A networking system, method and apparatus based on a quantum secure server
By connecting base station nodes and quantum-safe server nodes into a network system, data encryption and decryption between quantum-safe terminals and application services are achieved, solving the problem of application service access in quantum-safe networks, improving communication security and reliability, and reducing deployment costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MATRICTIME DIGITAL TECH CO LTD
- Filing Date
- 2023-06-01
- Publication Date
- 2026-07-21
Smart Images

Figure CN116527255B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum security technology, and in particular to a networking system, method and apparatus based on a quantum security server. Background Technology
[0002] Quantum communication is a new interdisciplinary field that has developed over the past two decades, combining quantum theory and information theory. Recently, this discipline has gradually moved from theory to experiment and is developing towards practical application. Efficient and secure information transmission is attracting increasing attention. Physically, quantum communication can be understood as high-performance communication achieved using quantum effects. In informatics, we consider quantum communication to utilize fundamental principles of quantum mechanics (such as the no-cloning principle and the measurement collapse property of quantum states) to achieve secure transmission of information between communicating parties (quantum key distribution, QKD) or to utilize quantum entanglement and quantum measurement to achieve reliable transmission of quantum states between two locations (quantum teleportation).
[0003] In practical applications, quantum-safe terminals in a quantum-safe network need to request application services. However, existing internet application server nodes cannot be directly connected to a quantum-safe network. For example, quantum cryptography based on QKD technology is one of the most important practical applications of quantum communication at present; however, QKD networks are hardware infrastructures independent of the internet and cannot be directly integrated with application services provided by the internet.
[0004] Therefore, how to provide application services for quantum-safe terminals and how to deploy these application services in quantum-safe networks are problems that urgently need to be solved. Summary of the Invention
[0005] This application provides a networking system, method, and apparatus based on a quantum-safe server to solve the problem that existing systems cannot provide application services for quantum-safe terminals in quantum-safe networks.
[0006] In a first aspect, this application provides that the system includes: an access base station node, a quantum-safe terminal node accessing the access base station node, and a first quantum-safe server node corresponding to the target application service;
[0007] The first quantum-secure server node is configured to encrypt first application data of the target application service based on the acquired first key to obtain first ciphertext data; send the first ciphertext data and the first key to the quantum-secure terminal node; and receive second ciphertext data and a second key corresponding to the second ciphertext data sent by the quantum-secure terminal node; decrypt the second ciphertext data sent by the quantum-secure terminal node based on the second key, and send the decrypted second application data to the target application service.
[0008] The quantum-secure terminal node is configured to receive the first ciphertext data, and obtain the first key through the access base station node; decrypt the first ciphertext data based on the first key to obtain the first application data; encrypt the second application data based on the obtained second key to obtain the second ciphertext data; send the second ciphertext data to the first quantum-secure server node, and relay the second key to the first quantum-secure server node through the access base station node.
[0009] Secondly, this application also provides a networking method based on a quantum-safe server, the method being applied to a first quantum-safe server node corresponding to a target application service, the method comprising:
[0010] Based on the obtained first key, the first application data of the target application service is encrypted to obtain first ciphertext data; the first ciphertext data and the first key are sent to the quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain the first application data; wherein, the first key is obtained by the quantum secure terminal node through the access base station node it accesses; and
[0011] The system receives second encrypted data and a second key corresponding to the second encrypted data sent by the quantum-safe terminal node; wherein the second key is sent by the quantum-safe terminal node through the access base station node; based on the second key, the system decrypts the second encrypted data sent by the quantum-safe terminal node and sends the decrypted second application data to the target application service.
[0012] Thirdly, this application provides a networking device based on a quantum-safe server, the device being applied to a first quantum-safe server node corresponding to a target application service, the device comprising:
[0013] The transceiver unit is configured to send first ciphertext data and a first key to a quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain first application data of the target application service; wherein the first key is obtained by the quantum secure terminal node through an access base station node; and to receive second ciphertext data and a second key corresponding to the second ciphertext data sent by the quantum secure terminal node; wherein the second key is sent by the quantum secure terminal node through the access base station node.
[0014] The processing unit is configured to encrypt the first application data based on the first key to obtain the first ciphertext data; and to decrypt the second ciphertext data sent by the quantum-safe terminal node based on the second key, and send the decrypted second application data to the target application service.
[0015] Fourthly, this application provides a quantum-safe server, which includes at least a processor and a memory. The processor is used to execute a computer program stored in the memory to implement the steps of the networking method based on the quantum-safe server described above.
[0016] Fifthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the networking method based on a quantum-safe server as described above.
[0017] Sixthly, this application also provides a computer program product, the computer program product comprising: computer program code, which, when run on a computer, causes the computer to perform the steps of the above-described networking method based on a quantum-safe server.
[0018] The beneficial effects of this application are as follows:
[0019] 1. Through this first quantum-safe server node, any target application service can be connected to the quantum-safe network, improving the flexibility of deploying target application services to the quantum-safe network.
[0020] 2. Through this first quantum-safe server node, the first ciphertext data received by the target application service can be decrypted and the second application data sent by the target application service can be encrypted. This enables the application data between the quantum-safe terminal node in the quantum-safe network and the target application service to be transmitted in ciphertext form, thereby improving the security and reliability of the communication between the quantum-safe terminal node and the target application service.
[0021] 3. Through this first quantum-safe server node, the target application service can be deployed to the quantum-safe network without changing the original architecture of the quantum-safe network. It is compatible with the original quantum-safe devices in the quantum-safe network, that is, it is highly compatible with the access base station node in the quantum-safe network and the quantum-safe terminal node connected to the access base station node, thus reducing the cost required to deploy the target application service to the quantum-safe network. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 A schematic diagram of a networking system based on a quantum-safe server provided for an embodiment of this application;
[0024] Figure 2 This is a schematic diagram of the external converged networking structure provided in the embodiments of this application;
[0025] Figure 3 This is a schematic diagram of the external independent network structure provided in the embodiments of this application;
[0026] Figure 4 This is a schematic diagram of the external composite network structure provided in the embodiments of this application;
[0027] Figure 5 This is a schematic diagram of the internal fusion networking structure provided in the embodiments of this application;
[0028] Figure 6 This is a schematic diagram of the internal independent networking structure provided in an embodiment of this application;
[0029] Figure 7 This is a schematic diagram of the internal composite network structure provided in the embodiments of this application;
[0030] Figure 8 This is a schematic diagram of the dual-group gateway network structure provided in the embodiments of this application;
[0031] Figure 9 A schematic diagram of a networking process based on a quantum-safe server is provided for an embodiment of this application;
[0032] Figure 10 A schematic diagram of a networking device based on a quantum-safe server provided for embodiments of this application;
[0033] Figure 11This is a schematic diagram of the structure of a quantum-safe server provided in an embodiment of this application. Detailed Implementation
[0034] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0035] In order to flexibly deploy application services in a quantum-safe network and provide application services for quantum-safe terminals in the quantum-safe network, this application provides a networking system, method and apparatus based on a quantum-safe server.
[0036] Example 1:
[0037] Figure 1 This application provides a schematic diagram of a networking system based on a quantum-safe server. The system includes: an access base station node 12, a quantum-safe terminal node 13 accessing the access base station node, and a first quantum-safe server node 11 corresponding to the target application service.
[0038] The first quantum-secure server node 11 is configured to encrypt the first application data of the target application service based on the acquired first key to obtain first ciphertext data; send the first ciphertext data and the first key to the quantum-secure terminal node 13; and receive the second ciphertext data sent by the quantum-secure terminal node and the second key corresponding to the second ciphertext data; decrypt the second ciphertext data sent by the quantum-secure terminal node 13 based on the second key, and send the decrypted second application data to the target application service.
[0039] The quantum-secure terminal node 13 is configured to receive the first ciphertext data, and obtain the first key through the access base station node 12; decrypt the first ciphertext data based on the first key to obtain the first application data; encrypt the second application data based on the obtained second key to obtain the second ciphertext data; send the second ciphertext data to the first quantum-secure server node 11, and relay the second key to the first quantum-secure server node 11 through the access base station node 12.
[0040] To flexibly deploy application services within a quantum-secure network and ensure the security of application data corresponding to these services, this application requires at least one access base station node 12 (referred to as the second access base station 12), a quantum-secure terminal node 13 connected to the second access base station node 12, and a security server corresponding to the target application service (referred to as the first quantum-secure server node 11). The second access base station node 12 is used to connect at least one quantum-secure terminal node 13, thereby enabling the quantum-secure terminal node 13 to access the quantum-secure network and relaying the keys sent and received by the quantum-secure terminal node 13. After accessing the quantum-secure terminal node 13, it can request the application service (referred to as the target application service) within the quantum-secure network. Each target application service corresponds to a quantum-safe server (referred to as the first quantum-safe server node 11). For any target application service, the target application service can be connected to the quantum-safe network through the security server corresponding to the target application service. That is, the target application service can be flexibly deployed to the quantum-safe network to provide the target application service to each quantum-safe terminal node 13 in the quantum-safe network.
[0041] It should be noted that the quantum security servers corresponding to different target application services can be completely different, partially the same, or completely the same; no specific limitations are made here.
[0042] Considering the potential security risks of the application data being stolen or tampered with during communication between the target application service and the quantum-secure terminal node 13 in the quantum-secure network, this application further addresses this issue. The first quantum-secure server node 11 can also perform quantum encryption and decryption on the application data communicated between the quantum-secure terminal node 13 and the target application service. This allows the application data to be transmitted as ciphertext between the quantum-secure terminal node 13 and the target application service, ensuring the security of communication between them. In other words, the first quantum-secure server node 11 can encrypt the application data (denoted as the first application data) sent by the target application service to the quantum-secure terminal node 13, thereby obtaining the first ciphertext data. It can also decrypt the second ciphertext data sent by the quantum-secure terminal node 13 to the target application service, thereby obtaining the application data (denoted as the second application data) sent by the quantum-secure terminal node 13 to the target application service, and then send the second application data to the target application service.
[0043] For example, after obtaining the first application data, the first quantum-secure server node 11 can obtain the first key. For instance, it can obtain the first key from its key pool. Then, based on the first key, it encrypts the first application data to obtain first ciphertext data. The first quantum-secure server node 11 can then send the first ciphertext data and the second key to the quantum-secure terminal node 13.
[0044] Based on the above embodiment, the quantum-safe terminal node 13 can receive first encrypted data sent by the first quantum-safe server node 11 and obtain the first key through the second access base station node 12. The quantum-safe terminal node 13 then decrypts the first encrypted data using the first key to obtain the first application data sent by the first quantum-safe server node 11.
[0045] In another example, the quantum-safe terminal node 13 can also obtain second application data and a second key. For instance, it can obtain the second key from its key pool. Based on the second key, it encrypts the second application data to obtain second ciphertext data, which is then sent to the first quantum-safe server node 11. Simultaneously, after obtaining the second ciphertext data, the quantum-safe terminal node 13 can also transmit the second key to the first quantum-safe server node 11 via the second access base station node 12.
[0046] After receiving the second ciphertext data and the corresponding second key from the quantum-secure terminal node 13, the first quantum-secure server node 11 can decrypt the second ciphertext data using the second key to obtain the second application data. Then, the first quantum-secure server node 11 can send the second application data to the target application service.
[0047] In one possible implementation, the first quantum-secure server node 11 includes a first intranet region;
[0048] The first intranet area is specifically used to obtain the first key from the key pool of the first quantum security server node 11; and to encrypt the first application data according to the first key to obtain the first ciphertext data.
[0049] The first intranet area is specifically used to decrypt the second ciphertext data based on the received second key, and send the decrypted second application data to the target application service.
[0050] Considering that the security of the key used by the first quantum-secure server node 11 for quantum encryption and decryption of application data directly affects the security of the application data, this application includes, in this application, an internal network area (denoted as the first internal network area) that does not directly communicate with the external network. This first internal network area stores quantum-secure data, such as keys, and quantum encryption and decryption of application data can be achieved through this area. For example, the first internal network area can obtain the first application data of the target application service. Then, it obtains a first key from the key pool of the first quantum-secure server node 11 and encrypts the first application data using the first key to obtain the first ciphertext data. In another example, the first internal network area obtains the second ciphertext data sent by the quantum-secure terminal node 13 and the second key corresponding to the second ciphertext data. It can then decrypt the second ciphertext data using the second key to obtain the second application data. The first internal network area can then transmit the second application data to the target application service.
[0051] It should be noted that the first quantum-safe server node 11 may include at least one quantum-safe server. If the first quantum-safe server node 11 includes only one quantum-safe server, then the first internal network area is a part of the modules in the quantum-safe server, such as the processor in the quantum-safe server. If the first quantum-safe server node 11 includes multiple quantum-safe servers, then the first internal network area may be at least one of the multiple quantum-safe servers. For example, the first internal network area may be one of the multiple quantum-safe servers, the first internal network area may be a part of the multiple quantum-safe servers, or the first internal network area may be all of the multiple quantum-safe servers.
[0052] In one possible implementation, the target application service can be deployed on the first quantum-secure server node 11. If the target application service is deployed on the first quantum-secure server node 11, the first quantum-secure server node 11 can directly transmit the second application data to the target application service using an internal machine switching method. For example, if the first quantum-secure server node 11 includes a first intranet area, the first intranet area can obtain the first application data initiated by the target application service installed in the first intranet area through an internal machine switching method. After obtaining the second application data, the first intranet area can also transmit the second application data to the target application service through an internal machine switching method.
[0053] In another possible implementation, if the target application service is deployed on an application server node, and the application server node and the first quantum-safe server node 11 are different nodes deployed in the same local area network, the system also includes the application server node.
[0054] The first intranet area is specifically used to receive the first application data sent by the application server node through the local area network; and to send the second application data to the application server node through the local area network, so that the application server node can respond to the second application data and provide the target application service to the quantum-safe terminal node 13.
[0055] The target application service can also be deployed on other nodes different from the first quantum-safe server node 11. For example, the target application service can be deployed on an application server node. If the target application service is deployed on other nodes, the first quantum-safe server node 11 needs to use an outgoing network exchange method to transmit application data of the target application service with the other nodes. Based on this, in this application, the first quantum-safe server node 11 and the other nodes are deployed in the same local area network. For example, the first quantum-safe server node 11 and the application server node where the target application service is deployed are located in the same local area network.
[0056] For example, if the target application service is deployed on an application server node, the first quantum-safe server node 11 can transmit application data to the application server node via a local area network (LAN). If the first quantum-safe server node 11 includes a first intranet area, the first intranet area can receive the first application data of the target application service sent by the application server node via the LAN. The first intranet area can also, after obtaining the second application data, send the second application data to the application server node via the LAN, so that the application server node can respond to the second application data and thus provide the target application service to the quantum-safe terminal node 13.
[0057] Based on the above embodiments, the quantum-safe terminal node 13 can receive the first ciphertext data.
[0058] In one possible implementation, the second access base station node 12 includes a second internal network area and a second external network area;
[0059] The second internal network area is used to receive key information of the second key sent by the quantum-safe terminal node 13 through the second external network area; obtain the second key from the key pool paired with the quantum-safe terminal node 13 according to the key information of the second key; relay the second key to the first quantum-safe server node 11; and obtain the first key; obtain the third key from the key pool paired with the quantum-safe terminal node 13; encrypt the first key according to the third key to obtain the encrypted first key; and send the key information of the third key and the encrypted first key to the quantum-safe terminal node 13 through the second external network area.
[0060] The quantum-safe terminal node 13 is specifically configured to receive the key information of the third key and the encrypted first key sent by the second access base station node 12; obtain the third key from the key pool paired with the second access base station node 12 based on the key information of the third key; decrypt the encrypted first key according to the third key to obtain the first key; and send the key information of the second key to the second external network area of the second access base station node 12.
[0061] Considering the security of the key during transmission between the access base station node (referred to as the second access base station node 12) and the quantum secure terminal node 13, which directly affects the security of the encrypted data sent and received by the quantum secure terminal node 13, this application includes, in this case, an internal network area (referred to as the second internal network area) that does not directly communicate with the external network and an external network area that directly communicates with the external network (referred to as the second external network area). The second internal network area stores quantum secure data, enabling quantum encryption and decryption of the data, and the second external network area enables communication between the second access base station node 12 and the external network.
[0062] For example, the process by which the quantum-safe terminal node 13 obtains the first key through the second access base station node 12 includes:
[0063] Step 1: The second intranet area of the second access base station node 12 can obtain the first key.
[0064] In one possible implementation, if the second access base station node 12 and the first quantum security server node 11 are deployed in different local area networks, the second internal network area can obtain the first key through the second external network area. That is, the second external network area obtains the first key sent by the first quantum security server node 11 from the quantum security network and transmits the first key to the second internal network area.
[0065] In another possible implementation, if the second access base station node 12 and the first quantum security server node 11 are deployed on the same local area network, the second intranet area can also directly obtain the first key sent by the first intranet area of the first quantum security server node 11 through the local area network.
[0066] Step 2: The second intranet region obtains a third key from the key pool paired with the quantum-safe terminal node 13, and encrypts the first key according to the third key to obtain the encrypted first key, thereby ensuring the security of transmitting the first key to the quantum-safe terminal node 13.
[0067] Step 3: The second intranet area can transmit the key information of the third key and the encrypted first key to the second extranet area.
[0068] For example, the second intranet area encapsulates the key information of the third key and the encrypted first key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second extranet area. After obtaining the internal transmission data, the second extranet area can obtain the key information of the third key and the encrypted first key from the internal transmission data according to the preset customized transmission protocol.
[0069] Step 4: The second external network area sends the key information of the third key and the encrypted first key to the quantum secure terminal node 13.
[0070] For example, the second external network region relays the key information of the third key and the encrypted first key to the quantum-safe terminal node 13 via a link with the quantum-safe terminal node 13. Specifically, if a link has already been established between the second external network region and the quantum-safe terminal node 13, the established link is reused to relay the key information of the third key and the encrypted first key to the quantum-safe terminal node 13. If a link has not been established between the second external network region and the quantum-safe terminal node 13, a new link is established, and the key information of the third key and the encrypted first key are then relayed to the quantum-safe terminal node 13 via this new link.
[0071] Based on steps 1-4 above, the quantum-safe terminal node 13 can obtain the key information of the third key sent by the second access base station node 12 and the encrypted first key. Then, based on the key information of the third key, the quantum-safe terminal node 13 can obtain the third key from its key pool. Using the third key, the quantum-safe terminal node 13 decrypts the encrypted first key to obtain the first key, and then uses the first key to decrypt the first ciphertext data to obtain the first application data.
[0072] To ensure the security of the second key during transmission from the quantum-secure terminal node 13 to the first quantum-secure server node 11, in this application, the quantum-secure terminal node 13 sends the key information of the second key to the second access base station node 12. After obtaining the key information, the second access base station node 12 retrieves the second key from the key pool paired with the quantum-secure terminal node 13. Then, the second access base station node 12 relays the second key to the first quantum-secure server node 11.
[0073] In one possible implementation, when the quantum-safe terminal node 13 sends the key information of the second key to the second access base station node 12, it can send the key information of the second key and the network access identifier of the first quantum-safe server node 11 to the second access base station node 12 together, so that the second access base station node 12 can accurately relay the second key to the first quantum-safe server node 11 based on the network access identifier.
[0074] For example, the process by which the quantum-safe terminal node 13 sends the second key to the first quantum-safe server node 11 through the second access base station node 12 includes:
[0075] Step 1: After obtaining the second ciphertext data, the quantum-safe terminal node 13 sends the key information of the second key to the second external network area of the second access base station node 12.
[0076] For example, the quantum-safe terminal node 13 sends the key information of the second key to the second external network area based on the link between the quantum-safe terminal node 13 and the second external network area of the second access base station node 12. Specifically, if the quantum-safe terminal node 13 has already established a link with the second external network area of the second access base station node 12, then the established link is reused to send the key information of the second key to the second external network area. If the quantum-safe terminal node 13 has not established a link with the second external network area of the second access base station node 12, then a new link is established between the quantum-safe terminal node 13 and the second external network area of the second access base station node 12, and then the key information of the second key is sent to the second external network area using this new link.
[0077] Step II: After receiving the key information of the second key in the second external network area of the second access base station node 12, the second access base station node 12 transmits the key information of the second key to the second internal network area of the second access base station node 12.
[0078] For example, the second external network area encapsulates the key information of the second key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second internal network area. After obtaining the internal transmission data, the second internal network area can obtain the key information of the second key from the internal transmission data according to the preset customized transmission protocol.
[0079] Step III: After obtaining the key information of the second key in the second intranet area, the second key is obtained from the key pool paired with the quantum-safe terminal node 13 based on the key information.
[0080] Step IV: The second intranet area relays the second key to the first quantum-secure server node 11.
[0081] In one possible implementation, if the second access base station node 12 and the first quantum secure server node 11 are deployed in different local area networks, the second intranet area can relay the second key to the first quantum secure server node 11 through the second extranet area. That is, the second intranet area transmits the second key to the second extranet area, and the second extranet area sends the second key to the first quantum secure server node 11.
[0082] In another possible implementation, if the second access base station node 12 and the first quantum secure server node 11 are deployed on the same local area network, the second intranet area can also directly relay the second key to the first intranet area of the first quantum secure server node 11 through the local area network.
[0083] It should be noted that the second access base station node 12 may include at least one quantum secure device. If the second access base station node 12 includes only one quantum secure device, then the second internal network area of the second access base station node 12 is a module within the quantum secure device, such as a processor. If the second access base station node 12 includes multiple quantum secure devices, then the second internal network area of the second access base station node 12 may be at least one of the multiple quantum secure devices. For example, the second internal network area of the second access base station node 12 may be one of the multiple quantum secure devices, or it may be an implementation of some of the multiple quantum secure devices. The second external network area of the second access base station node 12 and the second internal network area are two completely different areas within the second access base station node 12.
[0084] The beneficial effects of this application are as follows:
[0085] 1. Through the first quantum-safe server node 11, any target application service can be connected to the quantum-safe network, which improves the flexibility of deploying target application services to the quantum-safe network.
[0086] 2. Through the first quantum-safe server node 11, the first ciphertext data received by the target application service can be decrypted and the second application data sent by the target application service can be encrypted, so that the application data between the quantum-safe terminal node 13 in the quantum-safe network and the target application service is transmitted in ciphertext form, thereby improving the security and reliability of the communication between the quantum-safe terminal node 13 and the target application service.
[0087] 3. Through the first quantum-safe server node 11, the target application service can be deployed to the quantum-safe network without changing the original architecture of the quantum-safe network. It is compatible with the original quantum-safe devices in the quantum-safe network, that is, it is highly compatible with the access base station node in the quantum-safe network and the quantum-safe terminal node 13 connected to the access base station node, which reduces the cost required to deploy the target application service to the quantum-safe network.
[0088] Example 2:
[0089] To ensure that the first quantum-secure server node 11 accurately sends and receives ciphertext data (including first ciphertext data and second ciphertext data) and the corresponding key, based on the above embodiments, in this application, the first quantum-secure server node 11 sends and receives ciphertext data and the corresponding key in the following two ways:
[0090] Scenario 1: The first quantum-safe server node 11 and the second access base station node 12 are deployed in different local area networks.
[0091] In one possible implementation, when the first quantum secure server node 11 and the second access base station node 12 are deployed in different local area networks, the first quantum secure server node 11 further includes a first external network area;
[0092] The first external network area is specifically used to receive the key information of the first key and the first ciphertext data transmitted from the first internal network area; relay the key information of the first key to the second access base station node 12 to which the first quantum secure server node 11 is connected, so that the second access base station node 12 can obtain the first key based on the key information of the first key, and relay the first key to the quantum secure terminal node 13 through the quantum secure network; and send the first ciphertext data to the quantum secure terminal node 13 through a traditional network.
[0093] The first external network area is specifically used to receive the second encrypted data through the traditional network; transmit the second encrypted data to the first internal network area; and receive the second key through the second access base station node 12 connected by the first quantum security server node 11, and transmit the second key to the first internal network area.
[0094] The second external network area is also used to receive the first key sent by the first quantum secure server node 11; transmit the first key to the second internal network area; and obtain the second key sent by the second internal network area; and relay the second key to the first quantum secure server node 11 through the second access base station node 12 accessed by the first quantum secure server node 11.
[0095] When the first quantum secure server node 11 and the second access base station node 12 are deployed in different local area networks, the first quantum secure server node 11 needs to have the ability to send and receive encrypted data and the corresponding key via the Internet. Based on this, the first quantum secure server node 11 may also include an external network area (denoted as the first external network area) to enable the first quantum secure server node 11 to communicate via the external network.
[0096] For example, the first quantum-secure server node 11 sends and receives encrypted data through the first external network area:
[0097] M1, the first internal network area sends the first encrypted data through the first external network area.
[0098] After obtaining the first encrypted data, the first internal network area of the first quantum-secure server node 11 can transmit the first encrypted data to the first external network area of the first quantum-secure server node 11. For example, the first internal network area encapsulates the first encrypted data according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the first quantum-secure server node 11. The isolation area verifies the data format of the internal transmission data. After confirming that the internal transmission data has passed the verification, the isolation area transmits the internal transmission data to the first external network area. After obtaining the internal transmission data, the first external network area can extract the first encrypted data from the internal transmission data according to the preset customized transmission protocol. After obtaining the first encrypted data, the first external network area can send the first encrypted data to the quantum-secure terminal node 13 through a traditional network.
[0099] M2, the first internal network area obtains the second encrypted data through the first external network area.
[0100] The first external network area of the first quantum-safe server node 11 can obtain the second encrypted data sent by the quantum-safe terminal node 13 through a conventional network. After obtaining the second encrypted data, the first external network area can transmit the second encrypted data to the first internal network area of the first quantum-safe server node 11. For example, the first external network area encapsulates the second encrypted data according to a preset customized transmission protocol, obtains the internal transmission data, and sends the internal transmission data to the isolation area of the first quantum-safe server node 11. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the first internal network area. After obtaining the internal transmission data, the first internal network area can retrieve the second encrypted data from the internal transmission data according to the preset customized transmission protocol.
[0101] Another example is the key corresponding to the first quantum-secure server node 11 sending and receiving encrypted data through the first external network area:
[0102] N1. The first internal network area sends the first key through the first external network area.
[0103] After obtaining the first ciphertext data, the first intranet area of the first quantum secure server node 11 can transmit the first key to the first external network area of the first quantum secure server node 11. After obtaining the key information of the first key, the first external network area sends the first key to the quantum secure terminal node 13 through the quantum secure network.
[0104] To ensure the security of the first key during transmission from the first quantum-secure server node 11 to the quantum-secure terminal node 13, in this application, the first quantum-secure server node 11 can send the key information of the first key to an access base station node (denoted as the first access base station node) to which it is connected. After obtaining the key information, the first access base station node retrieves the first key from the key pool paired with the first quantum-secure server node 11. Then, the first access base station node relays the first key to the quantum-secure terminal node 13.
[0105] For example, after the first quantum secure server node 11 obtains the first ciphertext data in its first internal network area, it can transmit the key information of the first key to its first external network area. After obtaining the key information of the first key, the first external network area can transmit it to the first access base station node. After obtaining the key information of the first key, the first access base station node can retrieve the first key from the key pool paired with the first quantum secure server node 11 based on the key information. Then, the first access base station node relays the first key to the second access base station node 12, so that the first key can be transmitted to the quantum secure terminal through the second access base station node 12.
[0106] In one possible implementation, when the first quantum-safe server node 11 sends the key information of the first key to the first access base station node, it can also send the key information of the first key and the network access identifier of the quantum-safe terminal node 13 to the first access base station node together, so as to accurately relay the first key to the quantum-safe terminal node 13 based on the network access identifier.
[0107] In this scenario, if the second access base station node 12 includes a second internal network area and a second external network area, then the second external network area can receive the first key sent by the first quantum security server node 11. For example, the second external network area can receive the first key sent by the first quantum security server node 11 through the first access base station node. After obtaining the first key, the second external network area can transmit the first key to the second internal network area. For example, the second external network area encapsulates the first key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed verification, it transmits the internal transmission data to the second internal network area. After obtaining the internal transmission data, the second internal network area can obtain the first key from the internal transmission data according to the preset customized transmission protocol. After obtaining the first key, the second internal network area can retrieve a third key from the key pool paired with the quantum-safe terminal node 13. Using the third key, it encrypts the first key to obtain the encrypted first key, thus ensuring the security of transmitting the first key to the quantum-safe terminal node 13. The second internal network area can then transmit the key information of the third key and the encrypted first key to the second external network area. The second external network area relays the key information of the third key and the encrypted first key to the quantum-safe terminal node 13 through the quantum-safe network.
[0108] N2. The first internal network area obtains the second key through the first external network area.
[0109] After obtaining the second ciphertext data, the quantum-safe terminal node 13 sends the second key to the first quantum-safe server through the second access base station node 12.
[0110] For example, if the second access base station node 12 includes a second intranet area and a second extranet area, the second extranet area can also obtain the second key transmitted by the second intranet area. For instance, the second intranet area encapsulates the second key according to a preset customized transmission protocol, obtains internal transmission data, and sends this internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed verification, it transmits the internal transmission data to the second extranet area. After obtaining the internal transmission data, the second extranet area can obtain the second key from the internal transmission data according to the preset customized transmission protocol. After obtaining the second key, the second extranet area can relay the second key to the first quantum security server node 11.
[0111] The first quantum-secure server node 11 can receive the second key through a first external network area. After obtaining the second key, the first external network area can transmit it to the first internal network area of the first quantum-secure server node 11. For example, the first external network area encapsulates the second key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the first quantum-secure server node 11. The isolation area verifies the data format of the internal transmission data. After confirming that the internal transmission data has passed verification, the isolation area transmits the internal transmission data to the first internal network area. After obtaining the internal transmission data, the first internal network area can retrieve the second key from the internal transmission data according to the preset customized transmission protocol.
[0112] Scenario 2: The first quantum security server node 11 and the second access base station node 12 are deployed on the same local area network.
[0113] In one possible implementation, when the first quantum-secure server node 11 and the second access base station node 12 are deployed in the same local area network, the first internal network area is further used to transmit the first ciphertext data to the second external network area, and to receive the second ciphertext data sent by the second external network area; and to send the first key to the second internal network area through the local area network; and to obtain the second key from the second internal network area through the local area network.
[0114] The second intranet area is specifically used to obtain the first key from the first intranet area through the local area network; and to transmit the second key to the first intranet area through the local area network.
[0115] The second external network area is also used to receive the first encrypted data transmitted from the first internal network area; send the first encrypted data to the quantum-secure terminal through a conventional network; and receive the second encrypted data sent by the quantum-secure terminal through the conventional network; and transmit the second encrypted data to the first internal network area.
[0116] In some potential application scenarios, the first security server and the second access base station may be deployed on the same quantum-secure local area network (LAN). In this case, considering that the first security server and the second access base station only need this LAN to transmit keys, in this application, the first security server can share the same external network area with the second access base station. That is, the first security server only includes the first internal network area. If the first security server needs to relay keys, it can directly relay keys with the second internal network area of the second access base station through the LAN; if the first security server needs to send and receive encrypted data with the external network, it can also directly send and receive encrypted data through the second external network area of the second access base station.
[0117] For example, the key corresponding to the transmission and reception of encrypted data for the first quantum-secure server node 11:
[0118] Y1. The first intranet area obtains the second key through the second intranet area.
[0119] The second access base station node 12 obtains the second key through the second external network area in its second internal network area, and then transmits the second key to the first internal network area of the first quantum security server node 11 through the local area network.
[0120] It should be noted that the process of the second internal network area obtaining the second key through the second external network area can refer to the above embodiment, and the repeated parts will not be described again.
[0121] Y2. The first intranet area sends the first key through the second intranet area.
[0122] After obtaining the first ciphertext data, the first quantum security server node 11 can send the first key to the second intranet area of the second access base station node 12 via the local area network.
[0123] After receiving the first key in the second internal network area of the second access base station node 12, the first key can be sent to the quantum-safe terminal node 13 through the second external network area.
[0124] It should be noted that the process of the second intranet area processing the first key after receiving it can refer to the above embodiment, and the repeated parts will not be described again.
[0125] In another example, the first quantum-secure server node 11 performs the sending and receiving of encrypted data:
[0126] Z1, the first quantum-secure server node 11 sends the first encrypted data.
[0127] After obtaining the first encrypted data, the first quantum-secure server node 11 can transmit the first encrypted data to the second external network area of the second access base station node 12. After obtaining the first encrypted data, the second external network area sends the first encrypted data to the quantum-secure terminal node 13 through a traditional network.
[0128] Z2, the first quantum-secure server node 11 receives the second encrypted data.
[0129] After obtaining the second encrypted data, the quantum-safe terminal node 13 can send the second encrypted data to the second external network area of the second access base station node 12 via a traditional network. After receiving the second encrypted data, the second external network area can transmit the second encrypted data to the first internal network area of the first quantum-safe server node 11.
[0130] Example 3:
[0131] To enhance the diversity of the quantum-safe terminal node 13, based on the above embodiments, the implementation forms of the quantum-safe terminal node 13 in this application include the following:
[0132] Form 1: This quantum-safe terminal node 13 only includes quantum-safe terminals.
[0133] The quantum-safe terminal node 13 can be a single quantum-safe terminal or multiple quantum-safe terminals. The quantum-safe terminal node 13 can include an internal network area that does not communicate with the external network and an external network area that directly communicates with the external network. The internal network area stores quantum-safe data, enabling quantum encryption and decryption of the data. The external network area enables communication between the quantum-safe terminal node 13 and the Internet and quantum-safe networks. When the quantum-safe terminal node 13 is a single quantum-safe terminal, the internal network area comprises some modules within the quantum-safe terminal, such as the processor, while the external network area comprises modules different from the internal network area. When the quantum-safe terminal node 13 comprises multiple quantum-safe terminals, the internal network area can be one or more of the multiple quantum-safe terminals, while the external network area of the quantum-safe terminal node 13 comprises areas different from the internal network area among the multiple quantum-safe terminals.
[0134] For example, the intranet area of the quantum-safe terminal node 13 is used to acquire second application data, and then obtain a second key from the key pool of the quantum-safe terminal node 13. Based on the second key, the second application data is encrypted to obtain second ciphertext data. The second intranet area transmits the second ciphertext data and the key information of the second key to the extranet area of the quantum-safe terminal node 13. After obtaining the second ciphertext data and the key information of the second key, the extranet area can, based on the above embodiment, send the second ciphertext data to the first quantum-safe server node 11, and, based on the above embodiment, send the key information of the second key to the first quantum-safe server node 11 through the second access base station node 12.
[0135] In another example, after the external network area of the quantum-safe terminal node 13 obtains the first encrypted data through a traditional network, it can transmit the first encrypted data to the internal network area of the quantum-safe terminal node 13. After obtaining the first encrypted data, the internal network area obtains the first key corresponding to the first encrypted data, and decrypts the first encrypted data using the first key to obtain the first application data. The first key is obtained by the internal network area through the external network area of the quantum-safe terminal node 13.
[0136] It should be noted that the process of transmitting ciphertext data and the corresponding key between the external network area of the quantum secure terminal node 13 and the internal network area of the quantum secure terminal node 13 is similar to the process of transmitting ciphertext data and the corresponding key between the first external network area and the first internal network area, and will not be described in detail here.
[0137] Form 2: The quantum-safe terminal node 13 includes a quantum-safe server node (denoted as the second quantum-safe server node) and a general-purpose terminal node. The general-purpose terminal node includes at least one general-purpose terminal that does not have quantum communication capabilities.
[0138] In one possible implementation, the quantum-safe terminal node 13 includes a second quantum-safe server node and a general-purpose terminal node; wherein the general-purpose terminal node and the second quantum-safe server node are different nodes within the same local area network;
[0139] The second quantum-secure server node is specifically configured to receive the first ciphertext data, and obtain the first key through the access base station node; decrypt the first ciphertext data based on the first key to obtain first application data; send the first application data to the general terminal node; receive the second application data initiated by the general terminal node; encrypt the second application data based on the second key to obtain second ciphertext data; send the second ciphertext data to the first quantum-secure server node 11; and send the second key to the first quantum-secure server node 11 through the access base station node.
[0140] Considering that some general-purpose terminal nodes without quantum-safe communication capabilities can also access the quantum-safe network and request target application services within it, this application allows general-purpose terminal nodes to access the quantum-safe network via a quantum-safe server node (denoted as the second quantum-safe server node). That is, the quantum-safe terminal node 13 may include both the second quantum-safe server node and the general-purpose terminal node. The second quantum-safe server node communicates with the second access base station node 12, and the general-purpose terminal node communicates with the second quantum-safe server node. The general-purpose terminal node is used to request target application services, and the second quantum-safe server node is used to provide quantum-safe communication for the general-purpose terminal node.
[0141] It should be noted that, since the general terminal node and the second quantum secure server node need to transmit application data, in order to ensure the security of the transmitted application data, the second quantum secure server node is deployed within the local area network where the general terminal node is located.
[0142] For example, after the general terminal node initiates the second application data, it can send the second application data to the second quantum secure server node via the local area network. After receiving the second application data, the second quantum secure server node can obtain the second key from its key pool, encrypt the second application data according to the second key, obtain the second ciphertext data, and then send the second ciphertext data to the first quantum secure server node 11, and send the key information of the second key to the second access base station node 12.
[0143] In another example, after the first quantum-secure server node 11 obtains the first encrypted data, it sends the first encrypted data to the second quantum-secure server node. After the second access base station node 12 obtains the first key, it transmits the first key to the second quantum-secure server node. After obtaining the first key and the first encrypted data, the second quantum-secure server node decrypts the first encrypted data according to the first key to obtain the first application data, and then sends the first application data to the general terminal node through the local area network.
[0144] For example, after obtaining the first key, the second access base station node 12 retrieves a third key from the key pool paired with the second quantum secure server node. Based on the third key, it encrypts the first key to obtain the encrypted first key. The second access base station node 12 then sends the key information of the first and third keys to the second quantum secure server node. Upon receiving the key information of the first and third keys, the second quantum secure server node retrieves the third key from the key pool paired with the second access base station node 12. Based on the third key, it decrypts the encrypted first key to obtain the first key.
[0145] In one possible implementation, the second quantum-safe server node includes a third internal network area and a third external network area;
[0146] The third external network area is specifically used to receive the first ciphertext data, transmit the first ciphertext data to the third internal network area; and receive the key information of the third key and the encrypted first key sent by the access base station; transmit the key information of the third key and the encrypted first key to the third internal network area; and receive the key information of the second key transmitted by the third internal network area; send the key information of the second key to the access base station node, so that the access base station node can obtain the second key based on the key information of the second key, and relay the second key to the first quantum secure server node 11 through the quantum secure network; and send the second ciphertext data to the first quantum secure server node 11.
[0147] The third intranet area is specifically used to obtain the key information of the third key, the encrypted first key, and the first ciphertext data through the third extranet area; based on the key information of the third key, obtain the third key from the key pool of the second quantum-safe server node; decrypt the encrypted first key according to the third key to obtain the first key; decrypt the first ciphertext data according to the first key to obtain the first application data; send the first application data to the general terminal node through the local area network; and receive the second application data initiated by the general terminal node through the local area network; obtain the second key from the key pool of the second quantum-safe server node; encrypt the second application data according to the second key to obtain the second ciphertext data; and transmit the second ciphertext data and the key information of the second key to the third extranet area respectively.
[0148] Since the security of the key used by the second quantum-secure server node for quantum encryption and decryption of application data is directly related to the security of the application data, this application includes, in this second quantum-secure server node, an internal network area (denoted as the third internal network area) that does not directly communicate with the external network and an external network area that directly communicates with the external network (denoted as the third external network area). The third internal network area stores quantum-secure data, such as keys. Quantum encryption and decryption of application data can be achieved through the third internal network area, and communication between the second quantum-secure server node and the external network can be achieved through the third external network area.
[0149] For example, after receiving the first ciphertext data sent by the first quantum secure server node 11, the third external network area of the second quantum secure server node can transmit the first ciphertext data to the third internal network area of the second quantum secure server node. After obtaining the first ciphertext data, the third internal network area obtains the first key, decrypts the first ciphertext data according to the first key, obtains the first application data, and then transmits the first application data to the general terminal node through the local area network.
[0150] In another example, the third intranet area of the second quantum-secure server node receives the second application data sent by the general-purpose terminal node via a local area network, then obtains the second key from the key pool of the second quantum-secure server node, encrypts the second application data using the second key, and obtains the second ciphertext data. The third intranet area transmits the key information of the second key and the second ciphertext data to the third extranet area. The third extranet area sends the key information of the second key to the second access base station node 12, and sends the second ciphertext data to the first quantum-secure server node 11.
[0151] The second quantum-safe server node may include at least one quantum-safe server. If the second quantum-safe server node includes only one quantum-safe server, then the third internal network area is a portion of the modules in the quantum-safe server, such as the processor in the quantum-safe server, and the third external network area is a module in the quantum-safe server that is different from the internal network area. If the second quantum-safe server node includes multiple quantum-safe servers, then the third internal network area may be one of the multiple quantum-safe servers or the third internal network area may be a portion of the multiple quantum-safe servers, and the third external network area is a region in the multiple quantum-safe servers that is different from the third internal network area.
[0152] It should be noted that the process of how the third external network area transmits encrypted data and the corresponding key to the third internal network area is similar to the process of transmitting encrypted data and the corresponding key between the first external network area and the first internal network area, and will not be described in detail here.
[0153] Example 4:
[0154] The following specific embodiments illustrate the networking system based on a quantum-safe server provided in this application. This networking system based on a quantum-safe server can include the following seven networking methods:
[0155] Method 1: External converged networking.
[0156] External connection refers to the first quantum secure server node 11 being connected to the second access base station node 12 via an external connection, meaning that the first quantum secure server node 11 and the second access base station node 12 are connected to different local area networks. Convergence refers to the target application service being deployed on the first quantum secure server node 11, and the communication between the target application service and the first quantum secure server node 11 using an internal machine exchange method.
[0157] Figure 2 This is a schematic diagram of the external converged networking structure provided in the embodiments of this application. If the first quantum security server node 11 includes a first internal network area and a first external network area, and the second access base station node 12 includes a second internal network area and a second external network area, then the system workflow of this method 1 includes:
[0158] A. The target application service sends the first application data to the quantum security terminal node 13.
[0159] The first intranet area can acquire the first application data of the target application service through internal machine switching. Then, the first intranet area obtains a first key from the key pool and encrypts the first application data using the first key to obtain the first ciphertext data. After obtaining the first ciphertext data, the first intranet area can transmit the first ciphertext data and the first key to the first external network area respectively. After obtaining the first ciphertext data and the first key, the first external network area can send the first ciphertext data to the quantum-secure terminal node 13 via a traditional network, and transmit the first key to the second external network area of the second access base station node 12 via the quantum-secure network.
[0160] For example, after obtaining the key information of the first key, the first external network area transmits the key information of the first key to the external network area of the first access base station node. The external network area of the first access base station node then transmits the key information of the first key to its internal network area. After obtaining the key information of the first key, the internal network area of the first access base station node retrieves the first key from the key pool paired with the first quantum secure server node 11 and transmits the first key to the external network area of the first access base station node. After obtaining the first key, the external network area of the first access base station node relays the first key to the second external network area of the second access base station node 12. After obtaining the first key, the second external network area can transmit the first key to the second internal network area. After obtaining the first key, the second internal network area retrieves the third key from the key pool paired with the quantum secure terminal node 13, encrypts the first key using the third key, and obtains the encrypted first key, thereby ensuring the security of transmitting the first key to the quantum secure terminal node 13. Then, the second internal network area can transmit the key information of the third key and the encrypted first key to the second external network area. For example, the second internal network area encapsulates the key information of the third key and the encrypted first key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second external network area. After obtaining the internal transmission data, the second external network area can obtain the key information of the third key and the encrypted first key from the internal transmission data according to the preset customized transmission protocol. The second external network area then sends the key information of the third key and the encrypted first key to the quantum secure terminal node 13. For example, the second external network area relays the key information of the third key and the encrypted first key to the quantum secure terminal node 13 through a link with the quantum secure terminal node 13. After obtaining the key information of the third key and the encrypted first key, the quantum-safe terminal node 13 can retrieve the third key from the key pool paired with the second access base station node 12 based on the key information of the third key. The quantum-safe terminal node 13 then decrypts the encrypted first key using the third key to obtain the first key, and subsequently decrypts the first ciphertext data using the first key to obtain the first application data.
[0161] B. Quantum-safe terminal node 13 sends second application data to the target application service.
[0162] The quantum-safe terminal node 13 can obtain the second application data, then retrieve the second key from its key pool, and encrypt the second application data using the second key to obtain the second ciphertext data. This second ciphertext data is then sent to the first external network area of the first quantum-safe server node 11 via a conventional network. Simultaneously, after obtaining the second ciphertext data, the quantum-safe terminal node 13 sends the key information of the second key to the second external network area of the second access base station node 12. The second access base station node 12 can receive the key information of the second key sent by the quantum-safe terminal node 13 through its second external network area. The second external network area then transmits the received key information of the second key to the second internal network area of the second access base station node 12. For example, the second external network area encapsulates the key information of the second key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second internal network area. After obtaining the internal transmission data, the second internal network area can obtain the key information of the second key from the internal transmission data according to the preset customized transmission protocol. Based on the key information, the second internal network area obtains the second key from the key pool paired with the quantum secure terminal node 13. Then, the second internal network area transmits the second key to the second external network area. After obtaining the second key, the second external network area relays the second key to the first external network area of the first quantum secure server node 11. The first external network area can obtain the second encrypted data through the traditional network and the second key through the quantum secure network. The first external network area transmits the second encrypted data and the second key to the first internal network area respectively. After the first intranet area obtains the second encrypted data and the second key, it decrypts the second encrypted data according to the second key to obtain the second application data, and then uses an internal machine exchange method to transmit the second application data to the target application service.
[0163] Method 2: External independent networking.
[0164] "External connection" refers to the first quantum-safe server node 11 being connected to the second access base station node 12 via an external connection, meaning the first quantum-safe server node 11 and the second access base station node 12 are connected to different local area networks (LANs). "Independent" means the target application service is deployed on an application server node within the same LAN as the first quantum-safe server node 11, but this application server node is different from the first quantum-safe server node 11, and communication between the target application service and the first quantum-safe server node 11 uses an outbound network exchange method.
[0165] Figure 3 This is a schematic diagram of the external independent networking structure provided in the embodiments of this application. If the first quantum security server node 11 includes a first internal network area and a first external network area, and the second access base station node 12 includes a second internal network area and a second external network area, then the difference between the system workflow of this method 2 and the system workflow of the above method 1 is only that the target application service is deployed in the application server node, instead of being deployed in the first quantum security server node 11 as in method 1. The communication between the target application service and the first quantum security server node 11 adopts an outbound network exchange method, instead of the communication between the target application service and the first quantum security server node 11 adopts an internal machine exchange method as in method 1. Here, the parts that are repeated with the system workflow of the above method 1 will not be described again.
[0166] Method 3: External composite networking method.
[0167] "External connection" refers to the first quantum-safe server node 11 being connected to the second access base station node 12 via an external connection, meaning the first quantum-safe server node 11 and the second access base station node 12 are connected to different local area networks (LANs). "Composite" means the target application service can be deployed either on an application server node within the same LAN as the first quantum-safe server node 11 (which may be different from the first quantum-safe server node 11) or on the first quantum-safe server node 11. The target application service deployed on the application server node and the target application service deployed on the first quantum-safe server node 11 can be the same or different.
[0168] Figure 4 This is a schematic diagram of the external composite network structure provided in the embodiments of this application. If the first quantum security server node 11 includes a first internal network area and a first external network area, and the second access base station node 12 includes a second internal network area and a second external network area, then in the system workflow of this method 3, the system workflow of method 2 in the above embodiments is adopted for the target application service deployed on the application server node, and the system workflow of method 1 in the above embodiments is adopted for the target application service deployed in the first quantum security server node 11. For details, please refer to the above embodiments, and repeated parts will not be described again.
[0169] Method 4: Internal converged networking.
[0170] "Internal connection" refers to the first quantum secure server node 11 being internally connected to the second access base station node 12, meaning that the first quantum secure server node 11 and the second access base station node 12 are connected to the same local area network, and the first quantum secure server node 11 and the second access base station node 12 share the same external network area. "Convergence" means that the target application service is deployed on the first quantum secure server node 11, and the communication between the target application service and the first quantum secure server node 11 uses an internal machine switching method.
[0171] Figure 5 This is a schematic diagram of the internal converged networking structure provided in the embodiments of this application. If the first quantum security server node 11 includes a first internal network area, and the second access base station node 12 includes a second internal network area and a second external network area, then the system workflow of this method 4 includes:
[0172] A. The target application service sends the first application data to the quantum security terminal node 13.
[0173] The first intranet area can acquire the first application data of the target application service through internal machine exchange. Then, the first intranet area obtains a first key from the key pool and encrypts the first application data using the first key to obtain first ciphertext data. After obtaining the first ciphertext data, the first intranet area can transmit the first ciphertext data to the second external network area. Furthermore, the first intranet area transmits the first key to the second intranet area of the second access base station node 12 via the local area network. After obtaining the first ciphertext data, the second external network area can send the first ciphertext data to the quantum-secure terminal node 13 via a traditional network. After obtaining the first key, the second intranet area obtains a third key from the key pool paired with the quantum-secure terminal node 13, encrypts the first key using the third key to obtain the encrypted first key, thereby ensuring the security of transmitting the first key to the quantum-secure terminal node 13. Then, the second intranet area can transmit the key information of the third key and the encrypted first key to the second external network area. For example, the second internal network area encapsulates the key information of the third key and the encrypted first key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second external network area. After obtaining the internal transmission data, the second external network area can obtain the key information of the third key and the encrypted first key from the internal transmission data according to the preset customized transmission protocol. The second external network area then sends the key information of the third key and the encrypted first key to the quantum secure terminal node 13. For example, the second external network area relays the key information of the third key and the encrypted first key to the quantum secure terminal node 13 through a link in the quantum secure network. After obtaining the key information of the third key and the encrypted first key, the quantum-safe terminal node 13 can retrieve the third key from the key pool paired with the second access base station node 12 based on the key information of the third key. The quantum-safe terminal node 13 then decrypts the encrypted first key using the third key to obtain the first key, and subsequently decrypts the first ciphertext data using the first key to obtain the first application data.
[0174] B. Quantum-safe terminal node 13 sends second application data to the target application service.
[0175] The quantum-safe terminal node 13 can obtain the second application data, then retrieve the second key from its key pool, and encrypt the second application data using the second key to obtain the second ciphertext data. This ciphertext data is then sent to the second external network area of the second access base station node 12 via a conventional network. Simultaneously, after obtaining the second ciphertext data, the quantum-safe terminal node 13 sends the key information of the second key to the second external network area of the second access base station node 12, from which the second external network area transmits the second ciphertext data to the first internal network area of the first quantum-safe server node 11. The second access base station node 12 can receive the key information of the second key sent by the quantum-safe terminal node 13 through its second external network area. The second external network area then transmits the received key information of the second key to the second internal network area of the second access base station node 12. For example, the second external network area encapsulates the key information of the second key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second internal network area. After obtaining the internal transmission data, the second internal network area can obtain the key information of the second key from the internal transmission data according to the preset customized transmission protocol. Based on the key information of the second key, the second internal network area obtains the second key from the key pool paired with the quantum secure terminal node 13. Then, the second internal network area relays the second key to the first internal network area of the first quantum secure server node 11 through the local area network. After obtaining the second ciphertext data and the second key, the first internal network area decrypts the second ciphertext data according to the second key to obtain the second application data, and then transmits the second application data to the target application service using an internal machine exchange method.
[0176] Method 5: Internal independent networking.
[0177] "Internal connection" means that the first quantum-secure server node 11 is connected to the second access base station node 12 in an internal connection manner. That is, the first quantum-secure server node 11 and the second access base station node 12 are connected to the same local area network, and the first quantum-secure server node 11 and the second access base station node 12 share the same external network area. "Independent" means that the target application service is deployed in an application server node in the same local area network as the first quantum-secure server node 11. This application server node is different from the first quantum-secure server node 11, and the communication between the target application service and the first quantum-secure server node 11 adopts an outgoing network exchange method.
[0178] Figure 6This is a schematic diagram of the internal independent networking structure provided in the embodiments of this application. If the first quantum security server node 11 includes a first internal network area and the second access base station node 12 includes a second internal network area and a second external network area, then the difference between the system workflow of this method 5 and the system workflow of the above method 4 is only that the target application service is deployed in the application server node, instead of being deployed in the first quantum security server node 11 as in method 4. The communication between the target application service and the first quantum security server node 11 adopts an outgoing network exchange method, instead of the communication between the target application service and the first quantum security server node 11 adopts an internal machine exchange method as in method 4. Here, the parts that are repeated with the system workflow of the above method 4 will not be described again.
[0179] Method 6: Internal composite networking method.
[0180] "Internal connection" means that the first quantum-safe server node 11 is internally connected to the second access base station node 12, that is, the first quantum-safe server node 11 and the second access base station node 12 are connected to the same local area network, and the first quantum-safe server node 11 and the second access base station node 12 share the same external network area. "Combined" means that the target application service can be deployed either on an application server node in the same local area network as the first quantum-safe server node 11 (which may be different from the first quantum-safe server node 11), or the target application service can be deployed on the first quantum-safe server node 11. The target application service deployed on the application server node and the target application service deployed on the first quantum-safe server node 11 can be the same or different.
[0181] Figure 7 This is a schematic diagram of the internal composite network structure provided in the embodiments of this application. If the first quantum security server node 11 includes a first internal network area and a first external network area, and the second access base station node 12 includes a second internal network area and a second external network area, then in the system workflow of this method 6, the system workflow of method 5 in the above embodiments is adopted for the target application service deployed on the application server node, and the system workflow of method 4 in the above embodiments is adopted for the target application service deployed in the first quantum security server node 11. For details, please refer to the above embodiments, and repeated parts will not be described again.
[0182] Method 7: Dual-group gateway networking.
[0183] The dual-group gateway networking method refers to the security server nodes all being externally connected to their respective access base station nodes. Specifically, the first quantum security server node 11 is externally connected to the first access base station node, and the second quantum security server nodes are all externally connected to the second access base station node 12. The target application service can be deployed in the application server node on the same local area network as the first quantum security server node 11. The quantum security terminal node 13 includes a general terminal node and a second quantum security server node. The communication between the target application service and the first quantum security server node 11 adopts an outgoing network exchange method, and the communication between the general terminal node and the second quantum security server node also adopts an outgoing network exchange method.
[0184] Figure 8 This is a schematic diagram of the dual-group gateway network structure provided in this application embodiment. If the first quantum security server node 11 includes a first internal network area and a first external network area, the second quantum security server node includes a third internal network area and a third external network area, the first access base station node includes an internal network area and an external network area, and the second access base station node 12 includes a second internal network area and a second external network area, then the system workflow of this method 7 includes:
[0185] A. The target application service sends the first application data to the general terminal node.
[0186] The first internal network area can use an outgoing network exchange method to obtain the first application data of the target application service from the application server node. Then, the first internal network area obtains a first key from the key pool and encrypts the first application data using the first key to obtain first ciphertext data. After obtaining the first ciphertext data, the first internal network area can transmit the first ciphertext data and the first key to the first external network area respectively. After obtaining the first ciphertext data and the first key, the first external network area can send the first ciphertext data to the third external network area of the second quantum-secure server node via a traditional network, and transmit the first key to the external network area of the first access base station node via a quantum-secure network. For example, the first internal network area transmits the key information of the first key to the first external network area, and after obtaining the key information of the first key, the first external network area transmits the key information of the first key to the external network area of the first access base station node via a quantum-secure network. The external network area of the first access base station node then transmits the key information of the first key to its internal network area. After obtaining the key information of the first key in its internal network area, the first access base station node retrieves the first key from the key pool paired with the first quantum-safe server node 11, and transmits the first key to its external network area. The external network area then relays the first key to the second external network area of the second access base station node 12. The second external network area, upon receiving the first key, can transmit it to its second internal network area. The second internal network area, after receiving the first key, retrieves the third key from the key pool paired with the quantum-safe terminal node 13, encrypts the first key using the third key, and obtains the encrypted first key, thus ensuring the security of transmitting the first key to the quantum-safe terminal node 13. The second internal network area can then transmit the key information of the third key and the encrypted first key to the second external network area. For example, the second intranet area encapsulates the key information of the third key and the encrypted first key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed the verification, it transmits the internal transmission data to the second extranet area. After obtaining the internal transmission data, the second extranet area can obtain the key information of the third key and the encrypted first key from the internal transmission data according to the preset customized transmission protocol. The second extranet area then sends the key information of the third key and the encrypted first key to the quantum secure terminal node 13.For example, the second external network area relays the key information of the third key and the encrypted first key to the third external network area of the second quantum secure server node through the link between the quantum secure network and the quantum secure terminal node 13. After obtaining the key information of the third key and the encrypted first key, the third external network area transmits them to the third internal network area of the second quantum secure server node. Furthermore, after obtaining the first ciphertext data, the third external network area also transmits the first ciphertext data to the third internal network area. After obtaining the key information of the third key and the encrypted first key, the third internal network area can obtain the third key from the key pool paired with the second access base station node 12 based on the key information of the third key. The third internal network area decrypts the encrypted first key using the third key to obtain the first key, and then decrypts the first ciphertext data using the first key to obtain the first application data. Then, the third internal network area transmits the first application data to the general terminal node through an outgoing network exchange method.
[0187] B. The general terminal node sends the second application data to the target application service.
[0188] After the general-purpose terminal node initiates the second application data, it can send the second application data to the third internal network area of the second quantum-safe server node via an outgoing network exchange. Upon receiving the second application data, the third internal network area retrieves the second key from the key pool of the second quantum-safe server node, and then encrypts the second application data using the second key to obtain the second ciphertext data. The third internal network area then transmits the key information of the second key and the second ciphertext data to the third external network area. The third external network area sends the key information of the second key to the second external network area of the second access base station node 12, and also sends the second ciphertext data to the first external network area of the first quantum-safe server node 11 via a traditional network. The second access base station node 12 can receive the key information of the second key sent by the quantum-safe terminal node 13 through the second external network area. The second external network area then transmits the received key information of the second key to the second internal network area of the second access base station node 12. For example, the second external network area encapsulates the key information of the second key according to a preset customized transmission protocol, obtains internal transmission data, and sends the internal transmission data to the isolation area of the second access base station node 12. The isolation area verifies the data format of the internal transmission data. After the isolation area determines that the internal transmission data has passed verification, it transmits the internal transmission data to the second internal network area. After obtaining the internal transmission data, the second internal network area can obtain the key information of the second key from the internal transmission data according to the preset customized transmission protocol. Based on the key information, the second internal network area obtains the second key from the key pool paired with the quantum-safe terminal node 13. Then, the second internal network area transmits the second key to the second external network area. The second external network area relays the second key to the external network area of the first access base station node through the quantum-safe network. After receiving the second key, the external network area of the first access base station node transmits the second key to the internal network area of the first access base station node. After obtaining the second key, the intranet area of the first access base station node retrieves a key (denoted as the fourth key) from the key pool paired with the first quantum secure server node 11. Based on the fourth key, it encrypts the second key to obtain the encrypted second key. The intranet area of the first access base station node transmits the key information of the fourth key and the encrypted second key to the extranet area of the first access base station node. The extranet area of the first access base station node then sends the key information of the fourth key and the encrypted second key to the first extranet area of the first quantum secure server node 11. The first extranet area can transmit the received second ciphertext data to the first intranet area. Furthermore, the first extranet area can also transmit the received key information of the fourth key and the encrypted second key to the first intranet area.After obtaining the key information of the fourth key and the encrypted second key, the first intranet area retrieves the fourth key from the key pool of the first quantum security server node 11 based on the key information of the fourth key. Using the fourth key, it decrypts the encrypted second key to obtain the second key. The first intranet area then decrypts the second ciphertext data using the second key to obtain the second application data. Finally, the first intranet area transmits the second application data to the application server node via an outgoing network exchange method.
[0189] Example 5:
[0190] This application provides a networking method based on a quantum-safe server, wherein the method is applied to the first quantum-safe server node corresponding to the target application service. Figure 9 A schematic diagram of a networking process based on a quantum-safe server is provided for an embodiment of this application. The process includes:
[0191] S901: Based on the obtained first key, encrypt the first application data of the target application service to obtain first ciphertext data; send the first ciphertext data and the first key to the quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain the first application data; wherein, the first key is obtained by the quantum secure terminal node through the access base station node it accesses; and
[0192] S902: Receive the second encrypted data and the second key corresponding to the second encrypted data sent by the quantum-safe terminal node; wherein the second key is sent by the quantum-safe terminal node through the access base station node; based on the second key, decrypt the second encrypted data sent by the quantum-safe terminal node, and send the decrypted second application data to the target application service.
[0193] It should be noted that S901 and S902 are not limited in execution order. S901 and S902 can be executed simultaneously, or S901 can be executed first and then S902, or S902 can be executed first and then S901. The execution order of S901 and S902 is not limited here.
[0194] In some possible implementations, if the first quantum-secure server node includes a first intranet region, the step of encrypting the first application data of the target application service based on the acquired first key to obtain first ciphertext data includes:
[0195] The first intranet region obtains the first key from the key pool of the first quantum-safe server node;
[0196] The first intranet area encrypts the first application data according to the first key to obtain the first ciphertext data;
[0197] The step of decrypting the second ciphertext data sent by the quantum-safe terminal node based on the second key, and sending the decrypted second application data to the target application service, includes:
[0198] The first intranet region decrypts the second ciphertext data based on the received second key, and sends the decrypted second application data to the target application service.
[0199] In some possible implementations, if the access base station node includes a second intranet area and a second extranet area, the quantum-secure terminal node obtains the first key through the access base station node, including:
[0200] The second intranet area obtains the first key; obtains the third key from the key pool paired with the quantum-safe terminal node; encrypts the first key according to the third key to obtain the encrypted first key; and sends the key information of the third key and the encrypted first key to the quantum-safe terminal node through the second extranet area.
[0201] The quantum-safe terminal node receives the key information of the third key and the encrypted first key sent by the access base station node; based on the key information of the third key, it obtains the third key from the key pool paired with the access base station node; and according to the third key, it decrypts the encrypted first key to obtain the first key.
[0202] The quantum-secure terminal node sends the second key through the access base station node, including:
[0203] After obtaining the second ciphertext data, the quantum-secure terminal node sends the key information of the second key to the second external network area;
[0204] The second intranet region receives the key information of the second key sent by the quantum-safe terminal node through the second extranet region; according to the key information of the second key, it obtains the second key from the key pool paired with the quantum-safe terminal node; and relays the second key to the first quantum-safe server node.
[0205] In some possible implementations, if the quantum-safe terminal node includes a second quantum-safe server node and a general-purpose terminal node, and the general-purpose terminal node and the second quantum-safe server node are different nodes within the same local area network, then the following two steps are performed through the second quantum-safe server node:
[0206] Step A: Receive the first encrypted data and obtain the first key through the access base station node;
[0207] Based on the first key, the first ciphertext data is decrypted to obtain the first application data;
[0208] Send the first application data to the general terminal node;
[0209] Step B: Receive the second application data initiated by the general terminal node;
[0210] Based on the second key, the acquired second application data is encrypted to obtain the second ciphertext data;
[0211] The second encrypted data is sent to the first quantum secure server node, and the second key is sent to the first quantum secure server node through the access base station node.
[0212] In some possible implementations, if the second quantum-safe server node includes a third intranet area and a third extranet area, then the third extranet area receives the first ciphertext data and transmits the first ciphertext data to the third intranet area; and receives key information of a third key and an encrypted first key sent by the access base station; transmits the key information of the third key and the encrypted first key to the third intranet area; after obtaining the key information of the third key, the encrypted first key, and the first ciphertext data through the third extranet area, the third intranet area obtains the third key from the key pool of the second quantum-safe server node based on the key information of the third key; decrypts the encrypted first key according to the third key to obtain the first key; decrypts the first ciphertext data based on the first key to obtain the first application data; and sends the first application data to the general terminal node through the local area network; and
[0213] The third intranet region receives the second application data initiated by the general terminal node through the local area network; the third intranet region obtains the second key from the key pool of the second quantum-secure server node; the third intranet region encrypts the second application data according to the second key to obtain the second ciphertext data; the third intranet region transmits the second ciphertext data and the key information of the second key to the third extranet region respectively; after obtaining the second ciphertext data and the key information of the second key, the third extranet region sends the key information of the second key to the access base station node, so that the access base station node obtains the second key based on the key information of the second key, and relays the second key to the first quantum-secure server node through the quantum-secure network; and the third extranet region sends the second ciphertext data to the first quantum-secure server node.
[0214] In some possible implementations, where the first quantum-secure server node and the access base station node are deployed in different local area networks, the first quantum-secure server node further includes a first external network area. The first quantum-secure server node sends the first ciphertext data and the first key to the quantum-secure terminal node, including:
[0215] The first external network area receives the key information of the first key and the first ciphertext data transmitted from the first internal network area;
[0216] The first external network area sends the first encrypted data through a traditional network; and relays the key information of the first key to the access base station node to which the first quantum-safe server node is connected, so that the access base station node obtains the first key based on the key information of the first key, and relays the first key to the quantum-safe terminal node through the quantum-safe network.
[0217] The second intranet zone obtains the first key, including:
[0218] The second internal network region acquires the first key transmitted by the second external network region; wherein the first key is received by the second external network region through the quantum secure network;
[0219] The second intranet region relays the second key to the first quantum-secure server node, including:
[0220] The second intranet region transmits the second key to the second extranet region, so that the second extranet region, through the access base station node accessed by the first quantum secure server node, relays the second key to the first quantum secure server node;
[0221] The first quantum-secure server node receives the second ciphertext data and the second key corresponding to the second ciphertext data sent by the quantum-secure terminal node, including:
[0222] The first external network region receives the second key through the access base station node connected to the first quantum security server node and transmits the second key to the first internal network region; and receives the second ciphertext data through the traditional network and transmits the second ciphertext data to the first internal network region.
[0223] In some possible implementations, when the first quantum-safe server node and the access base station node are deployed on the same local area network, the first quantum-safe server node sending the first ciphertext data includes:
[0224] The first intranet area transmits the first ciphertext data to the second extranet area;
[0225] The second external network area sends the first encrypted data to the quantum-secure terminal through a traditional network;
[0226] The second intranet zone obtains the first key, including:
[0227] After obtaining the first key, the first intranet area transmits the first key to the second intranet area through the local area network;
[0228] The first quantum-secure server node receives the second ciphertext data, including:
[0229] The first intranet region obtains the second encrypted data through the second extranet region; wherein, the second encrypted data is sent by the quantum-safe terminal node to the second extranet region through the traditional network;
[0230] The first quantum-secure server node receives the second key, including:
[0231] After obtaining the second key, the second intranet area transmits the second key to the first intranet area through the local area network.
[0232] In some possible implementations, the target application service is deployed in the first intranet area.
[0233] In some possible implementations, if the target application service is deployed on an application server node, and the application server node and the first quantum-safe server node are different nodes deployed within the same local area network, the first intranet region acquires the first application data sent by the target application service, including:
[0234] The first intranet area receives the first application data sent by the application server node through the local area network;
[0235] The first intranet region sends the second application data to the target application service, including:
[0236] The first intranet region sends the second application data to the application server node through the local area network, so that the application server node can respond to the second application data and provide the target application service to the quantum-safe terminal node.
[0237] The beneficial effects of this application are as follows:
[0238] 1. Through this first quantum-safe server node, any target application service can be connected to the quantum-safe network, improving the flexibility of deploying target application services to the quantum-safe network.
[0239] 2. Through this first quantum-safe server node, the first ciphertext data received by the target application service can be decrypted and the second application data sent by the target application service can be encrypted. This enables the application data between the quantum-safe terminal node in the quantum-safe network and the target application service to be transmitted in ciphertext form, thereby improving the security and reliability of the communication between the quantum-safe terminal node and the target application service.
[0240] 3. Through this first quantum-safe server node, the target application service can be deployed to the quantum-safe network without changing the original architecture of the quantum-safe network. It is compatible with the original quantum-safe devices in the quantum-safe network, that is, it is highly compatible with the access base station node in the quantum-safe network and the quantum-safe terminal node connected to the access base station node, thus reducing the cost required to deploy the target application service to the quantum-safe network.
[0241] Example 6:
[0242] This application also provides a networking device based on a quantum-safe server, wherein the device is applied to the first quantum-safe server node corresponding to the target application service. Figure 10 A schematic diagram of a network structure based on a quantum-safe server provided in this application embodiment, the device comprising:
[0243] The transceiver unit 1001 is configured to send first ciphertext data and a first key to a quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain first application data of the target application service; wherein the first key is obtained by the quantum secure terminal node through an access base station node; and to receive second ciphertext data and a second key corresponding to the second ciphertext data sent by the quantum secure terminal node; wherein the second key is sent by the quantum secure terminal node through the access base station node.
[0244] The processing unit 1002 is configured to encrypt the first application data based on the first key to obtain the first ciphertext data; and to decrypt the second ciphertext data sent by the quantum-safe terminal node based on the second key, and send the decrypted second application data to the target application service.
[0245] Since the principle of the above-mentioned quantum-safe server-based networking device for solving the problem is similar to that of the quantum-safe server-based networking method, the implementation of the above-mentioned quantum-safe server-based networking device can be found in the embodiments of the method, and repeated details will not be repeated.
[0246] Example 7:
[0247] Based on the above embodiments, this application also provides a quantum-safe server. Figure 11 This is a schematic diagram of the structure of a quantum-safe server provided in an embodiment of this application, as shown below. Figure 11 As shown, it includes: processor 41, communication interface 42, memory 43 and communication bus 44, wherein processor 41, communication interface 42 and memory 43 communicate with each other through communication bus 44.
[0248] The memory 43 stores a computer program, which, when executed by the processor 41, causes the processor 41 to perform the following steps:
[0249] Based on the obtained first key, the first application data of the target application service is encrypted to obtain first ciphertext data; the first ciphertext data and the first key are sent to the quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain the first application data; wherein, the first key is obtained by the quantum secure terminal node through the access base station node it accesses; and
[0250] The system receives second encrypted data and a second key corresponding to the second encrypted data sent by the quantum-safe terminal node; wherein the second key is sent by the quantum-safe terminal node through the access base station node; based on the second key, the system decrypts the second encrypted data sent by the quantum-safe terminal node and sends the decrypted second application data to the target application service.
[0251] Since the principle of solving the problem by the quantum-safe server is similar to the networking method based on the quantum-safe server, the implementation of the quantum-safe server can be found in the embodiments of the method, and the repeated parts will not be described again.
[0252] Example 8:
[0253] Based on the above embodiments, this application also provides a computer-readable storage medium storing a computer program executable by a processor. When the program runs on the processor, it causes the processor to perform the following steps:
[0254] Based on the obtained first key, the first application data of the target application service is encrypted to obtain first ciphertext data; the first ciphertext data and the first key are sent to the quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain the first application data; wherein, the first key is obtained by the quantum secure terminal node through the access base station node it accesses; and
[0255] The system receives second encrypted data and a second key corresponding to the second encrypted data sent by the quantum-safe terminal node; wherein the second key is sent by the quantum-safe terminal node through the access base station node; based on the second key, the system decrypts the second encrypted data sent by the quantum-safe terminal node and sends the decrypted second application data to the target application service.
[0256] Since the principle of the computer-readable storage medium in solving the problem is similar to the networking method based on quantum-safe servers, the implementation of the computer-readable storage medium can be found in the embodiments of the method, and repeated details will not be described again.
[0257] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A networking system based on a quantum-safe server, characterized in that, The system includes: an access base station node, a quantum-safe terminal node connected to the access base station node, and a first quantum-safe server node corresponding to the target application service; The first quantum-secure server node is configured to encrypt first application data of the target application service based on the acquired first key to obtain first ciphertext data; send the first ciphertext data and the first key to the quantum-secure terminal node; and receive second ciphertext data and a second key corresponding to the second ciphertext data sent by the quantum-secure terminal node; decrypt the second ciphertext data sent by the quantum-secure terminal node based on the second key, and send the decrypted second application data to the target application service. The quantum-safe terminal node is configured to receive the first ciphertext data, and obtain the first key through the access base station node; decrypt the first ciphertext data based on the first key to obtain the first application data; encrypt the second application data based on the obtained second key to obtain the second ciphertext data; send the second ciphertext data to the first quantum-safe server node, and relay the second key to the first quantum-safe server node through the access base station node; Wherein, the first quantum-secure server node includes the first intranet region; The first intranet area is specifically used to obtain the first key from the key pool of the first quantum-safe server node; and to encrypt the first application data according to the first key to obtain the first ciphertext data. The first intranet area is specifically used to decrypt the second ciphertext data based on the received second key, and send the decrypted second application data to the target application service; The access base station node includes a second internal network area and a second external network area; The second intranet area is used to receive key information of the second key sent by the quantum-safe terminal node through the second extranet area; obtain the second key from the key pool paired with the quantum-safe terminal node according to the key information of the second key; relay the second key to the first quantum-safe server node; obtain the first key; obtain a third key from the key pool paired with the quantum-safe terminal node; encrypt the first key according to the third key to obtain the encrypted first key; and send the key information of the third key and the encrypted first key to the quantum-safe terminal node through the second extranet area. The quantum-safe terminal node is specifically configured to receive the key information of the third key and the encrypted first key sent by the access base station node; obtain the third key from the key pool paired with the access base station node based on the key information of the third key; decrypt the encrypted first key according to the third key to obtain the first key; and send the key information of the second key to the second external network area of the access base station node.
2. The system as described in claim 1, characterized in that, The quantum-safe terminal node includes a second quantum-safe server node and a general-purpose terminal node; wherein, the general-purpose terminal node and the second quantum-safe server node are different nodes within the same local area network; The second quantum-secure server node is specifically configured to receive the first ciphertext data, and obtain the first key through the access base station node; decrypt the first ciphertext data based on the first key to obtain first application data; send the first application data to the general terminal node; receive the second application data initiated by the general terminal node; encrypt the second application data based on the second key to obtain second ciphertext data; send the second ciphertext data to the first quantum-secure server node; and send the second key to the first quantum-secure server node through the access base station node.
3. The system as described in claim 2, characterized in that, The second quantum-secure server node includes a third internal network area and a third external network area; The third external network area is specifically used to receive the first ciphertext data, transmit the first ciphertext data to the third internal network area; and receive the key information of the third key and the encrypted first key sent by the access base station. Transmit the key information of the third key and the encrypted first key to the third intranet area; and receive the key information of the second key transmitted from the third intranet area. The key information of the second key is sent to the access base station node, so that the access base station node can obtain the second key based on the key information of the second key, and relay the second key to the first quantum secure server node through the quantum secure network; And, send the second encrypted data to the first quantum-secure server node; The third intranet area is specifically used to obtain the key information of the third key, the encrypted first key, and the first ciphertext data through the third extranet area; based on the key information of the third key, obtain the third key from the key pool of the second quantum-safe server node; decrypt the encrypted first key according to the third key to obtain the first key; and decrypt the first ciphertext data according to the first key to obtain the first application data. The first application data is sent to the general terminal node via the local area network; and the second application data initiated by the general terminal node is received via the local area network. Obtain the second key from the key pool of the second quantum-safe server node; The second application data is encrypted using the second key to obtain the second ciphertext data; The second ciphertext data and the key information of the second key are respectively transmitted to the third external network area.
4. The system as described in any one of claims 1-3, characterized in that, In the case where the first quantum secure server node and the access base station node are deployed in different local area networks, the first quantum secure server node also includes a first external network area; The first external network area is specifically used to receive the key information of the first key and the first ciphertext data transmitted from the first internal network area; relay the key information of the first key to the access base station node to which the first quantum-safe server node is connected, so that the access base station node can obtain the first key based on the key information of the first key, and relay the first key to the quantum-safe terminal node through the quantum-safe network; and send the first ciphertext data to the quantum-safe terminal node through a traditional network. The first external network area is specifically used to receive the second encrypted data through the traditional network; The second encrypted data is transmitted to the first intranet area; and the access base station node connected through the first quantum security server node receives the second key and transmits the second key to the first intranet area. The second external network area is also used to receive the first key sent by the first quantum secure server node; transmit the first key to the second internal network area; and obtain the second key sent by the second internal network area; and relay the second key to the first quantum secure server node through the access base station node accessed by the first quantum secure server node.
5. The system as described in any one of claims 1-3, characterized in that, When the first quantum-secure server node and the access base station node are deployed in the same local area network, the first intranet area is further used to transmit the first ciphertext data to the second extranet area, and to receive the second ciphertext data sent by the second extranet area; and to send the first key to the second intranet area through the local area network. And, the second key is obtained from the second intranet area via the local area network; The second intranet area is specifically used to obtain the first key from the first intranet area through the local area network; and to transmit the second key to the first intranet area through the local area network. The second external network area is also used to receive the first encrypted data transmitted from the first internal network area; The system sends the first encrypted data to the quantum-secure terminal via a conventional network; and receives the second encrypted data sent by the quantum-secure terminal via the conventional network; and transmits the second encrypted data to the first intranet area.
6. The system as described in claim 1, characterized in that, The target application service is deployed in the first intranet region.
7. The system as described in claim 1, characterized in that, If the target application service is deployed on an application server node, and the application server node and the first quantum security server node are different nodes deployed in the same local area network, the system also includes the application server node. The first intranet area is specifically used to receive the first application data sent by the application server node through the local area network; and to send the second application data to the application server node through the local area network, so that the application server node can respond to the second application data and provide the target application service to the quantum-safe terminal node.
8. A networking method based on a quantum-safe server, characterized in that, The method is applied to the first quantum-secure server node corresponding to the target application service, and the method includes: Based on the obtained first key, the first application data of the target application service is encrypted to obtain first ciphertext data; the first ciphertext data and the first key are sent to the quantum secure terminal node, so that the quantum secure terminal node can decrypt the first ciphertext data based on the first key to obtain the first application data; wherein, the first key is obtained by the quantum secure terminal node through the access base station node it accesses; and The system receives second encrypted data and a second key corresponding to the second encrypted data sent by the quantum-safe terminal node; wherein the second key is sent by the quantum-safe terminal node through the access base station node; based on the second key, the system decrypts the second encrypted data sent by the quantum-safe terminal node and sends the decrypted second application data to the target application service; Wherein, if the first quantum-secure server node includes a first intranet region, the step of encrypting the first application data of the target application service based on the obtained first key to obtain the first ciphertext data includes: The first intranet region obtains the first key from the key pool of the first quantum-safe server node; The first intranet area encrypts the first application data according to the first key to obtain the first ciphertext data; The step of decrypting the second ciphertext data sent by the quantum-safe terminal node based on the second key, and sending the decrypted second application data to the target application service, includes: The first intranet region decrypts the second ciphertext data based on the received second key, and sends the decrypted second application data to the target application service; If the access base station node includes a second internal network area and a second external network area, the quantum-secure terminal node obtains the first key through the access base station node, including: The second intranet area obtains the first key; obtains the third key from the key pool paired with the quantum-safe terminal node; encrypts the first key according to the third key to obtain the encrypted first key; and sends the key information of the third key and the encrypted first key to the quantum-safe terminal node through the second extranet area. The quantum-safe terminal node receives the key information of the third key and the encrypted first key sent by the access base station node; based on the key information of the third key, it obtains the third key from the key pool paired with the access base station node; and according to the third key, it decrypts the encrypted first key to obtain the first key. The quantum-secure terminal node sends the second key through the access base station node, including: After obtaining the second ciphertext data, the quantum-secure terminal node sends the key information of the second key to the second external network area; The second intranet region receives the key information of the second key sent by the quantum-safe terminal node through the second extranet region; according to the key information of the second key, it obtains the second key from the key pool paired with the quantum-safe terminal node; and relays the second key to the first quantum-safe server node.
9. The method as described in claim 8, characterized in that, If the quantum-safe terminal node includes a second quantum-safe server node and a general-purpose terminal node, and the general-purpose terminal node and the second quantum-safe server node are different nodes within the same local area network, then the following two steps are performed through the second quantum-safe server node: Step A: Receive the first encrypted data and obtain the first key through the access base station node; Based on the first key, the first ciphertext data is decrypted to obtain the first application data; Send the first application data to the general terminal node; Step B: Receive the second application data initiated by the general terminal node; Based on the second key, the acquired second application data is encrypted to obtain the second ciphertext data; The second encrypted data is sent to the first quantum secure server node, and the second key is sent to the first quantum secure server node through the access base station node.
10. The method as described in claim 9, characterized in that, If the second quantum-secure server node includes a third internal network area and a third external network area, then the third external network area receives the first ciphertext data and transmits the first ciphertext data to the third internal network area; and receives the key information of the third key and the encrypted first key sent by the access base station. The key information of the third key and the encrypted first key are transmitted to the third intranet area; after the third intranet area obtains the key information of the third key, the encrypted first key, and the first ciphertext data through the third extranet area, it obtains the third key from the key pool of the second quantum-safe server node based on the key information of the third key; it decrypts the encrypted first key according to the third key to obtain the first key; and it decrypts the first ciphertext data according to the first key to obtain the first application data. The first application data is sent to the general terminal node via the local area network; as well as The third intranet region receives the second application data initiated by the general terminal node through the local area network; the third intranet region obtains the second key from the key pool of the second quantum-safe server node; The third intranet area encrypts the second application data according to the second key to obtain the second ciphertext data; The third internal network area transmits the second ciphertext data and the key information of the second key to the third external network area respectively; after obtaining the second ciphertext data and the key information of the second key, the third external network area sends the key information of the second key to the access base station node, so that the access base station node can obtain the second key based on the key information of the second key, and relay the second key to the first quantum secure server node through the quantum secure network; Furthermore, the third external network region sends the second encrypted data to the first quantum-secure server node.
11. The method according to any one of claims 8-10, characterized in that, When the first quantum-secure server node and the access base station node are deployed in different local area networks, the first quantum-secure server node further includes a first external network area. The first quantum-secure server node sends the first ciphertext data and the first key to the quantum-secure terminal node, including: The first external network area receives the key information of the first key and the first ciphertext data transmitted from the first internal network area; The first external network area sends the first encrypted data through a traditional network; and relays the key information of the first key to the access base station node to which the first quantum-safe server node is connected, so that the access base station node obtains the first key based on the key information of the first key, and relays the first key to the quantum-safe terminal node through the quantum-safe network. The second intranet zone obtains the first key, including: The second internal network region acquires the first key transmitted by the second external network region; wherein the first key is received by the second external network region through the quantum secure network; The second intranet region relays the second key to the first quantum-secure server node, including: The second intranet region transmits the second key to the second extranet region, so that the second extranet region, through the access base station node accessed by the first quantum secure server node, relays the second key to the first quantum secure server node; The first quantum-secure server node receives the second ciphertext data and the second key corresponding to the second ciphertext data sent by the quantum-secure terminal node, including: The first external network region receives the second key through the access base station node connected to the first quantum security server node and transmits the second key to the first internal network region; and receives the second ciphertext data through the traditional network and transmits the second ciphertext data to the first internal network region.
12. The method according to any one of claims 8-10, characterized in that, When the first quantum-secure server node and the access base station node are deployed on the same local area network, the first quantum-secure server node sends the first ciphertext data including: The first intranet area transmits the first ciphertext data to the second extranet area; The second external network area sends the first encrypted data to the quantum-secure terminal through a traditional network; The second intranet zone obtains the first key, including: After obtaining the first key, the first intranet area transmits the first key to the second intranet area through the local area network; The first quantum-secure server node receives the second ciphertext data, including: The first intranet region obtains the second encrypted data through the second extranet region; wherein, the second encrypted data is sent by the quantum-safe terminal node to the second extranet region through the traditional network; The first quantum-secure server node receives the second key, including: After obtaining the second key, the second intranet area transmits the second key to the first intranet area through the local area network.
13. The method as described in claim 8, characterized in that, The target application service is deployed in the first intranet region.
14. The method as described in claim 8, characterized in that... If the target application service is deployed on an application server node, and the application server node and the first quantum-secure server node are different nodes deployed within the same local area network, the first intranet region acquires the first application data sent by the target application service, including: The first intranet area receives the first application data sent by the application server node through the local area network; The first intranet region sends the second application data to the target application service, including: The first intranet region sends the second application data to the application server node through the local area network, so that the application server node can respond to the second application data and provide the target application service to the quantum-safe terminal node.