A method for writing and reading the identity of a quantum terminal device

Through encryption processing and seed key management, the problem of leakage and multiple use of identity information of quantum terminal devices is solved, and the uniqueness and non-replicability of identity information are achieved.

CN116599674BActive Publication Date: 2025-08-22MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310488173.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-04
Publication Date
2025-08-22
Estimated Expiration
2043-05-04

AI Technical Summary

Technical Problem

When existing quantum terminal devices use flash chips to identify identity information, there are problems such as information leakage and multiple use of identity information.

Method used

Encryption processing is used to write the identity information of the quantum terminal device into ciphertext form, and the seed key management of the encryption and decryption module and the processing module ensures the uniqueness and non-replicability of the identity information.

Benefits of technology

Prevent identity information leakage and ensure that identity information cannot be decrypted when the device is replaced, realizing the non-replicability and uniqueness of identity information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116599674B_ABST
    Figure CN116599674B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for writing and reading the identity of a quantum terminal device, which relates to the field of quantum communication. The quantum terminal device includes a processing module, a decryption unit, an encryption / decryption module, and a storage module. The identity writing method comprises: the identity writing unit generates and encrypts the identity information of the quantum terminal device to obtain first ciphertext information, which is then sent to the decryption unit via the processing module. The decryption unit performs decryption processing on the first ciphertext information, which is then sent to the encryption / decryption module via the processing module. After encryption, second ciphertext information is obtained, which is then sent to the storage module via the processing module for storage. The identity reading method comprises: the identity reading unit sends a request to read the identity information, the processing module receives the request and sends the second ciphertext information read from the storage module to the encryption / decryption module, which decrypts the second ciphertext information and then sends it to the identity reading unit via the processing module for storage. The present invention ensures the uniqueness, non-replicability, and non-repeatability of the identity of the quantum terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum communication, and in particular to a method for writing and reading the identity of a quantum terminal device. Background Art

[0002] Quantum communication is a new type of communication method that uses quantum superposition and entanglement effects to transmit information. Based on the three principles of uncertainty, measurement collapse and non-cloning in quantum mechanics, it provides absolute security that cannot be eavesdropped or cracked by calculation. The identity of quantum terminal devices based on quantum communication should be unique, non-replicable and non-repeatable.

[0003] Currently, the identification information of quantum terminal devices is usually written into flash chips. Flash chips combine the advantages of ROM and RAM. They are not only electronically erasable and programmable, but also do not lose data due to power outages. They have the characteristics of storing quantum terminal identity information and providing fast reading. However, flash chips still have defects in actual use, such as:

[0004] 1. Information thieves can extract information from the flash chip without contact by sensing the characteristic changes of the flash chip, thus leaking identity information;

[0005] 2. Uninstall the flash chip from the quantum terminal device and use a dedicated reading device to extract the information in the flash chip, thereby leaking the identity information;

[0006] 3. Uninstalling the flash chip from one quantum terminal device and then installing it on another quantum terminal device will cause the same identity information to be used multiple times and the correct identity information cannot be identified. Summary of the Invention

[0007] Purpose of the Invention: The purpose of the present invention is to provide a method for writing and reading the identity of a quantum terminal device, addressing the issues of identity information leakage and multiple uses of the same identity caused by the use of flash chips in current quantum terminal devices. In the present invention, the information extracted from the flash chip cannot directly identify the correct identity information, and even if the flash chip is installed from one quantum terminal device to another, it cannot identify the correct identity information. The present invention ensures the uniqueness, non-replicability, and non-repeatability of the identity of the quantum terminal device.

[0008] Technical solution: A method for writing an identity into a quantum terminal device, the quantum terminal device comprising a processing module, a decryption unit, an encryption / decryption module, and a storage module, the method comprising the following steps:

[0009] Step 1: The identity writing unit generates identity information of the quantum terminal device, performs encryption processing to obtain first ciphertext information, and then sends the first ciphertext information to the processing module;

[0010] Step 2: The processing module receives the first ciphertext information and sends the first ciphertext information to the decryption unit;

[0011] Step 3: The decryption unit decrypts the received first ciphertext information and sends the decrypted information to the processing module;

[0012] Step 4: The processing module sends the decrypted information received from the decryption unit to the encryption and decryption module. The encryption and decryption module encrypts the decrypted information to obtain second ciphertext information, and sends the second ciphertext information to the processing module.

[0013] Step 5: The processing module receives the second ciphertext information and sends the received second ciphertext information to the storage module;

[0014] Step 6: The storage module receives and stores the second ciphertext information.

[0015] Furthermore, the identity writing unit includes a PC server and an encryption unit, and step 1 further includes:

[0016] The PC server generates identity information of the quantum terminal device and sends the generated identity information of the quantum terminal device to the encryption unit. The encryption unit encrypts the received identity information of the quantum terminal device to obtain first ciphertext information.

[0017] Furthermore, the seed key used for encryption and decryption of the encryption and decryption module is stored in the processing module.

[0018] Furthermore, the encryption and decryption module stores a seed key for encryption and decryption.

[0019] Furthermore, the step 4 further comprises:

[0020] The encryption and decryption module extracts a seed key from the processing module, and uses the extracted seed key to encrypt the information decrypted by the decryption unit to obtain second ciphertext information.

[0021] Furthermore, the step 4 further comprises:

[0022] The encryption and decryption module extracts the seed key from the memory to encrypt the information decrypted by the decryption unit to obtain second ciphertext information.

[0023] Furthermore, the processing module is an FPGA chip, and the storage module is a flash chip.

[0024] A method for reading the identity of a quantum terminal device, the quantum terminal device comprising a processing module, a decryption unit, an encryption / decryption module, and a storage module, wherein the storage module stores second ciphertext information, the method comprising the following steps:

[0025] Step 1: The identity reading unit sends a request to read identity information to the quantum terminal device;

[0026] Step 2: The processing module receives a request from the identity reading unit, and then the processing module reads the second ciphertext information from the storage module and sends the read second ciphertext information to the encryption and decryption module;

[0027] Step 3: The encryption / decryption module decrypts the received second ciphertext information and sends the decrypted information to the processing module;

[0028] Step 4: The processing module receives the decrypted information from the encryption and decryption module and sends the information to the identity reading unit.

[0029] Furthermore, the seed key used for encryption and decryption of the encryption and decryption module is stored in the processing module, and the step 3 further includes:

[0030] The encryption and decryption module pulls the seed key from the processing module and uses the pulled seed key to decrypt the received second ciphertext information.

[0031] Furthermore, the encryption and decryption module stores a seed key for encryption and decryption, and step 3 further includes:

[0032] The encryption and decryption module extracts the seed key from the memory to decrypt the received second ciphertext information.

[0033] Beneficial effects of the present invention:

[0034] 1. The identity information of the quantum terminal device of the present invention is stored in the flash chip in the form of encrypted ciphertext. The information extracted from the flash chip cannot directly identify the correct identity information, thus preventing identity leakage.

[0035] 2. The identity information of the quantum terminal device of the present invention is stored in a flash chip in encrypted form. Even if the flash chip is removed from one quantum terminal device and then installed on another quantum terminal device, the information in the flash chip cannot be decrypted, resulting in the inability to identify the correct identity information. As a result, the identity information in the flash chip cannot be used multiple times.

[0036] 3. The seed key used for encryption and decryption in the encryption and decryption module of the present invention can be stored internally. The encryption chip used in the encryption and decryption module of the present invention is powered by a battery after the quantum terminal device is powered off, protecting the seed key inside the encryption chip from loss. Once the encryption chip is manually removed, the seed key stored inside the encryption chip will be lost or return to the default value due to the loss of power to maintain the normal operation of the encryption chip. As a result, even if the flash chip and the encryption chip are removed at the same time and then installed together on another quantum terminal device, the identity information inside the flash chip cannot be decrypted, resulting in the inability to identify the correct identity information, thereby preventing the identity information in the flash chip from being used multiple times.

[0037] 4. The seed key used for encryption and decryption by the encryption and decryption module of the present invention can be stored in the processing module. In this way, even if the flash chip and the encryption and decryption module are removed at the same time and then installed together on another quantum terminal device, the identity information inside the flash chip cannot be decrypted, resulting in the inability to identify the correct identity information, thereby preventing the identity information in the flash chip from being used multiple times. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 Schematic diagram of the hardware structure involved in the identity writing and reading method of the quantum terminal device of the present invention;

[0039] Figure 2 This is a flowchart of a method for writing an identity into a quantum terminal device according to the present invention;

[0040] Figure 3 This is a flowchart of a method for reading the identity of a quantum terminal device according to the present invention. DETAILED DESCRIPTION

[0041] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0042] like Figure 1 As shown, the quantum terminal device of the present invention includes a processing module, a decryption unit, an encryption and decryption module and a storage module. The identity writing unit of the present invention includes a PC server and an encryption unit. The present invention also includes an identity reading unit.

[0043] The PC server is used to generate the identity information of the quantum terminal device.

[0044] The processing module is an FPGA chip, and the processing module is used for transmitting information.

[0045] The storage module is a flash chip, and the identity information of the quantum terminal device of the present invention is stored in the storage chip in the form of encrypted ciphertext.

[0046] The encryption unit and the decryption unit have symmetric keys. The encryption unit performs an encryption operation on the identity information of the quantum terminal device, and the corresponding decryption unit performs a decryption operation on the identity information of the quantum terminal device.

[0047] The encryption and decryption module is used for encryption and decryption operations of information. The seed key used by the encryption and decryption module for encryption and decryption can be stored in the internal memory or in the processing module.

[0048] When the seed key is stored in the processing module, the encryption and decryption module implements information encryption and decryption operations by pulling the seed key from the processing module. This will result in the inability to obtain the correct seed key for identity information decryption operations during the identity information reading process of the quantum terminal device, even if the encryption and decryption module is removed and reinstalled on another quantum terminal device.

[0049] When the seed key is stored in memory, the encryption and decryption module of the present invention can directly use an existing encryption chip, such as the IS32U512V1.0 terminal security chip. The quantum terminal device contains a built-in button battery, such as a CR2032. This battery powers the encryption chip when the quantum terminal device is powered off, ensuring that the seed key stored in the encryption chip is not lost. However, if the encryption chip is removed, the power required to maintain normal operation of the encryption chip is lost, and the seed key stored in the encryption chip is lost or returns to the default value. This makes it impossible to obtain the correct seed key for identity information decryption operations during the quantum terminal device's identity information reading process, even if the encryption and decryption module is removed and reinstalled on another quantum terminal device.

[0050] The encryption and decryption of the present invention is quantum encryption and decryption.

[0051] like Figure 2 As shown, a method for writing an identity of a quantum terminal device includes the following steps:

[0052] Step 1: The PC server generates identity information of the quantum terminal device and sends the generated identity information of the quantum terminal device to the encryption unit. The encryption unit encrypts the received identity information of the quantum terminal device to obtain first ciphertext information, and then sends the first ciphertext information to the processing module via network transmission.

[0053] Step 2: The processing module receives the first ciphertext information and sends the first ciphertext information to the decryption unit;

[0054] Step 3: The decryption unit and the encryption unit have a symmetric key. The decryption unit decrypts the received first ciphertext information and sends the decrypted information to the processing module. The information obtained by the decryption unit from decrypting the first ciphertext information is the plaintext identity information of the quantum terminal device.

[0055] Step 4: The processing module sends the decrypted information received from the decryption unit to the encryption and decryption module. That is, the processing module sends the plaintext identity information of the quantum terminal device obtained after the decryption process by the decryption unit in step 3 to the encryption and decryption module. The encryption and decryption module encrypts the information decrypted by the decryption unit. That is, the encryption and decryption module encrypts the plaintext information of the quantum terminal device sent by the processing module to obtain second ciphertext information. The second ciphertext information is sent to the processing module.

[0056] Step 5: The processing module receives the second ciphertext information and sends the received second ciphertext information to the storage module;

[0057] Step 6: The storage module receives and stores the second ciphertext information. The plaintext identity information of the quantum terminal device is encrypted into the second ciphertext information and stored in the storage module.

[0058] When the seed key used for encryption and decryption of the encryption and decryption module is stored in the processing module, the encryption and decryption module pulls the seed key from the processing module, and uses the pulled seed key to encrypt the information decrypted by the decryption unit, that is, the pulled seed key is used to encrypt the plaintext identity information of the quantum terminal device sent by the processing module to obtain the second ciphertext information, and the second ciphertext information is sent to the processing module.

[0059] When the encryption and decryption module stores a seed key for encryption and decryption, the encryption and decryption module extracts the seed key from the memory to encrypt the information decrypted by the decryption unit, that is, the encryption and decryption module extracts the seed key from the memory to encrypt the plaintext identity information of the quantum terminal device sent by the processing module to obtain the second ciphertext information, and the second ciphertext information is sent to the processing module.

[0060] like Figure 3 As shown, a method for reading the identity of a quantum terminal device is provided. The plaintext identity information of the quantum terminal device is encrypted into second ciphertext information and stored in a storage module using the above-mentioned method for writing the identity of the quantum terminal device. The identity reading method includes the following steps:

[0061] Step 1: The identity reading unit sends a request to read identity information to the quantum terminal device through the network. The identity reading unit of the present invention can be a service unit such as a base station;

[0062] Step 2: The processing module receives a request from the identity reading unit, and then the processing module reads the second ciphertext information from the storage module and sends the read second ciphertext information to the encryption and decryption module;

[0063] Step 3: The encryption / decryption module decrypts the received second ciphertext information and sends the decrypted information to the processing module;

[0064] Step 4: The processing module receives the information obtained after decryption from the encryption and decryption module, and sends the information to the identity reading unit. The information obtained after the encryption and decryption module decrypts the second ciphertext information is the plaintext identity information of the quantum terminal device.

[0065] When the seed key used for encryption and decryption of the encryption and decryption module is stored in the processing module, the encryption and decryption module pulls the seed key from the processing module and uses the pulled seed key to decrypt the received second ciphertext information. The decrypted information is the plaintext identity information of the quantum terminal device.

[0066] When the encryption and decryption module stores a seed key for encryption and decryption, the module extracts the seed key from the memory to decrypt the received second ciphertext information. The decrypted information is the plaintext identity information of the quantum terminal device.

Claims

1. A method for writing an identity into a quantum terminal device, characterized in that: The quantum terminal device includes a processing module, a decryption unit, an encryption and decryption module, and a storage module. The identity writing method includes the following steps: Step 1: The identity writing unit generates identity information of the quantum terminal device, performs encryption processing to obtain first ciphertext information, and then sends the first ciphertext information to the processing module; Step 2: The processing module receives the first ciphertext information and sends the first ciphertext information to the decryption unit; Step 3: The decryption unit decrypts the received first ciphertext information and sends the decrypted information to the processing module; Step 4: The processing module sends the decrypted information received from the decryption unit to the encryption and decryption module. The encryption and decryption module encrypts the decrypted information to obtain second ciphertext information, and sends the second ciphertext information to the processing module. Step 5: The processing module receives the second ciphertext information and sends the received second ciphertext information to the storage module; Step 6: The storage module receives and stores the second ciphertext information.

2. The method for writing an identity of a quantum terminal device according to claim 1, characterized in that: The identity writing unit includes a PC server and an encryption unit, and step 1 further includes: The PC server generates identity information of the quantum terminal device and sends the generated identity information of the quantum terminal device to the encryption unit. The encryption unit encrypts the received identity information of the quantum terminal device to obtain first ciphertext information.

3. The method for writing an identity of a quantum terminal device according to claim 1, characterized in that: The seed key used for encryption and decryption of the encryption and decryption module is stored in the processing module.

4. The method for writing an identity of a quantum terminal device according to claim 1, characterized in that: The encryption and decryption module stores a seed key for encryption and decryption.

5. The method for writing an identity of a quantum terminal device according to claim 3, characterized in that: The step 4 further comprises: The encryption and decryption module extracts a seed key from the processing module, and uses the extracted seed key to encrypt the information decrypted by the decryption unit to obtain second ciphertext information.

6. The method for writing an identity of a quantum terminal device according to claim 4, characterized in that: The step 4 further comprises: The encryption and decryption module extracts the seed key from the memory to encrypt the information decrypted by the decryption unit to obtain second ciphertext information.

7. The method for writing an identity of a quantum terminal device according to claim 1, characterized in that: The processing module is an FPGA chip, and the storage module is a flash chip.

8. A method for reading the identity of a quantum terminal device, characterized in that: The quantum terminal device includes a processing module, a decryption unit, an encryption / decryption module, and a storage module. The storage module stores second ciphertext information. The second ciphertext information is obtained and stored in the storage module by the identity writing method for a quantum terminal device according to claim 1. The identity reading method includes the following steps: Step 1: The identity reading unit sends a request to read identity information to the quantum terminal device; Step 2: The processing module receives a request from the identity reading unit, and then the processing module reads the second ciphertext information from the storage module and sends the read second ciphertext information to the encryption and decryption module; Step 3: The encryption / decryption module decrypts the received second ciphertext information and sends the decrypted information to the processing module; Step 4: The processing module receives the decrypted information from the encryption and decryption module and sends the information to the identity reading unit.

9. The method for reading the identity of a quantum terminal device according to claim 8, characterized in that: The seed key used for encryption and decryption of the encryption and decryption module is stored in the processing module, and the step 3 further includes: The encryption and decryption module pulls the seed key from the processing module and uses the pulled seed key to decrypt the received second ciphertext information.

10. The method for reading the identity of a quantum terminal device according to claim 8, characterized in that: The encryption / decryption module stores a seed key for encryption / decryption, and step 3 further includes: The encryption and decryption module extracts the seed key from the memory to decrypt the received second ciphertext information.

Citation Information

Patent Citations

  • Quantum security identity issuing system, issuing method and use method

    CN113938281A

  • Terminal digital identity writing method and system

    CN115118440A