基于Kerberos协议的量子密钥迁移方法、系统及介质
By using the Kerberos protocol for authentication and data encryption, the security issues in the quantum key transfer process are resolved, enabling secure transfer and confidential communication of quantum keys between different devices, thus ensuring the security and efficiency of communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI CIRCULATION QUANTUM TECH CO LTD
- Filing Date
- 2023-07-03
- Publication Date
- 2026-04-21
AI Technical Summary
In existing technologies, quantum keys are not secure enough during migration, making them easy to be stolen or tampered with, and thus unable to achieve quantum secure communication between business application terminals and different convergence side security encryption devices.
The Kerberos protocol is used for authentication and data encryption. The identity information of the security encryption device on the aggregation side is verified through the authentication server. The identity is authenticated using tickets, and the key index QID is reassigned after successful authentication to achieve secure migration of quantum keys.
To ensure the security of quantum keys, prevent forgery or tampering, enable secure transmission of quantum keys between different devices, improve communication efficiency and speed, and defend against quantum computer attacks.
Smart Images

Figure CN116760540B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of quantum secure communication, and more specifically, to a quantum key transfer method, system, and medium based on the Kerberos protocol. Background Technology
[0002] Traditional encryption methods primarily rely on mathematical algorithms, such as public-key encryption and symmetric encryption algorithms. However, with the rapid development of computer and communication technologies, traditional encryption algorithms face the risk of being attacked by quantum computers. Quantum computers possess powerful computing capabilities, enabling them to crack widely used encryption algorithms in a short time, posing a threat to the security of traditional encrypted communication. To address this security challenge, quantum key distribution (QKD) technology has emerged. QKD utilizes the principles and properties of quantum mechanics to distribute keys through the transmission and measurement of qubits. The principles of quantum mechanics restrict the measurement and replication of quantum states, thus preventing potential eavesdroppers from obtaining a copy of the key undetected. This allows QKD to provide higher security against quantum computer attacks. Therefore, quantum keys are used for the encrypted transmission of business data, enabling quantum-secure communication between business application terminals and secure encryption devices on the aggregation side.
[0003] However, when a business application terminal with a quantum key moves, there may be situations where it needs to communicate with another aggregation-side secure encryption device. In this case, the secure encryption device does not possess the corresponding quantum key for the business application terminal, making quantum-encrypted communication impossible. Therefore, it is necessary to migrate the quantum key to enable quantum-secure communication between the business application terminal and other aggregation-side secure encryption devices. To ensure secure quantum key migration, a robust authentication and data encryption mechanism is required. The Kerberos protocol, as a network authentication protocol, provides a secure authentication solution. It can prevent unauthorized users from accessing system resources and ensure the confidentiality and integrity of communication data, preventing data theft or tampering. Summary of the Invention
[0004] In view of the shortcomings of the prior art, the purpose of this invention is to provide a quantum key transfer method, system and medium based on the Kerberos protocol.
[0005] According to the present invention, a quantum key transfer method based on the Kerberos protocol is provided, the method comprising the following steps:
[0006] Step S1: During migration, the business application terminal sends a request to the aggregation-side security encryption device A to request quantum-secure communication with the aggregation-side security encryption device B;
[0007] Step S2: The aggregation-side security encryption device A sends its identity information to the authentication server. The authentication server verifies the identity information and returns a ticket to the aggregation-side security encryption device A based on the information from the aggregation-side security encryption device B. The aggregation-side security encryption device A uses the ticket to authenticate its identity with the aggregation-side security encryption device B, thus completing the authentication process.
[0008] Step S3: The aggregation-side security encryption device B reallocates the key index QID to the business application terminal and sends the encryption key to the aggregation-side security encryption device A. The aggregation-side security encryption device A decrypts the received key and uses it to encrypt the quantum key, which is then sent to the aggregation-side security encryption device B for quantum key migration.
[0009] Step S4: The business application terminal binds the quantum key to the newly assigned key index QID, completes identity authentication with the aggregation-side security encryption device B, and establishes quantum secure communication.
[0010] Preferably, step S1 includes the following steps:
[0011] Step S1.1: The business application terminal initiates a migration request and a quantum key migration application;
[0012] Step S1.2: The aggregation-side security encryption device A responds to the quantum key migration instruction request, verifies the account identity information of the business application terminal, and agrees to the quantum key request initiated by the business application terminal if the account information matches that on the aggregation-side security encryption device A.
[0013] Preferably, step S2 includes the following steps:
[0014] Step S2.1: The aggregation-side security encryption device A sends its own device configuration information, the username of the aggregation-side security encryption device B, and the timestamp encrypted with the hash value corresponding to its own key to the authentication server;
[0015] Step S2.2: The authentication server queries whether the user is in the whitelist based on the configuration information sent by the aggregation-side security encryption device A. If so, it queries the corresponding hash value and uses the hash value to encrypt a randomly generated string. At the same time, it uses the special hash value in the authentication server to encrypt the user information TGT of the aggregation-side security encryption device A. The encryption result and the randomly generated string are returned to the aggregation-side security encryption device A.
[0016] Step S2.3: After receiving the information returned by the authentication server, the aggregation-side security encryption device A decrypts the string, uses the value to encrypt its own user information and current timestamp, and sends the encryption result and TGT to the authentication server.
[0017] Step S2.4: After obtaining the information, the authentication server decrypts and compares whether the user information contained in the TGT is consistent with the information sent by the aggregation side security encryption device A. If they are consistent, the authentication with the aggregation side security encryption device A is successful. The server then re-encrypts a random string using the string mentioned above and uses the hash value corresponding to the aggregation side security encryption device B to encrypt the information ticket of the aggregation side security encryption device A. The encryption result is then returned to the aggregation side security encryption device.
[0018] Step S2.5: The aggregation-side security encryption device A decrypts the received information, obtains a new string, uses the string to encrypt its own information and timestamp, and sends this encryption result along with the ticket to the aggregation-side security encryption device B;
[0019] Step S2.6: The aggregation-side security encryption device B decrypts the received information and verifies whether the aggregation-side security encryption device A is trustworthy. If it is trustworthy, it returns confirmation information to the aggregation-side security encryption device A. At this point, the aggregation-side security encryption device A and the aggregation-side security encryption device B have successfully completed identity authentication.
[0020] Preferably, the ticket sent by the authentication server to the aggregation-side security encryption device A includes information about encrypting the aggregation-side security encryption device A using the hash value corresponding to the aggregation-side security encryption device B, a random string, and an end time.
[0021] Preferably, step S3 includes the following steps:
[0022] Step S3.1: The aggregation-side security encryption device B sends the key index QID reassigned to the business application terminal and the key that needs to be encrypted and migrated to the aggregation-side security encryption device A;
[0023] Step S3.2: The aggregation-side security encryption device A sends the key index to the business application terminal, encrypts the quantum key that needs to be migrated using the received key, and sends it to the aggregation-side security encryption device B;
[0024] Step S3.3: The convergence-side security encryption device B binds the received quantum key with the key index QID and returns confirmation information to the convergence-side security encryption device A, thus completing the quantum key migration.
[0025] Preferably, the method includes a business application terminal, a convergence-side security encryption device A, an authentication server, and a convergence-side security encryption device B;
[0026] The business application terminal initiates a quantum key migration request;
[0027] The convergence-side security encryption device A responds to the quantum key migration request, searches for the corresponding quantum key according to the key index of the business application terminal, migrates the quantum key to the convergence-side security encryption device B, and performs identity authentication between the convergence-side security encryption device A and the authentication server through the authentication server, thereby performing identity authentication between the convergence-side security encryption device A and the convergence-side security encryption device B.
[0028] The authentication server performs identity authentication with the aggregation-side security encryption device A, and sends a ticket to the aggregation-side security encryption device A based on the information from the aggregation-side security encryption device B, thereby performing identity authentication between the aggregation-side security encryption device A and the aggregation-side security encryption device B, and exchanging information between the two to complete the quantum key transfer.
[0029] The aforementioned convergence-side security encryption device B is the destination of quantum key transfer. The quantum key from convergence-side security encryption device A is transferred to convergence-side security encryption device B. Convergence-side security encryption device B will assign a new key index QID to the business application terminal. First, the key index QID is sent to convergence-side security encryption device A, and then convergence-side security encryption device A sends the key index QID to the business application terminal.
[0030] Preferably, the Kerberos protocol is used to authenticate the identities of the convergence-side security encryption device A and the convergence-side security encryption device B and to perform quantum key transfer.
[0031] The present invention also provides a quantum key transfer system based on the Kerberos protocol, the system performing the quantum key transfer method based on the Kerberos protocol as described above, the system comprising:
[0032] Business application terminal: A terminal device used in a specific business scenario to perform specific business operations and data processing;
[0033] The convergence-side security encryption device includes key management, identity registration and authentication, and data encryption.
[0034] Authentication server: Responsible for handling identity authentication requests, including identity authentication, identity authentication authorization, and user account management.
[0035] Preferably, the business application terminal includes a computer, smartphone, tablet computer, or other device with computing and communication capabilities.
[0036] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the quantum key transfer method based on the Kerberos protocol described above.
[0037] Compared with the prior art, the present invention has the following beneficial effects:
[0038] 1. This invention applies the Kerberos protocol to quantum key transfer to achieve secure quantum key transfer, ensuring the security of quantum keys and effectively resisting various attacks, including cryptographic cracking, replay attacks and man-in-the-middle attacks, preventing quantum keys from being forged or tampered with.
[0039] 2. The quantum key transfer based on the Kerberos protocol described in this invention is only for quantum key transfer and is compatible with traditional symmetric encryption algorithms;
[0040] 3. The quantum key transfer based on the Kerberos protocol described in this invention provides a robust authentication and key management mechanism to ensure the authentication of both communicating parties and the security of their keys;
[0041] 4. By using the Kerberos protocol, quantum keys can be securely transmitted between communicating parties, preventing security threats such as man-in-the-middle attacks, password cracking, and data tampering. The Kerberos protocol uses a pre-shared key method for authentication, which means that the communicating parties do not need to frequently perform public key encryption and decryption operations, thereby improving the efficiency and speed of communication.
[0042] 5. The Kerberos protocol of this invention has been widely applied and is mature. It can leverage existing technological foundations and experience, and has a high degree of maturity and reliability. Quantum keys are resistant to quantum attacks and have unconditional security. Through quantum key transfer, quantum secure communication can be achieved in different devices, making the application of quantum keys more flexible and widespread. Attached Figure Description
[0043] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:
[0044] Figure 1 This is a flowchart illustrating the principle of the Kerberos protocol in this invention.
[0045] Figure 2 This is a flowchart of the quantum key transfer process based on the Kerberos protocol of this invention. Detailed Implementation
[0046] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the scope of protection of the present invention.
[0047] Example 1:
[0048] According to the present invention, a quantum key transfer method based on the Kerberos protocol is provided, the method comprising the following steps:
[0049] Step S1: During migration, the business application terminal sends a request to the aggregation-side security encryption device A to request quantum-secure communication with the aggregation-side security encryption device B;
[0050] Step S1.1: The business application terminal initiates a migration request and a quantum key migration application;
[0051] Step S1.2: The aggregation-side security encryption device A responds to the quantum key migration instruction request, verifies the account identity information of the business application terminal, and agrees to the quantum key request initiated by the business application terminal if the account information matches that on the aggregation-side security encryption device A.
[0052] Step S2: The aggregation-side security encryption device A sends its identity information to the authentication server. The authentication server verifies the identity information and returns a ticket to the aggregation-side security encryption device A based on the information from the aggregation-side security encryption device B. The aggregation-side security encryption device A uses the ticket to authenticate its identity with the aggregation-side security encryption device B, thus completing the authentication process.
[0053] Step S2.1: The aggregation-side security encryption device A sends its own device configuration information, the username of the aggregation-side security encryption device B, and the timestamp encrypted with the hash value corresponding to its own key to the authentication server;
[0054] Step S2.2: The authentication server queries whether the user is in the whitelist based on the configuration information sent by the aggregation-side security encryption device A. If so, it queries the corresponding hash value and uses the hash value to encrypt a randomly generated string. At the same time, it uses the special hash value in the authentication server to encrypt the user information TGT of the aggregation-side security encryption device A. The encryption result and the randomly generated string are returned to the aggregation-side security encryption device A.
[0055] Step S2.3: After receiving the information returned by the authentication server, the aggregation-side security encryption device A decrypts the string, uses the value to encrypt its own user information and current timestamp, and sends the encryption result and TGT to the authentication server.
[0056] Step S2.4: After obtaining the information, the authentication server decrypts and compares whether the user information contained in the TGT is consistent with the information sent by the aggregation side security encryption device A. If they are consistent, the authentication with the aggregation side security encryption device A is successful. The server then re-encrypts a random string using the string mentioned above and uses the hash value corresponding to the aggregation side security encryption device B to encrypt the information ticket of the aggregation side security encryption device A. The encryption result is then returned to the aggregation side security encryption device.
[0057] Step S2.5: The aggregation-side security encryption device A decrypts the received information, obtains a new string, uses the string to encrypt its own information and timestamp, and sends this encryption result along with the ticket to the aggregation-side security encryption device B;
[0058] Step S2.6: The aggregation-side security encryption device B decrypts the received information and verifies whether the aggregation-side security encryption device A is trustworthy. If it is trustworthy, it returns confirmation information to the aggregation-side security encryption device A. At this point, the aggregation-side security encryption device A and the aggregation-side security encryption device B have successfully completed identity authentication.
[0059] The ticket sent by the authentication server to the aggregation-side secure encryption device A contains information encrypted using the hash value corresponding to the aggregation-side secure encryption device B, a random string, and an end time.
[0060] Step S3: The aggregation-side security encryption device B reallocates the key index QID to the business application terminal and sends the encryption key to the aggregation-side security encryption device A. The aggregation-side security encryption device A decrypts the received key and uses it to encrypt the quantum key, which is then sent to the aggregation-side security encryption device B for quantum key migration.
[0061] Step S3.1: The aggregation-side security encryption device B sends the key index QID reassigned to the business application terminal and the key that needs to be encrypted and migrated to the aggregation-side security encryption device A;
[0062] Step S3.2: The aggregation-side security encryption device A sends the key index to the business application terminal, encrypts the quantum key that needs to be migrated using the received key, and sends it to the aggregation-side security encryption device B;
[0063] Step S3.3: The convergence-side security encryption device B binds the received quantum key with the key index QID and returns confirmation information to the convergence-side security encryption device A, thus completing the quantum key migration.
[0064] Step S4: The business application terminal binds the quantum key to the newly assigned key index QID, completes identity authentication with the aggregation-side security encryption device B, and establishes quantum secure communication.
[0065] The method includes a business application terminal, a convergence-side security encryption device A, an authentication server, and a convergence-side security encryption device B;
[0066] The business application terminal initiates a quantum key migration request;
[0067] The aggregation-side security encryption device A responds to the quantum key migration request, looks up the corresponding quantum key according to the key index of the business application terminal, migrates the quantum key to the aggregation-side security encryption device B, and performs identity authentication between the aggregation-side security encryption device A and the authentication server through the authentication server, and then performs identity authentication between the aggregation-side security encryption device A and the aggregation-side security encryption device B.
[0068] The authentication server authenticates the identity with the aggregation-side security encryption device A, and sends a ticket to the aggregation-side security encryption device A based on the information from the aggregation-side security encryption device B. This process facilitates identity authentication between the aggregation-side security encryption device A and the aggregation-side security encryption device B, and enables information exchange between the two devices to complete the quantum key transfer.
[0069] The aggregation-side security encryption device B is the destination for quantum key migration. It migrates the quantum key from aggregation-side security encryption device A to aggregation-side security encryption device B. Aggregation-side security encryption device B will assign a new key index QID to the business application terminal. It will first send the key index QID to aggregation-side security encryption device A, and then aggregation-side security encryption device A will send the key index QID to the business application terminal.
[0070] The Kerberos protocol is used to authenticate the identities of convergence-side security encryption device A and convergence-side security encryption device B and to perform quantum key transfer.
[0071] This invention also provides a quantum key transfer system based on the Kerberos protocol, which executes the quantum key transfer method based on the Kerberos protocol as described above. The system includes:
[0072] Business application terminal: A terminal device used in a specific business scenario to perform specific business operations and data processing;
[0073] The convergence-side security encryption device includes key management, identity registration and authentication, and data encryption.
[0074] Authentication server: Responsible for handling identity authentication requests, including identity authentication, identity authentication authorization, and user account management.
[0075] Business application terminals include computers, smartphones, tablets, or other devices with computing and communication capabilities.
[0076] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the quantum key transfer method based on the Kerberos protocol described above.
[0077] Example 2:
[0078] Because existing key migration methods are relatively simple in design, keys are easily leaked or stolen during the migration and transmission process, potentially causing losses to users. In practice, existing key migration methods often suffer from insecure key migration and susceptibility to leakage.
[0079] To address the aforementioned issues, this invention provides a quantum key transfer method based on the Kerberos protocol, comprising: a key transfer application step: during migration, the application terminal needs to submit a transfer application to the aggregation-side encryption device A, requesting the transfer of the quantum key to the aggregation-side encryption device B; an authentication step: based on the application terminal's request, the aggregation-side encryption device A needs to authenticate itself with the aggregation-side security encryption device B through a third-party authentication server; firstly, the aggregation-side encryption device A sends its identity information to the authentication server for authentication. After successful authentication via information comparison, the authentication server generates a ticket for the aggregation-side security encryption device A, which then uses this ticket to authenticate itself with the aggregation-side security encryption device B; and a quantum key transfer step: the aggregation-side security encryption device B assigns a new QID to the application terminal and sends it to the aggregation-side security encryption device A with an encryption key. The aggregation-side security encryption device A uses this key to encrypt the quantum key and successfully transfers it to the aggregation-side security encryption device B. The quantum key on the aggregation-side security encryption device A becomes invalid, and the application terminal's quantum key is bound to the QID, establishing quantum secure communication with the aggregation-side security encryption device B. This invention utilizes the Kerberos protocol for authentication between secure encryption devices on the aggregation side and to encrypt quantum keys to achieve quantum key migration. It is mainly used for quantum secure communication between business application terminals and different secure encryption devices on the aggregation side during migration, realizing secure quantum key migration and establishing quantum secure communication between different devices, thus preventing business data leakage and data tampering.
[0080] The method should include a business application terminal, a convergence-side security encryption device A, an authentication server, and a convergence-side security encryption device B. The method includes:
[0081] The business application terminal initiates a quantum key migration request;
[0082] In response to the quantum key migration request, the aggregation-side security encryption device A searches for the corresponding quantum key based on the key index of the application terminal, migrates the quantum key to the aggregation-side security encryption device B, and completes identity authentication between aggregation-side security encryption device A and the authentication server through an authentication server, thereby achieving identity authentication between aggregation-side security encryption device A and aggregation-side security encryption device B. After successful identity authentication, aggregation-side security encryption device B assigns a new key index QID to the application terminal and sends the key index QID to aggregation-side security encryption device A, which then sends the key index QID to the application terminal.
[0083] The main steps of the method include:
[0084] Application steps for business application terminals: When migrating, business application terminals need to send a request to the aggregation-side security encryption device A to request quantum secure communication with the aggregation-side security encryption device B.
[0085] Identity authentication steps: The aggregation-side security encryption device A sends identity information to the authentication server. The authentication server verifies the identity information and returns a ticket to the aggregation-side security encryption device A based on the information from the aggregation-side security encryption device B. The aggregation-side security encryption device A uses this ticket to authenticate with the aggregation-side security encryption device B, thus completing the identity authentication process.
[0086] Quantum key migration steps: The aggregation-side security encryption device B reassigns the key index QID to the application terminal and simultaneously sends the encryption key to the aggregation-side security encryption device A. Aggregation-side security encryption device A decrypts the received key and uses it to encrypt the quantum key before sending it to aggregation-side security encryption device B, thus completing the quantum key migration.
[0087] Steps to establish quantum secure communication: The business application terminal binds the quantum key to the newly assigned key index QID, completes identity authentication with the aggregation-side security encryption device B, and establishes quantum secure communication.
[0088] The above-mentioned application steps for business application terminals include:
[0089] The business application terminal initiates a migration request and a quantum key migration application;
[0090] The aggregation-side security encryption device A responds to the quantum key migration instruction request by verifying the account identity information of the business application terminal. If the account information matches that on the aggregation-side security encryption device A, the device agrees to the quantum key request initiated by the business application terminal.
[0091] The identity authentication process includes:
[0092] Step A1: The aggregation-side security encryption device A sends its own device configuration information, the username of the aggregation-side security encryption device B, and the timestamp encrypted with the hash value corresponding to its own key to the authentication server;
[0093] Step A2: The authentication server queries whether the user is in the whitelist based on the configuration information sent by the aggregation-side security encryption device A. If so, it queries the corresponding hash value and uses the hash value to encrypt a randomly generated string. At the same time, it uses a special hash value in the authentication server to encrypt the user information (TGT) of the aggregation-side security encryption device A. The encryption result and the randomly generated string are returned to the aggregation-side security encryption device A.
[0094] Step A3: After receiving the information returned by the authentication server, the aggregation-side security encryption device A decrypts the string, uses the value to encrypt its own user information and current timestamp, and sends the encryption result and TGT to the authentication server.
[0095] Step A4: After obtaining the information, the authentication server decrypts and compares whether the user information contained in the TGT is consistent with the information sent by the aggregation-side security encryption device A. If they are consistent, the authentication with the aggregation-side security encryption device A is successful. The server then re-encrypts a random string using the string mentioned above and uses the hash value corresponding to the aggregation-side security encryption device B to encrypt the information (ticket) of the aggregation-side security encryption device A. The encryption result is then returned to the aggregation-side security encryption device.
[0096] Step A5: The aggregation-side security encryption device A decrypts the received information, obtains a new string, uses the string to encrypt its own information and timestamp, and sends this encryption result along with the ticket to the aggregation-side security encryption device B;
[0097] Step A6: The aggregation-side security encryption device B decrypts the received information and verifies whether the aggregation-side security encryption device A is trustworthy. If it is trustworthy, it returns confirmation information to the aggregation-side security encryption device A. At this point, the aggregation-side security encryption device A and the aggregation-side security encryption device B have successfully completed identity authentication.
[0098] The quantum key transfer step includes:
[0099] Step B1: The aggregation-side security encryption device B sends the key index QID reassigned to the business application terminal and the key that needs to be encrypted and migrated to the aggregation-side security encryption device A;
[0100] Step B2: The aggregation-side security encryption device A sends the key index to the business application terminal, encrypts the quantum key that needs to be migrated using the received key, and sends it to the aggregation-side security encryption device B.
[0101] Step B3: The convergence-side security encryption device B binds the received quantum key with the key index QID and returns confirmation information to the convergence-side security encryption device A, thus completing the quantum key migration.
[0102] Those skilled in the art can understand this embodiment as a more specific description of Embodiment 1.
[0103] Those skilled in the art will understand that, besides implementing the system and its various devices, modules, and units provided by this invention in the form of purely computer-readable program code, the same functions can be achieved entirely through logical programming of the method steps, making the system and its various devices, modules, and units of this invention function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, the system and its various devices, modules, and units provided by this invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be considered as structures within the hardware component; alternatively, the devices, modules, and units for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0104] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.