A quantum secure identity authentication apparatus, method, device and storage medium

By generating and updating quantum key information through an integrated platform, the problem of independent deployment of encryption devices in IoT platforms is solved, achieving efficient and secure identity authentication while reducing costs and terminal resource consumption.

CN116094698BActive Publication Date: 2026-02-10E SURFING IOT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211724501.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2026-02-10
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

In existing IoT platforms, deploying encryption devices separately on each platform leads to longer implementation cycles, higher equipment costs, and increased terminal power consumption and storage resource consumption.

Method used

A centralized platform generates quantum key information, which is stored on a sub-platform and sent to the terminal for authentication. The authentication is performed by combining the quantum security key and basic identity information. The centralized platform updates the quantum key information, reducing the deployment of encryption devices on the sub-platform.

Benefits of technology

Shorten the implementation cycle, reduce equipment costs and terminal power consumption, improve the security and reliability of identity authentication, simplify the authentication process, and reduce the deployment and testing of quantum key management devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116094698B_ABST
    Figure CN116094698B_ABST
Patent Text Reader

Abstract

The application discloses a kind of quantum security identity authentication device, method, equipment and storage medium, the first quantum secret key information is generated by intensive platform in response to the first identification information of at least one sub-platform, the first quantum secret key information is stored by sub-platform, the first basic identity information of at least one terminal is obtained, the first quantum secret key information is sent to terminal, the registration information of terminal is received, identity authentication is carried out according to the registration information, the first quantum security key and the first basic identity information, the generation of first quantum secret key information is carried out in intensive platform, corresponding encryption equipment does not need to be independently set on sub-platform, it is favorable to shorten implementation cycle, reduce equipment cost, reduce the power consumption and the occupation of storage resource of terminal, the application can be widely applied in computer technology field as a kind of quantum security identity authentication device, method, equipment and storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computers, and in particular to a quantum-secure identity authentication device, method, apparatus, and storage medium. Background Technology

[0002] With the development of industrial digitalization and market-driven forces, the demand for IoT platform construction is becoming increasingly strong. As terminals, platforms, and applications develop on a large scale, cybersecurity has attracted much attention.

[0003] In related technologies, each IoT cloud platform deploys its own encryption device for data encryption and authentication, which leads to a longer implementation cycle and higher equipment costs. At the same time, the terminal needs to set up access with each encryption device, which increases the terminal's power consumption and storage resource usage. Summary of the Invention

[0004] In view of this, in order to solve at least one of the above-mentioned technical problems, the object of the present invention is to provide a quantum-secure identity authentication device, method, apparatus and storage medium.

[0005] The technical solution adopted in this invention is:

[0006] A quantum-secure identity authentication device, comprising:

[0007] The intensive platform, in response to the first identification information of at least one sub-platform, generates first quantum key information, wherein the first quantum key information includes a first quantum security key;

[0008] The sub-platform is used to store the first quantum key information, obtain the first basic identity information of at least one terminal, send the first quantum key information to the terminal, receive the registration information of the terminal, and perform identity verification based on the registration information, the first quantum security key, and the first basic identity information; the registration information includes a second quantum security key and second basic identity information.

[0009] This invention also provides a quantum-secure identity authentication method, comprising:

[0010] The first quantum key information is generated by responding to the first identification information of at least one sub-platform through the intensive platform, and the first quantum key information includes a first quantum security key;

[0011] The first quantum key information is stored on a separate platform to obtain the first basic identity information of at least one terminal. The first quantum key information is sent to the terminal, and the registration information of the terminal is received. Identity verification is performed based on the registration information, the first quantum security key, and the first basic identity information. The registration information includes a second quantum security key and second basic identity information.

[0012] Furthermore, the authentication process based on the registration information, the first quantum security key, and the first basic identity information includes:

[0013] When the first quantum security key is the same as the second quantum security key, and the first basic identity information is the same as the second basic identity information, the authentication result indicates success.

[0014] Furthermore, the step of generating first quantum key information in response to the identification information of at least one platform includes:

[0015] In response to the identification information of at least one platform, the first quantum security key and the first channel encryption key are generated based on the quantum key management service; the first quantum key information also includes the first channel encryption key.

[0016] Furthermore, the quantum-secure identity authentication method also includes:

[0017] When the authentication result is successful, the centralized platform responds to the second identification information of the sub-platform to generate second quantum key information; the second quantum key information includes a third quantum security key and a second channel encryption key;

[0018] The platform receives the second quantum key information, encrypts the second quantum key information according to the first channel encryption key, sends the encryption result to the terminal for decryption, and updates the first quantum key information to the second quantum key information.

[0019] Furthermore, the decryption process includes:

[0020] The encryption result is decrypted using a software development kit to obtain the second quantum key information, which is then stored.

[0021] Furthermore, updating the first quantum key information to the second quantum key information includes:

[0022] The sub-platform responds to the key update reply and updates the first quantum key information to the second quantum key information.

[0023] Furthermore, the first identification information is obtained through the following steps:

[0024] The sub-platform responds to the creation command and generates first identification information; the first identification information includes at least the sub-platform name, product ID, and terminal ID.

[0025] The present invention also provides an electronic device, the electronic device including a processor and a memory, the memory storing at least one instruction, at least one program, code set or instruction set, the at least one instruction, the at least one program, the code set or instruction set being loaded and executed by the processor to implement the method.

[0026] The present invention also provides a computer-readable storage medium storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement the method.

[0027] The beneficial effects of this invention are as follows: by responding to the first identification information of at least one sub-platform through the centralized platform, first quantum key information is generated; the first quantum key information is stored through the sub-platform; the first basic identity information of at least one terminal is obtained; the first quantum key information is sent to the terminal; the registration information of the terminal is received; and identity verification is performed based on the registration information, the first quantum security key, and the first basic identity information. The generation of the first quantum key information is carried out in the centralized platform, which eliminates the need to set up corresponding encryption devices independently on the sub-platforms. This helps to shorten the implementation cycle, reduce equipment costs, reduce terminal power consumption, and reduce storage resource occupation. Attached Figure Description

[0028] Figure 1 This is a structural block diagram of the quantum-secure identity authentication device of the present invention;

[0029] Figure 2 This is a schematic diagram of the steps of the quantum-secure identity authentication method of the present invention. Detailed Implementation

[0030] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0031] The terms "first," "second," "third," and "fourth," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a particular order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.

[0032] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0033] like Figure 1 As shown, this embodiment of the invention provides a quantum-secure identity authentication device, including a centralized platform, at least one sub-platform, and at least one routing engine. Exemplarily, the centralized platform can be a centralized IoT platform, and the sub-platforms can be IoT sub-platforms or vertical industry platforms, etc. Each sub-platform can communicate with at least one terminal. The terminal can be configured with a security carrier and a (secure) SDK (software development kit). The security carrier is used to store quantum keys, and the SDK is used for decrypting downlink data from the sub-platform; no specific limitations are imposed.

[0034] In this embodiment of the invention, the centralized platform integrates a quantum key management service (QMS), responsible for the generation and storage of quantum keys and channel encryption keys. The centralized platform and the sub-platforms are connected through a routing engine; in other embodiments, the connection can be achieved through other methods. It should be noted that this embodiment of the invention uses one of the sub-platforms as an example to illustrate the identity authentication process.

[0035] In this embodiment of the invention, the intensive platform responds to the first identification information of at least one sub-platform to generate first quantum key information, the first quantum key information including a first quantum security key.

[0036] In this embodiment of the invention, the sub-platform is used to store the first quantum key information, obtain the first basic identity information of at least one terminal, send the first quantum key information to the terminal, receive the registration information of the terminal, and perform identity verification based on the registration information, the first quantum security key, and the first basic identity information; the registration information includes a second quantum security key and second basic identity information.

[0037] like Figure 2 As shown, this embodiment of the invention also provides a quantum-secure identity authentication method, applied to the above-mentioned quantum-secure identity authentication device, including steps S100-S200:

[0038] S100. The first quantum key information is generated by responding to the first identification information of at least one sub-platform through the intensive platform. The first quantum key information includes a first quantum security key.

[0039] In this embodiment of the invention, the first identification information can be cached in Redis and obtained through the following steps:

[0040] The sub-platform responds to the creation command and generates first identification information; the first identification information includes, but is not limited to, at least one of the following: sub-platform name, product ID, terminal ID, and product authentication method.

[0041] Optionally, the sub-platform responds to the creation command, for example, creating an NB network standard product under tenant 100 of the sub-platform, with product ID product1, product authentication method quantum security authentication, and adding terminal device1 and terminal device2 to the product. The generated first identification information can then be:

[0042] The first identifier information is then transmitted from the sub-platform to the centralized platform via a routing engine, using the identifier {"paltform":"A","tenantId":"100","productId":"product1","deviceId":["device1","device2"]}. The centralized platform then generates the first quantum key information in response to the first identifier information from the sub-platform. Optionally, the first quantum key information may include at least one of a first channel encryption key and a first quantum security key. In this embodiment, the first quantum key information including both a first channel encryption key and a first quantum security key is used as an example.

[0043] Optionally, the step S100, which involves generating first quantum key information in response to the identification information of at least one platform, specifically includes:

[0044] In response to the identification information of at least one platform, the first quantum security key and the first channel encryption key are generated based on the quantum key management service.

[0045] In this embodiment of the invention, based on the quantum key management service, the quantum random generator generates a first quantum security key according to the number of terminals. For example, if there are terminal device1 and terminal device2, each terminal corresponds to a first quantum security key and is stored in the cryptographic machine. At the same time, each terminal generates a first channel encryption key, forming first quantum key information, which is saved to the key list. That is, each first quantum key information is a key pair, and each terminal has a corresponding first quantum key information as id (first quantum security key) + key (first channel encryption key).

[0046] S200: Store the first quantum key information through a sub-platform, obtain the first basic identity information of at least one terminal, send the first quantum key information to the terminal, receive the registration information of the terminal, and perform identity verification based on the registration information, the first quantum security key, and the first basic identity information; the registration information includes a second quantum security key and second basic identity information.

[0047] In this embodiment of the invention, after the centralized platform generates the first quantum key information, it pulls the first identifier information cached in Redis and sends it back to the sub-platform through the routing engine. The sub-platform obtains the first quantum key information and takes an information snapshot (stored in the terminal information table of the sub-platform as a terminal shadow).

[0048] Then, the sub-platform obtains the terminal's first basic identity information on the sub-platform, such as the IMEI for Narrow Band (NB) devices and the token for cellular devices, and then sends the first quantum key information to the corresponding terminal. It should be noted that when the terminal can obtain its own first basic identity information, the sub-platform may not send the first basic identity information to the terminal; otherwise, in addition to sending the first quantum key information to the terminal, the sub-platform may also send the first basic identity information to the terminal for storage. In this embodiment of the invention, after receiving the first quantum key information, the terminal stores the first quantum key information in a secure carrier; optionally, the secure carrier includes, but is not limited to, a SIM card, a module, and a chip.

[0049] Optionally, when authentication is required, the terminal sends registration information to the sub-platform. This registration information includes, but is not limited to, a quantum identity authentication code formed by the second quantum security key and the second basic identity information, which helps improve the reliability of identity authentication. The second quantum security key refers to the second basic identity information of the terminal sending the registration information and the second quantum security key stored in the terminal.

[0050] Optionally, in step S200, identity verification is performed based on the registration information, the first quantum security key, and the first basic identity information, specifically as follows:

[0051] If the first quantum security key is the same as the second quantum security key, and the first basic identity information is the same as the second basic identity information, the authentication result is successful; otherwise, the authentication result is unsuccessful.

[0052] The quantum-secure identity authentication method of this invention further includes steps S300-S400:

[0053] S300. When the authentication result is successfully represented, the second quantum key information is generated by responding to the second identification information of the sub-platform through the centralized platform.

[0054] Optionally, when the authentication result is successful, the sub-platform generates second identification information. This second identification information includes information about the terminal whose authentication result was successful. For example, if the authentication result of terminal device1 is successful, the second identification information can be: {"paltform":"A","tenantId":"100","productId":"product1","deviceId"}

[0055] The sub-platform sends the second identification information and key update request to the centralized platform. In response to the second identification information of the sub-platform, the centralized platform generates the second quantum key information in the same way as the first quantum key information. The second quantum key information includes the third quantum security key and the second channel encryption key. The second quantum key information is also a key pair. The centralized platform updates the key list.

[0056] S400: Receive the second quantum key information through the sub-platform, encrypt the second quantum key information according to the first channel encryption key, send the encryption result to the terminal for decryption, and update the first quantum key information to the second quantum key information.

[0057] In this embodiment of the invention, the sub-platform receives the second quantum key information sent by the integrated platform, encrypts the second quantum key information using the first channel encryption key, and then sends the encryption result to the terminal.

[0058] Optionally, decryption processing is performed in step S400, specifically as follows:

[0059] The encryption result is decrypted using a software development kit to obtain the second quantum key information, which is then stored.

[0060] Specifically, the terminal decrypts the encryption result using a software development kit (SDK) to obtain the second quantum key information, which is then stored for the next authentication.

[0061] Optionally, in step S400, updating the first quantum key information to the second quantum key information specifically involves:

[0062] The sub-platform responds to the key update reply and updates the first quantum key information to the second quantum key information.

[0063] In this embodiment of the invention, after the terminal decrypts and obtains the second quantum key information, either the terminal or the sub-platform generates a key update response, so that the sub-platform responds to the key update response and updates the first quantum key information to the second quantum key information for the next identity authentication, while avoiding the situation where the authentication information is not refreshed due to factors such as power outages.

[0064] The quantum-secure identity authentication method of this invention, even with multiple sub-platforms and multiple terminals, can easily achieve secure and reliable identity authentication for massive terminal access across a cross-domain IoT platform by deploying a quantum key management device (supporting quantum key management services) in the cloud environment of the centralized platform. This eliminates the need to deploy quantum key management devices on each sub-platform, simplifying the authentication process. It satisfies the requirement for efficient and secure access to the platform for massive numbers of devices without affecting terminal power consumption and storage resources, and significantly reduces the deployment and debugging of quantum key management devices, lowering project costs and shortening the project cycle. Furthermore, the combined authentication method using quantum-secure keys and basic identity authentication information offers higher security and reliability; updating the quantum key information after each successful authentication further enhances security.

[0065] The content of the above method embodiments is applicable to the device embodiments. The specific functions implemented by the device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0066] This invention also provides an electronic device, which includes a processor and a memory. The memory stores at least one instruction, at least one program, a code set, or an instruction set. The processor loads and executes the at least one instruction, at least one program, a code set, or an instruction set to implement the quantum-secure identity authentication method of the aforementioned embodiments. The electronic devices of this invention include, but are not limited to, mobile phones, tablet computers, computers, and in-vehicle computers.

[0067] The content of the above method embodiments is applicable to this device embodiment. The specific functions implemented in this device embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.

[0068] This invention also provides a computer-readable storage medium storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to implement the quantum-secure identity authentication method of the foregoing embodiments.

[0069] This invention also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the quantum-secure identity authentication method of the foregoing embodiments.

[0070] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0071] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0072] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Additionally, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.

[0073] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0074] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A quantum-secure identity authentication device, characterized in that, include: The intensive platform, in response to the first identification information of at least one sub-platform, generates first quantum key information, the first quantum key information including a first quantum security key and a first channel encryption key; The sub-platform is used to store the first quantum key information, obtain the first basic identity information of at least one terminal, send the first quantum key information to the terminal, receive the registration information of the terminal, and perform identity verification based on the registration information, the first quantum security key, and the first basic identity information; the registration information includes a second quantum security key and second basic identity information. When the authentication result is successful, the centralized platform responds to the second identification information of the sub-platform to generate second quantum key information; the second quantum key information includes a third quantum security key and a second channel encryption key, and the second identification information includes information about the terminal whose authentication result is successful; The sub-platform is also used to receive the second quantum key information, encrypt the second quantum key information according to the first channel encryption key, send the encryption result to the terminal for decryption, and update the first quantum key information to the second quantum key information; wherein, both the sub-platform and the terminal store the second quantum key information, and the second quantum key information is used for the next authentication.

2. A quantum-secure identity authentication method, characterized in that, include: The first quantum key information is generated by responding to the first identification information of at least one sub-platform through the intensive platform. The first quantum key information includes a first quantum security key and a first channel encryption key. The first quantum key information is stored on a sub-platform, the first basic identity information of at least one terminal is obtained, the first quantum key information is sent to the terminal, the registration information of the terminal is received, and identity verification is performed based on the registration information, the first quantum security key and the first basic identity information. The registration information includes a second quantum security key and second basic identity information; The quantum-secure identity authentication method further includes: When the authentication result is successful, the centralized platform responds to the second identification information of the sub-platform to generate second quantum key information; the second quantum key information includes a third quantum security key and a second channel encryption key, and the second identification information includes information about the terminal whose authentication result was successful; The sub-platform receives the second quantum key information, encrypts the second quantum key information according to the first channel encryption key, sends the encryption result to the terminal for decryption, and updates the first quantum key information to the second quantum key information; wherein, both the sub-platform and the terminal store the second quantum key information, which is used for the next authentication.

3. The quantum-secure identity authentication method according to claim 2, characterized in that: The authentication process based on the registration information, the first quantum security key, and the first basic identity information includes: When the first quantum security key is the same as the second quantum security key, and the first basic identity information is the same as the second basic identity information, the authentication result indicates success.

4. The quantum-secure identity authentication method according to claim 2, characterized in that: The first quantum key information is generated in response to the identification information of at least one platform, including: In response to the identification information of at least one platform, the first quantum security key and the first channel encryption key are generated based on the quantum key management service.

5. The quantum-secure identity authentication method according to claim 2, characterized in that: The decryption process includes: The encryption result is decrypted using a software development kit to obtain the second quantum key information, which is then stored.

6. The quantum-secure identity authentication method according to claim 2, characterized in that: The step of updating the first quantum key information to the second quantum key information includes: The sub-platform responds to the key update reply and updates the first quantum key information to the second quantum key information.

7. The quantum-secure identity authentication method according to any one of claims 2-6, characterized in that: The first identification information is obtained through the following steps: The sub-platform responds to the creation command and generates first identification information; the first identification information includes at least the sub-platform name, product ID, and terminal ID.

8. An electronic device, characterized in that: The electronic device includes a processor and a memory, the memory storing at least one instruction, at least one program, a code set, or an instruction set, the at least one instruction, the at least one program, the code set, or the instruction set being loaded and executed by the processor to implement the method as described in any one of claims 2-7.

9. A computer-readable storage medium, characterized in that: The storage medium stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement the method as described in any one of claims 2-7.

Citation Information

Patent Citations

  • Method, system and equipment for enhancing MQTT protocol identity authentication by using symmetric cryptographic technology

    CN113612605A