5g network element security communication method and device based on quantum technology, and medium
Patent Information
- Application Number
- CN202310876595.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-17
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-07-17
AI Technical Summary
但上述这种提前预置方式,会存在CA证书到期和/或密钥泄露的问题,一旦发生CA证书到期和/或密钥泄露,也会导致通信安全存在隐患
Smart Images

Figure CN116782213B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technology, and in particular to 5G network element secure communication methods, devices and media based on quantum technology. Background Technology
[0002] In 5G communication networks, the core network is typically deployed centrally by province or region, while the access network is usually distributed closer to the user. Furthermore, in 5G private industry networks, users often request that User Plane Function (UPF) network elements be deployed within the enterprise campus, placing the 5G core network in the operator domain and the UPF network elements in the user domain, such as in Mobile Edge Computing (MEC). However, this deployment method can easily lead to security vulnerabilities during transmission between the 5G core network and the UPF.
[0003] To address the aforementioned issues, the 5G core network and MEC typically employ protocols such as Hypertext Transfer Protocol Secure (HTTPS) or Internet Protocol Security (IPSec) to achieve identity authentication and secure communication between network elements.
[0004] This authentication mechanism requires pre-configuring a Certificate Authority (CA) certificate and / or key for each network element. For example, the authentication key and data encryption key required within the network element must be pre-configured. During communication, a new key is needed for each session to ensure security, achieving one-time key secure communication. However, this pre-configuration method is susceptible to CA certificate expiration and / or key leakage. Expiration of the CA certificate and / or key leakage can lead to communication security vulnerabilities. Summary of the Invention
[0005] This application provides a secure communication method for 5G network elements based on quantum technology to ensure the security of communication.
[0006] The first aspect provides a secure communication method for 5G network elements based on quantum technology, including:
[0007] The 5G core network equipment receives a communication message from the MEC, wherein the communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key. The first communication key is obtained by the MEC selecting a first effective quantum key from its own stored effective quantum keys according to the service communication data and converting the first effective quantum key.
[0008] The 5G core network device obtains a second effective quantum key corresponding to the key identification information from its own stored effective quantum keys according to the key identification information of the first communication key, and converts the second effective quantum key into a second communication key;
[0009] The 5G core network equipment uses the second communication key to perform a decryption operation on the encrypted service communication data.
[0010] In this embodiment, the 5G core network device receives a communication message from the MEC. This communication message includes at least key identification information of a first communication key and service communication data encrypted using that first communication key. The first communication key is obtained by the MEC from its stored valid quantum keys based on the service communication data, and then converting the first valid quantum key. The 5G core network device, based on the key identification information of the first communication key, obtains a second valid quantum key corresponding to the key identification information from its stored valid quantum keys, and converts the second valid quantum key into a second communication key. Finally, the second communication key is used to decrypt the encrypted service communication data. Because valid quantum keys can be selected based on different encrypted service communication data during communication, and the selected valid quantum key can be converted into a communication key, and then used to decrypt the data, compared to existing technologies, this method combines the characteristics of quantum keys and allows for flexible transformation of the selected valid quantum key, further preventing key leakage and thus improving the communication security between the 5G core network device and the MEC.
[0011] Optionally, before the 5G core network equipment receives communication messages from the MEC, it further includes:
[0012] The 5G core network equipment encodes the generated initial key to obtain a quantum key;
[0013] The 5G core network equipment sends the quantum key to the MEC;
[0014] The 5G core network device receives a first measurement basis vector sent by the MEC, compares the first measurement basis vector with a second measurement basis vector to obtain a candidate quantum key with consistent measurement basis vector bits, and sends the candidate quantum key to the MEC; wherein, the first measurement basis vector is the measurement basis vector used by the MEC to decode the quantum key, and the second measurement basis vector is the measurement basis vector used by the 5G core network device to encode the quantum key;
[0015] The 5G core network equipment receives a portion of the candidate quantum keys selected by the MEC from the candidate quantum keys, and determines the effective quantum key based on the portion of the candidate quantum keys;
[0016] The 5G core network equipment assigns key identification information to the effective quantum key and stores the effective quantum key;
[0017] The 5G core network device sends a valid quantum key confirmation message to the MEC based on the valid quantum key, so that the MEC stores the determined valid quantum key based on the valid quantum key confirmation message and assigns key identification information to the valid quantum key.
[0018] Optionally, the 5G core network equipment determines the effective quantum key based on the candidate partial quantum key, including:
[0019] The 5G core network equipment will sample and detect some of the candidate quantum keys.
[0020] When the sampling detection of the partial candidate quantum keys passes, the 5G core network equipment deletes the partial candidate quantum keys and uses the remaining candidate quantum keys as the valid quantum keys.
[0021] Optionally, converting the second effective quantum key into a second communication key includes:
[0022] Perform a merging operation on the second effective quantum key, and generate the second communication key based on the merged second effective quantum key; or
[0023] Perform a cut operation on the second effective quantum key, and generate the second communication key based on the cut second effective quantum key.
[0024] Secondly, it provides a secure communication method for 5G network elements based on quantum technology, including:
[0025] MEC generates a key retrieval request for encrypting business communication data;
[0026] The MEC determines the first valid quantum key from its stored valid quantum keys according to the key acquisition request;
[0027] The MEC converts the first effective quantum key into a first communication key;
[0028] The MEC sends a communication message to the 5G core device, wherein the communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key; so that the 5G core network device can obtain a second valid quantum key corresponding to the key identification information from its own stored valid quantum keys according to the key identification information of the first communication key, convert the second valid quantum key into a second communication key, and use the second communication key to perform a decryption operation on the encrypted communication data.
[0029] In this embodiment, the MEC can generate a key acquisition request for encrypting service communication data, and determine a first valid quantum key from its stored valid quantum keys based on the key acquisition request; convert the first valid quantum key into a first communication key; and send a communication message to the 5G core device. This communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key. Because valid quantum keys can be selected based on different service communication data requiring encryption during communication, and the selected valid quantum key can be converted into a communication key for encryption, compared to existing technologies, this approach combines the characteristics of quantum keys and allows for flexible transformation of the selected valid quantum key, further preventing key leakage and thus improving the communication security between the 5G core network device and the MEC.
[0030] Optionally, the method further includes:
[0031] The MEC receives a quantum key sent by the 5G core network device; wherein the quantum key is obtained by the 5G core network device encoding the generated initial key;
[0032] The MEC decodes the received quantum key and sends the first measurement basis vector used for decoding to the 5G core network device, so that the 5G core network device compares the second measurement basis vector encoded with the quantum key with the first measurement basis vector to obtain a candidate quantum key with consistent measurement basis vector bits.
[0033] The MEC receives the candidate quantum keys sent by the 5G core network equipment, and selects a portion of the candidate quantum keys to send to the 5G core network equipment, so that the 5G core network equipment can determine the effective quantum key based on the portion of the candidate quantum keys;
[0034] The MEC receives a valid quantum key confirmation message sent by the 5G core network equipment, deletes some candidate quantum keys according to the valid quantum key confirmation message, assigns key identification information to the determined valid quantum key, and stores the valid quantum key.
[0035] Optionally, the MEC converts the first effective quantum key into a first communication key, including:
[0036] Perform a merging operation on the first valid quantum key, and generate the first communication key based on the merged first valid quantum key; or
[0037] A truncation operation is performed on the first valid quantum key, and the first communication key is generated based on the truncation of the first valid quantum key.
[0038] Optionally, the key acquisition request may include the length and / or number of valid quantum keys.
[0039] Thirdly, it provides 5G core network equipment, including:
[0040] A security application unit is configured to receive communication messages from the MEC, wherein the communication message includes at least key identification information of a first communication key and business communication data encrypted using the first communication key. The first communication key is obtained by the MEC selecting a first effective quantum key from its own stored effective quantum keys based on the business communication data and converting the first effective quantum key.
[0041] The quantum key management unit is configured to obtain a second valid quantum key corresponding to the key identification information from the valid quantum keys stored in the quantum key distribution unit according to the key identification information of the first communication key, and convert the second valid quantum key into a second communication key; and to use the second communication key to perform a decryption operation on the encrypted business communication data;
[0042] The quantum key distribution unit is used to store the valid quantum key and provide the quantum key management unit with a second valid quantum key corresponding to the key identification information according to the call of the quantum key management unit.
[0043] Optionally, the quantum key distribution unit includes a quantum key generation module and a quantum key distribution module;
[0044] The quantum key distribution module is configured to encode the initial key generated by the quantum key generation module to obtain a quantum key; send the quantum key to the MEC; receive a first measurement basis vector sent by the MEC, compare the first measurement basis vector with a second measurement basis vector to obtain candidate quantum keys with consistent measurement basis vector bits; wherein, the first measurement basis vector is the measurement basis vector used by the MEC to decode the quantum key, and the second measurement basis vector is the measurement basis vector used by the 5G core network equipment to encode the quantum key; receive a portion of candidate quantum keys selected by the MEC from the candidate quantum keys, determine a valid quantum key based on the portion of candidate quantum keys; and send a valid quantum key confirmation message to the MEC based on the valid quantum key, so that the MEC stores the valid quantum key based on the valid quantum key confirmation message and assigns key identification information to the valid quantum key;
[0045] The quantum key generation module is used to generate the initial key, assign key identification information to the effective quantum key, and store the effective quantum key.
[0046] Optionally, the quantum key distribution module is specifically used for:
[0047] The candidate quantum keys are sampled and tested.
[0048] When the sampling detection of the partial candidate quantum keys passes, the quantum key distribution module deletes the partial candidate quantum keys and uses the remaining candidate quantum keys as the valid quantum keys.
[0049] Optionally, the quantum key management unit includes a quantum key exchange module and a communication key generation module;
[0050] The quantum key exchange module is used to perform a merging operation on the second effective quantum key and instruct the communication key generation module to generate the second communication key from the merged second effective quantum key; or to perform a truncation operation on the second effective quantum key and instruct the communication key generation module to generate the second communication key based on the truncation second effective quantum key.
[0051] Fourthly, MEC is provided, including:
[0052] A quantum key management unit is used to generate a key acquisition request for encrypting business communication data; and to convert the first valid quantum key into a first communication key after the quantum key distribution unit determines the first valid quantum key.
[0053] The security application unit is used to send communication messages to the 5G core network device; wherein, the communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key; so that the 5G core network device can obtain a second valid quantum key corresponding to the key identification information from its own stored valid quantum keys according to the key identification information of the first communication key, convert the second valid quantum key into a second communication key, and use the second communication key to perform a decryption operation on the encrypted service communication data;
[0054] The quantum key distribution unit determines the first valid quantum key from its stored valid quantum keys according to the key acquisition request.
[0055] Optionally, the quantum key distribution unit includes: a quantum key generation module and a quantum key distribution module; the quantum key distribution module is used to receive a quantum key sent by the 5G core network device; wherein, the quantum key is obtained by the 5G core network device encoding an initial key generated;
[0056] The received quantum key is decoded, and the second measurement basis vector used for decoding is sent to the 5G core network device, so that the 5G core network device compares the second measurement basis vector encoded with the quantum key with the first measurement basis vector to obtain a candidate quantum key with consistent measurement basis vector bits;
[0057] The system receives the candidate quantum keys sent by the 5G core network device, selects a portion of the candidate quantum keys from the candidate quantum keys, and sends them to the 5G core network device so that the 5G core network device can determine the effective quantum key based on the portion of the candidate quantum keys.
[0058] The system receives a valid quantum key confirmation message from the 5G core network device, deletes some candidate quantum keys based on the valid quantum key confirmation message, instructs the quantum key generation module to allocate key identification information for the valid quantum key, and stores the valid quantum key.
[0059] Optionally, the quantum key management unit includes a quantum key exchange module and a communication key generation module;
[0060] The quantum key exchange module is configured to perform a merging operation on the first valid quantum key and instruct the communication key generation module to generate the first communication key based on the merged first valid quantum key; or to perform a truncation operation on the first valid quantum key and instruct the communication key generation module to generate the first communication key based on the truncation first valid quantum key.
[0061] Fifthly, providing electronic devices, including:
[0062] A memory for storing computer programs; a processor for executing the computer programs stored in the memory to implement the method steps described in any one of the first aspects.
[0063] A sixth aspect provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method steps described in any one aspect. Attached Figure Description
[0064] Figure 1 This is a schematic diagram illustrating the application scenarios applicable to the embodiments of this application;
[0065] Figure 2 This is a schematic diagram of the internal structure of a 5G core network device provided in an embodiment of this application;
[0066] Figure 3 This is a schematic diagram of the internal structure of the MEC provided in an embodiment of this application;
[0067] Figure 4 A flowchart illustrating a secure communication method for 5G network elements based on quantum technology on the 5G core network side, as provided in this application embodiment;
[0068] Figure 5 This is a schematic diagram of the signaling interaction for key distribution provided in an embodiment of this application;
[0069] Figure 6 A flowchart illustrating a 5G network element secure communication method based on quantum technology on the MEC side, as provided in this application embodiment;
[0070] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0071] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. A connected to B can represent: A and B directly connected, and A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.
[0072] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application will be explained below.
[0073] (1) Quantum Key Distribution (QKD) technology utilizes quantum mechanical properties to ensure communication security, such as quantum entanglement and the quantum no-cloning theorem. In the field of communication, it enables the two parties to generate and share a random, secure key to encrypt and decrypt messages, thereby effectively ensuring the security of the communication content.
[0074] (2) The UPF is an important component of the 5G core network system architecture. First, it is mainly responsible for the routing and forwarding of user plane data packets in the 5G core network. The UPF plays an important role in low latency and high bandwidth in 5G edge computing and network slicing technologies. Second, the UPF is the connection anchor between the 5G network and MEC. All core network data must be forwarded by the UPF before it can flow to the external network.
[0075] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.
[0076] Figure 1 This is a schematic diagram illustrating an application scenario applicable to the embodiments of this application. The scenario mainly includes a 5G core network device 101 and an MEC 102. Wired and / or wireless communication is possible between the 5G core network device 101 and the MEC 102.
[0077] Both 5G core network equipment 101 and MEC 102 can be equipped with QKD systems to achieve secure distribution of quantum keys. Furthermore, both 5G core network equipment 101 and MEC 102 can be equipped with quantum key management systems to flexibly convert quantum keys into the required communication keys based on business needs, thereby enabling capabilities such as identity authentication, data encryption, data decryption, and channel information security during communication.
[0078] Based on the above Figure 1 The 5G core network equipment 101 shown is... Figure 2 This is a schematic diagram of the internal structure of a 5G core network device provided in an embodiment of this application. Figure 2 As shown, the structure of the 5G core network equipment 101 mainly includes a quantum key distribution unit 201, a quantum key management unit 202, and a security application unit 203. Each of these units will be introduced in detail below.
[0079] The quantum key distribution unit 201 can communicate with the MEC (such as...) via a quantum key distribution channel. Figure 1 The MEC 102 shown interacts with the MEC to generate and distribute valid quantum keys. Specifically, it may include a quantum key generation module 201a and a quantum key distribution module 201b. For example, the quantum key generation module 201a generates an initial key at a predetermined period and notifies the quantum key distribution module 201b to distribute this initial key to the MEC. After obtaining the initial key, the quantum key distribution module 201b can encode it and send the encoded quantum key to the MEC through a quantum key distribution channel. This allows both parties to negotiate, verify, correct errors, and perform sampling checks to confirm the valid quantum key. Finally, the quantum key generation module 201a assigns key identification information to the valid quantum key and stores it for use by the quantum key management unit 202.
[0080] The quantum key management unit 202 can obtain a valid quantum key from the quantum key distribution unit 201 according to the business needs of the security application unit 203, process the obtained valid quantum key, and send the processed valid quantum key to the security application unit 203 for its use. Specifically, it may include: a key open interface module 202a, a quantum key transformation module 202b, a quantum key acquisition module 202c, and a communication key generation module 202d. For example, the quantum key open interface module 202a can send a key acquisition request to the quantum key transformation module 202b according to the business needs of the security application unit 203; the quantum key transformation module 202b, based on this request, triggers the quantum key acquisition module 202c to apply for a valid quantum key from the quantum key generation module 201a; after obtaining the valid quantum key, the quantum key transformation module 202b can call the communication key generation module 202 to transform the valid quantum key according to business needs, generating a communication key; finally, the communication key is sent to the security application unit 203 via the key open interface module 202a.
[0081] The security application unit 203 can communicate with the MEC for business purposes. For example, it can receive communication messages sent by the MEC. These communication messages may include key identification information of the communication key and business communication data encrypted using the key. When the communication message is received, the unit can obtain a communication key for decryption from the key interface open module 202a based on the key identification information provided in the message. After receiving the key, the unit can use the key to perform cryptographic operations (e.g., decryption, signature verification) on the communication message through the cryptographic operation module 203a, key management module 203b, etc., thereby realizing security capabilities such as mutual authentication, business communication data decryption, and channel information decryption.
[0082] Based on the above Figure 1 The MEC 102 shown is... Figure 3 This is a schematic diagram of the internal structure of the MEC provided in an embodiment of this application. Figure 3 As shown, the structure of the MEC 102 mainly includes a quantum key distribution unit 301, a quantum key management unit 302, and a security application unit 303. Each of these units will be described in detail below.
[0083] The quantum key distribution unit 301 can communicate with 5G core equipment (such as quantum key distribution channel) via the quantum key distribution channel. Figure 1 The MEC101 shown interacts with other quantum key generators (QKs) to generate and distribute valid quantum keys. Specifically, it may include a quantum key generation module 301a and a quantum key distribution module 301b. For example, the quantum key distribution module 301b can receive... Figure 2 The quantum key distribution module 201a sends the quantum key, decodes it, and sends the measurement basis vectors used for decoding back to the quantum key distribution module 201a so that both parties can perform negotiation, verification, error correction, and sampling detection processes to confirm the valid quantum key. Finally, the quantum key generation module 301a can assign key identification information to the valid quantum key and store it for use by the quantum key management unit 302.
[0084] The quantum key management unit 302 can obtain a valid quantum key from the quantum key distribution unit 301 according to the business needs of the security application unit 303, process the obtained valid quantum key, and send the processed valid quantum key to the security application unit 303 for use. Specifically, it may include: a key open interface module 302a, a quantum key transformation module 302b, a quantum key acquisition module 302c, and a communication key generation module 302d. For example, the quantum key open interface module 302a can send a key acquisition request to the quantum key transformation module 302b according to the business needs of the security application unit 303; the quantum key transformation module 302b, based on this request, triggers the quantum key acquisition module 302c to apply for a valid quantum key from the quantum key generation module 301a; after obtaining the valid quantum key, the quantum key transformation module 302b can call the communication key generation module 302 to transform the valid quantum key according to business needs, generating a communication key; finally, the communication key is sent to the security application unit 203 via the key open interface module 302a.
[0085] Security application unit 303 can be integrated with security application units on the 5G core network equipment side (such as...) Figure 2The security application unit 203 shown performs business communication. For example, after obtaining the required communication key from the quantum key management unit 302 according to business needs, the key can be used to perform cryptographic operations (e.g., encryption, signing) through the cryptographic operation module 303a, key management module 303b, etc., and then the authentication of both parties, encryption of business communication data, and encryption of channel information are sent to the security application unit 203 in the form of a communication message, so that the security application unit 203 can decrypt it, thereby realizing secure communication between the secure 5G core network equipment and the MEC.
[0086] It should be noted that the above Figure 2 , Figure 3 The structural diagrams shown are merely examples. In real-world scenarios, the internal modules can be expanded or improved according to business needs, and the embodiments in this application are not limited in this regard.
[0087] In this embodiment, a quantum key distribution unit and a quantum key management unit are added simultaneously to the 5G core network equipment and the MEC, respectively. The respective quantum key distribution units can distribute secure quantum keys to the 5G core network equipment and the MEC, thereby improving the security of key distribution between network elements across security domains within the 5G network. Furthermore, the respective quantum key management units can flexibly convert the acquired quantum keys according to different service requirements to generate the required communication keys, enabling the security application units of both parties to achieve the ability to authenticate each other's identities, encrypt or decrypt service communication data, and encrypt or decrypt channel information, thereby improving the security of communication between the two parties.
[0088] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, the method may include more or fewer operation steps based on conventional or non-inventive methods. For steps that do not logically have a necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or system execution, the method may be executed in the order shown in the embodiments or drawings, or in combination.
[0089] Figure 4 A flowchart illustrating a secure communication method for 5G network elements based on quantum technology on the 5G core network side, as provided in this application embodiment. Figure 4 As shown, the process includes the following steps:
[0090] It should be noted that the terms "first effective quantum key" and "second effective quantum key" in the following text are for ease of distinction only, and their quantity is not specifically limited; there can be one or more.
[0091] 401: 5G core network equipment receives communication messages from MEC.
[0092] The 5G core network equipment can specifically be Figure 1 The 5G core network equipment 101 shown can specifically be... Figure 1 The MEC 102 shown.
[0093] In this step, the 5G core network equipment receives communication messages from the MEC, specifically: the security application unit 203 receives communication messages from the security application unit 303.
[0094] Optionally, the communication message may include key identification information of the first communication key, and business communication data encrypted using the first communication key, and may also include encrypted channel information, identity authentication information, key exchange mechanism, etc.
[0095] The first communication key is obtained by MEC selecting the first effective quantum key from its own stored effective quantum keys based on the business communication data, and then converting the first effective quantum key.
[0096] 402: The 5G core network equipment obtains the second valid quantum key corresponding to the key identification information from its own stored valid quantum keys according to the key identification information of the first communication key, and converts the second valid quantum key into the second communication key.
[0097] Based on the above Figure 2 For example, the internal interaction process in this step can be as follows: the security application unit 203 in the 5G core network equipment requests a key acquisition request from the quantum key management unit 202 for decryption; the quantum key management unit 202 can obtain a second valid quantum key corresponding to the key identification information from the quantum key generation module 201a according to the key identification information carried in the request; after obtaining the second valid quantum key, it can be converted into a second communication key for decryption by combining the key transformation module 202b and the communication key generation module 202d, and then the second communication key is sent to the security application unit 203 through the key open docking module 202a.
[0098] Optionally, converting the second effective quantum key into a second communication key can be achieved by the quantum key exchange module 202b performing a merging operation on the second effective quantum key and instructing the communication key generation module 202d to generate a second communication key based on the merged second effective quantum key; alternatively, it can be achieved by performing a truncation operation on the second effective quantum key through the quantum key exchange module 202b and instructing the communication key generation module 202d to generate a second communication key based on the truncation of the second effective quantum key.
[0099] Since keys typically come in two lengths, 128 bits and 256 bits, when applying effective quantum keys to 5G networks, one or more effective quantum keys can be used depending on specific business needs.
[0100] Through the above steps, 5G core network equipment can concatenate one or more fixed-length valid quantum keys (e.g., concatenate two valid quantum keys) or truncate them (e.g., divide the original 128-bit valid quantum key into two 64-bit keys) according to different service requirements, thereby flexibly converting them into the required communication keys, preventing key leakage and ensuring the security of the communication process.
[0101] In some embodiments, prior to applying an effective quantum key to achieve secure communication, secure distribution of the quantum key between the 5G core network equipment and the MEC can also be completed, specifically as follows: Figure 5 As shown, an exemplary schematic diagram of the signaling interaction for quantum key distribution provided in an embodiment of this application is illustrated.
[0102] 501: The quantum key generation module 201a in the 5G core network equipment sends the generated initial key to the quantum key distribution module 201b.
[0103] 502: The quantum key distribution module 201b encodes the generated initial key to obtain the quantum key.
[0104] 503: Quantum key distribution module 201b sends the quantum key to quantum key distribution module 301b in MEC.
[0105] 504: The quantum key distribution module 301b decodes the received quantum key and sends the first measurement basis vector used for decoding to the quantum key distribution module 201b.
[0106] 505: The quantum key distribution module 201b compares the second measurement basis vector encoded with the quantum key with the first measurement basis vector to obtain the candidate quantum key with consistent measurement basis bits, and sends the candidate quantum key to the quantum key distribution module 301b.
[0107] 506: Quantum key distribution module 301b selects a portion of the candidate quantum keys from the candidate quantum keys and sends them to quantum key distribution module 201b.
[0108] 507: The quantum key distribution module 201b determines the effective quantum key based on this part of the candidate quantum keys.
[0109] Optionally, determining a valid quantum key can specifically involve: sampling and testing a portion of the received candidate quantum keys (e.g., further correcting and comparing the keys corresponding to the selected candidate quantum keys in the valid quantum keys); when the sampling and testing of a portion of the candidate quantum keys passes, deleting the selected candidate quantum keys and using the remaining candidate quantum keys in the valid quantum keys as the valid quantum keys.
[0110] 508: The quantum key distribution module 201b provides the valid quantum key to the quantum key generation module 201a for storage.
[0111] After receiving a valid quantum key, the quantum key generation module 201a can assign a unique identifier to each valid quantum key (e.g., number it) to distinguish each valid quantum key.
[0112] 509: Quantum key distribution module 201b sends a valid quantum key confirmation message to quantum key distribution module 301b based on the valid quantum key.
[0113] It should be noted that the execution order of 508 and 509 is not limited; 508 can be executed first, or 508 and 509 can be executed simultaneously.
[0114] 510: After receiving the valid quantum key confirmation message, the quantum key distribution module 301b deletes some candidate quantum keys according to the valid quantum key confirmation message, and gives the determined valid quantum key to the quantum key generation module 301a for storage.
[0115] After receiving a valid quantum key, the quantum key generation module 301a can assign a unique identifier to each valid quantum key (e.g., number it) to distinguish each valid quantum key.
[0116] Through the above Figure 5 The steps shown demonstrate that the key distribution between the 5G core network equipment and the MEC incorporates the characteristics of quantum key distribution technology to achieve secure distribution and online updating of quantum keys between different security domains of the 5G network.
[0117] 403: The 5G core network equipment uses the second communication key to perform a decryption operation on the encrypted service communication data.
[0118] In this step, specifically, the security application unit 203 in the 5G core network equipment may use the second communication key to perform decryption operation on the encrypted service communication data. Similarly, if it is a request for identity authentication, the second communication key is used to perform identity authentication operation, or if it is encrypted channel information, the second communication key is used to perform channel decryption operation.
[0119] In this embodiment, the 5G core network device receives a communication message from the MEC. This communication message includes at least key identification information of a first communication key and service communication data encrypted using that first communication key. The first communication key is obtained by the MEC from its stored valid quantum keys based on the service communication data, and then converting the first valid quantum key. The 5G core network device, based on the key identification information of the first communication key, obtains a second valid quantum key corresponding to the key identification information from its stored valid quantum keys, and converts the second valid quantum key into a second communication key. Finally, the second communication key is used to decrypt the encrypted service communication data. Because valid quantum keys can be selected based on different encrypted service communication data during communication, and the selected valid quantum key can be converted into a communication key, and then used to decrypt the data, compared to existing technologies, this method combines the characteristics of quantum keys and allows for flexible transformation of the selected valid quantum key, further preventing key leakage and thus improving the communication security between the 5G core network device and the MEC.
[0120] Figure 6 This is a flowchart illustrating a secure communication method for 5G network elements based on quantum technology on the MEC side, as provided in an embodiment of this application. Figure 6 As shown, the process includes the following steps:
[0121] 601: MEC generates a key retrieval request for encrypting business communication data.
[0122] by Figure 3 For example, this step can be as follows: the security application unit 303 in MEC 102 calls the key open docking module 302a in the quantum key management unit 302 to apply for a key according to business needs. The key open docking module 302a sends a key acquisition request to the quantum key transformation module 302b according to the business needs.
[0123] Optionally, the key acquisition request may include the length of the valid quantum key, or the number of valid quantum keys, or both the length and the number of valid quantum keys.
[0124] 602: Based on the key acquisition request, MEC determines the first valid quantum key from its own stored valid quantum keys.
[0125] Specifically, this step may involve the quantum key transformation module 302b triggering the quantum key acquisition module 302c to request the first valid quantum key from the quantum key generation module 301a based on the aforementioned key acquisition request.
[0126] 603: MEC converts the first effective quantum key into the first communication key.
[0127] Optionally, converting the first effective quantum key into the first communication key can be achieved by the quantum key exchange module 302b performing a merging operation on the first effective quantum key and instructing the communication key generation module 302d to generate the first communication key based on the merged first effective quantum key; alternatively, it can be achieved by performing a truncation operation on the first effective quantum key through the quantum key exchange module 302b and instructing the communication key generation module 302d to generate the first communication key based on the truncation of the first effective quantum key.
[0128] Since keys typically come in two lengths, 128 bits and 256 bits, when applying effective quantum keys to 5G networks, one or more effective quantum keys can be used depending on specific business needs.
[0129] Through the above steps, MEC can concatenate one or more fixed-length valid quantum keys (e.g., concatenate two valid quantum keys) or truncate them (e.g., divide the original 128-bit valid quantum key into two 64-bit keys) according to different business needs, thereby flexibly converting them into the required communication keys, preventing key leakage and ensuring the security of the communication process.
[0130] In some embodiments, secure distribution of quantum keys between the 5G core network equipment and the MEC can also be completed before applying quantum keys to achieve secure communication. The specific process can be referred to the above. Figure 5 This will not be described again here.
[0131] 604: The MEC sends a communication message to the 5G core equipment. This communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key. Specifically, this step may be as follows: After obtaining the first communication key through the key open interface module 302a, the security application unit 303 can encrypt the service communication data, key exchange mechanism, channel information, etc. using the first communication key and send them to the security application unit 203 as a communication message.
[0132] In this embodiment, the MEC can generate a key acquisition request for encrypting service communication data, and determine a first valid quantum key from its stored valid quantum keys based on the key acquisition request; convert the first valid quantum key into a first communication key; and send a communication message to the 5G core device. This communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key. Because valid quantum keys can be selected based on different service communication data requiring encryption during communication, and the selected valid quantum key can be converted into a communication key for encryption, compared to existing technologies, this approach combines the characteristics of quantum keys and allows for flexible transformation of the selected valid quantum key, further preventing key leakage and thus improving the communication security between the 5G core network device and the MEC.
[0133] Based on the same technical concept, this application also provides an electronic device that can realize the aforementioned functions based on 5G core network equipment or MEC.
[0134] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0135] At least one processor 701 and a memory 702 connected to at least one processor 701. In this embodiment, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 The example shown is the connection between processor 701 and memory 702 via bus 700. Bus 700 is... Figure 7 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The 700 bus can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 7 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 701 can also be called a controller; there is no restriction on the name.
[0136] In this embodiment, the memory 702 stores instructions executable by at least one processor 701. By executing the instructions stored in the memory 702, the at least one processor 701 can execute the quantum-based 5G network element secure communication method discussed above. The processor 701 can implement... Figure 2 or Figure 3 The functions of each module in the device shown.
[0137] The processor 701 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 702 and calling data stored in memory 702, the processor can perform various functions and process data, thereby monitoring the device as a whole.
[0138] In one possible design, processor 701 may include one or more processing units. Processor 701 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 701. In some embodiments, processor 701 and memory 702 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.
[0139] The processor 701 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the quantum technology-based 5G network element secure communication method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0140] Memory 702, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 702 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 702 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 702 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0141] By designing and programming the processor 701, the code corresponding to the quantum technology-based 5G network element secure communication method described in the aforementioned embodiments can be embedded into the chip, enabling the chip to execute the code during operation. Figure 4 or Figure 6 The illustrated embodiment presents a secure communication method for 5G network elements based on quantum technology. How to design and program the processor 701 is a technique well-known to those skilled in the art and will not be described further here.
[0142] It should be noted that the communication electronic device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0143] This application also provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the quantum technology-based 5G network element secure communication method described in the above embodiments.
[0144] This application also provides a computer program product, which, when invoked by a computer, causes the computer to execute the 5G network element secure communication method based on quantum technology described in the above embodiments.
[0145] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0146] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0147] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0148] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
Claims
1. A secure communication method for 5G network elements based on quantum technology, characterized in that, include: The 5G core network equipment receives a communication message from the mobile edge computing (MEC). The communication message includes at least key identification information of a first communication key and service communication data encrypted using the first communication key. The first communication key is obtained by the MEC selecting a first effective quantum key from its own stored effective quantum keys based on the service communication data and converting the first effective quantum key. The 5G core network device obtains a second effective quantum key corresponding to the key identification information from its own stored effective quantum keys according to the key identification information of the first communication key, and converts the second effective quantum key into a second communication key; The 5G core network equipment uses the second communication key to perform a decryption operation on the encrypted service communication data; Before the 5G core network equipment receives communication messages from the mobile edge computing (MEC), it also includes: The 5G core network equipment encodes the generated initial key to obtain a quantum key; The 5G core network equipment sends the quantum key to the MEC; The 5G core network device receives a first measurement basis vector sent by the MEC, compares the first measurement basis vector with a second measurement basis vector to obtain a candidate quantum key with consistent measurement basis vector bits, and sends the candidate quantum key to the MEC; wherein, the first measurement basis vector is the measurement basis vector used by the MEC to decode the quantum key, and the second measurement basis vector is the measurement basis vector used by the 5G core network device to encode the quantum key; The 5G core network equipment receives a portion of the candidate quantum keys selected by the MEC from the candidate quantum keys, and determines the effective quantum key based on the portion of the candidate quantum keys; The 5G core network equipment assigns key identification information to the effective quantum key and stores the effective quantum key; The 5G core network device sends a valid quantum key confirmation message to the MEC based on the valid quantum key, so that the MEC stores the determined valid quantum key based on the valid quantum key confirmation message and assigns key identification information to the valid quantum key.
2. The method as described in claim 1, characterized in that, The 5G core network equipment determines the effective quantum key based on the candidate quantum keys, including: The 5G core network equipment will sample and detect some of the candidate quantum keys. When the sampling detection of the partial candidate quantum keys passes, the 5G core network equipment deletes the partial candidate quantum keys and uses the remaining candidate quantum keys as the valid quantum keys.
3. The method as described in claim 1 or 2, characterized in that, The step of converting the second effective quantum key into a second communication key includes: Perform a merging operation on the second effective quantum key, and generate the second communication key based on the merged second effective quantum key; or Perform a cut operation on the second effective quantum key, and generate the second communication key based on the cut second effective quantum key.
4. A secure communication method for 5G network elements based on quantum technology, characterized in that, include: Mobile edge computing (MEC) generates a key retrieval request for encrypting business communication data; The MEC determines the first valid quantum key from its stored valid quantum keys according to the key acquisition request; The MEC converts the first effective quantum key into a first communication key; The MEC sends a communication message to the 5G core network device, wherein the communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key; so that the 5G core network device can obtain a second valid quantum key corresponding to the key identification information from its own stored valid quantum keys according to the key identification information of the first communication key, convert the second valid quantum key into a second communication key, and use the second communication key to perform a decryption operation on the encrypted communication data; The method further includes: The MEC receives a quantum key sent by the 5G core network device; wherein the quantum key is obtained by the 5G core network device encoding the generated initial key; The MEC decodes the received quantum key and sends the first measurement basis vector used for decoding to the 5G core network device, so that the 5G core network device compares the second measurement basis vector encoded with the quantum key with the first measurement basis vector to obtain a candidate quantum key with consistent measurement basis vector bits. The MEC receives the candidate quantum keys sent by the 5G core network equipment, and selects a portion of the candidate quantum keys to send to the 5G core network equipment, so that the 5G core network equipment can determine the effective quantum key based on the portion of the candidate quantum keys; The MEC receives a valid quantum key confirmation message sent by the 5G core network equipment, deletes some candidate quantum keys according to the valid quantum key confirmation message, assigns key identification information to the determined valid quantum key, and stores the valid quantum key.
5. The method as described in claim 4, characterized in that, The MEC converts the first effective quantum key into a first communication key, including: Perform a merging operation on the first valid quantum key, and generate the first communication key based on the merged first valid quantum key; or A truncation operation is performed on the first valid quantum key, and the first communication key is generated based on the truncation of the first valid quantum key.
6. The method as described in claim 4 or 5, characterized in that, The key acquisition request includes the length and / or number of valid quantum keys. 7.5G core network equipment, characterized in that, include: A security application unit is configured to receive communication messages from a mobile edge computing (MEC), wherein the communication message includes at least key identification information of a first communication key and service communication data encrypted using the first communication key. The first communication key is obtained by the MEC selecting a first valid quantum key from its own stored valid quantum keys based on the service communication data and converting the first valid quantum key. A quantum key management unit is configured to obtain a second valid quantum key corresponding to the key identification information from the valid quantum keys stored in the quantum key distribution unit according to the key identification information of the first communication key, and convert the second valid quantum key into a second communication key; and to perform a decryption operation on the encrypted business communication data using the second communication key; The quantum key distribution unit is used to store the valid quantum key and provide the quantum key management unit with a second valid quantum key corresponding to the key identification information according to the call of the quantum key management unit; The quantum key distribution unit includes a quantum key generation module and a quantum key distribution module; The quantum key distribution module is configured to encode the initial key generated by the quantum key generation module to obtain a quantum key; send the quantum key to the MEC; receive a first measurement basis vector sent by the MEC, compare the first measurement basis vector with a second measurement basis vector to obtain candidate quantum keys with consistent measurement basis vector bits; wherein, the first measurement basis vector is the measurement basis vector used by the MEC to decode the quantum key, and the second measurement basis vector is the measurement basis vector used by the 5G core network equipment to encode the quantum key; receive a portion of candidate quantum keys selected by the MEC from the candidate quantum keys, determine a valid quantum key based on the portion of candidate quantum keys; and send a valid quantum key confirmation message to the MEC based on the valid quantum key, so that the MEC stores the determined valid quantum key based on the valid quantum key confirmation message and assigns key identification information to the valid quantum key. The quantum key generation module is used to generate the initial key, assign key identification information to the effective quantum key, and store the effective quantum key.
8. The device as described in claim 7, characterized in that, The quantum key distribution module is specifically used for: The candidate quantum keys are sampled and tested. When the sampling detection of the partial candidate quantum keys passes, the quantum key distribution module deletes the partial candidate quantum keys and uses the remaining candidate quantum keys as the valid quantum keys.
9. The device as described in claim 7, characterized in that, The quantum key management unit includes a quantum key exchange module and a communication key generation module; The quantum key exchange module is used to perform a merging operation on the second effective quantum key and instruct the communication key generation module to generate the second communication key from the merged second effective quantum key; or The second valid quantum key is intercepted, and the communication key generation module is instructed to generate the second communication key based on the intercepted second valid quantum key.
10. Mobile Edge Computing (MEC), characterized in that, include: A quantum key management unit is used to generate key acquisition requests for encrypting business communication data; This is used to convert the first valid quantum key into a first communication key after the quantum key distribution unit determines the first valid quantum key; The security application unit is used to send communication messages to the 5G core network device; wherein, the communication message includes at least the key identification information of the first communication key and the service communication data encrypted using the first communication key; so that the 5G core network device can obtain a second valid quantum key corresponding to the key identification information from its own stored valid quantum keys according to the key identification information of the first communication key, convert the second valid quantum key into a second communication key, and use the second communication key to perform a decryption operation on the encrypted service communication data; The quantum key distribution unit determines the first valid quantum key from its own stored valid quantum keys according to the key acquisition request; The quantum key distribution unit includes: a quantum key generation module and a quantum key distribution module; The quantum key distribution module is used to receive the quantum key sent by the 5G core network equipment; wherein the quantum key is obtained by the 5G core network equipment encoding the generated initial key; The received quantum key is decoded, and the first measurement basis vector used for decoding is sent to the 5G core network device, so that the 5G core network device compares the second measurement basis vector encoded with the quantum key with the first measurement basis vector to obtain a candidate quantum key with consistent measurement basis vector bits; The system receives the candidate quantum keys sent by the 5G core network device, selects a portion of the candidate quantum keys from the candidate quantum keys, and sends them to the 5G core network device so that the 5G core network device can determine the effective quantum key based on the portion of the candidate quantum keys. The system receives a valid quantum key confirmation message from the 5G core network device, deletes some candidate quantum keys based on the valid quantum key confirmation message, instructs the quantum key generation module to allocate key identification information for the valid quantum key, and stores the valid quantum key.
11. The MEC as described in claim 10, characterized in that, The quantum key management unit includes a quantum key exchange module and a communication key generation module; The quantum key exchange module is used to perform a merging operation on the first valid quantum key, and instruct the communication key generation module to generate the first communication key according to the merged first valid quantum key; or It is used to perform a truncation operation on the first valid quantum key, and instruct the communication key generation module to generate the first communication key based on the truncation of the first valid quantum key.
12. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the method steps of any one of claims 1-3 or 4-6.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-3 or 4-6.
Citation Information
Patent Citations
KR20220080344A