Key distribution method and system for internet of things terminal
By combining the quantum cryptography service platform and the quantum service card, key sharing between IoT terminals and business servers is realized, solving the problem of inconvenient key distribution for IoT terminals under the symmetric key system, improving security and convenience, and reducing application costs.
Patent Information
- Application Number
- CN202111643299.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-29
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2041-12-29
AI Technical Summary
When using symmetric key systems, IoT terminals face challenges in key distribution due to inconvenience and inflexibility. This is especially true in application scenarios where devices are geographically dispersed and data is offline most of the time, making it difficult to securely and conveniently share keys.
A quantum cryptography service platform is used to generate quantum keys, and encrypted information is exchanged between the quantum service card and the input terminal to realize key sharing between IoT terminals and business servers. The quantum keys are pre-charged inside the terminal, and no power consumption is required during the network access process. Users can purchase and access the network themselves.
It enables convenient and secure key distribution for IoT terminals, reduces battery consumption, simplifies the network access process, lowers the application threshold, and enhances the marketability and modular application of IoT terminals.
Smart Images

Figure CN116418484B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of secret communication, and particularly relates to a key distribution method and system for an Internet of Things terminal. BACKGROUND
[0002] The statements in this section merely provide background information related to the present application and do not necessarily constitute the prior art.
[0003] With the rapid development of information technology, networks and hardware, the number of various types of Internet of Things terminal devices is rapidly increasing in daily production and life. However, compared with traditional computer terminals, the Internet of Things terminal is more urgent in resisting attacks due to its simple structure, weak physical protection, spatial dispersion and other characteristics.
[0004] At present, the key distribution of the Internet of Things terminal is mainly based on the asymmetric key (public-private key pair) system. However, with the progress of computer technology, the asymmetric algorithm based on traditional mathematical calculation complexity has the possibility of being cracked. If quantum keys and the like are used as symmetric keys, the problem of not being easy to distribute keys for the Internet of Things terminal is faced.
[0005] When the Internet of Things terminal uses a symmetric key system such as a quantum key, unlike ordinary computers that can be connected in real time, the Internet of Things terminal device often has difficulty in keeping the power on at all times due to the need for battery power saving. Therefore, if the symmetric key is to support "one-time pad" or at least "one-industry pad" such high-security secret communication, it is relatively troublesome to distribute a large number of keys to the Internet of Things terminals scattered in different spaces through the network.
[0006] On the other hand, if the Internet of Things terminal is pre-filled with a key, the problem of "who should be shared with the pre-filled key" is faced. For the application scenario of the Internet of Things terminal, which is relatively dispersed in space and mostly keeps data offline, it is difficult to distribute the key. SUMMARY
[0007] The present application proposes a key distribution method and system for an Internet of Things terminal, which can solve the inconvenience and inflexibility of using a symmetric key system to share a session key for the Internet of Things terminal device.
[0008] According to some embodiments, the present application adopts the following technical solutions:
[0009] A key distribution system for an Internet of Things terminal, comprising:
[0010] A quantum password service platform is configured to pre-generate a first quantum key, a second quantum key and a third quantum key, the second quantum key and the third quantum key correspond to a pair, for each key pair, a corresponding identification information is configured to identify it; receiving the identification information sent by the service server, finding the corresponding key pair, encrypting the third quantum key using the corresponding second quantum key to obtain second encrypted information, and feeding back;
[0011] A service server is configured to store the first quantum key, receive the first encrypted information and the identification information, and decrypt to obtain the second quantum key, send the identification information, receive the second encrypted information fed back and decrypt to obtain the third quantum key, and form a key sharing with the corresponding Internet of Things terminal;
[0012] A quantum service card is configured to have a first quantum key in a recognizable manner;
[0013] An input terminal is configured to recognize the first quantum key, the second quantum key and the identification information, encrypt the second quantum key using the first quantum key to obtain the first encrypted information, and send the first encrypted information and the identification information to the service server;
[0014] An Internet of Things terminal is configured to have a second quantum key and identification information in a recognizable manner on the outside, and pre-charge a third quantum key inside, and use the third quantum key to interact with the service server through a communication network.
[0015] As an optional implementation, the quantum service card is provided with recognizable code information on the surface, the code information is the first quantum key, and the code information is provided with a removable cover.
[0016] As an optional implementation, the Internet of Things terminal is provided with recognizable code information on the outer surface or its packaging, the code information is the second quantum key and the identification information, and the code information is provided with a removable cover.
[0017] As an optional implementation, the third quantum key is charged in the production environment inside the Internet of Things terminal, and the third quantum key can only be used inside the Internet of Things terminal and cannot be exported from the Internet of Things terminal.
[0018] As a further limitation, the code information is at least one of a two-dimensional code, a bar code, a digital code, a character code, an optical symbol code and a multi-dimensional code.
[0019] As a further limitation, the cover is a scratchable coating, a tearable film or a removable baffle.
[0020] As an alternative embodiment, the shared key between the service server and the input terminal is a first quantum key.
[0021] As an alternative embodiment, the shared key between the service server and the quantum cryptography service platform is a second quantum key.
[0022] As an alternative embodiment, the shared key between the service server and the Internet of Things terminal is a third quantum key.
[0023] As an alternative embodiment, the quantum cryptography service platform further generates a fourth quantum key, and the fourth quantum key and the second quantum key are stored together with the identification information.
[0024] As a further limitation, the input terminal is configured to identify the first quantum key, the second quantum key, the fourth quantum key and the identification information, encrypt the splicing body formed by the first quantum key and the identification information using the fourth quantum key to obtain third encrypted information, and send the fourth quantum key, the first encrypted information and the identification information to the service server.
[0025] As a further limitation, the third encrypted information is used as a new shared key between the input terminal and the service server.
[0026] As an alternative embodiment, the Internet of Things terminal has multiple terminals, each of which is configured with an independent second quantum key, a third quantum key and identification information.
[0027] As a further limitation, the quantum cryptography service platform is configured to generate multiple sets of second quantum keys and third quantum keys, each set of second quantum keys and third quantum keys corresponding to a pair, and for each key pair, the corresponding identification information is configured to identify it.
[0028] A method based on the above system, comprising the following steps:
[0029] The service server obtains the first quantum key and accesses the quantum cryptography service platform.
[0030] The input terminal obtains the first quantum key, the second quantum key and the identification information, encrypts the second quantum key using the first quantum key to obtain the first encrypted information, and sends the first encrypted information and the identification information to the service server.
[0031] The service server decrypts to obtain the second quantum key, sends the identification information to the quantum cryptography service platform, and applies for the third quantum key.
[0032] The quantum password service platform finds the corresponding key pair according to the identification information, encrypts the third quantum key by using the corresponding second quantum key, obtains second encrypted information, and sends the second encrypted information to the service server;
[0033] The service server receives the feedback second encrypted information, decrypts to obtain the third quantum key, forms a key sharing with the corresponding Internet of Things terminal, and uses the shared third quantum key to perform information security transmission of the communication network.
[0034] As an alternative embodiment, the first quantum key and the second quantum key are discarded after the Internet of Things terminal successfully enters the network.
[0035] As an alternative embodiment, the method further comprises the following steps:
[0036] The quantum password service platform generates the first quantum key, the second quantum key and the third quantum key, the second quantum key and the third quantum key correspond to a pair, and for each key pair, the corresponding identification information is configured to identify it.
[0037] As an alternative embodiment, the method further comprises the following steps:
[0038] The first quantum key is arranged on the quantum service card in a recognizable manner;
[0039] The second quantum key and the identification information are arranged on the surface of the Internet of Things terminal or the packaging thereof in a recognizable manner;
[0040] The third quantum key is filled into the internal storage of the Internet of Things terminal.
[0041] As an alternative embodiment, the method further comprises the following steps:
[0042] The quantum password service platform generates a fourth quantum key;
[0043] The input terminal identifies the first quantum key, the second quantum key, the fourth quantum key and the identification information, encrypts the splicing body formed by the first quantum key and the identification information by using the fourth quantum key, obtains third encrypted information, sends the fourth quantum key, the first encrypted information and the identification information to the service server, and forms sharing.
[0044] Compared with the prior art, the present application has the following advantages:
[0045] The Internet of Things terminal of the present application has been pre-filled with quantum keys, so that during the network entry process of the Internet of Things terminal, it does not need to be powered on and consume power, and the network entry work is replaced to the input terminal, the service server and the quantum password service platform side, which is convenient for deployment and saves battery life.
[0046] The application does not need to assign one-to-one quantum key for service server-Internet of Things terminal in advance, thereby avoiding inconvenience caused by bundling. The key is filled for several Internet of Things terminals, which are put on the market, and the corresponding users can directly buy these Internet of Things terminals, and then simply download software programs to log in the network.
[0047] The shared key relationship between the Internet of Things terminal and the service server of the application is dynamically bound by the user himself / herself when the user purchases and uses it, which facilitates the marketization and modularization of the product. The quantum key as a symmetric key system is safe, and the convenience is comparable to that of the asymmetric key system.
[0048] The user of the application can purchase the quantum service card and the Internet of Things terminal filled with quantum key by himself / herself to realize "password self-making", and no longer need to build expensive quantum private line, thereby greatly reducing the threshold of applying quantum key and improving the convenience.
[0049] In order to make the above-mentioned purposes, features and advantages of the application more obvious and easy to understand, the following preferred embodiments are described in detail below, and the accompanying drawings are described as follows. BRIEF DESCRIPTION OF DRAWINGS
[0050] The drawings accompanying the specification of the application are used to provide further understanding of the application, the schematic embodiments of the application and the description thereof are used to explain the application, and do not constitute improper limitation on the application.
[0051] Figure 1 The schematic diagram of the key distribution system of at least one embodiment of the application is shown in the figure.
[0052] Figure 2 The schematic diagram of the key distribution system of at least one embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0053] The application will be further described below in combination with the drawings and embodiments.
[0054] It should be pointed out that the following detailed description is exemplary and is intended to provide further description of the application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as generally understood by those skilled in the art to which the application belongs.
[0055] It should be noted that the terms used herein are only for the purpose of describing specific embodiments, and are not intended to limit the exemplary embodiments according to the application. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form, and in addition, it should be understood that when the terms "comprise" and / or "include" are used in the specification, they indicate the presence of the features, steps, operations, devices, components and / or their combinations.
[0056] The present application aims to solve the problems in the background art:
[0057] The asymmetric key system distributes session keys, which has security risks;
[0058] The symmetric key system distributes session keys, which has certain difficulties in the special environment of the Internet of Things terminal, such as spatial dispersion, most of the time in data offline state, and uncertain sharing of keys with others.
[0059] The existing technology can solve the problem by establishing a quantum private line, but the cost is high, which is not conducive to the promotion of small and micro users.
[0060] Especially for the problem of spatial dispersion of the Internet of Things terminal, most of the time in data offline state, and uncertain sharing of keys with others, for example, an Internet of Things security chip is not sure whether it will be sold to A manufacturer or B manufacturer to be integrated into a device on the production line, and A manufacturer and B manufacturer have their own business servers. When the Internet of Things security chip is produced, it is difficult to choose to share the key.
[0061] The present application provides a key distribution system for Internet of Things terminals, comprising:
[0062] A quantum cryptography service platform is used to pre-generate a first quantum key, a second quantum key and a third quantum key, the second quantum key and the third quantum key correspond to a pair, and for each key pair, the corresponding identification information is configured to identify it; receive the identification information sent by the business server, find the corresponding key pair, encrypt the third quantum key using the corresponding second quantum key, obtain the second encrypted information, and feedback;
[0063] A business server stores the first quantum key, receives the first encrypted information and the identification information, and decrypts to obtain the second quantum key, sends the identification information, receives the second encrypted information fed back and decrypts to obtain the third quantum key, and forms a key sharing with the corresponding Internet of Things terminal;
[0064] A quantum service card is provided with a first quantum key in a recognizable manner;
[0065] An input terminal is used to identify the first quantum key, the second quantum key and the identification information, encrypt the second quantum key using the first quantum key, obtain the first encrypted information, and send the first encrypted information and the identification information to the business server;
[0066] An Internet of Things terminal is externally provided with a second quantum key and identification information in a recognizable manner, and is internally pre-filled with a third quantum key, and is used to interact information between the business server and the communication network using the third quantum key.
[0067] It should be noted that the quantum service card referred to in the present application can not appear in the form of a card, but can appear in the form of other portable devices.
[0068] For the convenience of understanding, specific embodiments are described.
[0069] Embodiment one:
[0070] As shown in Figure 1 , the system comprises:
[0071] Quantum cryptography service platform Q: generates quantum keys and provides key distribution functions.
[0072] Internet of Things terminal A: has Internet of Things communication functions, can securely store a certain number of quantum keys, and is a terminal with computing functions. Its form can be a device, or a chip, board card, etc. intermediate element.
[0073] Input terminal T: a mobile terminal with computing functions, communication functions, and scanning and reading information functions, supporting the installation and running of APP applications. In actual operation, mobile phones, tablets, smart wearable devices, etc. can be qualified, and are not limited here.
[0074] Business server S: a manufacturer accessing quantum cryptography services, which has its own business server.
[0075] Internet of Things terminal network access: the Internet of Things terminal and the business server S realize shared quantum keys.
[0076] The key distribution process between the above devices includes:
[0077] The quantum cryptography service platform Q generates quantum keys k1, k2, and ks. Wherein k2 and ks are a one-to-one correspondence. For each k2-ks key pair, the quantum cryptography service platform Q identifies it through a keyID.
[0078] In this embodiment, k1 is printed on the card or other portable carrier in the form of a two-dimensional code, a bar code, or other optically recognizable manner, to make a quantum service card. At the same time, k1 is printed on the quantum service card in a readable manner. The two k1 expression forms on the quantum service card are both covered with a one-time, scratchable coating or a peelable sticker, etc.
[0079] In this embodiment, k2 and keyID are printed on the surface of the Internet of Things terminal or the packaging surface thereof in the form of a two-dimensional code, a bar code or other optically recognizable manner, and the two-dimensional code, the bar code or other optically recognizable information is covered with a one-time, scratchable coating or a peelable film.
[0080] Of course, in other embodiments, the coded information in the recognizable manner can also be in other forms provided on the surface of the object, such as provided on a label, which is then pasted on the surface of the corresponding object. These are all conventional techniques in the art, and will not be described here.
[0081] Similarly, in other embodiments, the recognizable information is shielded in other ways, such as by setting a movable shield or by being provided on the inside of the packaging, for temporary security.
[0082] In this embodiment, ks is pre-filled into the internal storage of the Internet of Things terminal A in a production environment. Once the quantum key ks is filled into the Internet of Things terminal, it can only be used inside the Internet of Things terminal, i.e., it cannot be exported from the Internet of Things terminal.
[0083] When the corresponding business vendor wants to access the quantum cryptography service platform Q, the quantum service card is obtained, and the one-time cover is removed. The terminal T downloads and installs the APP provided by the quantum cryptography service platform Q.
[0084] The business vendor inputs the content of k1 on the quantum service card to the business server S; the terminal T can also obtain the quantum key k1 by scanning the two-dimensional code, bar code or other optically recognizable information on the card through the APP. Thus, the business server S and the terminal T share the quantum key k1.
[0085] Before the Internet of Things terminal A is accessed, the cover is removed; the terminal T can obtain the quantum key k2 and its keyID by scanning its two-dimensional code, bar code or other optically recognizable information through the APP.
[0086] The terminal T can use the quantum key k1 to encrypt the quantum key k2 through the APP to obtain k1(k2), and send k1(k2) and keyID to the business server S; after obtaining them, the business server S decrypts k1(k2) using k1 to obtain k2. Thus, the business server S and the quantum cryptography service platform Q share the quantum key k2.
[0087] The service server S sends the keyID to the quantum cryptography service platform Q to apply for a quantum key ks; the quantum cryptography service platform Q finds the k2-ks key pair stored by itself according to the keyID, encrypts the ks using the k2 to obtain k2(ks), and sends the k2(ks) to the service server S, which decrypts the k2(ks) using the k2 to obtain the ks. Thus, the service server S realizes sharing of the quantum key ks with the Internet of Things terminal A. The Internet of Things terminal A is successfully connected to the network, and the k2 is discarded and no longer used.
[0088] The Internet of Things terminal A and the service server S realize secure transmission of information on the public network through the shared quantum key ks.
[0089] Embodiment Two:
[0090] The difference from Embodiment One is that:
[0091] If more than one Internet of Things terminal needs to realize sharing of a quantum key with the service server S, the k1 will face the problem of being used multiple times, thus failing to meet the requirement of "one industry one key". Therefore, in this embodiment, the quantum cryptography service platform Q also generates a quantum key k3, and preprints the k3 together with the k2 and the keyID in a two-dimensional code, a bar code, or other optically recognizable manner on the surface of the Internet of Things terminal or the surface of the packaging thereof, as shown in FIG. 2. Figure 2
[0092] When the input terminal T scans it, the k3 is obtained in addition to the information described in the above embodiments, and the input terminal T sends the k3 to the service server S. The input terminal T and the service server S both encrypt the concatenation of the k1+keyID using the k3 to obtain k3(k1+keyID), so that both parties realize sharing of the key k3(k1+keyID). After the Internet of Things terminal A is successfully connected to the network, the k1 is discarded, and the k3(k1+keyID) replaces the k1 to become a new shared key between the input terminal T and the service server S. That is, the initial k1 is used only once, and after that, each Internet of Things terminal is connected to the network at the same time, and the key update between the input terminal T and the service server S is also realized.
[0093] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program codes.
[0094] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flow or flows and / or block or blocks. Figure 1 one or more flow or flows and / or block or blocks.
[0095] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flow or flows and / or block or blocks. Figure 1 one or more flow or flows and / or block or blocks.
[0096] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flow or flows and / or block or blocks. Figure 1 one or more flow or flows and / or block or blocks.
[0097] The above description is only a specific implementation of the present application, and is not intended to limit the protection scope of the present application. Those skilled in the art should understand that various modifications or changes can be made to the technical solutions of the present application without departing from the spirit and scope of the present application, and these modifications or changes should also be considered as falling within the protection scope of the present application.
Claims
1. A key distribution system for an Internet of Things terminal, characterized by: The application relates to a quantum cryptography service platform, a service server, a quantum service card, an input terminal and an Internet of Things terminal. The quantum cryptography service platform comprises: a quantum cryptography service platform, which is used for pre-generating a first quantum key, a second quantum key and a third quantum key, the second quantum key and the third quantum key corresponding to a pair, for each key pair, corresponding identification information is configured to identify the key pair; receiving identification information sent by a service server, searching for a corresponding key pair, encrypting the third quantum key by using the corresponding second quantum key to obtain second encrypted information, and feeding back the second encrypted information; The service server stores the first quantum key, receives first encrypted information and identification information sent by an input terminal, decrypts to obtain the second quantum key, sends the identification information to the quantum cryptography service platform, receives second encrypted information fed back by the quantum cryptography service platform and decrypts to obtain the third quantum key, and forms a key share with a corresponding Internet of Things terminal; The quantum service card is provided with a first quantum key in a recognizable manner; The input terminal is used for recognizing the first quantum key, the second quantum key and the identification information, encrypting the second quantum key by using the first quantum key to obtain first encrypted information, and sending the first encrypted information and the identification information to the service server; The Internet of Things terminal is externally provided with a second quantum key and identification information in a recognizable manner, and is internally pre-filled with a third quantum key, and is used for interacting with the service server through a communication network by using the third quantum key.
2. The key distribution system of claim 1, wherein the key distribution server is further configured to: The surface of the quantum service card is provided with recognizable code information, the code information is the first quantum key, and the code information is provided with a removable cover. 3. The key distribution system of claim 1, wherein: The surface of the Internet of Things terminal or the packaging thereof is provided with recognizable code information, the code information is the second quantum key and the identification information, and the code information is provided with a removable cover.
4. The key distribution system of claim 3, wherein: The code information is at least one of a two-dimensional code, a bar code, a digital code, a character code, an optical symbol code and a multi-dimensional code.
5. The key distribution system of claim 3, wherein: The cover is a scratchable coating, a tearable film or a removable baffle.
6. The key distribution system of claim 1, wherein: The third quantum key is filled in the Internet of Things terminal in a production environment, and the third quantum key can only be used in the Internet of Things terminal and cannot be exported from the Internet of Things terminal.
7. The key distribution system of claim 1, wherein: The shared key between the service server and the input terminal is the first quantum key.
8. The key distribution system of claim 1, wherein: The shared key between the service server and the quantum cryptography service platform is the second quantum key.
9. The key distribution system of claim 1, wherein: the IoT terminal is a smart meter. The shared key between the service server and the Internet of Things terminal is the third quantum key.
10. A key distribution system for an Internet of Things terminal as claimed in any one of claims 1 to 9, characterized in that: The quantum cryptography service platform further generates a fourth quantum key, and the fourth quantum key and the second quantum key are stored together with the identification information.
11. The key distribution system for an Internet of Things (IoT) terminal as described in claim 10, characterized in that: The input terminal is used for recognizing the first quantum key, the second quantum key, the fourth quantum key and the identification information, encrypting a splicing body formed by the first quantum key and the identification information by using the fourth quantum key to obtain third encrypted information, and sending the fourth quantum key, the first encrypted information and the identification information to the service server.
12. The key distribution system of claim 11, wherein: The third encrypted information is used as a new shared key between the input terminal and the service server.
13. A key distribution system for an Internet of Things terminal as claimed in any one of claims 1 to 9, characterized in that: The Internet of Things terminal has a plurality of Internet of Things terminals, and each Internet of Things terminal is configured with an independent second quantum key, a third quantum key and identification information.
14. The key distribution system for an Internet of Things (IoT) terminal as described in claim 10, characterized in that: The Internet of Things terminal has multiple, each Internet of Things terminal is configured as an independent second quantum key, third quantum key and identification information.
15. The key distribution system for an Internet of Things (IoT) terminal as described in claim 11, characterized in that: The Internet of Things terminal has multiple, each Internet of Things terminal is configured as an independent second quantum key, third quantum key and identification information.
16. The key distribution system of claim 12, wherein: the IoT terminal is a smart meter; and the IoT server is a smart grid server. The Internet of Things terminal has multiple, each Internet of Things terminal is configured as an independent second quantum key, third quantum key and identification information.
17. The key distribution system of claim 13, wherein: the IoT terminal is a smart meter. The quantum cryptography service platform is configured to generate multiple sets of second quantum keys and third quantum keys, each set of second quantum keys and third quantum keys corresponding to a pair, and for each key pair, corresponding identification information is configured to identify it.
18. A method based on the system of any of claims 1-17, characterized by: The method comprises the following steps: The business server obtains the first quantum key and accesses the quantum cryptography service platform; The input terminal obtains the first quantum key, the second quantum key and the identification information, encrypts the second quantum key using the first quantum key to obtain first encrypted information, and sends the first encrypted information and the identification information to the business server; The business server decrypts to obtain the second quantum key, sends the identification information to the quantum cryptography service platform, and applies for the third quantum key; The quantum cryptography service platform finds the corresponding key pair according to the identification information, encrypts the third quantum key using the corresponding second quantum key to obtain second encrypted information and sends it to the business server; The business server receives the feedback second encrypted information and decrypts to obtain the third quantum key, forms a key sharing with the corresponding Internet of Things terminal, and uses the shared third quantum key for information security transmission of the communication network.
19. The method of claim 18 wherein: The first quantum key and the second quantum key are discarded after the Internet of Things terminal successfully enters the network.
20. The method of claim 18 wherein: The method further comprises the following steps: The quantum cryptography service platform generates the first quantum key, the second quantum key and the third quantum key, the second quantum key and the third quantum key corresponding to a pair, and for each key pair, corresponding identification information is configured to identify it.
21. The method of claim 18 wherein: The method further comprises the following steps: The first quantum key is set on the quantum service card in a recognizable manner; The second quantum key and the identification information are set on the surface of the Internet of Things terminal or its packaging in a recognizable manner; The third quantum key is filled into the internal storage of the Internet of Things terminal.
22. The method of claim 19 wherein: The method further comprises the following steps: The first quantum key is set on the quantum service card in a recognizable manner; The second quantum key and the identification information are set on the surface of the Internet of Things terminal or its packaging in a recognizable manner; The third quantum key is filled into the internal storage of the Internet of Things terminal.
23. The method of claim 20 wherein: The method further comprises the following steps: The first quantum key is set on the quantum service card in a recognizable manner; The second quantum key and the identification information are set on the surface of the Internet of Things terminal or its packaging in a recognizable manner; The third quantum key is filled into the internal storage of the Internet of Things terminal.
24. The method of any of claims 18-23, wherein: The method further comprises the following steps: The quantum cryptography service platform generates a fourth quantum key; The input terminal identifies the first quantum key, the second quantum key, the fourth quantum key and the identification information, encrypts the splicing body formed by the first quantum key and the identification information using the fourth quantum key to obtain third encrypted information, sends the fourth quantum key, the first encrypted information and the identification information to the business server, and forms sharing.
Citation Information
Patent Citations
Identity authentication method and system based on wearable equipment
CN110493162A
System for sharing quantum key and secure communication method based on system
CN113132090A