Quantum encryption system for multi-party mobile communication, quantum key distribution method and encryption method

By using a quantum key distribution device to form a local area network with the terminal in a multi-party mobile communication environment, quantum keys are generated and distributed, and the terminal device encrypts data locally, thus solving the problem of key theft during transmission and realizing highly secure quantum encrypted communication.

CN116155487BActive Publication Date: 2026-02-06ANHUI QASKY QUANTUM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211626403.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-16
Publication Date
2026-02-06
Estimated Expiration
2042-12-16

AI Technical Summary

Technical Problem

In existing communication encryption systems, keys are at risk of being stolen during transmission, especially in multi-party mobile communication environments. The security of existing RSA encryption algorithms under quantum computing is difficult to guarantee.

Method used

The quantum encryption system employing multi-party mobile communication forms a local area network with the communication server and terminal through the first and second quantum key distribution devices. Quantum keys are generated and distributed using a quantum key distribution protocol. Terminal devices download keys from the key pool to the terminal key chip for encryption, transmitting only encrypted data and reducing the risk of key theft.

Benefits of technology

This has improved the security of multi-party mobile communication, reduced the risk of quantum key theft, and enhanced the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116155487B_ABST
    Figure CN116155487B_ABST
Patent Text Reader

Abstract

The application discloses a multi-party mobile communication quantum encryption system, which comprises a first quantum key distribution device arranged in a first region, a first communication server in communication connection with the first quantum key distribution device, and a plurality of first communication terminals in communication connection with the first communication server; a second quantum key distribution device arranged in a second region, a second communication server in communication connection with the second quantum key distribution device, and a plurality of second communication terminals in communication connection with the second communication server; the first quantum key distribution device is in remote communication connection with the second quantum key distribution device, and the first communication server is in remote communication connection with the second communication server. Terminal equipment downloads keys belonging to it from a key pool to a terminal key chip in batches, selects quantum keys from a local terminal key chip for encryption during encrypted communication, and only transmits encrypted data to a target terminal through a communication server, so that the risk of stealing quantum keys during communication is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of quantum communication, and more particularly, the present application relates to a quantum encryption system for multi-party mobile communication, a quantum key distribution method and an encryption method. BACKGROUND

[0002] With the rapid development of modern communication technology, the communication environment is becoming more and more complex, and the communication security problem is becoming more and more serious, and various industries pay more and more attention to communication security. The most commonly used RSA encryption algorithm is under the impact of quantum computing, and the security has been difficult to guarantee. Quantum secure communication is based on the basic laws of quantum mechanics, quantum non-cloning and Heisenberg uncertainty principle, and uses "one-time one-key" encryption to ensure the unconditional security of quantum cryptography, and the application of quantum key distribution technology is also becoming more and more widely. Since quantum key distribution technology (QKD) was proposed in 1984, due to its provable security, it has attracted the attention and research of many researchers in the world. The technology generates a secure true random key between different places by loading key information on light quantum, and its security is not affected by the computing and storage capacity of the eavesdropper, and the eavesdropping behavior on the system can be detected in real time. By using the secure key generated by quantum key distribution to perform "one-time one-key" encryption of plaintext, theoretically, an unbreakable information encryption means against quantum computing can be realized.

[0003] The existing communication encryption is that the server generates a key, sends it to the client, the client encrypts the data to be transmitted based on the key, sends the encrypted data and the key to the target object, and the target object decrypts the encrypted data based on the key. The key is transmitted together with the encrypted data, and there is a high risk of key theft.

[0004] The present application provides a quantum encryption system for multi-party mobile communication, which aims to improve the above problems.

[0005] The present application is implemented as follows: a quantum encryption system for multi-party mobile communication, the system comprises:

[0006] A first quantum key distribution device is arranged in a first region, the first quantum key distribution device is in communication connection with a first communication server, the first communication server is in communication connection with a plurality of first communication terminals, and the first quantum key distribution device, the first communication server and the first communication terminals form a local area network;

[0007] A second quantum key distribution device is arranged in a second region, the second quantum key distribution device is in communication connection with a second communication server, the second communication server is in communication connection with a plurality of second communication terminals, and the second quantum key distribution device, the second communication server and the second communication terminals form a local area network;

[0008] The first quantum key distribution device is in remote communication connection with the second quantum key distribution device, and the first communication server is in remote communication connection with the second communication server.

[0009] Further, the first communication server is provided with a first preliminary key pool C1, the second server is provided with a second preliminary key pool C2, each first communication terminal is provided with a sub-key pool C 1i , and the sub-key pool C 1i is shared by the i-th first communication terminal and the first communication server. 2i , and the sub-key pool C 2i is shared by the i-th second communication terminal and the second communication server.

[0010] Further, the first preliminary key pool C1 includes a shared sub-key pool C 12 ' for communication encryption between the first communication server and the second server, and a supplementary sub-key pool C 1i ' for key supplement in the sub-key pool C 11 ';

[0011] The second preliminary key pool C2 includes a shared sub-key pool C 21 ' for communication encryption between the first communication server and the second server, and a supplementary sub-key pool C 2i ' for key supplement in the sub-key pool C 22 ';

[0012] The shared sub-key pool C 21 ' and the shared sub-key pool C 12 ' have the same quantum key.

[0013] The application is implemented as follows: a quantum key distribution method based on a multi-party mobile communication quantum encryption system, which specifically includes the following steps:

[0014] S1, the first quantum key distribution device and the second quantum key distribution device generate quantum keys consistent with each other according to a quantum key distribution protocol, and send the quantum keys to the first communication server and the second communication server respectively;

[0015] S1, the first quantum key distribution device and the second quantum key distribution device generate quantum keys consistent with each other according to a quantum key distribution protocol, and send the quantum keys to the first communication server and the second communication server respectively;

[0016] S2, the first communication server stores the quantum key distributed by the first quantum key distribution device in the first preliminary key pool C1, and stores part of the quantum key in the first preliminary key pool C1 in the shared sub-key pool C 12the rest of the quantum keys are stored in the supplementary sub-key pool C 11 the quantum keys in the supplementary sub-key pool C 11 are distributed to the first communication terminal T 1i according to a set proportion, and the rest of the quantum keys are stored in the sub-key pool C 1i of the first communication terminal T 1i , and the terminal key chip X 1i takes all the quantum keys in the sub-key pool C 1i .

[0017] The second communication server stores the quantum keys distributed by the second quantum key distribution device in the second preliminary key pool C2, and stores part of the quantum keys in the second preliminary key pool C2 into the shared sub-key pool C 21 , and the rest of the quantum keys are stored in the supplementary sub-key pool C 22 . The quantum keys in the supplementary sub-key pool C 22 are distributed to the second communication terminal X 2i according to a set proportion, and the rest of the quantum keys are stored in the sub-key pool C 2i of the second communication terminal T 2i , and the terminal key chip X 2i takes all the quantum keys in the sub-key pool C 2i .

[0018] Further, the method is specifically as follows:

[0019] The first communication server distributes the quantum keys in the first preliminary key pool C1 to the shared sub-key pool C 12 and the supplementary sub-key pool C 11 according to a proportion, and the second communication server distributes the quantum keys in the first preliminary key pool C2 to the shared sub-key pool C 21 and the supplementary sub-key pool C 22 according to a proportion.

[0020] Further, when the quantum keys in the sub-key pool C 1i are insufficient, the supplementary sub-key pool C 11 supplements the quantum keys to the corresponding sub-key pool C 1i , and the terminal key chip X 1i takes the supplemented quantum keys from the sub-key pool C 1i , and when the quantum keys in the sub-key pool C 2i are insufficient, the supplementary sub-key pool C 22 supplements the quantum keys to the corresponding sub-key pool C 2i , and the terminal key chip X 2i takes the supplemented quantum keys from the sub-key pool C 2i .

[0021] This invention is implemented as follows: an encryption method for a quantum encryption system based on multi-party mobile communication, the method being as follows:

[0022] S1. Communication terminal A establishes a communication connection with communication terminal B;

[0023] S2. Detect whether communication terminal A and communication terminal B are located in the same local area network. If the detection result is yes, then communication between communication terminal A and communication terminal B is completed based on the communication server in the local area network. If the detection result is no, then proceed to step S3.

[0024] S3. Establish two communication servers in two local area networks to complete communication between communication terminal A and communication terminal B.

[0025] Furthermore, the communication method between communication terminal A and communication terminal B in the same local area network is as follows:

[0026] Communication terminal A receives terminal key chip X A Select quantum key K A Based on quantum key distribution K A Encrypt the data M0 to be sent to form encrypted data M. A And send it to the communication server within the local area network;

[0027] The communication server receives the subkey pool C. A Obtaining quantum key K A For encrypted data M A Decryption is performed to obtain the data M0 to be sent, and the data is retrieved from the subkey pool C of communication terminal B. B Select quantum key K B Based on quantum key distribution K B Encrypt the data M0 to be sent to form encrypted data M. B And send it to communication terminal B;

[0028] Communication terminal B from terminal key chip X B Obtaining quantum key K B For encrypted data M B Decrypt the data to obtain the data M0 sent by communication terminal A.

[0029] Among them, terminal key chip X A Terminal key chip X B They come from sub-key pool C respectively A Subkey pool C B C A C B ∈C 1i Or C A C B ∈C 2i .

[0030] Furthermore, the communication methods between communication terminal A and communication terminal B in the two local area networks are as follows:

[0031] Communication terminal A receives terminal key chip X A Select quantum key K A Based on quantum key distribution K A Encrypt the data M0 to be sent to form encrypted data M. A And send it to communication server A within the local area network;

[0032] Communication server A from sub-key pool C A Obtaining quantum key K A For encrypted data M A Decrypt to obtain the data M0 to be sent, and retrieve it from the shared subkey pool C. 12 Quantum key K1′2 is selected from the quantum key to encrypt data M0, forming encrypted data M. 12 And send it to the communication server B in the local area network where the communication terminal B is located;

[0033] Communication server B from shared subkey pool C 21 Obtain the quantum key K1′2 from the quantum key K1′2, and encrypt the data M based on the quantum key K1′2. 12 Decrypt and obtain data M0 from the subkey pool C of communication terminal B. B Select quantum key K B Based on quantum key distribution K B Encrypt the data M0 to be sent to form encrypted data M. B And send it to communication terminal B;

[0034] Communication terminal B from terminal key chip X B Obtaining quantum key K B For encrypted data M B Decrypt the data to obtain data M0 sent by communication terminal A;

[0035] Among them, terminal key chip X A Terminal key chip X B They come from sub-key pool C respectively A Subkey pool C B C A ∈C 1i C B ∈C 2i .

[0036] The quantum encryption system for multi-party mobile communication provided by the application can realize simultaneous encryption communication of multiple parties, greatly improves the security of communication by using quantum key encryption, and reduces the risk of quantum key theft during communication by downloading the quantum key from the key pool to the terminal key chip and selecting the quantum key from the local terminal key chip for encryption. BRIEF DESCRIPTION OF DRAWINGS

[0037] Figure 1 The structure diagram of the quantum encryption system for multi-party mobile communication provided by the embodiment of the application is shown.

[0038] Figure 2 The flowchart of the quantum key distribution method provided by the embodiment of the application is shown. DETAILED DESCRIPTION

[0039] The specific embodiments of the application are further described below with reference to the drawings, and the description of the embodiments helps those skilled in the art to have a more complete, accurate and in-depth understanding of the inventive concept and technical solution of the application.

[0040] Figure 1 The structure diagram of the quantum encryption system for multi-party mobile communication provided by the embodiment of the application is shown, and only the parts related to the embodiment of the application are shown for convenience of description.

[0041] The system comprises:

[0042] The first quantum key distribution device is arranged in the first region and is in communication connection with the first communication server, the first communication server is in communication connection with a plurality of first communication terminals, and the first quantum key distribution device, the first communication server and the first communication terminals form a local area network.

[0043] The second quantum key distribution device is arranged in the second region and is in communication connection with the second communication server, the second communication server is in communication connection with a plurality of second communication terminals, and the second quantum key distribution device, the second communication server and the second communication terminals form a local area network.

[0044] The first quantum key distribution device and the second quantum key distribution device are in remote communication connection, and the first communication server and the second communication server are in remote communication connection.

[0045] The first communication server is provided with a first preliminary key pool C1, the second server is provided with a second preliminary key pool C2, and each first communication terminal is provided with a sub-key pool C 1i 1i ​To ensure that the i-th first communication terminal shares a key pool with the first communication server, each second communication terminal has a sub-key pool C. 2i Subkey pool C 2i The second communication terminal and the second communication server share the same communication.

[0046] In this embodiment of the invention, the first pre-shared key pool C1 includes: a shared sub-key pool C for encrypting communication between the first communication server and the second server. 12 ′ and used for subkey pool C 1i Supplementary subkey pool C for internal key supplementation 11 The second preliminary key pool C2 includes: a shared sub-key pool C for encryption of communication between the first communication server and the second server. 21 ′ and used for subkey pool C 2i Supplementary subkey pool C for internal key supplementation 22 ′, Shared subkey pool C 12 ′ and shared subkey pool C 21 The quantum key is the same in ′.

[0047] Figure 2 A flowchart of a quantum key distribution method provided in an embodiment of the present invention is shown, which specifically includes the following steps:

[0048] S1. The first quantum key distribution device and the second quantum key distribution device generate quantum keys that are completely identical to each other in accordance with the quantum key distribution protocol, and send them to the first communication server and the second communication server respectively.

[0049] S2. The first communication server stores the quantum keys distributed by the first quantum key distribution device in the first preliminary key pool C1, and stores a portion of the quantum keys in the first preliminary key pool C1 into the shared sub-key pool C. 12 The remaining portion is stored in the supplementary subkey pool C. 11 In ', supplement the sub-key pool C 11 The quantum key within ′ is distributed to each first communication terminal X according to a set ratio. 1i Subkey pool C 1i First communication terminal T 1i Terminal key chip X 1i Take subkey pool C 1i All quantum keys in the database;

[0050] The second communication server stores the quantum keys distributed by the second quantum key distribution device in the second preliminary key pool C2, and stores a portion of the quantum keys in the second preliminary key pool C2 into the shared sub-key pool C. 21 The remaining portion is stored in the supplementary subkey pool C. 22 In ', supplement the subkey pool C22 The quantum key within ′ is distributed to each second communication terminal T according to a set ratio. 2i Subkey pool C 2i Second communication terminal T 2i Terminal key chip X 2i Take subkey pool C 2i All quantum keys in the database.

[0051] The first communication server distributes the quantum keys in the first preliminary key pool C1 to the shared subkey pool C according to the proportion. 12 ′ and supplementary subkey pool C 11 In the process, the second communication server distributes the quantum keys in the second preliminary key pool C2 to the shared sub-key pool C according to the specified ratio. 21 ′ and supplementary subkey pool C 22 ′.

[0052] In this embodiment of the invention, in the sub-key pool C 1i When the quantum key pool is insufficient, supplement the sub-key pool C. 11 'Give the corresponding subkey pool C 1i To replenish the key, the terminal key chip X... 1i From subkey pool C 1i Take the supplementary quantum key in subkey pool C. 2i When the quantum key pool is insufficient, supplement the sub-key pool C. 22 'Give the corresponding subkey pool C 2i After supplementing the key, the terminal key chip X 2i From subkey pool C 2i Take away the supplementary quantum key.

[0053] Initially, the first and second communication servers each receive 10,000 bits of a shared key. An equal 5,000 bits (e.g., the latter half) are allocated to the first reserve key pool C1. The remaining 5,000 bits (the first half) are distributed to sub-key pools C1 in the order of 1000 bits, 1500 bits, 1200 bits, and 1300 bits respectively. 11 C 12 C 13 C 14 The system then notifies the terminal key chip of the corresponding first communication terminal to retrieve the relevant quantum key from the first communication server; the second communication server allocates the same 5000 bits (e.g., the latter half) to the second reserve key pool C2, and the remaining 5000 bits (the first half) are allocated to the sub-key pools C1, C2, C3, C4, C5, C6, C7, C8, C9, C1 ... 21 C 22 C23 C 24 In the middle, it notifies the terminal key chip of the second communication terminal to retrieve the relevant quantum key from the second communication server.

[0054] Subkey pool C 1i This sub-key pool is used only for encrypted communication between the i-th first communication terminal and the first communication server, and has no relation to other first communication terminals. Other sub-key pools follow the same principle. Sub-key pool C 2i It is used only for encrypted communication between the i-th second communication terminal and the second communication server, and has no relation to other second communication terminals. The same applies to other sub-key pools.

[0055] Figure 2 The flowchart of a quantum encryption method for multi-party mobile communication provided in this embodiment of the invention includes the following steps:

[0056] S1. Communication terminal A establishes a communication connection with communication terminal B;

[0057] S2. Detect whether communication terminal A and communication terminal B are located in the same local area network. If the detection result is yes, then communication between communication terminal A and communication terminal B is completed based on the communication server in the local area network. If the detection result is no, then proceed to step S3.

[0058] S3. Establish two communication servers in two local area networks to complete communication between communication terminal A and communication terminal B.

[0059] In this embodiment of the invention, the communication method between communication terminal A and communication terminal B in the same local area network is as follows:

[0060] Communication terminal A obtains key information from terminal key chip X. A Select quantum key K A Based on quantum key distribution K A Encrypt the data M0 to be sent to form encrypted data M. A And send it to the communication server within the local area network;

[0061] The communication server obtains key information from subkey pool C. A Obtaining quantum key K A For encrypted data M A Decryption is performed to obtain the data M0 to be sent, and the data is then retrieved from the subkey pool C of communication terminal B based on the key index information. B Select quantum key K B Based on quantum key distribution K B Encrypt the data M0 to be sent to form encrypted data M. B And send it to communication terminal B;

[0062] Communication terminal B obtains key information from terminal key chip X. B Obtaining quantum key K B For encrypted data M B Decrypt the data to obtain the data M0 sent by communication terminal A.

[0063] Among them, terminal key chip X A Terminal key chip X B They come from sub-key pool C respectively A Subkey pool C B C A C B ∈C 1i Or C A C B ∈C 2i When communication terminal B replies to communication terminal A, it also sends the data to be sent to communication terminal A using the method described above.

[0064] In this embodiment of the invention, the communication method between communication terminal A and communication terminal B in two local area networks is as follows:

[0065] Communication terminal A obtains key information from terminal key chip X. A Select quantum key K A Based on quantum key distribution K A Encrypt the data M0 to be sent to form encrypted data M. A And send it to communication server A within the local area network;

[0066] Communication server A obtains key information from subkey pool C. A Obtaining quantum key K A For encrypted data M A Decryption is performed to obtain the data M0 to be sent, and the data is retrieved from the shared subkey pool C based on the key index information. 12 Quantum key K1′2 is selected from the quantum key to encrypt data M0, forming encrypted data M. 12 And send it to the communication server B in the local area network where the communication terminal B is located;

[0067] Communication server B obtains key information from shared subkey pool C. 21 Obtain the quantum key K1′2 from the quantum key K1′2, and encrypt the data M based on the quantum key K1′2. 12 Decryption is performed to obtain data M0, and based on the key index information, it is retrieved from the subkey pool C of communication terminal B. B Select quantum key K B Based on quantum key distribution K B Encrypt the data M0 to be sent to form encrypted data M. Band sends to the communication terminal B;

[0068] The communication terminal B obtains the quantum key K from the terminal key chip X based on the key index information B B decrypts the encrypted data M B and obtains the data M0 sent by the communication terminal A.

[0069] The terminal key chip X A The terminal key chip X B are respectively from the sub-key pool C A The terminal key chip X B C A ∈C 1i C B ∈C 2i When the communication terminal B replies data to the communication terminal A, the data to be sent to the communication terminal A is also sent by the above method.

[0070] In the embodiment of the present application, the communication terminal A can select the non-encrypted communication mode or the encrypted communication mode when communicating with the communication terminal B. The encryption method of the encrypted communication mode is as described above.

[0071] In the embodiment of the present application, the quantum key index information of the quantum keys in the sub-key pool C 1i The sub-key pool C 2i The shared sub-key pool C 12 ′ and the shared sub-key pool C 21 ′ is destroyed. Since the quantum key index information of the shared sub-key pool C 12 ′ and the shared sub-key pool C 21 ′ is the same, if the first quantum key index in the shared sub-key pool C 12 ′ is used to encrypt the quantum key, the index of the first quantum key is deleted in the quantum key index information, and the quantum key is deleted in the shared sub-key pool C 12 ′. Then, if the first quantum key index in the shared sub-key pool C 21 ′ is used to decrypt the quantum key, the first quantum key is deleted in the quantum key list, and the quantum key is deleted in the shared sub-key pool C 21 ′.

[0072] The present application is described by way of example, and it is obvious that the specific implementation of the present application is not limited to the above method. Any non-essential improvement or direct application of the concept and technical solution of the present application to other occasions is within the protection scope of the present application.​

Claims

1. A quantum encryption system for multi-party mobile communications, characterized by, The system comprises: The first quantum key distribution device is arranged in the first region, and is in communication connection with the first communication server. The first communication server is in communication connection with a plurality of first communication terminals. The first quantum key distribution device, the first communication server, and the first communication terminals form a local area network. The second quantum key distribution device is arranged in the second region, and is in communication connection with the second communication server. The second communication server is in communication connection with a plurality of second communication terminals. The second quantum key distribution device, the second communication server, and the second communication terminals form a local area network. The first quantum key distribution device and the second quantum key distribution device are in remote communication connection. The first communication server and the second communication server are in remote communication connection. The first quantum key distribution device and the second quantum key distribution device are respectively configured to generate quantum keys consistent with both parties according to a quantum key distribution protocol, and to send the quantum keys to the first communication server and the second communication server respectively through the local area network. The first communication server is provided with a first preliminary key pool. The first communication server is configured to store the quantum keys generated by the first quantum key distribution device into the first preliminary key pool. The first communication terminal is provided with a terminal key chip. The first communication terminal is configured to download the quantum keys from the first preliminary key pool in batches, and to store the quantum keys into the terminal key chip. When performing encrypted communication, the first communication terminal is configured to select quantum keys from the terminal key chip to perform encryption, and to send only encrypted data. The second communication server is provided with a second preliminary key pool. The second communication server is configured to store the quantum keys generated by the second quantum key distribution device into the second preliminary key pool. The second communication terminal is provided with a terminal key chip. The second communication terminal is configured to download the quantum keys from the second preliminary key pool in batches, and to store the quantum keys into the terminal key chip. When performing encrypted communication, the second communication terminal is configured to select quantum keys from the terminal key chip to perform encryption, and to send only encrypted data.

2. The quantum encryption system for multi-party mobile communications of claim 1, wherein, The first communication server is provided with a first pool of preliminary keys C1, the second server is provided with a second pool of preliminary keys C2, each first communication terminal is provided with a pool of sub-keys C 1i , the pool of sub-keys C 1i is shared by the i-th first communication terminal and the first communication server, each second communication terminal is provided with a pool of sub-keys C 2i , the pool of sub-keys C 2i is shared by the i-th second communication terminal and the second communication server.

3. The quantum encryption system for multi-party mobile communications of claim 2, wherein, The first prepared key pool C1 includes a shared sub-key pool C for communication encryption between the first communication server and the second server 12 and a sub-key pool C supplemented by an internal key 1i for supplementing the sub-key pool C 11 ′ The second preliminary key pool C2 includes a shared sub-key pool C for encryption of communication between the first communication server and the second server 21 and a sub-key pool C supplemented by an internal key 2i supplemented by an internal key 22 supplemented by an internal key The shared sub-key pool C 21 The shared sub-key pool C 12 The shared sub-key pool C 4. A quantum key distribution method based on the quantum encryption system for multi-party mobile communication according to any one of claims 1 to 3, characterized in that, The method specifically comprises the following steps: S1. The first quantum key distribution device and the second quantum key distribution device generate quantum keys consistent with both parties according to a quantum key distribution protocol, and send the quantum keys to the first communication server and the second communication server respectively. S2. The first communication server stores the quantum keys distributed by the first quantum key distribution device in the first preliminary key pool C1, and stores a portion of the quantum keys in the first preliminary key pool C1 into the shared sub-key pool C. 12 The remaining portion is stored in the supplementary subkey pool C. 11 In ', supplement the sub-key pool C 11 The quantum key within ′ is distributed to each first communication terminal T according to a set ratio. 1i Subkey pool C 1i First communication terminal T 1i Terminal key chip X 1i Take subkey pool C 1i All quantum keys in the database; The second communication server stores the quantum keys distributed by the second quantum key distribution device in a second preliminary key pool C2, stores part of the quantum keys in the second preliminary key pool C2 into a shared sub-key pool C 21 ', and stores the remaining part in a supplementary sub-key pool C 22 '. The quantum keys in the supplementary sub-key pool C 22 ' are distributed to the sub-key pools C 2i of the second communication terminals X 2i in a set proportion. The terminal key chips X 2i of the second communication terminals T 2i take away all the quantum keys in the sub-key pool C 2i .

5. The quantum key distribution method of claim 4, wherein, The method is specifically as follows: The first communication server allocates quantum keys in the first preliminary key pool C1 to the shared sub-key pool C 12 and the supplementary sub-key pool C 11 in proportion. The second communication server allocates quantum keys in the first preliminary key pool C2 to the shared sub-key pool C 21 and the supplementary sub-key pool C 22 in proportion.

6. The quantum key distribution method of claim 5, wherein, When the quantum keys in the sub-key pool C 1i are insufficient, the corresponding sub-key pool C 11 is replenished with quantum keys. 1i After the replenishment of the keys, the terminal key chip X 1i takes out the replenished quantum keys from the sub-key pool C 1i When the quantum keys in the sub-key pool C 2i are insufficient, the corresponding sub-key pool C 22 is replenished with quantum keys. 2i After the replenishment of the keys, the terminal key chip X 2i takes out the replenished quantum keys from the sub-key pool C 2i .

7. An encryption method based on the multi-party mobile communication quantum encryption system of any one of claims 1 to 3, characterized in that, The communication method of the communication terminal A and the communication terminal B in the same local area network is specifically as follows: Communication terminal A receives terminal key chip X A Select quantum key K A Based on quantum key distribution K A Encrypt the data M0 to be sent to form encrypted data M. A And send it to the communication server within the local area network; The communication server acquires a quantum key K from the sub-key pool C A of the communication terminal A A , decrypts the encrypted data M A to obtain the data to be sent M0, selects a quantum key K from the sub-key pool C B of the communication terminal B B , encrypts the data to be sent M0 based on the quantum key K B to form encrypted data M B , and sends it to the communication terminal B; Communication terminal B from terminal key chip X B Obtaining quantum key K B For encrypted data M B Decrypt the data to obtain data M0 sent by communication terminal A; Wherein, the terminal key chip X A , the terminal key chip X B respectively from the sub-key pool C A , the sub-key pool C B , C A , C B ∈C 1i or C A , C B ∈C 2i .

8. An encryption method for the multi-party mobile communication quantum encryption system according to any one of claims 1 to 3, characterized in that, The communication method of the communication terminal A and the communication terminal B in the two local area networks is specifically as follows: The communication terminal A selects a quantum key K from the terminal key chip X A A A A encrypts the to-be-sent data M0 based on the quantum key K, forms encrypted data M, and sends the encrypted data M to the communication server A in the local area network​​​ Communication server A from sub-key pool C A Obtaining quantum key K A For encrypted data M A Decrypt to obtain the data M0 to be sent, and retrieve it from the shared subkey pool C. 12 Selecting a quantum key K′ 12 Encrypt the data M0 to form encrypted data M 12 And send it to the communication server B in the local area network where the communication terminal B is located; Communication server B from shared subkey pool C 21 Obtaining the quantum key K′ 12 Based on quantum key distribution K′ 12 For encrypted data M 12 Decrypt and obtain data M0 from the subkey pool C of communication terminal B. B Select quantum key K B Based on quantum key distribution K B Encrypt the data M0 to be sent to form encrypted data M. B And send it to communication terminal B; Communication terminal B from terminal key chip X B Obtaining quantum key K B For encrypted data M B Decrypt the data to obtain data M0 sent by communication terminal A; Wherein, the terminal key chip X A , the terminal key chip X B respectively from the sub-key pool C A , the sub-key pool C B , C A ∈C 1i , C B ∈C 2i .

Citation Information

Patent Citations

  • Quantum key based satellite communication encryption system and method

    CN106953729A

  • Cloud platform management method and system based on quantum key distribution technology

    CN112134695A