the quantum secure storage device, the output conditions including one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported;

[0162] Determining key files that meet the output condition and authentication parameters corresponding to the key files; wherein the key files include at least one root key file, the at least one root key file is used for quantum encryption and decryption, the authentication parameters include a first random number to be expanded for encrypting and decrypting the key files, an authentication index for searching the authentication parameters, a first random number for encrypting data to be encrypted in an access request, and a second random number for decrypting data to be decrypted in an access response message, the first random number to be expanded is configured in a quantum security device, the access request is a message from the quantum security device requesting first access to a quantum security base station in a quantum security network, the access response message is a feedback message sent by the quantum security base station to the quantum security device in response to the access request, and after the quantum security base station allows the quantum security device to access, it relays the key sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center;

[0163] Obtaining encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file;

[0164] For each key file, determining an encryption and decryption key corresponding to the key file based on the encryption and decryption root key corresponding to the key file, encrypting the key file based on the encryption and decryption key to obtain an encrypted key file, and determining, based on the authentication parameters corresponding to the key file, the fixed data corresponding to the encrypted key file; wherein the fixed data includes the first random number to be expanded;

[0165] According to the file serial numbers corresponding to the encryption key files, the encryption key files and the hardened data corresponding to the encryption key files are exported to the target storage directory in sequence in units of device identification.

[0166] Since the principle of solving the problem by the above-mentioned root key center is similar to the method of outputting quantum security keys and authenticating parameters, the implementation of the above-mentioned root key center can refer to the embodiment of the method, and the repeated parts will not be repeated.

[0167] The communication bus mentioned in the root key center can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface 42 is used for communication between the root key center and other devices. The memory can include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk storage. Optionally, the memory can also be at least one storage device located away from the aforementioned processor.

[0168] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processing processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.

[0169] Example 6:

[0170] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium, which stores a computer program executable by a processor. When the program runs on the processor, the processor implements the following steps:

[0171] Obtain an output command; wherein the output command carries the key output conditions and the target storage directory of the quantum secure storage device, the output conditions including one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported;

[0172] Determining key files that meet the output condition and authentication parameters corresponding to the key files; wherein the key files include at least one root key file, the at least one root key file is used for quantum encryption and decryption, the authentication parameters include a first random number to be expanded for encrypting and decrypting the key files, an authentication index for searching the authentication parameters, a first random number for encrypting data to be encrypted in an access request, and a second random number for decrypting data to be decrypted in an access response message, the first random number to be expanded is configured in a quantum security device, the access request is a message from the quantum security device requesting first access to a quantum security base station in a quantum security network, the access response message is a feedback message sent by the quantum security base station to the quantum security device in response to the access request, and after the quantum security base station allows the quantum security device to access, it relays the key sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center;

[0173] Obtaining encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file;

[0174] For each key file, determining an encryption and decryption key corresponding to the key file based on the encryption and decryption root key corresponding to the key file, encrypting the key file based on the encryption and decryption key to obtain an encrypted key file, and determining, based on the authentication parameters corresponding to the key file, the fixed data corresponding to the encrypted key file; wherein the fixed data includes the first random number to be expanded;

[0175] According to the file serial numbers corresponding to the encryption key files, the encryption key files and the hardened data corresponding to the encryption key files are exported to the target storage directory in sequence in units of device identification.

[0176] Since the principle of solving the problem by the above-mentioned computer-readable storage medium is similar to the method for outputting quantum secure keys and authentication parameters, the implementation of the above-mentioned computer-readable storage medium can be referred to the embodiment of the method, and the repeated parts will not be repeated.

[0177] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on two or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0178] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each of the two processes and / or blocks in the flowcharts and / or block diagrams, as well as the combination of the processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate two machines, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 2 a process or multiple processes and / or boxes Figure 2 A device that provides the functions specified in a block or multiple blocks.

[0179] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 2 a process or multiple processes and / or boxes Figure 2 The function specified in one or more boxes.

[0180] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 2 a process or multiple processes and / or boxes Figure 2 A step that specifies a function in one or more boxes.

[0181] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A device for outputting quantum secure keys and authentication parameters, characterized in that: The device comprises: an acquisition unit, a determination unit and a processing unit; The acquisition unit is configured to acquire an output command; wherein the output command carries an output condition for the key and a target storage directory of the quantum secure storage device, the output condition including one or more of the following: a device identifier, a device type, a batch number of a key generation batch, a key generation time, an information import time, and an information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported; The determining unit is configured to determine each key file that meets the output condition and the authentication parameters corresponding to each key file; wherein each key file includes at least one root key file, and the at least one root key file is used for quantum encryption and decryption. The authentication parameters include a first random number to be expanded for encrypting and decrypting each key file, an authentication index for searching the authentication parameter, a first random number for encrypting the data to be encrypted in the access request, and a second random number for decrypting the data to be decrypted in the access response information. The first random number to be expanded is configured in the quantum security device. The access request is a message for the quantum security device to request the first access to a quantum security base station in the quantum security network. The access response information is a message sent by the quantum security base station to the quantum security device in response to the access request. After the quantum security base station allows the quantum security device to access, the quantum security base station relays the keys sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center; obtains the encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file; for each key file, determines the encryption and decryption key corresponding to the key file according to the encryption and decryption root key corresponding to the key file, encrypts the key file according to the encryption and decryption key, obtains the encrypted key file, and determines the solidified data corresponding to the encrypted key file according to the authentication parameter corresponding to the key file; wherein the solidified data includes the first random number to be expanded; The processing unit is used to export each encryption key file and the solidified data corresponding to each encryption key file to the target storage directory in sequence based on the device identification according to the file serial numbers corresponding to each pre-saved key file.

2. The device according to claim 1, wherein If the output condition further includes outputting a quantum-safe computing random number, then each key file further includes at least one quantum-safe computing random number file; wherein the quantum-safe computing random number is used for quantum-safe computing.

3. The device according to claim 1, wherein If the output condition further includes outputting an encryption key, then each key file further includes at least one encryption key file; wherein, the encryption key is used to decrypt the received encryption supplementary key after the quantum security device identified by the device leaves the factory.

4. The device according to any one of claims 1 to 3, characterized in that The determination unit is specifically used to determine, for each key file, the multiple groups of authentication parameters corresponding to the device identifier of the key file based on the correspondence between the device identifier and the authentication parameter if multiple groups of key files corresponding to at least one device identifier are stored, and each key file in the same group corresponds to the same group identifier and the same authentication parameter; and determine the authentication parameter corresponding to the key file based on the group identifier corresponding to the multiple groups of authentication parameters and the group identifier corresponding to the key file; wherein any group of key files includes at least one key file, and the group identifier is used to identify the group to which the key file belongs.

5. The device according to claim 4, characterized in that The determination unit is specifically used to determine the target key file corresponding to the group identifier in each key file according to the group identifier corresponding to each key file; determine the root key to be expanded based on the first random number to be expanded in the authentication parameter corresponding to the group identifier; determine the encryption and decryption root key corresponding to each target key file according to the first preset key expansion algorithm corresponding to the group identifier and the root key to be expanded.

6. The device according to claim 4, characterized in that The processing unit is specifically used to export the device identification corresponding to each key file and the solidified data corresponding to each encryption key file of the device identification in sequence to the target storage directory in units of group identification according to the file serial numbers corresponding to each key file of the device identification.

7. The device according to claim 1, wherein Any key file carries the checksum corresponding to the key file.

8. The device according to claim 1, wherein The solidified data includes a first preset key expansion algorithm for determining an encryption and decryption root key, a second preset key expansion algorithm for determining an encryption and decryption key, the device identifier, the authentication index, the first random number, and the second random number.

9. The device according to claim 8, wherein The determining unit is specifically configured to determine, for each key file, the encryption and decryption key corresponding to the key file according to the length of the key file, the second preset key expansion algorithm, and the encryption and decryption root key corresponding to the key file.

10. The device according to claim 1, wherein The processing unit is further configured to record, for each key file, output information of the key file; wherein the output information includes one or more of the following: whether the key file is completely output, device information of the quantum secure storage device, output time of the key file, key type of the key file, and file identifier of the key file.

11. The device according to claim 10, wherein The determining unit is specifically configured to determine each key file that meets the output condition and is not successfully output.

12. The device according to claim 1, wherein The determining unit is specifically configured to determine each key file that meets the output condition according to the account authority if the output command carries the account authority.

13. A method for outputting quantum secure keys and authentication parameters, characterized in that: The method comprises: Obtain an output command; wherein the output command carries the key output conditions and the target storage directory of the quantum secure storage device, the output conditions including one or more of the following: device identification, device type, batch number of the key generation batch, key generation time, information import time, and information import status, wherein the information import time is the time for importing the information required for key generation, and the information import status indicates whether the information required for key generation is successfully imported; Determining key files that meet the output condition and authentication parameters corresponding to the key files; wherein the key files include at least one root key file, the at least one root key file is used for quantum encryption and decryption, the authentication parameters include a first random number to be expanded for encrypting and decrypting the key files, an authentication index for searching the authentication parameters, a first random number for encrypting data to be encrypted in an access request, and a second random number for decrypting data to be decrypted in an access response message, the first random number to be expanded is configured in a quantum security device, the access request is a message from the quantum security device requesting first access to a quantum security base station in a quantum security network, the access response message is a feedback message sent by the quantum security base station to the quantum security device in response to the access request, and after the quantum security base station allows the quantum security device to access, it relays the key sent and received by the quantum security device according to the key file of the quantum security device sent by the root key center; Obtaining encryption and decryption root keys corresponding to each of the key files; wherein any encryption and decryption root key is determined based on the first random number to be expanded corresponding to the key file; For each key file, determining an encryption and decryption key corresponding to the key file based on the encryption and decryption root key corresponding to the key file, encrypting the key file based on the encryption and decryption key to obtain an encrypted key file, and determining, based on the authentication parameters corresponding to the key file, the fixed data corresponding to the encrypted key file; wherein the fixed data includes the first random number to be expanded; According to the pre-saved file serial numbers corresponding to the key files, the encryption key files and the hardened data corresponding to the encryption key files are exported to the target storage directory in sequence based on the device identification.

14. A root key center, characterized in that: The root key center includes at least a processor and a memory, and the processor is used to implement the steps of the method for outputting quantum security keys and authentication parameters as claimed in claim 13 when executing a computer program stored in the memory.

15. A computer-readable storage medium, characterized in that It stores a computer program, which, when executed by a processor, implements the steps of the method for outputting quantum security keys and authentication parameters as claimed in claim 13.

16. A computer program product, characterized in that The computer program product includes: computer program code, which, when executed on a computer, causes the computer to execute the steps of the method for outputting quantum secure keys and authentication parameters as claimed in claim 13.

Citation Information

Patent Citations

  • Quantum security root key exporting device and method, root key center and medium

    CN115913547A

  • Method and device for generating quantum security key and authentication parameter, and root key center

    CN116032472A