A quantum key injection method, device and electronic equipment

By establishing a secure channel between the 5G core network and the quantum key management terminal, online quantum key refilling is achieved, solving the problem of low efficiency in offline quantum key prefilling for wireless devices, improving refilling efficiency and ensuring security.

CN117081732BActive Publication Date: 2026-04-17CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2023-07-17
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, the offline pre-charging method for quantum keys results in low quantum key charging efficiency for wireless devices, requiring manual offline charging, which cannot meet the demand for efficient online charging.

Method used

By receiving the quantum key injection strategy and encrypted data packets, a secure channel is established using the 5G core network and the quantum key management terminal to achieve online quantum key injection. The terminal device can obtain the quantum key data packets online, decrypt and store them, thereby improving injection efficiency and ensuring security.

Benefits of technology

This technology enables terminal devices to acquire quantum key data packets online, avoiding manual offline key filling, improving quantum key filling efficiency, and ensuring transmission security through an encrypted channel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117081732B_ABST
    Figure CN117081732B_ABST
Patent Text Reader

Abstract

This application provides a quantum key injection method, apparatus, and electronic device, relating to the field of network security technology. In this application, a quantum key injection strategy and a quantum key encryption data packet are first received. Then, based on the decryption algorithm in the quantum key injection strategy, the quantum key encryption data packet is decrypted to obtain the quantum key data packet. Finally, the quantum key data packet is injected into a designated storage unit. Using this method, not only can online quantum key injection be performed on terminal devices, improving the efficiency of quantum key injection, but the security of transmitting quantum key data packets can also be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a quantum key injection method, apparatus and electronic device. Background Technology

[0002] Quantum Key Distribution (QKD) is a technology that uses the properties of quantum mechanics to ensure the security of communication between two parties, enabling them to generate and share a random, secure key to encrypt and decrypt messages.

[0003] The goal of QKD networking is to extend point-to-point QKD key distribution to end-to-end key distribution among multiple users, and to use end-to-end keys to achieve encrypted transmission of user service information. However, QKD networking is typically deployed on top of existing fiber optic network infrastructure and relies on fiber optic media for key distribution.

[0004] To avoid dependence on fiber optic media and apply quantum key distribution to wireless devices, existing methods provide quantum keys to wireless devices through offline pre-charging at the terminal. This offline pre-charging method involves injecting a pre-generated set number of quantum keys into a terminal security medium such as a Universal Subscriber Identity Module (USIM) or a Trans-Flash TF card, and then distributing the quantum keys from the terminal security medium to the mobile terminal. However, when the pre-generated quantum keys are exhausted or need to be recharged, manual offline recharging is required, resulting in low recharging efficiency. Summary of the Invention

[0005] This invention application provides a quantum key injection method for online injection of quantum keys into terminal devices, thereby improving the efficiency of quantum key injection.

[0006] In a first aspect, this application provides a quantum key injection method, including:

[0007] Receive a quantum key injection strategy and a quantum key encryption data packet, wherein the quantum key injection strategy is used to encrypt or decrypt the quantum key data packet;

[0008] Based on the decryption algorithm in the quantum key injection strategy, the quantum key encrypted data packet is decrypted to obtain the quantum key data packet;

[0009] The quantum key data packet is filled into a designated storage unit.

[0010] Based on the above method, the terminal device can obtain the quantum key data packet issued by the quantum key management terminal online, avoiding manual offline quantum key injection for the terminal device and improving the efficiency of quantum key injection; by establishing a secure channel for the transmission of quantum key data packets between the terminal device and the quantum key management terminal, the quantum key data packet pre-obtained by the terminal device is encrypted and transmitted, ensuring the security of the transmitted quantum key data packet.

[0011] In one possible implementation, prior to the received quantum key injection strategy, the following is also included:

[0012] The authentication server forwards the quantum key refill service request to the service authentication server, so that the service authentication server can determine the quantum key refill service subscription status of the terminal device based on the terminal device identifier in the quantum key refill service request.

[0013] The service authentication terminal receives a subscription status message returned based on the quantum key injection service request. The subscription status message is either a first feedback message that provides the terminal device with a quantum key injection strategy corresponding to the quantum key injection service, or a second feedback message that refuses to provide the terminal device with a quantum key injection service.

[0014] Based on the above method, it is possible to perform service subscription authentication for the quantum key injection service of terminal devices, thereby ensuring the security of terminal devices obtaining quantum key injection services.

[0015] In one possible implementation, receiving the quantum key injection strategy and the quantum key encryption data packet includes:

[0016] From the set of derived algorithms of the quantum key injection strategy, select the candidate derived algorithm with the highest priority, and from the set of encryption algorithms of the quantum key injection strategy, select the candidate encryption algorithm with the highest priority.

[0017] Send a quantum key injection request carrying the candidate derived algorithm, the candidate encryption algorithm, and the quantum key identifier to the authentication server, so that the authentication server generates a derived key based on the candidate derived algorithm and the original key;

[0018] The authentication server forwards a quantum key injection request carrying the derived key, the candidate encryption algorithm, and the quantum key identifier to the quantum key management terminal, so that the quantum key management terminal generates the quantum key encryption data packet.

[0019] Receive the quantum key encryption data packet returned by the quantum key management terminal.

[0020] Based on the above method, the terminal device can first receive the quantum key injection strategy sent by the service authentication terminal, then determine a candidate derived algorithm from the set of derived algorithms of the quantum key injection strategy and a candidate encryption algorithm from the set of encryption algorithms of the quantum key injection strategy, and forward them to the authentication server, so that the authentication server can generate a derived key according to the candidate derived algorithm; and then forward the quantum key injection request to the quantum key management terminal through the authentication server, so that the quantum key management terminal can encrypt the quantum key data packet to be obtained according to the derived key and the candidate encryption algorithm to generate a quantum key encrypted data packet; finally, it receives the quantum key encrypted data packet returned by the key management terminal.

[0021] Secondly, this application provides a quantum key processing method, including:

[0022] Obtain a quantum key injection strategy and a raw key, and forward the quantum key injection strategy to a terminal device. The quantum key injection strategy is obtained after the terminal device successfully authenticates the quantum key injection service it has subscribed to, and the raw key is generated by the terminal device after registering and authenticating the quantum key injection service.

[0023] The system receives a quantum key injection request sent by the terminal device, and derives a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request.

[0024] A quantum key injection request carrying the derived key is sent to the quantum key management terminal, so that the quantum key management terminal can package and encrypt the quantum key data packet corresponding to the quantum key identifier based on the quantum key identifier, the candidate encryption algorithm and the derived key in the quantum key injection request, to obtain a quantum key encrypted data packet, and forward the quantum key encrypted data packet to the terminal device.

[0025] Using the above method, the authentication server can forward the quantum key strategy issued by the service authentication server to the terminal device. After receiving the quantum key injection request from the terminal device (where the terminal device determines the candidate derivation algorithm and candidate encryption algorithm), the server derives or updates the original key of the terminal device to obtain a derived key. This allows the quantum key management terminal to generate a quantum key encryption data packet based on the derived key and the candidate encryption algorithm, and then forwards the quantum key encryption data packet to the terminal device. This enables the terminal device to obtain the quantum key encryption data packet online, achieving online quantum key injection and improving the efficiency of quantum key injection. Furthermore, after receiving the quantum key injection request from the terminal device, the authentication server derives or updates the original key according to the candidate derivation algorithm in the quantum key injection request, achieving one-time pad quantum key distribution and improving the security of quantum key transmission.

[0026] In one possible implementation, prior to acquiring the quantum key injection strategy, the following is also included:

[0027] The system receives a quantum key refill service request sent by the terminal device and forwards the quantum key refill service request to the service authentication terminal, so that the service authentication terminal can determine the quantum key refill service subscription status of the terminal device based on the terminal device identifier in the quantum key refill service request.

[0028] The system receives a subscription status message returned by the service authentication terminal based on the quantum key injection service request, and forwards the subscription status message to the terminal device. The subscription status message is either a first feedback message that provides the terminal device with a quantum key injection strategy corresponding to the quantum key injection service, or a second feedback message that refuses to provide the terminal device with the quantum key injection service.

[0029] Using the above method, the authentication server can obtain the quantum key injection service and the corresponding quantum key injection strategy that the terminal device has subscribed to, and forward the subscribed quantum key injection service and quantum key injection strategy to the terminal device.

[0030] In one possible implementation, the step of deriving a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request includes:

[0031] Determine the derivation parameters associated with the candidate derivation algorithm, and derive the original key based on the candidate derivation algorithm and the derivation parameters to obtain the derived key.

[0032] The above method enables the quantum key management terminal to derive or update the original key once a quantum key is issued, thereby improving the security of quantum key transmission.

[0033] Thirdly, this application provides a quantum key injection device, comprising:

[0034] A data receiving module is used to receive a quantum key injection strategy and a quantum key encryption data packet, wherein the quantum key injection strategy includes an algorithm for encrypting or decrypting the quantum key data packet;

[0035] The data decryption module is used to decrypt the quantum key encrypted data packet based on the decryption algorithm in the quantum key injection strategy to obtain the quantum key data packet;

[0036] A quantum key filling module is used to fill the quantum key data packet into a designated storage unit.

[0037] The aforementioned device enables online quantum key injection into terminal devices, improving the efficiency of quantum key injection while ensuring the security of quantum key data packet transmission.

[0038] Fourthly, this application provides a quantum key processing device, comprising:

[0039] The data acquisition module is used to acquire the quantum key injection strategy and the original key, and forward the quantum key injection strategy to the terminal device. The quantum key injection strategy is obtained after the terminal device successfully authenticates the quantum key injection service it subscribes to, and the original key is generated by the terminal device after registering and authenticating the quantum key injection service.

[0040] A quantum key processing module is used to receive a quantum key injection request sent by the terminal device, and derive a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request.

[0041] A quantum key injection request carrying the derived key is sent to the quantum key management terminal, so that the quantum key management terminal can package and encrypt the quantum key data packet corresponding to the quantum key identifier based on the quantum key identifier, the candidate encryption algorithm and the derived key in the quantum key injection request, to obtain a quantum key encrypted data packet, and forward the quantum key encrypted data packet to the terminal device.

[0042] The aforementioned device enables the quantum key management terminal to derive or update the original key once a quantum key is issued, thereby improving the security of quantum key data packet transmission.

[0043] Fifthly, this application provides an electronic device, comprising:

[0044] Memory, used to store computer programs;

[0045] When the processor executes the computer program stored in the memory, it implements the steps of the quantum key injection method described above.

[0046] Sixthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described quantum key injection method.

[0047] For the various aspects of the second to sixth aspects mentioned above, and the technical effects that each aspect may achieve, please refer to the above description of the technical effects that can be achieved for the first aspect or the various possible solutions in the first aspect, which will not be repeated here. Attached Figure Description

[0048] Figure 1 A flowchart of a quantum key injection method provided in Embodiment 1 of this application;

[0049] Figure 2 A schematic diagram of a quantum key injection system architecture is provided for this application;

[0050] Figure 3 This is a flowchart of quantum key injection for a terminal device provided in Embodiment 1 of this application;

[0051] Figure 4 A flowchart of a quantum key processing method provided in Embodiment 2 of this application;

[0052] Figure 5 This is a schematic diagram of the quantum key injection device structure corresponding to the method provided in Embodiment 1 of this application;

[0053] Figure 6 This is a schematic diagram of the quantum key processing device structure corresponding to the method provided in Embodiment 2 of this application;

[0054] Figure 7 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. A connected to B can represent: A and B directly connected, and A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.

[0056] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0057] Example 1:

[0058] Quantum key distribution is a technology that uses the properties of quantum mechanics to ensure the security of communication between two parties, enabling them to generate and share a random, secure key to encrypt and decrypt messages.

[0059] The goal of QKD networking is to extend point-to-point QKD key distribution to end-to-end key distribution among multiple users, and to use end-to-end keys to achieve encrypted transmission of user service information. However, QKD networking is typically deployed on top of existing fiber optic network infrastructure and relies on fiber optic media for key distribution.

[0060] To avoid dependence on fiber optic media and apply quantum key distribution to wireless devices, existing methods provide quantum keys to wireless devices through offline pre-charging at the terminal. This offline pre-charging method involves injecting a pre-generated set number of quantum keys into a terminal security medium such as a global user identification card or TF cryptographic card, and then distributing the quantum keys from the terminal security medium to the mobile terminal. However, when the pre-generated quantum keys are exhausted or need to be recharged, manual offline recharging is required, resulting in low recharging efficiency.

[0061] In view of this, in order to realize online quantum key injection for wireless devices (terminal devices) and improve the efficiency of quantum key injection, in the first aspect, this application provides a quantum key injection method, which specifically includes: firstly receiving a quantum key injection strategy and a quantum key encryption data packet, then decrypting the quantum key encryption data packet based on the decryption algorithm in the quantum key injection strategy to obtain a quantum key data packet, and finally injecting the quantum key data packet into a set storage unit.

[0062] The method provided in this application enables terminal devices to obtain quantum key encrypted data packets issued by the quantum key management terminal online, avoiding manual offline quantum key injection into the terminal devices and improving the efficiency of quantum key injection. Furthermore, by establishing a secure channel for quantum key data packet transmission between the terminal devices and the quantum key management terminal, the quantum key data packets pre-obtained by the terminal devices are encrypted and transmitted according to the quantum key injection strategy, ensuring the security of the transmitted quantum key data packets.

[0063] Reference Figure 1 The diagram shown is a flowchart of a quantum key injection method provided in Embodiment 1 of this application. The method includes:

[0064] S1 receives the quantum key injection strategy and quantum key encryption data packets.

[0065] Firstly, the method provided in this application can be applied to Figure 2 The system architecture shown includes: a terminal device, a 5G core network, a quantum key management terminal, and a QKD network. The method provided in Embodiment 1 of this application can be run on the terminal device.

[0066] Terminal devices include various mobile terminal devices with communication functions, such as mobile phones, laptops, tablets, POS machines, walkie-talkies, and other internet or voice terminals. This application does not impose specific restrictions on the types and quantities of terminal devices.

[0067] The 5G core network provides a secure channel for quantum key injection to terminal devices, enabling registration and authentication of the quantum key injection service. By combining the 5G core network with the quantum key management terminal, the 5G core network can distribute quantum keys stored in the quantum key management terminal to terminal devices online. Furthermore, the quantum keys are encrypted according to the quantum key injection strategy during distribution, ensuring the security of quantum key transmission.

[0068] In this embodiment, the 5G core network includes an authentication service network element (authentication server) and a unified data management network element (service authentication terminal). The authentication service network element receives authentication requests or quantum key service requests sent by terminal devices and forwards them to the unified data management network element for service authentication. The unified data management network element is used to authenticate the quantum key charging service subscription of terminal devices and can also be used to manage the terminal device identifier and the quantum key service information subscribed to by the terminal device. For example, when the quantum key service subscribed to by the terminal device changes, the quantum key service information subscribed to by the terminal device is automatically updated.

[0069] The quantum key management terminal is used to store and manage the various quantum keys obtained from the QKD network. The quantum key management terminal can be deployed inside the 5G core network or communicate with the 5G core network through the Network Exposure Function (NEF). This application does not impose specific restrictions on the deployment location, number, or communication method between the quantum key management terminal and the 5G core network.

[0070] QKD networks are used to allocate corresponding quantum keys to the quantum key management terminal.

[0071] In Embodiment 1 of this application, before receiving the quantum key injection strategy, the terminal device needs to subscribe to and authenticate the quantum key injection service. The steps for subscribing to and authenticating the quantum key injection service are as follows:

[0072] The terminal device sends a quantum key recharge service request to the authentication server. Specifically, the terminal device can send the quantum key recharge service request to the authentication server through the functional layer (non-access strayum, abbreviated as NAS) channel between the 5G core network and the terminal device. The quantum key recharge service request includes the terminal device's terminal device identifier, which can be used to authenticate the identity of the current terminal device or to authenticate the quantum key recharge service subscribed to by the terminal device.

[0073] In addition to the terminal device identifier, the quantum key refilling service request also includes information such as the number of quantum keys pre-acquired by the terminal device and the quantum key identifier / key length corresponding to the quantum key. This application does not impose specific restrictions on the content included in the quantum key refilling service request, and can flexibly add content according to actual application needs, which will not be elaborated here.

[0074] After the terminal device sends a quantum key refill service request to the authentication server, the authentication server can forward the quantum key refill service request to the service authentication server, so that the service authentication server can determine the quantum key refill service subscription status of the terminal device based on the terminal device identifier in the quantum key refill service request.

[0075] Specifically, the service authentication terminal can store and manage the quantum key refilling service information that the terminal device has subscribed to.

[0076] Information on subscribed quantum key delivery services can be found in Table 1 below:

[0077]

[0078] Table 1

[0079] It should be noted that the quantum key injection strategy includes multiple derived algorithms and multiple encryption algorithms.

[0080] After receiving a quantum key refill service request, the service authentication terminal can extract the terminal device identifier from the quantum key refill service according to the set data extraction method, or identify the terminal device identifier in the quantum key refill service request. Based on the terminal device identifier, the terminal authentication terminal can search for whether there is a subscribed quantum key refill service information that matches the current terminal device identifier in the subscribed quantum key refill service information shown in Table 1, thereby determining the quantum key refill service subscription status of the terminal device.

[0081] In Embodiment 1 of this application, the terminal device receives a subscription status message returned by the service authentication terminal based on the quantum key injection service request. The subscription status information returned by the service authentication terminal is determined as follows:

[0082] The service authentication terminal first determines whether a quantum key injection service matching the current terminal device's identifier exists among the subscribed quantum key injection service information. Upon finding a matching service (successful authentication), the terminal retrieves the subscribed quantum key injection service and its corresponding quantum key injection strategy. For example, if the current terminal device identifier is A, it retrieves Service1 and Strategy1 from Table 1. Then, it sends the first feedback information of the quantum key injection strategy (stategy1) corresponding to the quantum key injection service (Service1) to the terminal device. This first feedback information notifies the terminal device of the subscribed quantum key injection service and carries the corresponding quantum key injection strategy.

[0083] When the service authentication terminal determines that there is no quantum key refilling service information that matches the current terminal device identifier among the subscribed quantum key refilling service information (authentication failure), for example, if the current terminal device identifier is S, the service authentication terminal determines that the current terminal device has not subscribed to the quantum key refilling service, and then returns a second feedback information to the terminal device that refuses to provide the quantum key refilling service. The second feedback information is used to notify the terminal device that it has not subscribed to the quantum key refilling service.

[0084] The above methods enable subscription authentication of the quantum key injection service for terminal devices, ensuring the security of terminal devices obtaining the quantum key injection service.

[0085] The service authentication terminal performs service subscription authentication for the quantum key injection service of the terminal device. After the authentication function is completed, both the terminal device and the authentication server can receive the subscribed quantum key injection strategy.

[0086] In Embodiment 1 of this application, after receiving the subscribed quantum key injection strategy, the terminal device first determines the set of derived algorithms and the set of encryption algorithms in the quantum key injection strategy. Then, according to the priority of the derived algorithms supported by the terminal device, it sorts the derived algorithms in the set of derived algorithms and selects the candidate derived algorithm with the highest priority. Similarly, according to the priority of the encryption algorithms supported by the terminal device, it sorts the encryption algorithms in the set of encryption algorithms and selects the candidate encryption algorithm with the highest priority. It should be noted that the candidate derived algorithms and candidate encryption algorithms can be selected from the set of derived algorithms and the candidate encryption algorithms from the set of encryption algorithms using the corresponding algorithm tags. This application does not impose specific restrictions on the selection method of candidate derived algorithms and candidate encryption algorithms.

[0087] The terminal device sends a quantum key injection request to the authentication server, carrying the aforementioned candidate derivation algorithm, candidate encryption algorithm, and quantum key identifier. Upon receiving the quantum key injection request, the authentication server can derive or update the original key set in the quantum key data packet according to the candidate derivation algorithm to obtain the derived key. Then, it automatically sends a quantum key injection request to the quantum key management terminal, carrying the derived key, candidate encryption algorithm, and quantum key identifier, so that the quantum key management terminal can generate a quantum key encryption data packet based on the derived key and candidate encryption algorithm. The terminal device receives the quantum key encryption data packet returned by the quantum key management terminal. The original key is generated after the terminal device is registered and authenticated for the quantum key injection service. The quantum key injection request also includes information such as the number of quantum keys pre-acquired by the terminal device and the key length of the quantum keys.

[0088] In one possible implementation, after the terminal device determines the candidate derivation algorithm and candidate encryption algorithm from the subscribed quantum key injection strategy, it can also derive or update the original key according to the candidate derivation algorithm to obtain the derived key. Then, it sends the same request to the quantum key management terminal as the quantum key injection request sent by the authentication server to obtain the quantum key encryption data packet returned by the quantum key management terminal according to the quantum key injection request. This will not be elaborated further here.

[0089] In this manner, the terminal device first receives the quantum key injection strategy sent by the service authentication terminal, then determines a candidate derived algorithm from the set of derived algorithms of the quantum key injection strategy and a candidate encryption algorithm from the set of encryption algorithms of the quantum key injection strategy, and forwards them to the authentication server, so that the authentication server can generate a derived key according to the candidate derived algorithm; and then forwards the quantum key injection request to the quantum key management terminal through the authentication server, so that the quantum key management terminal can encrypt the quantum key data packet to be obtained according to the derived key and the candidate encryption algorithm to generate a quantum key encrypted data packet; finally, it receives the quantum key encrypted data packet returned by the key management terminal.

[0090] S2, based on the decryption algorithm in the quantum key injection strategy, decrypts the quantum key encrypted data packet to obtain the quantum key data packet.

[0091] In Embodiment 1 of this application, after the terminal device receives the quantum key encryption data packet sent by the quantum key management terminal, since the encryption algorithm used by the quantum key encryption data packet is selected by the terminal device from the set of encryption algorithms of the quantum key policy obtained from the service authentication terminal, that is, the encryption algorithm used by the quantum key encryption data packet is the above-mentioned candidate encryption algorithm, the candidate encryption algorithm can be used as the decryption algorithm to decrypt the quantum key encryption data packet to obtain the quantum key data packet.

[0092] The above methods can decrypt quantum key encrypted data packets, thereby improving the security of quantum keys issued by the quantum key management terminal.

[0093] S3 is a designated storage unit that fills the quantum key packet.

[0094] In Embodiment 1 of this application, after the terminal device decrypts the quantum key encrypted data packet, it can directly fill the quantum key data packet into the set storage unit, thereby realizing online filling of the quantum key of the terminal device and improving the efficiency of quantum key filling.

[0095] In summary, the quantum key injection method provided in this application enables the terminal device to obtain the quantum key encrypted data packet issued by the quantum key management terminal online, and decrypt the obtained quantum key encrypted data packet according to the decryption algorithm in the quantum key injection strategy to obtain the quantum key data packet, thereby realizing online quantum key injection and improving the efficiency of quantum key injection; and by combining the terminal device and the service authentication terminal through the 5G core network, the security of transmitting quantum key data packets is ensured.

[0096] To more clearly illustrate the inventive points of this application, the following description is in conjunction with the appendix. Figure 3 An example illustrating the process of quantum key injection into a terminal device:

[0097] Step 1, Send Quantum Key Imprinting Service Request: The terminal device (UE) sends a quantum key imprinting service request to the authentication server (AUSF) through the NAS layer secure channel.

[0098] Step 2, Request forwarding: AUSF forwards the quantum key filling service request to the service authentication terminal (UDM).

[0099] Step 3, Service Subscription Authentication and Return of Quantum Key Imbuing Policy: UDM performs quantum key imbuing service subscription authentication on UE and returns the successfully authenticated quantum key imbuing policy to AUSF and UE.

[0100] Step 4: Determine the candidate derived algorithm and candidate encryption algorithm, and send a quantum key injection request to AUSF: The UE receives the quantum key injection strategy forwarded by AUSF, selects the candidate derived algorithm with the highest priority from the derived algorithm set of the quantum key injection strategy, and selects the candidate encryption algorithm with the highest priority from the encryption algorithm set of the quantum key injection strategy. The UE sends a quantum key injection request to AUSF carrying the candidate derived algorithm, candidate encryption algorithm, and quantum key identifier.

[0101] Step 5: Generate derived key and forward quantum key injection request: AUSF derives the original key from the candidate derivation algorithm in the quantum key injection request to generate a derived key; and sends a quantum key injection request carrying the derived key, candidate encryption algorithm, and quantum key identifier to the quantum key management terminal (KMS).

[0102] Step 6: Generate quantum key encryption data packet: KMS packages the target quantum key corresponding to the quantum key identifier in the quantum key injection request, encrypts it using the candidate encryption algorithm, and generates quantum key encryption data packet.

[0103] Step 7, Send quantum key encrypted data packet: KMS sends quantum key encrypted data packet to UE through a network security channel.

[0104] Step 8: Decrypt the quantum key encrypted data packet and store the quantum key data packet: The UE receives the quantum key encrypted data packet, uses the candidate encryption algorithm as the decryption algorithm to decrypt the quantum key encrypted data packet, obtains the quantum key data packet, and stores the quantum key data packet in the set storage unit.

[0105] Example 2:

[0106] Based on the above Figure 2 The system architecture shown in this application also provides a quantum key processing method, which can be run on an authentication server. Specifically, the method includes: first, obtaining a quantum key injection strategy and an original key, and forwarding the quantum key injection strategy to a terminal device; then, receiving a quantum key injection request from the terminal device, and deriving a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request; finally, sending a quantum key injection request carrying the derived key to a quantum key management terminal, so that the quantum key management terminal can package and encrypt the quantum key data packet corresponding to the quantum key identifier based on the quantum key identifier, candidate encryption algorithm, and derived key in the quantum key injection request, obtaining a quantum key encrypted data packet, and forwarding the quantum key encrypted data packet to the terminal device.

[0107] The method provided in this application enables the authentication server to forward the quantum key strategy issued by the service authentication server to the terminal device. After receiving the quantum key injection request from the terminal device (where the terminal device determines the candidate derivation algorithm and candidate encryption algorithm), the authentication server derives a derived key from the original key generated by the terminal device after registering and authenticating for the quantum key injection service. This derives the derived key, which enables the quantum key management terminal to generate a quantum key encryption data packet based on the derived key and the candidate encryption algorithm. The quantum key encryption data packet is then forwarded to the terminal device, allowing the terminal device to obtain the quantum key encryption data packet online and achieve online quantum key injection, thus improving the efficiency of quantum key injection. Furthermore, after receiving the quantum key injection request from the terminal device, the authentication server derives or updates the original key according to the candidate derivation algorithm in the quantum key injection request. This allows the original key to be updated every time the quantum key management terminal issues a quantum key, improving the security of quantum key transmission.

[0108] Reference Figure 4 As shown, it is a flowchart of a quantum key processing method provided in Embodiment 2 of this application. The method includes:

[0109] S1, obtain the quantum key injection strategy and the original key, and forward the quantum key injection strategy to the terminal device.

[0110] In Embodiment 2 of this application, before obtaining the quantum key injection strategy, the authentication server first receives the quantum key injection service request sent by the terminal device and forwards the quantum key injection service request to the service authentication server, so that the service authentication server can determine the quantum key injection service subscription status of the terminal device based on the terminal device identifier in the quantum key injection service. The method by which the service authentication server determines the quantum key injection service subscription status of the terminal device is the same as the method in Embodiment 1 above, and will not be described again here.

[0111] The authentication server receives the subscription status message returned by the service authentication server based on the quantum key injection service request, and forwards the subscription status message to the terminal device. The subscription status message received by the authentication server is the same as the subscription status message in Embodiment 1 above, and will not be described again here.

[0112] Through the above methods, the authentication server can obtain the quantum key injection services and corresponding quantum key injection strategies that the terminal device has subscribed to, and forward the subscribed quantum key injection services and quantum key injection strategies to the terminal device.

[0113] S2 receives a quantum key injection request sent by the terminal device, and derives a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request.

[0114] In Embodiment 2 of this application, after the authentication server forwards the quantum key injection strategy to the terminal device, the terminal device selects a candidate derived algorithm from the set of derived algorithms of the quantum key injection strategy and a candidate encryption algorithm from the set of encryption algorithms of the quantum key injection strategy. Then, the terminal device sends a quantum key injection request carrying the candidate derived algorithm, the candidate encryption algorithm and the quantum key identifier to the authentication server. The selection process of the candidate derived algorithm and the candidate encryption algorithm can refer to Embodiment 1 above, and will not be repeated here.

[0115] The authentication server receives a quantum key injection request sent by the terminal device. First, it can determine the candidate derived algorithm in the quantum key injection request, and determine the type of the candidate derived algorithm and the derived parameters associated with the candidate derived algorithm. The candidate derived algorithm can be the SM3 algorithm or the HASH algorithm; the derived parameters can be information such as random numbers and time sources. This application does not impose specific restrictions on the type of candidate derived algorithm and the content of the derived parameters.

[0116] The authentication server uses the original key (K) AUSF The candidate derivation algorithm (KDF) and derivation parameters (S) are used to derive a derived key (K) from the original key. QKMS The derived key can be generated using the following formula:

[0117] K QKMS =KDF(K AUSF ,S)

[0118] Optionally, after generating the derived key, the authentication server can also determine the candidate encryption algorithm in the quantum key injection request and determine the type of the candidate encryption algorithm. The candidate encryption algorithm can be the SM4 algorithm or the AES algorithm. This application does not impose specific restrictions on the type of candidate encryption algorithm.

[0119] In this way, when the authentication server receives a quantum key injection request from the terminal device, it can derive / update the original key according to the candidate derivation algorithm in the quantum key injection request. This allows the original key to be updated every time a quantum key is issued by the quantum key management terminal, thereby improving the efficiency of online quantum key distribution while ensuring the security of quantum key transmission.

[0120] S3, send a quantum key injection request carrying the derived key to the quantum key management terminal.

[0121] In the second embodiment of this application, after generating the derived key, the authentication server can send a quantum key injection request to the quantum key management terminal. The quantum key injection request includes the derived key, the candidate encryption algorithm, and the quantum key identifier.

[0122] After receiving a quantum key injection request, the quantum key management terminal can first identify the derived key, quantum key identifier, and candidate encryption algorithm in the quantum key injection request; then, it selects the target quantum key data packet that matches the quantum key identifier from the set of quantum key data packets obtained from the QKD network; then, it determines the type of candidate encryption algorithm, which can also be the SM4 algorithm or the AES algorithm mentioned above, which will not be elaborated here.

[0123] Based on the selected encryption algorithm and derived key, the target quantum key data packet can be encrypted using the following formula:

[0124] Quantum key encrypted data packet = SM4(K) QKMS (Target quantum key data packet)

[0125] Finally, the quantum key encrypted data packet is forwarded to the terminal device.

[0126] In summary, the method provided in this application allows the authentication server to derive or update the original key based on the candidate derivation algorithm and associated derivation parameters in the quantum key injection request sent by the terminal device after receiving the quantum key policy from the service authentication server and forwarding the quantum key policy to the terminal device. The server then automatically forwards the quantum key injection request carrying the derived key and candidate encryption algorithm to the quantum key management terminal, enabling the quantum key management terminal to generate a quantum key encryption data packet based on the derived key and candidate encryption algorithm. This achieves an update to the original key every time the quantum key management terminal issues a quantum key, improving the security of quantum key transmission. Furthermore, the quantum key management terminal forwarding the quantum key encryption data packet to the terminal device enables online quantum key injection for the terminal device, avoiding offline quantum key injection and improving the efficiency of quantum key injection.

[0127] Based on the method provided in Embodiment 1 above, this application also provides a quantum key injection device corresponding to this method, such as... Figure 5 The diagram shown is a schematic representation of a quantum key injection device according to Embodiment 1 of this application. The device includes:

[0128] The data receiving module 501 is used to receive a quantum key injection strategy and a quantum key encryption data packet, wherein the quantum key injection strategy includes an algorithm for encrypting or decrypting the quantum key data packet;

[0129] Data decryption module 502 is used to decrypt the quantum key encrypted data packet based on the decryption algorithm in the quantum key injection strategy to obtain the quantum key data packet;

[0130] The quantum key filling module 503 is used to fill the quantum key data packet into a designated storage unit.

[0131] Based on the method provided in Embodiment 2 above, this application also provides a quantum key processing device corresponding to this method, such as... Figure 6 The diagram shown is a schematic representation of a quantum key processing device according to Embodiment 2 of this application. The device includes:

[0132] The data acquisition module 601 is used to acquire a quantum key injection strategy and a raw key, and forward the quantum key injection strategy to the terminal device. The quantum key injection strategy is obtained after the terminal device successfully authenticates the quantum key injection service it subscribes to, and the raw key is generated by the terminal device after registering and authenticating the quantum key injection service.

[0133] The quantum key processing module 602 is used to receive a quantum key injection request sent by the terminal device, and derive a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request.

[0134] A quantum key injection request carrying the derived key is sent to the quantum key management terminal, so that the quantum key management terminal can package and encrypt the quantum key data packet corresponding to the quantum key identifier based on the quantum key identifier, the candidate encryption algorithm and the derived key in the quantum key injection request, to obtain a quantum key encrypted data packet, and forward the quantum key encrypted data packet to the terminal device.

[0135] Based on the same inventive concept, this application also provides an electronic device that can realize the function of the aforementioned quantum key injection device. (Refer to...) Figure 7 The electronic device includes:

[0136] At least one processor 701 and a memory 702 connected to at least one processor 701. In this embodiment, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 The example shown is the connection between processor 701 and memory 702 via bus 700. Bus 700 is... Figure 7 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The 700 bus can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 7 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 701 can also be called a controller; there is no restriction on the name.

[0137] In this embodiment, memory 702 stores instructions executable by at least one processor 701. By executing the instructions stored in memory 702, at least one processor 701 can execute the quantum key injection method described above. Processor 701 can implement... Figure 5 The functions of each module in the device shown.

[0138] The processor 701 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 702 and calling data stored in memory 702, the processor can perform various functions and process data, thereby monitoring the device as a whole.

[0139] In one possible design, processor 701 may include one or more processing units. Processor 701 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 701. In some embodiments, processor 701 and memory 702 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.

[0140] The processor 701 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the quantum key injection method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0141] Memory 702, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 702 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 702 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 702 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0142] By designing and programming the processor 701, the code corresponding to the quantum key injection method described in the foregoing embodiments can be embedded into the chip, enabling the chip to execute the code during operation. Figure 1 The steps of the quantum key injection method in the illustrated embodiment are described below. How to design and program the processor 701 is a technique well-known to those skilled in the art and will not be elaborated upon here.

[0143] Based on the same inventive concept, embodiments of this application also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the quantum key injection method described above.

[0144] In some possible implementations, various aspects of the quantum key injection method provided in this application can also be implemented in the form of a program product, which includes program code that, when the program product is run on a device, causes the control device to perform the steps in the quantum key injection method according to the various exemplary embodiments of this application described above.

[0145] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0146] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0147] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0148] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0149] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A quantum key injection method, characterized in that, include: Receive a quantum key injection strategy and a quantum key encryption data packet, wherein the quantum key injection strategy is used to encrypt or decrypt the quantum key data packet; Based on the decryption algorithm in the quantum key injection strategy, the quantum key encrypted data packet is decrypted to obtain the quantum key data packet; The quantum key packet is filled into a designated storage unit; The received quantum key injection strategy and quantum key encryption data packet include: From the set of derived algorithms of the quantum key injection strategy, select the candidate derived algorithm with the highest priority, and from the set of encryption algorithms of the quantum key injection strategy, select the candidate encryption algorithm with the highest priority. Send a quantum key injection request carrying the candidate derived algorithm, the candidate encryption algorithm, and the quantum key identifier to the authentication server, so that the authentication server generates a derived key based on the candidate derived algorithm and the original key; The authentication server forwards a quantum key injection request carrying the derived key, the candidate encryption algorithm, and the quantum key identifier to the quantum key management terminal, so that the quantum key management terminal generates the quantum key encryption data packet. Receive the quantum key encryption data packet returned by the quantum key management terminal.

2. The method of claim 1, wherein, Prior to the quantum key injection strategy, the following is also included: The authentication server forwards the quantum key injection service request to the service authentication server, so that the service authentication server can determine the quantum key injection service subscription status of the terminal device based on the terminal device identifier in the quantum key injection service request. The service authentication terminal receives a subscription status message returned based on the quantum key injection service request. The subscription status message is either a first feedback message that provides the terminal device with a quantum key injection strategy corresponding to the quantum key injection service, or a second feedback message that refuses to provide the terminal device with a quantum key injection service.

3. A quantum key processing method characterized by, include: Obtain a quantum key injection strategy and a raw key, and forward the quantum key injection strategy to a terminal device. The quantum key injection strategy is obtained after the terminal device successfully authenticates the quantum key injection service it has subscribed to, and the raw key is generated by the terminal device after registering and authenticating the quantum key injection service. The system receives a quantum key injection request from the terminal device, carrying a candidate derivation algorithm, a candidate encryption algorithm, and a quantum key identifier. Based on the candidate derivation algorithms in the quantum key injection request, the system derives a derived key from the original key. The candidate derivation algorithm is the highest-priority candidate derivation algorithm selected by the terminal device from the set of derivation algorithms of the quantum key injection strategy. The candidate encryption algorithm is the highest-priority candidate encryption algorithm selected by the terminal device from the set of encryption algorithms of the quantum key injection strategy. A quantum key injection request carrying the derived key, the candidate encryption algorithm, and the quantum key identifier is sent to the quantum key management terminal. The quantum key management terminal then packages and encrypts the quantum key data packet corresponding to the quantum key identifier based on the quantum key identifier, the candidate encryption algorithm, and the derived key in the quantum key injection request, to obtain a quantum key encrypted data packet, and forwards the quantum key encrypted data packet to the terminal device.

4. The method of claim 3, wherein, Before obtaining the quantum key injection strategy, the following is also included: The system receives a quantum key refill service request sent by the terminal device and forwards the quantum key refill service request to the service authentication terminal, so that the service authentication terminal can determine the quantum key refill service subscription status of the terminal device based on the terminal device identifier in the quantum key refill service request. The system receives a subscription status message returned by the service authentication terminal based on the quantum key injection service request, and forwards the subscription status message to the terminal device. The subscription status message is either a first feedback message that provides the terminal device with a quantum key injection strategy corresponding to the quantum key injection service, or a second feedback message that refuses to provide the terminal device with the quantum key injection service.

5. The method of claim 3, wherein, The process of deriving a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request includes: Determine the derivation parameters associated with the candidate derivation algorithm, and derive the original key based on the candidate derivation algorithm and the derivation parameters to obtain the derived key.

6. A quantum key injection device, characterized in that, include: A data receiving module is used to receive a quantum key injection strategy and a quantum key encryption data packet, wherein the quantum key injection strategy includes an algorithm for encrypting or decrypting the quantum key data packet; The data decryption module is used to decrypt the quantum key encrypted data packet based on the decryption algorithm in the quantum key injection strategy to obtain the quantum key data packet; A quantum key filling module is used to fill the quantum key data packet into a designated storage unit; Specifically, the data receiving module is configured to: select the highest priority candidate derived algorithm from the set of derived algorithms of the quantum key injection strategy; select the highest priority candidate encryption algorithm from the set of encryption algorithms of the quantum key injection strategy; send a quantum key injection request carrying the candidate derived algorithm, the candidate encryption algorithm, and a quantum key identifier to the authentication server, so that the authentication server generates a derived key based on the candidate derived algorithm and the original key; forward the quantum key injection request carrying the derived key, the candidate encryption algorithm, and the quantum key identifier to the quantum key management terminal through the authentication server, so that the quantum key management terminal generates the quantum key encryption data packet; and receive the quantum key encryption data packet returned by the quantum key management terminal.

7. A quantum key processing device, characterized in that, include: The data acquisition module is used to acquire the quantum key injection strategy and the original key, and forward the quantum key injection strategy to the terminal device. The quantum key injection strategy is obtained after the terminal device successfully authenticates the quantum key injection service it subscribes to, and the original key is generated by the terminal device after registering and authenticating the quantum key injection service. A quantum key processing module is configured to receive a quantum key injection request sent by the terminal device, carrying a candidate derivation algorithm, a candidate encryption algorithm, and a quantum key identifier; and to derive a derived key from the original key based on the candidate derivation algorithm in the quantum key injection request. The candidate derivation algorithm is the highest-priority candidate derivation algorithm selected by the terminal device from the set of derivation algorithms of the quantum key injection strategy; the candidate encryption algorithm is the highest-priority candidate encryption algorithm selected by the terminal device from the set of encryption algorithms of the quantum key injection strategy. A quantum key injection request carrying the derived key, the candidate encryption algorithm, and the quantum key identifier is sent to the quantum key management terminal. The quantum key management terminal then packages and encrypts the quantum key data packet corresponding to the quantum key identifier based on the quantum key identifier, the candidate encryption algorithm, and the derived key in the quantum key injection request, to obtain a quantum key encrypted data packet, and forwards the quantum key encrypted data packet to the terminal device.

8. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the method steps of any one of claims 1-5.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-5.

Citation Information

Patent Citations

  • Automatic quantum key charging method and system adapting to electric power services

    CN109412794A