A security server based on a quantum key network and a working method thereof

By introducing external network machines, isolation boards, and internal network machines into the server design, the complex adaptation problem when the server connects to the quantum network is solved, improving security and efficiency, and simplifying quantum encryption and decryption operations on the application server side.

CN116647359BActive Publication Date: 2026-04-14MATRICTIME DIGITAL TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MATRICTIME DIGITAL TECH CO LTD
Filing Date
2023-03-28
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing servers require significant time and effort to perform quantum encryption and decryption operations, such as interface adaptation and quantum key management, after connecting to the quantum network, and there are also security risks involved.

Method used

Design a secure server based on quantum key network, including an external network machine, an isolation board, and an internal network machine. The external network machine is used for packet splitting and reassembly, the isolation board is used for data transmission, and the internal network machine is used for quantum decryption and encryption. The application server is deployed in the internal network machine and isolated from the outside world by the isolation board.

Benefits of technology

It simplifies the quantum network access process for application servers, improves security and efficiency, reduces complex adaptation and management work, and ensures the security of data transmission and the convenience of later maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116647359B_ABST
    Figure CN116647359B_ABST
Patent Text Reader

Abstract

The application discloses a kind of security servers based on quantum key network and its working method, the security server includes the outer net machine, isolation board and inner net machine connected in turn;Outer net machine is used to split and reorganize the first UDP message data transmitted by the sender through the Internet into the first ciphertext data packet, and the first ciphertext data packet is transmitted to the isolation board.The application deploys application program server in the inner net machine of security server, has very high security, and the data attack of Internet cannot reach the inner net machine;At the same time, it can also support the deployment of multiple application program servers, customize the reorganization of Internet data transmission format to unify the data transmission format, and then send it to the inner net machine for unified quantum encryption and decryption, which reduces a large number of complex adaptation management work, saves a lot of time and energy, and also provides convenience for later maintenance and upgrading work, increases the efficiency and security of application program server access to quantum network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum security technology, specifically to a secure server based on a quantum key network and its operating method. Background Technology

[0002] Data security should ensure the security of the entire process of data production, storage, transmission, access, use, destruction, and publication, and guarantee the confidentiality, integrity, and availability of data processing. Furthermore, it should address the relationships between publicly available data, such as personal names, contact information, vehicle registrations, and social media posts. While these are non-physical, implicit data, they often involve personal privacy and may even pose public safety issues such as real-time location tracking. Therefore, encryption modules have been increasingly added to data transmission. Ciphertext transmission is more secure than plaintext transmission, is less prone to cracking, and makes it easier to detect data leaks, providing an extra layer of protection for data security.

[0003] With the advent of quantum computers, traditional encryption algorithms have become increasingly inadequate, especially in scenarios where information security is paramount. The high computing power of quantum computers renders traditional algorithms ineffective. Therefore, connecting to quantum networks has become an inevitable trend for ensuring the security and reliability of applications. Currently, many application servers are deployed on servers, such as FTP and email services. Adapting each application server to connect to a quantum network requires quantum encryption and decryption operations during data transmission. The collection of these operations across all application servers means a large number of quantum encryption and decryption operations, which is not a simple task. It requires significant time and effort, including adapting numerous interfaces, managing a large number of quantum keys, extensive integration, and debugging. Furthermore, adding such encryption and decryption functionality to different application services makes future modifications and maintenance very troublesome. Additionally, after extensive adaptation, security vulnerabilities may arise in the application server's security.

[0004] Therefore, in order to quickly access the quantum network and reduce the large amount of tedious adaptation work on the application server, it is necessary to find a fast and secure way to solve this problem with zero awareness and zero modification while ensuring information security. Summary of the Invention

[0005] Purpose of the invention: The purpose of this invention is to provide a secure server based on a quantum key network and its working method, which solves the problem that each application server in existing servers needs to spend a lot of time and effort to adapt to a large number of interfaces and manage a large number of quantum keys for quantum encryption and decryption operations after connecting to a quantum network; at the same time, it solves the problem that the security of the application server has security vulnerabilities after a lot of adaptation.

[0006] Technical solution: The present invention provides a secure server based on a quantum key network, the secure server comprising an external network machine, an isolation board, and an internal network machine connected in sequence;

[0007] The external network machine is used to split and reassemble the first UDP packet data transmitted by the sender via the Internet into a first ciphertext data packet, and transmit the first ciphertext data packet to the isolation board; and to split and reassemble the second ciphertext data packet transmitted by the isolation board into a second UDP packet data packet and transmit it to the receiver via the Internet.

[0008] The isolation board is used to transmit the first and second encrypted data packets;

[0009] The intranet machine is used to split and quantum decrypt the first encrypted data packet transmitted from the isolation board to obtain plaintext data, parse the plaintext data to obtain plaintext message and recipient address, process the plaintext message, and quantum encrypt the processed plaintext message, then generate a second encrypted data packet with the recipient address, and transmit the second encrypted data packet to the isolation board.

[0010] Furthermore, the external network machine includes a first network card, a first data splitting and reassembling module, a first transmission module, and a second network card connected in sequence, with the second network card connected to the isolation board;

[0011] The first network interface card (NIC) is used to receive first UDP packet data transmitted by the sender via the Internet and send it to the first data splitting and reassembly module; and to transmit second UDP packet data to the receiver via the Internet.

[0012] The first data splitting and reassembly module is used to split the first UDP packet data into a first UDP packet header and first UDP data, obtain the sender address from the first UDP packet header, calculate the length of the sender address and the first UDP data to obtain a first message length, and reassemble the first message length, the sender address, and the first UDP data into a first ciphertext data packet and send it to the first transmission module; and to split the second ciphertext data packet into a second message length, a receiver address, and second UDP data, and reassemble the receiver address and the second UDP data into a second UDP packet data according to the UDP packet format and send it to the first network interface card;

[0013] The first transmission module is used to transmit the first encrypted data packet to the second network interface card (NIC); and to transmit the second encrypted data packet received by the second NIC to the first data splitting and reassembly module;

[0014] The second network interface card (NIC) is used to transmit the first encrypted data packet to the isolation board; and to receive the second encrypted data packet transmitted from the isolation board and send it to the first transmission module.

[0015] Furthermore, the intranet machine includes a third network card, a second transmission module, a second data splitting and reassembly module, a quantum encryption and decryption module, and an application server. The third network card, the second transmission module, the second data splitting and reassembly module, and the application server are connected in sequence. The third network card is connected to the isolation board, and the second data splitting and reassembly module is connected to the quantum encryption and decryption module.

[0016] The third network interface card is used to receive the first encrypted data packet transmitted from the isolation board and send it to the second transmission module; and to transmit the second encrypted data packet to the isolation board;

[0017] The second transmission module is used to transmit the received first encrypted data packet to the second data splitting and reassembly module; and to transmit the second encrypted data packet to the third network interface card;

[0018] The second data splitting and reassembly module is used to split the first ciphertext data packet into a first message length, a sender address, and first UDP data, and send the first UDP data to the quantum encryption and decryption module for decryption to obtain plaintext data, and send the plaintext data to the application server; and to receive the plaintext message and the receiver address transmitted from the application server, send the plaintext message to the quantum encryption and decryption module for encryption to obtain second UDP data, calculate the receiver address and the length of the second UDP data to obtain the second message length, and reassemble the second message length, the receiver address, and the second UDP data into a second ciphertext data packet and send it to the second transmission module;

[0019] The application server is used to parse plaintext data to obtain plaintext messages and recipient addresses, process the plaintext messages, and send the processed plaintext messages and recipient addresses to the second data splitting and reassembly module.

[0020] The quantum encryption / decryption module is used to decrypt the first UDP data to obtain plaintext data and send it to the second data splitting and reassembly module; and to encrypt the plaintext message to obtain the second UDP data and send it to the second data splitting and reassembly module.

[0021] Furthermore, the isolation board is an FPGA, used to isolate external network machines and internal network machines.

[0022] This invention also includes a method for operating a secure server based on a quantum key network, comprising the following steps:

[0023] (1) The sender transmits the first UDP packet data to the external network machine via the Internet. The external network machine splits and reassembles the first UDP packet data into the first encrypted data packet and transmits the first encrypted data packet to the isolation board.

[0024] (2) The isolation board transmits the first encrypted data packet to the intranet machine. The intranet machine splits and quantum decrypts the first encrypted data packet to obtain plaintext data. It then parses the plaintext data to obtain the plaintext message and the recipient address, and processes the plaintext message. Then, it quantum encrypts the processed plaintext message and generates a second encrypted data packet with the recipient address, and transmits the second encrypted data packet to the isolation board.

[0025] (3) The isolation board transmits the second encrypted data packet to the external network machine, which then splits and reassembles the second encrypted data packet into a second UDP packet data packet and transmits it to the receiver via the Internet.

[0026] Furthermore, the specific process of step (1) is as follows:

[0027] The sender transmits the first UDP packet data to the first network interface card (NIC) of the external network machine via the Internet. The first NIC then sends the first UDP packet data to the first data splitting and reassembly module. The first data splitting and reassembly module splits the first UDP packet data into a first UDP header and first UDP data. It obtains the sender's address from the first UDP header, calculates the length of the sender's address and the length of the first UDP data to obtain the first message length, and reassembles the first message length, the sender's address, and the first UDP data into a first encrypted data packet, which is then sent to the first transmission module. The first transmission module transmits the first encrypted data packet to the second NIC, and the second NIC transmits the first encrypted data packet to the isolation board.

[0028] Furthermore, the specific process of step (2) is as follows:

[0029] 1) The isolation board transmits the first encrypted data packet to the third network card of the intranet machine. The third network card sends the first encrypted data packet to the second transmission module. The second transmission module transmits the received first encrypted data packet to the second data splitting and reassembly module. The second data splitting and reassembly module splits the first encrypted data packet into a first message length, a sender address, and first UDP data. The first UDP data is sent to the quantum encryption and decryption module for decryption to obtain plaintext data. The plaintext data is then sent to the application server. The application server parses the plaintext data to obtain the plaintext message and the receiver address, and processes the plaintext message.

[0030] 2) The application server sends the processed plaintext message and the recipient address to the second data splitting and reassembly module; the second data splitting and reassembly module receives the transmitted plaintext message and the recipient address, and sends the plaintext message to the quantum encryption and decryption module for encryption to obtain the second UDP data. It calculates the recipient address and the length of the second UDP data to obtain the second message length, and reassembles the second message length, the recipient address, and the second UDP data into a second ciphertext data packet and sends it to the second transmission module; the second transmission module transmits the second ciphertext data packet to the third network card, and the third network card transmits the second ciphertext data packet to the isolation board.

[0031] Furthermore, the specific process of step (3) is as follows:

[0032] The isolation board transmits the second encrypted data packet to the second network card of the external network machine. The second network card sends the second encrypted data packet to the first transmission module. The first transmission module transmits the received second encrypted data packet to the first data splitting and reassembling module. The first data splitting and reassembling module splits the second encrypted data packet into a second message length, a receiver address, and second UDP data. It then reassembles the receiver address and the second UDP data into a second UDP packet according to the UDP packet format and sends it to the first network card. The first network card transmits the second UDP packet to the receiver via the Internet.

[0033] The beneficial effects of this invention are as follows: This invention deploys the application server on the intranet machine of a secure server, which has extremely high security, and the intranet machine cannot be attacked by Internet data; moreover, it can support the deployment of multiple application servers, and customizes and recombines the Internet data transmission format to unify the data transmission format before sending it to the intranet machine for unified quantum encryption and decryption, which reduces a lot of complex adaptation and management work, saves a lot of time and energy, and also provides convenience for later maintenance and upgrade work, increasing the efficiency and security of application servers accessing the quantum network. Attached Figure Description

[0034] Figure 1 This is a structural diagram of the secure server of the present invention;

[0035] Figure 2 This is a data flow diagram of the present invention, showing the data flow from the Internet to the intranet machine;

[0036] Figure 3 This is a data flow diagram of the present invention, showing the data flow from an intranet machine to the Internet. Detailed Implementation

[0037] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0038] In current internet communication, if user A and user B communicate using an application server, such as WeChat, the information sent by user A will be transmitted to that application server. The server will then process the data, such as persisting it, before transmitting the information to user B. Since information transmission between user A and user B inevitably involves the application server, if this entire process is to be integrated into a quantum network, the application server will need to be adjusted accordingly. The specific process is as follows:

[0039] After connecting to the quantum network, user A and user B communicate using the application. The information sent by user A is quantum encrypted using a quantum key relayed from the quantum network to obtain ciphertext. This ciphertext is first sent to the application server via the Internet. For the application server to decrypt this ciphertext, it needs at least a corresponding encryption and decryption module. This is the problem we face. There are many applications on the market. Adding encryption and decryption modules to each application server connected to the quantum network would require a lot of effort in development and debugging.

[0040] This invention proposes a secure server based on a quantum key network that avoids many of these complex processes. The invention deploys the application server directly within the secure server, unifying the handling of other complex modules. After the ciphertext is transmitted to the secure server, the server decrypts it, sends the plaintext back to the application server, processes it, and then sends the information back to the secure server. The secure server then uses quantum encryption to obtain the ciphertext, which is finally transmitted to the recipient via the internet. Throughout this process, the application server does not need to concern itself with how the data is quantum encrypted or decrypted, making it much simpler and easier for programs to access the quantum network.

[0041] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0042] like Figure 1 As shown, this invention provides a secure server based on a quantum key network. The secure server includes an external network machine 1, an isolation board 2, and an internal network machine 3 connected sequentially. This design aims to completely isolate the internal network machine 3 from the outside world, further ensuring information security. The external network machine 1 handles communication with the outside world, while the internal network machine 3 is completely isolated by the isolation board 2 and has no connection to the outside world. Its information is transmitted entirely by the external network machine 1 through its network card, while the application server that needs to access the quantum key network is deployed in the internal network machine 3.

[0043] External network device 1 is used to split and reassemble the first UDP packet data transmitted by the sender via the Internet into a first ciphertext data packet, and transmit the first ciphertext data packet to isolation board 2; and to split and reassemble the second ciphertext data packet transmitted by isolation board 2 into a second UDP packet data and transmit it to the receiver via the Internet.

[0044] The external network machine 1 specifically includes: a first network card 11, a first data splitting and reassembling module 12, a first transmission module 13 and a second network card 14 connected in sequence, with the second network card 14 connected to the isolation plate 2;

[0045] The first network interface card 11 is used to receive the first UDP packet data transmitted by the sender via the Internet and send it to the first data splitting and reassembly module 12; and to transmit the second UDP packet data to the receiver via the Internet.

[0046] The first data splitting and reassembly module 12 is used to split the first UDP packet data into a first UDP packet header and first UDP data, obtain the sender address from the first UDP packet header, calculate the length of the sender address and the first UDP data to obtain the first message length, and reassemble the first message length, the sender address and the first UDP data into a first ciphertext data packet and send it to the first transmission module 13; and to split the second ciphertext data packet into a second message length, a receiver address and second UDP data, and reassemble the receiver address and the second UDP data into a second UDP packet data according to the UDP packet format and send it to the first network interface card 11;

[0047] The first transmission module 13 is used to transmit the first encrypted data packet to the second network card 14; and to transmit the second encrypted data packet received by the second network card 14 to the first data splitting and reassembly module 12;

[0048] The second network interface card 14 is used to transmit the first encrypted data packet to the isolation board 2; and to receive the second encrypted data packet transmitted from the isolation board 2 and send it to the first transmission module 13.

[0049] Isolation board 2 physically isolates external network machine 1 and internal network machine 3, completely isolating internal network machine 3 from the outside world. Isolation board 2 is used to transmit the first and second encrypted data packets; isolation board 2 can be an FPGA used to isolate external network machine 1 and internal network machine 3.

[0050] Internal network machine 3 is used to split and quantum decrypt the first ciphertext data packet transmitted from isolation board 2 to obtain plaintext data, parse the plaintext data to obtain plaintext message and recipient address, process the plaintext message, and quantum encrypt the processed plaintext message, then generate a second ciphertext data packet with the recipient address, and transmit the second ciphertext data packet to isolation board 2.

[0051] The internal components of the intranet machine 3 specifically include: a third network card 31, a second transmission module 32, a second data splitting and reassembly module 33, a quantum encryption and decryption module 34, and an application server 35. The third network card 31, the second transmission module 32, the second data splitting and reassembly module 33, and the application server 35 are connected in sequence. The third network card 31 is connected to the isolation board 2, and the second data splitting and reassembly module 33 is connected to the quantum encryption and decryption module 34.

[0052] The third network interface card 31 is used to receive the first encrypted data packet transmitted from the isolation board 2 and send it to the second transmission module 32; and to transmit the second encrypted data packet to the isolation board 2;

[0053] The second transmission module 32 is used to transmit the received first encrypted data packet to the second data splitting and reassembly module 33; and to transmit the second encrypted data packet to the third network card 31;

[0054] The second data splitting and reassembly module 33 is used to split the first ciphertext data packet into a first message length, a sender address, and first UDP data, and send the first UDP data to the quantum encryption and decryption module 34 for decryption to obtain plaintext data, and send the plaintext data to the application server 35; and to receive the plaintext message and the receiver address transmitted from the application server 35, send the plaintext message to the quantum encryption and decryption module 34 for encryption to obtain second UDP data, calculate the receiver address and the length of the second UDP data to obtain the second message length, and reassemble the second message length, the receiver address, and the second UDP data into a second ciphertext data packet and send it to the second transmission module 32;

[0055] The application server 35 is used to parse plaintext data to obtain plaintext messages and recipient addresses, process the plaintext messages, and send the processed plaintext messages and recipient addresses to the second data splitting and reassembly module 33.

[0056] The quantum encryption / decryption module 34 is used to decrypt the first UDP data to obtain plaintext data and send it to the second data splitting and reassembly module 33; and to encrypt the plaintext message to obtain the second UDP data and send it to the second data splitting and reassembly module 33.

[0057] like Figure 2 and Figure 3 As shown, the present invention also includes a method for operating a secure server based on a quantum key network, which describes how data flows from the Internet to the secure server and from the secure server to the Internet, including the following steps:

[0058] (1) The sender transmits the first UDP packet data to the external network machine 1 via the Internet. The external network machine 1 splits the first UDP packet data and reassembles it into the first encrypted data packet, and transmits the first encrypted data packet to the isolation board 2.

[0059] (2) Isolation board 2 transmits the first encrypted data packet to intranet machine 3. Intranet machine 3 splits and quantum decrypts the first encrypted data packet to obtain plaintext data. It then parses the plaintext data to obtain plaintext message and recipient address, and processes the plaintext message. Then, it quantum encrypts the processed plaintext message and generates a second encrypted data packet with the recipient address, and transmits the second encrypted data packet to isolation board 2.

[0060] (3) The isolation board 2 transmits the second encrypted data packet to the external network machine 1. The external network machine 1 splits the second encrypted data packet and reassembles it into a second UDP packet data packet, which is then transmitted to the receiver via the Internet.

[0061] The specific process of step (1) is as follows:

[0062] The sender transmits the first UDP packet data to the first network interface card 11 of the external network machine 1 via the Internet. The first network interface card 11 sends the first UDP packet data to the first data splitting and reassembly module 12. The first data splitting and reassembly module 12 splits the first UDP packet data into a first UDP packet header and first UDP data. It obtains the sender address from the first UDP packet header, calculates the length of the sender address and the length of the first UDP data to obtain the first message length, and reassembles the first message length, the sender address, and the first UDP data into a first encrypted data packet and sends it to the first transmission module 13. The first transmission module 13 transmits the first encrypted data packet to the second network interface card 14, and the second network interface card 14 transmits the first encrypted data packet to the isolation board 2.

[0063] The specific process of step (2) is as follows:

[0064] 1) Isolation board 2 transmits the first encrypted data packet to the third network card 31 of the intranet machine 3. The third network card 31 sends the first encrypted data packet to the second transmission module 32. The second transmission module 32 transmits the received first encrypted data packet to the second data splitting and reassembly module 33. The second data splitting and reassembly module 33 splits the first encrypted data packet into a first message length, a sender address, and first UDP data, and sends the first UDP data to the quantum encryption and decryption module 34 for decryption to obtain plaintext data. The plaintext data is then sent to the application server 35. The application server 35 parses the plaintext data to obtain the plaintext message and the receiver address, and processes the plaintext message. This processing includes message persistence or other custom operations, thus completing the one-way data flow.

[0065] 2) The application server 35 sends the processed plaintext message and the recipient address to the second data splitting and reassembly module 33; the second data splitting and reassembly module 33 receives the transmitted plaintext message and the recipient address, and sends the plaintext message to the quantum encryption and decryption module 34 for encryption to obtain the second UDP data, calculates the recipient address and the length of the second UDP data to obtain the second message length, and reassembles the second message length, the recipient address and the second UDP data into a second ciphertext data packet and sends it to the second transmission module 32; the second transmission module 32 transmits the second ciphertext data packet to the third network card 31, and the third network card 31 transmits the second ciphertext data packet to the isolation board 2;

[0066] The specific process of step (3) is as follows:

[0067] Isolation board 2 transmits the second encrypted data packet to the second network card 14 of external network machine 1. The second network card 14 sends the second encrypted data packet to the first transmission module 13. The first transmission module 13 transmits the received second encrypted data packet to the first data splitting and reassembling module 12. The first data splitting and reassembling module 12 splits the second encrypted data packet into a second message length, a receiver address, and second UDP data. It then reassembles the receiver address and second UDP data into a second UDP packet according to the UDP packet format and sends it to the first network card 11. The first network card 11 transmits the second UDP packet to the receiver via the Internet. At this point, the entire data encryption and decryption process of the secure server is completed.

[0068] The secure server proposed in this invention deploys the application server on an intranet machine within the secure server, providing extremely high security and preventing internet data attacks from reaching the intranet machine. Simultaneously, it improves the efficiency of the application server's access to the quantum network, ensures data security, and also provides possibilities for future version upgrades and maintenance.

Claims

1. A secure server based on a quantum key network, characterized in that: The security server includes an external network machine, an isolation board, and an internal network machine connected in sequence. The external network machine is used to split and reassemble the first UDP packet data transmitted by the sender via the Internet into a first encrypted data packet, and transmit the first encrypted data packet to the isolation board; And the second encrypted data packet transmitted from the isolation board is split and reassembled into a second UDP packet data and transmitted to the receiver via the Internet; The isolation board is used to transmit the first and second encrypted data packets; The intranet machine is used to split and quantum decrypt the first encrypted data packet transmitted from the isolation board to obtain plaintext data, parse the plaintext data to obtain plaintext messages and the recipient's address, and process the plaintext messages; The plaintext message is then quantum encrypted, and a second ciphertext data packet is generated by combining it with the recipient's address. This second ciphertext data packet is then transmitted to the isolation board. The external network device includes a first network card, a first data splitting and reassembling module, a first transmission module, and a second network card connected in sequence, with the second network card connected to an isolation board; The first network interface card is used to receive the first UDP packet data transmitted by the sender via the Internet and send it to the first data splitting and reassembly module; And transmit the second UDP packet data to the receiver via the Internet; The first data splitting and reassembling module is used to split the first UDP packet data into a first UDP packet header and first UDP data, obtain the sender address from the first UDP packet header, calculate the length of the sender address and the first UDP data to obtain the first message length, and reassemble the first message length, the sender address and the first UDP data into a first encrypted data packet and send it to the first transmission module. And the second encrypted data packet is split into a second message length, a receiver address and second UDP data, and the receiver address and second UDP data are reassembled into second UDP data according to the UDP packet format and sent to the first network card; The first transmission module is used to transmit the first encrypted data packet to the second network interface card (NIC); and to transmit the second encrypted data packet received by the second NIC to the first data splitting and reassembly module; The second network interface card is used to transmit the first encrypted data packet to the isolation board; and to receive the second encrypted data packet transmitted from the isolation board and send it to the first transmission module; The intranet machine includes a third network card, a second transmission module, a second data splitting and reassembly module, a quantum encryption and decryption module, and an application server. The third network card, the second transmission module, the second data splitting and reassembly module, and the application server are connected in sequence. The third network card is connected to the isolation board, and the second data splitting and reassembly module is connected to the quantum encryption and decryption module. The third network interface card is used to receive the first encrypted data packet transmitted from the isolation board and send it to the second transmission module; And transmit the second encrypted data packet to the isolation board; The second transmission module is used to transmit the received first encrypted data packet to the second data splitting and reassembly module; And transmit the second encrypted data packet to the third network card; The second data splitting and reassembly module is used to split the first ciphertext data packet into a first message length, a sender address, and first UDP data, and send the first UDP data to the quantum encryption and decryption module for decryption to obtain plaintext data, and send the plaintext data to the application server; and to receive the plaintext message and the receiver address transmitted from the application server, send the plaintext message to the quantum encryption and decryption module for encryption to obtain second UDP data, calculate the receiver address and the length of the second UDP data to obtain the second message length, and reassemble the second message length, the receiver address, and the second UDP data into a second ciphertext data packet and send it to the second transmission module; The application server is used to parse plaintext data to obtain plaintext messages and recipient addresses, and to process the plaintext messages. And send the processed plaintext message and the recipient's address to the second data splitting and reassembly module; The quantum encryption / decryption module is used to decrypt the first UDP data to obtain plaintext data and send it to the second data splitting and reassembly module; And encrypt the plaintext message to obtain the second UDP data and send it to the second data splitting and reassembly module.

2. A secure server based on a quantum key network according to claim 1, characterized in that: The isolation board is an FPGA, used to isolate external network machines and internal network machines.

3. A method for operating a security server as described in claim 1, characterized in that, Includes the following steps: (1) The sender transmits the first UDP packet data to the external network machine via the Internet. The external network machine splits and reassembles the first UDP packet data into the first encrypted data packet and transmits the first encrypted data packet to the isolation board. (2) The isolation board transmits the first encrypted data packet to the intranet machine. The intranet machine splits and decrypts the first encrypted data packet to obtain plaintext data. It then parses the plaintext data to obtain the plaintext message and the recipient's address, and processes the plaintext message. Then, the processed plaintext message is quantum encrypted, and a second ciphertext data packet is generated with the recipient's address. The second ciphertext data packet is then transmitted to the isolation board. (3) The isolation board transmits the second encrypted data packet to the external network machine, which then splits and reassembles the second encrypted data packet into a second UDP packet data packet and transmits it to the receiver via the Internet.

4. The method for operating a secure server according to claim 3, characterized in that: The specific process of step (1) is as follows: The sender transmits the first UDP packet data to the first network card of the external network machine via the Internet, and the first network card sends the first UDP packet data to the first data splitting and reassembly module; The first data splitting and reassembly module splits the first UDP packet data into a first UDP packet header and first UDP data. It obtains the sender address from the first UDP packet header, calculates the length of the sender address and the length of the first UDP data to obtain the first message length, and reassembles the first message length, the sender address, and the first UDP data into a first encrypted data packet and sends it to the first transmission module. The first transmission module transmits the first encrypted data packet to the second network card, and the second network card transmits the first encrypted data packet to the isolation board.

5. The method for operating a secure server according to claim 3, characterized in that: The specific process of step (2) is as follows: 1) The isolation board transmits the first encrypted data packet to the third network card of the intranet machine, and the third network card sends the first encrypted data packet to the second transmission module; The second transmission module transmits the received first encrypted data packet to the second data splitting and reassembly module; The second data splitting and reassembly module splits the first ciphertext data packet into a first message length, a sender address, and first UDP data. The first UDP data is then sent to the quantum encryption and decryption module for decryption to obtain plaintext data, which is then sent to the application server. The application server parses the plaintext data to obtain the plaintext message and the receiver address, and processes the plaintext message. 2) The application server sends the processed plaintext message and the recipient's address to the second data splitting and reassembly module; The second data splitting and reassembly module receives the transmitted plaintext message and the recipient address, and sends the plaintext message to the quantum encryption and decryption module for encryption to obtain the second UDP data. It calculates the recipient address and the length of the second UDP data to obtain the second message length, and reassembles the second message length, the recipient address, and the second UDP data into a second ciphertext data packet and sends it to the second transmission module. The second transmission module transmits the second encrypted data packet to the third network card, and the third network card transmits the second encrypted data packet to the isolation board.

6. The method for operating a secure server according to claim 3, characterized in that: The specific process of step (3) is as follows: The isolation board transmits the second encrypted data packet to the second network card of the external network machine. The second network card sends the second encrypted data packet to the first transmission module. The first transmission module transmits the received second encrypted data packet to the first data splitting and reassembling module. The first data splitting and reassembly module splits the second encrypted data packet into a second message length, a receiver address, and second UDP data. It then reassembles the receiver address and second UDP data into a second UDP packet according to the UDP packet format and sends it to the first network interface card (NIC). The first NIC then transmits the second UDP packet to the receiver via the Internet.

Citation Information

Patent Citations

  • Service user terminal and secure transmission system and method

    CN114499849A

  • Communication method, extranet quantum gateway, intranet quantum gateway and system

    CN114826589A

  • Audio and video communication method for global quantum security

    CN115051857A